About Us
Queue builds robots to fill prescriptions. Our machine is designed to take stock bottles of medication and produce counted, labeled vials, so that pharmacists and technicians can spend their time on patients. Our first product is built to work behind the pharmacy counter and to be operated by pharmacy staff.
About the Role
You own security engineering for a pharmacy robot and everything it talks to: the machine, its operating-system image, the software that runs on it, the cloud service that commands it, and the path that updates it. When a customer asks how each machine proves its identity, who can reach it and how, and what an independent test found and what was done about it, the answer rests on your work, and every statement in it is backed by something the system produces.
What You'll Own
The threat model — A written model of the trust boundaries: machine to cloud, operator to screen, the update path, remote support, and suppliers. You keep it current as designs change.
Security review of designs — Designs come to you early; you review them and your review is recorded.
Device identity and key custody — The threat model, the priorities and the verification are yours. The engineers who own the operating-system image build the platform side with you.
Independent security testing — Scope, test environment, triage, remediation with the owning squads, and retest evidence. You run it end to end.
Finding and fixing weaknesses — How weaknesses in our code, dependencies, device images and cloud are found, triaged and fixed. It is shared with the squads that own each part: you set the rules, track each finding to closure and report where we stand.
Incident response — The security side of every incident: detection, triage, containment, evidence and what changes afterwards. It is shared with the owning squads, and you run it with the systems reliability engineers, who run the operational response.
Customer security reviews — A customer's security review asks detailed questions and treats our answers as commitments. Before a statement is sent, you check it against the evidence that can substantiate it: the versioned implementation, the deployed configuration and the operational records. A statement says what is built, what is designed and what is planned, and keeps the three apart.
Cloud posture — Identity and access, secrets, the review of infrastructure changes, and what the cloud provider's detection services report.
Security and privacy controls — For the controls Queue commits to, including those that follow from HIPAA, you verify each control in the system and take its evidence from the system.
You assess and you recommend. You do not accept risk on the company's behalf: an exception is recorded with its approver and conditions, and an authorized business owner accepts what remains.
First 90 Days
Day 30: You have traced the trust boundaries yourself, and you hold the threat model and the record of independent testing. You have reviewed your first design.
Day 60: You hold the priorities and the verification for device identity and key custody, with the engineers who own the operating-system image. You hold the inventory of secrets and keys and their rotation schedule. Every security statement that goes to a customer passes your check first.
Day 90: You have written the scope for the next independent test and prepared the environment it will run against. Every design that came to you has a recorded review. You can hand an assessor a control's evidence as output from the system.
What We're Looking For
Must-Have
Ownership — you have owned the security of a shipped product end to end, and you can describe a problem you found, fixed and followed until it stayed fixed. Consulting alone or compliance alone is not this.
You build — you read and write code. Ours is Rust, TypeScript and Python: deep skill in one and comfort reading the others. Your reviews come with a patch or with guidance precise enough to act on.
Systems and network depth — TLS and certificates, identity and access, secrets management, Linux hardening. You can reason about a trust boundary from the hardware to the cloud.
Offensive fluency with defensive judgment — you have run or worked closely with penetration tests. You rank issues by what they could do to this system and its users, and you can defend deferring one.
Threat modeling that engineers use — you would sooner remove an input than add a control, and engineers ask for your review.
Exact writing — you state what is true at the strength the evidence supports, to an engineer, an executive or a customer's assessor.
Nice-to-Have
Device security: verified start-up, hardware-held keys, signed updates, fleet identity.
Security in healthcare or another regulated industry, and customer security reviews from the supplier's side.
Cloud security engineering on AWS.
Supply-chain security: dependency policy, artifact signing, provenance.
Working knowledge of IEC 62443, UL 2900-1 or NISTIR 8259.
How We Hire
Recruiter Screen (30 min)
Technical Interview (90 min) — a take-home exercise of 2 to 3 hours, sent at least 24 hours before: a small working system to harden. We go through it together: what you fixed first, and why.
Design Interview (60 min) — on trust boundaries and key custody.
Leadership Interview (60 min) — how you own your work and work across squads.
Two interviewers score each technical stage independently.
What We Offer
Ownership — security engineering for the machine and everything it talks to
Hard problems: trust boundaries from the hardware to the cloud, device identity and key custody, and the path that updates the machine
Small team, zero bureaucracy, high trust
Why Join Us Now?
Impact & Growth
Team and Culture
Reports to the Head of Software Engineering with significant autonomy and influence
The same person sets the security requirements you work to
Who You Work With: You work every day with the engineers who build the on-machine software, the cloud service and the operating-system image
Where We Work: Hybrid, three days a week at our headquarters in the Bay Area; device security work needs the hardware in front of you
Our Values
Servant Leadership
Do the Hard Things
Own Your Work
Default is Now
Own Your Work comes first in this role: you follow a problem until it stays fixed.
Contact: If you have any questions, please contact us at careers@queue.inc