{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/burp-suite"},"x-facet":{"type":"skill","slug":"burp-suite","display":"Burp Suite","count":8},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_65b94380-b2c"},"title":"Penetration Tester","description":"<p>As a Penetration Tester, you will conduct penetration testing of web applications, APIs, and microservices architectures aligned with standards such as from OWASP. You will perform advanced security assessments of cloud environments (AWS, Azure, GCP), hybrid, and on-prem infrastructure. You will also perform security validation of Infrastructure as Code (IaC) implementations, identifying misconfigurations and compliance gaps.</p>\n<p>You will conduct mobile application security assessments for Android and iOS platforms. You will author detailed technical reports documenting vulnerabilities, risk analysis, and remediation recommendations. You will present findings to stakeholders and technical teams. You will mentor colleagues and contribute to team skill development. You will handle the development of testing methodologies and processes through automation and innovation.</p>\n<p><strong>Key Responsibilities:</strong></p>\n<ul>\n<li>Conduct penetration testing of web applications, APIs, and microservices architectures</li>\n<li>Perform advanced security assessments of cloud environments, hybrid, and on-prem infrastructure</li>\n<li>Validate Infrastructure as Code (IaC) implementations</li>\n<li>Conduct mobile application security assessments for Android and iOS platforms</li>\n<li>Author detailed technical reports</li>\n<li>Present findings to stakeholders and technical teams</li>\n<li>Mentor colleagues and contribute to team skill development</li>\n<li>Develop testing methodologies and processes through automation and innovation</li>\n</ul>\n<p><strong>Requirements:</strong></p>\n<ul>\n<li>Proven track record in web application security testing with Burp Suite proficiency</li>\n<li>Good understanding of IT architectures and security concepts</li>\n<li>Security assessment and testing certifications (e.g., OSCP, OSWE, WAPTX) or cloud security certs</li>\n<li>Experience with Infrastructure as Code (Terraform, Ansible)</li>\n<li>Experience writing clear, actionable reports</li>\n<li>Demonstrated experience in cloud security for at least one major platform (AWS/Azure/GCP)</li>\n</ul>\n<p><strong>Benefits:</strong></p>\n<ul>\n<li>Support and appreciation for colleagues as they are and celebrate successes together</li>\n<li>Welcome creativity and new impulses</li>\n<li>Opportunity to grow in tasks, knowledge, and responsibility</li>\n<li>Comprehensive overview of benefits available</li>\n</ul>\n<p><strong>Work Arrangements:</strong></p>\n<ul>\n<li>Start date by arrangement, always on the 1st and 15th of the month</li>\n<li>Full-time (40h) working hours</li>\n<li>27 vacation days</li>\n<li>Unlimited employment contract</li>\n<li>Flexibility and willingness to travel</li>\n<li>Valid work permit required</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_65b94380-b2c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"MHP","sameAs":"http://www.mhp.com/","logo":"https://logos.yubhub.co/mhp.com.png"},"x-apply-url":"https://jobs.porsche.com/index.php?ac=jobad&id=17643","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Burp Suite","OWASP","Cloud security","Infrastructure as Code","Mobile application security"],"x-skills-preferred":[],"datePosted":"2026-04-22T17:28:23.747Z","employmentType":"FULL_TIME","occupationalCategory":"IT","industry":"Consulting","skills":"Burp Suite, OWASP, Cloud security, Infrastructure as Code, Mobile application security"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_45a87931-4a2"},"title":"Security Engineer - Platform Security","description":"<p>We&#39;re seeking a talented and driven Security Engineer to join our Platform Security team. You will build cutting-edge security solutions to protect our Kubernetes-based infrastructure and advance secure AI-driven systems.</p>\n<p>In this role, you will design and implement AI-powered security tools, proactively address vulnerabilities, and champion secure engineering practices across the organisation.</p>\n<p>Ideal candidates are passionate about impactful innovation, excel at writing clean, efficient code, and thrive in fast-paced environments to support xAI&#39;s mission of creating a trusted and secure global digital platform.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Design and build AI-driven security tooling and agents using Grok to identify, analyse, and mitigate vulnerabilities in the platform infrastructure and customer-facing application(s)</li>\n</ul>\n<ul>\n<li>Proactively identify security problems to solve and own the design and implementation end-to-end</li>\n</ul>\n<ul>\n<li>Collaborate and be a security champion while driving technical decisions across the organisation</li>\n</ul>\n<p>Basic Qualifications:</p>\n<ul>\n<li>3+ years of experience in fast-paced, high-impact environments, ideally at startups or tech-driven companies.</li>\n</ul>\n<ul>\n<li>Expertise in Python, Rust, or Go, with strong problem-solving skills and a focus on clean, efficient code.</li>\n</ul>\n<ul>\n<li>Certifications like CISA, CRISC, CGEIT, Security+, CASP+, or similar preferred.</li>\n</ul>\n<ul>\n<li>Proven experience building tools or systems from scratch, with a focus on scalable solutions.</li>\n</ul>\n<ul>\n<li>Proficiency in designing scalable backend architectures to support secure systems.</li>\n</ul>\n<ul>\n<li>Familiarity with security testing frameworks (e.g., Burp Suite, OWASP ZAP, SAST/DAST).</li>\n</ul>\n<ul>\n<li>Experience with Docker and Kubernetes for deploying and securing containerized applications.</li>\n</ul>\n<ul>\n<li>Knowledge of software supply chain tools, including SBOM management and dependency scanning.</li>\n</ul>\n<p>Preferred Skills and Experience:</p>\n<ul>\n<li>Experience developing AI-driven security tools or integrating AI into security workflows.</li>\n</ul>\n<ul>\n<li>Familiarity with Kubernetes-based environments and securing cloud-native infrastructure.</li>\n</ul>\n<ul>\n<li>Proven ability to drive technical decisions and influence security practices across teams.</li>\n</ul>\n<ul>\n<li>A passion for challenging the status quo and building transformative security solutions.</li>\n</ul>\n<ul>\n<li>Strong collaboration skills, with experience working in dynamic, cross-functional teams.</li>\n</ul>\n<ul>\n<li>A sense of humour and adaptability to thrive in a fast-paced, mission-driven environment.</li>\n</ul>\n<p>ITAR Requirements:</p>\n<p>To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorisations from the U.S. Department of State. Learn more about the ITAR here.</p>\n<p>Compensation and Benefits:</p>\n<p>$180,000 - $440,000 USD</p>\n<p>Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_45a87931-4a2","directApply":true,"hiringOrganization":{"@type":"Organization","name":"xAI","sameAs":"https://www.xai.com/","logo":"https://logos.yubhub.co/xai.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/4835611007","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$180,000 - $440,000 USD","x-skills-required":["Python","Rust","Go","Grok","Docker","Kubernetes","Burp Suite","OWASP ZAP","SAST/DAST","SBOM management","dependency scanning"],"x-skills-preferred":["AI-driven security tools","integrating AI into security workflows","Kubernetes-based environments","securing cloud-native infrastructure","driving technical decisions","influencing security practices","challenging the status quo","transformative security solutions","collaboration skills","dynamic cross-functional teams"],"datePosted":"2026-04-18T15:51:56.952Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Rust, Go, Grok, Docker, Kubernetes, Burp Suite, OWASP ZAP, SAST/DAST, SBOM management, dependency scanning, AI-driven security tools, integrating AI into security workflows, Kubernetes-based environments, securing cloud-native infrastructure, driving technical decisions, influencing security practices, challenging the status quo, transformative security solutions, collaboration skills, dynamic cross-functional teams","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":180000,"maxValue":440000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_62900fcd-562"},"title":"Security Engineer - Offensive Security","description":"<p>As an Offensive Security Engineer on the Proactive Threat team at Stripe, you will simulate the tactics, techniques, and procedures (TTPs) of real-world adversaries to uncover security risks across Stripe&#39;s products and infrastructure.</p>\n<p>You&#39;ll conduct hands-on penetration testing, lead red team engagements, and collaborate with blue team counterparts to validate and improve detection and response capabilities. Your work will directly influence how Stripe builds, ships, and secures financial infrastructure used by millions of businesses worldwide.</p>\n<p>Responsibilities:</p>\n<p>Conduct comprehensive penetration tests across web applications, APIs, cloud environments (AWS/GCP/Azure), mobile applications, and internal infrastructure.</p>\n<p>Plan and execute red team engagements that emulate the TTPs of cyber and criminal threat actors targeting financial services, including initial access, lateral movement, persistence, and data exfiltration scenarios.</p>\n<p>Perform assumed-breach and objective-based assessments to test detection and response capabilities in coordination with defensive teams.</p>\n<p>Partner with detection engineering, threat intelligence, and incident response teams to validate security controls, identify coverage gaps, and improve detection fidelity.</p>\n<p>Contribute adversary tradecraft insights to inform detection rule development, threat hunting hypotheses, and incident response playbooks.</p>\n<p>Support incident investigations by providing offensive expertise, log analysis, and root cause analysis when required.</p>\n<p>Design, develop, and maintain custom offensive tools, scripts, and automation frameworks to enhance assessment efficiency and coverage.</p>\n<p>Build internal platforms and workflows that enable scalable, repeatable offensive operations.</p>\n<p>Contribute to internal security tooling repositories and champion engineering best practices within the team.</p>\n<p>Automate repetitive testing tasks, payload generation, and reporting workflows using modern development practices.</p>\n<p>Produce clear, actionable reports that communicate technical findings, business risk, and remediation guidance to both technical and non-technical stakeholders.</p>\n<p>Act as a subject-matter expert and primary point of contact for stakeholder teams engaged in offensive security programs and Stripe-wide security initiatives.</p>\n<p>Lead offensive security projects end-to-end, mentor junior team members, and foster a culture of continuous learning and knowledge sharing.</p>\n<p>Stay current with emerging threats, vulnerabilities, and attack techniques; share research internally and contribute to the broader security community.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_62900fcd-562","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Stripe","sameAs":"https://stripe.com/","logo":"https://logos.yubhub.co/stripe.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/stripe/jobs/7820898","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Python","Go","Web application security","Cloud platforms (AWS, Azure, or GCP)","Offensive tooling (Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound)","Adversary tradecraft and frameworks (MITRE ATT&CK)","Excellent written and verbal communication skills"],"x-skills-preferred":["Experience conducting offensive security in fintech, financial services, or other highly regulated environments","Background in vulnerability research, exploit development, or CVE discovery","Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations)","Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support","Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows"],"datePosted":"2026-04-18T15:51:01.913Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Ireland"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Go, Web application security, Cloud platforms (AWS, Azure, or GCP), Offensive tooling (Burp Suite, Cobalt Strike, Mythic, Sliver, BloodHound), Adversary tradecraft and frameworks (MITRE ATT&CK), Excellent written and verbal communication skills, Experience conducting offensive security in fintech, financial services, or other highly regulated environments, Background in vulnerability research, exploit development, or CVE discovery, Experience collaborating with threat intelligence, detection engineering, or incident response teams (purple team operations), Familiarity with big data and log analysis tools (Splunk, Databricks, PySpark, osquery, etc.) for threat hunting or investigative support, Proficiency with AI/LLM-assisted development tools (e.g., Claude Code, Cursor, GitHub Copilot) and experience applying them to offensive security workflows"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1e992e68-7cd"},"title":"Staff Engineer, Offensive Security","description":"<p>As a Staff Engineer, Offensive Security at Twilio, you will act as a Technical Lead and design complex attack chains that demonstrate systemic risk. You will spend as much time writing custom code and researching new bypasses as you do executing tests.</p>\n<p>In this role, you will:</p>\n<p>Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android). Conduct network and cloud level assessments with various tooling. Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives. Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs). Draft high-quality reports that detail the &quot;path to compromise&quot; with clear, reproducible steps for developers. Manage and update the team&#39;s testing infrastructure (e.g., Burp Suite, and basic C2 listeners). Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR. Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities. Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth. Build automated testing frameworks for AI systems (e.g., using PyRIT, Promptfoo, or Garak) to test for models related to sensitive data leakage. Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes. Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on the techniques used during an engagement. Oversee the organization&#39;s bug bounty program, identifying trends in submissions to suggest broad architectural security changes.</p>\n<p>Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1e992e68-7cd","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Twilio","sameAs":"https://www.twilio.com/","logo":"https://logos.yubhub.co/twilio.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/twilio/jobs/7622285","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Offensive security","Penetration testing","Bug bounty","AppSec","Vulnerability exploitation","MITRE ATT&CK matrix","OWASP Top 10 for web applications","OWASP Top 10 for LLMs","Post exploitation","Adversarial ML","Burp Suite professional","Nmap","Metasploit","Wireshark","LangChain","TensorFlow","C2 frameworks","Python","Bash","C++"],"x-skills-preferred":["Telecom expertise","Excellent written and verbal communication skills","Ability to influence and build effective working relationships with all levels of the organization","Proficiency in multiple languages applicable to the region"],"datePosted":"2026-04-18T15:49:45.138Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote - Ireland"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Offensive security, Penetration testing, Bug bounty, AppSec, Vulnerability exploitation, MITRE ATT&CK matrix, OWASP Top 10 for web applications, OWASP Top 10 for LLMs, Post exploitation, Adversarial ML, Burp Suite professional, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, C2 frameworks, Python, Bash, C++, Telecom expertise, Excellent written and verbal communication skills, Ability to influence and build effective working relationships with all levels of the organization, Proficiency in multiple languages applicable to the region"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_5c7e46c8-c5c"},"title":"Application Security Intern","description":"<p>We&#39;re looking for a curious and motivated Application Security Intern to help us build secure products and development practices at VGS. As an Application Security Intern, you will partner with security and engineering teams to evaluate application risk, improve secure software development workflows, and help developers ship software safely in an environment that handles highly sensitive payment and identity data.</p>\n<p>Your responsibilities will include:</p>\n<ul>\n<li>Supporting application security reviews for services, APIs, and new product features across the VGS platform.</li>\n<li>Helping identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.</li>\n<li>Participating in threat modeling and secure design discussions with engineering teams during feature development.</li>\n<li>Evaluating the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC.</li>\n<li>Assisting with manual testing and validation of web application and API security issues.</li>\n<li>Helping improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.</li>\n<li>Working with engineers to understand remediation options and clearly document security risks and recommendations.</li>\n<li>Contributing to improving security tooling and guardrails in CI/CD and development workflows.</li>\n</ul>\n<p>We&#39;re looking for someone with a strong interest in secure software design, cloud-native architectures, and automation. You should have a foundational understanding of application security concepts, such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.</p>\n<p>At VGS, we have a remote-first philosophy, and we&#39;re looking for someone who is comfortable working independently and collaboratively as part of a team.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_5c7e46c8-c5c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"VGS","sameAs":"https://www.vgs.com","logo":"https://logos.yubhub.co/vgs.com.png"},"x-apply-url":"https://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b","x-work-arrangement":"remote","x-experience-level":"entry","x-job-type":"internship","x-salary-range":null,"x-skills-required":["application security","secure software development","cloud-native architectures","automation","OWASP Top 10","API security","authentication and authorization","secure coding","common software vulnerabilities"],"x-skills-preferred":["LMMs","threat modeling","Burp Suite","SAST/DAST tools","CI/CD pipelines","Docker/Kubernetes","cloud environments"],"datePosted":"2026-04-17T13:08:01.601Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"jobLocationType":"TELECOMMUTE","employmentType":"INTERN","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, secure software development, cloud-native architectures, automation, OWASP Top 10, API security, authentication and authorization, secure coding, common software vulnerabilities, LMMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, cloud environments"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_544e96bb-5c3"},"title":"Security Engineer, Application Security","description":"<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>New York City</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are building a team of talented engineers, researchers, and designers who share our vision and values.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_544e96bb-5c3","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/ec5a5d98-6314-44d9-9466-8d4d7ee866f6","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:31:40.678Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York City"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_90d20db9-de4"},"title":"Security Engineer, Application Security","description":"<p><strong>Job Posting</strong></p>\n<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>San Francisco</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are committed to advancing the state-of-the-art in AI research and development.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_90d20db9-de4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/0322d6d8-6588-4209-a304-83e768063a25","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:30:51.618Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_659bf794-7b5"},"title":"Security Engineer, Application Security","description":"<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>Seattle</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_659bf794-7b5","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/1e110226-448a-4c0b-b0e4-d0f5df579fbf","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:29:22.823Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Seattle"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}}]}