{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/common-vulnerability-classes"},"x-facet":{"type":"skill","slug":"common-vulnerability-classes","display":"Common Vulnerability Classes","count":1},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_9f751fdd-209"},"title":"Software Engineer, Security","description":"<p><strong>About the role</strong></p>\n<p>You&#39;ll protect Gamma&#39;s platform, infrastructure, and data as we scale to serve hundreds of millions of users. This involves building security tooling and automation, partnering with engineering teams to embed security into everything we ship, and helping shape how the company thinks about security as a practice. You&#39;ll work across the organisation to identify and mitigate risks without slowing down development velocity.</p>\n<p>This role combines hands-on security engineering with strategic influence. You&#39;ll write code to solve security problems, conduct architecture reviews, lead vulnerability management, and drive initiatives for compliance frameworks like SOC 2 and ISO 27001. You&#39;ll work closely with engineering, product, and compliance to make security foundational rather than reactive.</p>\n<p>Our team has a strong in-office culture and works in person 4–5 days per week in San Francisco. We love working together to stay creative and connected, with flexibility to work from home when focus matters most.</p>\n<p><strong>What you&#39;ll do</strong></p>\n<ul>\n<li>Design and implement security controls across Gamma&#39;s AWS infrastructure and application layer</li>\n<li>Build security tooling and automation to detect, prevent, and respond to threats at scale</li>\n<li>Conduct security reviews of architecture designs, code, and infrastructure changes</li>\n<li>Lead vulnerability management, coordinate bug bounty responses, and drive remediation priorities</li>\n<li>Develop and maintain security monitoring, alerting, and incident response capabilities</li>\n<li>Partner with engineering teams on secure coding practices and threat modeling</li>\n</ul>\n<p><strong>What you&#39;ll bring</strong></p>\n<ul>\n<li>5+ years of software engineering experience with at least 2–3 years focused on security engineering or application security</li>\n<li>Strong hands-on experience securing AWS environments, including IAM, VPC, security groups, CloudTrail, and GuardDuty</li>\n<li>Proficiency in at least one backend language (Python, TypeScript/Node.js, or Go preferred) with experience building security tools</li>\n<li>Deep understanding of web application security including OWASP Top 10, common vulnerability classes, and authentication/authorisation patterns, with experience implementing security controls in CI/CD pipelines and infrastructure-as-code (Terraform, CloudFormation)</li>\n<li>Clear communicator who works well embedded with product engineering teams</li>\n<li>Background in penetration testing, offensive security, and SIEM/log analysis</li>\n<li>Experience at a high-growth SaaS startup navigating rapid scaling and compliance (Nice to have)</li>\n</ul>\n<p><strong>Compensation range:</strong></p>\n<p>The base salary for this full-time position, which spans multiple internal levels depending on qualifications, ranges between $180K - $310K plus benefits &amp; equity. _Final offer amounts are determined by multiple factors, including but not limited to experience and expertise in the requirements listed above._</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_9f751fdd-209","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Gamma","sameAs":"https://www.gamma.com","logo":"https://logos.yubhub.co/gamma.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/gamma/79b3efcd-0380-41bc-9556-bc7c681adc43","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"Full time","x-salary-range":"$180K - $310K","x-skills-required":["AWS","IAM","VPC","security groups","CloudTrail","GuardDuty","backend language","Python","TypeScript/Node.js","Go","web application security","OWASP Top 10","common vulnerability classes","authentication/authorisation patterns","CI/CD pipelines","infrastructure-as-code","Terraform","CloudFormation"],"x-skills-preferred":[],"datePosted":"2026-04-24T12:15:44.864Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"AWS, IAM, VPC, security groups, CloudTrail, GuardDuty, backend language, Python, TypeScript/Node.js, Go, web application security, OWASP Top 10, common vulnerability classes, authentication/authorisation patterns, CI/CD pipelines, infrastructure-as-code, Terraform, CloudFormation","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":180000,"maxValue":310000,"unitText":"YEAR"}}}]}