<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>6c1cd36d-464</externalid>
      <Title>Senior Security Operations Engineer, Detection &amp; Response</Title>
      <Description><![CDATA[<p>About Us</p>
<p>dbt Labs is the pioneer of analytics engineering, helping data teams transform raw data into reliable, actionable insights. As of February 2025, we’ve grown from an open source project into the leading analytics engineering platform, now used by over 90,000 teams every week, driving data transformations and AI use cases.</p>
<p>We’re backed by top-tier investors including Andreessen Horowitz, Sequoia Capital, and Altimeter. At our core, we believe in empowering data practitioners:</p>
<ul>
<li>Reliable, high-quality data is the fuel that propels AI-powered data engineering.</li>
<li>AI is changing data work, fast. dbt’s data control plane keeps data engineers ahead of that curve.</li>
<li>We empower engineers to deliver reliable, governed data faster, cheaper, and at scale.</li>
</ul>
<p>About the Security Team</p>
<p>The mission of the Security Engineering team at dbt Labs is to provide clear, opinionated security guidance and scalable, secure-by-default offerings to engineers for the purpose of securing software development and enabling pragmatic risk decisions at dbt.</p>
<p><strong>Responsibilities</strong></p>
<p>As a Senior Security Operations Engineer on the Detection &amp; Response team, you will strengthen and maintain the company&#39;s security posture throughout the threat detection lifecycle from telemetry collection and continuous monitoring through threat detection, incident response, and security event management. You will serve as a subject matter expert for security operations across the dbt Labs&#39; teams and technology infrastructure, including multi-cloud production environments, identity, endpoints, and SaaS technologies.</p>
<p><strong>Key Responsibilities</strong></p>
<ul>
<li>Participate in a 24/7 on-call rotation providing coverage for active security incidents, investigations, and security events across our global infrastructure.</li>
<li>Lead investigation and remediation of security incidents, coordinating cross-functional response efforts to minimize impact and recovery time.</li>
<li>Play a major role in bootstrapping an end to end D&amp;R alert and investigation pipeline.</li>
<li>Triage and investigate security alerts from detection tools including Wiz Defend, Crowdstrike, and cloud security platforms to identify genuine threats and reduce false positives.</li>
<li>Develop and maintain detection rules, runbooks, and response procedures mapped to the company&#39;s threat model.</li>
<li>Automate alert triage workflows and improve mean time to detection and response through tooling and process enhancements, including leveraging AI enrichment and processing.</li>
<li>Collaborate with Infrastructure and Application Security teams to implement secure-by-design principles and remediate identified security issues.</li>
<li>Conduct security event analysis to identify policy violations, misconfigurations, and potential attack vectors before they become incidents.</li>
<li>Partner with our Enterprise Security &amp; Technology team to enhance endpoint security controls and monitoring across endpoints (MacOS laptops &amp; some Windows and Linux-based development environments).</li>
<li>Design and facilitate tabletop exercises and game days to test detection, response, recovery, and remediation capabilities.</li>
<li>Contribute to the maturation of the security incident response program through documentation, training, and process improvements.</li>
<li>Mentor junior security engineers and cross-functional team members on incident handling best practices.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Demonstrated ability to excel in high-pressure situations; we need someone who can make sound decisions during active security incidents and can calmly serve as incident commander with confidence.</li>
</ul>
<p><strong>Qualifications</strong></p>
<ul>
<li>Have 8+ years of professional experience in security-related domains, including at least 4 years in security operations, incident response, threat hunting, or threat detection roles.</li>
<li>Have demonstrable experience leading security incident investigations and coordinating cross-team response efforts.</li>
</ul>
<p><strong>What We Offer</strong></p>
<ul>
<li>Competitive compensation packages commensurate with experience, including salary, equity, and where applicable, performance-based pay.</li>
<li>Opportunity to work with a leading analytics engineering platform and contribute to the growth and success of the company.</li>
<li>Collaborative and dynamic work environment with a team of experienced professionals.</li>
<li>Opportunities for professional growth and development.</li>
</ul>
<p><strong>How to Apply</strong></p>
<p>If you are a motivated and experienced security professional looking for a new challenge, please submit your resume and cover letter to [insert contact information]. We look forward to hearing from you!</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Security Operations, Incident Response, Threat Hunting, Threat Detection, Cloud Security, Endpoint Security, Security Event Analysis, Security Incident Response, Tabletop Exercises, Game Days, Documentation, Training, Process Improvements, Mentoring, Security Engineering, Data Control Plane, Analytics Engineering, AI-Powered Data Engineering, Reliable High-Quality Data, Secure-By-Default Offerings, Pragmatic Risk Decisions, Multi-Cloud Production Environments, Identity, Endpoints, SaaS Technologies, Wiz Defend, Crowdstrike, Cloud Security Platforms, Detection Rules, Runbooks, Response Procedures, Mean Time to Detection, Mean Time to Response, AI Enrichment, AI Processing, Secure-By-Design Principles, Infrastructure Security, Application Security, Endpoint Security Controls, Monitoring</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>dbt Labs</Employername>
      <Employerlogo>https://logos.yubhub.co/getdbt.com.png</Employerlogo>
      <Employerdescription>dbt Labs is a leading analytics engineering platform, used by over 90,000 teams every week, with annual recurring revenue (ARR) surpassing $100 million.</Employerdescription>
      <Employerwebsite>https://www.getdbt.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/dbtlabsinc/jobs/4674498005</Applyto>
      <Location>US - Remote</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>777a6e79-5d9</externalid>
      <Title>Senior Software Engineer, Security Engineering</Title>
      <Description><![CDATA[<p>Secure Every Identity ----------------------- Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>
<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work.</p>
<p>The Role -------- We seek a knowledgeable and development-focused Security Engineer, who will build micro-services to secure Customer Identity Products and Infrastructure.</p>
<p>Responsibilities --------------- Work across a globally distributed product-aligned team of security engineers Establish a deep understanding of Okta Customer Identity products and infrastructure Collaborate when necessary with the Okta Security team on security operations Build, deploy &amp; maintain scalable and reliable infrastructure services as well as security solutions for customer identity products Build, deploy &amp; maintain automation to improve platform security capabilities at scale including logging, threat detection and compliance benchmarks to increase our security posture Help meet our operational security commitments by thinking like an attacker, assessing the risk, and advising on mitigation strategies Support security investigations in coordination with the Okta Security team, participate in root cause analysis and perform necessary remediations. Support stakeholders by proposing mitigation strategies for end-of-life software and security vulnerability and patch management</p>
<p>Requirements ----------- You have 3+ years of hands-on development experience writing microservices with Golang You have 3+ years of experience in cloud infrastructure security, product security You have working knowledge and hands on development experience with one or more of the following: AWS and/or Azure security Kubernetes You have strong knowledge in OWASP Top 10 and secure coding best practices You have strong foundation on secure software development lifecycle best practices You have strong written and verbal communication skills You have experience working with a globally distributed and remote team.</p>
<p>Bonus points if: You have working knowledge and experience with one or more of the following: Full-stack engineering Site reliability engineering Identity and access management Vulnerability and threat management Security detection and response Governance, risk and compliance</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Golang, Cloud infrastructure security, Product security, AWS security, Azure security, Kubernetes, OWASP Top 10, Secure coding best practices, Secure software development lifecycle best practices, Full-stack engineering, Site reliability engineering, Identity and access management, Vulnerability and threat management, Security detection and response, Governance, risk and compliance</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a company that provides identity and access management solutions. It has a global presence with over 20 offices worldwide.</Employerdescription>
      <Employerwebsite>https://www.okta.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7744352</Applyto>
      <Location>Bengaluru, India</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>cbaf9906-291</externalid>
      <Title>Platform Hardware Security</Title>
      <Description><![CDATA[<p>We&#39;re seeking a Platform Hardware Security Engineer to design and implement security architectures for bare-metal infrastructure. You&#39;ll work with teams across Anthropic to build firmware, bootloaders, operating systems, and attestation systems to ensure the integrity of our infrastructure from the ground up.</p>
<p>This role requires expertise in low-level systems security and the ability to architect solutions that balance security requirements with the performance demands of training AI models across our massive fleet.</p>
<p>Responsibilities:</p>
<ul>
<li>Design and implement secure boot chains from firmware through OS initialization for diverse hardware platforms (CPUs, BMCs, switches, peripherals, and embedded microcontrollers)</li>
</ul>
<ul>
<li>Architect attestation systems that provide cryptographic proof of system state from hardware root of trust through application layer</li>
</ul>
<ul>
<li>Develop measured boot implementations and runtime integrity monitoring</li>
</ul>
<ul>
<li>Create reference architectures and security requirements for bare-metal deployments</li>
</ul>
<ul>
<li>Integrate security controls with infrastructure teams without impacting training performance</li>
</ul>
<ul>
<li>Prototype and validate security mechanisms before production deployment</li>
</ul>
<ul>
<li>Conduct firmware vulnerability assessments and penetration testing</li>
</ul>
<ul>
<li>Build firmware analysis pipelines for continuous security monitoring</li>
</ul>
<ul>
<li>Document security architectures and maintain threat models</li>
</ul>
<ul>
<li>Collaborate with software and hardware vendors to ensure security capabilities meet our requirements</li>
</ul>
<p>Who you are:</p>
<ul>
<li>8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security (firmware, bootloaders, and OS-level security)</li>
</ul>
<ul>
<li>Hands-on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone)</li>
</ul>
<ul>
<li>Strong understanding of cryptographic protocols and hardware security modules</li>
</ul>
<ul>
<li>Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain of trust implementation</li>
</ul>
<ul>
<li>Proficiency in low-level programming (C, Rust, Assembly) and systems programming</li>
</ul>
<ul>
<li>Knowledge of firmware vulnerability assessment and threat modeling</li>
</ul>
<ul>
<li>Track record of designing security architectures for complex, distributed systems</li>
</ul>
<ul>
<li>Experience with supply chain security</li>
</ul>
<ul>
<li>Ability to work effectively across hardware and software boundaries</li>
</ul>
<ul>
<li>Knowledge of NIST firmware security guidelines and hardware security frameworks</li>
</ul>
<p>Strong candidates may also have:</p>
<ul>
<li>Experience with confidential computing technologies and hardware-based TEEs</li>
</ul>
<ul>
<li>Knowledge of SLSA framework and software supply chain security standards</li>
</ul>
<ul>
<li>Experience securing large-scale HPC or cloud infrastructure</li>
</ul>
<ul>
<li>Contributions to open-source security projects (coreboot, CHIPSEC, etc.)</li>
</ul>
<ul>
<li>Background in formal verification or security proof techniques</li>
</ul>
<ul>
<li>Experience with silicon root of trust implementations</li>
</ul>
<ul>
<li>Experience working with building foundational technical designs, operational leadership, and vendor collaboration</li>
</ul>
<ul>
<li>Previous work with AI/ML infrastructure security</li>
</ul>
<p>Annual Salary: $405,000-$485,000 USD</p>
<p>Logistics:</p>
<ul>
<li>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience</li>
</ul>
<ul>
<li>Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience</li>
</ul>
<ul>
<li>Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position</li>
</ul>
<ul>
<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>
</ul>
<ul>
<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>
</ul>
<p>Why work with us?</p>
<ul>
<li>Competitive compensation and benefits</li>
</ul>
<ul>
<li>Optional equity donation matching</li>
</ul>
<ul>
<li>Generous vacation and parental leave</li>
</ul>
<ul>
<li>Flexible working hours</li>
</ul>
<ul>
<li>Lovely office space in which to collaborate with colleagues</li>
</ul>
<p>Guidance on Candidates&#39; AI Usage: Learn about our policy for using AI in our application process</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$405,000-$485,000 USD</Salaryrange>
      <Skills>Secure boot, Measured boot, Attestation technologies, Cryptographic protocols, Hardware security modules, UEFI/BIOS or embedded firmware security, Bootloader hardening, Chain of trust implementation, Low-level programming, Systems programming, Firmware vulnerability assessment, Threat modeling, Supply chain security, NIST firmware security guidelines, Hardware security frameworks, Confidential computing technologies, Hardware-based TEEs, SLSA framework, Software supply chain security standards, Large-scale HPC or cloud infrastructure, Open-source security projects, Formal verification, Security proof techniques, Silicon root of trust implementations, Vendor collaboration, AI/ML infrastructure security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a public benefit corporation that creates reliable, interpretable, and steerable AI systems.</Employerdescription>
      <Employerwebsite>https://www.anthropic.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4929689008</Applyto>
      <Location>New York City, NY | Seattle, WA; San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>8bf116df-95e</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>Job Title: Application Security Engineer</p>
<p>About the Role: The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. As an Application Security Engineer, you will partner closely with software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>
<p>Responsibilities:</p>
<ul>
<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>
<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>
<li>Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities</li>
<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>
<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>
<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>
<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>
<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>
</ul>
<p>Requirements:</p>
<ul>
<li>5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>
<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>
<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>
<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>
<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>
<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>
<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>
<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>
<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>
<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>
<li>Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>
<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>
<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>
<li>Experience building security tools, applications, and automated tools</li>
<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>
<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>
<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>
</ul>
<p>Annual Compensation Range:</p>
<p>$300,000-$405,000 USD</p>
<p>Logistics:</p>
<ul>
<li>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience</li>
<li>Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience</li>
<li>Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position</li>
<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>
<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>
</ul>
<p>How to Apply:</p>
<p>If you&#39;re interested in this role, please submit your application through our website. We look forward to reviewing your application!</p>
<p>Note:</p>
<p>Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you&#39;re ever unsure about a communication, don&#39;t click any links,visit anthropic.com/careers directly for confirmed position openings.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$300,000-$405,000 USD</Salaryrange>
      <Skills>application security, infrastructure security, cloud-based security, containerized environments, programming languages, Python, Rust, Go, Java, threat modeling, secure design reviews, vulnerability management, bug bounty program, security policies, standards, playbooks, security awareness training, hands-on technical expertise, complex cloud environments, microservices architectures, Kubernetes, Docker, AWS, GCP, offensive security techniques, vulnerability testing, pen testing, red team exercises, AI/ML security risks, prompt injection, data poisoning, model extraction, security tools, applications, automated tools, software engineering principles, communication skills</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a company that creates reliable, interpretable, and steerable AI systems.</Employerdescription>
      <Employerwebsite>https://www.anthropic.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4502508008</Applyto>
      <Location>Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>68e291fb-412</externalid>
      <Title>Senior Security Engineer</Title>
      <Description><![CDATA[<p>Talent Wanted. For hazardous journey. Small wages, bitter cold, long months of complete darkness, constant danger, safe return doubtful. Honour and recognition in case of success.</p>
<p>Fridtjof Nansen crossed the Arctic, going places no human had ever been. Together with our users, we&#39;re doing the same onchain , and someone needs to make sure we don&#39;t get killed on the way there.</p>
<p>We&#39;re building the single best platform for onchain investing , agentic trading, staking infrastructure, AI-powered analytics , and we&#39;re scaling fast. Fast enough that security can&#39;t be an afterthought bolted on later. It has to be built in, from the start, by someone who knows what they&#39;re doing.</p>
<p><strong>Our mission:</strong></p>
<p>Surface the signal and create winners.</p>
<p><strong>What you&#39;ll do at Nansen</strong></p>
<p>You&#39;ll be the person who makes sure we can move fast without breaking things that matter. That means embedding security into everything we build , cloud infrastructure, applications, CI/CD pipelines, AI systems, staking operations , across a generalist role that spans the full surface area.</p>
<ul>
<li>Run security assessments across systems, architectures, and code , find the vulnerabilities before someone else does</li>
<li>Advise engineering teams on secure design decisions. You&#39;re a partner, not a blocker</li>
<li>Deploy and maintain security infrastructure: SIEM, vulnerability scanning, endpoint protection, logging , the things that let us sleep at night</li>
<li>Secure our CI/CD pipelines and deployment workflows end-to-end</li>
<li>Own secrets management, key management, and access controls. No shortcuts</li>
<li>Address LLM security head-on: API key management, prompt injection prevention, and the risks that come with shipping AI-powered products at speed</li>
<li>Coordinate penetration tests and security audits with external vendors</li>
<li>Create and maintain secure coding guidelines and code review processes that engineers actually follow</li>
<li>Represent the Security Team in the incident response process</li>
<li>Drive compliance readiness , SOC 2, ISO 27001 , pragmatically, not bureaucratically</li>
</ul>
<p><strong>What we&#39;re looking for</strong></p>
<ul>
<li>You&#39;ve built and hardened production security at scale , you know the difference between a policy document and an actually secure system</li>
<li>Strong cloud security knowledge (AWS, GCP or equivalent). Container security and network security fundamentals</li>
<li>Hands-on experience implementing security tooling, not just evaluating it</li>
<li>Secrets and key management expertise , you&#39;ve managed this at a company where it actually mattered</li>
<li>You understand the security implications of AI/LLM and agent-based systems. This is new territory and we need someone thinking about it seriously</li>
<li>CI/CD pipeline security is second nature</li>
<li>Pragmatic about compliance , you can get us to SOC 2 without drowning the engineering team in process</li>
<li>You don&#39;t just use AI as a tool. You think with it. AI-first isn&#39;t a checkbox , it&#39;s how you work</li>
<li>Strong async communication skills , we&#39;re remote-first, Slack-and-docs-heavy, and EMEA hours are preferred for team overlap</li>
<li>Bonus: blockchain, smart contract, or staking infrastructure security experience. Kubernetes and Terraform security. Incident response or security operations background</li>
</ul>
<p><strong>What we offer our crew</strong></p>
<ul>
<li>Competitive salary. Meaningful equity. Real ownership in what you build</li>
<li>Fully remote with two no-meeting days a week , because deep work doesn&#39;t happen in a Google Meet</li>
<li>Annual company retreat and team off-sites in one of our offices: Singapore, Bangkok, London, and Oslo , flights and accommodation covered</li>
<li>Unlimited AI tokens , Claude, OpenAI, whatever helps you move fast</li>
<li>Your own OpenClaw for work</li>
<li>Nansen Pro account: giving you full access to the most detailed onchain data in the market</li>
<li>A team that started as data engineers and data scientists that has grown to over 80 builders. Your craft is respected here.</li>
<li>Speed, ownership, curiosity, courage. These aren&#39;t values on a wall , they&#39;re how we run.</li>
<li>A front-row seat (and a hand in building) the next chapter of finance</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>cloud security, container security, network security, security tooling, secrets management, key management, access controls, API key management, prompt injection prevention, LLM security, CI/CD pipeline security, compliance, SOC 2, ISO 27001, blockchain security, smart contract security, staking infrastructure security, Kubernetes security, Terraform security, incident response, security operations</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Nansen</Employername>
      <Employerlogo>https://logos.yubhub.co/nansen.ai.png</Employerlogo>
      <Employerdescription>Nansen is a company building a platform for onchain investing, agentic trading, staking infrastructure, and AI-powered analytics.</Employerdescription>
      <Employerwebsite>https://nansen.ai/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/nansen/jobs/5811520004</Applyto>
      <Location>Remote Europe | Remote Asia</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>d6302dc5-860</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>Fuse Energy is a forward-thinking renewable energy startup on a mission to deliver a terawatt of renewable energy - fast. We&#39;re combining first-principles thinking with cutting-edge technology to build a radically better energy system.</p>
<p>We&#39;re creating a fully integrated energy company: from developing solar, wind and hydrogen projects to real-time power trading and distributed energy installations. By selling directly to consumers, we cut out the middleman, lower costs and pass on savings to customers.</p>
<p>But we&#39;re not stopping there. We&#39;re also building the Energy Network: a decentralised platform of smart devices that rewards users in Energy Dollars for electrifying their homes, shifting usage to off-peak hours, and helping balance the grid. This network strengthens grid stability - a critical foundation for scaling AI data centers and other energy-intensive industries.</p>
<p><strong>Responsibilities</strong></p>
<p><strong>Security Engineering &amp; Implementation</strong></p>
<ul>
<li>Assist in implementing and maintaining security controls across cloud infrastructure, web applications, and internal systems.</li>
<li>Support secure configuration of services, including access controls, secrets management, and API security.</li>
<li>Help review and improve the security of components related to identity, authentication, and transaction workflows.</li>
</ul>
<p><strong>Threat Modelling &amp; Risk Awareness</strong></p>
<ul>
<li>Participate in threat modelling exercises and security reviews for new features and system changes.</li>
<li>Help identify common security risks and misconfigurations, and work with engineers to remediate them.</li>
<li>Stay informed about common attack vectors and vulnerabilities relevant to modern cloud and web environments.</li>
</ul>
<p><strong>Security Operations &amp; Incident Support</strong></p>
<ul>
<li>Assist with monitoring, detection, and investigation of security alerts and events.</li>
<li>Support incident response activities, including analysis, documentation, and follow-up remediation tasks.</li>
<li>Help maintain and improve runbooks, alerts, and basic detection mechanisms.</li>
</ul>
<p><strong>Secure Development &amp; Best Practices</strong></p>
<ul>
<li>Contribute to secure development practices, including code reviews with a security lens.</li>
<li>Help document and promote security guidelines for engineers, such as secure coding and secrets handling.</li>
<li>Support ongoing efforts related to compliance readiness (e.g., evidence gathering, control checks).</li>
</ul>
<p><strong>Collaboration &amp; Learning</strong></p>
<ul>
<li>Work closely with engineering and product teams to integrate security into day-to-day development.</li>
<li>Learn from senior security engineers and actively develop your skills in cloud security, application security, and infrastructure security.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.</li>
<li>2–3 years of experience in a Security Engineer, Software Engineer, Infrastructure Engineer, or similar role with security exposure.</li>
<li>Foundational understanding of security concepts such as authentication, authorisation, encryption, and secure communication.</li>
<li>Familiarity with common web and cloud security risks (e.g., OWASP Top 10, IAM misconfigurations).</li>
<li>Basic experience with AWS and an interest in cloud security best practices.</li>
<li>Working knowledge of operating systems, networking fundamentals, and software development workflows.</li>
<li>Strong problem-solving skills and a willingness to learn and grow in a fast-moving environment.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Competitive salary and an equity sign-on bonus</li>
<li>Biannual bonus scheme</li>
<li>Fully expensed tech to match your needs</li>
<li>Paid annual leave</li>
<li>Breakfast and dinner allowance for office based employees</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AWS, cloud security, application security, infrastructure security, security concepts, authentication, authorisation, encryption, secure communication, OWASP Top 10, IAM misconfigurations, operating systems, networking fundamentals, software development workflows</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Fuse Energy</Employername>
      <Employerlogo>https://logos.yubhub.co/view.com.png</Employerlogo>
      <Employerdescription>Fuse Energy is a renewable energy startup that aims to deliver a terawatt of renewable energy. It has raised $170M from top-tier investors.</Employerdescription>
      <Employerwebsite>https://jobs.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.workable.com/view/pGZMLfYQcD1sroC7XJLzH2/hybrid-security-engineer-in-london-at-fuse-energy</Applyto>
      <Location>London, England</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>f7ac368b-fd2</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>Fuse Energy is a forward-thinking renewable energy startup on a mission to deliver a terawatt of renewable energy - fast. We&#39;re combining first-principles thinking with cutting-edge technology to build a radically better energy system.</p>
<p>We&#39;re creating a fully integrated energy company: from developing solar, wind and hydrogen projects to real-time power trading and distributed energy installations. By selling directly to consumers, we cut out the middleman, lower costs and pass on savings to customers.</p>
<p>But we&#39;re not stopping there. We&#39;re also building the Energy Network: a decentralised platform of smart devices that rewards users in Energy Dollars for electrifying their homes, shifting usage to off-peak hours, and helping balance the grid. This network strengthens grid stability - a critical foundation for scaling AI data centers and other energy-intensive industries.</p>
<p><strong>Responsibilities</strong></p>
<p><strong>Security Engineering &amp; Implementation</strong></p>
<ul>
<li>Assist in implementing and maintaining security controls across cloud infrastructure, web applications, and internal systems.</li>
<li>Support secure configuration of services, including access controls, secrets management, and API security.</li>
<li>Help review and improve the security of components related to identity, authentication, and transaction workflows.</li>
</ul>
<p><strong>Threat Modelling &amp; Risk Awareness</strong></p>
<ul>
<li>Participate in threat modelling exercises and security reviews for new features and system changes.</li>
<li>Help identify common security risks and misconfigurations, and work with engineers to remediate them.</li>
<li>Stay informed about common attack vectors and vulnerabilities relevant to modern cloud and web environments.</li>
</ul>
<p><strong>Security Operations &amp; Incident Support</strong></p>
<ul>
<li>Assist with monitoring, detection, and investigation of security alerts and events.</li>
<li>Support incident response activities, including analysis, documentation, and follow-up remediation tasks.</li>
<li>Help maintain and improve runbooks, alerts, and basic detection mechanisms.</li>
</ul>
<p><strong>Secure Development &amp; Best Practices</strong></p>
<ul>
<li>Contribute to secure development practices, including code reviews with a security lens.</li>
<li>Help document and promote security guidelines for engineers, such as secure coding and secrets handling.</li>
<li>Support ongoing efforts related to compliance readiness (e.g., evidence gathering, control checks).</li>
</ul>
<p><strong>Collaboration &amp; Learning</strong></p>
<ul>
<li>Work closely with engineering and product teams to integrate security into day-to-day development.</li>
<li>Learn from senior security engineers and actively develop your skills in cloud security, application security, and infrastructure security.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.</li>
<li>2–3 years of experience in a Security Engineer, Software Engineer, Infrastructure Engineer, or similar role with security exposure.</li>
<li>Foundational understanding of security concepts such as authentication, authorisation, encryption, and secure communication.</li>
<li>Familiarity with common web and cloud security risks (e.g., OWASP Top 10, IAM misconfigurations).</li>
<li>Basic experience with AWS and an interest in cloud security best practices.</li>
<li>Working knowledge of operating systems, networking fundamentals, and software development workflows.</li>
<li>Strong problem-solving skills and a willingness to learn and grow in a fast-moving environment.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Competitive salary and an equity sign-on bonus</li>
<li>Biannual bonus scheme</li>
<li>Fully expensed tech to match your needs</li>
<li>Paid annual leave</li>
<li>Breakfast and dinner allowance for office based employees</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AWS, cloud security, application security, infrastructure security, security concepts, authentication, authorisation, encryption, secure communication, OWASP Top 10, IAM misconfigurations, operating systems, networking fundamentals, software development workflows</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Fuse Energy</Employername>
      <Employerlogo>https://logos.yubhub.co/view.com.png</Employerlogo>
      <Employerdescription>Fuse Energy is a renewable energy startup that aims to deliver a terawatt of renewable energy. It has raised $170M from top-tier investors.</Employerdescription>
      <Employerwebsite>https://jobs.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.workable.com/view/eziLwb6ZKLhWWhioSWTY9L/hybrid-security-engineer-in-dubai-at-fuse-energy</Applyto>
      <Location>Dubai</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>9eb58719-bef</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p><strong>About the role:</strong></p>
<p>The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. In this hands-on technical role, you will partner closely with software engineers and researchers to ensure security is a core consideration from initial design through implementation.</p>
<p>You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>
<p>Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You&#39;ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions.</p>
<p><strong>Responsibilities:</strong></p>
<ul>
<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>
<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>
<li>Conduct secure design reviews and threat modeling. Identify and prioritise risks, attack surfaces, and vulnerabilities</li>
<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>
<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritise vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>
<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>
<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>
<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>
</ul>
<p><strong>You may be a good fit if you:</strong></p>
<ul>
<li>Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>
<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>
<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>
<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>
<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>
<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>
<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>
<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>
<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>
<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>
<li>Advocate for security fundamentals like least privilege, defence-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>
</ul>
<p><strong>Strong candidates may also:</strong></p>
<ul>
<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>
<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>
<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>
<li>Experience building security tools, applications, and automated tools</li>
<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>
<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>
<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>
</ul>
<p>The annual compensation range for this role is $300,000 - $405,000 USD.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$300,000 - $405,000 USD</Salaryrange>
      <Skills>application security, infrastructure security, cloud security, containerized environments, secure coding practices, vulnerability management, bug bounty program, offensive security, modern application stacks, security tools, Kubernetes, Docker, AWS, GCP, Python, Rust, Go, Java, vulnerability testing, pen testing, red team exercises, AI/ML security risks, security tools, automated tools</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a rapidly growing organisation developing reliable, interpretable, and steerable AI systems. The company&apos;s mission is to create safe and beneficial AI for users and society.</Employerdescription>
      <Employerwebsite>https://job-boards.greenhouse.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4502508008</Applyto>
      <Location>San Francisco, CA, Seattle, WA, New York City, NY</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>fb4fa003-a73</externalid>
      <Title>Platform Hardware Security Engineer</Title>
      <Description><![CDATA[<p><strong>About the Role</strong></p>
<p>We&#39;re seeking a Platform Hardware Security Engineer to design and implement security architectures for bare-metal infrastructure. You&#39;ll work with teams across Anthropic to build firmware, bootloaders, operating systems, and attestation systems to ensure the integrity of our infrastructure from the ground up.</p>
<p>This role requires expertise in low-level systems security and the ability to architect solutions that balance security requirements with the performance demands of training AI models across our massive fleet.</p>
<p><strong>What you&#39;ll do:</strong></p>
<ul>
<li>Design and implement secure boot chains from firmware through OS initialization for diverse hardware platforms (CPUs, BMCs, switches, peripherals, and embedded microcontrollers)</li>
<li>Architect attestation systems that provide cryptographic proof of system state from hardware root of trust through application layer</li>
<li>Develop measured boot implementations and runtime integrity monitoring</li>
<li>Create reference architectures and security requirements for bare-metal deployments</li>
<li>Integrate security controls with infrastructure teams without impacting training performance</li>
<li>Prototype and validate security mechanisms before production deployment</li>
<li>Conduct firmware vulnerability assessments and penetration testing</li>
<li>Build firmware analysis pipelines for continuous security monitoring</li>
<li>Document security architectures and maintain threat models</li>
<li>Collaborate with software and hardware vendors to ensure security capabilities meet our requirements</li>
</ul>
<p><strong>Who you are:</strong></p>
<ul>
<li>8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security (firmware, bootloaders, and OS-level security)</li>
<li>Hands-on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone)</li>
<li>Strong understanding of cryptographic protocols and hardware security modules</li>
<li>Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain of trust implementation</li>
<li>Proficiency in low-level programming (C, Rust, Assembly) and systems programming</li>
<li>Knowledge of firmware vulnerability assessment and threat modeling</li>
<li>Track record of designing security architectures for complex, distributed systems</li>
<li>Experience with supply chain security</li>
<li>Ability to work effectively across hardware and software boundaries</li>
<li>Knowledge of NIST firmware security guidelines and hardware security frameworks</li>
</ul>
<p><strong>Strong candidates may also have:</strong></p>
<ul>
<li>Experience with confidential computing technologies and hardware-based TEEs</li>
<li>Knowledge of SLSA framework and software supply chain security standards</li>
<li>Experience securing large-scale HPC or cloud infrastructure</li>
<li>Contributions to open-source security projects (coreboot, CHIPSEC, etc.)</li>
<li>Background in formal verification or security proof techniques</li>
<li>Experience with silicon root of trust implementations</li>
<li>Experience working with building foundational technical designs, operational leadership, and vendor collaboration</li>
<li>Previous work with AI/ML infrastructure security</li>
</ul>
<p><strong>Logistics</strong></p>
<ul>
<li>Education requirements: We require at least a Bachelor&#39;s degree in a related field or equivalent experience.</li>
<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>
<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>
</ul>
<p><strong>We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you&#39;re interested in this work.</strong></p>
<p><strong>Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you&#39;re ever unsure about a communication, don&#39;t click any links—visit anthropic.com/careers directly for confirmed position openings.</strong></p>
<p><strong>How we&#39;re different</strong></p>
<p>We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$405,000 - $485,000 USD</Salaryrange>
      <Skills>firmware security, hardware security, secure boot, measured boot, attestation technologies, cryptographic protocols, hardware security modules, UEFI/BIOS, embedded firmware security, bootloader hardening, chain of trust implementation, low-level programming, systems programming, firmware vulnerability assessment, threat modeling, supply chain security, NIST firmware security guidelines, hardware security frameworks, confidential computing technologies, hardware-based TEEs, SLSA framework, software supply chain security standards, large-scale HPC or cloud infrastructure, open-source security projects, formal verification, security proof techniques, silicon root of trust implementations, AI/ML infrastructure security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a quickly growing organisation that aims to create reliable, interpretable, and steerable AI systems. The company&apos;s mission is to build beneficial AI systems that are safe and beneficial for users and society as a whole.</Employerdescription>
      <Employerwebsite>https://job-boards.greenhouse.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4929689008</Applyto>
      <Location>New York City, NY; Seattle, WA; San Francisco, CA; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>a634db45-4fd</externalid>
      <Title>Security Engineer Lead, Corporate Security</Title>
      <Description><![CDATA[<p><strong>About the Role:</strong></p>
<p>We’re looking for a Security Engineering Lead to own and drive Anthropic’s Corporate Security programme. This is a player-coach Tech Lead Manager (TLM) role: you’ll be both the most senior technical individual contributor on corporate security and the people leader for a lean, high-impact team of Security Engineers.</p>
<p>Corporate Security at Anthropic encompasses everything that protects our people, endpoints, networks, SaaS ecosystem, and corporate data—the full surface area outside of production infrastructure. The scope is broad and the team is deliberately small, which means you’ll need deep technical skills across multiple domains, strong judgment about where to invest, and a bias toward automation and engineering-driven solutions over manual process.</p>
<p>You’ll report into Security leadership and partner closely with IT, Infrastructure Security, Detection &amp; Response, and GRC teams. This role is high-visibility and high-autonomy: you’ll be expected to define the roadmap, make architectural decisions, and represent Corporate Security across the company.</p>
<p><strong>Responsibilities:</strong></p>
<p><strong>Technical Leadership &amp; Hands-on Engineering</strong></p>
<ul>
<li>Own the security architecture, tooling, and controls for Anthropic’s corporate environment end-to-end, including endpoint fleets (macOS, Windows, ChromeOS), campus and office networks, SaaS applications, mobile devices</li>
<li>Design, build, and ship security automation, integrations, and internal tooling—including leveraging Claude and LLMs to accelerate security workflows</li>
<li>Define and enforce security baselines, hardening standards, and configuration policies across all corporate platforms</li>
<li>Define what it means to operate safely in an environment where AI agents act more like humans than actual humans</li>
<li>Evaluate, select, deploy, and operate corporate security tools (EDR/XDR, MDM, ZTNA, CASB/SSPM, email security, DLP, browser security, etc.)</li>
<li>Drive vulnerability management for corporate assets, including patch orchestration, risk-based prioritization, and exception management</li>
<li>Lead security reviews of new SaaS adoptions, corporate infrastructure changes, and IT projects</li>
</ul>
<p><strong>People Leadership &amp; Team Building</strong></p>
<ul>
<li>Manage, mentor, and grow a purposefully lean team of Security Engineers; set clear expectations, run effective 1:1s, and create an environment where engineers do the best work of their careers</li>
<li>Hire and build the team as scope expands—own the hiring bar and pipeline for Corporate Security Engineering roles</li>
<li>Balance your own IC contributions with the team’s needs; know when to go deep on a problem yourself and when to delegate and coach</li>
<li>Foster a culture of operational excellence, blameless incident review, and continuous improvement</li>
</ul>
<p><strong>Strategy &amp; Cross-Functional Partnership</strong></p>
<ul>
<li>Define and own the Corporate Security roadmap, aligning investments to Anthropic’s risk profile and growth trajectory</li>
<li>Partner with IT Operations to ensure security is embedded in endpoint provisioning, network design, and SaaS lifecycle management</li>
<li>Collaborate with Detection &amp; Response on telemetry coverage, detection engineering, and incident handling for corporate-sourced events</li>
<li>Partner with Infrastructure and Security Engineering teams to ensure security standards are consistent across all of Anthropic</li>
<li>Communicate security posture, risks, and investment needs to Security leadership and cross-functional stakeholders clearly and persuasively</li>
</ul>
<p><strong>You may be a good fit if you:</strong></p>
<ul>
<li>Have 8+ years of Security Engineering experience in a corporate/enterprise security domain (endpoint security, network security, SaaS security, identity, or a combination)</li>
<li>Have 2+ years of experience managing or tech-leading a team of engineers, with a demonstrated track record of developing talent and shipping results through others</li>
<li>Are a strong engineer who still writes code regularly—you can prototype a tool, write a detection, build an integration, or debug a complex configuration issue</li>
<li>Have deep experience with macOS fleet security (this is our primary platform) and solid working knowledge of Windows and ChromeOS security</li>
<li>Have hands-on experience deploying and operating EDR/XDR, MDM, ZTNA/zero trust, and identity security solutions at scale</li>
<li>Understand modern SaaS security challenges: shadow IT, OAuth token sprawl, data exfiltration paths, SaaS-to-SaaS integrations, and SSPM/CASB tooling</li>
<li>Can work independently with high autonomy, manage ambiguity, and make sound risk-based prioritization decisions in a fast-paced environment</li>
<li>Have excellent communication skills and can translate complex security topics into clear recommendations for technical and non-technical audiences</li>
</ul>
<p>Strong candidates may have:</p>
<ul>
<li>Securing corporate environments at high-growth AI, cloud, or developer-tools companies</li>
<li>Maturing a Corporate Security function from early stage, including defining scope, selecting the initial toolset, and hiring the founding team</li>
<li>Advanced macOS security (system extensions, endpoint security framework, MDM profile engineering, Declarative Device Management)</li>
<li>Network security architecture for hybrid/multi-office environments, including SD-WAN, ZTNA, DNS security, and network segmentation</li>
<li>Browser security and isolation technologies (e.g., Island, Talon/Palo Alto, Chrome Enterprise)</li>
<li>Proficiency in Python, Go, or similar languages for building sec</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>macOS fleet security, endpoint security, network security, SaaS security, identity security, EDR/XDR, MDM, ZTNA, CASB/SSPM, email security, DLP, browser security, patch orchestration, risk-based prioritization, exception management, security automation, integrations, internal tooling, Claude, LLMs, security baselines, hardening standards, configuration policies, vulnerability management, security reviews, IT projects, team management, team building, operational excellence, blameless incident review, continuous improvement, security roadmap, risk profile, growth trajectory, IT operations, endpoint provisioning, network design, SaaS lifecycle management, detection engineering, incident handling, infrastructure security, security engineering, security standards, communication, security posture, risks, investment needs, Python, Go, similar languages, macOS security, Windows security, ChromeOS security, advanced macOS security, system extensions, endpoint security framework, MDM profile engineering, Declarative Device Management, network security architecture, SD-WAN, ZTNA, DNS security, network segmentation, browser security and isolation technologies, Island, Talon/Palo Alto, Chrome Enterprise</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a quickly growing organisation that aims to create reliable, interpretable, and steerable AI systems. The company is working towards building beneficial AI systems that are safe and beneficial for users and society as a whole.</Employerdescription>
      <Employerwebsite>https://www.anthropic.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/5135098008</Applyto>
      <Location>San Francisco, CA | New York City, NY</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>23a792a8-cc4</externalid>
      <Title>Vendor Security Program Manager</Title>
      <Description><![CDATA[<p><strong>Job Posting</strong></p>
<p><strong>Vendor Security Program Manager</strong></p>
<p><strong>Location</strong></p>
<p>San Francisco; New York City; Seattle; Washington, DC</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Location Type</strong></p>
<p>Hybrid</p>
<p><strong>Department</strong></p>
<p>Security</p>
<p><strong>Compensation</strong></p>
<ul>
<li>SF, Seattle and NYC: $207K – $335K • Offers Equity</li>
<li>Zone A: $186K – $301.5K • Offers Equity</li>
<li>Zone B: $165.6K – $268K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>
<p><strong>About the Team</strong></p>
<p>The Vendor Security team sits at the core of our mission to ensure our technology benefits humanity safely and securely. We provide security assurances and robust compliance frameworks for our technology, people, and products. Our mission is to build trust with the world in our products and company. Our work is technical yet highly operational, strategically aligning with security and engineering teams to navigate and mitigate risks proactively. We prioritize impact, enable innovation, and foster a culture of continuous compliance and security awareness.</p>
<p><strong>About the Role</strong></p>
<p>As a Program Manager within the Vendor Security team, you will play a crucial role in protecting our organisation against external risks posed by suppliers, vendors, partners, and hardware manufacturers. Your responsibilities will include conducting comprehensive security assessments, building a program to manage global supply chain and vendor risks, and driving security initiatives across all of our third-party relationships. You will be analytical, detail-oriented, and proactive, capable of translating complex security evaluations into clear, actionable strategies.</p>
<p>The role is expected to operate with a strong point of view on risk. You will be responsible not only for identifying and documenting vendor and supply-chain risk, but for helping the company make informed trade-offs between speed, scale, and security. This role requires exceptional organisational skills, the ability to effectively communicate across different business functions, and a strong commitment to operational excellence in a dynamic environment.</p>
<p>This role may be based out of one of our US offices (San Francisco, Seattle, NYC or DC.) We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Be the interface for Security to the rest of the organisation for vendors.</li>
</ul>
<ul>
<li>Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.</li>
</ul>
<ul>
<li>Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.</li>
</ul>
<ul>
<li>Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.</li>
</ul>
<ul>
<li>Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.</li>
</ul>
<ul>
<li>Develop, propose, and implement effective controls to mitigate identified vendor risks.</li>
</ul>
<ul>
<li>Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.</li>
</ul>
<ul>
<li>Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.</li>
</ul>
<p><strong>You might thrive in this role if you have:</strong></p>
<ul>
<li>Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.</li>
</ul>
<ul>
<li>An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.</li>
</ul>
<ul>
<li>Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete or uncertain.</li>
</ul>
<ul>
<li>Strong analytical and problem-solving skills, with the ability to identify and mitigate complex security risks.</li>
</ul>
<ul>
<li>Excellent communication and interpersonal skills, with the ability to effectively collaborate with cross-functional teams and stakeholders.</li>
</ul>
<ul>
<li>Strong organisational and project management skills, with the ability to prioritise tasks and manage multiple projects simultaneously.</li>
</ul>
<ul>
<li>A strong commitment to operational excellence and continuous improvement, with a focus on delivering high-quality results in a dynamic environment.</li>
</ul>
<ul>
<li>A passion for security and a desire to make a meaningful impact in the field.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$207K – $335K • Offers Equity</Salaryrange>
      <Skills>information security principles and controls, data protection, access management, proactive and reactive security measures, application security, third-party or supply chain security assessments, vendor management security program, security risk management, compliance frameworks, security awareness, operational excellence, project management, communication and interpersonal skills, cloud security, infrastructure security, threat intelligence, security analytics, incident response, security testing, penetration testing, security consulting, security training, security awareness training</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is a technology company that focuses on developing artificial intelligence (AI) systems. It was founded in 2015 and is headquartered in San Francisco, California.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/fb1e823e-cfcc-4293-8893-cc77e467c561</Applyto>
      <Location>San Francisco; New York City; Seattle; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>28fd37f4-a07</externalid>
      <Title>Devops Developer</Title>
      <Description><![CDATA[<p>Join us for an opportunity to work with the best game development teams in the world. We are looking for a Devops Engineer to join the tools development and automation team supporting BioWare, Motive, Maxis, Full Circle.</p>
<p><strong>What you&#39;ll do</strong></p>
<p>This DevOps Developer role in the Software Quality organization works with Quality Assurance and Game Development teams to create tools and technical strategies. Our goal is to improve automation infrastructure and increase efficiencies in the Game Development and QA processes.</p>
<ul>
<li>Operate and maintain tools, ensuring exceptional uptime, secure environments.</li>
<li>First responder and driving continuous improvement based on root cause analysis.</li>
</ul>
<p><strong>What you need</strong></p>
<ul>
<li>5+ year experience in managing distributed, scalable and resilient high-performing systems</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>C#/.NET experience, Experience implementing data and infrastructure security best practices, Experience with container workload technologies such as Kubernetes, Helm and Docker, Experience with monitoring/observability systems such as Prometheus, Grafana and/or Datadog, Experience with continuous integration and delivery, using pipeline automation systems such as Jenkins, GitLab and GitHub</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Electronic Arts</Employername>
      <Employerlogo>https://logos.yubhub.co/jobs.ea.com.png</Employerlogo>
      <Employerdescription>Electronic Arts creates next-level entertainment experiences that inspire players and fans around the world. Here, everyone is part of the story. Part of a community that connects across the globe. A place where creativity thrives, new perspectives are invited, and ideas matter.</Employerdescription>
      <Employerwebsite>https://jobs.ea.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ea.com/en_US/careers/JobDetail/Software-Developer-II/212007</Applyto>
      <Location>Montreal</Location>
      <Country></Country>
      <Postedate>2026-02-06</Postedate>
    </job>
  </jobs>
</source>