<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>8ded847c-cd1</externalid>
      <Title>Security Engineer Intern (Summer 2026)</Title>
      <Description><![CDATA[<p>About Us</p>
<p>Cloudflare is on a mission to help build a better Internet. We protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code.</p>
<p>As a Security Engineer Intern, you will work alongside experienced security engineers to identify vulnerabilities, harden our infrastructure, and build tools that protect billions of Internet users. We are looking for interns who are curious, proactive, and able to approach problems with a &#39;security-first&#39; mindset.</p>
<p>Responsibilities</p>
<ul>
<li>Ship and deliver security-focused projects over 12-16 weeks with autonomy and support.</li>
<li>Work cross-functionally with Product, Infrastructure, and Engineering teams to integrate security into every stage of the development lifecycle.</li>
<li>Work closely with a mentor to guide you through the internship, develop your security expertise, and help with career goals.</li>
<li>Build your network across the company through our various in and out of office socials, networking programs, Employee Resource Group (ERG) programs, and Activity Groups.</li>
<li>Present your security project to the entire company at the end of the internship.</li>
<li>Connect and learn from our executives and leadership team including our co-founders.</li>
<li>Write for our Cloudflare blog (e.g., documenting a new security tool or a vulnerability research finding) and be featured on Cloudflare.tv sessions.</li>
</ul>
<p>What We&#39;re Looking For</p>
<ul>
<li>Education: Currently pursuing a degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field.</li>
<li>Security Fundamentals: A solid understanding of the OWASP Top 10, common attack vectors (XSS, SQLi, CSRF), and how to mitigate them.</li>
<li>Demonstrated critical thinking skills and drive to learn and adapt new technologies.</li>
<li>Curiosity, empathy and ability to get things done.</li>
<li>Ability to commit to a minimum 12 week summer internship.</li>
<li>In office 3-5 days a week in the location of the internship.</li>
<li>Local to Austin; relocation not provided.</li>
</ul>
<p>What Makes Cloudflare Special?</p>
<p>We&#39;re not just a highly ambitious, large-scale technology company. We&#39;re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.</p>
<p>Project Galileo: Since 2014, we&#39;ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare&#39;s enterprise customers--at no cost.</p>
<p>Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we&#39;ve provided services to more than 425 local government election websites in 33 states.</p>
<p>1.1.1.1: We released 1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released.</p>
<p>Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.</p>
<p>Sound like something you’d like to be a part of? We’d love to hear from you!</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>internship</Jobtype>
      <Experiencelevel>entry</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Go, Rust, Python, C/C++, OWASP Top 10, XSS, SQLi, CSRF</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Cloudflare</Employername>
      <Employerlogo>https://logos.yubhub.co/cloudflare.com.png</Employerlogo>
      <Employerdescription>Cloudflare runs one of the world&apos;s largest networks that powers millions of websites and other Internet properties.</Employerdescription>
      <Employerwebsite>https://www.cloudflare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/cloudflare/jobs/7582150</Applyto>
      <Location>In-Office</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>1e992e68-7cd</externalid>
      <Title>Staff Engineer, Offensive Security</Title>
      <Description><![CDATA[<p>As a Staff Engineer, Offensive Security at Twilio, you will act as a Technical Lead and design complex attack chains that demonstrate systemic risk. You will spend as much time writing custom code and researching new bypasses as you do executing tests.</p>
<p>In this role, you will:</p>
<p>Perform manual and automated testing of web applications, APIs, and mobile apps (iOS/Android). Conduct network and cloud level assessments with various tooling. Triage and validate reports from automated scanners or bug bounty hunters to eliminate false positives and escalate true positives. Perform initial prompt injection and jailbreak tests on AI prototypes, services, and applications using established checklists (OWASP Top 10 for LLMs). Draft high-quality reports that detail the &quot;path to compromise&quot; with clear, reproducible steps for developers. Manage and update the team&#39;s testing infrastructure (e.g., Burp Suite, and basic C2 listeners). Provide direct technical guidance to engineering teams on how to patch vulnerabilities like XSS, SQLi, and IDOR. Design and lead multi-week Red Team operations that mimic specific threat actors (APTs) to test the SIRT detection capabilities. Build custom payloads, droppers, and obfuscated scripts to bypass EDR/AV and maintain stealth. Build automated testing frameworks for AI systems (e.g., using PyRIT, Promptfoo, or Garak) to test for models related to sensitive data leakage. Execute sophisticated attacks against AWS/Azure/K8s, focusing on IAM misconfigurations and container escapes. Collaborate with SIRT and Detection Engineering to tune SIEM alerts based on the techniques used during an engagement. Oversee the organization&#39;s bug bounty program, identifying trends in submissions to suggest broad architectural security changes.</p>
<p>Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Offensive security, Penetration testing, Bug bounty, AppSec, Vulnerability exploitation, MITRE ATT&amp;CK matrix, OWASP Top 10 for web applications, OWASP Top 10 for LLMs, Post exploitation, Adversarial ML, Burp Suite professional, Nmap, Metasploit, Wireshark, LangChain, TensorFlow, C2 frameworks, Python, Bash, C++, Telecom expertise, Excellent written and verbal communication skills, Ability to influence and build effective working relationships with all levels of the organization, Proficiency in multiple languages applicable to the region</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Twilio</Employername>
      <Employerlogo>https://logos.yubhub.co/twilio.com.png</Employerlogo>
      <Employerdescription>Twilio delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide to craft personalized customer experiences.</Employerdescription>
      <Employerwebsite>https://www.twilio.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/twilio/jobs/7622285</Applyto>
      <Location>Remote - Ireland</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>1bb68827-243</externalid>
      <Title>Staff Software Engineer, Security</Title>
      <Description><![CDATA[<p>Secure Every Identity ----------------------- Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>
<p>We are looking for a Staff Software Engineer, Security to join our Security Engineering group. As a Staff Software Engineer, Security, you will act as a liaison between the Security org and the engineering org to build technical leverage and influence the security roadmap and direction.</p>
<p>Responsibilities ---------------</p>
<ul>
<li>Act as a liaison between the engineering and security org to develop innovative requirements for the security roadmap.</li>
<li>Evangelize security best practices across the engineering org.</li>
<li>Research, design, implement and own security oriented frameworks and features with the common goal of protecting Okta’s customers.</li>
<li>Routinely participate in cross-vertical code reviews with emphasis on Security.</li>
<li>Break down complex problems into sub-tasks while prototyping rapidly and iteratively contributing to security initiatives using agile practices.</li>
<li>Coach and mentor junior engineers in the team.</li>
</ul>
<p>Preferred Qualification and Abilities -----------------------------------</p>
<ul>
<li>7+ years of development experience in designing and implementing software systems in Java, building highly reliable and mission-critical software.</li>
<li>3+ years of work experience in designing and implementing security solutions for applications and distributed systems.</li>
<li>Work experience and excellent understanding in mitigating OWASP Top 10 attacks on applications, Application Security, Cryptography, Authentication, Authorization using Role-Based and Attribute-Based access controls.</li>
<li>Strong understanding of concepts such as Test-Driven development, Secure SDLC, Secure code reviews and the ability to identify and mitigate threat vectors and vulnerabilities in code and infrastructure.</li>
<li>Good understanding and experience in using cloud service providers such as AWS and GCP.</li>
<li>Developing and maintaining technical documentation such as cookbooks, design and architecture docs.</li>
<li>Troubleshooting and fixing production issues to ensure reliability, security and performance.</li>
<li>Work experience in using RDBMS like MySQL, good grasp of concepts such as replication and clustering along with familiarity in data stores such as Redis and Elasticsearch.</li>
<li>Excellent grasp of software engineering principles coupled with strong written and verbal communication skills.</li>
<li>B.S or M.S in Computer Science or related fields.</li>
</ul>
<p>The Okta Experience ------------------ Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Java, Software Systems Design, Security Solutions, OWASP Top 10 Attacks, Application Security, Cryptography, Authentication, Authorization, Test-Driven Development, Secure SDLC, Secure Code Reviews, Cloud Service Providers, AWS, GCP, Technical Documentation, RDBMS, MySQL, Redis, Elasticsearch, Agile Practices, Mentoring, Communication Skills</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta provides workforce identity cloud security solutions.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/6687504</Applyto>
      <Location>Bengaluru, India</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>0ae6f8dc-4fd</externalid>
      <Title>Staff Engineer, AI Security</Title>
      <Description><![CDATA[<p>Join the team as Twilio&#39;s next Staff Engineer, AI Security.</p>
<p>As a Staff Engineer, AI Security on the AppSec team, you&#39;ll lead autonomous defense for the AI lifecycle. Build multi-agent frameworks and secure gateways while integrating real-time security gates and identity standards. By mentoring Security and R&amp;D to define the MLSecOps roadmap, you&#39;ll ensure a &#39;secure-by-default&#39; future for agentic workflows and resilient AI innovation.</p>
<p>Responsibilities:</p>
<p>Serve as the primary subject matter expert for all AI and machine learning security initiatives across security and R&amp;D.</p>
<p>Design and manage AI gateways to provide a centralized control plane for authentication and authorization and rate limiting across all model and tool interactions.</p>
<p>Build and maintain an autonomous security agentic framework that utilizes multi agent orchestration for end to end investigation and alert triage and remediation.</p>
<p>Develop agentic identity models using OAuth 2.1 to propagate identity across trust boundaries and prevent the confused deputy problem.</p>
<p>Help govern the AI augmented software development lifecycle by integrating real time security gates into the developer environment and CI/CD pipeline.</p>
<p>Manage Agentic Security Solutions that secure AI lifecycle and manage AI workloads at runtime.</p>
<p>Author company wide AI security standards and implement these security checks across Twilio&#39;s stack.</p>
<p>Implement human in the loop checkpoints and transactional safety protocols for high impact or destructive agentic actions.</p>
<p>Partner with engineering leadership to set the long term roadmap for identity centric security and automated posture management.</p>
<p>Act as a knowledge multiplier by mentoring security engineers and developing secure by default paved road templates for R&amp;D teams</p>
<p>Qualifications:</p>
<p>8+ years of experience in security engineering with at least 3 years focused on AI or machine learning security operations (MLSecOps).</p>
<p>Expertise in orchestrating multi-agent systems with AWS Strands, LangGraph, and CrewAI, specializing in runtime isolation, PII redaction, and defending against indirect prompt injection in agentic environments.</p>
<p>Hands-on experience with AI-specific frameworks (e.g., MITRE ATLAS, MAESTRO, OWASP Top 10 for LLMs/Agents/MCP) to threat model and defend against a wide spectrum of risks, including direct/indirect prompt injection, training data poisoning, tool poisoning, and data exfiltration within agentic workflows.</p>
<p>Proficiency in securing end-to-end AI pipelines, from data ingestion and training to model deployment and monitoring.</p>
<p>Strong communication skills to translate complex AI risks into actionable business logic for stakeholders.</p>
<p>Desired:</p>
<p>Hands-on experience in modern application security tooling including SAST and SCA and DAST with experience adapting these tools to catch AI specific vulnerabilities like indirect prompt injection.</p>
<p>Expertise in identity standards including OAuth 2.1 and PKCE.</p>
<p>Experience with AI Red Teaming and conducting adversarial simulations against Large Language Models (LLMs) and agentic systems.</p>
<p>Proficiency in at least one general programming language (Python, Go, etc) with experience in container security and workload isolation.</p>
<p>Proven ability to operate with autonomy and drive high impact outcomes in ambiguous environments by identifying and executing on critical projects without predefined roadmaps or direct supervision.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>security engineering, AI and machine learning security, multi-agent systems, AWS Strands, LangGraph, CrewAI, runtime isolation, PII redaction, indirect prompt injection, AI-specific frameworks, MITRE ATLAS, MAESTRO, OWASP Top 10 for LLMs/Agents/MCP, end-to-end AI pipelines, data ingestion, training, model deployment, monitoring, strong communication skills, modern application security tooling, SAST and SCA and DAST, identity standards, OAuth 2.1, PKCE, AI Red Teaming, adversarial simulations, Large Language Models, container security, workload isolation</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Twilio</Employername>
      <Employerlogo>https://logos.yubhub.co/twilio.com.png</Employerlogo>
      <Employerdescription>Twilio delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide to craft personalized customer experiences.</Employerdescription>
      <Employerwebsite>https://www.twilio.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/twilio/jobs/7821462</Applyto>
      <Location>Remote - Ireland</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>777a6e79-5d9</externalid>
      <Title>Senior Software Engineer, Security Engineering</Title>
      <Description><![CDATA[<p>Secure Every Identity ----------------------- Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>
<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work.</p>
<p>The Role -------- We seek a knowledgeable and development-focused Security Engineer, who will build micro-services to secure Customer Identity Products and Infrastructure.</p>
<p>Responsibilities --------------- Work across a globally distributed product-aligned team of security engineers Establish a deep understanding of Okta Customer Identity products and infrastructure Collaborate when necessary with the Okta Security team on security operations Build, deploy &amp; maintain scalable and reliable infrastructure services as well as security solutions for customer identity products Build, deploy &amp; maintain automation to improve platform security capabilities at scale including logging, threat detection and compliance benchmarks to increase our security posture Help meet our operational security commitments by thinking like an attacker, assessing the risk, and advising on mitigation strategies Support security investigations in coordination with the Okta Security team, participate in root cause analysis and perform necessary remediations. Support stakeholders by proposing mitigation strategies for end-of-life software and security vulnerability and patch management</p>
<p>Requirements ----------- You have 3+ years of hands-on development experience writing microservices with Golang You have 3+ years of experience in cloud infrastructure security, product security You have working knowledge and hands on development experience with one or more of the following: AWS and/or Azure security Kubernetes You have strong knowledge in OWASP Top 10 and secure coding best practices You have strong foundation on secure software development lifecycle best practices You have strong written and verbal communication skills You have experience working with a globally distributed and remote team.</p>
<p>Bonus points if: You have working knowledge and experience with one or more of the following: Full-stack engineering Site reliability engineering Identity and access management Vulnerability and threat management Security detection and response Governance, risk and compliance</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Golang, Cloud infrastructure security, Product security, AWS security, Azure security, Kubernetes, OWASP Top 10, Secure coding best practices, Secure software development lifecycle best practices, Full-stack engineering, Site reliability engineering, Identity and access management, Vulnerability and threat management, Security detection and response, Governance, risk and compliance</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a company that provides identity and access management solutions. It has a global presence with over 20 offices worldwide.</Employerdescription>
      <Employerwebsite>https://www.okta.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7744352</Applyto>
      <Location>Bengaluru, India</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6d2bed6a-1bd</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies.</p>
<p>Responsibilities: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10</p>
<p>Basic Qualifications: Bachelor&#39;s degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences</p>
<p>Preferred Skills and Experience: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Experience with GitOps and infrastructure-as-code security Familiarity with federated learning and privacy-preserving machine learning techniques Experience in building custom security tooling to enhance and automate security processes Interest in leveraging AI to automate security tasks and improve efficiency Contributions to open-source security projects or tools Experience in securing AI/ML models and data pipelines</p>
<p>Compensation and Benefits: $200,000 - $340,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$200,000 - $340,000 USD</Salaryrange>
      <Skills>Python, Rust, Secure coding practices, Application security frameworks, Common vulnerabilities, OWASP Top 10, CI/CD pipelines, DevSecOps practices, Software supply chain security, SBOM generation tools, Security testing tools, Static/dynamic code analysis, AI/ML security implications, OWASP LLM Top 10, Cloud platforms, Security certifications, Data privacy and compliance regulations, GitOps, Infrastructure-as-code security, Federated learning, Privacy-preserving machine learning techniques, Custom security tooling, AI automation, Open-source security projects, AI/ML model security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>xAI</Employername>
      <Employerlogo>https://logos.yubhub.co/xai.com.png</Employerlogo>
      <Employerdescription>xAI creates AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.</Employerdescription>
      <Employerwebsite>https://www.xai.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/xai/jobs/4559147007</Applyto>
      <Location>Palo Alto, CA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>5c7e46c8-c5c</externalid>
      <Title>Application Security Intern</Title>
      <Description><![CDATA[<p>We&#39;re looking for a curious and motivated Application Security Intern to help us build secure products and development practices at VGS. As an Application Security Intern, you will partner with security and engineering teams to evaluate application risk, improve secure software development workflows, and help developers ship software safely in an environment that handles highly sensitive payment and identity data.</p>
<p>Your responsibilities will include:</p>
<ul>
<li>Supporting application security reviews for services, APIs, and new product features across the VGS platform.</li>
<li>Helping identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.</li>
<li>Participating in threat modeling and secure design discussions with engineering teams during feature development.</li>
<li>Evaluating the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC.</li>
<li>Assisting with manual testing and validation of web application and API security issues.</li>
<li>Helping improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.</li>
<li>Working with engineers to understand remediation options and clearly document security risks and recommendations.</li>
<li>Contributing to improving security tooling and guardrails in CI/CD and development workflows.</li>
</ul>
<p>We&#39;re looking for someone with a strong interest in secure software design, cloud-native architectures, and automation. You should have a foundational understanding of application security concepts, such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.</p>
<p>At VGS, we have a remote-first philosophy, and we&#39;re looking for someone who is comfortable working independently and collaboratively as part of a team.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>internship</Jobtype>
      <Experiencelevel>entry</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>application security, secure software development, cloud-native architectures, automation, OWASP Top 10, API security, authentication and authorization, secure coding, common software vulnerabilities, LMMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, cloud environments</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>VGS</Employername>
      <Employerlogo>https://logos.yubhub.co/vgs.com.png</Employerlogo>
      <Employerdescription>VGS is the world&apos;s leader in payment tokenization, providing processor-agnostic tokenization solutions to large banks, fintechs, and merchants.</Employerdescription>
      <Employerwebsite>https://www.vgs.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>395c1cc1-6a4</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking a Security Engineer to join our growing security team. This role will have a huge impact on maintaining and improving Greenlight&#39;s security posture by developing and implementing automated workflows or AI toolings.</p>
<p>The successful candidate will design, build, and maintain high-scale automation workflows and AI-assisted capabilities that proactively mature Greenlight&#39;s security posture. They will also architect and implement security guardrails for internal AI usage, ensuring LLM integrations and automated agents operate within company risk tolerances.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Developing custom integrations across the security and business systems stack (SaaS, FinTech tools, and internal APIs) to eliminate manual silos.</li>
<li>Building and configuring automated tooling for real-time monitoring of data security, privacy, and vulnerability management.</li>
<li>Partnering with IT, Engineering, and Business Owners to identify operational bottlenecks and deploy AI-powered solutions that enhance both security and efficiency.</li>
<li>Collaborating with DevOps to bake automated security controls into the CI/CD pipeline and cloud environments.</li>
<li>Creating high-quality designs, workflow diagrams, and playbooks to ensure automated systems are maintainable and transparent.</li>
</ul>
<p>Requirements include:</p>
<ul>
<li>4+ years of professional experience in Cybersecurity, DevOps, or Software Engineering.</li>
<li>Strong proficiency in Python (preferred) or Go for building custom security tools and API-heavy integrations.</li>
<li>Solid understanding of cloud security principles (AWS/GCP), containerization (Docker/K8s), and securing distributed systems.</li>
<li>Deep familiarity with the OWASP Top 10 (including LLM-specific risks) and CI/CD security best practices.</li>
<li>Hands-on experience with CI/CD platforms (GitHub Actions, GitLab CI) and no-code/low-code automation platforms (e.g., Tines, Torq, or Tray.io).</li>
<li>Proven experience using AI-assisted tools (Copilot, Cursor, etc.) to accelerate development and a curiosity for deploying AI-driven security solutions.</li>
</ul>
<p>Nice to have:</p>
<ul>
<li>Experience with Infrastructure-as-code (IaC)</li>
<li>Direct experience implementing security controls within both AWS and GCP.</li>
<li>Security certifications such as CISSP, Security+, or specialized GIAC certifications.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Python, Go, Cloud security principles, Containerization, Securing distributed systems, OWASP Top 10, CI/CD security best practices, CI/CD platforms, No-code/low-code automation platforms, AI-assisted tools</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Greenlight</Employername>
      <Employerlogo>https://logos.yubhub.co/greenlight.com.png</Employerlogo>
      <Employerdescription>Greenlight is a family fintech company that provides an award-winning banking app for families, serving over 6 million parents and kids.</Employerdescription>
      <Employerwebsite>https://www.greenlight.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/greenlight/2a76b288-50ec-4b8c-82b8-bf9543fcf054</Applyto>
      <Location></Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>ace25108-b9c</externalid>
      <Title>Staff Product Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. As a Staff Product Security Engineer, you will be responsible for the end-to-end security of our consumer products, digital platform, and emerging hardware device line.</p>
<p>Your day-to-day will involve leading security architecture/design review and threat modeling sessions with product and engineering teams, translating threats into actionable, risk-rated engineering remediations prioritized by severity, conducting hands-on penetration testing and security assessments across our full product stack, and driving PSIRT operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers, and on-call incidents.</p>
<p>You will also shape the posture of our AI-assisted development environment, defining and enforcing enterprise policies for Claude and Cursor, and partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers, and collaborating with the AI team on securing ML pipelines.</p>
<p>As a champion of security culture, you will run developer training on secure coding with AI assistants, evangelize security by design for products, and ensure every engineer understands that product security is an enabler and not a gate.</p>
<p>You will bring 10+ years of product security experience spanning application security, cloud security, and secure SDLC, expert-level threat modeling using STRIDE, PASTA, or equivalent across web, mobile, cloud, embedded, and AI systems, hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware, and deep hands-down AI security expertise and expert-level understanding of OWASP Top 10 for LLM, API, Web, Mobile, and practical experience with MITRE.</p>
<p>You will have strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor, and understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development.</p>
<p>You will also have strong programming ability and capability to review code, build security tools, automate workflows, and be credible with the engineering teams you partner with.</p>
<p>Preferred experience includes hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience, and experience in the Financial industry, knowledge of PCI DSS, COPPA, or demonstrated ability to learn regulated domains quickly.</p>
<p>Work perks at Greenlight include medical, dental, vision, and HSA match, paid life insurance, AD&amp;D, and disability benefits, traditional 401k with company match, unlimited PTO, paid company holidays and pop-up bonus holidays, professional development stipends, mental health resources, 1:1 financial planners, fertility healthcare, 100% paid parental and caregiving leave, plus cleaning service and meals during your leave, flexible WFH, both remote and in-office opportunities, fully stocked kitchen, catered lunches, and occasional in-office happy hours, and employee resource groups.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$165,000-200,000</Salaryrange>
      <Skills>product security, application security, cloud security, secure SDLC, threat modeling, penetration testing, security assessments, PSIRT operations, AI security, OWASP Top 10, MITRE, SAST, DAST, SCA, Claude, Cursor, MCP security, firmware integrity, hardware root of trust, IoT threat modeling, hardware and embedded security, PCI DSS, COPPA</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Greenlight</Employername>
      <Employerlogo>https://logos.yubhub.co/greenlight.com.png</Employerlogo>
      <Employerdescription>Greenlight is a family fintech company that provides a banking app for families, serving over 6 million parents and kids.</Employerdescription>
      <Employerwebsite>https://www.greenlight.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/greenlight/18b7ac30-dbf6-4078-bf50-06772c47fdc7</Applyto>
      <Location>Atlanta</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>d6302dc5-860</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>Fuse Energy is a forward-thinking renewable energy startup on a mission to deliver a terawatt of renewable energy - fast. We&#39;re combining first-principles thinking with cutting-edge technology to build a radically better energy system.</p>
<p>We&#39;re creating a fully integrated energy company: from developing solar, wind and hydrogen projects to real-time power trading and distributed energy installations. By selling directly to consumers, we cut out the middleman, lower costs and pass on savings to customers.</p>
<p>But we&#39;re not stopping there. We&#39;re also building the Energy Network: a decentralised platform of smart devices that rewards users in Energy Dollars for electrifying their homes, shifting usage to off-peak hours, and helping balance the grid. This network strengthens grid stability - a critical foundation for scaling AI data centers and other energy-intensive industries.</p>
<p><strong>Responsibilities</strong></p>
<p><strong>Security Engineering &amp; Implementation</strong></p>
<ul>
<li>Assist in implementing and maintaining security controls across cloud infrastructure, web applications, and internal systems.</li>
<li>Support secure configuration of services, including access controls, secrets management, and API security.</li>
<li>Help review and improve the security of components related to identity, authentication, and transaction workflows.</li>
</ul>
<p><strong>Threat Modelling &amp; Risk Awareness</strong></p>
<ul>
<li>Participate in threat modelling exercises and security reviews for new features and system changes.</li>
<li>Help identify common security risks and misconfigurations, and work with engineers to remediate them.</li>
<li>Stay informed about common attack vectors and vulnerabilities relevant to modern cloud and web environments.</li>
</ul>
<p><strong>Security Operations &amp; Incident Support</strong></p>
<ul>
<li>Assist with monitoring, detection, and investigation of security alerts and events.</li>
<li>Support incident response activities, including analysis, documentation, and follow-up remediation tasks.</li>
<li>Help maintain and improve runbooks, alerts, and basic detection mechanisms.</li>
</ul>
<p><strong>Secure Development &amp; Best Practices</strong></p>
<ul>
<li>Contribute to secure development practices, including code reviews with a security lens.</li>
<li>Help document and promote security guidelines for engineers, such as secure coding and secrets handling.</li>
<li>Support ongoing efforts related to compliance readiness (e.g., evidence gathering, control checks).</li>
</ul>
<p><strong>Collaboration &amp; Learning</strong></p>
<ul>
<li>Work closely with engineering and product teams to integrate security into day-to-day development.</li>
<li>Learn from senior security engineers and actively develop your skills in cloud security, application security, and infrastructure security.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.</li>
<li>2–3 years of experience in a Security Engineer, Software Engineer, Infrastructure Engineer, or similar role with security exposure.</li>
<li>Foundational understanding of security concepts such as authentication, authorisation, encryption, and secure communication.</li>
<li>Familiarity with common web and cloud security risks (e.g., OWASP Top 10, IAM misconfigurations).</li>
<li>Basic experience with AWS and an interest in cloud security best practices.</li>
<li>Working knowledge of operating systems, networking fundamentals, and software development workflows.</li>
<li>Strong problem-solving skills and a willingness to learn and grow in a fast-moving environment.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Competitive salary and an equity sign-on bonus</li>
<li>Biannual bonus scheme</li>
<li>Fully expensed tech to match your needs</li>
<li>Paid annual leave</li>
<li>Breakfast and dinner allowance for office based employees</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AWS, cloud security, application security, infrastructure security, security concepts, authentication, authorisation, encryption, secure communication, OWASP Top 10, IAM misconfigurations, operating systems, networking fundamentals, software development workflows</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Fuse Energy</Employername>
      <Employerlogo>https://logos.yubhub.co/view.com.png</Employerlogo>
      <Employerdescription>Fuse Energy is a renewable energy startup that aims to deliver a terawatt of renewable energy. It has raised $170M from top-tier investors.</Employerdescription>
      <Employerwebsite>https://jobs.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.workable.com/view/pGZMLfYQcD1sroC7XJLzH2/hybrid-security-engineer-in-london-at-fuse-energy</Applyto>
      <Location>London, England</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>f7ac368b-fd2</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>Fuse Energy is a forward-thinking renewable energy startup on a mission to deliver a terawatt of renewable energy - fast. We&#39;re combining first-principles thinking with cutting-edge technology to build a radically better energy system.</p>
<p>We&#39;re creating a fully integrated energy company: from developing solar, wind and hydrogen projects to real-time power trading and distributed energy installations. By selling directly to consumers, we cut out the middleman, lower costs and pass on savings to customers.</p>
<p>But we&#39;re not stopping there. We&#39;re also building the Energy Network: a decentralised platform of smart devices that rewards users in Energy Dollars for electrifying their homes, shifting usage to off-peak hours, and helping balance the grid. This network strengthens grid stability - a critical foundation for scaling AI data centers and other energy-intensive industries.</p>
<p><strong>Responsibilities</strong></p>
<p><strong>Security Engineering &amp; Implementation</strong></p>
<ul>
<li>Assist in implementing and maintaining security controls across cloud infrastructure, web applications, and internal systems.</li>
<li>Support secure configuration of services, including access controls, secrets management, and API security.</li>
<li>Help review and improve the security of components related to identity, authentication, and transaction workflows.</li>
</ul>
<p><strong>Threat Modelling &amp; Risk Awareness</strong></p>
<ul>
<li>Participate in threat modelling exercises and security reviews for new features and system changes.</li>
<li>Help identify common security risks and misconfigurations, and work with engineers to remediate them.</li>
<li>Stay informed about common attack vectors and vulnerabilities relevant to modern cloud and web environments.</li>
</ul>
<p><strong>Security Operations &amp; Incident Support</strong></p>
<ul>
<li>Assist with monitoring, detection, and investigation of security alerts and events.</li>
<li>Support incident response activities, including analysis, documentation, and follow-up remediation tasks.</li>
<li>Help maintain and improve runbooks, alerts, and basic detection mechanisms.</li>
</ul>
<p><strong>Secure Development &amp; Best Practices</strong></p>
<ul>
<li>Contribute to secure development practices, including code reviews with a security lens.</li>
<li>Help document and promote security guidelines for engineers, such as secure coding and secrets handling.</li>
<li>Support ongoing efforts related to compliance readiness (e.g., evidence gathering, control checks).</li>
</ul>
<p><strong>Collaboration &amp; Learning</strong></p>
<ul>
<li>Work closely with engineering and product teams to integrate security into day-to-day development.</li>
<li>Learn from senior security engineers and actively develop your skills in cloud security, application security, and infrastructure security.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field, or equivalent practical experience.</li>
<li>2–3 years of experience in a Security Engineer, Software Engineer, Infrastructure Engineer, or similar role with security exposure.</li>
<li>Foundational understanding of security concepts such as authentication, authorisation, encryption, and secure communication.</li>
<li>Familiarity with common web and cloud security risks (e.g., OWASP Top 10, IAM misconfigurations).</li>
<li>Basic experience with AWS and an interest in cloud security best practices.</li>
<li>Working knowledge of operating systems, networking fundamentals, and software development workflows.</li>
<li>Strong problem-solving skills and a willingness to learn and grow in a fast-moving environment.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Competitive salary and an equity sign-on bonus</li>
<li>Biannual bonus scheme</li>
<li>Fully expensed tech to match your needs</li>
<li>Paid annual leave</li>
<li>Breakfast and dinner allowance for office based employees</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AWS, cloud security, application security, infrastructure security, security concepts, authentication, authorisation, encryption, secure communication, OWASP Top 10, IAM misconfigurations, operating systems, networking fundamentals, software development workflows</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Fuse Energy</Employername>
      <Employerlogo>https://logos.yubhub.co/view.com.png</Employerlogo>
      <Employerdescription>Fuse Energy is a renewable energy startup that aims to deliver a terawatt of renewable energy. It has raised $170M from top-tier investors.</Employerdescription>
      <Employerwebsite>https://jobs.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.workable.com/view/eziLwb6ZKLhWWhioSWTY9L/hybrid-security-engineer-in-dubai-at-fuse-energy</Applyto>
      <Location>Dubai</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
  </jobs>
</source>