{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/secure-coding"},"x-facet":{"type":"skill","slug":"secure-coding","display":"Secure Coding","count":16},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1f736004-9d0"},"title":"Staff DevOps Engineer - PAM Core","description":"<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>\n<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>\n<p>Okta is the identity standard. The Okta Identity Cloud is an independent and neutral platform that securely connects the right people to the right technologies at the right time. We help organisations do two things - secure and manage their extended enterprise, and transform their customers&#39; experiences.</p>\n<p>With over 14,000 customers, 7,000+ app integrations, and well over 200 million registered users, we are only getting started.</p>\n<p>The Okta Privileged Access Management (PAM) is an identity-centric approach to a common and critical privileged access use case. Our elegant Zero Trust architecture is purpose-built for the modern cloud and helps customers solve challenging security and operations pain points at scale.</p>\n<p>We&#39;re looking for a staff-level Platform engineer to join a team of highly skilled and talented team players who&#39;re proud of what they own and deliver. Our elite team is fast, creative, and flexible; with a weekly release cycle and individual ownership, we expect great things from our engineers and reward them with stimulating new projects, new technologies, and the chance to have significant equity in a company that is changing the cloud computing landscape forever.</p>\n<p>You Will: Core contributor to Okta’s FedRAMP initiative Work with engineering teams to design, develop and deliver cloud-based infrastructure projects on a modern tech stack (Kubernetes/EKS, RDS, DynamoDB, Kinesis, MKS, Redis, OpenSearch, Docker, Terraform on AWS) Drive evaluation, development, and rollout of new common microservices Operate, support, and upgrade shared services and frameworks. Scale these as their usage invariably grows along with Okta&#39;s business. Evaluate existing systems to evolve them for serving in specialised circumstances to support Okta&#39;s future business needs Conduct design and code reviews. Ascertain that proposed designs consider scale, redundancy, and multi-tenancy. Ensure high programming standards by writing unit and functional tests. Monitor, troubleshoot, and fix services and frameworks the team owns Evaluate system performance and resolve bottlenecks Provide technical guidance and mentorship to junior developers Collaborate with architects, QA, product owners, security and operations engineers</p>\n<p>You Have: Immense passion for doing the right thing to help Okta&#39;s technology stay ahead of its anticipated business growth Solid technology chops in architecting, implementing, tuning, and debugging some of the largest cloud deployments in the enterprise world A good understanding of computer science fundamentals such as data structures and algorithms Bachelor&#39;s degree in computer science or equivalent; master&#39;s preferred 7+ years of extensive programming experience in a modern programming language like Go, Java, or C++ especially in backend services. Go is preferred. 4+ years experience working with PostgreSQL or equivalent relational database systems. Experience with designing and querying databases with optimisation in mind is a plus. Experience with Cloud fundamental building blocks like IaC, Observability, Secrets Management, CI / CD pipelines, secure coding practices, and compliance. Demonstrated experience of working with REST and thorough understanding of its fundamentals Experience with AWS, Redis, Elasticsearch / OpenSearch, Kinesis, Kafka, and Docker Knowledge of network security, authentication, and authorisation Demonstrably followed best software engineering principles Familiarity with Agile software development process</p>\n<p>This position requires the ability to access federal environments and/or have access to protected federal data. As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.</p>\n<p>Requires in-person onboarding and travel to our San Francisco, CA HQ office or our Chicago office during the first week of employment.</p>\n<p>#LI-Hybrid #LI-LSS1 requisition ID- P24954_3414076</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1f736004-9d0","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7838282","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$194,000-$267,000 USD","x-skills-required":["Go","Java","C++","PostgreSQL","AWS","Redis","Elasticsearch/OpenSearch","Kinesis","Kafka","Docker","IaC","Observability","Secrets Management","CI/CD pipelines","secure coding practices","compliance","REST","network security","authentication","authorisation"],"x-skills-preferred":[],"datePosted":"2026-04-24T12:13:28.735Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, California"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Go, Java, C++, PostgreSQL, AWS, Redis, Elasticsearch/OpenSearch, Kinesis, Kafka, Docker, IaC, Observability, Secrets Management, CI/CD pipelines, secure coding practices, compliance, REST, network security, authentication, authorisation","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":194000,"maxValue":267000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_edd2e001-25d"},"title":"Senior Software Engineer","description":"<p>The Edge browser is a strategic product and a key entry point to Microsoft’s new AI ecosystem serving hundreds of millions of users daily. The Edge Engineering System team is looking for exceptional engineers to help us streamline our engineering workflows and enable our development team to develop high-quality code at light speed. We build modern, AI-first engineering workflows and ensure that our releases are regular, timely, and automatic.</p>\n<p>As a Senior Software Engineer on the Edge Engineering System team, you will be responsible for using appropriate artificial intelligence (AI) tools and practices across the software development lifecycle (SDLC) in a disciplined manner. You will take responsibility for the content of your AI-generated changes to artifacts, reviewing all changes and applying appropriate tooling and processes with minimal guidance.</p>\n<p>You will use debugging, tests, tools, logs, telemetry, and other methods to proactively verify assumptions before issues occur for product features in production. You will conduct incident retrospectives and identify root causes of problems, implementing repair actions, and identifying mechanisms to prevent incident recurrence with minimal supervision.</p>\n<p>Under minimal guidance, you will apply least-access principles, and use logging, telemetry, and other appropriate mechanisms to investigate issues while retaining privacy and security. You will review product feature code and test code to ensure it meets team standards, contains the correct test coverage, and is appropriate for the product feature.</p>\n<p>You will bring insight to code reviews to help improve code quality, coaching and providing feedback to develop other engineers’ skills with minimal guidance. You will review code in a timely fashion that helps accelerate the pace of development on the team.</p>\n<p>You will consider diagnosability, reliability, testability, and maintainability when reviewing code and understand when code is ready to be shared or delivered. You will apply and review for coding patterns, security risks, compliance issues, and best practices in code reviews.</p>\n<p>You will understand and provide feedback for proposals for architecture, with technical leadership from others. With minimal supervision, you will test and explore various design options for a product/solution feature, outlining strengths and weaknesses of each option.</p>\n<p>You will own or collaborate with other engineers on the architecture of solutions, following technical leadership as applicable. You will contribute to the development of design documents that support user stories and other product requirements with oversight.</p>\n<p>You will develop an awareness of the current technology landscape. You will escalate and share findings from investigations with the team and own some design decisions.</p>\n<p>You will help to ensure system architecture and individual designs meet performance, scalability, resiliency, cost of goods sold (COGS), and other requirements and expectations.</p>\n<p>You will uphold Microsoft standards of security, privacy, and other compliance requirements and expectations.</p>\n<p>You will understand the importance of building solutions that expand upon the work of others.</p>\n<p>You will contribute to the refinement of product features by escalating findings from analyses to inform decisions regarding the engineering of products.</p>\n<p>You will create a clear test strategy that ensures solution quality, prevents regression from being introduced into existing code with minimal supervision.</p>\n<p>You will execute test plans that incorporate security testing to validate security invariants (including negative cases) with minimal supervision.</p>\n<p>You will add new tests to cover gaps, deleting or fixing broken tests, improving the speed, reliability, and defect localization of tests in the feature area.</p>\n<p>You will build testable code and consider testability during design for a set of features with minimal guidance.</p>\n<p>You will understand the different types of tests that can be done on a particular system (e.g., unit tests), and maintain up-to-date understanding of testing architectures used both across Microsoft and across the industry.</p>\n<p>You will identify dependencies and incorporate them into the development of design documents for a product area with little oversight.</p>\n<p>You will actively identify other teams and technologies to leverage, how they interact, and where their own system or team can support others.</p>\n<p>You will understand downstream interactions between systems.</p>\n<p>You will contribute to collaborating with other teams to reach common goals where dependencies and validation concerns overlap.</p>\n<p>You will contribute to the identification of requirements for, and development of automation within production and deployment of a complex product feature, targeting zero-touch deployment when possible.</p>\n<p>You will run code in simulated, or other non-production environments to confirm functionality and error-free runtime for products with little to no oversight.</p>\n<p>You will apply best practices to build code based on well-established methods and secure design principles while also applying best practices for new code development and formal validation of security invariants.</p>\n<p>You will follow best practices for product development and scaling to customer requirements and applies best practices for meeting scaling needs and performance expectations and security promises.</p>\n<p>You will ensure the correct processes are followed to achieve a high degree of security, privacy, safety, and accessibility.</p>\n<p>You will check for visible evidence (e.g., audit trail) to demonstrate compliance for product areas.</p>\n<p>You will develop and hold an understanding of the implications of onboarding new technologies following expectations of compliance at Microsoft.</p>\n<p>You will demonstrate and maintain an up-to-date understanding of both global and local regulations for technologies and system applications to ensure regulations are met.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_edd2e001-25d","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Microsoft","sameAs":"https://microsoft.ai","logo":"https://logos.yubhub.co/microsoft.ai.png"},"x-apply-url":"https://microsoft.ai/job/senior-software-engineer-127/","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["artificial intelligence","software development lifecycle","debugging","testing","logging","telemetry","security","compliance","best practices","design principles","secure coding","testability","maintainability","diagnosability","reliability","scalability","resiliency","cost of goods sold","performance","security invariants","negative cases","unit tests","testing architectures","dependencies","validation concerns","automation","zero-touch deployment","simulated environments","non-production environments","best practices for product development","scaling to customer requirements","meeting scaling needs","performance expectations","security promises","privacy","safety","accessibility","audit trail","regulations","global regulations","local regulations"],"x-skills-preferred":[],"datePosted":"2026-04-24T12:11:21.836Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Redmond"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"artificial intelligence, software development lifecycle, debugging, testing, logging, telemetry, security, compliance, best practices, design principles, secure coding, testability, maintainability, diagnosability, reliability, scalability, resiliency, cost of goods sold, performance, security invariants, negative cases, unit tests, testing architectures, dependencies, validation concerns, automation, zero-touch deployment, simulated environments, non-production environments, best practices for product development, scaling to customer requirements, meeting scaling needs, performance expectations, security promises, privacy, safety, accessibility, audit trail, regulations, global regulations, local regulations"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_9f60f6cb-24d"},"title":"Senior Application Security Engineer","description":"<p>At Webflow, our mission is to bring development superpowers to everyone. We&#39;re looking for a Senior Application Security Engineer to help us level up Webflow&#39;s secure development practices ranging from secure coding, tooling, and improving procedures.</p>\n<p>As a Senior Application Security Engineer, you&#39;ll collaborate with the Webflow engineering team to secure Webflow&#39;s web application platform and ecosystem. You&#39;ll bring security best practices to the software development lifecycle, work as part of a team to champion security standards while balancing business strategies and requirements, and support Webflow&#39;s security current and future compliance frameworks.</p>\n<p>You&#39;ll work to find security vulnerabilities through grey-box techniques, and propose solutions at the architecture and code level to mitigate findings. You&#39;ll contribute code and architecture improvements to enable security within Webflow&#39;s application for engineers, and cross-train entry-level application security engineers.</p>\n<p>In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we&#39;ll help you incorporate them into your role.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_9f60f6cb-24d","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Webflow","sameAs":"https://webflow.com","logo":"https://logos.yubhub.co/webflow.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/webflow/jobs/7793827","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$158,000 - $238,000 (Zone A), $149,000 - $224,000 (Zone B), $139,000 - $210,000 (Zone C), $199,000 - $250,000 (Canada)","x-skills-required":["application security","secure coding","modern web application security","threat modeling","penetration testing","security controls","agentic AI","security automation"],"x-skills-preferred":[],"datePosted":"2026-04-24T12:09:52.710Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"CA Remote (BC & ON only); U.S. Remote"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, secure coding, modern web application security, threat modeling, penetration testing, security controls, agentic AI, security automation","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":139000,"maxValue":250000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_f77c41bb-0ad"},"title":"Application Security Engineer","description":"<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert, you will have direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise.</p>\n<p>The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm’s information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</li>\n<li>Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).</li>\n<li>Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.</li>\n<li>Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.</li>\n<li>Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.</li>\n<li>Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.</li>\n<li>Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.</li>\n</ul>\n<p><strong>Qualifications</strong></p>\n<ul>\n<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field.</li>\n<li>5+ years’ experience working as an Application Security Engineer, Software Engineer, or similar role.</li>\n<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.</li>\n<li>Experience working with AI models, Agentic frameworks and security risks associated with AI.</li>\n<li>Experience in working with global teams, collaborating on code and presentations.</li>\n<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>\n<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.</li>\n<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>\n<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.</li>\n<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>\n<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.</li>\n<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>\n<li>Familiarity with web application security testing tools and methodologies.</li>\n<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>\n<li>Knowledge of Linux, OS internals and containers is a plus.</li>\n<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_f77c41bb-0ad","directApply":true,"hiringOrganization":{"@type":"Organization","name":"IT Infrastructure","sameAs":"https://mlp.eightfold.ai","logo":"https://logos.yubhub.co/mlp.eightfold.ai.png"},"x-apply-url":"https://mlp.eightfold.ai/careers/job/755955629927","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["AI-specific risks","Generative AI","LLMs","Agentic frameworks","Security guardrails","Threat modeling","Red teaming","Risk assessments","Application risk assessments","Design reviews","Mitigation strategies","Secure coding standards","Automated security testing","CI/CD pipelines","Security architectures","Secure configuration principles","Cryptography fundamentals","Encryption protocols","SCM & CI/CD technologies","Security scanning","Vulnerability management","Static and dynamic security analysis tools","SCA/SBOM solutions","Secrets management","Password vault technologies","Secure programming","Infrastructure as Code tools","Web application security testing tools","Methodologies","Security frameworks","Standards","Linux","OS internals","Containers"],"x-skills-preferred":[],"datePosted":"2026-04-18T22:14:17.280Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dublin, Ireland"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Automated security testing, CI/CD pipelines, Security architectures, Secure configuration principles, Cryptography fundamentals, Encryption protocols, SCM & CI/CD technologies, Security scanning, Vulnerability management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets management, Password vault technologies, Secure programming, Infrastructure as Code tools, Web application security testing tools, Methodologies, Security frameworks, Standards, Linux, OS internals, Containers"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_6a75ea8b-5b4"},"title":"Application Security Engineer","description":"<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies, you will play a key role in building toolsets and processes to drive adoption of secure practices across the enterprise.</p>\n<p>The successful candidate will have a proven understanding in enterprise security and AI security and will focus on defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks</li>\n<li>Conducting specialized threat modeling, red teaming, and risk assessments for AI/ML models</li>\n<li>Leading risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects</li>\n<li>Engaging throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards</li>\n<li>Evangelizing AppSec and AI security best practices through developer education, training materials, and outreach</li>\n</ul>\n<p>Qualifications include:</p>\n<ul>\n<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field</li>\n<li>5+ years&#39; experience working as an Application Security Engineer, Software Engineer, or similar role</li>\n<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs</li>\n<li>Experience working with AI models, Agentic frameworks and security risks associated with AI</li>\n<li>Experience in working with global teams, collaborating on code and presentations</li>\n</ul>\n<p>Preferred qualifications include:</p>\n<ul>\n<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>\n<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols</li>\n<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>\n<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions</li>\n<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>\n<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar</li>\n<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>\n<li>Familiarity with web application security testing tools and methodologies</li>\n<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>\n<li>Knowledge of Linux, OS internals and containers is a plus</li>\n<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous</li>\n</ul>\n<p>We offer a competitive salary and benefits package, as well as opportunities for professional growth and development.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_6a75ea8b-5b4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"IT Infrastructure","sameAs":"https://mlp.eightfold.ai","logo":"https://logos.yubhub.co/mlp.eightfold.ai.png"},"x-apply-url":"https://mlp.eightfold.ai/careers/job/755955629908","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["AI-specific risks","Generative AI","LLMs","Agentic frameworks","Security guardrails","Threat modeling","Red teaming","Risk assessments","Application risk assessments","Design reviews","Mitigation strategies","Secure coding standards","Developer education","Training materials","Outreach","Common SCM & CI/CD technologies","GitHub","Jenkins","Artifactory","Security Scanning","Vulnerability Management","Static and dynamic security analysis tools","SCA/SBOM solutions","Secrets Management & Password Vault technologies","Delinea Secret Server","Hashicorp Vault","Secure programming","Python","Java","C++","C#","Infrastructure as Code tools","CloudFormation","Terraform","Ansible","Web application security testing tools","Methodologies","Security frameworks","Standards","ISO 27001","NIST","OWASP","Linux","OS internals","Containers"],"x-skills-preferred":[],"datePosted":"2026-04-18T22:14:06.620Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London, United Kingdom"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Developer education, Training materials, Outreach, Common SCM & CI/CD technologies, GitHub, Jenkins, Artifactory, Security Scanning, Vulnerability Management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets Management & Password Vault technologies, Delinea Secret Server, Hashicorp Vault, Secure programming, Python, Java, C++, C#, Infrastructure as Code tools, CloudFormation, Terraform, Ansible, Web application security testing tools, Methodologies, Security frameworks, Standards, ISO 27001, NIST, OWASP, Linux, OS internals, Containers"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ffaf189f-831"},"title":"Principal Software Engineer, Architect - Java Backend","description":"<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes.</p>\n<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>\n<p>We&#39;re building a world where Identity belongs to you.</p>\n<p>Okta is the leading independent provider of enterprise identity. The Okta Identity Cloud enables organisations to securely connect the right people to the right technologies at the right time. With over 6,500 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business.</p>\n<p>Access Management Foundation Team</p>\n<p>The Access Management Pillar at Okta is on a mission to seamlessly and securely authorise users to access any resource they need to get their work done. Our goal is to lead the industry in Zero Trust identity management. The Access Foundation Backend Team is at the core of this mission, building and maintaining the foundational components and frameworks that power Okta&#39;s identity and access management solutions.</p>\n<p>We develop Okta cloud services and client software that allow users to seamlessly login to devices and use Okta authenticators to access applications securely.</p>\n<p>Learn more about Okta’s Engineering on our blog.</p>\n<p>About You</p>\n<p>We are looking for a seasoned Principal Engineer to join our team and help us build the future of identity and access management. Ideal candidate should be:</p>\n<ul>\n<li>A strong Java developer with a passion for building high-quality, secure, and performant applications and frameworks.</li>\n<li>Excited by the opportunity to work on cutting-edge security and identity management challenges and are a thought leader who can drive technical strategy and mentor other engineers.</li>\n<li>A collaborative individual with excellent communication skills, capable of working with cross-functional teams to deliver on a shared vision.</li>\n<li>Not just be a builder; but a force multiplier who can create frameworks and solutions that enable other teams to be more productive.</li>\n</ul>\n<p>Job Duties and Responsibilities:</p>\n<ul>\n<li>Design, develop, and maintain core components of the Okta Access Management platform</li>\n<li>Lead the architectural design and implementation of new features and services, with a focus on scalability, performance, and security.</li>\n<li>Build and maintain frameworks that enable other engineering teams to ship modular and secure code quickly.</li>\n<li>Collaborate with product managers, architects, and other engineering teams to define the technical strategy and lead the prototyping of framework components</li>\n<li>Following best practices, contribute to technical designs, proposals, and architectural decisions.</li>\n<li>Drive a culture of quality and continuous improvement, with a focus on robust testing, monitoring, and operational excellence.</li>\n<li>Stay up-to-date with the latest industry trends and technologies in identity, security, and distributed systems.</li>\n</ul>\n<p>Minimum Requirements:</p>\n<ul>\n<li>12+ years of experience building and scaling Java-based web applications and services.</li>\n<li>A deep understanding of design patterns, scalability patterns, security engineering, and object-oriented principles.</li>\n<li>Experience working in a fast-paced, agile environment, with a strong understanding of CI/CD practices.</li>\n<li>Strong communication skills and the ability to work across functions</li>\n</ul>\n<p>Nice to have:</p>\n<ul>\n<li>Experience with identity and access management (IAM) protocols such as SAML, OAuth, FIDO, and WebAuthn</li>\n<li>Experience with security best practices and threat modeling</li>\n<li>Experience with one or more UI technologies such as Angular, ReactJS, Backbone, and Vue.</li>\n<li>Knowledge of cybersecurity principles, secure coding practices, and certifications like CISSP or Security+</li>\n</ul>\n<p>Education and Training:</p>\n<ul>\n<li>Bachelor’s degree in Computer Science or equivalent experience.</li>\n<li>12+ years of software development experience</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ffaf189f-831","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7600755","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Java","Identity and Access Management","Security Engineering","Object-Oriented Principles","CI/CD Practices","Agile Environment","Cloud Services","Client Software","UI Technologies","Cybersecurity Principles","Secure Coding Practices"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:57:11.622Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Bengaluru, India"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Java, Identity and Access Management, Security Engineering, Object-Oriented Principles, CI/CD Practices, Agile Environment, Cloud Services, Client Software, UI Technologies, Cybersecurity Principles, Secure Coding Practices"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ef348b50-2ac"},"title":"Product Security Engineer","description":"<p>Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our rapidly evolving platform. You will partner closely with product engineering teams to build paved roads, frameworks, and automated controls that make the secure path the easy path for our engineering teams.</p>\n<p>Your responsibilities will include developing self-service security frameworks and &#39;paved roads&#39; that allow engineering teams to ship secure code by default. You will focus on automated guardrails for common vulnerabilities, while prioritising deep-dive design reviews into complex business logic and data isolation issues. You will also partner with product and engineering teams to review designs early, contribute to threat modelling for new features and complex initiatives, and provide clear, actionable security guidance.</p>\n<p>You will research emerging threats and evolving best practices, specifically regarding AI and LLM safety, and implement controls to secure these workflows. You will manage and evolve our approach to external penetration testing and bug bounties, driving remediation for findings and treating vulnerability management as an engineering problem.</p>\n<p>You will contribute to the long-term roadmaps, metrics, and strategic planning for the security team. As a senior member of the team, you will lead complex threat modelling sessions for major product launches and define secure coding standards, and actively mentor other engineers to raise the technical security bar across the organisation.</p>\n<p>We are looking for a highly experienced Product Security Engineer with a strong background in computer science or a related field, and proficiency in writing clean, maintainable code. You should have deep familiarity with JavaScript or TypeScript, Node.js, and modern web application frameworks, and be able to reason about the security implications of systems built on them. You should also have hands-on experience securing LLM integrations and identifying prompt injection or data leakage risks.</p>\n<p>You will excel at communicating complex security risks to non-security stakeholders and enjoy collaborating cross-functionally to find solutions that balance security with engineering velocity. You will be comfortable working in a fast-paced environment, navigating ambiguity, continuously learning about emerging threats and technologies, and contributing to long-term security strategy.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ef348b50-2ac","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Airtable","sameAs":"https://airtable.com/","logo":"https://logos.yubhub.co/airtable.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/airtable/jobs/8194662002","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["JavaScript","TypeScript","Node.js","Modern web application frameworks","LLM integrations","Prompt injection","Data leakage risks","Threat modelling","Secure coding standards"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:55:21.514Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA; New York, NY; Remote (Seattle, WA only)"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"JavaScript, TypeScript, Node.js, Modern web application frameworks, LLM integrations, Prompt injection, Data leakage risks, Threat modelling, Secure coding standards"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_aff17a60-097"},"title":"Application Security Engineer","description":"<p>As a Security Engineer focused on Application and Product Security, you will play a key role in improving the security posture of our applications, services, and development ecosystem.</p>\n<p>You will work closely with engineering teams to integrate security into the software development lifecycle, build secure-by-default patterns, and ensure that products are resilient against modern threats.</p>\n<p>This role combines hands-on technical work, security engineering, and collaboration with developers to guide secure design and remediation.</p>\n<p>You will help implement security controls, perform assessments, and contribute to the continuous improvement of our security program.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Integrating application security best practices into the development lifecycle by partnering with engineering teams and enabling automated security checks within CI/CD pipelines.</li>\n</ul>\n<ul>\n<li>Supporting and maintaining Application Security based tooling,including SAST, DAST, SCA, and secrets scanning,and helping developers interpret and remediate findings.</li>\n</ul>\n<ul>\n<li>Conducting secure code reviews, threat modeling sessions, and application architecture assessments to identify risks and propose mitigation strategies.</li>\n</ul>\n<ul>\n<li>Developing and maintaining security automation, guardrails, and reusable components.</li>\n</ul>\n<ul>\n<li>Assisting in defining and improving secure coding standards and application hardening practices.</li>\n</ul>\n<ul>\n<li>Supporting monitoring and detection efforts by helping improve application-level logging, telemetry, and alerting.</li>\n</ul>\n<ul>\n<li>Assisting in incident response activities related to application vulnerabilities, including verification, triage, and remediation support.</li>\n</ul>\n<ul>\n<li>Staying current on emerging threats, vulnerabilities, and best practices in application and product security.</li>\n</ul>\n<ul>\n<li>Contributing to documentation including security requirements, guidelines, and remediation playbooks.</li>\n</ul>\n<ul>\n<li>Participating in internal security reviews, compliance-driven assessments, and architectural walkthroughs.</li>\n</ul>\n<ul>\n<li>Developing and helping maintain existing application security tools, pipelines, and workflows.</li>\n</ul>\n<ul>\n<li>Collaborating with engineering and product teams to ensure secure deployment and continuous improvement of applications.</li>\n</ul>\n<p>Requirements include:</p>\n<ul>\n<li>A bachelor’s degree in Computer Science, Engineering, MIS, or equivalent practical experience.</li>\n</ul>\n<ul>\n<li>2–5 years of experience in application security, product security, software engineering with a security focus, or a related technical role.</li>\n</ul>\n<ul>\n<li>Strong understanding of application vulnerabilities and mitigation strategies (OWASP Top 10, CWE).</li>\n</ul>\n<ul>\n<li>Experience with CI/CD tooling, Git-based workflows, and modern development practices.</li>\n</ul>\n<ul>\n<li>Familiarity with cloud security concepts and hands-on experience with at least one cloud platform (AWS, Azure, or GCP).</li>\n</ul>\n<ul>\n<li>Experience with one or more programming languages such as Python, Go, Java, JavaScript/Typescript, or Ruby. (Java and Python preferred.)</li>\n</ul>\n<ul>\n<li>Experience with application security tools such as OWASP ZAP, Burp Suite, SAST/DAST tools, SCA, or dependency scanning.</li>\n</ul>\n<ul>\n<li>Knowledge of secure coding principles, API security, authentication, authorization, and secrets management.</li>\n</ul>\n<ul>\n<li>Strong problem-solving skills and the ability to communicate technical issues clearly to developers and cross-functional stakeholders.</li>\n</ul>\n<ul>\n<li>Understanding of agile development processes and working within engineering teams.</li>\n</ul>\n<ul>\n<li>Ability to Travel: This role will require 25% in-person travel for purposes including but not limited to new hire onboarding, team and department offsites, customer engagements, and other company events.</li>\n</ul>\n<p>This role is based in our Boston office and follows a hybrid model, with an expectation of being onsite 1-2 days per week.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_aff17a60-097","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Starburst","sameAs":"https://www.starburst.io/","logo":"https://logos.yubhub.co/starburst.io.png"},"x-apply-url":"https://job-boards.greenhouse.io/starburst/jobs/5119301008","x-work-arrangement":"hybrid","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$130,000-$170,000 USD","x-skills-required":["CI/CD tooling","Git-based workflows","modern development practices","cloud security concepts","application security tools","secure coding principles","API security","authentication","authorization","secrets management"],"x-skills-preferred":["Python","Go","Java","JavaScript/Typescript","Ruby"],"datePosted":"2026-04-18T15:51:05.628Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Boston, MA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"CI/CD tooling, Git-based workflows, modern development practices, cloud security concepts, application security tools, secure coding principles, API security, authentication, authorization, secrets management, Python, Go, Java, JavaScript/Typescript, Ruby","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":130000,"maxValue":170000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_46d6bdd3-23c"},"title":"Senior Backend Engineer (RoR), AST: Secret Detection","description":"<p>As a Senior Backend Engineer on the Secret Detection team, you&#39;ll help protect sensitive data by building services, scanning workflows, and remediation paths that prevent leaked secrets from reaching production.</p>\n<p>Your work will contribute to the full secret management lifecycle, from push protection to pipeline-based scanning, validation, and auditability, so developers can move quickly without taking on avoidable security risk.</p>\n<p>This is a strong opportunity if you want to work on security features with clear customer impact, improve detection quality, and help teams act when credentials, API keys, or other secrets are exposed.</p>\n<p>You&#39;ll focus on backend systems that power Secret Detection across GitLab&#39;s DevSecOps platform, working closely with product management and engineering peers in an async-first environment.</p>\n<p>In your first year, you&#39;ll contribute to core product capabilities, improve performance and result quality, and help shape technical direction through code reviews, RFCs, and proof of concepts.</p>\n<p>Some examples of our projects:</p>\n<ul>\n<li>Prevent secret leaks in source code with GitLab Secret Push Protection</li>\n<li>Verify validity of secret detection findings</li>\n</ul>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Guide the design and implementation of backend features for GitLab Secret Detection in Ruby on Rails, GraphQL, and Go, delivering capabilities that improve coverage, reliability, or response time for secret detection workflows.</li>\n<li>Build clean, well-tested, maintainable code that meets GitLab standards for reliability and performance, helping reduce regressions and maintain backend systems at scale.</li>\n<li>Partner with product management and engineering peers to deliver backend capabilities that improve detection, validation, remediation, and audit trail coverage across the secret management lifecycle.</li>\n<li>Improve detection quality by reducing false positives, strengthening secret validation workflows, and enabling faster, more effective remediation paths.</li>\n<li>Contribute to code reviews, RFCs, and proof-of-concept work that guide technical approaches across the Secret Detection category.</li>\n<li>Identify technical debt and operational inefficiencies, then propose and implement practical improvements.</li>\n<li>Diagnose performance and optimization issues in backend systems and implement improvements that increase efficiency, scalability, and service reliability.</li>\n<li>Work effectively in a globally distributed, async-first team while participating in planning, engineering discussions, and pairing when needed.</li>\n</ul>\n<p><strong>Requirements</strong></p>\n<ul>\n<li>Experience building backend applications and services using Ruby on Rails, with working knowledge of GraphQL and interest in backend-focused product development.</li>\n<li>Experience designing and delivering secure, maintainable systems that power production web applications at scale.</li>\n<li>Knowledge of security concepts, common vulnerabilities, mitigation techniques, and secure coding practices.</li>\n<li>Background developing or working with security tools or products, especially in areas related to code scanning or secret detection.</li>\n<li>Experience investigating performance issues and improving backend reliability, efficiency, and maintainability.</li>\n<li>Ability to work closely with cross-functional partners, including product, design, and technical writing, to deliver useful product outcomes.</li>\n<li>Communicate clearly in writing and in conversation, especially in remote, async-first environments with distributed teams.</li>\n<li>Bring transferable experience and a willingness to grow into parts of the security or Go stack.</li>\n</ul>\n<p><strong>About the Team</strong></p>\n<p>The Secret Detection team owns GitLab&#39;s Secret Detection category, and we build the backend systems and related user workflows that help developers identify and mitigate exposed secrets as code is contributed.</p>\n<p>We work with the broader security product suite while maintaining focused investment in secret scanning quality, validation, remediation, and developer experience.</p>\n<p>Our work spans Rails and Go services, and we work primarily asynchronously across time zones as a globally distributed team.</p>\n<p>Current opportunities include expanding coverage across the secret management lifecycle and improving result quality across the findings our tools detect.</p>\n<p>For more on how we work, see the Team Handbook page.</p>\n<p><strong>Benefits</strong></p>\n<ul>\n<li>Benefits to support your health, finances, and well-being</li>\n<li>Flexible Paid Time Off</li>\n<li>Team Member Resource Groups</li>\n<li>Equity Compensation &amp; Employee Stock Purchase Plan</li>\n<li>Growth and Development Fund</li>\n<li>Parental leave</li>\n<li>Home office support</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_46d6bdd3-23c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"GitLab","sameAs":"https://about.gitlab.com/","logo":"https://logos.yubhub.co/about.gitlab.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/gitlab/jobs/8432262002","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$117,600-$252,000 USD","x-skills-required":["Ruby on Rails","GraphQL","Go","Backend development","Security","Secure coding practices","Code scanning","Secret detection"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:50:50.538Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote, Canada; Remote, Ireland; Remote, Israel; Remote, Netherlands; Remote, United Kingdom; Remote, US"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Ruby on Rails, GraphQL, Go, Backend development, Security, Secure coding practices, Code scanning, Secret detection","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":117600,"maxValue":252000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_777a6e79-5d9"},"title":"Senior Software Engineer, Security Engineering","description":"<p>Secure Every Identity ----------------------- Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>\n<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work.</p>\n<p>The Role -------- We seek a knowledgeable and development-focused Security Engineer, who will build micro-services to secure Customer Identity Products and Infrastructure.</p>\n<p>Responsibilities --------------- Work across a globally distributed product-aligned team of security engineers Establish a deep understanding of Okta Customer Identity products and infrastructure Collaborate when necessary with the Okta Security team on security operations Build, deploy &amp; maintain scalable and reliable infrastructure services as well as security solutions for customer identity products Build, deploy &amp; maintain automation to improve platform security capabilities at scale including logging, threat detection and compliance benchmarks to increase our security posture Help meet our operational security commitments by thinking like an attacker, assessing the risk, and advising on mitigation strategies Support security investigations in coordination with the Okta Security team, participate in root cause analysis and perform necessary remediations. Support stakeholders by proposing mitigation strategies for end-of-life software and security vulnerability and patch management</p>\n<p>Requirements ----------- You have 3+ years of hands-on development experience writing microservices with Golang You have 3+ years of experience in cloud infrastructure security, product security You have working knowledge and hands on development experience with one or more of the following: AWS and/or Azure security Kubernetes You have strong knowledge in OWASP Top 10 and secure coding best practices You have strong foundation on secure software development lifecycle best practices You have strong written and verbal communication skills You have experience working with a globally distributed and remote team.</p>\n<p>Bonus points if: You have working knowledge and experience with one or more of the following: Full-stack engineering Site reliability engineering Identity and access management Vulnerability and threat management Security detection and response Governance, risk and compliance</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_777a6e79-5d9","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7744352","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Golang","Cloud infrastructure security","Product security","AWS security","Azure security","Kubernetes","OWASP Top 10","Secure coding best practices","Secure software development lifecycle best practices"],"x-skills-preferred":["Full-stack engineering","Site reliability engineering","Identity and access management","Vulnerability and threat management","Security detection and response","Governance, risk and compliance"],"datePosted":"2026-04-18T15:44:00.927Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Bengaluru, India"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Golang, Cloud infrastructure security, Product security, AWS security, Azure security, Kubernetes, OWASP Top 10, Secure coding best practices, Secure software development lifecycle best practices, Full-stack engineering, Site reliability engineering, Identity and access management, Vulnerability and threat management, Security detection and response, Governance, risk and compliance"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_6d2bed6a-1bd"},"title":"Application Security Engineer","description":"<p>We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies.</p>\n<p>Responsibilities: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10</p>\n<p>Basic Qualifications: Bachelor&#39;s degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences</p>\n<p>Preferred Skills and Experience: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Experience with GitOps and infrastructure-as-code security Familiarity with federated learning and privacy-preserving machine learning techniques Experience in building custom security tooling to enhance and automate security processes Interest in leveraging AI to automate security tasks and improve efficiency Contributions to open-source security projects or tools Experience in securing AI/ML models and data pipelines</p>\n<p>Compensation and Benefits: $200,000 - $340,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_6d2bed6a-1bd","directApply":true,"hiringOrganization":{"@type":"Organization","name":"xAI","sameAs":"https://www.xai.com/","logo":"https://logos.yubhub.co/xai.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/xai/jobs/4559147007","x-work-arrangement":"onsite","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$200,000 - $340,000 USD","x-skills-required":["Python","Rust","Secure coding practices","Application security frameworks","Common vulnerabilities","OWASP Top 10","CI/CD pipelines","DevSecOps practices","Software supply chain security","SBOM generation tools","Security testing tools","Static/dynamic code analysis","AI/ML security implications","OWASP LLM Top 10"],"x-skills-preferred":["Cloud platforms","Security certifications","Data privacy and compliance regulations","GitOps","Infrastructure-as-code security","Federated learning","Privacy-preserving machine learning techniques","Custom security tooling","AI automation","Open-source security projects","AI/ML model security"],"datePosted":"2026-04-18T15:23:13.995Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Rust, Secure coding practices, Application security frameworks, Common vulnerabilities, OWASP Top 10, CI/CD pipelines, DevSecOps practices, Software supply chain security, SBOM generation tools, Security testing tools, Static/dynamic code analysis, AI/ML security implications, OWASP LLM Top 10, Cloud platforms, Security certifications, Data privacy and compliance regulations, GitOps, Infrastructure-as-code security, Federated learning, Privacy-preserving machine learning techniques, Custom security tooling, AI automation, Open-source security projects, AI/ML model security","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":200000,"maxValue":340000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_5c7e46c8-c5c"},"title":"Application Security Intern","description":"<p>We&#39;re looking for a curious and motivated Application Security Intern to help us build secure products and development practices at VGS. As an Application Security Intern, you will partner with security and engineering teams to evaluate application risk, improve secure software development workflows, and help developers ship software safely in an environment that handles highly sensitive payment and identity data.</p>\n<p>Your responsibilities will include:</p>\n<ul>\n<li>Supporting application security reviews for services, APIs, and new product features across the VGS platform.</li>\n<li>Helping identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.</li>\n<li>Participating in threat modeling and secure design discussions with engineering teams during feature development.</li>\n<li>Evaluating the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC.</li>\n<li>Assisting with manual testing and validation of web application and API security issues.</li>\n<li>Helping improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.</li>\n<li>Working with engineers to understand remediation options and clearly document security risks and recommendations.</li>\n<li>Contributing to improving security tooling and guardrails in CI/CD and development workflows.</li>\n</ul>\n<p>We&#39;re looking for someone with a strong interest in secure software design, cloud-native architectures, and automation. You should have a foundational understanding of application security concepts, such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.</p>\n<p>At VGS, we have a remote-first philosophy, and we&#39;re looking for someone who is comfortable working independently and collaboratively as part of a team.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_5c7e46c8-c5c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"VGS","sameAs":"https://www.vgs.com","logo":"https://logos.yubhub.co/vgs.com.png"},"x-apply-url":"https://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b","x-work-arrangement":"remote","x-experience-level":"entry","x-job-type":"internship","x-salary-range":null,"x-skills-required":["application security","secure software development","cloud-native architectures","automation","OWASP Top 10","API security","authentication and authorization","secure coding","common software vulnerabilities"],"x-skills-preferred":["LMMs","threat modeling","Burp Suite","SAST/DAST tools","CI/CD pipelines","Docker/Kubernetes","cloud environments"],"datePosted":"2026-04-17T13:08:01.601Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"jobLocationType":"TELECOMMUTE","employmentType":"INTERN","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, secure software development, cloud-native architectures, automation, OWASP Top 10, API security, authentication and authorization, secure coding, common software vulnerabilities, LMMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, cloud environments"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_9eb58719-bef"},"title":"Application Security Engineer","description":"<p><strong>About the role:</strong></p>\n<p>The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. In this hands-on technical role, you will partner closely with software engineers and researchers to ensure security is a core consideration from initial design through implementation.</p>\n<p>You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>\n<p>Your insights will shape our tooling, detection capabilities, and defenses against emerging threats to AI/ML. You&#39;ll develop the standards, processes, and educational resources that enable all Anthropic engineers to be security champions.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>\n<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>\n<li>Conduct secure design reviews and threat modeling. Identify and prioritise risks, attack surfaces, and vulnerabilities</li>\n<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>\n<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritise vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>\n<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>\n<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>\n<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>\n</ul>\n<p><strong>You may be a good fit if you:</strong></p>\n<ul>\n<li>Have 5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>\n<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>\n<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>\n<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>\n<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>\n<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>\n<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>\n<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>\n<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>\n<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>\n<li>Advocate for security fundamentals like least privilege, defence-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>\n</ul>\n<p><strong>Strong candidates may also:</strong></p>\n<ul>\n<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>\n<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>\n<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>\n<li>Experience building security tools, applications, and automated tools</li>\n<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>\n<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>\n<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>\n</ul>\n<p>The annual compensation range for this role is $300,000 - $405,000 USD.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_9eb58719-bef","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4502508008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$300,000 - $405,000 USD","x-skills-required":["application security","infrastructure security","cloud security","containerized environments","secure coding practices","vulnerability management","bug bounty program","offensive security","modern application stacks","security tools"],"x-skills-preferred":["Kubernetes","Docker","AWS","GCP","Python","Rust","Go","Java","vulnerability testing","pen testing","red team exercises","AI/ML security risks","security tools","automated tools"],"datePosted":"2026-03-08T13:57:18.711Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA, Seattle, WA, New York City, NY"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, infrastructure security, cloud security, containerized environments, secure coding practices, vulnerability management, bug bounty program, offensive security, modern application stacks, security tools, Kubernetes, Docker, AWS, GCP, Python, Rust, Go, Java, vulnerability testing, pen testing, red team exercises, AI/ML security risks, security tools, automated tools","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":300000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_544e96bb-5c3"},"title":"Security Engineer, Application Security","description":"<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>New York City</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are building a team of talented engineers, researchers, and designers who share our vision and values.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_544e96bb-5c3","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/ec5a5d98-6314-44d9-9466-8d4d7ee866f6","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:31:40.678Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York City"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_90d20db9-de4"},"title":"Security Engineer, Application Security","description":"<p><strong>Job Posting</strong></p>\n<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>San Francisco</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are committed to advancing the state-of-the-art in AI research and development.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_90d20db9-de4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/0322d6d8-6588-4209-a304-83e768063a25","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:30:51.618Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_659bf794-7b5"},"title":"Security Engineer, Application Security","description":"<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>Seattle</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_659bf794-7b5","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/1e110226-448a-4c0b-b0e4-d0f5df579fbf","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:29:22.823Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Seattle"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}}]}