{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/secure-sdlc"},"x-facet":{"type":"skill","slug":"secure-sdlc","display":"Secure Sdlc","count":4},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1bb68827-243"},"title":"Staff Software Engineer, Security","description":"<p>Secure Every Identity ----------------------- Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>\n<p>We are looking for a Staff Software Engineer, Security to join our Security Engineering group. As a Staff Software Engineer, Security, you will act as a liaison between the Security org and the engineering org to build technical leverage and influence the security roadmap and direction.</p>\n<p>Responsibilities ---------------</p>\n<ul>\n<li>Act as a liaison between the engineering and security org to develop innovative requirements for the security roadmap.</li>\n<li>Evangelize security best practices across the engineering org.</li>\n<li>Research, design, implement and own security oriented frameworks and features with the common goal of protecting Okta’s customers.</li>\n<li>Routinely participate in cross-vertical code reviews with emphasis on Security.</li>\n<li>Break down complex problems into sub-tasks while prototyping rapidly and iteratively contributing to security initiatives using agile practices.</li>\n<li>Coach and mentor junior engineers in the team.</li>\n</ul>\n<p>Preferred Qualification and Abilities -----------------------------------</p>\n<ul>\n<li>7+ years of development experience in designing and implementing software systems in Java, building highly reliable and mission-critical software.</li>\n<li>3+ years of work experience in designing and implementing security solutions for applications and distributed systems.</li>\n<li>Work experience and excellent understanding in mitigating OWASP Top 10 attacks on applications, Application Security, Cryptography, Authentication, Authorization using Role-Based and Attribute-Based access controls.</li>\n<li>Strong understanding of concepts such as Test-Driven development, Secure SDLC, Secure code reviews and the ability to identify and mitigate threat vectors and vulnerabilities in code and infrastructure.</li>\n<li>Good understanding and experience in using cloud service providers such as AWS and GCP.</li>\n<li>Developing and maintaining technical documentation such as cookbooks, design and architecture docs.</li>\n<li>Troubleshooting and fixing production issues to ensure reliability, security and performance.</li>\n<li>Work experience in using RDBMS like MySQL, good grasp of concepts such as replication and clustering along with familiarity in data stores such as Redis and Elasticsearch.</li>\n<li>Excellent grasp of software engineering principles coupled with strong written and verbal communication skills.</li>\n<li>B.S or M.S in Computer Science or related fields.</li>\n</ul>\n<p>The Okta Experience ------------------ Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1bb68827-243","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/6687504","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Java","Software Systems Design","Security Solutions","OWASP Top 10 Attacks","Application Security","Cryptography","Authentication","Authorization","Test-Driven Development","Secure SDLC","Secure Code Reviews","Cloud Service Providers","AWS","GCP","Technical Documentation","RDBMS","MySQL","Redis","Elasticsearch"],"x-skills-preferred":["Agile Practices","Mentoring","Communication Skills"],"datePosted":"2026-04-18T15:46:50.924Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Bengaluru, India"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Java, Software Systems Design, Security Solutions, OWASP Top 10 Attacks, Application Security, Cryptography, Authentication, Authorization, Test-Driven Development, Secure SDLC, Secure Code Reviews, Cloud Service Providers, AWS, GCP, Technical Documentation, RDBMS, MySQL, Redis, Elasticsearch, Agile Practices, Mentoring, Communication Skills"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ace25108-b9c"},"title":"Staff Product Security Engineer","description":"<p>We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. As a Staff Product Security Engineer, you will be responsible for the end-to-end security of our consumer products, digital platform, and emerging hardware device line.</p>\n<p>Your day-to-day will involve leading security architecture/design review and threat modeling sessions with product and engineering teams, translating threats into actionable, risk-rated engineering remediations prioritized by severity, conducting hands-on penetration testing and security assessments across our full product stack, and driving PSIRT operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers, and on-call incidents.</p>\n<p>You will also shape the posture of our AI-assisted development environment, defining and enforcing enterprise policies for Claude and Cursor, and partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers, and collaborating with the AI team on securing ML pipelines.</p>\n<p>As a champion of security culture, you will run developer training on secure coding with AI assistants, evangelize security by design for products, and ensure every engineer understands that product security is an enabler and not a gate.</p>\n<p>You will bring 10+ years of product security experience spanning application security, cloud security, and secure SDLC, expert-level threat modeling using STRIDE, PASTA, or equivalent across web, mobile, cloud, embedded, and AI systems, hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware, and deep hands-down AI security expertise and expert-level understanding of OWASP Top 10 for LLM, API, Web, Mobile, and practical experience with MITRE.</p>\n<p>You will have strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor, and understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development.</p>\n<p>You will also have strong programming ability and capability to review code, build security tools, automate workflows, and be credible with the engineering teams you partner with.</p>\n<p>Preferred experience includes hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience, and experience in the Financial industry, knowledge of PCI DSS, COPPA, or demonstrated ability to learn regulated domains quickly.</p>\n<p>Work perks at Greenlight include medical, dental, vision, and HSA match, paid life insurance, AD&amp;D, and disability benefits, traditional 401k with company match, unlimited PTO, paid company holidays and pop-up bonus holidays, professional development stipends, mental health resources, 1:1 financial planners, fertility healthcare, 100% paid parental and caregiving leave, plus cleaning service and meals during your leave, flexible WFH, both remote and in-office opportunities, fully stocked kitchen, catered lunches, and occasional in-office happy hours, and employee resource groups.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ace25108-b9c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Greenlight","sameAs":"https://www.greenlight.com/","logo":"https://logos.yubhub.co/greenlight.com.png"},"x-apply-url":"https://jobs.lever.co/greenlight/18b7ac30-dbf6-4078-bf50-06772c47fdc7","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$165,000-200,000","x-skills-required":["product security","application security","cloud security","secure SDLC","threat modeling","penetration testing","security assessments","PSIRT operations","AI security","OWASP Top 10","MITRE","SAST","DAST","SCA","Claude","Cursor","MCP security","firmware integrity","hardware root of trust","IoT threat modeling"],"x-skills-preferred":["hardware and embedded security","PCI DSS","COPPA"],"datePosted":"2026-04-17T12:35:45.706Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Atlanta"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"product security, application security, cloud security, secure SDLC, threat modeling, penetration testing, security assessments, PSIRT operations, AI security, OWASP Top 10, MITRE, SAST, DAST, SCA, Claude, Cursor, MCP security, firmware integrity, hardware root of trust, IoT threat modeling, hardware and embedded security, PCI DSS, COPPA","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":165000,"maxValue":200000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_76d0b73d-4cb"},"title":"Solutions Engineer, Security Specialist","description":"<p><strong>Solutions Engineer, Security Specialist</strong></p>\n<p><strong>Location</strong></p>\n<p>Tokyo, Japan</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p><strong><strong>About the Team</strong></strong></p>\n<p>The Technical Success team is responsible for ensuring the safe and effective deployment of ChatGPT and OpenAI API applications for developers and enterprises, acting as a trusted advisor so customers maximize value from our models and products.</p>\n<p>As OpenAI’s enterprise footprint grows—especially across regulated industries—security and compliance diligence is increasingly happening live with CISOs, risk teams, privacy officers, and auditors.</p>\n<p><strong><strong>About the Role</strong></strong></p>\n<p>We are hiring a <strong>Security Solutions Engineer</strong> to serve as the <strong>customer-facing security and compliance pre-sales subject matter expert</strong> for priority customer accounts—especially in regulated industries. You will lead security deep dives, diligence workflows, and questionnaires, and help customers understand OpenAI’s security posture, controls, and architectural patterns.</p>\n<p>This role is designed to <strong>increase deal velocity and customer confidence</strong> while reducing the operational load on internal security teams by owning the customer-facing workstream and escalating selectively.</p>\n<p><strong><strong>In this role, you will</strong></strong></p>\n<ul>\n<li><strong>Lead customer security engagements end-to-end</strong>: discovery, security deep dives, live calls, follow-ups, and action tracking—especially for regulated customers.</li>\n</ul>\n<ul>\n<li><strong>Own security questionnaires/RFIs</strong> for priority customers: coordinate inputs, ensure accuracy, drive turnaround time, and manage escalations.</li>\n</ul>\n<ul>\n<li><strong>Translate security posture into customer-relevant narratives</strong>: data flows, tenant boundaries, identity and access controls, encryption, logging/monitoring, incident response, privacy controls, and risk mitigations.</li>\n</ul>\n<ul>\n<li><strong>Guide customers to standardized resources</strong> (e.g., trust collateral) and explain what is standard vs. what requires escalation or exceptions.</li>\n</ul>\n<ul>\n<li><strong>Partner closely with GRC and Security teams</strong> to escalate non-standard requirements, clarify control intent, and ensure customer-facing responses remain aligned with approved posture.</li>\n</ul>\n<ul>\n<li><strong>Create scalable enablement</strong>: playbooks, FAQs, response libraries, and training that reduce repeated work for Solutions Engineers and Sales.</li>\n</ul>\n<ul>\n<li><strong>Represent the voice of regulated customers internally</strong> by identifying themes and recurring blockers; propose improvements to packaging, documentation, and product readiness.</li>\n</ul>\n<p><strong><strong>You’ll thrive in this role if you</strong></strong></p>\n<ul>\n<li>Have <strong>5+ years (guideline)</strong> in a customer-facing security role such as security pre-sales/solutions engineering, security consulting, security architecture, or GRC-adjacent customer advisory in B2B SaaS or cloud environments.</li>\n</ul>\n<ul>\n<li>Can credibly engage and influence <strong>CISOs, security architects, privacy teams, and procurement/risk stakeholders</strong> in real-time discussions.</li>\n</ul>\n<ul>\n<li>Understand modern cloud/security fundamentals: IAM, network/security architecture, encryption/key management concepts, logging/monitoring, vulnerability management, incident response, and secure SDLC.</li>\n</ul>\n<ul>\n<li>Are strong in structured writing and can produce crisp, consistent answers under time pressure (questionnaires, RFIs, executive summaries).</li>\n</ul>\n<ul>\n<li>Can operate in ambiguity, own problems end-to-end, and create repeatable processes that scale beyond yourself.</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_76d0b73d-4cb","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/79f7dfb2-3dff-4411-afb2-f0aacb1fa641","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["security pre-sales/solutions engineering","security consulting","security architecture","GRC-adjacent customer advisory","B2B SaaS","cloud environments","IAM","network/security architecture","encryption/key management concepts","logging/monitoring","vulnerability management","incident response","secure SDLC"],"x-skills-preferred":[],"datePosted":"2026-03-06T18:41:37.318Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Tokyo, Japan"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"security pre-sales/solutions engineering, security consulting, security architecture, GRC-adjacent customer advisory, B2B SaaS, cloud environments, IAM, network/security architecture, encryption/key management concepts, logging/monitoring, vulnerability management, incident response, secure SDLC"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_7670f72a-ca5"},"title":"Security Solutions Engineer, Pre-Sales (Security Specialist) - APAC","description":"<p><strong>About the Team</strong></p>\n<p>The Technical Success team is responsible for ensuring the safe and effective deployment of ChatGPT and OpenAI API applications for developers and enterprises, acting as a trusted advisor so customers maximize value from our models and products.</p>\n<p>As OpenAI’s enterprise footprint grows—especially across regulated industries—security and compliance diligence is increasingly happening live with CISOs, risk teams, privacy officers, and auditors.</p>\n<p><strong>About the Role</strong></p>\n<p>We are hiring a <strong>Security Solutions Engineer</strong> to serve as the <strong>customer-facing security and compliance pre-sales subject matter expert</strong> for priority customer accounts—especially in regulated industries. You will lead security deep dives, diligence workflows, and questionnaires, and help customers understand OpenAI’s security posture, controls, and architectural patterns.</p>\n<p>This role is designed to <strong>increase deal velocity and customer confidence</strong> while reducing the operational load on internal security teams by owning the customer-facing workstream and escalating selectively.</p>\n<p>This role is based in Singapore. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will</strong></p>\n<ul>\n<li><strong>Lead customer security engagements end-to-end</strong>: discovery, security deep dives, live calls, follow-ups, and action tracking—especially for regulated customers.</li>\n</ul>\n<ul>\n<li><strong>Own security questionnaires/RFIs</strong> for priority customers: coordinate inputs, ensure accuracy, drive turnaround time, and manage escalations.</li>\n</ul>\n<ul>\n<li><strong>Translate security posture into customer-relevant narratives</strong>: data flows, tenant boundaries, identity and access controls, encryption, logging/monitoring, incident response, privacy controls, and risk mitigations.</li>\n</ul>\n<ul>\n<li><strong>Guide customers to standardized resources</strong> (e.g., trust collateral) and explain what is standard vs. what requires escalation or exceptions.</li>\n</ul>\n<ul>\n<li><strong>Partner closely with GRC and Security teams</strong> to escalate non-standard requirements, clarify control intent, and ensure customer-facing responses remain aligned with approved posture.</li>\n</ul>\n<ul>\n<li><strong>Create scalable enablement</strong>: playbooks, FAQs, response libraries, and training that reduce repeated work for Solutions Engineers and Sales.</li>\n</ul>\n<ul>\n<li><strong>Represent the voice of regulated customers internally</strong> by identifying themes and recurring blockers; propose improvements to packaging, documentation, and product readiness.</li>\n</ul>\n<p><strong>You’ll thrive in this role if you</strong></p>\n<ul>\n<li>Have <strong>5+ years (guideline)</strong> in a customer-facing security role such as security pre-sales/solutions engineering, security consulting, security architecture, or GRC-adjacent customer advisory in B2B SaaS or cloud environments.</li>\n</ul>\n<ul>\n<li>Can credibly engage and influence <strong>CISOs, security architects, privacy teams, and procurement/risk stakeholders</strong> in real-time discussions.</li>\n</ul>\n<ul>\n<li>Understand modern cloud/security fundamentals: IAM, network/security architecture, encryption/key management concepts, logging/monitoring, vulnerability management, incident response, and secure SDLC.</li>\n</ul>\n<ul>\n<li>Are strong in structured writing and can produce crisp, consistent answers under time pressure (questionnaires, RFIs, executive summaries).</li>\n</ul>\n<ul>\n<li>Can operate in ambiguity, own problems end-to-end, and create repeatable processes that scale beyond yourself.</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_7670f72a-ca5","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/215b02db-1cbf-4f97-8866-7a460ddf7b35","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["security pre-sales/solutions engineering","security consulting","security architecture","GRC-adjacent customer advisory","B2B SaaS","cloud environments","IAM","network/security architecture","encryption/key management concepts","logging/monitoring","vulnerability management","incident response","secure SDLC"],"x-skills-preferred":[],"datePosted":"2026-03-06T18:37:25.183Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Singapore"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"security pre-sales/solutions engineering, security consulting, security architecture, GRC-adjacent customer advisory, B2B SaaS, cloud environments, IAM, network/security architecture, encryption/key management concepts, logging/monitoring, vulnerability management, incident response, secure SDLC"}]}