<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>f77c41bb-0ad</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert, you will have direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise.</p>
<p>The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm’s information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</li>
<li>Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).</li>
<li>Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.</li>
<li>Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.</li>
<li>Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.</li>
<li>Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.</li>
<li>Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.</li>
</ul>
<p><strong>Qualifications</strong></p>
<ul>
<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field.</li>
<li>5+ years’ experience working as an Application Security Engineer, Software Engineer, or similar role.</li>
<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.</li>
<li>Experience working with AI models, Agentic frameworks and security risks associated with AI.</li>
<li>Experience in working with global teams, collaborating on code and presentations.</li>
<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>
<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.</li>
<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>
<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.</li>
<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>
<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.</li>
<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>
<li>Familiarity with web application security testing tools and methodologies.</li>
<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>
<li>Knowledge of Linux, OS internals and containers is a plus.</li>
<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Automated security testing, CI/CD pipelines, Security architectures, Secure configuration principles, Cryptography fundamentals, Encryption protocols, SCM &amp; CI/CD technologies, Security scanning, Vulnerability management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets management, Password vault technologies, Secure programming, Infrastructure as Code tools, Web application security testing tools, Methodologies, Security frameworks, Standards, Linux, OS internals, Containers</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>IT Infrastructure</Employername>
      <Employerlogo>https://logos.yubhub.co/mlp.eightfold.ai.png</Employerlogo>
      <Employerdescription>IT Infrastructure is a technology-focused organisation that provides infrastructure services to various businesses.</Employerdescription>
      <Employerwebsite>https://mlp.eightfold.ai</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://mlp.eightfold.ai/careers/job/755955629927</Applyto>
      <Location>Dublin, Ireland</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6a75ea8b-5b4</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies, you will play a key role in building toolsets and processes to drive adoption of secure practices across the enterprise.</p>
<p>The successful candidate will have a proven understanding in enterprise security and AI security and will focus on defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks</li>
<li>Conducting specialized threat modeling, red teaming, and risk assessments for AI/ML models</li>
<li>Leading risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects</li>
<li>Engaging throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards</li>
<li>Evangelizing AppSec and AI security best practices through developer education, training materials, and outreach</li>
</ul>
<p>Qualifications include:</p>
<ul>
<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field</li>
<li>5+ years&#39; experience working as an Application Security Engineer, Software Engineer, or similar role</li>
<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs</li>
<li>Experience working with AI models, Agentic frameworks and security risks associated with AI</li>
<li>Experience in working with global teams, collaborating on code and presentations</li>
</ul>
<p>Preferred qualifications include:</p>
<ul>
<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>
<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols</li>
<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>
<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions</li>
<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>
<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar</li>
<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>
<li>Familiarity with web application security testing tools and methodologies</li>
<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>
<li>Knowledge of Linux, OS internals and containers is a plus</li>
<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous</li>
</ul>
<p>We offer a competitive salary and benefits package, as well as opportunities for professional growth and development.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Developer education, Training materials, Outreach, Common SCM &amp; CI/CD technologies, GitHub, Jenkins, Artifactory, Security Scanning, Vulnerability Management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets Management &amp; Password Vault technologies, Delinea Secret Server, Hashicorp Vault, Secure programming, Python, Java, C++, C#, Infrastructure as Code tools, CloudFormation, Terraform, Ansible, Web application security testing tools, Methodologies, Security frameworks, Standards, ISO 27001, NIST, OWASP, Linux, OS internals, Containers</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>IT Infrastructure</Employername>
      <Employerlogo>https://logos.yubhub.co/mlp.eightfold.ai.png</Employerlogo>
      <Employerdescription>IT Infrastructure is a department within a larger organisation that focuses on providing and maintaining the underlying technology infrastructure.</Employerdescription>
      <Employerwebsite>https://mlp.eightfold.ai</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://mlp.eightfold.ai/careers/job/755955629908</Applyto>
      <Location>London, United Kingdom</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>b687767a-7a1</externalid>
      <Title>Director of Engineering, Security Risk Management</Title>
      <Description><![CDATA[<p>We&#39;re seeking an exceptional Engineering Lead to drive the evolution of GitLab&#39;s Security Risk Management (SRM) stage into a world-class platform for vulnerability analysis and remediation at enterprise scale.</p>
<p>This is a rare opportunity to architect and build distributed systems that will fundamentally change how large organisations approach application security and developer security workflows.</p>
<p>As the SRM Stage Lead, you&#39;ll be responsible for transforming our engineering culture toward high-performance distributed systems while delivering an exceptional user experience for both Application Security professionals and Developers.</p>
<p>You&#39;ll own the technical strategy for processing, analysing, and remediating vulnerabilities across massive codebases and complex enterprise environments.</p>
<p><strong>Technical Leadership &amp; Architecture</strong></p>
<ul>
<li>Design distributed systems architecture capable of processing vulnerability data from thousands of repositories, millions of commits, and complex dependency graphs in real-time</li>
<li>Drive storage system decisions for multi-petabyte security datasets, balancing query performance, cost efficiency, and data retention requirements across time-series, graph, and document storage paradigms</li>
<li>Architect scalable analysis pipelines that can ingest vulnerability feeds, correlate findings across multiple security tools, and provide actionable intelligence to both security teams and individual developers</li>
<li>Lead the technical evolution from monolithic security scanning to microservices-based, event-driven vulnerability management systems</li>
</ul>
<p><strong>Engineering Culture Transformation</strong></p>
<ul>
<li>Champion high-performance systems thinking throughout the team, establishing patterns for horizontal scaling, efficient resource utilisation, and fault-tolerant distributed computing</li>
<li>Establish technical standards for system observability, chaos engineering, and performance optimisation in security-critical systems</li>
<li>Mentor and develop senior engineers in distributed systems design, database optimisation, and large-scale system architecture</li>
<li>Drive architectural decision records (ADRs) for major technical decisions, particularly around data storage, processing frameworks, and system boundaries</li>
</ul>
<p><strong>Product &amp; User Experience Excellence</strong></p>
<ul>
<li>Own the end-to-end user journey (in partnership with PM) for both AppSec professionals managing enterprise-wide risk and developers receiving actionable security feedback in their workflow</li>
<li>Design APIs and interfaces that abstract complexity while providing the power and flexibility that security professionals demand</li>
<li>Collaborate with Product Management, UX and Product Design to translate complex technical capabilities into intuitive user experiences</li>
<li>Establish feedback loops with large enterprise customers to ensure our technical solutions scale with their organisational complexity</li>
</ul>
<p><strong>Strategic Technical Execution</strong></p>
<ul>
<li>Evaluate and integrate cutting-edge technologies in areas such as graph databases, stream processing, machine learning inference at scale, and distributed caching, in collaboration with GitLab’s Infrastructure, Data and AI teams</li>
<li>Own the technical roadmap for vulnerability correlation, risk scoring, and automated remediation workflows</li>
<li>Drive partnerships with other GitLab stages to ensure seamless integration across the DevSecOps platform</li>
<li>Lead incident response for availability and performance issues in customer-facing security systems</li>
</ul>
<p><strong>What You’ll Bring</strong></p>
<ul>
<li>10+ years of software engineering experience with 5+ years leading distributed systems at scale (&gt;100M daily operations)</li>
<li>Deep expertise in designing and operating high-throughput, low-latency distributed systems with complex data models</li>
<li>Proven experience with polyglot persistence strategies, including relational databases (PostgreSQL, Cloud Spanner), time-series databases, graph databases, and distributed key-value stores</li>
<li>Strong background in stream processing frameworks (Apache Kafka, Apache Flink, or similar) and event-driven architectures</li>
<li>Hands-on experience with container orchestration (Kubernetes) and cloud-native observability stacks</li>
<li>Security domain knowledge with understanding of vulnerability assessment, static analysis, dependency scanning, or application security testing</li>
</ul>
<p><strong>Leadership &amp; Communication</strong></p>
<ul>
<li>Proven track record of leading and growing high-performing engineering teams (40+ engineers)</li>
<li>Experience transforming engineering culture and establishing technical excellence standards in fast-growing organisations</li>
<li>Strong technical communication skills with ability to present complex architectural decisions to executive stakeholders</li>
<li>Collaborative leadership style with experience working across multiple engineering teams and product stakeholders</li>
</ul>
<p><strong>Problem-Solving &amp; Innovation</strong></p>
<ul>
<li>Systems thinking approach to complex technical problems with demonstrated ability to make appropriate trade-offs between performance, scalability, and maintainability</li>
<li>Experience with A/B testing frameworks and data-driven decision making in technical contexts</li>
<li>Track record of successfully delivering large-scale technical migrations or architectural transformations</li>
<li>Startup or high-growth company experience with ability to balance technical debt with rapid feature delivery</li>
</ul>
<p><strong>About the team</strong></p>
<p>Security Risk Management sits at the heart of modern DevSecOps. The systems you build will directly impact how Fortune 500 companies protect their applications and how millions of developers integrate security into their daily workflow.</p>
<p>You&#39;ll have the opportunity to define the future of application security tooling while working with some of the most challenging distributed systems problems in the industry.</p>
<p>The Technical Challenge</p>
<p>You&#39;ll be solving some of the most interesting distributed systems problems in the security space:</p>
<ul>
<li>Scale: Processing vulnerability data for organisations with 100,000+ repositories and millions of developers</li>
<li>Performance: Sub-second query response times for complex security analytics across massive datasets</li>
<li>Reliability: 99.95%+ uptime SLAs for security-critical workflows that can&#39;t afford downtime</li>
<li>Complexity: Correlating findings across 20+ different security tools while maintaining data lineage and audit trails</li>
<li>User Experience: Making complex security data accessible to both security experts and developers with varying security expertise</li>
</ul>
<p><strong>Salary</strong></p>
<p>The base salary range for this role’s listed level is currently for residents of the United States.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>executive</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>Base salary range for this role’s listed level is currently for residents of the United States.</Salaryrange>
      <Skills>Distributed systems, Polyglot persistence strategies, Stream processing frameworks, Event-driven architectures, Container orchestration, Cloud-native observability stacks, Security domain knowledge, Vulnerability assessment, Static analysis, Dependency scanning, Application security testing</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>GitLab</Employername>
      <Employerlogo>https://logos.yubhub.co/about.gitlab.com.png</Employerlogo>
      <Employerdescription>GitLab is anデvelopment platform for DevSecOps, trusted by over 50 million registered users and more than 50% of the Fortune 100.</Employerdescription>
      <Employerwebsite>https://about.gitlab.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/gitlab/jobs/8195921002</Applyto>
      <Location>Remote, Canada; Remote, EMEA; Remote, US</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>f3f72cf8-865</externalid>
      <Title>Security Engineer, Offensive Security</Title>
      <Description><![CDATA[<p>We are seeking a highly skilled Security Engineer, Offensive Security to join our team. As a member of our Security Engineering team, you will play a key role in safeguarding our AI systems and maintaining the trust of our users and society at large.</p>
<p>Key Responsibilities: Conduct red and purple team engagements simulating advanced threat actors across our cloud infrastructure, endpoints, and bare metal deployments. Penetration test specific, high-value deployments. Contribute to AI-assisted security testing tooling and workflows. Work cross-functionally with other security and engineering teams, particularly on AI-specific attack scenarios. Document and present findings to technical and executive audiences, translating attack narratives into actionable risk insights that inform security roadmaps.</p>
<p>Requirements: 5+ years of hands-on experience in red teaming and offensive security operations. Deep expertise in at least two of: macOS security, Linux Security, Cloud security (GCP/AWS/Azure), Kubernetes, CI/CD pipelines. Track record of discovering novel attack vectors and chaining vulnerabilities creatively. Experience conducting adversarial simulations against well-defended environments. Strong engineering skills (Python, Go, or similar). Ability to write clear findings that drive action, helping teams understand risk and prioritize fixes. Collaborative approach, working in close collaboration with the blue team.</p>
<p>Preferred Qualifications: Prior work at organizations with state actor threat models. Interest in AI safety and how security engineering contributes to responsible AI developments. Background testing AI/ML systems or agentic workflows. Familiarity with detection engineering and SIEM/EDR platforms from the defensive side. Experience with data center security or hardware-based attacks.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$300,000-$320,000 USD</Salaryrange>
      <Skills>macOS security, Linux Security, Cloud security (GCP/AWS/Azure), Kubernetes, CI/CD pipelines, Python, Go, AI-assisted security testing tooling, Detection engineering, SIEM/EDR platforms, Data center security, Hardware-based attacks</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a technology company that aims to create reliable, interpretable, and steerable AI systems.</Employerdescription>
      <Employerwebsite>https://www.anthropic.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/5105509008</Applyto>
      <Location>Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>5ca1d076-26a</externalid>
      <Title>Information Systems Security Manager</Title>
      <Description><![CDATA[<p>Job Title: Information Systems Security Manager</p>
<p>About the Team: Anduril employs a variety of networks and networking infrastructures to support global operations. Information Systems Security Managers are in charge of directly supporting business lines that wish to deploy Anduril products in classified environments.</p>
<p>About the Job: As an Information Systems Security Manager, you will be responsible for providing expertise in documenting security controls to reduce the administrative cost of deploying Anduril&#39;s products into operational environments. You will partner with program and security teams to coordinate security artifacts in support of classified deployments. You will apply technology standards from the commercial space in classified, air-gapped environments.</p>
<p>Responsibilities:</p>
<ul>
<li>Provide expertise in documenting security controls to reduce the administrative cost of deploying Anduril&#39;s products into operational environments.</li>
<li>Partner with program and security teams to coordinate security artifacts in support of classified deployments.</li>
<li>Apply technology standards from the commercial space in classified, air-gapped environments.</li>
<li>Collaborate with Information System Owners to understand key stakeholders&#39; needs and provide complex technical solutions to meet contractual obligations.</li>
<li>Tailor NIST 800-53 controls to determine applicability to the network environment and oversee the implementation of Continuous Monitoring for respective programs.</li>
<li>Define, document, and conduct security scanning on Anduril&#39;s products and accredited information systems.</li>
<li>Scope, shape, and orchestrate the development of features to ensure products meet compliance goals.</li>
</ul>
<p>Required Qualifications:</p>
<ul>
<li>Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards.</li>
<li>Integrate security best practices into Anduril&#39;s Software Development Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams.</li>
<li>Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats.</li>
<li>Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and secure communications technologies.</li>
<li>Develop and enforce access controls, encryption strategies, and other technical measures to safeguard systems.</li>
<li>Maintain and update System Security Plans (SSPs), POA&amp;Ms, and other accreditation documentation.</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience with application security paradigms such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).</li>
<li>Proven experience in securing micro-services architecture, including implementing best practices and compliance with DoD cybersecurity standards.</li>
<li>Experience with cybersecurity in unmanned and ground control system within DoD environments.</li>
<li>Experience with containerization and kubernetes along with the best practices for securing them.</li>
<li>Experience with Cloud Service Providers (CSPs) and the various tools they offer for implementing security and compliance best practices.</li>
</ul>
<p>Salary: The salary range for this role is $146,000-$194,000 USD.</p>
<p>Benefits: Anduril offers top-tier benefits for full-time employees, including comprehensive medical, dental, and vision plans at little to no cost to you. Anduril also offers income protection, generous time off, family planning and parenting support, mental health resources, professional development, commuter benefits, relocation assistance, and a retirement savings plan.</p>
<p>Protecting Yourself from Recruitment Scams: Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We&#39;ve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.</p>
<p>To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:</p>
<ul>
<li>No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.</li>
<li>Please always verify communications:</li>
<li>Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.</li>
<li>Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency&#39;s authenticity by reaching out to contact@anduril.com.</li>
<li>Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not respond or engage with the sender.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$146,000-$194,000 USD</Salaryrange>
      <Skills>Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards, Integrate security best practices into Anduril&apos;s Software Development Lifecycle (SDLC) and infrastructure design, collaborating with internal IT and engineering teams, Conduct security risk assessments, vulnerability assessments, and audits to identify and mitigate threats, Recommend and implement security solutions, such as IDS/IPS, encryption protocols, and secure communications technologies, Develop and enforce access controls, encryption strategies, and other technical measures to safeguard systems, Experience with application security paradigms such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA), Proven experience in securing micro-services architecture, including implementing best practices and compliance with DoD cybersecurity standards, Experience with cybersecurity in unmanned and ground control system within DoD environments, Experience with containerization and kubernetes along with the best practices for securing them, Experience with Cloud Service Providers (CSPs) and the various tools they offer for implementing security and compliance best practices</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anduril</Employername>
      <Employerlogo>https://logos.yubhub.co/anduril.com.png</Employerlogo>
      <Employerdescription>Anduril is a technology company that employs a variety of networks and networking infrastructures to support global operations.</Employerdescription>
      <Employerwebsite>https://www.anduril.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/andurilindustries/jobs/4861096007</Applyto>
      <Location>Washington, District of Columbia, United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6d2bed6a-1bd</externalid>
      <Title>Application Security Engineer</Title>
      <Description><![CDATA[<p>We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies.</p>
<p>Responsibilities: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10</p>
<p>Basic Qualifications: Bachelor&#39;s degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences</p>
<p>Preferred Skills and Experience: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Experience with GitOps and infrastructure-as-code security Familiarity with federated learning and privacy-preserving machine learning techniques Experience in building custom security tooling to enhance and automate security processes Interest in leveraging AI to automate security tasks and improve efficiency Contributions to open-source security projects or tools Experience in securing AI/ML models and data pipelines</p>
<p>Compensation and Benefits: $200,000 - $340,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short &amp; long-term disability insurance, life insurance, and various other discounts and perks.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$200,000 - $340,000 USD</Salaryrange>
      <Skills>Python, Rust, Secure coding practices, Application security frameworks, Common vulnerabilities, OWASP Top 10, CI/CD pipelines, DevSecOps practices, Software supply chain security, SBOM generation tools, Security testing tools, Static/dynamic code analysis, AI/ML security implications, OWASP LLM Top 10, Cloud platforms, Security certifications, Data privacy and compliance regulations, GitOps, Infrastructure-as-code security, Federated learning, Privacy-preserving machine learning techniques, Custom security tooling, AI automation, Open-source security projects, AI/ML model security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>xAI</Employername>
      <Employerlogo>https://logos.yubhub.co/xai.com.png</Employerlogo>
      <Employerdescription>xAI creates AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.</Employerdescription>
      <Employerwebsite>https://www.xai.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/xai/jobs/4559147007</Applyto>
      <Location>Palo Alto, CA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>c629a0da-f6c</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re seeking a Security Engineer at the senior-level or above focused on hardware, embedded systems, and firmware security to own the security posture of Saronic&#39;s vessel hardware platforms from silicon to system.</p>
<p>You will be the technical authority on hardware root of trust, secure boot, firmware integrity, embedded system hardening, and the security of third-party hardware integrations. Your work ensures that every component on the vessel is resilient against tampering, exploitation, and supply chain compromise, designed in from the start and maintained across the fleet lifecycle.</p>
<p>Key Responsibilities:</p>
<ul>
<li><p>Conduct hardware security assessments including fault injection, side-channel analysis, interface evaluation, and bus protocol analysis across Saronic-built and third-party hardware including sensors, radios, navigation systems, propulsion controllers, and communication modules</p>
</li>
<li><p>Evaluate and harden physical interfaces, debug ports, maintenance access points, and removable media interfaces on vessel hardware</p>
</li>
<li><p>Evaluate supply chain security risks for hardware components and recommend provenance validation, anti-tamper, and attestation controls</p>
</li>
<li><p>Develop and maintain a hardware security testing capability including tooling, methodology, and repeatable test procedures</p>
</li>
<li><p>Design and implement secure boot chains establishing hardware root of trust from power-on through application launch, integrating TPM, secure elements, and HSMs for device identity, key storage, measured boot, and remote attestation</p>
</li>
<li><p>Design and implement secure firmware update mechanisms including signed updates, rollback protection, and verified delivery across the fleet</p>
</li>
<li><p>Own the cryptographic key lifecycle for hardware-bound keys, including provisioning, rotation, revocation, and escrow</p>
</li>
<li><p>Harden embedded Linux systems on vessel platforms, including kernel configuration, mandatory access controls, secure IPC, and attack surface reduction</p>
</li>
<li><p>Secure operational technology protocols and interfaces used in vessel control systems, propulsion, navigation, and sensor fusion including CAN bus, NMEA, and maritime/industrial communication protocols</p>
</li>
<li><p>Define security boundaries, trust zones, and segmentation strategies for vessel-internal compute and communication architectures</p>
</li>
<li><p>Drive threat modeling across vessel hardware subsystems and translate findings into actionable engineering requirements</p>
</li>
<li><p>Produce secure-by-design reference architectures and define hardware and firmware security standards, testing requirements, and acceptance criteria integrated into engineering workflows</p>
</li>
</ul>
<p>Required Qualifications:</p>
<ul>
<li><p>6+ years of hands-on experience in hardware security, embedded systems security, firmware security, or a closely related security engineering role</p>
</li>
<li><p>Deep expertise in hardware hacking techniques including fault injection, side-channel attacks, JTAG/SWD exploitation, bus sniffing/injection, and physical security assessments</p>
</li>
<li><p>Demonstrated experience designing and implementing secure boot chains, hardware root of trust, and secure firmware update mechanisms in production systems</p>
</li>
<li><p>Strong experience assessing third-party hardware integrations and evaluating supply chain security risks</p>
</li>
<li><p>Deep knowledge of embedded Linux security hardening, kernel security, and mandatory access control frameworks</p>
</li>
<li><p>Experience with operational technology security, industrial protocols, or control system security</p>
</li>
<li><p>Proficiency in C, C++, Python, or Rust in the context of firmware, embedded, or systems-level security work, and with hardware security testing tools</p>
</li>
<li><p>Ability to obtain and maintain a security clearance</p>
</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li><p>Experience in defense, aerospace, robotics, autonomy, maritime, or other high-assurance environments</p>
</li>
<li><p>Experience with autonomous systems, unmanned vehicles, or safety-critical embedded platforms</p>
</li>
<li><p>Experience with RTOS, microcontroller security, or resource-constrained device environments</p>
</li>
<li><p>Knowledge of CAN bus, NMEA protocols, maritime communication systems, RF/GPS/GNSS security, or ICS security standards</p>
</li>
<li><p>Familiarity with defense or safety-critical compliance frameworks (NIST SP 800-53, IEC 62443, Common Criteria, or equivalent)</p>
</li>
<li><p>Relevant certifications such as OSEE, GXPN, GSE, or hardware-focused credentials</p>
</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Hardware security, Embedded systems security, Firmware security, Fault injection, Side-channel analysis, Interface evaluation, Bus protocol analysis, Physical security assessments, Secure boot chains, Hardware root of trust, Firmware integrity, Embedded system hardening, Third-party hardware integrations, Supply chain security risks, Provenance validation, Anti-tamper, Attestation controls, Hardware security testing, Tooling, Methodology, Repeatable test procedures, Device identity, Key storage, Measured boot, Remote attestation, Signed updates, Rollback protection, Verified delivery, Cryptographic key lifecycle, Provisioning, Rotation, Revocation, Escrow, Embedded Linux systems, Kernel configuration, Mandatory access controls, Secure IPC, Attack surface reduction, Operational technology protocols, Industrial protocols, Control system security, CAN bus, NMEA, Maritime/industrial communication protocols, Security boundaries, Trust zones, Segmentation strategies, Threat modeling, Actionable engineering requirements, Secure-by-design reference architectures, Hardware and firmware security standards, Testing requirements, Acceptance criteria, Engineering workflows, C, C++, Python, Rust, Hardware security testing tools, Defense, Aerospace, Robotics, Autonomy, Maritime, High-assurance environments, Autonomous systems, Unmanned vehicles, Safety-critical embedded platforms, RTOS, Microcontroller security, Resource-constrained device environments, NMEA protocols, Maritime communication systems, RF/GPS/GNSS security, ICS security standards, Defense or safety-critical compliance frameworks, OSEE, GXPN, GSE, Hardware-focused credentials</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Saronic Technologies</Employername>
      <Employerlogo>https://logos.yubhub.co/saronictechnologies.com.png</Employerlogo>
      <Employerdescription>Saronic Technologies is a leader in revolutionizing defense autonomy at sea, dedicated to developing state-of-the-art solutions that enhance maritime operations for the Department of Defense (DoD) through autonomous and intelligent platforms.</Employerdescription>
      <Employerwebsite>https://www.saronictechnologies.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/saronic/4b15b1b4-3c34-47ad-b964-dbcf0f8a3dc4</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>b1f3d4c9-57d</externalid>
      <Title>Internship DevSecOps – master level</Title>
      <Description><![CDATA[<p>Our internship programs offer real-world projects, hands-on experience, and opportunities to collaborate with passionate teams globally. Explore your interests, share your ideas, and bring them to life while shaping your career path within our inclusive culture that fosters innovation and collaboration.</p>
<p>At Synopsys, interns dive into real-world projects, gaining hands-on experience while collaborating with our passionate teams worldwide,and having fun in the process! You&#39;ll have the freedom to share your ideas, unleash your creativity, and explore your interests. This is your opportunity to bring your solutions to life and work with cutting-edge technology that shapes not only the future of innovation but also your own career path.</p>
<p><strong>Deploy and configure security tools for Software Composition Analysis (SCA), Static Application Security Testing (SAST), and Dynamic Application Security Testing (DAST), including project onboarding, configuration, and policy management.</strong></p>
<p><strong>Integrate security controls into CI/CD pipelines, such as quality gates, reporting mechanisms, and threshold management, to ensure early vulnerability detection.</strong></p>
<p><strong>Automate the collection, normalization, and publication of security results using dashboards, artifacts, and notifications.</strong></p>
<p><strong>Implement and manage dependency updates with tools like Dependabot and Renovate, including automated pull requests and update strategies.</strong></p>
<p><strong>Contribute to documentation (integration guides, best practices) while collaborating with development and infrastructure teams to improve the developer experience.</strong></p>
<p><strong>Participate in the analysis, prioritization, and tracking of security findings and remediation efforts.</strong></p>
<p>Currently pursuing a Master’s degree or equivalent in cybersecurity, software engineering, DevOps/Cloud, or a related field.</p>
<p>Comfortable working in both Windows and Linux environments.</p>
<p>Understanding of CI/CD concepts and a keen interest in DevSecOps practices.</p>
<p>Experience with programming/scripting languages such as Python, Bash, Go, or Rust is a plus.</p>
<p>Familiarity with build and tooling systems (e.g., Bazel, Docker) and SDLC tools (e.g., Mend, Dependabot, Renovate).</p>
<p>Autonomy, attention to detail, strong problem-solving skills, and effective communication for collaboration within multidisciplinary teams.</p>
<p>Fluent/Professional English</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>internship</Jobtype>
      <Experiencelevel>entry</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Software Composition Analysis (SCA), Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), CI/CD pipelines, DevSecOps practices, Python, Bash, Go, Rust, Bazel, Docker, Mend, Dependabot, Renovate</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Synopsys</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.synopsys.com.png</Employerlogo>
      <Employerdescription>Synopsys is a leading provider of electronic design automation (EDA) software and services, delivering design solutions to companies across various industries.</Employerdescription>
      <Employerwebsite>https://careers.synopsys.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://careers.synopsys.com/job/villeurbanne/internship-devsecops-master-level/44408/93253148208</Applyto>
      <Location>Villeurbanne</Location>
      <Country></Country>
      <Postedate>2026-04-05</Postedate>
    </job>
    <job>
      <externalid>a6a63728-1cf</externalid>
      <Title>Senior Penetration Tester</Title>
      <Description><![CDATA[<p>We&#39;re seeking a Senior Penetration Tester to join our established team, working with talented cyber security professionals to ensure our services are designed, developed, and operated securely. As an internal tester, you&#39;ll gain a strong understanding of how technology works at Starling to enable in-depth testing. You&#39;ll also support remediation processes, seeing your findings lead to tangible security improvements.</p>
<p>Responsibilities:
Scoping and performing mobile, web application, cloud, and infrastructure penetration tests.
Collaborating with engineering teams to facilitate secure development, including reviewing and analysing proposed technical solutions to identify appropriate security controls, conducting code reviews of features and critical security components, and performing in-depth practical security testing.
Advising on the remediation of security issues and identifying solutions to address root causes.
Automating security testing and developing internal tooling to achieve continuous assurance.
Identifying and implementing improvements to the team&#39;s internal processes and procedures.
Mentoring less-experienced team members, leading by example in technical assessments, and promoting a collaborative approach to security across Starling.</p>
<p>Requirements:
5+ years technical information security experience.
Experience in mobile, web application, cloud, and infrastructure penetration testing.
Technical knowledge in mobile security (iOS and Android), web application security, networking and associated protocols, cloud security (AWS and GCP), containers and Kubernetes.
Penetration testing qualifications (e.g. CREST Certified Tester, OSCP) or equivalent industry experience.
Excellent verbal and written communication skills.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>penetration testing, mobile security, web application security, cloud security, networking, containers and Kubernetes, security testing, code review, automation, Java, Go, Python, CREST Certified Tester, OSCP</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Starling</Employername>
      <Employerlogo>https://logos.yubhub.co/starlingbank.com.png</Employerlogo>
      <Employerdescription>Starling is a digital bank that provides financial services to customers. It has over 3,000 employees across its offices in London, Southampton, Cardiff, and Manchester.</Employerdescription>
      <Employerwebsite>https://www.starlingbank.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/4F1A58C8DC</Applyto>
      <Location>Southampton</Location>
      <Country></Country>
      <Postedate>2026-03-31</Postedate>
    </job>
    <job>
      <externalid>85fab307-8f1</externalid>
      <Title>自动化测试工程师</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>We are seeking an automation testing engineer to join our team in Shenzhen, China. As an automation testing engineer, you will be responsible for testing software products, including web and mobile applications, to ensure they meet high quality standards.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Test software products, including web and mobile applications, to ensure they meet high quality standards.</li>
<li>Write and execute automation testing scripts to improve testing efficiency and coverage.</li>
<li>Use Postman, RestAssured, or other tools to validate APIs.</li>
<li>Use JIRA or similar tools to record and track defects.</li>
<li>Design and execute test cases, test scenarios, and regression tests.</li>
<li>Collaborate with development teams, product managers, and designers to ensure software quality.</li>
<li>Perform performance and security testing as needed.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Have experience in manual and automation testing.</li>
<li>Familiar with testing methods, test case design, and defect tracking.</li>
<li>Have experience in testing web and mobile applications.</li>
<li>Familiar with automation testing tools such as Selenium, Cypress, or Appium.</li>
<li>Familiar with API testing using Postman, RestAssured, or other tools.</li>
<li>Understand CI/CD processes and can integrate testing into development workflows.</li>
<li>Have good English communication skills (written and spoken).</li>
<li>Currently reside in Shenzhen or surrounding areas and can travel to Hong Kong as needed.</li>
</ul>
<p><strong>Preferred Skills</strong></p>
<ul>
<li>Have experience in performance testing and security testing.</li>
<li>Familiar with programming languages such as Python, Java, or JavaScript.</li>
<li>Have experience in remote team collaboration and working with cross-time zone teams.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>manual and automation testing, testing methods, test case design, defect tracking, web and mobile applications, Selenium, Cypress, Appium, API testing, Postman, RestAssured, CI/CD processes, English communication skills, performance testing, security testing, Python, Java, JavaScript, remote team collaboration, cross-time zone teams</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Kody</Employername>
      <Employerlogo>https://logos.yubhub.co/view.com.png</Employerlogo>
      <Employerdescription>Kody is a fintech company that develops software solutions for brick and mortar businesses. It has offices in Singapore, London, and Hong Kong.</Employerdescription>
      <Employerwebsite>https://jobs.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.workable.com/view/igYyenDGEVP1RugBVrnPXp/%E8%87%AA%E5%8A%A8%E5%8C%96%E6%B5%8B%E8%AF%95%E5%B7%A5%E7%A8%8B%E5%B8%88---%E6%B7%B1%E5%9C%B3%2C-%E4%B8%AD%E5%9B%BD-in-shenzhen-at-kody</Applyto>
      <Location>深圳</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>0d862e68-88e</externalid>
      <Title>手工测试工程师</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>We are seeking a manual testing engineer to ensure our software products have an excellent user experience and high-quality standards.</p>
<p><strong>Job Summary</strong></p>
<p>As a manual testing engineer, your primary responsibility is to test software new features, including web and mobile application UI interfaces, user flows, and API testing. You will play a key role in discovering defects, optimizing testing processes, and ensuring high-quality delivery.</p>
<p>This role requires working from our Shenzhen office and may involve occasional travel to Hong Kong to collaborate with the team.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li><strong>Manual Testing</strong>: Test web and mobile applications&#39; new features to ensure UI interfaces and user flows meet expectations.</li>
<li><strong>API Testing</strong>: Use Postman, RestAssured, or other tools to validate API functionality.</li>
<li><strong>Defect Tracking &amp; Reporting</strong>: Use JIRA or similar tools to record and track issues.</li>
<li><strong>Testing Planning &amp; Execution</strong>: Design and execute test cases, test scenarios, and regression testing.</li>
<li><strong>Cross-Team Collaboration</strong>: Work closely with developers, product managers, and designers to ensure software quality.</li>
<li><strong>Performance &amp; Security Testing (if required)</strong>: Evaluate application performance, stability, and security.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li><strong>Manual Testing Experience</strong>: Have solid manual testing experience and knowledge of software testing lifecycles and processes.</li>
<li><strong>Test Methodology</strong>: Familiar with test methods, test case design, and defect tracking.</li>
<li><strong>Web &amp; Mobile UI/UX Testing Experience</strong>: Have experience testing web and mobile application UI/UX.</li>
<li><strong>API Testing</strong>: Familiar with API testing and use of Postman, RestAssured, or other tools.</li>
<li><strong>Good English Communication Skills</strong>: Have excellent written and verbal communication skills.</li>
<li><strong>Location</strong>: Reside in Shenzhen or surrounding areas and be able to work from the office, with occasional travel to Hong Kong.</li>
</ul>
<p><strong>Preferred Qualifications</strong></p>
<ul>
<li><strong>Performance Testing &amp; Security Testing Experience</strong>: Have experience in performance testing and security testing.</li>
<li><strong>Programming Skills</strong>: Familiar with Python, Java, or JavaScript programming, which can be used for testing automation.</li>
<li><strong>Automation Testing Tools</strong>: Familiar with Selenium, Cypress, Appium, or other automation testing tools.</li>
<li><strong>CI/CD Process</strong>: Familiar with CI/CD processes and how to integrate testing into continuous delivery systems.</li>
<li><strong>Remote &amp; Cross-Time Zone Team Collaboration</strong>: Have experience working with remote and cross-time zone teams, with excellent asynchronous communication skills.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li><strong>Global Fintech Company</strong>: Work for a global fintech company with offices in Singapore, London, and Hong Kong.</li>
<li><strong>On-Site Work with Flexibility</strong>: Work primarily from the office with some flexibility, and collaborate with the Hong Kong team as needed.</li>
<li><strong>Front-End Projects</strong>: Participate in cutting-edge projects, enhancing your testing and automation skills.</li>
<li><strong>Quality-Driven Culture</strong>: Work in a quality-driven culture where the testing team plays a critical role in the development process.</li>
<li><strong>Competitive Salary &amp; Benefits</strong>: Receive a competitive salary and benefits package, reflecting your contributions.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>manual testing, API testing, test case design, defect tracking, cross-team collaboration, performance testing, security testing, performance testing, security testing, programming, automation testing tools, CI/CD process, remote team collaboration</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Kody</Employername>
      <Employerlogo>https://logos.yubhub.co/view.com.png</Employerlogo>
      <Employerdescription>Kody is a fintech company with offices in Singapore, London, and Hong Kong. It develops high-quality software solutions.</Employerdescription>
      <Employerwebsite>https://jobs.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.workable.com/view/bEPoUi1NgEHKVchLQiKhCk/%E6%89%8B%E5%B7%A5%E6%B5%8B%E8%AF%95%E5%B7%A5%E7%A8%8B%E5%B8%88---%E6%B7%B1%E5%9C%B3%2C-%E4%B8%AD%E5%9B%BD-in-shenzhen-at-kody</Applyto>
      <Location>深圳, 中国</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>1a10d476-cae</externalid>
      <Title>Test Engineer - Platform</Title>
      <Description><![CDATA[<p>We&#39;re looking for an intermediate to senior Test Engineer to join our Platform Team, with a key focus on our platform modernisation and stabilisation initiatives. You&#39;ll predominantly be involved in technical, backend testing, with an approximate 60% manual / 40% automation split. The work is almost entirely focused on backend libraries and services, with no front-end testing involved.</p>
<p>This is an ideal role for an experienced tester with an interest in cloud platform solutions, who is looking to further develop their automation testing experience.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>A variety of backend testing with a focus on containers, deployments, APIs, authentication, access tokens etc...</li>
<li>Functional, non-functional, regression and security testing</li>
<li>Familiar with modern coding standards/practices and DevOps, CI/CD pipelines</li>
<li>Strong knowledge of software QA methodologies, tools, and processes</li>
<li>Experience with testing tools like JMeter, Postman, or other similar tools would be advantageous</li>
<li>Exposure to C# / .Net would be beneficial</li>
<li>Excellent troubleshooting and problem-solving skills, and a proven ability to write clear, concise, and comprehensive test plans and test cases</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Excellent work/life balance, including a 4 ½ day working week</li>
<li>Hybrid working (home and office-based split, requiring regular weekly attendance in the Auckland office)</li>
<li>Medical and Life insurance (after qualifying period)</li>
<li>Volunteer day, enhanced paid parental leave and wellness benefits</li>
<li>Strong mentoring &amp; career development focus</li>
<li>Fun team events including the Vista Innovation Cup</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>backend testing, containers, deployments, APIs, authentication, access tokens, functional testing, non-functional testing, regression testing, security testing, DevOps, CI/CD pipelines, software QA methodologies, testing tools, JMeter, Postman, C#, .Net</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Vista</Employername>
      <Employerlogo>https://logos.yubhub.co/j.com.png</Employerlogo>
      <Employerdescription>Vista makes software for the cinema industry and serves cinemas, film distributors, and moviegoers worldwide.</Employerdescription>
      <Employerwebsite>https://apply.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/94E2692BD4</Applyto>
      <Location>Auckland</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>4f61d7fc-6c1</externalid>
      <Title>Testing Manager</Title>
      <Description><![CDATA[<p><strong>Testing Manager</strong></p>
<p>We are seeking a highly skilled Testing Manager to lead and manage the testing process for IT projects and small changes, ensuring the quality and reliability of software applications and systems.</p>
<p>The Testing Manager plays a critical role in ensuring that software products meet quality standards, adhere to requirements, and deliver a positive user experience.</p>
<p><strong>Key Responsibilities &amp; Accountabilities</strong></p>
<p><strong>Test Planning</strong></p>
<ul>
<li>Develop and implement comprehensive test strategies, plans, and schedules in alignment with project goals and timelines.</li>
</ul>
<p><strong>Test Execution</strong></p>
<ul>
<li>Lead and oversee the testing process, including test case creation, test script development, test environment setup, and test execution.</li>
</ul>
<p><strong>Test Team Management</strong></p>
<ul>
<li>Build and manage a high-performing test team (with contract and perm), including resource allocation, task assignment, performance monitoring, coaching and mentoring.</li>
</ul>
<p><strong>Stakeholder Management</strong></p>
<ul>
<li>Collaborate with project stakeholders, such as project managers, business analysts, and developers, to ensure clear communication, requirements understanding, and timely issue resolution.</li>
</ul>
<p><strong>Test Documentation</strong></p>
<ul>
<li>Create and maintain test artifacts, including test cases, test scripts, test data, and test reports, to ensure proper documentation and traceability of testing activities.</li>
</ul>
<p><strong>Defect Management</strong></p>
<ul>
<li>Establish defect tracking and management processes, including defect identification, prioritisation, and resolution, to ensure timely and effective defect resolution.</li>
</ul>
<p><strong>Test Automation</strong></p>
<ul>
<li>Define and implement test automation frameworks and tools to improve test efficiency, coverage, and reliability.</li>
</ul>
<p><strong>Quality Assurance</strong></p>
<ul>
<li>Ensure quality assurance standards are in place and adherence to quality standards, processes, and best practices is maintained throughout the testing lifecycle across all projects and programmes.</li>
</ul>
<p><strong>Risk Management</strong></p>
<ul>
<li>Identify and mitigate testing risks and issues, proactively addressing potential roadblocks that could impact testing timelines or quality.</li>
</ul>
<p><strong>Skills &amp; Experience</strong></p>
<ul>
<li>8+ years in software testing, with at least 3 years in a managerial role.</li>
</ul>
<ul>
<li>Strong knowledge of functional, regression, performance, and security testing.</li>
</ul>
<ul>
<li>Experience in tools such as Playwright and knowledge of integrating testing in CI/CD pipelines.</li>
</ul>
<ul>
<li>Familiarity with Agile, Scrum, and DevOps practices.</li>
</ul>
<ul>
<li>Excellent leadership, communication, and stakeholder management skills.</li>
</ul>
<ul>
<li>Experience with cloud-based testing environments (Azure).</li>
</ul>
<ul>
<li>Knowledge of API testing and Dynamics 365 desirable.</li>
</ul>
<ul>
<li>ISTQB or similar certification.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>functional testing, regression testing, performance testing, security testing, test automation, Agile, Scrum, DevOps, Playwright, CI/CD pipelines, cloud-based testing environments, API testing, Dynamics 365, leadership, communication, stakeholder management, Azure, ISTQB</Skills>
      <Category>IT</Category>
      <Industry>Technology</Industry>
      <Employername>Central Functions</Employername>
      <Employerlogo>https://logos.yubhub.co/j.com.png</Employerlogo>
      <Employerdescription>Central Functions is a department within a larger organisation, responsible for various administrative and support functions.</Employerdescription>
      <Employerwebsite>https://apply.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/81352FEB06</Applyto>
      <Location>High Wycombe</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>b2f3cc65-797</externalid>
      <Title>Software Engineer II (Sr AI QA Engineer – Python)</Title>
      <Description><![CDATA[<p>We&#39;re looking for an experienced Senior AI QA Engineer to improve our quality engineering for AI/ML solutions and web platforms. You will use your Python expertise to improve test automation, performance, and security frameworks that inspire product excellence.</p>
<p><strong>Role Details</strong></p>
<p><strong>What You Will Do</strong></p>
<ul>
<li>Lead the development of comprehensive evaluation frameworks for AI/ML systems</li>
<li>Develop core AI/ML modules, APIs, and backend services in Python required for framework development</li>
<li>Conduct advanced performance and security testing, resolving systemic issues across AI pipelines and application stacks</li>
<li>Build automation, performance and security test frameworks for web applications and services</li>
<li>Collaborate with product owners, development teams</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Bachelor&#39;s degree in Computer Science, Engineering, or related field</li>
<li>Overall 5+ years of experience</li>
<li>4+ years of experience developing AI/ML modules, APIs, and backend services using Python</li>
<li>3+ years of experience testing web applications and web services</li>
<li>2+ years in building test automation frameworks using Python or similar languages</li>
<li>Experience with AWS cloud services (Lambda, S3, EC2, EKS) and containerization tools like Docker</li>
<li>Experience with software quality assurance processes and methodologies</li>
</ul>
<p><strong>Benefits</strong></p>
<p>We adopt a holistic approach to our benefits programs, emphasizing physical, emotional, financial, career, and community wellness to support a balanced life. Our packages are tailored to meet local needs and may include healthcare coverage, mental well-being support, retirement savings, paid time off, family leaves, complimentary games, and more.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Python, AI/ML, AWS cloud services, containerization tools like Docker, software quality assurance processes and methodologies, performance and security testing, web applications and services</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Electronic Arts</Employername>
      <Employerlogo>https://logos.yubhub.co/jobs.ea.com.png</Employerlogo>
      <Employerdescription>Electronic Arts is a multinational video game developer and publisher with a portfolio of games and experiences. It has locations around the world and opportunities across various departments.</Employerdescription>
      <Employerwebsite>https://jobs.ea.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ea.com/en_US/careers/JobDetail/Software-Engineer-II/212862</Applyto>
      <Location>Hyderabad</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>fcee67f8-7e6</externalid>
      <Title>Software Tester</Title>
      <Description><![CDATA[<p><strong>Job Description</strong></p>
<p>Helpshift is looking for a skilled Software Tester to join our team. As a Software Tester, you will work on projects that impact our conversations with consumers, bringing maximum value to them.</p>
<p><strong>About the Team</strong></p>
<p>At Helpshift, we have a QA Guild established which is responsible for performing QA for all projects that are executed across the organisation. The QA guild collaborates with engineering, product and design teams on implementation and user scenarios.</p>
<p><strong>Role Details</strong></p>
<p><strong>Key Responsibilities</strong></p>
<ul>
<li>Design Test Plans, Test Specifications and Test Cases for Product features.</li>
<li>Take ownership of feature testing and drive to completion.</li>
<li>Identify challenges, risks and provide test estimates for feature testing.</li>
<li>Execute regression test suites.</li>
<li>Perform exploratory testing.</li>
<li>Driving and maintaining the automation test suites.</li>
<li>Maximize test coverage for the most critical features of the system using automation.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>3+ years of experience in software testing and engineering.</li>
<li>Proficiency in one of the programming/scripting languages (Java/JS).</li>
<li>Hands on experience in version control systems like Git or SVN.</li>
</ul>
<p><strong>Benefits</strong></p>
<ul>
<li>Hybrid setup.</li>
<li>Worker&#39;s insurance.</li>
<li>Paid Time Offs.</li>
<li>Other employee benefits to be discussed by our Talent Acquisition team in India.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Java, JS, Git, SVN, Playwright, Appium, Postman, Selenium, Performance testing, Security testing</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Helpshift</Employername>
      <Employerlogo>https://logos.yubhub.co/j.com.png</Employerlogo>
      <Employerdescription>Helpshift enables companies to provide a modern customer support experience to a mobile consumer base, installed on over 2 Billion devices and serving over 900 Million active users every month.</Employerdescription>
      <Employerwebsite>https://apply.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/B8A3F010CC</Applyto>
      <Location></Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>aa015612-5ff</externalid>
      <Title>Product &amp; Solutions Lead, Safety and Security</Title>
      <Description><![CDATA[<p><strong>Job Posting</strong></p>
<p><strong>Product &amp; Solutions Lead, Safety and Security</strong></p>
<p><strong>Location</strong></p>
<p>San Francisco</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Department</strong></p>
<p>Intelligence &amp; Investigations</p>
<p><strong>Compensation</strong></p>
<ul>
<li>$288K – $425K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>
<p><strong>About the Team</strong></p>
<p>The Intelligence &amp; Investigations (I2) team detects and disrupts abuse and strategic risks so people can use AI safely. We translate real-world signals, investigations, and external threat intelligence into practical mitigations, operating guidance, and partner-ready support that improves safety outcomes across the AI ecosystem.</p>
<p><strong>About the Role</strong></p>
<p>As a Product &amp; Solutions Lead focused on safety and security, you will build and operate 0–1 products, services, and technical solution packages that help developers and public institutions move from experimentation to durable, trusted outcomes—while maintaining public safety, transparency, and respect for privacy and rights.</p>
<p>This role balances two modes of delivery:</p>
<ol>
<li>Bespoke products and technical solutions for strategic internal and external partners, and</li>
</ol>
<ol>
<li>Scalable product and solution packages that can be reused broadly across partners and deployments.</li>
</ol>
<p>Training is a component of scale, but not the center of gravity. You will also ship reference implementations, playbooks, evaluation kits, and repeatable operating models that partners can adopt and operate.</p>
<p>You will work directly with engineers and a multidisciplinary group of safety and geopolitical analysts, and data and quantitative scientists to convert complex, evolving challenges into solutions that teams can adopt in high-stakes environments.</p>
<p>This role is based in San Francisco, CA (hybrid, 3 days/week). Relocation support is available.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Own the 0–1 roadmap for safety and security solution offerings: define the target users, problem statements, tools, operating models, success metrics, and the set of reusable deliverables we ship.</li>
</ul>
<ul>
<li>Design and ship bespoke technical solutions for priority partners (internal and external), then abstract what works into reusable patterns and toolkits.</li>
</ul>
<ul>
<li>Build partner-ready technical artifacts: solution blueprints, reference architectures, evaluation and monitoring guidance, incident/response playbooks, and deployment checklists.</li>
</ul>
<ul>
<li>Package open-source and proprietary capabilities into adoption-ready solutions (e.g., reference implementations, configuration patterns, validated workflows).</li>
</ul>
<ul>
<li>Maintain a consistent delivery model across engagements: intake, scoping, governance alignment, execution cadence, and retrospectives that improve the offering over time.</li>
</ul>
<ul>
<li>Translate evolving threats into actionable guidance and updates for solution packages (e.g., scams/fraud patterns, cyber-enabled threats, ecosystem abuse trends).</li>
</ul>
<ul>
<li>Develop lightweight enablement components as needed: targeted technical modules, hands-on labs, and readiness assessments that accelerate adoption of the solutions.</li>
</ul>
<ul>
<li>Define and instrument impact measurement: adoption milestones, readiness indicators, reliability and safety posture improvements, and partner satisfaction with outputs.</li>
</ul>
<ul>
<li>Partner closely across engineering, safety, geopolitical analysis, and quantitative teams to ensure solutions are technically credible, threat-informed, and measurable.</li>
</ul>
<ul>
<li>Communicate crisply and decision-readily to internal and external stakeholders: progress, trade-offs, risks, and recommendations.</li>
</ul>
<p><strong>You might thrive in this role if you:</strong></p>
<ul>
<li>Have 6+ years in product, technical program leadership, solutions, or platform operations, especially in safety, security, risk, integrity, or enterprise/public-sector contexts.</li>
</ul>
<ul>
<li>Have built 0–1 solution offerings (product plus services or productized services): taking ambiguous needs, shipping something concrete, then scaling it into a repeatable model.</li>
</ul>
<ul>
<li>Have a builder’s mindset: comfortable incubating early-stage ideas, testing them with partners, and evolving them into durable, repeatable safety and security solutions.</li>
</ul>
<ul>
<li>Can go deep with engineers and still produce partner-ready artifacts that are clear</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$288K – $425K</Salaryrange>
      <Skills>product leadership, technical program leadership, solutions, platform operations, safety, security, risk, integrity, enterprise/public-sector contexts, product development, solution development, technical writing, communication, project management, team leadership, collaboration, problem-solving, analytical skills, data analysis, data visualization, machine learning, artificial intelligence, cybersecurity, threat intelligence, incident response, compliance, regulatory affairs, cloud computing, containerization, DevOps, agile development, scrum, kanban, continuous integration, continuous deployment, continuous testing, test automation, security testing, penetration testing, vulnerability assessment, compliance testing, regulatory testing, data protection, information security, cybersecurity frameworks, risk management, compliance management, regulatory compliance, data governance, information governance, data quality, data integrity, data validation, data verification, data certification, data assurance, data security, data encryption, data masking, data tokenization, data anonymization, data pseudonymization, data aggregation, data fusion, data integration, data warehousing, data mart, data lake, data catalog, data governance, data quality, data integrity, data validation, data verification, data certification, data assurance, data security, data encryption, data masking, data tokenization, data anonymization, data pseudonymization, data aggregation, data fusion, data integration, data warehousing, data mart, data lake, data catalog</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is a technology company that focuses on developing and applying artificial intelligence in a way that benefits humanity. It was founded in 2015 and has since grown to become one of the leading AI research and development companies in the world.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/c664cc09-d996-450c-8683-ad591ac27c11</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>23a792a8-cc4</externalid>
      <Title>Vendor Security Program Manager</Title>
      <Description><![CDATA[<p><strong>Job Posting</strong></p>
<p><strong>Vendor Security Program Manager</strong></p>
<p><strong>Location</strong></p>
<p>San Francisco; New York City; Seattle; Washington, DC</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Location Type</strong></p>
<p>Hybrid</p>
<p><strong>Department</strong></p>
<p>Security</p>
<p><strong>Compensation</strong></p>
<ul>
<li>SF, Seattle and NYC: $207K – $335K • Offers Equity</li>
<li>Zone A: $186K – $301.5K • Offers Equity</li>
<li>Zone B: $165.6K – $268K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>
<p><strong>About the Team</strong></p>
<p>The Vendor Security team sits at the core of our mission to ensure our technology benefits humanity safely and securely. We provide security assurances and robust compliance frameworks for our technology, people, and products. Our mission is to build trust with the world in our products and company. Our work is technical yet highly operational, strategically aligning with security and engineering teams to navigate and mitigate risks proactively. We prioritize impact, enable innovation, and foster a culture of continuous compliance and security awareness.</p>
<p><strong>About the Role</strong></p>
<p>As a Program Manager within the Vendor Security team, you will play a crucial role in protecting our organisation against external risks posed by suppliers, vendors, partners, and hardware manufacturers. Your responsibilities will include conducting comprehensive security assessments, building a program to manage global supply chain and vendor risks, and driving security initiatives across all of our third-party relationships. You will be analytical, detail-oriented, and proactive, capable of translating complex security evaluations into clear, actionable strategies.</p>
<p>The role is expected to operate with a strong point of view on risk. You will be responsible not only for identifying and documenting vendor and supply-chain risk, but for helping the company make informed trade-offs between speed, scale, and security. This role requires exceptional organisational skills, the ability to effectively communicate across different business functions, and a strong commitment to operational excellence in a dynamic environment.</p>
<p>This role may be based out of one of our US offices (San Francisco, Seattle, NYC or DC.) We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Be the interface for Security to the rest of the organisation for vendors.</li>
</ul>
<ul>
<li>Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.</li>
</ul>
<ul>
<li>Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.</li>
</ul>
<ul>
<li>Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.</li>
</ul>
<ul>
<li>Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.</li>
</ul>
<ul>
<li>Develop, propose, and implement effective controls to mitigate identified vendor risks.</li>
</ul>
<ul>
<li>Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.</li>
</ul>
<ul>
<li>Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.</li>
</ul>
<p><strong>You might thrive in this role if you have:</strong></p>
<ul>
<li>Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.</li>
</ul>
<ul>
<li>An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.</li>
</ul>
<ul>
<li>Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete or uncertain.</li>
</ul>
<ul>
<li>Strong analytical and problem-solving skills, with the ability to identify and mitigate complex security risks.</li>
</ul>
<ul>
<li>Excellent communication and interpersonal skills, with the ability to effectively collaborate with cross-functional teams and stakeholders.</li>
</ul>
<ul>
<li>Strong organisational and project management skills, with the ability to prioritise tasks and manage multiple projects simultaneously.</li>
</ul>
<ul>
<li>A strong commitment to operational excellence and continuous improvement, with a focus on delivering high-quality results in a dynamic environment.</li>
</ul>
<ul>
<li>A passion for security and a desire to make a meaningful impact in the field.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$207K – $335K • Offers Equity</Salaryrange>
      <Skills>information security principles and controls, data protection, access management, proactive and reactive security measures, application security, third-party or supply chain security assessments, vendor management security program, security risk management, compliance frameworks, security awareness, operational excellence, project management, communication and interpersonal skills, cloud security, infrastructure security, threat intelligence, security analytics, incident response, security testing, penetration testing, security consulting, security training, security awareness training</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is a technology company that focuses on developing artificial intelligence (AI) systems. It was founded in 2015 and is headquartered in San Francisco, California.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/fb1e823e-cfcc-4293-8893-cc77e467c561</Applyto>
      <Location>San Francisco; New York City; Seattle; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
  </jobs>
</source>