{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/threat-modeling"},"x-facet":{"type":"skill","slug":"threat-modeling","display":"Threat Modeling","count":45},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_f77c41bb-0ad"},"title":"Application Security Engineer","description":"<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert, you will have direct experience in a wide range of security technologies, tools, and methodologies. The role is suited for an experienced Application Security engineer with proven understanding in enterprise security and AI security and will focus on building toolsets and processes to drive adoption of secure practices across the enterprise.</p>\n<p>The team fosters a collaborative environment and is building a best-in-class program to partner with the business to protect the Firm’s information and computer systems. Millennium is a complex and robust technical environment and securing the Firm from external and internal threats is a top priority.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Define and implement security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</li>\n<li>Conduct specialized threat modeling, red teaming, and risk assessments for AI/ML models (e.g., testing for prompt injection, model theft, and data poisoning).</li>\n<li>Lead risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects.</li>\n<li>Engage throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards.</li>\n<li>Evangelize AppSec and AI security best practices through developer education, training materials, and outreach.</li>\n<li>Design robust security architectures and integrate automated security testing (SAST/DAST/SCA) into CI/CD pipelines.</li>\n<li>Partner with Technology, Trading, Legal, and Compliance to create policies and communicate technical risks to non-technical stakeholders.</li>\n</ul>\n<p><strong>Qualifications</strong></p>\n<ul>\n<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field.</li>\n<li>5+ years’ experience working as an Application Security Engineer, Software Engineer, or similar role.</li>\n<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs.</li>\n<li>Experience working with AI models, Agentic frameworks and security risks associated with AI.</li>\n<li>Experience in working with global teams, collaborating on code and presentations.</li>\n<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>\n<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols.</li>\n<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>\n<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions.</li>\n<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>\n<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar.</li>\n<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>\n<li>Familiarity with web application security testing tools and methodologies.</li>\n<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>\n<li>Knowledge of Linux, OS internals and containers is a plus.</li>\n<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_f77c41bb-0ad","directApply":true,"hiringOrganization":{"@type":"Organization","name":"IT Infrastructure","sameAs":"https://mlp.eightfold.ai","logo":"https://logos.yubhub.co/mlp.eightfold.ai.png"},"x-apply-url":"https://mlp.eightfold.ai/careers/job/755955629927","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["AI-specific risks","Generative AI","LLMs","Agentic frameworks","Security guardrails","Threat modeling","Red teaming","Risk assessments","Application risk assessments","Design reviews","Mitigation strategies","Secure coding standards","Automated security testing","CI/CD pipelines","Security architectures","Secure configuration principles","Cryptography fundamentals","Encryption protocols","SCM & CI/CD technologies","Security scanning","Vulnerability management","Static and dynamic security analysis tools","SCA/SBOM solutions","Secrets management","Password vault technologies","Secure programming","Infrastructure as Code tools","Web application security testing tools","Methodologies","Security frameworks","Standards","Linux","OS internals","Containers"],"x-skills-preferred":[],"datePosted":"2026-04-18T22:14:17.280Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dublin, Ireland"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Automated security testing, CI/CD pipelines, Security architectures, Secure configuration principles, Cryptography fundamentals, Encryption protocols, SCM & CI/CD technologies, Security scanning, Vulnerability management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets management, Password vault technologies, Secure programming, Infrastructure as Code tools, Web application security testing tools, Methodologies, Security frameworks, Standards, Linux, OS internals, Containers"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_6a75ea8b-5b4"},"title":"Application Security Engineer","description":"<p>We are seeking an experienced Application Security Engineer to join our team. As a subject matter expert with direct experience in a wide range of security technologies, tools, and methodologies, you will play a key role in building toolsets and processes to drive adoption of secure practices across the enterprise.</p>\n<p>The successful candidate will have a proven understanding in enterprise security and AI security and will focus on defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks, ensuring safe enterprise adoption.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Defining and implementing security guardrails for Generative AI, LLMs, and Agentic frameworks</li>\n<li>Conducting specialized threat modeling, red teaming, and risk assessments for AI/ML models</li>\n<li>Leading risk management activities, including application risk assessments, design reviews, and mitigation strategies for IT projects</li>\n<li>Engaging throughout the SDLC to identify vulnerabilities, conduct code reviews/penetration testing, and enforce secure coding standards</li>\n<li>Evangelizing AppSec and AI security best practices through developer education, training materials, and outreach</li>\n</ul>\n<p>Qualifications include:</p>\n<ul>\n<li>Bachelor&#39;s degree or higher in Computer Science, Computer Engineering, IT Security or related field</li>\n<li>5+ years&#39; experience working as an Application Security Engineer, Software Engineer, or similar role</li>\n<li>Deep understanding of AI-specific risks (OWASP Top 10 for LLMs) and experience securing applications utilizing LLMs</li>\n<li>Experience working with AI models, Agentic frameworks and security risks associated with AI</li>\n<li>Experience in working with global teams, collaborating on code and presentations</li>\n</ul>\n<p>Preferred qualifications include:</p>\n<ul>\n<li>Demonstrated work experience in hybrid on-premise and Public Cloud environments (AWS/GCP/Azure)</li>\n<li>Strong understanding of security architectures, secure configuration principles/coding practices, cryptography fundamentals and encryption protocols</li>\n<li>Experience with common SCM &amp; CI/CD technologies like GitHub, Jenkins, Artifactory, etc. and integrating Security Scanning and Vulnerability Management into the CI/CD Pipelines</li>\n<li>Familiarity with static and dynamic security analysis tools, and SCA/SBOM solutions</li>\n<li>Hands on experience with Secrets Management &amp; Password Vault technologies such as Delinea Secret Server and/or Hashicorp Vault, etc.</li>\n<li>Strong experience in secure programming in languages such as Python, Java, C++, C#, or similar</li>\n<li>Familiarity with Infrastructure as Code tools (CloudFormation, Terraform, Ansible, etc.)</li>\n<li>Familiarity with web application security testing tools and methodologies</li>\n<li>Knowledge of various security frameworks and standards such as ISO 27001, NIST, OWASP, etc.</li>\n<li>Knowledge of Linux, OS internals and containers is a plus</li>\n<li>Certifications like CISSP, CISM, CompTIA Security+, or CEH are advantageous</li>\n</ul>\n<p>We offer a competitive salary and benefits package, as well as opportunities for professional growth and development.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_6a75ea8b-5b4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"IT Infrastructure","sameAs":"https://mlp.eightfold.ai","logo":"https://logos.yubhub.co/mlp.eightfold.ai.png"},"x-apply-url":"https://mlp.eightfold.ai/careers/job/755955629908","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["AI-specific risks","Generative AI","LLMs","Agentic frameworks","Security guardrails","Threat modeling","Red teaming","Risk assessments","Application risk assessments","Design reviews","Mitigation strategies","Secure coding standards","Developer education","Training materials","Outreach","Common SCM & CI/CD technologies","GitHub","Jenkins","Artifactory","Security Scanning","Vulnerability Management","Static and dynamic security analysis tools","SCA/SBOM solutions","Secrets Management & Password Vault technologies","Delinea Secret Server","Hashicorp Vault","Secure programming","Python","Java","C++","C#","Infrastructure as Code tools","CloudFormation","Terraform","Ansible","Web application security testing tools","Methodologies","Security frameworks","Standards","ISO 27001","NIST","OWASP","Linux","OS internals","Containers"],"x-skills-preferred":[],"datePosted":"2026-04-18T22:14:06.620Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London, United Kingdom"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"AI-specific risks, Generative AI, LLMs, Agentic frameworks, Security guardrails, Threat modeling, Red teaming, Risk assessments, Application risk assessments, Design reviews, Mitigation strategies, Secure coding standards, Developer education, Training materials, Outreach, Common SCM & CI/CD technologies, GitHub, Jenkins, Artifactory, Security Scanning, Vulnerability Management, Static and dynamic security analysis tools, SCA/SBOM solutions, Secrets Management & Password Vault technologies, Delinea Secret Server, Hashicorp Vault, Secure programming, Python, Java, C++, C#, Infrastructure as Code tools, CloudFormation, Terraform, Ansible, Web application security testing tools, Methodologies, Security frameworks, Standards, ISO 27001, NIST, OWASP, Linux, OS internals, Containers"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_10d097fc-787"},"title":"Blockchain Security Engineer","description":"<p>Ready to be pushed beyond what you think you’re capable of?</p>\n<p>At Coinbase, our mission is to increase economic freedom in the world.</p>\n<p>We&#39;re seeking a very specific candidate who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system.</p>\n<p>As a Blockchain Security Engineer on the Decentralized Financial Security Team, you will work closely with engineers, technical product managers and senior leadership on designing secure products from the ground up.</p>\n<p>You will be responsible for performing secure design reviews, threat modeling, vendor reviews, working with vendors, and secure code reviews for upcoming Coinbase products or features that will be used by millions of customers.</p>\n<p>You will have an opportunity to work on the latest technology and provide leadership visibility of the current risk posture.</p>\n<p>You’ll also have an opportunity to pitch, lead and participate in cross-functional initiatives that uplevel the security of all Coinbase products and services.</p>\n<p>To be completed by all business teams except Eng:</p>\n<p>Perform design reviews, threat modeling and code reviews of upcoming features and products.</p>\n<p>Identify top product risk areas and lead risk-reduction initiatives with cross-functional teams.</p>\n<p>Improve and/or automate existing processes to increase efficiency, utilizing agentic/AI tooling.</p>\n<p>Create monitoring solutions to ensure identified risks remain at acceptable levels for Coinbase.</p>\n<p>Participate in the team on-call rotation to support engineering teams through timely design consultations, vulnerability analysis, bug fix verification, etc.</p>\n<p>Publish blogs and give talks (internal and external) on newfound vulnerabilities, incident investigations, unique integration risks, and related topics</p>\n<p>To be completed by all business teams except Eng:</p>\n<p>Strong understanding of blockchains (particularly EVM chains) and highly “crypto forward”</p>\n<p>Expertise in blockchain technology and foundational knowledge in security principles</p>\n<p>2+ years of threat modeling/design review experience</p>\n<p>Strong communication skills with the ability to translate technical security requirements and risks into terms that anyone can understand.</p>\n<p>High ownership and drive, including the ability to work independently and unblock yourself.</p>\n<p>Experience with using AI/agentic tooling (Claude Code, Cursor, GPT Codex, etc.)</p>\n<p>Demonstrates the ability to responsibly use generative AI tools and copilots (e.g., LibreChat, Gemini, Glean) in daily workflows, continuously learn as tools evolve, and apply human-in-the-loop practices to deliver business-ready outputs and drive measurable improvements in efficiency, cost, and quality.</p>\n<p>Nice to haves:</p>\n<p>MS or PhD in Computer Science or related field.</p>\n<p>Experience in at least one of: Snowflake, Databricks, Dune.</p>\n<p>Experience automating manual processes or carrying out process improvements.</p>\n<p>Experience in Blockchain, Exchange, or Decentralized Exchange Security.</p>\n<p>Job ID: P76318</p>\n<p>#LI-Remote</p>\n<p>Pay Transparency Notice: Depending on your work location, the target annual base salary for this position can range as detailed below.</p>\n<p>Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, vision and 401(k)).</p>\n<p>Annual base salary range (excluding equity and bonus):</p>\n<p>$152,405-$179,300 USD</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_10d097fc-787","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Coinbase","sameAs":"https://www.coinbase.com/","logo":"https://logos.yubhub.co/coinbase.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coinbase/jobs/7701657","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$152,405-$179,300 USD","x-skills-required":["blockchain","security","threat modeling","design review","vendor review","code review","AI/agentic tooling","generative AI tools","copilots","LibreChat","Gemini","Glean"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:55:39.659Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote - USA"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"blockchain, security, threat modeling, design review, vendor review, code review, AI/agentic tooling, generative AI tools, copilots, LibreChat, Gemini, Glean","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":152405,"maxValue":179300,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_611720bf-294"},"title":"Senior Application Security Engineer","description":"<p>Why join us</p>\n<p>Brex is a financial platform that enables companies to spend smarter and move faster in over 200 markets. It combines global corporate cards and banking with intuitive spend management, bill pay, and travel software.</p>\n<p>As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. In this role, you will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows.</p>\n<p>Application Security is part of our wider Financial Scale organization, which means you will work closely with Security Operations, GRC, Product Security, Front End Platform, IT Infrastructure teams.</p>\n<p>We’re looking for individuals with a strong background and interest in penetration testing. You should have a demonstrated ability to find vulnerabilities in complex systems and craft exploits to demonstrate business impact.</p>\n<p>This role is highly cross-functional and collaborative, you will have the opportunity to work with every engineering team across Brex.</p>\n<p>Building a world-class financial service requires world-class security. Brex is pioneering the next wave of AI-driven financial services for dynamic, high-impact companies like Coinbase, Robinhood, and Anthropic.</p>\n<p>Responsibilities</p>\n<ul>\n<li>Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts</li>\n</ul>\n<ul>\n<li>Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features</li>\n</ul>\n<ul>\n<li>Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices</li>\n</ul>\n<ul>\n<li>Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization</li>\n</ul>\n<p>Requirements</p>\n<ul>\n<li>5+ years work experience in an Application Security or related role</li>\n</ul>\n<ul>\n<li>Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains</li>\n</ul>\n<ul>\n<li>Experience with a wide range of secure development activities including, threat modeling, developer education, and incident response</li>\n</ul>\n<ul>\n<li>Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity</li>\n</ul>\n<ul>\n<li>Collaborative mindset paired with strong written and verbal communication skills</li>\n</ul>\n<p>Bonus points</p>\n<ul>\n<li>Proficiency with Kotlin, gRPC, GraphQL, Kubernetes</li>\n</ul>\n<ul>\n<li>Previous experience as a software engineer</li>\n</ul>\n<ul>\n<li>Consultancy experience performing web application security reviews</li>\n</ul>\n<ul>\n<li>Experience with securing distributed systems in AWS and cloud environments</li>\n</ul>\n<ul>\n<li>Experience with pentesting and securing agentic features and systems</li>\n</ul>\n<ul>\n<li>Contributions to the wider technical community, open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc</li>\n</ul>\n<p>Experience submitting to bug bounty programs or responsible disclosure programs</p>\n<p>Compensation</p>\n<p>The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_611720bf-294","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Brex","sameAs":"https://brex.com/","logo":"https://logos.yubhub.co/brex.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/brex/jobs/8249884002","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$192,000 - $240,000","x-skills-required":["Python","Secure development activities","Threat modeling","Developer education","Incident response","AI/agentic workflows","Collaborative mindset","Strong written and verbal communication skills"],"x-skills-preferred":["Kotlin","gRPC","GraphQL","Kubernetes","Software engineering","Web application security reviews","Distributed systems in AWS and cloud environments","Pentesting and securing agentic features and systems","Contributions to the wider technical community"],"datePosted":"2026-04-18T15:55:36.756Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Seattle, Washington, United States"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"Python, Secure development activities, Threat modeling, Developer education, Incident response, AI/agentic workflows, Collaborative mindset, Strong written and verbal communication skills, Kotlin, gRPC, GraphQL, Kubernetes, Software engineering, Web application security reviews, Distributed systems in AWS and cloud environments, Pentesting and securing agentic features and systems, Contributions to the wider technical community","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":192000,"maxValue":240000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b7959209-0c2"},"title":"Safeguards Policy Analyst, Fraud & Scams","description":"<p>As a Safeguards Policy Analyst focused on Fraud &amp; Scams, you will design, build, and execute enforcement workflows that detect and mitigate fraud and scam-related harms on Anthropic&#39;s products.</p>\n<p>This role sits within the Integrity &amp; Authenticity (I&amp;A) team, where you will function both as a policy owner and work closely with threat investigative and enforcement teams.</p>\n<p>Key responsibilities include drafting, maintaining, and iterating on Fraud &amp; Scams policies; conducting regular structured policy reviews; developing detailed threat models for fraud and scam vectors; and staying current on the fraud and scam landscape.</p>\n<p>You will also design and architect automated enforcement systems and human review workflows that scale effectively while maintaining high precision and recall.</p>\n<p>Additionally, you will serve as the primary policy point of contact for ML and Engineering teams developing fraud detection classifiers, working to translate policy intent into technical artifacts and training signals.</p>\n<p>If you have experience working as a Trust &amp; Safety professional with a focused background in fraud, scams, or financial crime, particularly in a tech platform or AI context, you may be a good fit for this role.</p>\n<p>Preferred qualifications include experience at a major technology platform, financial institution, or fraud intelligence firm in a policy, operations, or investigative capacity, familiarity with the generative AI risk landscape, and background in threat intelligence, financial crimes compliance (AML/KYC), or law enforcement focused on cyber-enabled fraud.</p>\n<p>The annual compensation range for this role is $245,000-$285,000 USD.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b7959209-0c2","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.co/","logo":"https://logos.yubhub.co/anthropic.co.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5174857008","x-work-arrangement":"hybrid","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$245,000-$285,000 USD","x-skills-required":["policy design","fraud and scam analysis","threat modeling","automated enforcement systems","human review workflows","ML and Engineering collaboration"],"x-skills-preferred":["generative AI risk landscape","threat intelligence","financial crimes compliance","law enforcement"],"datePosted":"2026-04-18T15:55:28.514Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote-Friendly (Travel-Required) | San Francisco, CA | New York City, NY"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"policy design, fraud and scam analysis, threat modeling, automated enforcement systems, human review workflows, ML and Engineering collaboration, generative AI risk landscape, threat intelligence, financial crimes compliance, law enforcement","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":245000,"maxValue":285000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_f5d87e3c-d74"},"title":"Offensive Security Engineer","description":"<p>As an Offensive Security Engineer at CoreWeave, you will lead efforts to identify and mitigate security risks across internal and external systems.</p>\n<p>You&#39;ll perform penetration testing, conduct threat modeling, and provide guidance to engineering teams on secure design and best practices. This role also involves developing security tooling, researching emerging threats, and contributing to the continuous improvement of CoreWeave&#39;s overall security posture.</p>\n<p>Some of what you&#39;ll work on:</p>\n<ul>\n<li>Perform penetration testing as well as purple and red team exercises.</li>\n<li>Conduct threat modeling, code reviews, and design reviews for development teams.</li>\n<li>Research new attack techniques and develop strategies to counter them.</li>\n<li>Develop and enforce security best practices and standards, maintaining internal compliance.</li>\n<li>Provide solutions to complex security issues, manage multiple tasks, and prioritize effectively in a fast-paced environment.</li>\n<li>Present technical security information to both technical and non-technical audiences.</li>\n<li>Maintain technical documentation, reports, and security tooling with attention to detail.</li>\n<li>Participate in other security-related initiatives as assigned.</li>\n</ul>\n<p>Who You Are:</p>\n<ul>\n<li>5+ years of experience in offensive information security roles.</li>\n<li>Proficiency in at least one programming or scripting language (e.g., Go, Python, C/C++) for automation, code reviews, and tooling.</li>\n<li>Hands-on penetration testing experience and familiarity with offensive security tools.</li>\n<li>Strong technical knowledge of Linux operating systems and containerized environments.</li>\n<li>Experience securing Kubernetes and understanding related security practices.</li>\n<li>Able to navigate ambiguity, identify root causes, and solve complex security problems.</li>\n<li>Excellent written and verbal communication skills with strong technical documentation abilities.</li>\n<li>Capable of working independently while managing multiple priorities in a fast-paced environment.</li>\n<li>Strong desire to continuously learn and adopt new technologies and security techniques.</li>\n</ul>\n<p>Preferred:</p>\n<ul>\n<li>Experience with firmware reverse engineering, analyzing binaries, bootloaders, and embedded systems for vulnerabilities.</li>\n<li>Relevant certifications such as Sec+, Net+, OSCP, or equivalent.</li>\n<li>Experience with EDR tuning, detections-as-code, or threat hunting as part of a Blue Team.</li>\n<li>Deep understanding of business-wide security best practices and implementation strategies.</li>\n</ul>\n<p>Wondering if you&#39;re a good fit?</p>\n<p>We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams – even if you aren&#39;t a 100% skill or experience match.</p>\n<p>Here are a few qualities we&#39;ve found compatible with our team.</p>\n<p>If some of this describes you, we&#39;d love to talk.</p>\n<ul>\n<li>You love hunting vulnerabilities and proactively improving security.</li>\n<li>You&#39;re curious about evolving attack vectors and defense strategies.</li>\n<li>You&#39;re an expert in offensive security techniques and tooling, with a passion for safeguarding systems.</li>\n</ul>\n<p>Why CoreWeave?</p>\n<p>At CoreWeave, we work hard, have fun, and move fast!</p>\n<p>We&#39;re in an exciting stage of hyper-growth that you will not want to miss out on.</p>\n<p>We&#39;re not afraid of a little chaos, and we&#39;re constantly learning.</p>\n<p>Our team cares deeply about how we build our product and how we work together, which is represented through our core values:</p>\n<ul>\n<li>Be Curious at Your Core</li>\n<li>Act Like an Owner</li>\n<li>Empower Employees</li>\n<li>Deliver Best-in-Class Client Experiences</li>\n<li>Achieve More Together</li>\n</ul>\n<p>We support and encourage an entrepreneurial outlook and independent thinking.</p>\n<p>We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems.</p>\n<p>As we get set for takeoff, the organization&#39;s growth opportunities are constantly expanding.</p>\n<p>You will be surrounded by some of the best talent in the industry, who will want to learn from you, too.</p>\n<p>Come join us!</p>\n<p>The base salary range for this role is $165,000 to $242,000.</p>\n<p>The starting salary will be determined based on job-related knowledge, skills, experience, and market location.</p>\n<p>We strive for both market alignment and internal equity when determining compensation.</p>\n<p>In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).</p>\n<p>What We Offer</p>\n<p>The range we&#39;ve posted represents the typical compensation range for this role.</p>\n<p>To determine actual compensation, we review the market rate for each candidate which can include a variety of factors.</p>\n<p>These include qualifications, experience, interview performance, and location.</p>\n<p>In addition to a competitive salary, we offer a variety of benefits to support your needs, including:</p>\n<ul>\n<li>Medical, dental, and vision insurance</li>\n<li>100% paid for by CoreWeave</li>\n<li>Company-paid Life Insurance</li>\n<li>Voluntary supplemental life insurance</li>\n<li>Short and long-term disability insurance</li>\n<li>Flexible Spending Account</li>\n<li>Health Savings Account</li>\n<li>Tuition Reimbursement</li>\n<li>Ability to Participate in Employee Stock Purchase Program (ESPP)</li>\n<li>Mental Wellness Benefits through Spring Health</li>\n<li>Family-Forming support provided by Carrot</li>\n<li>Paid Parental Leave</li>\n<li>Flexible, full-service childcare support with Kinside</li>\n<li>401(k) with a generous employer match</li>\n<li>Flexible PTO</li>\n<li>Catered lunch each day in our office and data center locations</li>\n<li>A casual work environment</li>\n<li>A work culture focused on innovative disruption</li>\n</ul>\n<p>Our Workplace</p>\n<p>While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets.</p>\n<p>New hires will be invited to attend onboarding at one of our hubs within their first month.</p>\n<p>Teams also gather quarterly to support collaboration.</p>\n<p>California Consumer Privacy Act - California applicants only</p>\n<p>CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace.</p>\n<p>All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information.</p>\n<p>As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship.</p>\n<p>If reasonable accommodation is needed, please contact: careers@coreweave.com.</p>\n<p>Export Control Compliance</p>\n<p>This position requires access to export controlled information.</p>\n<p>To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the information under an appropriate export license, or (C) otherwise exempt from the regulations.</p>\n<p>Applicant must also comply with all applicable laws and regulations related to the handling and transfer of export-controlled information.</p>\n<p>By applying for this position, applicant acknowledges that they have read, understand, and will comply with these requirements.</p>\n<p>Failure to comply with these requirements may result in termination of employment, revocation of any security clearances, or other disciplinary action.</p>\n<p>Applicant must also agree to undergo a background investigation and obtain any necessary security clearances prior to commencing employment.</p>\n<p>Please note that this position is subject to U.S. Government export regulations and may require applicant to sign a non-disclosure agreement (NDA) prior to commencing employment.</p>\n<p>Applicant must also agree to comply with all applicable laws and regulations related to the handling and transfer of export-controlled information.</p>\n<p>By applying for this position, applicant acknowledges that they have read, understand, and will comply with these requirements.</p>\n<p>Failure to comply with these requirements may result in termination of employment, revocation of any security clearances, or other disciplinary action.</p>\n<p>Applicant must also agree to undergo a background investigation and obtain any necessary security clearances prior to commencing employment.</p>\n<p>Please note that this position is subject to U.S. Government export regulations and may require applicant to sign a non-disclosure agreement (NDA) prior to commencing employment.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_f5d87e3c-d74","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4657803006","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$165,000 to $242,000","x-skills-required":["programming or scripting language","penetration testing","threat modeling","code reviews","design reviews","security best practices","Linux operating systems","containerized environments","Kubernetes","security practices"],"x-skills-preferred":["firmware reverse engineering","analyzing binaries","bootloaders","embedded systems","EDR tuning","detections-as-code","threat hunting","business-wide security best practices"],"datePosted":"2026-04-18T15:52:56.746Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"programming or scripting language, penetration testing, threat modeling, code reviews, design reviews, security best practices, Linux operating systems, containerized environments, Kubernetes, security practices, firmware reverse engineering, analyzing binaries, bootloaders, embedded systems, EDR tuning, detections-as-code, threat hunting, business-wide security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":165000,"maxValue":242000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_f296b6b0-e66"},"title":"Senior Software Security Engineer","description":"<p>Job Title: Senior Software Security Engineer</p>\n<p>About the Role: The Security Engineering team&#39;s mission is to safeguard our AI systems and maintain the trust of our users and society at large. Whether we&#39;re developing critical security infrastructure, building secure development practices, or partnering with our research and product teams, we are committed to operating as a world-class security organization and keeping the safety and trust of our users at the forefront of everything we do.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Build security for large-scale AI clusters, implementing robust cloud security architecture including IAM, network segmentation, and encryption controls</li>\n</ul>\n<ul>\n<li>Design secure-by-design workflows, secure CI/CD pipelines across our services, help build secure cloud infrastructure, with expertise in various cloud environments, Kubernetes security, container orchestration and identity management</li>\n</ul>\n<ul>\n<li>Ship and operate secure, high-reliability services using Infrastructure-as-Code (IaC) practices and GitOps workflows</li>\n</ul>\n<ul>\n<li>Apply deep expertise in threat modeling and risk assessment to secure complex multi cloud environments</li>\n</ul>\n<ul>\n<li>Mentor engineers and contribute to hiring and growth of the Security team</li>\n</ul>\n<p>Requirements:</p>\n<ul>\n<li>5-15+ years of software engineering experience implementing and maintaining critical systems at scale</li>\n</ul>\n<ul>\n<li>Bachelor&#39;s degree in Computer Science/Software Engineering or equivalent industry experience</li>\n</ul>\n<ul>\n<li>Strong software engineering skills in Python or at least one systems language (Go, Rust, C/C++)</li>\n</ul>\n<ul>\n<li>Experience managing infrastructure at scale with DevOps and cloud automation best practices</li>\n</ul>\n<ul>\n<li>Track record of driving engineering excellence through high standards, constructive code reviews, and mentorship</li>\n</ul>\n<ul>\n<li>Proven ability to lead cross-functional security initiatives and navigate complex organizational dynamics</li>\n</ul>\n<ul>\n<li>Outstanding communication skills, translating technical concepts effectively across all organizational levels</li>\n</ul>\n<ul>\n<li>Demonstrated success in bringing clarity and ownership to ambiguous technical problems</li>\n</ul>\n<ul>\n<li>Strong systems thinking with ability to identify and mitigate risks in complex environments</li>\n</ul>\n<ul>\n<li>Low ego, high empathy engineer who attracts talent and supports diverse, inclusive teams</li>\n</ul>\n<ul>\n<li>Experience supporting fast-paced startup engineering teams</li>\n</ul>\n<ul>\n<li>Passionate about AI safety and alignment, with keen interest in making AI systems more interpretable and aligned with human values</li>\n</ul>\n<p>Salary: The annual compensation range for this role is £240,000-£325,000 GBP.</p>\n<p>Experience Level: senior Employment Type: full-time Workplace Type: hybrid Category: Engineering Industry: Technology Salary Range: £240,000-£325,000 GBP Required Skills:</p>\n<ul>\n<li>Cloud security architecture</li>\n<li>IAM</li>\n<li>Network segmentation</li>\n<li>Encryption controls</li>\n<li>Kubernetes security</li>\n<li>Container orchestration</li>\n<li>Identity management</li>\n<li>Infrastructure-as-Code (IaC)</li>\n<li>GitOps</li>\n<li>Threat modeling</li>\n<li>Risk assessment</li>\n<li>DevOps</li>\n<li>Cloud automation</li>\n<li>Python</li>\n<li>Go</li>\n<li>Rust</li>\n<li>C/C++</li>\n</ul>\n<p>Preferred Skills:</p>\n<ul>\n<li>Secure-by-design workflows</li>\n<li>CI/CD pipelines</li>\n<li>Secure cloud infrastructure</li>\n<li>Cloud environments</li>\n<li>Containerization</li>\n<li>Identity and access management</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_f296b6b0-e66","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.com/","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5022845008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"£240,000-£325,000 GBP","x-skills-required":["Cloud security architecture","IAM","Network segmentation","Encryption controls","Kubernetes security","Container orchestration","Identity management","Infrastructure-as-Code (IaC)","GitOps","Threat modeling","Risk assessment","DevOps","Cloud automation","Python","Go","Rust","C/C++"],"x-skills-preferred":["Secure-by-design workflows","CI/CD pipelines","Secure cloud infrastructure","Cloud environments","Containerization","Identity and access management"],"datePosted":"2026-04-18T15:51:17.687Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London, UK"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Cloud security architecture, IAM, Network segmentation, Encryption controls, Kubernetes security, Container orchestration, Identity management, Infrastructure-as-Code (IaC), GitOps, Threat modeling, Risk assessment, DevOps, Cloud automation, Python, Go, Rust, C/C++, Secure-by-design workflows, CI/CD pipelines, Secure cloud infrastructure, Cloud environments, Containerization, Identity and access management","baseSalary":{"@type":"MonetaryAmount","currency":"GBP","value":{"@type":"QuantitativeValue","minValue":240000,"maxValue":325000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b85fa3c5-892"},"title":"Senior Application Security Engineer","description":"<p><strong>Job Title</strong></p>\n<p>Senior Application Security Engineer</p>\n<p><strong>Company Overview</strong></p>\n<p>Brex is a financial platform that enables companies to spend smarter and move faster in over 200 markets. It combines global corporate cards and banking with intuitive spend management, bill pay, and travel software.</p>\n<p><strong>Job Description</strong></p>\n<p>As a Senior Application Security Engineer, you will focus on finding and responding to security vulnerabilities across the Brex platform. You will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts</li>\n<li>Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features</li>\n<li>Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices</li>\n<li>Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization</li>\n</ul>\n<p><strong>Requirements</strong></p>\n<ul>\n<li>5+ years work experience in an Application Security or related role</li>\n<li>Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains</li>\n<li>Experience with a wide range of secure development activities including, threat modeling, developer education, and incident response</li>\n<li>Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity</li>\n<li>Collaborative mindset paired with strong written and verbal communication skills</li>\n</ul>\n<p><strong>Bonus Points</strong></p>\n<ul>\n<li>Proficiency with Kotlin, gRPC, GraphQL, Kubernetes</li>\n<li>Previous experience as a software engineer</li>\n<li>Consultancy experience performing web application security reviews</li>\n<li>Experience with securing distributed systems in AWS and cloud environments</li>\n<li>Experience with pentesting and securing agentic features and systems</li>\n<li>Contributions to the wider technical community, open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc</li>\n</ul>\n<p><strong>Compensation</strong></p>\n<p>The expected salary range for this role is $192,000 - $240,000 CAD. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b85fa3c5-892","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Brex","sameAs":"https://brex.com/","logo":"https://logos.yubhub.co/brex.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/brex/jobs/8249892002","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$192,000 - $240,000 CAD","x-skills-required":["Python","scripting languages","AI/agentic workflows","secure development activities","threat modeling","developer education","incident response"],"x-skills-preferred":["Kotlin","gRPC","GraphQL","Kubernetes"],"datePosted":"2026-04-18T15:50:15.407Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Vancouver, British Columbia, Canada"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"Python, scripting languages, AI/agentic workflows, secure development activities, threat modeling, developer education, incident response, Kotlin, gRPC, GraphQL, Kubernetes","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":192000,"maxValue":240000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_de168cba-02c"},"title":"Principal Software Engineer, Platform Security","description":"<p>We&#39;re looking for a principal-level engineer to serve as a technical leader for platform security across Anduril. This role combines deep expertise in cryptography, systems security, and secure architecture with the ability to drive security strategy across business lines and the platform.</p>\n<p>As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.</p>\n<p>Key Responsibilities:</p>\n<ul>\n<li>Own the technical vision and architecture for platform security across Anduril&#39;s product ecosystem</li>\n<li>Design cryptographic systems, protocols, and key management architectures for autonomous and robotic platforms operating in contested and disconnected environments</li>\n<li>Lead the design of hardware root-of-trust architectures integrating TPMs, TEEs, HSMs, and secure boot across diverse embedded platforms</li>\n<li>Drive the strategy for promoting business-line security implementations into shared, composable platform services</li>\n<li>Serve as the senior technical authority for security architecture reviews across the organization, providing definitive guidance on cryptographic design, protocol security, and system hardening</li>\n<li>Define security patterns, reference architectures, and engineering standards that enable teams across Anduril to build securely and independently</li>\n<li>Mentor and develop senior engineers on the team, raising the bar for security engineering across the organization</li>\n<li>Represent Anduril&#39;s security engineering capabilities to customers, partners, and auditors when deep technical credibility is required</li>\n<li>Evaluate emerging threats, cryptographic standards, and security technologies, driving adoption where they strengthen the platform</li>\n</ul>\n<p>Required Qualifications:</p>\n<ul>\n<li>12+ years of experience in software engineering, with significant depth in systems security and cryptography</li>\n<li>Expert-level knowledge of cryptographic protocol design, including key management architectures, certificate systems, and cryptographic agility</li>\n<li>Deep experience with hardware security: TPM, TEE, HSM, secure boot, and hardware root-of-trust design across multiple platform types</li>\n<li>Proficient in two or more of: C++, Rust, Go</li>\n<li>Experience designing security architectures for embedded, real-time, or robotic systems with constrained environments</li>\n<li>Track record of leading cross-organizational technical initiatives and driving architectural decisions that span multiple teams</li>\n<li>Strong ability to communicate complex security concepts to engineering leadership, product teams, and external stakeholders</li>\n<li>Experience performing and leading threat modeling, security architecture reviews, and cryptographic design reviews</li>\n<li>Eligible to obtain and maintain active U.S. Secret security clearance</li>\n</ul>\n<p>Preferred Qualifications:</p>\n<ul>\n<li>Experience with post-quantum cryptography, distributed key generation (DKG), or threshold cryptographic schemes</li>\n<li>Background in defense, aerospace, or autonomous systems with exposure to FIPS 140, Common Criteria, or NSA CSfC requirements</li>\n<li>Experience designing secure communication protocols for autonomous platforms or mesh networks</li>\n<li>Deep knowledge of Linux kernel security, mandatory access controls (SELinux/AppArmor), and OS hardening at scale</li>\n<li>Experience building and evolving platform security services consumed by dozens of teams</li>\n<li>Familiarity with compliance frameworks (STIGs, NIST 800-53, CMMC) and translating them into engineering controls that don&#39;t compromise developer velocity</li>\n<li>Publications, patents, or recognized contributions in cryptography or systems security</li>\n<li>Experience with Nix build systems and reproducible build pipelines for security-critical software</li>\n</ul>\n<p>US Salary Range: $254,000-$336,000 USD</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_de168cba-02c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anduril Industries","sameAs":"https://www.andurilindustries.com/","logo":"https://logos.yubhub.co/andurilindustries.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/andurilindustries/jobs/5087992007","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$254,000-$336,000 USD","x-skills-required":["cryptography","systems security","secure architecture","cryptographic protocol design","key management architectures","certificate systems","cryptographic agility","hardware security","TPM","TEE","HSM","secure boot","hardware root-of-trust design","embedded systems","real-time systems","robotic systems","constrained environments","cross-organizational technical initiatives","architectural decisions","complex security concepts","threat modeling","security architecture reviews","cryptographic design reviews","U.S. Secret security clearance"],"x-skills-preferred":["post-quantum cryptography","distributed key generation","threshold cryptographic schemes","defense","aerospace","autonomous systems","FIPS 140","Common Criteria","NSA CSfC requirements","secure communication protocols","mesh networks","Linux kernel security","mandatory access controls","OS hardening","compliance frameworks","STIGs","NIST 800-53","CMMC","publications","patents","recognized contributions","Nix build systems","reproducible build pipelines"],"datePosted":"2026-04-18T15:49:36.448Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Boston, Massachusetts, United States; Costa Mesa, California, United States; Seattle, Washington, United States; Washington, District of Columbia, United States"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"cryptography, systems security, secure architecture, cryptographic protocol design, key management architectures, certificate systems, cryptographic agility, hardware security, TPM, TEE, HSM, secure boot, hardware root-of-trust design, embedded systems, real-time systems, robotic systems, constrained environments, cross-organizational technical initiatives, architectural decisions, complex security concepts, threat modeling, security architecture reviews, cryptographic design reviews, U.S. Secret security clearance, post-quantum cryptography, distributed key generation, threshold cryptographic schemes, defense, aerospace, autonomous systems, FIPS 140, Common Criteria, NSA CSfC requirements, secure communication protocols, mesh networks, Linux kernel security, mandatory access controls, OS hardening, compliance frameworks, STIGs, NIST 800-53, CMMC, publications, patents, recognized contributions, Nix build systems, reproducible build pipelines","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":254000,"maxValue":336000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_3d7cf056-f6b"},"title":"Senior Application Security Engineer","description":"<p>As a Senior Application Security Engineer at Brex, you will focus on finding and responding to security vulnerabilities across the Brex platform. You will perform code reviews, design reviews, penetration testing, and vulnerability management. You will develop and maintain tooling to perform static and dynamic testing of the Brex platform and tooling which supports secure developer workflows.</p>\n<p>Application Security is part of our wider Financial Scale organization, which means you will work closely with Security Operations, GRC, Product Security, Front End Platform, IT Infrastructure teams.</p>\n<p>We’re looking for individuals with a strong background and interest in penetration testing. You should have a demonstrated ability to find vulnerabilities in complex systems and craft exploits to demonstrate business impact.</p>\n<p>This role is highly cross-functional and collaborative, you will have the opportunity to work with every engineering team across Brex.</p>\n<p>Building a world-class financial service requires world-class security. Brex is pioneering the next wave of AI-driven financial services for dynamic, high-impact companies like Coinbase, Robinhood, and Anthropic. We&#39;re at the early stages of integrating AI across our product suite, this role will have the opportunity to influence and secure the future of AI Security at Brex.</p>\n<p>You&#39;ll be at the forefront of securing our novel AI implementations, identifying attack vectors in agentic-powered features, and partnering with product and engineering teams to build AI capabilities that our customers can trust with their critical financial operations.</p>\n<p>Responsibilities: Identifying vulnerabilities, demonstrating business impact, and articulating the risk of specific vulnerabilities to drive prioritization efforts Perform penetration testing and design reviews, looking for vulnerabilities and insecure designs, work with engineering and product to design secure product features Maintain and build internal tools to automate security efforts, perform SAST and DAST testing of the Brex platform, and support secure development practices Build and contribute to a culture of collaborative security excellence through technical leadership, learning sessions, and mentorship within the team and wider organization</p>\n<p>Requirements: 5+ years work experience in an Application Security or related role Ability to find vulnerabilities in complex systems, demonstrating business impact through custom attack chains Experience with a wide range of secure development activities including, threat modeling, developer education, and incident response Knowledge of Python, scripting languages, and AI/agentic workflows to automate tasks, build tools and improve productivity Collaborative mindset paired with strong written and verbal communication skills</p>\n<p>Bonus points: Proficiency with Kotlin, gRPC, GraphQL, Kubernetes Previous experience as a software engineer Consultancy experience performing web application security reviews Experience with securing distributed systems in AWS and cloud environments Experience with pentesting and securing agentic features and systems Contributions to the wider technical community, open source, public research, mentorship, community organizing, blogging, CVEs, presentations, etc</p>\n<p>Compensation: The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_3d7cf056-f6b","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Brex","sameAs":"https://brex.com/","logo":"https://logos.yubhub.co/brex.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/brex/jobs/8249658002","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$192,000 - $240,000","x-skills-required":["Python","scripting languages","AI/agentic workflows","penetration testing","vulnerability management","secure development activities","threat modeling","developer education","incident response"],"x-skills-preferred":["Kotlin","gRPC","GraphQL","Kubernetes"],"datePosted":"2026-04-18T15:48:44.951Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, California, United States"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"Python, scripting languages, AI/agentic workflows, penetration testing, vulnerability management, secure development activities, threat modeling, developer education, incident response, Kotlin, gRPC, GraphQL, Kubernetes","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":192000,"maxValue":240000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_c97d7951-486"},"title":"Safeguards Policy Analyst, Fraud & Scams","description":"<p>As a Safeguards Policy Analyst focused on Fraud &amp; Scams, you will design, build, and execute enforcement workflows that detect and mitigate fraud and scam-related harms on Anthropic&#39;s products.</p>\n<p>This role sits within the Integrity &amp; Authenticity (I&amp;A) team, where you will function both as a policy owner and work closely with threat investigative and enforcement teams.</p>\n<p>Key responsibilities include drafting, maintaining, and iterating on Fraud &amp; Scams policies; conducting regular structured policy reviews; developing detailed threat models for fraud and scam vectors; and staying current on the fraud and scam landscape.</p>\n<p>You will also design and architect automated enforcement systems and human review workflows that scale effectively while maintaining high precision and recall.</p>\n<p>Additionally, you will serve as the primary policy point of contact for ML and Engineering teams developing fraud detection classifiers, working to translate policy intent into technical artifacts and training signals.</p>\n<p>You may be a good fit if you have experience working as a Trust &amp; Safety professional with a focused background in fraud, scams, or financial crime, particularly in a tech platform or AI context.</p>\n<p>Preferred qualifications include experience at a major technology platform, financial institution, or fraud intelligence firm in a policy, operations, or investigative capacity, familiarity with the generative AI risk landscape, and background in threat intelligence, financial crimes compliance (AML/KYC), or law enforcement focused on cyber-enabled fraud.</p>\n<p>The annual compensation range for this role is $245,000-$285,000 USD.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_c97d7951-486","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.co/","logo":"https://logos.yubhub.co/anthropic.co.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5174857008","x-work-arrangement":"hybrid","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$245,000-$285,000 USD","x-skills-required":["Fraud and scam policy design and implementation","Threat modeling and risk assessment","Automated enforcement system design and architecture","Policy translation and technical artifact development","Collaboration with ML and Engineering teams"],"x-skills-preferred":["Generative AI risk landscape knowledge","Threat intelligence and financial crimes compliance","Law enforcement and cyber-enabled fraud expertise"],"datePosted":"2026-04-18T15:46:56.104Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote-Friendly (Travel-Required) | San Francisco, CA | New York City, NY"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Fraud and scam policy design and implementation, Threat modeling and risk assessment, Automated enforcement system design and architecture, Policy translation and technical artifact development, Collaboration with ML and Engineering teams, Generative AI risk landscape knowledge, Threat intelligence and financial crimes compliance, Law enforcement and cyber-enabled fraud expertise","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":245000,"maxValue":285000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_a3a1df2f-184"},"title":"Principal Engineer, Software Supply Chain Security","description":"<p>As the Principal Engineer, Software Supply Chain Security, you&#39;ll own the technical strategy that secures how software is built and delivered on GitLab&#39;s DevSecOps platform. You&#39;ll provide architectural leadership across multiple engineering teams.</p>\n<p>Your work will shape GitLab&#39;s enterprise security posture in the rapidly growing software supply chain security market. You&#39;ll focus on SLSA Level 3 compliance, secrets management, CI/CD security hardening, and the foundations of GitLab&#39;s global zero trust architecture.</p>\n<p>Some examples of our projects:</p>\n<ul>\n<li>SLSA Level 3 compliance and provenance attestation across GitLab&#39;s CI/CD platform</li>\n<li>Integrated secrets management and runner security for container-isolated, secure pipelines</li>\n</ul>\n<p>You&#39;ll lead the end-to-end software supply chain security architecture for GitLab&#39;s CI/CD platform, including SLSA Level 3 implementation and CI infrastructure hardening. You&#39;ll drive cross-team technical strategy and decisions across our Software Supply Chain Security (SSCS) stage teams, aligning engineering work to SSCS strategic plans.</p>\n<p>You&#39;ll collaborate with infrastructure and CI/CD teams to design and land long-term initiatives for secure, scalable runner architecture, container isolation, and pipeline security at scale. You&#39;ll propose and validate technical implementations that support architectural changes to improve CI/CD scaling and performance on critical paths.</p>\n<p>You&#39;ll teach, mentor, and coach Staff Engineers and individual contributors, raising the bar on supply chain threat modeling, secrets management, artifact signing, and SBOM lifecycle practices.</p>\n<p>You&#39;ll partner with Engineering Managers and senior leadership to define roadmaps, break down complex initiatives, and enable Staff Engineers to lead sub-department-wide efforts.</p>\n<p>You&#39;ll engage with customers and external stakeholders as a technical consultant and spokesperson for GitLab&#39;s software supply chain security capabilities and roadmap.</p>\n<p>You&#39;ll collaborate with product, security, and compliance stakeholders to ensure features meet enterprise security, governance, and regulatory expectations in the software supply chain security market.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Providing architectural leadership across multiple engineering teams</li>\n<li>Shaping GitLab&#39;s enterprise security posture in the rapidly growing software supply chain security market</li>\n<li>Focusing on SLSA Level 3 compliance, secrets management, CI/CD security hardening, and the foundations of GitLab&#39;s global zero trust architecture</li>\n</ul>\n<p>Key requirements include:</p>\n<ul>\n<li>Deep expertise in software supply chain security, including threat modeling for supply chain attack vectors, SLSA implementation and attestation systems, and SBOM generation and lifecycle management</li>\n<li>Strong knowledge of artifact signing and verification using the Sigstore ecosystem, including Cosign, Fulcio, Rekor, and in-toto attestations</li>\n<li>Experience designing and hardening CI/CD security, such as runner isolation, pipeline security controls, and secrets management in large-scale environments</li>\n</ul>\n<p>Preferred qualifications include:</p>\n<ul>\n<li>Background in distributed systems and infrastructure, including building resilient CI/CD platforms that process high pipeline volumes and optimizing performance for critical paths</li>\n<li>Practical experience with container security and Kubernetes security, including admission controllers, policy controllers, workload isolation, and registry hardening</li>\n<li>Proficiency in Go or Rust in a production environment, combined with expert-level understanding of CI/CD workflows and DevSecOps best practices</li>\n<li>Experience operating as a Principal or Staff Engineer across multiple development teams, providing architectural leadership and partnering with Engineering Managers and senior leaders</li>\n<li>Demonstrated capacity to clearly communicate complex problems and solutions</li>\n</ul>\n<p>Our Software Supply Chain Security stage engineering teams are responsible for authentication and access within GitLab. We also build features that help customers manage vulnerabilities, dependencies, security policies, and compliance frameworks across their organizations.</p>\n<p>The base salary range for this role&#39;s listed level is currently for residents of the United States only. This range is intended to reflect the role&#39;s base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_a3a1df2f-184","directApply":true,"hiringOrganization":{"@type":"Organization","name":"GitLab","sameAs":"https://about.gitlab.com/","logo":"https://logos.yubhub.co/about.gitlab.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/gitlab/jobs/8373553002","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$157,900-$338,400 USD","x-skills-required":["software supply chain security","threat modeling","SLSA implementation","attestation systems","SBOM generation","lifecycle management","artifact signing","verification","Sigstore ecosystem","Cosign","Fulcio","Rekor","in-toto attestations","CI/CD security","runner isolation","pipeline security controls","secrets management","distributed systems","infrastructure","container security","Kubernetes security","admission controllers","policy controllers","workload isolation","registry hardening","Go","Rust","CI/CD workflows","DevSecOps best practices"],"x-skills-preferred":["background in distributed systems and infrastructure","practical experience with container security and Kubernetes security","proficiency in Go or Rust in a production environment","expert-level understanding of CI/CD workflows and DevSecOps best practices","experience operating as a Principal or Staff Engineer across multiple development teams"],"datePosted":"2026-04-18T15:45:22.426Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote, Canada; Remote, Israel; Remote, Netherlands; Remote, United Kingdom; Remote, US"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"software supply chain security, threat modeling, SLSA implementation, attestation systems, SBOM generation, lifecycle management, artifact signing, verification, Sigstore ecosystem, Cosign, Fulcio, Rekor, in-toto attestations, CI/CD security, runner isolation, pipeline security controls, secrets management, distributed systems, infrastructure, container security, Kubernetes security, admission controllers, policy controllers, workload isolation, registry hardening, Go, Rust, CI/CD workflows, DevSecOps best practices, background in distributed systems and infrastructure, practical experience with container security and Kubernetes security, proficiency in Go or Rust in a production environment, expert-level understanding of CI/CD workflows and DevSecOps best practices, experience operating as a Principal or Staff Engineer across multiple development teams","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":157900,"maxValue":338400,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_bdf949b3-c66"},"title":"Databricks Enterprise Lead Security Architect -   Principal IT Software Engineer","description":"<p>We are seeking a highly skilled Lead Security Architect to join our team within Databricks IT. As a Lead Security Architect, you will be responsible for designing and implementing a secure and scalable architecture to protect our corporate assets. You will focus on key areas of IT security, including Identity and Access Management, Zero Trust architecture, and endpoint security, while also working to secure critical business applications and sensitive data.</p>\n<p>Your expertise will be crucial in building proactive security strategies that align with our business goals and protect the company from an ever-evolving threat landscape. This position demands deep expertise in security principles and a comprehensive understanding of the entire infrastructure stack and IAM systems to design robust, future-ready security solutions.</p>\n<p>You will be instrumental in safeguarding our systems&#39; resilience and integrity against ever-evolving cyber threats. You will play a critical role in shaping our security strategy for modern platforms across AWS, Azure, GCP, network infrastructure, storage, and SaaS solutions, help establish a strong least privilege (PoLP) model, providing specialized IAM expertise, and securely supporting SaaS with sensitive information (NHI).</p>\n<p>You will also be a key contributor in building our internal strategy for secure AI development. Additionally, you will support the secure integration of SaaS platforms such as Google Workspace, collaboration tools, and GTM systems, maintaining alignment with enterprise security standards.</p>\n<p>Close collaboration with cross-functional teams is essential to embed security throughout the technology stack.</p>\n<p>The impact you will have:</p>\n<ul>\n<li>Design and implement secure, scalable reference architectures for the Databricks IT across Cloud Infra (Compute, DBs, Network, Storage), SaaS, Custom Built Applications, Data &amp; AI systems.</li>\n<li>Establish and enforce security controls for: Core Security Areas: - Databricks Workspace Management: Workspace isolation, Unity Catalog for data governance.</li>\n<li>Secure Networking: VPC configs, PrivateLink, IP Allow Lists.</li>\n<li>Identity and Access Management (IAM): SSO, SCIM user provisioning, RBAC via Un, Strong MFA best practices for enterprise identities and customers.</li>\n<li>Data Encryption: At rest and in transit, customer-managed keys for critical assets.</li>\n<li>Data Exfiltration Prevention: Admin console settings, VPC endpoint controls.</li>\n<li>Cluster Security: User isolation, compliance with enhanced security monitoring/Compliance Security Profiles (HIPAA, PCI-DSS, FedRAMP).</li>\n<li>Offensive Security: Test and challenge the effectiveness of the organization’s security defenses by mimicking the tactics, techniques, and procedures used by actual attackers.</li>\n<li>Specialized Security Functions: - Non-human Identity Management: Design and implement secure authentication and authorization for automated systems (service accounts, API keys, machine identities), focusing on automation and integration with existing identity management systems.</li>\n<li>IAM Best Practices: Develop and document comprehensive Identity and Access Management policies, including user provisioning, de-provisioning, access reviews, privileged access management, and multi-factor authentication, ensuring security and compliance.</li>\n<li>Data Loss Prevention (DLP): Implement DLP solutions to identify, monitor, and protect sensitive data across endpoints, networks, and cloud environments, preventing unauthorized access, use, or transmission.</li>\n<li>SaaS Proxy Design and Implementation: Design and implement cloud-based proxies for SaaS applications (SASE solutions) to provide secure access, enforce security policies, monitor user activity, and protect against threats.</li>\n<li>Cloud Infrastructure Best Practices: Establish and document best practices for VPC configurations, cloud networking, and infrastructure as code using Terraform, ensuring secure network segmentation, routing, firewalls, and VPNs for consistent, automated, and secure deployments.</li>\n<li>Least Privilege Access for Data Security: Design and implement data security controls based on the principle of least privilege, ensuring users and systems have only the minimum necessary access through fine-grained controls, data classification, and regular access reviews.</li>\n<li>Guide internal IT on Databricks’ security and compliance certifications (SOC 2, ISO 27001/27017/27018, HIPAA, PCI-DSS, FedRAMP), and support security reviews/audits.</li>\n<li>Support incident response, vulnerability management, threat modeling, and red teaming using audit logs, cluster policies, and enhanced monitoring.</li>\n<li>Stay current on industry trends and emerging threats in GenAI, AI Agentic flow, MCPs to enhance security posture.</li>\n<li>Advise executive leadership on security architecture, risks, and mitigation.</li>\n<li>Mentor security engineers and developers on secure design and best practices.</li>\n</ul>\n<p>What we look for:</p>\n<ul>\n<li>Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field</li>\n<li>Master’s degree in Computer Science specifically in Information Security or a related discipline is strongly preferred</li>\n<li>Minimum 12 years in cybersecurity, with 5+ in security architecture or senior technical roles.</li>\n<li>Experience in FedRAMP High systems/ GovCloud preferred.</li>\n<li>Must have direct experience designing and securing enterprise platforms in complex multi-cloud environments, deep knowledge of enterprise architecture and security features (control plane/data plane separation, network infra, workspace hardening, network segmentation/ isolation), and hands-on experience automating security controls with Terraform and scripting.</li>\n<li>Proven expertise securing data analytics pipelines, SaaS integrations, and workload isolation in enterprise ecosystems.</li>\n<li>Experience with Enterprise Security Analysis Tools and monitoring/security policy optimization.</li>\n<li>Deep experience in threat modeling, design, PoC, and implementing large-scale enterprise solutions.</li>\n<li>Extensive hands-on experience in AWS cloud security, network security, with knowledge of Zero Trust, Data Protection, and Appsec.</li>\n<li>Strong understanding of enterprise IAM systems (Okta, SailPoint, VDI, Entra ID) and Data Protection.</li>\n<li>Expert experience with SIEM platforms, XDR, and cloud-native threat detection tools.</li>\n<li>Expert in web application security, OWASP, API security, and secure design and testing.</li>\n<li>Hands-on experience with security automation is required, with proficiency in AI-assisted development, Python, Cursor, Lambda, Terraform, or comparable scripting/IaC tools for operational efficiency.</li>\n<li>Industry certifications like CISSP, CCSP, CEH, AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, or AWS Certified Advanced Networking – Specialty (or equivalent) are preferred.</li>\n<li>Ability to influence stakeholders and drive alignment.</li>\n<li>Strategic thinker with a passion for security innovation, continuous improvement, and building scalable defenses.</li>\n</ul>\n<p>Pay Range Transparency</p>\n<p>Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipates utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_bdf949b3-c66","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Databricks","sameAs":"https://databricks.com","logo":"https://logos.yubhub.co/databricks.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/databricks/jobs/8207910002","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Security Architecture","Identity and Access Management","Zero Trust","Endpoint Security","Data Encryption","Data Exfiltration Prevention","Cluster Security","Offensive Security","Non-human Identity Management","IAM Best Practices","Data Loss Prevention","SaaS Proxy Design and Implementation","Cloud Infrastructure Best Practices","Least Privilege Access for Data Security","Guide internal IT on Databricks’ security and compliance certifications","Support incident response, vulnerability management, threat modeling, and red teaming","Stay current on industry trends and emerging threats in GenAI, AI Agentic flow, MCPs","Advise executive leadership on security architecture, risks, and mitigation","Mentor security engineers and developers on secure design and best practices"],"x-skills-preferred":["Terraform","Python","Cursor","Lambda","AWS cloud security","Network security","Data Protection","Appsec","SIEM platforms","XDR","cloud-native threat detection tools","Web application security","OWASP","API security","Secure design and testing","AI-assisted development","Security automation","Scripting/IaC tools","CISSP","CCSP","CEH","AWS Certified Security – Specialty","AWS Certified Solutions Architect – Professional","AWS Certified Advanced Networking – Specialty"],"datePosted":"2026-04-18T15:45:19.828Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Mountain View, California; San Francisco, California"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Security Architecture, Identity and Access Management, Zero Trust, Endpoint Security, Data Encryption, Data Exfiltration Prevention, Cluster Security, Offensive Security, Non-human Identity Management, IAM Best Practices, Data Loss Prevention, SaaS Proxy Design and Implementation, Cloud Infrastructure Best Practices, Least Privilege Access for Data Security, Guide internal IT on Databricks’ security and compliance certifications, Support incident response, vulnerability management, threat modeling, and red teaming, Stay current on industry trends and emerging threats in GenAI, AI Agentic flow, MCPs, Advise executive leadership on security architecture, risks, and mitigation, Mentor security engineers and developers on secure design and best practices, Terraform, Python, Cursor, Lambda, AWS cloud security, Network security, Data Protection, Appsec, SIEM platforms, XDR, cloud-native threat detection tools, Web application security, OWASP, API security, Secure design and testing, AI-assisted development, Security automation, Scripting/IaC tools, CISSP, CCSP, CEH, AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional, AWS Certified Advanced Networking – Specialty"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_549fc0bc-10b"},"title":"Software Architect, Lifecycle Management","description":"<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>\n<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>\n<p>Okta is an enterprise-grade identity management platform, built from the ground up in the cloud and delivered with an unwavering focus on customer success. With Okta, organisations can manage access across any application, person or device. Whether the people are employees, partners or customers or the applications are in the cloud, on premises or on a mobile device, Okta helps organisations become more secure, make people more productive, and maintain compliance.</p>\n<p>The Okta platform provides directory services, single sign-on, strong authentication, provisioning, workflow, and built-in reporting. It runs in the cloud on a secure, reliable, extensively audited platform and integrates deeply with on-premises applications, directories, and identity management systems.</p>\n<p>We are looking for an experienced Principal Software Engineer to work on our Onboarding and Lifecycle Management (LCM) Platform team with focus on enhancing and managing services for importing, syncing and provisioning identities and access policies i.e., users, groups, roles, entitlements, etc. These features allow customers the flexibility to link and enhance their business processes with Okta’s identity management product.</p>\n<p>Ideal candidate should be Hands-on expert developer in Java who is deeply technical with a passion for building high-quality, secure, and performant applications and frameworks. Demonstrable experience leading technical projects involving more than 20 engineers across multiple workstreams Excited by the opportunity to work on cutting-edge security and identity management challenges and are a thought leader who can drive technical strategy and mentor other engineers.</p>\n<p>A collaborative individual with excellent communication skills, capable of working with cross-functional teams to deliver on a shared vision. Not just be a builder; but a force multiplier who can create frameworks and solutions that enable other teams to be more productive.</p>\n<p>This role is to build, design solutions, and maintain our platform for scale. The ideal candidate is someone who has experience building software systems to manage and deploy reliable and performant infrastructure and product code at scale on a cloud infrastructure.</p>\n<p>Job Duties And Responsibilities</p>\n<ul>\n<li>Work with senior engineering team in major development projects, design and implementation</li>\n<li>Lead the architectural design and implementation of new features and services, with a focus on scalability, performance, and security.</li>\n<li>Collaborate with product managers, architects, and other engineering teams to define the technical strategy and lead the prototyping of software components.</li>\n<li>Directly oversee and coordinate complex technical initiatives involving 20+ engineers, ensuring alignment across disparate sub-teams</li>\n<li>Drive a culture of engineering excellence and continuous improvement, with a focus on robust testing, monitoring, and operational excellence.</li>\n<li>Stay up-to-date with the latest industry trends and technologies in identity, security, and distributed systems.</li>\n<li>Partner with our Product Development, QA, and Site Reliability Engineering teams for scoping the development and deployment work.</li>\n</ul>\n<p>Required Knowledge, Skills, And Abilities</p>\n<ul>\n<li>The ideal candidate is someone who is experienced building software systems to manage and deploy reliable and performant infrastructure and product code at scale on a cloud infrastructure</li>\n<li>15+ years of Software Development in Java, preferably significant experience with Hibernate and Spring Boot</li>\n<li>A deep understanding of design patterns, scalability patterns, security engineering, and object-oriented principles.</li>\n<li>4+ years experience automating and deploying large scale production services in AWS, GCP or similar</li>\n<li>Deep understanding of infrastructure level technologies: caching, stream processing, resilient architectures.</li>\n<li>Experience working with relational databases, ideally MySQL, PostgreSQL or GraphDB</li>\n<li>Strong communication skills and the ability to work across functions, distributed teams.</li>\n<li>Lead and mentor junior engineers</li>\n</ul>\n<p>Nice to haves:</p>\n<ul>\n<li>Experience with server-side technologies including caching, asynchronous processing, and multi-threading.</li>\n<li>Experience with security best practices and threat modeling</li>\n<li>Knowledge of Identity and Access Management protocols and technologies: OAuth, OpenID Connect, SAML, SCIM</li>\n</ul>\n<p>Education</p>\n<ul>\n<li>B.E. Computer Science or equivalent</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_549fc0bc-10b","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7771673","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Java","Hibernate","Spring Boot","design patterns","scalability patterns","security engineering","object-oriented principles","AWS","GCP","caching","stream processing","resilient architectures","relational databases","MySQL","PostgreSQL","GraphDB","communication skills","leadership skills","mentoring skills"],"x-skills-preferred":["server-side technologies","asynchronous processing","multi-threading","security best practices","threat modeling","Identity and Access Management protocols","OAuth","OpenID Connect","SAML","SCIM"],"datePosted":"2026-04-18T15:44:29.840Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Bengaluru, India"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Java, Hibernate, Spring Boot, design patterns, scalability patterns, security engineering, object-oriented principles, AWS, GCP, caching, stream processing, resilient architectures, relational databases, MySQL, PostgreSQL, GraphDB, communication skills, leadership skills, mentoring skills, server-side technologies, asynchronous processing, multi-threading, security best practices, threat modeling, Identity and Access Management protocols, OAuth, OpenID Connect, SAML, SCIM"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_dc0287c3-e30"},"title":"Research Engineer / Scientist, Frontier Red Team (Cyber)","description":"<p><strong>About the Role</strong></p>\n<p>In the last year, we&#39;ve seen compelling signs that LLMs and agents are increasingly capable of novel cyber capabilities. We think 2026 will be the year where models reach expert-level, even superhuman, in several cybersecurity domains. This is a novel and massive threat surface.</p>\n<p>As a Research Scientist on FRT focusing on cyber, you&#39;ll build the tools and frameworks needed to defend the world against advanced AI-enabled cyber threats. Senior candidates will have the opportunity to shape and grow Anthropic&#39;s cyberdefense research program, working with Security, Safeguards, Policy, and other partner teams.</p>\n<p>This work sits at the intersection of AI capabilities research, cybersecurity, and policy,what we learn directly shapes how Anthropic and the world prepare for AI-enabled cyber threats. This is applied research with real-world stakes. Your work will inform decisions at the highest levels of the company, contribute to demonstrations that shape policy discourse, and build the technical defenses that we will need for a future of increasingly powerful AI systems.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Develop systems, tools, and frameworks for AI-empowered cybersecurity, such as autonomous vulnerability discovery and remediation, malware detection and management, network hardening, and pentesting</li>\n<li>Design and run experiments to elicit and evaluate autonomous AI cyber capabilities in realistic scenarios</li>\n<li>Design and build infrastructure for evaluating and enabling AI systems to operate in security environments</li>\n<li>Translate technical findings into compelling demonstrations and artifacts that inform policymakers and the public</li>\n<li>Collaborate with external experts in cybersecurity, national security, and AI safety to scope and validate research directions</li>\n</ul>\n<p><strong>Sample Projects</strong></p>\n<ul>\n<li>Building frameworks and tools that enable AI models to autonomously find and patch vulnerabilities</li>\n<li>Running purple-team simulations where AI defenders compete against AI attackers in network environments</li>\n<li>Pointing autonomous AI systems at real-world security challenges (bug bounties, CTFs etc.) to characterize risks, defensive potential, and compare to human experts</li>\n<li>Building demonstrations of frontier AI cyber capabilities for policy stakeholders</li>\n</ul>\n<p><strong>You May Be a Good Fit If You</strong></p>\n<ul>\n<li>Have deep expertise in cybersecurity or security research</li>\n<li>Are driven to find solutions to complex, high-stakes problems</li>\n<li>Have experience doing technical research with LLM-based agents or autonomous systems</li>\n<li>Have strong software engineering skills, particularly in Python</li>\n<li>Can own entire problems end-to-end, including both technical and non-technical components</li>\n<li>Design and run experiments quickly, iterating fast toward useful results</li>\n<li>Thrive in collaborative environments</li>\n<li>Care deeply about AI safety and want your work to have real-world impact on how humanity navigates advanced AI</li>\n<li>Are comfortable working on sensitive projects that require discretion and integrity</li>\n<li>Have proven ability to lead cross-functional security initiatives and navigate complex organizational dynamics</li>\n</ul>\n<p><strong>Strong Candidates May Also Have</strong></p>\n<ul>\n<li>Experience with offensive security research, vulnerability research, or exploit development</li>\n<li>Research or professional experience applying LLMs to security problems</li>\n<li>Track record in competitive CTFs, bug bounties, or other security-related competitions</li>\n<li>Experience building security tools or automation</li>\n<li>Track record of building demos or prototypes that communicate complex technical ideas</li>\n<li>Experience working with external stakeholders (policymakers, government, researchers)</li>\n<li>Familiarity with AI safety research and threat modeling for advanced AI systems</li>\n</ul>\n<p><strong>Logistics</strong></p>\n<p>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices. Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</p>\n<p><strong>How we&#39;re different</strong></p>\n<p>We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts. And we value impact , advancing our long-term goals of steerable, trustworthy AI , rather than work on smaller and more specific puzzles. We view AI research as an empirical science, which has as much in common with physics and biology as with traditional efforts in computer science. We&#39;re an extremely collaborative group, and we host frequent research discussions and workshops.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_dc0287c3-e30","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.com/","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5076477008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$320,000-$485,000 USD","x-skills-required":["cybersecurity","security research","LLM-based agents","autonomous systems","software engineering","Python","AI safety","threat modeling"],"x-skills-preferred":["offensive security research","vulnerability research","exploit development","research or professional experience applying LLMs to security problems","competitive CTFs","bug bounties","security tools or automation","demos or prototypes","external stakeholders","AI safety research"],"datePosted":"2026-04-18T15:43:56.704Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"cybersecurity, security research, LLM-based agents, autonomous systems, software engineering, Python, AI safety, threat modeling, offensive security research, vulnerability research, exploit development, research or professional experience applying LLMs to security problems, competitive CTFs, bug bounties, security tools or automation, demos or prototypes, external stakeholders, AI safety research","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":320000,"maxValue":485000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_cbaf9906-291"},"title":"Platform Hardware Security","description":"<p>We&#39;re seeking a Platform Hardware Security Engineer to design and implement security architectures for bare-metal infrastructure. You&#39;ll work with teams across Anthropic to build firmware, bootloaders, operating systems, and attestation systems to ensure the integrity of our infrastructure from the ground up.</p>\n<p>This role requires expertise in low-level systems security and the ability to architect solutions that balance security requirements with the performance demands of training AI models across our massive fleet.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Design and implement secure boot chains from firmware through OS initialization for diverse hardware platforms (CPUs, BMCs, switches, peripherals, and embedded microcontrollers)</li>\n</ul>\n<ul>\n<li>Architect attestation systems that provide cryptographic proof of system state from hardware root of trust through application layer</li>\n</ul>\n<ul>\n<li>Develop measured boot implementations and runtime integrity monitoring</li>\n</ul>\n<ul>\n<li>Create reference architectures and security requirements for bare-metal deployments</li>\n</ul>\n<ul>\n<li>Integrate security controls with infrastructure teams without impacting training performance</li>\n</ul>\n<ul>\n<li>Prototype and validate security mechanisms before production deployment</li>\n</ul>\n<ul>\n<li>Conduct firmware vulnerability assessments and penetration testing</li>\n</ul>\n<ul>\n<li>Build firmware analysis pipelines for continuous security monitoring</li>\n</ul>\n<ul>\n<li>Document security architectures and maintain threat models</li>\n</ul>\n<ul>\n<li>Collaborate with software and hardware vendors to ensure security capabilities meet our requirements</li>\n</ul>\n<p>Who you are:</p>\n<ul>\n<li>8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security (firmware, bootloaders, and OS-level security)</li>\n</ul>\n<ul>\n<li>Hands-on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone)</li>\n</ul>\n<ul>\n<li>Strong understanding of cryptographic protocols and hardware security modules</li>\n</ul>\n<ul>\n<li>Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain of trust implementation</li>\n</ul>\n<ul>\n<li>Proficiency in low-level programming (C, Rust, Assembly) and systems programming</li>\n</ul>\n<ul>\n<li>Knowledge of firmware vulnerability assessment and threat modeling</li>\n</ul>\n<ul>\n<li>Track record of designing security architectures for complex, distributed systems</li>\n</ul>\n<ul>\n<li>Experience with supply chain security</li>\n</ul>\n<ul>\n<li>Ability to work effectively across hardware and software boundaries</li>\n</ul>\n<ul>\n<li>Knowledge of NIST firmware security guidelines and hardware security frameworks</li>\n</ul>\n<p>Strong candidates may also have:</p>\n<ul>\n<li>Experience with confidential computing technologies and hardware-based TEEs</li>\n</ul>\n<ul>\n<li>Knowledge of SLSA framework and software supply chain security standards</li>\n</ul>\n<ul>\n<li>Experience securing large-scale HPC or cloud infrastructure</li>\n</ul>\n<ul>\n<li>Contributions to open-source security projects (coreboot, CHIPSEC, etc.)</li>\n</ul>\n<ul>\n<li>Background in formal verification or security proof techniques</li>\n</ul>\n<ul>\n<li>Experience with silicon root of trust implementations</li>\n</ul>\n<ul>\n<li>Experience working with building foundational technical designs, operational leadership, and vendor collaboration</li>\n</ul>\n<ul>\n<li>Previous work with AI/ML infrastructure security</li>\n</ul>\n<p>Annual Salary: $405,000-$485,000 USD</p>\n<p>Logistics:</p>\n<ul>\n<li>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience</li>\n</ul>\n<ul>\n<li>Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience</li>\n</ul>\n<ul>\n<li>Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position</li>\n</ul>\n<ul>\n<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>\n</ul>\n<ul>\n<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>\n</ul>\n<p>Why work with us?</p>\n<ul>\n<li>Competitive compensation and benefits</li>\n</ul>\n<ul>\n<li>Optional equity donation matching</li>\n</ul>\n<ul>\n<li>Generous vacation and parental leave</li>\n</ul>\n<ul>\n<li>Flexible working hours</li>\n</ul>\n<ul>\n<li>Lovely office space in which to collaborate with colleagues</li>\n</ul>\n<p>Guidance on Candidates&#39; AI Usage: Learn about our policy for using AI in our application process</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_cbaf9906-291","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.com/","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4929689008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$405,000-$485,000 USD","x-skills-required":["Secure boot","Measured boot","Attestation technologies","Cryptographic protocols","Hardware security modules","UEFI/BIOS or embedded firmware security","Bootloader hardening","Chain of trust implementation","Low-level programming","Systems programming","Firmware vulnerability assessment","Threat modeling","Supply chain security","NIST firmware security guidelines","Hardware security frameworks"],"x-skills-preferred":["Confidential computing technologies","Hardware-based TEEs","SLSA framework","Software supply chain security standards","Large-scale HPC or cloud infrastructure","Open-source security projects","Formal verification","Security proof techniques","Silicon root of trust implementations","Vendor collaboration","AI/ML infrastructure security"],"datePosted":"2026-04-18T15:43:00.394Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York City, NY | Seattle, WA; San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Secure boot, Measured boot, Attestation technologies, Cryptographic protocols, Hardware security modules, UEFI/BIOS or embedded firmware security, Bootloader hardening, Chain of trust implementation, Low-level programming, Systems programming, Firmware vulnerability assessment, Threat modeling, Supply chain security, NIST firmware security guidelines, Hardware security frameworks, Confidential computing technologies, Hardware-based TEEs, SLSA framework, Software supply chain security standards, Large-scale HPC or cloud infrastructure, Open-source security projects, Formal verification, Security proof techniques, Silicon root of trust implementations, Vendor collaboration, AI/ML infrastructure security","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":405000,"maxValue":485000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_27d6fab4-848"},"title":"Staff Product Security Engineer","description":"<p>Job Title: Staff Product Security Engineer</p>\n<p>Location: United States</p>\n<p>Department: Security</p>\n<p>Job Description:</p>\n<p>This role can be based remotely anywhere in the United States. The Product Security Team&#39;s mission is to left-shift SDLC (Security Development Lifecycle) processes for all code written in Databricks (for customer use or supporting customers internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.</p>\n<p>You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing, and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident.</p>\n<p>You will work with a global team, spread across various locations in the US and EMEA.</p>\n<p>The impact you will have:</p>\n<ul>\n<li>Full SDLC support for new product features being developed in ENG and non-ENG teams. This would include threat modeling, design review, manual code review, exploit writing, etc.</li>\n</ul>\n<ul>\n<li>Work with other security teams to provide support for incident response and vulnerability response as and when needed.</li>\n</ul>\n<ul>\n<li>Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.</li>\n</ul>\n<ul>\n<li>Work on DAST tools and related automation for auto-assessment and defect filing.</li>\n</ul>\n<ul>\n<li>Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPAA, etc.</li>\n</ul>\n<ul>\n<li>Prioritize security from a risk management perspective, rather than an absolute textbook version.</li>\n</ul>\n<ul>\n<li>Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general</li>\n</ul>\n<p>What we look for:</p>\n<ul>\n<li>3-10 years&#39; experience with the threat modeling process and ability to find design problems based on a block diagram of data flow.</li>\n</ul>\n<ul>\n<li>Solid understanding on at least two of the following domains: web security, cloud security, systems security, and applied cryptography.</li>\n</ul>\n<ul>\n<li>Proficient with one or more of programming languages (Python/Java/Scala/JavaScript) and ability to read code to identify security defects.</li>\n</ul>\n<ul>\n<li>Strong skills on scripting and automation on exploits.</li>\n</ul>\n<ul>\n<li>Fuzzing skills are good to have.</li>\n</ul>\n<ul>\n<li>Exploit writing skills are a positive and greatly required.</li>\n</ul>\n<p>Pay Range Transparency:</p>\n<p>Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above.</p>\n<p>For more information regarding which range your location is in visit our page here.</p>\n<p>Zone 1 Pay Range: $190,000 - $261,250 USD</p>\n<p>Zone 2 Pay Range: $171,000 - $235,200 USD</p>\n<p>Zone 3 Pay Range: $161,500 - $222,100 USD</p>\n<p>Zone 4 Pay Range: $152,000 - $209,000 USD</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_27d6fab4-848","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Databricks","sameAs":"https://databricks.com","logo":"https://logos.yubhub.co/databricks.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/databricks/jobs/7882009002","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$190,000 - $261,250 USD","x-skills-required":["threat modeling","security design reviews","manual code reviews","exploit writing","exploit chain creation","incident response","vulnerability response","SAST tools","DAST tools","automation","FedRamp","PCI","HIPAA","risk management","security processes","productivity","SDLC process","web security","cloud security","systems security","applied cryptography","programming languages","scripting","fuzzing"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:42:34.724Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"United States"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"threat modeling, security design reviews, manual code reviews, exploit writing, exploit chain creation, incident response, vulnerability response, SAST tools, DAST tools, automation, FedRamp, PCI, HIPAA, risk management, security processes, productivity, SDLC process, web security, cloud security, systems security, applied cryptography, programming languages, scripting, fuzzing","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":190000,"maxValue":261250,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_8bf116df-95e"},"title":"Application Security Engineer","description":"<p>Job Title: Application Security Engineer</p>\n<p>About the Role: The Application Security team at Anthropic is at the forefront of building security into every phase of the software development lifecycle. As an Application Security Engineer, you will partner closely with software engineers and researchers to ensure that security is a core consideration from initial design through implementation. You will lead threat modeling and secure design reviews to proactively identify and mitigate risks early, and help with continuous risk assessment. You will build tools and systems to support developers shipping code securely, adhering to secure coding best practices.</p>\n<p>Responsibilities:</p>\n<ul>\n<li>Help secure AI products and internal tools that are introducing industry-novel security risks and pushing established security boundaries</li>\n<li>Lead “shift left” security efforts to build security into the software development lifecycle</li>\n<li>Conduct secure design reviews and threat modeling. Identify and prioritize risks, attack surfaces, and vulnerabilities</li>\n<li>Develop tooling to scale security code reviews and respond to developer questions, including advising developers on remediating vulnerabilities and following secure coding practices</li>\n<li>Manage Anthropic&#39;s vulnerability management program, including integrating data ingestion pipelines, coding logic to prioritize vulnerability fixes, supporting teams remediating vulnerabilities and developing automated systems at scale</li>\n<li>Oversee Anthropic&#39;s bug bounty program. Set scope, validate submissions, perform root cause analysis, coordinate remediation with engineering teams, and award bounties. Cultivate relationships with the ethical hacker community</li>\n<li>Collaborate closely with product engineers and researchers to instill security best practices. Advocate for secure architecture, design, and development</li>\n<li>Develop and document security policies, standards, and playbooks. Conduct security awareness training for engineers</li>\n</ul>\n<p>Requirements:</p>\n<ul>\n<li>5+ years of hands-on experience in application and infrastructure security, including securing cloud-based and containerized environments</li>\n<li>Strong proficiency in at least one programming language (e.g., Python, Rust, Go, Java)</li>\n<li>Lead with empathy, a collaborative spirit, and a learning mindset to work cross-functionally with engineers of all levels to build security into the software development life cycle</li>\n<li>Leverage creative and strategic thinking to reduce risk through secure design and simplicity, not just controls</li>\n<li>Possess broad security knowledge to connect the dots across domains and identify holistic ways to decrease the overall threat surface</li>\n<li>Are keen to distill complex security concepts into clear actions and drive consensus without direct authority</li>\n<li>Embody a proactive mindset to thread security throughout the product lifecycle through activities like threat modeling, secure code review, and education</li>\n<li>Have a strong grasp of offensive security to anticipate risks from an adversary&#39;s perspective, not just check compliance boxes</li>\n<li>Bring experience with modern application stacks, infrastructure, and security tools to implement pragmatic defenses</li>\n<li>Are practiced at collaborating cross-functionally and effectively balancing security requirements with business objectives</li>\n<li>Advocate for security fundamentals like least privilege, defense-in-depth, and eliminating complexity that could sub-linearly scale security through smart design</li>\n</ul>\n<p>Preferred Qualifications:</p>\n<ul>\n<li>Hands-on technical expertise securing complex cloud environments and microservices architectures leveraging technologies like Kubernetes, Docker, and AWS / GCP</li>\n<li>Exposure to offensive security techniques like vulnerability testing, bug bounty, pen testing, and red team exercises</li>\n<li>Familiarity with AI/ML security risks such as prompt injection, data poisoning, model extraction, etc. and mitigations</li>\n<li>Experience building security tools, applications, and automated tools</li>\n<li>Solid foundational knowledge of both software and security engineering principles and are keen to continue learning</li>\n<li>Excellent communication skills, able to distill complex security topics for broad audiences</li>\n<li>Worked and thrived in fast-paced environments, and comfortable navigating ambiguity</li>\n</ul>\n<p>Annual Compensation Range:</p>\n<p>$300,000-$405,000 USD</p>\n<p>Logistics:</p>\n<ul>\n<li>Minimum education: Bachelor’s degree or an equivalent combination of education, training, and/or experience</li>\n<li>Required field of study: A field relevant to the role as demonstrated through coursework, training, or professional experience</li>\n<li>Minimum years of experience: Years of experience required will correlate with the internal job level requirements for the position</li>\n<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>\n<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>\n</ul>\n<p>How to Apply:</p>\n<p>If you&#39;re interested in this role, please submit your application through our website. We look forward to reviewing your application!</p>\n<p>Note:</p>\n<p>Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you&#39;re ever unsure about a communication, don&#39;t click any links,visit anthropic.com/careers directly for confirmed position openings.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_8bf116df-95e","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.com/","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4502508008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$300,000-$405,000 USD","x-skills-required":["application security","infrastructure security","cloud-based security","containerized environments","programming languages","Python","Rust","Go","Java","threat modeling","secure design reviews","vulnerability management","bug bounty program","security policies","standards","playbooks","security awareness training"],"x-skills-preferred":["hands-on technical expertise","complex cloud environments","microservices architectures","Kubernetes","Docker","AWS","GCP","offensive security techniques","vulnerability testing","pen testing","red team exercises","AI/ML security risks","prompt injection","data poisoning","model extraction","security tools","applications","automated tools","software engineering principles","communication skills"],"datePosted":"2026-04-18T15:35:09.635Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote-Friendly (Travel-Required) | San Francisco, CA | Seattle, WA | New York City, NY"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, infrastructure security, cloud-based security, containerized environments, programming languages, Python, Rust, Go, Java, threat modeling, secure design reviews, vulnerability management, bug bounty program, security policies, standards, playbooks, security awareness training, hands-on technical expertise, complex cloud environments, microservices architectures, Kubernetes, Docker, AWS, GCP, offensive security techniques, vulnerability testing, pen testing, red team exercises, AI/ML security risks, prompt injection, data poisoning, model extraction, security tools, applications, automated tools, software engineering principles, communication skills","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":300000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b284be7d-7d6"},"title":"Product Security Engineer","description":"<p>Meet Yubico: the creator of the most secure passkeys and leading provider of hardware authentication security keys. Our company’s mission is to make secure login easy and available for everyone.</p>\n<p>Yubico was founded in 2007 by Stina and Jakob Ehrensvard, and is public on Nasdaq Stockholm Main Market: YUBICO. Our customers include Fortune 500 companies, hundreds of government agencies and millions of individuals in over 160 countries that rely on Yubico technology to secure access to computers, online services and mobile apps.</p>\n<p>The Role: The Product Security team is responsible for ensuring Yubico develops and maintains secure products and services. As part of the Product Security team, your primary responsibility will be to collaborate with the firmware and software teams to design and integrate solutions that support secure design and development practices.</p>\n<p>Tasks &amp; Responsibilities:</p>\n<ul>\n<li>Define and evangelize requirements and guidance for secure by design and secure by default principles</li>\n<li>Implement automation to prevent and detect security flaws in all phases of development</li>\n<li>Conduct design reviews and manual security assessments</li>\n<li>Lead training and awareness sessions</li>\n<li>Define and implement metrics to provide visibility into the impact of your work</li>\n<li>Define, lead, and influence processes to secure products and services</li>\n<li>Identify and advocate for new and novel uses of Yubico’s technology</li>\n</ul>\n<p>Basic Qualifications:</p>\n<ul>\n<li>3+ years in a product security role</li>\n<li>3+ years of software development</li>\n<li>Proficiency in threat modeling</li>\n<li>Proficiency in C</li>\n<li>Knowledge of common vulnerability classes</li>\n<li>Experience in static code analysis</li>\n</ul>\n<p>Optional Skills and Experience:</p>\n<ul>\n<li>Knowledge of WebAuthn, OATH HOTP, OATH TOTP, U2F, PIV, or OpenPGP</li>\n<li>Proficiency in .NET or C++</li>\n<li>Experience developing for ARM</li>\n<li>Experience in targeted fuzzing</li>\n</ul>\n<p>Additional Information\nWe are an equal opportunity employer, we value diversity and uphold an inclusive environment where all people feel that they are equally respected and valued. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity or expression, age, marital status, religion, national origin, disability, protected Veteran status or any other characteristic protected by law.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b284be7d-7d6","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Yubico","sameAs":"https://www.yubico.com/","logo":"https://logos.yubhub.co/yubico.com.png"},"x-apply-url":"https://jobs.lever.co/yubico/646cd3ab-3be7-4987-a508-6bfdf83c71cc","x-work-arrangement":"remote","x-experience-level":"mid","x-job-type":"full-time","x-salary-range":"$120,000-140,000 per year","x-skills-required":["product security","software development","threat modeling","C","static code analysis"],"x-skills-preferred":["WebAuthn",".NET","C++","ARM","targeted fuzzing"],"datePosted":"2026-04-17T13:13:08.372Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Western US"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"product security, software development, threat modeling, C, static code analysis, WebAuthn, .NET, C++, ARM, targeted fuzzing","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":120000,"maxValue":140000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_5c7e46c8-c5c"},"title":"Application Security Intern","description":"<p>We&#39;re looking for a curious and motivated Application Security Intern to help us build secure products and development practices at VGS. As an Application Security Intern, you will partner with security and engineering teams to evaluate application risk, improve secure software development workflows, and help developers ship software safely in an environment that handles highly sensitive payment and identity data.</p>\n<p>Your responsibilities will include:</p>\n<ul>\n<li>Supporting application security reviews for services, APIs, and new product features across the VGS platform.</li>\n<li>Helping identify, validate, and track security findings from static analysis, dependency scanning, container scanning, and other security testing tools.</li>\n<li>Participating in threat modeling and secure design discussions with engineering teams during feature development.</li>\n<li>Evaluating the security of AI-enabled development workflows, including internal AI systems integrated into the SDLC.</li>\n<li>Assisting with manual testing and validation of web application and API security issues.</li>\n<li>Helping improve secure SDLC processes by contributing to developer guidance, secure coding resources, and repeatable review checklists.</li>\n<li>Working with engineers to understand remediation options and clearly document security risks and recommendations.</li>\n<li>Contributing to improving security tooling and guardrails in CI/CD and development workflows.</li>\n</ul>\n<p>We&#39;re looking for someone with a strong interest in secure software design, cloud-native architectures, and automation. You should have a foundational understanding of application security concepts, such as the OWASP Top 10, API security, authentication and authorization, secure coding, and common software vulnerabilities.</p>\n<p>At VGS, we have a remote-first philosophy, and we&#39;re looking for someone who is comfortable working independently and collaboratively as part of a team.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_5c7e46c8-c5c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"VGS","sameAs":"https://www.vgs.com","logo":"https://logos.yubhub.co/vgs.com.png"},"x-apply-url":"https://jobs.lever.co/verygoodsecurity/32fe92a6-13d5-4132-b77c-a7a5ed74f38b","x-work-arrangement":"remote","x-experience-level":"entry","x-job-type":"internship","x-salary-range":null,"x-skills-required":["application security","secure software development","cloud-native architectures","automation","OWASP Top 10","API security","authentication and authorization","secure coding","common software vulnerabilities"],"x-skills-preferred":["LMMs","threat modeling","Burp Suite","SAST/DAST tools","CI/CD pipelines","Docker/Kubernetes","cloud environments"],"datePosted":"2026-04-17T13:08:01.601Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"jobLocationType":"TELECOMMUTE","employmentType":"INTERN","occupationalCategory":"Engineering","industry":"Technology","skills":"application security, secure software development, cloud-native architectures, automation, OWASP Top 10, API security, authentication and authorization, secure coding, common software vulnerabilities, LMMs, threat modeling, Burp Suite, SAST/DAST tools, CI/CD pipelines, Docker/Kubernetes, cloud environments"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b417d598-574"},"title":"Lead Survivability Engineer","description":"<p>At Shield AI, we&#39;re building the most intelligent autonomous aircraft ever deployed. As we push the boundaries of what&#39;s possible in contested environments, we are looking for a Lead Survivability Engineer to shape and optimize the low observable (LO) performance of our next-generation autonomous aircraft.</p>\n<p>This role is ideal for an experienced engineer with deep expertise in radar cross-section (RCS) shaping, LO materials, and electromagnetic signature modeling who thrives in a fast-paced, mission-driven environment. You&#39;ll work across disciplines to ensure our aircraft can survive, evade, and complete missions in highly contested airspace.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n<li>Design and optimize low observable (LO) features across the airframe focusing on shaping, edge treatments, radar-absorbing materials, and subsystem integration.</li>\n<li>Conduct modeling and simulation of electromagnetic signatures using industry-standard tools such as HFSS, CST Studio Suite, Xpatch, and SENTRi.</li>\n<li>Work with multidisciplinary teams in propulsion, avionics, structures, and AI to ensure survivability is baked into the system architecture from day one.</li>\n<li>Lead or support signature testing efforts, including indoor and outdoor RCS range tests, validation campaigns, and supplier-level hardware evaluations.</li>\n<li>Translate mission threats and requirements into survivability features that address RCS, thermal, visual, and acoustic observability constraints.</li>\n<li>Partner with materials scientists to mature radar-absorbing coatings and structural RAM for manufacturability and field durability.</li>\n<li>Support internal and customer assessments, threat modeling reviews, and milestone decisions throughout the program lifecycle.</li>\n</ul>\n<p><strong>Requirements:</strong></p>\n<ul>\n<li>B.S. or M.S. in Aerospace Engineering, Electrical Engineering, Physics, or a related discipline.</li>\n<li>7+ years of hands-on experience in LO or survivability engineering, preferably on tactical aircraft, UAVs, or stealth systems.</li>\n<li>Proficiency with EM simulation tools such as HFSS, CST, Xpatch, or SENTRi.</li>\n<li>Strong understanding of RCS shaping principles, edge treatments, cavity suppression, and materials integration.</li>\n<li>Practical experience with LO testing methods and RCS measurement equipment.</li>\n<li>Familiarity with radar-absorbing materials (RAM), LO coatings, and structural LO trade studies.</li>\n<li>Solid collaboration and communication skills with the ability to work across design, test, and manufacturing teams.</li>\n<li>U.S. Citizenship and active Secret clearance required (TS/SCI preferred).</li>\n</ul>\n<p><strong>Preferred Qualifications:</strong></p>\n<ul>\n<li>Experience with military UAV platforms or 5th-gen fighter programs.</li>\n<li>Background in survivability analysis in contested environments (e.g., IADS, radar networks).</li>\n<li>Familiarity with platform CONOPS, threat modeling, and mission-level survivability assessments.</li>\n<li>Ability to contribute to the design, test, and fielding of a fully integrated LO platform.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b417d598-574","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Shield AI","sameAs":"https://www.shield.ai","logo":"https://logos.yubhub.co/shield.ai.png"},"x-apply-url":"https://jobs.lever.co/shieldai/0ea1cea2-6bb5-40e9-a3ca-c9ab45498454","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$168,476 - $252,714 a year","x-skills-required":["Radar Cross-Section (RCS) Shaping","Low Observable (LO) Materials","Electromagnetic Signature Modeling","HFSS","CST Studio Suite","Xpatch","SENRi","Low Observable (LO) Testing Methods","Radar-Absorbing Materials (RAM)","LO Coatings","Structural LO Trade Studies"],"x-skills-preferred":["Military UAV Platforms","5th-Gen Fighter Programs","Survivability Analysis in Contested Environments","Platform CONOPS","Threat Modeling","Mission-Level Survivability Assessments"],"datePosted":"2026-04-17T13:06:40.508Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Dallas"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Radar Cross-Section (RCS) Shaping, Low Observable (LO) Materials, Electromagnetic Signature Modeling, HFSS, CST Studio Suite, Xpatch, SENRi, Low Observable (LO) Testing Methods, Radar-Absorbing Materials (RAM), LO Coatings, Structural LO Trade Studies, Military UAV Platforms, 5th-Gen Fighter Programs, Survivability Analysis in Contested Environments, Platform CONOPS, Threat Modeling, Mission-Level Survivability Assessments","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":168476,"maxValue":252714,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b7c2d733-43f"},"title":"Principal Engineer, Survivability","description":"<p>At Shield AI, we&#39;re building the most intelligent autonomous aircraft ever deployed. As we push the boundaries of what&#39;s possible in contested environments, we are looking for a Survivability Engineer to shape and optimize the low observable (LO) performance of our next-generation autonomous aircraft.</p>\n<p>This role is ideal for an experienced engineer with expertise in radar cross-section (RCS) shaping, LO materials, and electromagnetic signature modeling who thrives in a fast-paced, mission-driven environment. You&#39;ll work across disciplines to ensure our aircraft can survive, evade, and complete missions in highly contested airspace.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n<li>Design and optimize low observable (LO) features across the airframe focusing on shaping, edge treatments, radar-absorbing materials, and subsystem integration.</li>\n<li>Conduct modeling and simulation of electromagnetic signatures using industry-standard tools such as HFSS, CST Studio Suite, Xpatch, and SENTRi.</li>\n<li>Work with multidisciplinary teams in propulsion, avionics, structures, and AI to ensure survivability is baked into the system architecture from day one.</li>\n<li>Lead or support signature testing efforts, including indoor and outdoor RCS range tests, validation campaigns, and supplier-level hardware evaluations.</li>\n<li>Translate mission threats and requirements into survivability features that address RCS, thermal, visual, and acoustic observability constraints.</li>\n<li>Partner with materials scientists to mature radar-absorbing coatings and structural RAM for manufacturability and field durability.</li>\n<li>Support internal and customer assessments, threat modeling reviews, and milestone decisions throughout the program lifecycle.</li>\n</ul>\n<p><strong>Requirements:</strong></p>\n<ul>\n<li>B.S. or M.S. in Aerospace Engineering, Electrical Engineering, Physics, or a related discipline.</li>\n<li>10+ years of hands-on experience in LO or survivability engineering, preferably on tactical aircraft, UAVs, or stealth systems.</li>\n<li>Proficiency with EM simulation tools such as HFSS, CST, Xpatch, or SENTRi.</li>\n<li>Strong understanding of RCS shaping principles, edge treatments, cavity suppression, and materials integration.</li>\n<li>Practical experience with LO testing methods and RCS measurement equipment.</li>\n<li>Familiarity with radar-absorbing materials (RAM), LO coatings, and structural LO trade studies.</li>\n<li>Solid collaboration and communication skills with the ability to work across design, test, and manufacturing teams.</li>\n<li>U.S. Citizenship and active Secret clearance required.</li>\n</ul>\n<p><strong>Preferred Qualifications:</strong></p>\n<ul>\n<li>Experience with military UAV platforms or 5th-gen fighter programs.</li>\n<li>Background in survivability analysis in contested environments (e.g., IADS, radar networks).</li>\n<li>Familiarity with platform CONOPS, threat modeling, and mission-level survivability assessments.</li>\n<li>Ability to contribute to the design, test, and fielding of a fully integrated LO platform.</li>\n<li>Active Top Secret or SCI clearance.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b7c2d733-43f","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Shield AI","sameAs":"https://www.shield.ai","logo":"https://logos.yubhub.co/shield.ai.png"},"x-apply-url":"https://jobs.lever.co/shieldai/0d1400ec-f456-4d5b-8592-740a656260b0","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$200,000 - $310,000 a year","x-skills-required":["Radar Cross-Section (RCS) Shaping","Low Observable (LO) Materials","Electromagnetic Signature Modeling","HFSS","CST Studio Suite","Xpatch","SENRi","Collaboration","Communication"],"x-skills-preferred":["Military UAV Platforms","5th-Gen Fighter Programs","Survivability Analysis","Platform CONOPS","Threat Modeling","Mission-Level Survivability Assessments"],"datePosted":"2026-04-17T13:03:40.793Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Diego"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Radar Cross-Section (RCS) Shaping, Low Observable (LO) Materials, Electromagnetic Signature Modeling, HFSS, CST Studio Suite, Xpatch, SENRi, Collaboration, Communication, Military UAV Platforms, 5th-Gen Fighter Programs, Survivability Analysis, Platform CONOPS, Threat Modeling, Mission-Level Survivability Assessments","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":200000,"maxValue":310000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_eec951b9-d96"},"title":"Security Engineer","description":"<p>We&#39;re seeking a Security Engineer at the senior-level or above to own the product security and authorization lifecycle for Saronic&#39;s autonomous surface vessels. You will serve as the responsible security engineer for one or more vessel programs, owning the security posture from design through production, authorization, and operational deployment.</p>\n<p>This is a hands-on security engineering role; not a GRC or project management role. You&#39;ll identify the frameworks that apply, architect the vessel&#39;s security to satisfy them, and drive authorization to completion. Where standards don&#39;t yet exist, you&#39;ll define them.</p>\n<p>Key Responsibilities:</p>\n<ul>\n<li>Own the security posture for one or more vessel programs from architecture through fielding, serving as the responsible security engineer for the product</li>\n<li>Drive threat modeling across vessel subsystems including embedded compute, communications, navigation, propulsion controls, sensor fusion, and C2 interfaces and define security architectures, trust boundaries, and segmentation strategies based on findings</li>\n<li>Identify and mitigate security risks unique to autonomous maritime platforms, including GPS/GNSS spoofing, RF interference, sensor manipulation, supply chain compromise, and physical access threats</li>\n<li>Own the end-to-end authorization lifecycle for vessel programs, from initial security planning through ATO or equivalent customer authorization milestones</li>\n<li>Navigate DoD cybersecurity authorization frameworks including RMF, CSRMC, and service-specific requirements across Navy, Coast Guard, Marine Corps, and joint programs</li>\n<li>Prepare and maintain authorization artifacts, security documentation, and evidence packages that satisfy Authorizing Officials and program offices</li>\n<li>Identify and map applicable compliance frameworks for each vessel and customer segment including NIST SP 800-53, NIST SP 800-171, CMMC 2.0, FedRAMP, IEC 62443, IMO MASS Code, and IACS UR E26/E27 and proactively define Saronic&#39;s compliance posture where standards are still emerging</li>\n<li>Engage directly with government program offices, Authorizing Officials, DOT&amp;E evaluators, and classification societies as a credible technical representative of Saronic&#39;s security posture</li>\n<li>Support cybersecurity testing and evaluation efforts, including preparation for operational test events, red team assessments, and cooperative vulnerability assessments</li>\n<li>Partner with supply chain and manufacturing teams to address hardware provenance, firmware integrity, and anti-tamper requirements for production vessels</li>\n<li>Work with Legal and Contracts to ensure security and compliance requirements are accurately reflected in customer agreements, proposals, and contract deliverables</li>\n</ul>\n<p>Required Qualifications:</p>\n<ul>\n<li>6+ years of hands-on experience in product security, systems security engineering, authorization engineering, or a closely related security engineering role for defense or high-assurance platforms</li>\n<li>Strong understanding of DoD cybersecurity authorization processes (RMF, ATO/IATT, CSRMC, continuous ATO) with experience contributing to or driving systems through authorization</li>\n<li>Working knowledge of NIST SP 800-53, NIST SP 800-171, and CMMC 2.0 and their application to weapons systems, autonomous platforms, or similarly complex defense products</li>\n<li>Experience with threat modeling, security architecture, or risk assessment for cyber-physical systems, embedded systems, or operational technology environments</li>\n<li>Strong technical foundation, able to read architecture diagrams, evaluate security controls at a systems level, and hold credible technical conversations with hardware, software, and cloud engineers</li>\n<li>Ability to clearly communicate with both technical and non-technical stakeholders, including production of security documentation and authorization artifacts</li>\n<li>Ownership mindset with the ability to operate in ambiguity, define the path forward, and move work to completion across teams</li>\n<li>Ability to obtain and maintain a security clearance</li>\n</ul>\n<p>Preferred Qualifications:</p>\n<ul>\n<li>Experience as a product security lead, systems security engineer, or authorization lead for a defense platform or program of record</li>\n<li>Direct experience engaging with government Authorizing Officials, program offices, or DOT&amp;E as a technical security representative</li>\n<li>Experience in defense technology startups, DARPA programs, or organizations that move at speed within the defense acquisition system</li>\n<li>Familiarity with maritime-specific frameworks including IMO MASS Code, IACS UR E26/E27, IEC 62443, or classification society autonomous vessel rules</li>\n<li>Understanding of autonomous systems security challenges including communications security, electronic warfare hardening, GPS/GNSS resilience, and AI/ML system security</li>\n<li>Experience with ITAR/EAR compliance, supply chain security, or manufacturing security for defense products</li>\n<li>Familiarity with the defense acquisition lifecycle and how authorization milestones integrate into program schedules</li>\n</ul>\n<p>Additional Information:</p>\n<ul>\n<li>Benefits: Medical Insurance, Dental and Vision Insurance, Time Off, Parental Leave, Competitive Salary, Retirement Plan, Stock Options, Life and Disability Insurance, Pet Insurance</li>\n<li>This role requires access to export-controlled information or items that require “U.S. Person” status.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_eec951b9-d96","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Saronic Technologies","sameAs":"https://www.saronictech.com/","logo":"https://logos.yubhub.co/saronictech.com.png"},"x-apply-url":"https://jobs.lever.co/saronic/6e800df8-6173-4f13-863e-b8803017f317","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["product security","systems security engineering","authorization engineering","threat modeling","security architecture","risk assessment","cyber-physical systems","embedded systems","operational technology environments","NIST SP 800-53","NIST SP 800-171","CMMC 2.0","RMF","CSRMC","ATO/IATT","continuous ATO","FedRAMP","IEC 62443","IMO MASS Code","IACS UR E26/E27"],"x-skills-preferred":["product security lead","systems security engineer","authorization lead","defense platform","program of record","government Authorizing Officials","program offices","DOT&E","technical security representative","defense technology startups","DARPA programs","organizations","defense acquisition system","maritime-specific frameworks","ITAR/EAR compliance","supply chain security","manufacturing security"],"datePosted":"2026-04-17T12:58:42.019Z","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"product security, systems security engineering, authorization engineering, threat modeling, security architecture, risk assessment, cyber-physical systems, embedded systems, operational technology environments, NIST SP 800-53, NIST SP 800-171, CMMC 2.0, RMF, CSRMC, ATO/IATT, continuous ATO, FedRAMP, IEC 62443, IMO MASS Code, IACS UR E26/E27, product security lead, systems security engineer, authorization lead, defense platform, program of record, government Authorizing Officials, program offices, DOT&E, technical security representative, defense technology startups, DARPA programs, organizations, defense acquisition system, maritime-specific frameworks, ITAR/EAR compliance, supply chain security, manufacturing security"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_c629a0da-f6c"},"title":"Security Engineer","description":"<p>We&#39;re seeking a Security Engineer at the senior-level or above focused on hardware, embedded systems, and firmware security to own the security posture of Saronic&#39;s vessel hardware platforms from silicon to system.</p>\n<p>You will be the technical authority on hardware root of trust, secure boot, firmware integrity, embedded system hardening, and the security of third-party hardware integrations. Your work ensures that every component on the vessel is resilient against tampering, exploitation, and supply chain compromise, designed in from the start and maintained across the fleet lifecycle.</p>\n<p>Key Responsibilities:</p>\n<ul>\n<li><p>Conduct hardware security assessments including fault injection, side-channel analysis, interface evaluation, and bus protocol analysis across Saronic-built and third-party hardware including sensors, radios, navigation systems, propulsion controllers, and communication modules</p>\n</li>\n<li><p>Evaluate and harden physical interfaces, debug ports, maintenance access points, and removable media interfaces on vessel hardware</p>\n</li>\n<li><p>Evaluate supply chain security risks for hardware components and recommend provenance validation, anti-tamper, and attestation controls</p>\n</li>\n<li><p>Develop and maintain a hardware security testing capability including tooling, methodology, and repeatable test procedures</p>\n</li>\n<li><p>Design and implement secure boot chains establishing hardware root of trust from power-on through application launch, integrating TPM, secure elements, and HSMs for device identity, key storage, measured boot, and remote attestation</p>\n</li>\n<li><p>Design and implement secure firmware update mechanisms including signed updates, rollback protection, and verified delivery across the fleet</p>\n</li>\n<li><p>Own the cryptographic key lifecycle for hardware-bound keys, including provisioning, rotation, revocation, and escrow</p>\n</li>\n<li><p>Harden embedded Linux systems on vessel platforms, including kernel configuration, mandatory access controls, secure IPC, and attack surface reduction</p>\n</li>\n<li><p>Secure operational technology protocols and interfaces used in vessel control systems, propulsion, navigation, and sensor fusion including CAN bus, NMEA, and maritime/industrial communication protocols</p>\n</li>\n<li><p>Define security boundaries, trust zones, and segmentation strategies for vessel-internal compute and communication architectures</p>\n</li>\n<li><p>Drive threat modeling across vessel hardware subsystems and translate findings into actionable engineering requirements</p>\n</li>\n<li><p>Produce secure-by-design reference architectures and define hardware and firmware security standards, testing requirements, and acceptance criteria integrated into engineering workflows</p>\n</li>\n</ul>\n<p>Required Qualifications:</p>\n<ul>\n<li><p>6+ years of hands-on experience in hardware security, embedded systems security, firmware security, or a closely related security engineering role</p>\n</li>\n<li><p>Deep expertise in hardware hacking techniques including fault injection, side-channel attacks, JTAG/SWD exploitation, bus sniffing/injection, and physical security assessments</p>\n</li>\n<li><p>Demonstrated experience designing and implementing secure boot chains, hardware root of trust, and secure firmware update mechanisms in production systems</p>\n</li>\n<li><p>Strong experience assessing third-party hardware integrations and evaluating supply chain security risks</p>\n</li>\n<li><p>Deep knowledge of embedded Linux security hardening, kernel security, and mandatory access control frameworks</p>\n</li>\n<li><p>Experience with operational technology security, industrial protocols, or control system security</p>\n</li>\n<li><p>Proficiency in C, C++, Python, or Rust in the context of firmware, embedded, or systems-level security work, and with hardware security testing tools</p>\n</li>\n<li><p>Ability to obtain and maintain a security clearance</p>\n</li>\n</ul>\n<p>Preferred Qualifications:</p>\n<ul>\n<li><p>Experience in defense, aerospace, robotics, autonomy, maritime, or other high-assurance environments</p>\n</li>\n<li><p>Experience with autonomous systems, unmanned vehicles, or safety-critical embedded platforms</p>\n</li>\n<li><p>Experience with RTOS, microcontroller security, or resource-constrained device environments</p>\n</li>\n<li><p>Knowledge of CAN bus, NMEA protocols, maritime communication systems, RF/GPS/GNSS security, or ICS security standards</p>\n</li>\n<li><p>Familiarity with defense or safety-critical compliance frameworks (NIST SP 800-53, IEC 62443, Common Criteria, or equivalent)</p>\n</li>\n<li><p>Relevant certifications such as OSEE, GXPN, GSE, or hardware-focused credentials</p>\n</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_c629a0da-f6c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Saronic Technologies","sameAs":"https://www.saronictechnologies.com/","logo":"https://logos.yubhub.co/saronictechnologies.com.png"},"x-apply-url":"https://jobs.lever.co/saronic/4b15b1b4-3c34-47ad-b964-dbcf0f8a3dc4","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Hardware security","Embedded systems security","Firmware security","Fault injection","Side-channel analysis","Interface evaluation","Bus protocol analysis","Physical security assessments","Secure boot chains","Hardware root of trust","Firmware integrity","Embedded system hardening","Third-party hardware integrations","Supply chain security risks","Provenance validation","Anti-tamper","Attestation controls","Hardware security testing","Tooling","Methodology","Repeatable test procedures","Device identity","Key storage","Measured boot","Remote attestation","Signed updates","Rollback protection","Verified delivery","Cryptographic key lifecycle","Provisioning","Rotation","Revocation","Escrow","Embedded Linux systems","Kernel configuration","Mandatory access controls","Secure IPC","Attack surface reduction","Operational technology protocols","Industrial protocols","Control system security","CAN bus","NMEA","Maritime/industrial communication protocols","Security boundaries","Trust zones","Segmentation strategies","Threat modeling","Actionable engineering requirements","Secure-by-design reference architectures","Hardware and firmware security standards","Testing requirements","Acceptance criteria","Engineering workflows","C","C++","Python","Rust","Hardware security testing tools"],"x-skills-preferred":["Defense","Aerospace","Robotics","Autonomy","Maritime","High-assurance environments","Autonomous systems","Unmanned vehicles","Safety-critical embedded platforms","RTOS","Microcontroller security","Resource-constrained device environments","NMEA protocols","Maritime communication systems","RF/GPS/GNSS security","ICS security standards","Defense or safety-critical compliance frameworks","OSEE","GXPN","GSE","Hardware-focused credentials"],"datePosted":"2026-04-17T12:57:49.070Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Hardware security, Embedded systems security, Firmware security, Fault injection, Side-channel analysis, Interface evaluation, Bus protocol analysis, Physical security assessments, Secure boot chains, Hardware root of trust, Firmware integrity, Embedded system hardening, Third-party hardware integrations, Supply chain security risks, Provenance validation, Anti-tamper, Attestation controls, Hardware security testing, Tooling, Methodology, Repeatable test procedures, Device identity, Key storage, Measured boot, Remote attestation, Signed updates, Rollback protection, Verified delivery, Cryptographic key lifecycle, Provisioning, Rotation, Revocation, Escrow, Embedded Linux systems, Kernel configuration, Mandatory access controls, Secure IPC, Attack surface reduction, Operational technology protocols, Industrial protocols, Control system security, CAN bus, NMEA, Maritime/industrial communication protocols, Security boundaries, Trust zones, Segmentation strategies, Threat modeling, Actionable engineering requirements, Secure-by-design reference architectures, Hardware and firmware security standards, Testing requirements, Acceptance criteria, Engineering workflows, C, C++, Python, Rust, Hardware security testing tools, Defense, Aerospace, Robotics, Autonomy, Maritime, High-assurance environments, Autonomous systems, Unmanned vehicles, Safety-critical embedded platforms, RTOS, Microcontroller security, Resource-constrained device environments, NMEA protocols, Maritime communication systems, RF/GPS/GNSS security, ICS security standards, Defense or safety-critical compliance frameworks, OSEE, GXPN, GSE, Hardware-focused credentials"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_abafedbd-d92"},"title":"CyberSecurity Engineer, DevSecOps","description":"<p>About Mistral At Mistral AI, we believe in the power of AI to simplify tasks, save time, and enhance learning and creativity. Our technology is designed to integrate seamlessly into daily working life. We democratize AI through high-performance, optimized, open-source and cutting-edge models, products and solutions. Our comprehensive AI platform is designed to meet enterprise needs, whether on-premises or in cloud environments. Our offerings include le Chat, the AI assistant for life and work. We are a team passionate about AI and its potential to transform society. Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between France, USA, UK, Germany and Singapore. We are creative, low-ego and team-spirited. Join us to be part of a pioneering company shaping the future of AI. Together, we can make a meaningful impact.</p>\n<p>Role summary Mistral AI is looking for a DevSecOps Engineer to architect and maintain the security posture of our rapidly scaling AI infrastructure and application lifecycle. You will treat security as a seamless enabler for our research and engineering teams. Your objective is to embed robust security controls into our CI/CD pipelines, infrastructure environments, and developer workflows, without compromising deployment velocity.</p>\n<p>Responsibilities\n• Drive threat modeling and risk prioritization exercises, serving as the security counterpart to system-design reviews for our core infrastructure and new products.\n• Own end-to-end vulnerability management across CI/CD pipelines and runtime environments, covering both underlying infrastructure and applications.\n• Secure our Kubernetes deployments and containerized workloads, implementing advanced pod and node hardening to prevent lateral movement across distributed systems.\n• Define and enforce Infrastructure-as-Code security by building robust Terraform guardrails and integrating policy-as-code directly into deployment pipelines.\n• Design and execute a comprehensive security tooling strategy, managing solutions for CNAPP, CSPM, SAST, SCA, secrets management, and SBOM-CVE tracking.\n• Champion developer enablement by building secure defaults, streamlining remediation workflows, and drafting actionable security guidelines.\n• Build foundational security automation to scale alongside hyper-growth, minimizing manual overhead while establishing a pragmatic security culture from the ground up.</p>\n<p>About you\n• 5+ years of experience in DevSecOps, Security Engineering, or Cloud Security, ideally acting as an early security hire in a fast-paced or hyper-scale environment.\n• Deep understanding of Kubernetes and container security, alongside strong experience securing Infrastructure-as-Code (Terraform) across major cloud providers.\n• Strong programming and scripting skills (Python, Go, or similar) to build security automation and seamlessly integrate diverse security tools into the developer workflow.\n• Extensive experience deploying and tuning modern security tooling with a pragmatic approach to vulnerability management and threat modeling.\n• Strong communication skills with a proven track record of partnering with developers and researchers to embed secure defaults without creating engineering friction.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_abafedbd-d92","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Mistral AI","sameAs":"https://mistral.ai","logo":"https://logos.yubhub.co/mistral.ai.png"},"x-apply-url":"https://jobs.lever.co/mistral/94a331c8-0ddf-4e88-a6ad-7a70c212e0fa","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Kubernetes","container security","Infrastructure-as-Code","Terraform","DevSecOps","security engineering","cloud security","Python","Go","security automation","vulnerability management","threat modeling"],"x-skills-preferred":[],"datePosted":"2026-04-17T12:46:54.417Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Paris"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Kubernetes, container security, Infrastructure-as-Code, Terraform, DevSecOps, security engineering, cloud security, Python, Go, security automation, vulnerability management, threat modeling"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ace25108-b9c"},"title":"Staff Product Security Engineer","description":"<p>We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. As a Staff Product Security Engineer, you will be responsible for the end-to-end security of our consumer products, digital platform, and emerging hardware device line.</p>\n<p>Your day-to-day will involve leading security architecture/design review and threat modeling sessions with product and engineering teams, translating threats into actionable, risk-rated engineering remediations prioritized by severity, conducting hands-on penetration testing and security assessments across our full product stack, and driving PSIRT operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers, and on-call incidents.</p>\n<p>You will also shape the posture of our AI-assisted development environment, defining and enforcing enterprise policies for Claude and Cursor, and partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features, briefing executives on emerging AI threats, mentoring junior security engineers, and collaborating with the AI team on securing ML pipelines.</p>\n<p>As a champion of security culture, you will run developer training on secure coding with AI assistants, evangelize security by design for products, and ensure every engineer understands that product security is an enabler and not a gate.</p>\n<p>You will bring 10+ years of product security experience spanning application security, cloud security, and secure SDLC, expert-level threat modeling using STRIDE, PASTA, or equivalent across web, mobile, cloud, embedded, and AI systems, hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware, and deep hands-down AI security expertise and expert-level understanding of OWASP Top 10 for LLM, API, Web, Mobile, and practical experience with MITRE.</p>\n<p>You will have strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor, and understand MCP security risks and know how to architect enterprise guardrails that enable safe AI-assisted development.</p>\n<p>You will also have strong programming ability and capability to review code, build security tools, automate workflows, and be credible with the engineering teams you partner with.</p>\n<p>Preferred experience includes hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience, and experience in the Financial industry, knowledge of PCI DSS, COPPA, or demonstrated ability to learn regulated domains quickly.</p>\n<p>Work perks at Greenlight include medical, dental, vision, and HSA match, paid life insurance, AD&amp;D, and disability benefits, traditional 401k with company match, unlimited PTO, paid company holidays and pop-up bonus holidays, professional development stipends, mental health resources, 1:1 financial planners, fertility healthcare, 100% paid parental and caregiving leave, plus cleaning service and meals during your leave, flexible WFH, both remote and in-office opportunities, fully stocked kitchen, catered lunches, and occasional in-office happy hours, and employee resource groups.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ace25108-b9c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Greenlight","sameAs":"https://www.greenlight.com/","logo":"https://logos.yubhub.co/greenlight.com.png"},"x-apply-url":"https://jobs.lever.co/greenlight/18b7ac30-dbf6-4078-bf50-06772c47fdc7","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$165,000-200,000","x-skills-required":["product security","application security","cloud security","secure SDLC","threat modeling","penetration testing","security assessments","PSIRT operations","AI security","OWASP Top 10","MITRE","SAST","DAST","SCA","Claude","Cursor","MCP security","firmware integrity","hardware root of trust","IoT threat modeling"],"x-skills-preferred":["hardware and embedded security","PCI DSS","COPPA"],"datePosted":"2026-04-17T12:35:45.706Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Atlanta"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"product security, application security, cloud security, secure SDLC, threat modeling, penetration testing, security assessments, PSIRT operations, AI security, OWASP Top 10, MITRE, SAST, DAST, SCA, Claude, Cursor, MCP security, firmware integrity, hardware root of trust, IoT threat modeling, hardware and embedded security, PCI DSS, COPPA","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":165000,"maxValue":200000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_576661da-536"},"title":"Member of Technical Staff, Security Engineering","description":"<p>At Anchorage Digital, we are building the world’s most advanced digital asset platform for institutions to participate in crypto.\\n\\nWe are seeking a highly skilled Member of Technical Staff, Security Engineering to join our team. This role will be responsible for developing and implementing high-quality, secure code for cryptographic controls throughout our infrastructure.\\n\\nKey Responsibilities:\\n\\n* Develop and implement high-quality, secure code for cryptographic controls throughout our infrastructure.\\n* Review code throughout the technology stack and help engineering teams resolve issues related to security guardrails.\\n* Foster an efficient testing culture while reducing technical debt and unnecessary processes.\\n\\nComplexity and Impact of Work:\\n\\n* Build robust, resilient components that are easily integrated by other teams to ensure asset and data security.\\n* Develop and maintain threat models for cryptosystem guarantees, both internal and external.\\n* Monitor technical debt and proactively identify areas for improvement.\\n* Lead or substantially contribute to medium and large Security Team initiatives with minimal oversight.\\n* Coordinate team members across engineering boundaries and drive projects from inception to completion.\\n\\nOrganizational Knowledge:\\n\\n* Understand and help implement the company&#39;s strategy by participating in planning and defining the Security Team&#39;s strategic goals in alignment with Anchorage Digital&#39;s overall objectives.\\n* Stay alert to emerging company objectives and industry trends that could affect organizational success.\\n* Consider security holistically across the entire product ecosystem while fostering a security-first company culture.\\n\\nCommunication and Influence:\\n\\n* Share knowledge broadly across the team while preventing single points of failure.\\n* Mentor and guide engineers throughout the Engineering team.\\n* Collaborate across teams to solve problems, review specifications, and engage in technical discussions.\\n* Communicate insights and recommendations clearly to improve processes and address technical debt.\\n\\nYou may be a fit for this role if you have:\\n\\n* A strong foundation in applied cryptography, including symmetric/asymmetric encryption, hashing algorithms, digital signatures, key exchange protocols, and common cryptographic libraries.\\n* Experience with the configuration and use of Hardware Security Modules (HSMs) for secure key generation, storage, and management.\\n* Understanding and implementation of various authentication and authorization mechanisms, including multi-factor authentication, OAuth 2.0, and role-based access control (RBAC).\\n* Ability to identify and assess potential threats to systems and applications, and effectively prioritize mitigation strategies.\\n* Developed computer science fundamentals, such as concurrency, algorithms, and data structures.\\n* Genuine care about code quality and test infrastructure.\\n* Prioritization of security, end-user experience, and business value over &#39;cool tech&#39;.\\n\\nAlthough not a requirement, bonus points if:\\n\\n* You read blockchain protocol white papers for fun, and stay up to date with the proliferation of cryptoasset innovations.\\n* You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_576661da-536","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anchorage Digital","sameAs":"https://anchorage.com","logo":"https://logos.yubhub.co/anchorage.com.png"},"x-apply-url":"https://jobs.lever.co/anchorage/e5d0f1ac-3126-481e-857f-db6ae8eb67e9","x-work-arrangement":"remote","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["cryptography","symmetric/asymmetric encryption","hashing algorithms","digital signatures","key exchange protocols","Hardware Security Modules (HSMs)","authentication and authorization","multi-factor authentication","OAuth 2.0","role-based access control (RBAC)","threat modeling","computer science fundamentals","concurrency","algorithms","data structures"],"x-skills-preferred":[],"datePosted":"2026-04-17T12:24:08.463Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"United States"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"cryptography, symmetric/asymmetric encryption, hashing algorithms, digital signatures, key exchange protocols, Hardware Security Modules (HSMs), authentication and authorization, multi-factor authentication, OAuth 2.0, role-based access control (RBAC), threat modeling, computer science fundamentals, concurrency, algorithms, data structures"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b7d5aa44-517"},"title":"Member of Product, Security","description":"<p>At Anchorage Digital, we are building the world&#39;s most advanced digital asset platform for institutions to participate in crypto. As our first Security Product Manager, you will own the product strategy and execution that strengthens our defense-in-depth architecture and operational controls across custody, wallets, authorization, policy, and risk systems.</p>\n<p>You&#39;ll partner with Security, Platform, Core Experience, Protocols, and Compliance to ship secure-by-default capabilities that meet bank-grade and auditor expectations while preserving developer velocity and client experience. You will define and own the roadmap for security platform capabilities across cloud defense, secrets management, HSM-bound workflows, and secure-by-default developer tooling.</p>\n<p>You&#39;ll translate regulatory, audit, and risk requirements into usable product surfaces and guardrails for internal teams and client-facing flows. You will also establish crisp product requirements, success metrics, and post-ship control evidence so Security, Risk, and Audit can verify effectiveness without slowing teams.</p>\n<p>We have created the Factors of Growth &amp; Impact to help Villagers better measure impact and articulate coaching, feedback, and the rich and rewarding learning that happens while exploring, developing, and mastering the capabilities and contributions within and outside of the Security Product Manager role:</p>\n<p><strong>Technical Skills:</strong></p>\n<ul>\n<li>Work closely with the security engineering team on the detail prioritization of the security product roadmap, balancing new capability development with technical debt retirement to ensure long-term platform health.</li>\n<li>Demonstrate deep strategic thinking in shaping the roadmap, considering threat landscape, regulatory requirements, competitive positioning, and customer needs to drive long-term security product success.</li>\n<li>Deliver complex, cross-functional security projects with multiple dependencies (Security Engineering, Platform, Core Experience, Compliance), demonstrating strong product management skills and ability to drive swift execution while maintaining quality.</li>\n<li>Drive comprehensive go-to-market strategy for security capabilities, including defining success metrics, tracking KPIs, and iterating based on data-driven insights.</li>\n</ul>\n<p><strong>Complexity and Impact of Work:</strong></p>\n<ul>\n<li>Contribute strategic insights that significantly impact company direction, control coverage, and the security roadmap.</li>\n<li>Demonstrate product leadership that elevates team performance and effectiveness across security and platform domains.</li>\n</ul>\n<p><strong>Organizational Knowledge:</strong></p>\n<ul>\n<li>Develop deep understanding of Anchorage&#39;s business model, organizational structure, regulatory posture, and strategic priorities.</li>\n<li>Build and maintain strong relationships with stakeholders across Security, Engineering, Compliance, Risk, and Ops to ensure effective collaboration.</li>\n<li>Navigate and improve organizational processes to enhance efficiency, safety, and auditability across teams.</li>\n<li>Contribute to organizational strategy through security product expertise, control design insights, and market intelligence.</li>\n<li>Drive company objectives through strategic security product decisions and initiatives.</li>\n</ul>\n<p><strong>Communication and Influence:</strong></p>\n<ul>\n<li>Effectively influence and motivate others through respectful engagement, aligning teams with broader organizational security and product goals.</li>\n<li>Enable cross-functional collaboration through clear, consistent communication and strategic influence on decision-making at every level of the organization.</li>\n<li>Communicate clearly with executives, auditors, and prospective customers on control intent, coverage, evidence, and roadmap tradeoffs.</li>\n<li>Act as a thoughtful knowledge partner to senior leadership, helping improve organizational security dynamics through empathetic understanding.</li>\n</ul>\n<p><strong>You may be a fit for this role if you have:</strong></p>\n<ul>\n<li>6+ years in product management with 3+ focused on platform or security products in regulated or high-assurance environments.</li>\n<li>Strong technical fluency in one or more: cryptographic primitives, authN/Z, HSMs and key management, secrets management, secure software delivery, runtime isolation, threat modeling.</li>\n<li>Proven record shipping platform controls that are both developer-friendly and audit-ready.</li>\n<li>Experience converting regulatory or control frameworks (e.g., SOC 2, FFIEC, OCC expectations, ISO 27001) into practical product requirements.</li>\n<li>Comfortable operating across deeply technical teams and non-technical stakeholders (Security, Compliance, Risk, Ops, Client Success).</li>\n<li>Excellent written and verbal communication skills, adept at conveying complex security concepts clearly to diverse audiences.</li>\n<li>Experience in driving and managing complex projects across multiple teams, demonstrating exceptional leadership and problem-solving skills.</li>\n<li>Your empathy and adaptability not only complement others&#39; working styles but also embody our culture of curiosity, creativity, and shared understanding.</li>\n<li>You self describe as some combination of the following: creative, humble, ambitious, detail oriented, hard working, trustworthy, eager to learn, methodical, action oriented, and tenacious.</li>\n</ul>\n<p><strong>Although not a requirement, bonus points if:</strong></p>\n<ul>\n<li>Experience in digital assets or financial infrastructure.</li>\n<li>Hands-on experience with hardware signing flows, policy engines, or secure enclave/HSM integrations.</li>\n<li>Built systems for straight-through-processing with pre-authorization risk decisions.</li>\n<li>Familiarity with incident response and detection engineering product needs.</li>\n<li>You have written your own smart contract or dApp.</li>\n<li>You have built 0 to 1 products for financial institutions either as a PM or a developer.</li>\n</ul>\n<p><strong>Additional Information About Anchorage Digital:</strong></p>\n<p>Who we are The Anchorage Village, what we call our team, brings together the brightest minds from platform security, financial services, and distributed ledger technology.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b7d5aa44-517","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anchorage Digital","sameAs":"https://anchorage.com","logo":"https://logos.yubhub.co/anchorage.com.png"},"x-apply-url":"https://jobs.lever.co/anchorage/43703182-aa1f-4db4-a13a-1e890ae2fae9","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["cryptographic primitives","authN/Z","HSMs and key management","secrets management","secure software delivery","runtime isolation","threat modeling"],"x-skills-preferred":[],"datePosted":"2026-04-17T12:18:34.651Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"United States"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"cryptographic primitives, authN/Z, HSMs and key management, secrets management, secure software delivery, runtime isolation, threat modeling"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1da9829d-f32"},"title":"Cyber Security Engineering - Architect","description":"<p>Synopsys software engineers are key enablers in the world of Electronic Design Automation (EDA), developing and maintaining software used in chip design, verification and manufacturing. This role is for a Cyber Security Engineering - Architect who will design and implement comprehensive cybersecurity architectures aligned with business objectives.</p>\n<p>The successful candidate will have 5+ years of comprehensive experience in cybersecurity engineering roles, with hands-on experience with Azure, GCP, and AWS cloud providers and their security capabilities. They will also have excellent communication and collaboration skills, adept at working with multi-functional teams.</p>\n<p>As a Cybersecurity Architect, you will join a collaborative and innovative cybersecurity team dedicated to protecting Synopsys&#39; assets and intellectual property. The team values continuous learning, improvement, and embraces new technologies and approaches to build a resilient security environment.</p>\n<p>Key responsibilities include:</p>\n<ul>\n<li>Designing and implementing comprehensive cybersecurity architectures aligned with business objectives</li>\n<li>Assessing current security frameworks and recommending enhancements to mitigate risks and vulnerabilities</li>\n<li>Collaborating with cross-functional teams, product managers, and business partners to integrate security throughout system development and deployment</li>\n<li>Developing and maintaining security policies, standards, and procedures to establish a robust cybersecurity foundation</li>\n<li>Conducting threat modeling, architecture reviews, and risk assessments to identify and address vulnerabilities</li>\n<li>Providing guidance and support to IT and engineering teams on security-related issues and best practices</li>\n<li>Documenting and communicating security architecture plans and updates to stakeholders at all levels</li>\n</ul>\n<p>The impact you will have:</p>\n<ul>\n<li>Shape and execute the organization&#39;s cybersecurity strategy, protecting sensitive data and critical systems</li>\n<li>Reduce vulnerabilities and enhance the overall security posture through innovative security frameworks</li>\n<li>Foster a culture of security awareness and resilience against cyber threats across the organization</li>\n<li>Maintain trust with clients, stakeholders, and partners by ensuring the integrity and confidentiality of information</li>\n<li>Support compliance with industry regulations and standards, contributing to business sustainability and reputation</li>\n<li>Enable secure digital transformation, empowering teams to innovate confidently within a protected environment</li>\n<li>Influence technology adoption and process improvements by providing expert guidance and leadership in security architecture</li>\n</ul>\n<p>Requirements:</p>\n<ul>\n<li>University degree or equivalent certified education and experience in a relevant field</li>\n<li>5+ years of comprehensive experience in cybersecurity engineering roles</li>\n<li>Ability to draft project plans for security services and technology deployments, coordinating with stakeholders organization-wide</li>\n<li>Hands-on experience with Azure, GCP, and AWS cloud providers and their security capabilities</li>\n<li>Excellent communication and collaboration skills, adept at working with multi-functional teams</li>\n<li>Strong presentation and speaking skills, especially for executive audiences</li>\n<li>Advanced problem-solving skills and adaptability in fast-paced, evolving environments</li>\n<li>Relevant certifications such as CISSP (ISSAP), CISA, CISM, CRISC, SABSA are preferred</li>\n</ul>\n<p>As a Cybersecurity Architect, you will join a collaborative and innovative cybersecurity team dedicated to protecting Synopsys&#39; assets and intellectual property. The team values continuous learning, improvement, and embraces new technologies and approaches to build a resilient security environment.</p>\n<p>Rewards and benefits:</p>\n<p>We offer a comprehensive range of health, wellness, and financial benefits to cater to your needs. Our total rewards include both monetary and non-monetary offerings. Your recruiter will provide more details about the salary range and benefits during the hiring process.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1da9829d-f32","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Synopsys","sameAs":"https://careers.synopsys.com","logo":"https://logos.yubhub.co/careers.synopsys.com.png"},"x-apply-url":"https://careers.synopsys.com/job/morrisville/cyber-security-engineering-architect-16496/44408/93015824800","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$201000-$301000","x-skills-required":["cybersecurity","cloud security","Azure","GCP","AWS","security architecture","threat modeling","risk assessment","security policy","security standard","procedure"],"x-skills-preferred":[],"datePosted":"2026-04-05T13:20:31.073Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Morrisville"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"cybersecurity, cloud security, Azure, GCP, AWS, security architecture, threat modeling, risk assessment, security policy, security standard, procedure","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":201000,"maxValue":301000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_053f3a1e-d2d"},"title":"Security Engineer, Detection and Response","description":"<p><strong>Compensation</strong></p>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer on Detection &amp; Response, you’ll help protect OpenAI’s most sensitive assets– including our intellectual property, customer data, and the infrastructure that supports them– by building and operating the systems we use to detect suspicious activity and respond effectively when it matters. You’ll work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering closely with security teams and infrastructure owners to define the telemetry and response requirements we need and building tooling and automation where it delivers the most leverage.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Build and evolve Detection &amp; Response capabilities across OpenAI’s infrastructure, products, and research environments, with an emphasis on high-signal detection and reliable operational response.</li>\n</ul>\n<ul>\n<li>Engineer detection pipelines and tooling: develop rule lifecycle management, measurement/quality loops (coverage, precision, latency), tuning processes, and safe rollout patterns.</li>\n</ul>\n<ul>\n<li>Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain.</li>\n</ul>\n<ul>\n<li>Partner with other Security teams and system/infrastructure owners across the company to ensure new systems ship with the right telemetry, threat models, and response playbooks from day one.</li>\n</ul>\n<ul>\n<li>Define D&amp;R requirements and drive visibility across endpoints, identity, SaaS, cloud, Kubernetes: identify telemetry/control gaps, prioritize them, and advocate for fixes with partner teams (and implement directly when it’s the fastest/most effective path).</li>\n</ul>\n<ul>\n<li>Evaluate and respond to emergent security concerns in a frontier AI lab environment, such as detection and response strategies for agents operating across infrastructure at scale.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Have hands-on threat detection and/or incident response experience, including building detections, running investigations, and improving operational playbooks.</li>\n</ul>\n<ul>\n<li>Understand modern adversary tradecraft (TTPs) and can translate it into practical detection strategies and response actions.</li>\n</ul>\n<ul>\n<li>Bring a threat modeling mindset. You can evaluate new infrastructure or features, identify D&amp;R implications (what could go wrong, what we’d need to see, how we’d respond), and turn that into concrete requirements for teams shipping the system.</li>\n</ul>\n<ul>\n<li>Have experience working in Kubernetes/containerized environments, including building detections from cluster telemetry and understanding common failure and attack modes (workloads, nodes, control plane, networking).</li>\n</ul>\n<ul>\n<li>Are comfortable reasoning about lower-level infrastructure and datacenter risks, such as firmware/BMC surfaces, network segmentation/telemetry, and hard-to-observe control paths.</li>\n</ul>\n<ul>\n<li>Have experience across major cloud platforms (Azure, AWS, GCP, OCI), and can design cloud-agnostic detection approaches where possible.</li>\n</ul>\n<ul>\n<li>Like building automation that replaces repetitive D&amp;R work, including thoughtfully using agent-style workflows where they meaningfully reduce toil, while keeping outcomes measurable, auditable, and safe.</li>\n</ul>\n<ul>\n<li>Are energized by new problem areas at a forward-leaning technology company: e.g., thinking through how to detect and respond to agents operating across systems at scale, and turning those ideas into pragmatic telemetry and response requirements.</li>\n</ul>\n<ul>\n<li>Communicate clearly and collaborate well across teams. You can translate D&amp;R needs into clear requirements, align stakeholders, and drive follow-through across technical and non-technical audiences.</li>\n</ul>\n<ul>\n<li>Are comfortable with scripting and enjoy using AI/agent tooling to accelerate investigations and automation—more “directing” than doing everything by hand.</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>\n<p><strong>Additional Information</strong></p>\n<p>We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.</p>\n<p>Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_053f3a1e-d2d","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/f956b77c-3cc5-4fdd-9463-2a6e5047e57c","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"Full time","x-salary-range":"The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.","x-skills-required":["threat detection","incident response","Kubernetes","cloud platforms","scripting","AI/agent tooling","security engineering","endpoint security","identity security","cloud security","hyperscale compute infrastructure","datacenter-adjacent layers"],"x-skills-preferred":["threat modeling","adversary tradecraft","TTPs","cloud-agnostic detection","automation","agent-style workflows","measurable outcomes","auditable outcomes","safe outcomes"],"datePosted":"2026-03-08T22:14:51.375Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco; New York City; Seattle"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"threat detection, incident response, Kubernetes, cloud platforms, scripting, AI/agent tooling, security engineering, endpoint security, identity security, cloud security, hyperscale compute infrastructure, datacenter-adjacent layers, threat modeling, adversary tradecraft, TTPs, cloud-agnostic detection, automation, agent-style workflows, measurable outcomes, auditable outcomes, safe outcomes"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_82598f5e-54b"},"title":"Senior Software Security Engineer","description":"<p><strong>About Anthropic</strong></p>\n<p>Anthropic&#39;s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p>\n<p><strong>About the role</strong></p>\n<p>The Security Engineering team&#39;s mission is to safeguard our AI systems and maintain the trust of our users and society at large. Whether we&#39;re developing critical security infrastructure, building secure development practices, or partnering with our research and product teams, we are committed to operating as a world-class security organisation and keeping the safety and trust of our users at the forefront of everything we do.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n<li>Build security for large-scale AI clusters, implementing robust cloud security architecture including IAM, network segmentation, and encryption controls</li>\n<li>Design secure-by-design workflows, secure CI/CD pipelines across our services, help build secure cloud infrastructure, with expertise in various cloud environments, Kubernetes security, container orchestration and identity management</li>\n<li>Ship and operate secure, high-reliability services using Infrastructure-as-Code (IaC) practices and GitOps workflows</li>\n<li>Apply deep expertise in threat modeling and risk assessment to secure complex multi cloud environments</li>\n<li>Mentor engineers and contribute to hiring and growth of the Security team</li>\n</ul>\n<p><strong>You may be a good fit if you:</strong></p>\n<ul>\n<li>5-15+ years of software engineering experience implementing and maintaining critical systems at scale</li>\n<li>Bachelor&#39;s degree in Computer Science/Software Engineering or equivalent industry experience</li>\n<li>Strong software engineering skills in Python or at least one systems language (Go, Rust, C/C++)</li>\n<li>Experience managing infrastructure at scale with DevOps and cloud automation best practices</li>\n<li>Track record of driving engineering excellence through high standards, constructive code reviews, and mentorship</li>\n<li>Proven ability to lead cross-functional security initiatives and navigate complex organisational dynamics</li>\n<li>Outstanding communication skills, translating technical concepts effectively across all organisational levels</li>\n<li>Demonstrated success in bringing clarity and ownership to ambiguous technical problems</li>\n<li>Strong systems thinking with ability to identify and mitigate risks in complex environments</li>\n<li>Low ego, high empathy engineer who attracts talent and supports diverse, inclusive teams</li>\n<li>Experience supporting fast-paced startup engineering teams</li>\n<li>Passionate about AI safety and alignment, with keen interest in making AI systems more interpretable and aligned with human values</li>\n</ul>\n<p><strong>Strong candidates may also have experience with:</strong></p>\n<ul>\n<li>Designing and hardening CI/CD pipelines against supply chain attacks through isolated environments, signed attestations, dependency verification, and automated policy enforcement</li>\n<li>Building secure development workflows through hardened remote environments</li>\n<li>Implementing network segmentation and access controls in cloud environments</li>\n<li>Managing infrastructure through automated configuration and policy enforcement</li>\n<li>Hardening containerized applications and enforcing security policies</li>\n</ul>\n<p><strong>Logistics</strong></p>\n<p><strong>Education requirements:</strong> We require at least a Bachelor&#39;s degree in a related field or equivalent experience. <strong>Location-based hybrid policy:</strong> Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</p>\n<p><strong>Salary</strong></p>\n<p>The annual compensation range for this role is £240,000 - £325,000GBP.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_82598f5e-54b","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5022845008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"£240,000 - £325,000GBP","x-skills-required":["Python","Go","Rust","C/C++","DevOps","Cloud automation","Kubernetes security","Container orchestration","Identity management"],"x-skills-preferred":["Threat modeling","Risk assessment","Secure-by-design workflows","CI/CD pipelines","Infrastructure-as-Code","GitOps workflows"],"datePosted":"2026-03-08T13:59:11.086Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London, UK"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Go, Rust, C/C++, DevOps, Cloud automation, Kubernetes security, Container orchestration, Identity management, Threat modeling, Risk assessment, Secure-by-design workflows, CI/CD pipelines, Infrastructure-as-Code, GitOps workflows","baseSalary":{"@type":"MonetaryAmount","currency":"GBP","value":{"@type":"QuantitativeValue","minValue":240000,"maxValue":325000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_1c3b4d6a-957"},"title":"Senior Software Security Engineer","description":"<p><strong>About Anthropic</strong></p>\n<p>Anthropic&#39;s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p>\n<p><strong>About the Team</strong></p>\n<p>The Security Engineering team protects Anthropic&#39;s AI systems and maintains the trust of our users and society. We define the authentication architecture for our training infrastructure, design the cryptographic foundations that protect model weights and training data, and drive the developer security program that shapes how engineers build and ship software.</p>\n<p>The team works across several areas that collaborate closely: identity and secrets management, developer security and supply chain, infrastructure security, and secure frameworks. You will support one of these areas while contributing across others, with your focus shaped by your strengths and the team&#39;s priorities.</p>\n<p><strong>Responsibilities:</strong></p>\n<ul>\n<li>Build and maintain identity and secrets management systems, including credential issuance, rotation, and workload authentication across our multi-cloud environments</li>\n<li>Contribute to cluster security controls including RBAC policies, namespace isolation, workload identity, and pod security</li>\n<li>Implement and maintain cloud security controls including IAM, network segmentation, VPC architecture, and encryption across our multi-cloud and on-prem environments</li>\n<li>Design and implement secure development frameworks and libraries that make secure coding the path of least resistance for our engineering teams, including service to service authentication, serialization libraries, and tool proxies.</li>\n<li>Harden CI/CD pipelines against supply chain attacks through isolated build environments, signed attestations, dependency verification, and automated policy enforcement</li>\n<li>Identify and remediate security gaps through code review, threat modeling, and hands-on debugging</li>\n<li>Contribute to continuous cloud security posture management using infrastructure-as-code scanning, misconfiguration detection, and automated remediation</li>\n</ul>\n<p><strong>You may be a good fit if you have:</strong></p>\n<ul>\n<li>At least 5 years of software engineering experience implementing and maintaining security-relevant systems in production</li>\n<li>Bachelor&#39;s degree in Computer Science or equivalent industry experience</li>\n<li>Strong programming skills in Python or at least one systems language such as Go or Rust</li>\n<li>Experience contributing to cloud security controls</li>\n<li>A track record of taking ownership of problems end to end, from identifying the issue to shipping and monitoring the fix</li>\n<li>Clear communication skills and the ability to work collaboratively across engineering teams</li>\n<li>Low ego and high empathy, with a genuine interest in helping teammates succeed</li>\n<li>Passion for AI safety and the role security engineering plays in building trustworthy AI systems</li>\n</ul>\n<p><strong>Strong candidates may also have:</strong></p>\n<ul>\n<li>Contributions to developer security tooling including SAST, dependency scanning, or secure build infrastructure</li>\n<li>Familiarity with Kubernetes security primitives including RBAC, namespaces, network policies, and admission controllers</li>\n<li>Experience with cloud security posture management tooling, infrastructure-as-code security scanning, or automated remediation</li>\n<li>Experience with network security and isolation techniques including east-west controls, traffic inspection, and cloud network policy</li>\n<li>Experience with eBPF for security monitoring and enforcement, or developing kernel security policies</li>\n<li>Experience building secrets management or workload authentication systems, including familiarity with protocols such as OAuth 2.0, OIDC, SAML, or SPIFFE/SPIRE</li>\n<li>Background building or operating security systems in environments that support research workflows and rapid iteration</li>\n</ul>\n<p><strong>Deadline to apply:</strong></p>\n<p>None. Applications will be reviewed on a rolling basis.</p>\n<p><strong>Logistics</strong></p>\n<p><strong>Education requirements:</strong> We require at least a Bachelor&#39;s degree in a related field or equivalent experience. <strong>Location-based hybrid policy:</strong> Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</p>\n<p><strong>Visa sponsorship:</strong> We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</p>\n<p><strong>We encourage you to apply even if you do not believe you meet every single qualification.</strong> Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you&#39;re interested in this work. We think AI systems like the ones we&#39;re building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.</p>\n<p><strong>Your safety matters to us.</strong> To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of unsolicited messages or requests for sensitive information.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_1c3b4d6a-957","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4887959008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$320,000 - $405,000 USD","x-skills-required":["Python","Go","Rust","Cloud security controls","Kubernetes security primitives","Infrastructure-as-code scanning","Automated remediation","Code review","Threat modeling","Hands-on debugging"],"x-skills-preferred":["SAST","Dependency scanning","Secure build infrastructure","Network security and isolation techniques","eBPF for security monitoring and enforcement","Kernel security policies","Secrets management or workload authentication systems","OAuth 2.0","OIDC","SAML","SPIFFE/SPIRE"],"datePosted":"2026-03-08T13:47:46.457Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA | New York City, NY | Seattle, WA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Go, Rust, Cloud security controls, Kubernetes security primitives, Infrastructure-as-code scanning, Automated remediation, Code review, Threat modeling, Hands-on debugging, SAST, Dependency scanning, Secure build infrastructure, Network security and isolation techniques, eBPF for security monitoring and enforcement, Kernel security policies, Secrets management or workload authentication systems, OAuth 2.0, OIDC, SAML, SPIFFE/SPIRE","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":320000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_fb4fa003-a73"},"title":"Platform Hardware Security Engineer","description":"<p><strong>About the Role</strong></p>\n<p>We&#39;re seeking a Platform Hardware Security Engineer to design and implement security architectures for bare-metal infrastructure. You&#39;ll work with teams across Anthropic to build firmware, bootloaders, operating systems, and attestation systems to ensure the integrity of our infrastructure from the ground up.</p>\n<p>This role requires expertise in low-level systems security and the ability to architect solutions that balance security requirements with the performance demands of training AI models across our massive fleet.</p>\n<p><strong>What you&#39;ll do:</strong></p>\n<ul>\n<li>Design and implement secure boot chains from firmware through OS initialization for diverse hardware platforms (CPUs, BMCs, switches, peripherals, and embedded microcontrollers)</li>\n<li>Architect attestation systems that provide cryptographic proof of system state from hardware root of trust through application layer</li>\n<li>Develop measured boot implementations and runtime integrity monitoring</li>\n<li>Create reference architectures and security requirements for bare-metal deployments</li>\n<li>Integrate security controls with infrastructure teams without impacting training performance</li>\n<li>Prototype and validate security mechanisms before production deployment</li>\n<li>Conduct firmware vulnerability assessments and penetration testing</li>\n<li>Build firmware analysis pipelines for continuous security monitoring</li>\n<li>Document security architectures and maintain threat models</li>\n<li>Collaborate with software and hardware vendors to ensure security capabilities meet our requirements</li>\n</ul>\n<p><strong>Who you are:</strong></p>\n<ul>\n<li>8+ years of experience in systems security, with at least 5 years focused on firmware and hardware security (firmware, bootloaders, and OS-level security)</li>\n<li>Hands-on experience with secure boot, measured boot, and attestation technologies (TPM, Intel TXT, AMD SEV, ARM TrustZone)</li>\n<li>Strong understanding of cryptographic protocols and hardware security modules</li>\n<li>Experience with UEFI/BIOS or embedded firmware security, bootloader hardening, and chain of trust implementation</li>\n<li>Proficiency in low-level programming (C, Rust, Assembly) and systems programming</li>\n<li>Knowledge of firmware vulnerability assessment and threat modeling</li>\n<li>Track record of designing security architectures for complex, distributed systems</li>\n<li>Experience with supply chain security</li>\n<li>Ability to work effectively across hardware and software boundaries</li>\n<li>Knowledge of NIST firmware security guidelines and hardware security frameworks</li>\n</ul>\n<p><strong>Strong candidates may also have:</strong></p>\n<ul>\n<li>Experience with confidential computing technologies and hardware-based TEEs</li>\n<li>Knowledge of SLSA framework and software supply chain security standards</li>\n<li>Experience securing large-scale HPC or cloud infrastructure</li>\n<li>Contributions to open-source security projects (coreboot, CHIPSEC, etc.)</li>\n<li>Background in formal verification or security proof techniques</li>\n<li>Experience with silicon root of trust implementations</li>\n<li>Experience working with building foundational technical designs, operational leadership, and vendor collaboration</li>\n<li>Previous work with AI/ML infrastructure security</li>\n</ul>\n<p><strong>Logistics</strong></p>\n<ul>\n<li>Education requirements: We require at least a Bachelor&#39;s degree in a related field or equivalent experience.</li>\n<li>Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</li>\n<li>Visa sponsorship: We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</li>\n</ul>\n<p><strong>We encourage you to apply even if you do not believe you meet every single qualification. Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you&#39;re interested in this work.</strong></p>\n<p><strong>Your safety matters to us. To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiting agencies who will identify themselves as working on behalf of Anthropic. Be cautious of emails from other domains. Legitimate Anthropic recruiters will never ask for money, fees, or banking information before your first day. If you&#39;re ever unsure about a communication, don&#39;t click any links—visit anthropic.com/careers directly for confirmed position openings.</strong></p>\n<p><strong>How we&#39;re different</strong></p>\n<p>We believe that the highest-impact AI research will be big science. At Anthropic we work as a single cohesive team on just a few large-scale research efforts.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_fb4fa003-a73","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/4929689008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$405,000 - $485,000 USD","x-skills-required":["firmware security","hardware security","secure boot","measured boot","attestation technologies","cryptographic protocols","hardware security modules","UEFI/BIOS","embedded firmware security","bootloader hardening","chain of trust implementation","low-level programming","systems programming","firmware vulnerability assessment","threat modeling","supply chain security","NIST firmware security guidelines","hardware security frameworks"],"x-skills-preferred":["confidential computing technologies","hardware-based TEEs","SLSA framework","software supply chain security standards","large-scale HPC or cloud infrastructure","open-source security projects","formal verification","security proof techniques","silicon root of trust implementations","AI/ML infrastructure security"],"datePosted":"2026-03-08T13:47:08.377Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York City, NY; Seattle, WA; San Francisco, CA; Washington, DC"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"firmware security, hardware security, secure boot, measured boot, attestation technologies, cryptographic protocols, hardware security modules, UEFI/BIOS, embedded firmware security, bootloader hardening, chain of trust implementation, low-level programming, systems programming, firmware vulnerability assessment, threat modeling, supply chain security, NIST firmware security guidelines, hardware security frameworks, confidential computing technologies, hardware-based TEEs, SLSA framework, software supply chain security standards, large-scale HPC or cloud infrastructure, open-source security projects, formal verification, security proof techniques, silicon root of trust implementations, AI/ML infrastructure security","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":405000,"maxValue":485000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_45350b41-7eb"},"title":"Research Engineer / Scientist, Frontier Red Team (Cyber)","description":"<p><strong>About Anthropic</strong></p>\n<p>Anthropic&#39;s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p>\n<p><strong>About the Team</strong></p>\n<p>The Frontier Red Team (FRT) is a small, focused technical research team within Anthropic&#39;s Policy organization. Our goal is to make the entire world safer in an era of advanced AI by understanding what these systems can do and building the defenses that matter.</p>\n<p>In 2026, we&#39;re focused on researching and ensuring safety with self-improving, highly autonomous AI systems, especially ones related to cyberphysical capabilities. See our previous related work on exploits, partnering with Mozilla, and zero days. This is early-stage, high-conviction research with the potential for outsized impact.</p>\n<p><strong>About the Role</strong></p>\n<p>In the last year, we&#39;ve seen compelling signs that LLMs and agents are increasingly capable of novel cyber capabilities. We think 2026 will be the year where models reach expert-level, even superhuman, in several cybersecurity domains. This is a novel and massive threat surface.</p>\n<p>As a Research Scientist on FRT focusing on cyber, you&#39;ll build the tools and frameworks needed to defend the world against advanced AI-enabled cyber threats. Senior candidates will have the opportunity to shape and grow Anthropic&#39;s cyberdefense research program, working with Security, Safeguards, Policy, and other partner teams. This work sits at the intersection of AI capabilities research, cybersecurity, and policy—what we learn directly shapes how Anthropic and the world prepare for AI-enabled cyber threats.</p>\n<p>This is applied research with real-world stakes. Your work will inform decisions at the highest levels of the company, contribute to demonstrations that shape policy discourse, and build the technical defenses that we will need for a future of increasingly powerful AI systems.</p>\n<p><strong>What You&#39;ll Do</strong></p>\n<ul>\n<li>Develop systems, tools, and frameworks for AI-empowered cybersecurity, such as autonomous vulnerability discovery and remediation, malware detection and management, network hardening, and pentesting</li>\n</ul>\n<ul>\n<li>Design and run experiments to elicit and evaluate autonomous AI cyber capabilities in realistic scenarios</li>\n</ul>\n<ul>\n<li>Design and build infrastructure for evaluating and enabling AI systems to operate in security environments</li>\n</ul>\n<ul>\n<li>Translate technical findings into compelling demonstrations and artifacts that inform policymakers and the public</li>\n</ul>\n<ul>\n<li>Collaborate with external experts in cybersecurity, national security, and AI safety to scope and validate research directions</li>\n</ul>\n<p><strong>Sample Projects</strong></p>\n<ul>\n<li>Building frameworks and tools that enable AI models to autonomously find and patch vulnerabilities</li>\n</ul>\n<ul>\n<li>Running purple-team simulations where AI defenders compete against AI attackers in network environments</li>\n</ul>\n<ul>\n<li>Pointing autonomous AI systems at real-world security challenges (bug bounties, CTFs etc.) to characterize risks, defensive potential, and compare to human experts</li>\n</ul>\n<ul>\n<li>Building demonstrations of frontier AI cyber capabilities for policy stakeholders</li>\n</ul>\n<p><strong>You May Be a Good Fit If You</strong></p>\n<ul>\n<li>Have deep expertise in cybersecurity or security research</li>\n</ul>\n<ul>\n<li>Are driven to find solutions to complex, high-stakes problems</li>\n</ul>\n<ul>\n<li>Have experience doing technical research with LLM-based agents or autonomous systems</li>\n</ul>\n<ul>\n<li>Have strong software engineering skills, particularly in Python</li>\n</ul>\n<ul>\n<li>Can own entire problems end-to-end, including both technical and non-technical components</li>\n</ul>\n<ul>\n<li>Design and run experiments quickly, iterating fast toward useful results</li>\n</ul>\n<ul>\n<li>Thrive in collaborative environments</li>\n</ul>\n<ul>\n<li>Care deeply about AI safety and want your work to have real-world impact on how humanity navigates advanced AI</li>\n</ul>\n<ul>\n<li>Are comfortable working on sensitive projects that require discretion and integrity</li>\n</ul>\n<ul>\n<li>Have proven ability to lead cross-functional security initiatives and navigate complex organizational dynamics</li>\n</ul>\n<p><strong>Strong Candidates May Also Have</strong></p>\n<ul>\n<li>Experience with offensive security research, vulnerability research, or exploit development</li>\n</ul>\n<ul>\n<li>Research or professional experience applying LLMs to security problems</li>\n</ul>\n<ul>\n<li>Track record in competitive CTFs, bug bounties, or other security-related competitions</li>\n</ul>\n<ul>\n<li>Experience building security tools or automation</li>\n</ul>\n<ul>\n<li>Track record of building demos or prototypes that communicate complex technical ideas</li>\n</ul>\n<ul>\n<li>Experience working with external stakeholders (policymakers, government, researchers)</li>\n</ul>\n<ul>\n<li>Familiarity with AI safety research and threat modeling for advanced AI systems</li>\n</ul>\n<p><strong>Logistics</strong></p>\n<p><strong>Education requirements:</strong> We require at least a Bachelor&#39;s degree in a related field or equivalent experience. <strong>Location-based hybrid policy:</strong> Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</p>\n<p><strong>Visa sponsorship:</strong> We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</p>\n<p><strong>We encourage you to apply even if you do not believe you meet every single qualification.</strong> Not all strong candidates will</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_45350b41-7eb","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://www.anthropic.com","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5076477008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$320,000 - $850,000USD","x-skills-required":["cybersecurity","security research","LLM-based agents","autonomous systems","Python","software engineering"],"x-skills-preferred":["offensive security research","vulnerability research","exploit development","AI safety research","threat modeling"],"datePosted":"2026-03-08T13:46:35.212Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"cybersecurity, security research, LLM-based agents, autonomous systems, Python, software engineering, offensive security research, vulnerability research, exploit development, AI safety research, threat modeling","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":320000,"maxValue":850000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_48f07618-377"},"title":"Research Engineer, Frontier Red Team (Autonomy)","description":"<p><strong>About Anthropic</strong></p>\n<p>Anthropic&#39;s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p>\n<p><strong>About the Team</strong></p>\n<p>The Frontier Red Team (FRT) is a small, focused technical research team within Anthropic&#39;s Policy organization. Our goal is to make the entire world safer in this era of advanced AI by understanding what these systems can do and building the defenses that matter.</p>\n<p>In 2026, we&#39;re focused on researching and ensuring safety with self-improving, highly autonomous AI systems—especially ones with cyberphysical capabilities. See our previous related work on cyberdefense, robotics, and Project Vend. This is early-stage, high-conviction research with the potential for outsized impact.</p>\n<p><strong>About the Role</strong></p>\n<p>Our team is focused on a critical question: how do we defend against a world where powerful, autonomous, self-improving AI systems may be used adversarially?</p>\n<p>As a Research Engineer on our team, you&#39;ll build and eval model organisms of autonomous systems and develop the defensive agents needed to counter them. This work sits at the intersection of AI capabilities research, security, and policy—what we learn directly shapes how Anthropic and the world prepare for advanced AI.</p>\n<p>This is applied research with real-world stakes. Your work will inform decisions at the highest levels of the company, contribute to public demonstrations that shape policy discourse, and help build technical defenses that could matter enormously as AI systems become more capable.</p>\n<p><strong>What You&#39;ll Do</strong></p>\n<ul>\n<li>Design and build autonomous AI systems that can use tools and operate across diverse environments—creating model organisms that help us understand and defend against advanced adversarial AI</li>\n</ul>\n<ul>\n<li>Create evals and training environments to understand and shape agent behavior in desirable ways</li>\n</ul>\n<ul>\n<li>Develop defensive agents that can detect, disrupt, or outcompete adversarial AI systems in realistic scenarios</li>\n</ul>\n<ul>\n<li>Interface Claude with hardware platforms (e.g. robotics, physical systems) to understand cyberphysical risks and defenses</li>\n</ul>\n<ul>\n<li>Translate technical findings into compelling demonstrations and artifacts that inform policymakers and the public</li>\n</ul>\n<ul>\n<li>Collaborate with external experts in cybersecurity, national security, and AI safety to scope and validate research directions</li>\n</ul>\n<p><strong>Sample Projects</strong></p>\n<ul>\n<li>Developing systems where Claude controls diverse hardware and robotics platforms simultaneously</li>\n</ul>\n<ul>\n<li>Creating attack-defend simulations (CTFs, wargames, adversarial games) to test defensive AI capabilities</li>\n</ul>\n<ul>\n<li>Designing and implementing RL environments for training defensive agents</li>\n</ul>\n<ul>\n<li>Pointing autonomous systems at real-world security challenges to characterize risks and develop mitigations</li>\n</ul>\n<p><strong>You May Be a Good Fit If You</strong></p>\n<ul>\n<li>Have strong software engineering skills, particularly in Python</li>\n</ul>\n<ul>\n<li>Have experience building and working with LLM-based agents or autonomous systems</li>\n</ul>\n<ul>\n<li>Are driven to find solutions to ambiguously scoped, high-stakes problems</li>\n</ul>\n<ul>\n<li>Design and run experiments quickly, iterating fast toward useful results</li>\n</ul>\n<ul>\n<li>Thrive in collaborative environments (we love pair programming!)</li>\n</ul>\n<ul>\n<li>Care deeply about AI safety and want your work to have real-world impact on how humanity navigates advanced AI</li>\n</ul>\n<ul>\n<li>Can own entire problems end-to-end, including both technical and non-technical components</li>\n</ul>\n<ul>\n<li>Are comfortable working on sensitive projects that require discretion and integrity</li>\n</ul>\n<p><strong>Strong Candidates May Also Have</strong></p>\n<ul>\n<li>Experience with reinforcement learning, self-play, or multi-agent systems</li>\n</ul>\n<ul>\n<li>Experience with robotics, hardware interfaces, or cyberphysical systems</li>\n</ul>\n<ul>\n<li>Track record of building demos or prototypes that communicate complex technical ideas</li>\n</ul>\n<ul>\n<li>Experience working with external stakeholders (policymakers, government, researchers)</li>\n</ul>\n<ul>\n<li>Familiarity with AI safety research and threat modeling for advanced AI systems</li>\n</ul>\n<p><strong>Logistics</strong></p>\n<p><strong>Education requirements:</strong> We require at least a Bachelor&#39;s degree in a related field or equivalent experience. <strong>Location-based hybrid policy:</strong> Currently, we expect all staff to be in one of our offices at least 25% of the time. However, some roles may require more time in our offices.</p>\n<p><strong>Visa sponsorship:</strong> We do sponsor visas! However, we aren&#39;t able to successfully sponsor visas for every role and every candidate. But if we make you an offer, we will make every reasonable effort to get you a visa, and we retain an immigration lawyer to help with this.</p>\n<p><strong>We encourage you to apply even if you do not believe you meet every single qualification.</strong> Not all strong candidates will meet every single qualification as listed. Research shows that people who identify as being from underrepresented groups are more prone to experiencing imposter syndrome and doubting the strength of their candidacy, so we urge you not to exclude yourself prematurely and to submit an application if you&#39;re interested in this work. We think AI systems like the ones we&#39;re building have enormous social and ethical implications. We think this makes representation even more important, and we strive to include a range of diverse perspectives on our team.</p>\n<p><strong>Your safety matters to us.</strong> To protect yourself from potential scams, remember that Anthropic recruiters only contact you from @anthropic.com email addresses. In some cases, we may partner with vetted recruiters to help us find the best candidates for our open roles.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_48f07618-377","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5067100008","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$320,000 - $850,000USD","x-skills-required":["Python","LLM-based agents","Autonomous systems","Reinforcement learning","Self-play","Multi-agent systems","Robotics","Hardware interfaces","Cyberphysical systems","AI safety research","Threat modeling"],"x-skills-preferred":["Software engineering","Collaborative environments","AI safety","Discretion and integrity"],"datePosted":"2026-03-08T13:45:56.349Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, LLM-based agents, Autonomous systems, Reinforcement learning, Self-play, Multi-agent systems, Robotics, Hardware interfaces, Cyberphysical systems, AI safety research, Threat modeling, Software engineering, Collaborative environments, AI safety, Discretion and integrity","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":320000,"maxValue":850000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b1149c30-15f"},"title":"Threat Modeler, Preparedness","description":"<p><strong>Threat Modeler, Preparedness</strong></p>\n<p><strong>Location</strong></p>\n<p>San Francisco</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Department</strong></p>\n<p>Safety Systems</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$325K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>The Preparedness team is an important part of the Safety Systems org at OpenAI, and is guided by OpenAI’s Preparedness Framework.</p>\n<p>Frontier AI models have the potential to benefit all of humanity, but also pose increasingly severe risks. To ensure that AI promotes positive change, the Preparedness team helps us prepare for the development of increasingly capable frontier AI models. This team is tasked with identifying, tracking, and preparing for catastrophic risks related to frontier AI models.</p>\n<p>The mission of the Preparedness team is to:</p>\n<ol>\n<li>Closely monitor and predict the evolving capabilities of frontier AI systems, with an eye towards misuse risks whose impact could be catastrophic to our society</li>\n</ol>\n<ol>\n<li>Ensure we have concrete procedures, infrastructure and partnerships to mitigate these risks and to safely handle the development of powerful AI systems</li>\n</ol>\n<p>Preparedness tightly connects capability assessment, evaluations, and internal red teaming, and mitigations for frontier models, as well as overall coordination on AGI preparedness. This is fast paced, exciting work that has far reaching importance for the company and for society.</p>\n<p><strong>About the Role</strong></p>\n<p>As a threat modeler, you will own OpenAI’s holistic approach to identifying, modeling, and forecasting frontier risks from frontier AI systems. This role ensures that our evaluation frameworks, safeguards, and taxonomies are robust, high-coverage, and forward-looking. You will help the company answer the “why” behind our most stringent risk-prevention efforts, shaping the rationale for prioritizing and mitigating risks across domains. You will serve as a central node connecting technical, governance, and policy perspectives on prioritization, focus and rationale on our approach to frontier risks from AI.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Develop and maintain comprehensive threat models across all misuse areas (bio, cyber, attack planning, etc.)</li>\n</ul>\n<ul>\n<li>Develop plausible and convincing threat models across loss of control, self-improvement, and other possible alignment risks from frontier AI systems</li>\n</ul>\n<ul>\n<li>Forecast risks by combining technical foresight, adversarial simulation, and emerging trends</li>\n</ul>\n<ul>\n<li>Pair closely with technical partners on capability evaluations to ensure these map to and cover the gambit of severe risks differentially enabled by frontier AI systems</li>\n</ul>\n<ul>\n<li>Pair closely with Bio and Cyber Leads to size the remaining risk of the designed safeguards and translate threat models into actionable mitigation designs</li>\n</ul>\n<ul>\n<li>Act as the thought partner and explainer of “why” and “when” for high-investment mitigation efforts—helping stakeholders understand the rationale behind prioritization</li>\n</ul>\n<ul>\n<li>Serve as the central node connecting technical, governance, and policy perspectives on prioritization, focus and rationale on our approach to misuse risk</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Understand risks from frontier AI systems and have a strong grasp of AI alignment literature</li>\n</ul>\n<p>Bring deep experience in threat modeling, risk analysis, or adversarial thinking (e.g., security, national security, or safety)</p>\n<ul>\n<li>Know how AI evaluations work and can connect eval results to both capability testing and safeguard sufficiency</li>\n</ul>\n<ul>\n<li>Enjoy working across technical and policy domains to drive rigorous, multidisciplinary risk assessments</li>\n</ul>\n<ul>\n<li>Communicate complex risks clearly and compellingly to both technical and non-technical audiences</li>\n</ul>\n<ul>\n<li>Think in systems and naturally anticipate second-order and cascading risks</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and that requires a deep understanding of the potential risks and benefits of AI.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b1149c30-15f","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/f735a48e-c3c2-4387-abf7-7b39452e1ec5","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$325K • Offers Equity","x-skills-required":["threat modeling","risk analysis","adversarial thinking","AI alignment literature","AI evaluations","capability testing","safeguard sufficiency"],"x-skills-preferred":["security","national security","safety","technical writing","communication"],"datePosted":"2026-03-06T18:40:46.437Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"threat modeling, risk analysis, adversarial thinking, AI alignment literature, AI evaluations, capability testing, safeguard sufficiency, security, national security, safety, technical writing, communication","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":325000,"maxValue":325000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_38e5f550-c43"},"title":"Security Engineer, Detection and Response - EMEA","description":"<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.</p>\n<p>The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer on Detection &amp; Response, you’ll help protect OpenAI’s most sensitive assets– including our intellectual property, customer data, and the infrastructure that supports them– by building and operating the systems we use to detect suspicious activity and respond effectively when it matters. You’ll work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering closely with security teams and infrastructure owners to define the telemetry and response requirements we need and building tooling and automation where it delivers the most leverage.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Build and evolve Detection &amp; Response capabilities across OpenAI’s infrastructure, products, and research environments, with an emphasis on high-signal detection and reliable operational response.</li>\n</ul>\n<ul>\n<li>Engineer detection pipelines and tooling: develop rule lifecycle management, measurement/quality loops (coverage, precision, latency), tuning processes, and safe rollout patterns.</li>\n</ul>\n<ul>\n<li>Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain.</li>\n</ul>\n<ul>\n<li>Partner with other Security teams and system/infrastructure owners across the company to ensure new systems ship with the right telemetry, threat models, and response playbooks from day one.</li>\n</ul>\n<ul>\n<li>Define D&amp;R requirements and drive visibility across endpoints, identity, SaaS, cloud, Kubernetes: identify telemetry/control gaps, prioritize them, and advocate for fixes with partner teams (and implement directly when it’s the fastest/most effective path).</li>\n</ul>\n<ul>\n<li>Evaluate and respond to emergent security concerns in a frontier AI lab environment, such as detection and response strategies for agents operating across infrastructure at scale.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Have hands-on threat detection and/or incident response experience, including building detections, running investigations, and improving operational playbooks.</li>\n</ul>\n<ul>\n<li>Understand modern adversary tradecraft (TTPs) and can translate it into practical detection strategies and response actions.</li>\n</ul>\n<ul>\n<li>Bring a threat modeling mindset. You can evaluate new infrastructure or features, identify D&amp;R implications (what could go wrong, what we’d need to see, how we’d respond), and turn that into concrete requirements for teams shipping the system.</li>\n</ul>\n<ul>\n<li>Have experience working in Kubernetes/containerized environments, including building detections from cluster telemetry and understanding common failure and attack modes (workloads, nodes, control plane, networking).</li>\n</ul>\n<ul>\n<li>Are comfortable reasoning about lower-level infrastructure and datacenter risks, such as firmware/BMC surfaces, network segmentation/telemetry, and hard-to-observe control paths.</li>\n</ul>\n<ul>\n<li>Have experience across major cloud platforms (Azure, AWS, GCP, OCI), and can design cloud-agnostic detection approaches where possible.</li>\n</ul>\n<ul>\n<li>Like building automation that replaces repetitive D&amp;R work, including thoughtfully using agent-style workflows where they meaningfully reduce toil, while keeping outcomes measurable, auditable, and safe.</li>\n</ul>\n<ul>\n<li>Are energized by new problem areas at a forward-leaning technology company: e.g., thinking through how to detect and respond to agents operating across systems at scale, and turning those ideas into pragmatic telemetry and response requirements.</li>\n</ul>\n<ul>\n<li>Communicate clearly and collaborate well across teams. You can translate D&amp;R needs into clear requirements, align stakeholders, and drive follow-through across technical and non-technical audiences.</li>\n</ul>\n<ul>\n<li>Are comfortable with scripting and enjoy using AI/agent tooling to accelerate investigations and automation—more “directing” than doing everything by hand.</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_38e5f550-c43","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/2d8b30c7-afa3-42ca-b315-ead35e8457ab","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["threat detection","incident response","Kubernetes","cloud platforms","scripting","AI/agent tooling","security","datacenter risks","firmware/BMC surfaces","network segmentation/telemetry","hard-to-observe control paths"],"x-skills-preferred":["threat modeling","adversary tradecraft","TTPs","detection strategies","response actions","cloud-agnostic detection approaches","automation","agent-style workflows","measurable outcomes","auditable outcomes","safe outcomes"],"datePosted":"2026-03-06T18:32:29.366Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"London, UK; Dublin, Ireland"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"threat detection, incident response, Kubernetes, cloud platforms, scripting, AI/agent tooling, security, datacenter risks, firmware/BMC surfaces, network segmentation/telemetry, hard-to-observe control paths, threat modeling, adversary tradecraft, TTPs, detection strategies, response actions, cloud-agnostic detection approaches, automation, agent-style workflows, measurable outcomes, auditable outcomes, safe outcomes"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_544e96bb-5c3"},"title":"Security Engineer, Application Security","description":"<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>New York City</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are building a team of talented engineers, researchers, and designers who share our vision and values.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_544e96bb-5c3","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/ec5a5d98-6314-44d9-9466-8d4d7ee866f6","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:31:40.678Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"New York City"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_40148359-2ac"},"title":"Software Engineer, Privacy","description":"<p><strong>Job Posting</strong></p>\n<p><strong>Software Engineer, Privacy</strong></p>\n<p><strong>Location</strong></p>\n<p>San Francisco</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$230K – $325K</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>The Privacy Engineering Team at OpenAI is committed to integrating privacy as a foundational element in OpenAI&#39;s mission of advancing Artificial General Intelligence (AGI). Our focus is on all OpenAI products and systems handling user data, striving to uphold the highest standards of data privacy and security.</p>\n<p>We build essential production services, develop novel privacy-preserving techniques, and equip cross-functional engineering and research partners with the necessary tools to ensure responsible data use. Our approach to prioritizing responsible data use is integral to OpenAI&#39;s mission of safely introducing AGI that offers widespread benefits.</p>\n<p><strong>About the Role</strong></p>\n<p>We are looking for a Software Engineer with experience developing secure backend systems that prioritize customer data protection. This role is ideal for someone who is deeply committed to the nexus of product development, security, and privacy.</p>\n<p><strong>This position is located in San Francisco. Relocation assistance is available.</strong></p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Design, build, and implement back-end systems that power privacy and security functions within our API products and consumer applications.</li>\n</ul>\n<ul>\n<li>Conduct threat modeling, privacy design reviews, and code-level assessments to ensure the highest privacy and security standards.</li>\n</ul>\n<ul>\n<li>Collaborate with product managers, and other engineering teams to develop new products that leverage emerging research while maintaining privacy and security integrity.</li>\n</ul>\n<ul>\n<li>Work closely with the legal team to document and evaluate internal compliance practices, ensuring alignment with legal requirements and organizational standards, and conduct thorough internal audits to maintain the highest levels of compliance and integrity.</li>\n</ul>\n<ul>\n<li>Coordinate and actively participate in privacy incident response efforts.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Have substantial experience in building (and re-engineering) production systems to meet legal requirements, manage increased scale, and uphold privacy and security standards.</li>\n</ul>\n<ul>\n<li>Have led or been a significant contributor to security projects, demonstrating a cross-functional collaboration skill set.</li>\n</ul>\n<ul>\n<li>Deeply care about user experience and take pride in developing products that meet customer needs whilst drawing on experience in threat modeling, secure design, and regulatory compliance.</li>\n</ul>\n<ul>\n<li>Possess a humble attitude, strong communication skills, and an eagerness to support your colleagues, reflecting a readiness to do whatever is necessary for team success.</li>\n</ul>\n<ul>\n<li>Take responsibility for problems from beginning to end, demonstrating problem-solving abilities and preparedness to acquire any missing knowledge necessary to get the job done.</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_40148359-2ac","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/8a1b804f-b070-4c61-bd3d-cdf39ef9d935","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$230K – $325K","x-skills-required":["Software development","Security","Privacy","Backend systems","API products","Consumer applications","Threat modeling","Privacy design reviews","Code-level assessments","Collaboration","Product development","Security integrity","Regulatory compliance"],"x-skills-preferred":["Cloud computing","Containerization","DevOps","Agile development","Scrum","Kanban","Test-driven development","Behavior-driven development","Continuous integration","Continuous deployment","Continuous monitoring"],"datePosted":"2026-03-06T18:31:22.037Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Software development, Security, Privacy, Backend systems, API products, Consumer applications, Threat modeling, Privacy design reviews, Code-level assessments, Collaboration, Product development, Security integrity, Regulatory compliance, Cloud computing, Containerization, DevOps, Agile development, Scrum, Kanban, Test-driven development, Behavior-driven development, Continuous integration, Continuous deployment, Continuous monitoring","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":230000,"maxValue":325000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_90d20db9-de4"},"title":"Security Engineer, Application Security","description":"<p><strong>Job Posting</strong></p>\n<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>San Francisco</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Hybrid</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are committed to advancing the state-of-the-art in AI research and development.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_90d20db9-de4","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/0322d6d8-6588-4209-a304-83e768063a25","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:30:51.618Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_a100bbea-105"},"title":"Security Engineer, Detection and Response","description":"<p><strong>Security Engineer, Detection and Response</strong></p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.</p>\n<p>The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer on Detection &amp; Response, you’ll help protect OpenAI’s most sensitive assets– including our intellectual property, customer data, and the infrastructure that supports them– by building and operating the systems we use to detect suspicious activity and respond effectively when it matters. You’ll work across endpoints, identity, cloud, hyperscale compute infrastructure, and datacenter-adjacent layers, partnering closely with security teams and infrastructure owners to define the telemetry and response requirements we need and building tooling and automation where it delivers the most leverage.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Build and evolve Detection &amp; Response capabilities across OpenAI’s infrastructure, products, and research environments, with an emphasis on high-signal detection and reliable operational response.</li>\n</ul>\n<ul>\n<li>Engineer detection pipelines and tooling: develop rule lifecycle management, measurement/quality loops (coverage, precision, latency), tuning processes, and safe rollout patterns.</li>\n</ul>\n<ul>\n<li>Automate response and investigations by building workflows that reduce toil (triage, enrichment, containment, evidence capture) and improve time-to-understand/time-to-contain.</li>\n</ul>\n<ul>\n<li>Partner with other Security teams and system/infrastructure owners across the company to ensure new systems ship with the right telemetry, threat models, and response playbooks from day one.</li>\n</ul>\n<ul>\n<li>Define D&amp;R requirements and drive visibility across endpoints, identity, SaaS, cloud, Kubernetes: identify telemetry/control gaps, prioritize them, and advocate for fixes with partner teams (and implement directly when it’s the fastest/most effective path).</li>\n</ul>\n<ul>\n<li>Evaluate and respond to emergent security concerns in a frontier AI lab environment, such as detection and response strategies for agents operating across infrastructure at scale.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Have hands-on threat detection and/or incident response experience, including building detections, running investigations, and improving operational playbooks.</li>\n</ul>\n<ul>\n<li>Understand modern adversary tradecraft (TTPs) and can translate it into practical detection strategies and response actions.</li>\n</ul>\n<ul>\n<li>Bring a threat modeling mindset. You can evaluate new infrastructure or features, identify D&amp;R implications (what could go wrong, what we’d need to see, how we’d respond), and turn that into concrete requirements for teams shipping the system.</li>\n</ul>\n<ul>\n<li>Have experience working in Kubernetes/containerized environments, including building detections from cluster telemetry and understanding common failure and attack modes (workloads, nodes, control plane, networking).</li>\n</ul>\n<ul>\n<li>Are comfortable reasoning about lower-level infrastructure and datacenter risks, such as firmware/BMC surfaces, network segmentation/telemetry, and hard-to-observe control paths.</li>\n</ul>\n<ul>\n<li>Have experience across major cloud platforms (Azure, AWS, GCP, OCI), and can design cloud-agnostic detection approaches where possible.</li>\n</ul>\n<ul>\n<li>Like building automation that replaces repetitive D&amp;R work, including thoughtfully using agent-style workflows where they meaningfully reduce toil, while keeping outcomes measurable, auditable, and safe.</li>\n</ul>\n<ul>\n<li>Are energized by new problem areas at a forward-leaning technology company: e.g., thinking through how to detect and respond to agents operating across systems at scale, and turning those ideas into pragmatic telemetry and response requirements.</li>\n</ul>\n<ul>\n<li>Communicate clearly and collaborate well across teams. You can translate D&amp;R needs into clear requirements, align stakeholders, and drive follow-through across technical and non-technical audiences.</li>\n</ul>\n<ul>\n<li>Are comfortable with scripting and enjoy using AI/agent tooling to accelerate investigations and automation—more “directing” than doing everything by hand.</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_a100bbea-105","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/3728b144-f640-42be-84af-94f6b0743d7c","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"Competitive salary and benefits package","x-skills-required":["threat detection","incident response","Kubernetes","cloud platforms","scripting","AI/agent tooling","security automation","threat modeling","adversary tradecraft"],"x-skills-preferred":["cloud-agnostic detection","network segmentation","firmware/BMC surfaces","datacenter risks","containerized environments","cloud platforms","security orchestration","incident response automation"],"datePosted":"2026-03-06T18:30:38.077Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Sydney, Australia; Singapore; Tokyo, Japan"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"threat detection, incident response, Kubernetes, cloud platforms, scripting, AI/agent tooling, security automation, threat modeling, adversary tradecraft, cloud-agnostic detection, network segmentation, firmware/BMC surfaces, datacenter risks, containerized environments, cloud platforms, security orchestration, incident response automation"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_659bf794-7b5"},"title":"Security Engineer, Application Security","description":"<p><strong>Security Engineer, Application Security</strong></p>\n<p><strong>Location</strong></p>\n<p>Seattle</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>$260K – $385K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>\n</ul>\n<ul>\n<li>Mental health and wellness support</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p>More details about our benefits are available to candidates during the hiring process.</p>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>\n<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>\n<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>\n</ul>\n<ul>\n<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>\n</ul>\n<ul>\n<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>\n</ul>\n<ul>\n<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>\n</ul>\n<ul>\n<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>\n</ul>\n<ul>\n<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>\n</ul>\n<ul>\n<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>\n</ul>\n<p><strong>You might thrive in this role if you:</strong></p>\n<ul>\n<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>\n</ul>\n<ul>\n<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>\n</ul>\n<ul>\n<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>\n</ul>\n<ul>\n<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>\n</ul>\n<ul>\n<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>\n</ul>\n<p><strong>About OpenAI</strong></p>\n<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_659bf794-7b5","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/1e110226-448a-4c0b-b0e4-d0f5df579fbf","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$260K – $385K • Offers Equity","x-skills-required":["information security","cybersecurity","secure coding practices","threat modeling","risk assessments","incident response","application security","software development","secure coding guidelines","security protocols","encryption methods","programming languages","security tools","Burp Suite","OWASP ZAP"],"x-skills-preferred":["Python","Java","C++","security frameworks","security best practices"],"datePosted":"2026-03-06T18:29:22.823Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Seattle"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":260000,"maxValue":385000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ca5aa9a9-fff"},"title":"Browser Security Engineer","description":"<p>We are seeking a skilled Browser Security Engineer to join our team. As a key member of our security team, you will be responsible for leading threat modeling and security architecture reviews for all Comet browser surfaces. You will also collaborate closely with product and engineering teams to proactively identify and mitigate browser vulnerabilities, especially issues specific to custom Chrome engineering and browser extension architecture.</p>\n<p><strong>What you&#39;ll do</strong></p>\n<ul>\n<li>Lead threat modeling and security architecture reviews for all Comet browser surfaces.</li>\n<li>Collaborate closely with product and engineering teams to proactively identify and mitigate browser vulnerabilities, especially issues specific to custom Chrome engineering and browser extension architecture.</li>\n</ul>\n<p><strong>What you need</strong></p>\n<ul>\n<li>Prior experience in browser, application, or product security (ideally with Chrome/Chromium or other browser engine experience).</li>\n<li>Deep knowledge of modern browser architectures; understanding of XSS, CSP, sandboxing, extension security, and WebView-specific threats.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ca5aa9a9-fff","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Perplexity","sameAs":"https://www.perplexity.ai/","logo":"https://logos.yubhub.co/perplexity.ai.png"},"x-apply-url":"https://jobs.ashbyhq.com/perplexity/0fd96ad3-49ec-4098-a881-a0d5127b3403","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$220K – $405K","x-skills-required":["browser security","threat modeling","security architecture"],"x-skills-preferred":["custom Chrome engineering","browser extension architecture"],"datePosted":"2026-03-04T12:27:40.977Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, London, New York City, Remote (United States), Serbia"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"browser security, threat modeling, security architecture, custom Chrome engineering, browser extension architecture","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":220000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b474ff4a-8ab"},"title":"Application Security Engineer","description":"<p>Perplexity is seeking a highly skilled, experienced and hands-on Application Security Engineer to join our dynamic security team, revolutionizing the way people search and interact with the internet. You’ll build the systems, tools, and processes that make security seamless for developers and strong by default, enabling rapid innovation while protecting our users at scale.</p>\n<p><strong>What you&#39;ll do</strong></p>\n<p>Design and implement scalable, developer-friendly security solutions that integrate directly into engineering workflows</p>\n<p><strong>What you need</strong></p>\n<ul>\n<li>8+ years of experience in Application Security, Product Security, or similar roles</li>\n<li>Deep understanding of secure software development practices, threat modeling, and common vulnerabilities (e.g., OWASP Top 10)</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b474ff4a-8ab","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Perplexity","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/perplexity.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/perplexity/63abf041-c7ba-4bd6-840c-1a4ac7925dee","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$220K – $405K","x-skills-required":["Application Security","Product Security","Secure Software Development Practices","Threat Modeling","Common Vulnerabilities"],"x-skills-preferred":["Modern Authentication and Authorization Patterns","OAuth","OIDC","SSO","Zero Trust"],"datePosted":"2026-03-04T12:27:27.307Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, London, New York City, Remote (United States), Serbia"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Application Security, Product Security, Secure Software Development Practices, Threat Modeling, Common Vulnerabilities, Modern Authentication and Authorization Patterns, OAuth, OIDC, SSO, Zero Trust","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":220000,"maxValue":405000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_288b7601-65a"},"title":"Software Engineer - Security","description":"<p>Perplexity is seeking a hands-on Software Engineer to build and evolve the software, automations, and systems that power our security operations. This role focuses on engineering security tools and internal AI-driven agents that improve detection and response, vulnerability management, and the overall security posture of our products and infrastructure.</p>\n<p><strong>What you&#39;ll do</strong></p>\n<p>Design, build, and maintain software and automation that improves our detection and response program, including alert enrichment, triage workflows, and investigation tooling.</p>\n<p><strong>What you need</strong></p>\n<ul>\n<li>Proficiency in at least one major programming language (such as Python, Go, or TypeScript) and experience building production services, CLIs, or internal tools.</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_288b7601-65a","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Perplexity","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/perplexity.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/perplexity/6c9b3c71-85ba-47db-bce5-44fd9fa95d03","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$220K – $405K","x-skills-required":["proficiency in at least one major programming language","experience building production services, CLIs, or internal tools"],"x-skills-preferred":["experience integrating with security-relevant systems","practical experience with threat modeling, secure design, or application security reviews for services or features"],"datePosted":"2026-03-04T12:27:14.181Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, London, New York City, Remote (United States), Serbia"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"proficiency in at least one major programming language, experience building production services, CLIs, or internal tools, experience integrating with security-relevant systems, practical experience with threat modeling, secure design, or application security reviews for services or features","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":220000,"maxValue":405000,"unitText":"YEAR"}}}]}