<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>ef348b50-2ac</externalid>
      <Title>Product Security Engineer</Title>
      <Description><![CDATA[<p>Join Airtable as a Product Security Engineer and play a pivotal role in shaping the security of our rapidly evolving platform. You will partner closely with product engineering teams to build paved roads, frameworks, and automated controls that make the secure path the easy path for our engineering teams.</p>
<p>Your responsibilities will include developing self-service security frameworks and &#39;paved roads&#39; that allow engineering teams to ship secure code by default. You will focus on automated guardrails for common vulnerabilities, while prioritising deep-dive design reviews into complex business logic and data isolation issues. You will also partner with product and engineering teams to review designs early, contribute to threat modelling for new features and complex initiatives, and provide clear, actionable security guidance.</p>
<p>You will research emerging threats and evolving best practices, specifically regarding AI and LLM safety, and implement controls to secure these workflows. You will manage and evolve our approach to external penetration testing and bug bounties, driving remediation for findings and treating vulnerability management as an engineering problem.</p>
<p>You will contribute to the long-term roadmaps, metrics, and strategic planning for the security team. As a senior member of the team, you will lead complex threat modelling sessions for major product launches and define secure coding standards, and actively mentor other engineers to raise the technical security bar across the organisation.</p>
<p>We are looking for a highly experienced Product Security Engineer with a strong background in computer science or a related field, and proficiency in writing clean, maintainable code. You should have deep familiarity with JavaScript or TypeScript, Node.js, and modern web application frameworks, and be able to reason about the security implications of systems built on them. You should also have hands-on experience securing LLM integrations and identifying prompt injection or data leakage risks.</p>
<p>You will excel at communicating complex security risks to non-security stakeholders and enjoy collaborating cross-functionally to find solutions that balance security with engineering velocity. You will be comfortable working in a fast-paced environment, navigating ambiguity, continuously learning about emerging threats and technologies, and contributing to long-term security strategy.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>JavaScript, TypeScript, Node.js, Modern web application frameworks, LLM integrations, Prompt injection, Data leakage risks, Threat modelling, Secure coding standards</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Airtable</Employername>
      <Employerlogo>https://logos.yubhub.co/airtable.com.png</Employerlogo>
      <Employerdescription>Airtable is a no-code app platform that empowers organisations to transform how work gets done. Over 500,000 organisations, including 80% of the Fortune 100, rely on Airtable.</Employerdescription>
      <Employerwebsite>https://airtable.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/airtable/jobs/8194662002</Applyto>
      <Location>San Francisco, CA; New York, NY; Remote (Seattle, WA only)</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>85f63ecb-5fc</externalid>
      <Title>Staff Security Engineer</Title>
      <Description><![CDATA[<p>Secure Every Identity, from AI to Human</p>
<p>Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.</p>
<p>This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>
<p><strong>Staff Security Engineer</strong></p>
<p>Okta is The World’s Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.</p>
<p>At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.</p>
<p>Join our team! We’re building a world where Identity belongs to you.</p>
<p><strong>Responsibilities</strong></p>
<p>The Staff Security Engineer is a key role for strengthening the organisation&#39;s security posture. You&#39;ll be responsible for performing security assessments of third-party integrations and connected apps, with a focus on mitigating API-related security risks. This position is vital for ensuring a &#39;secure-by-design&#39; approach for critical systems within the organisation.</p>
<p><strong>What You Will Do</strong></p>
<ul>
<li>Lead Technical Security Reviews: Perform in-depth security reviews and threat modelling for complex enterprise applications and third-party integrations.</li>
</ul>
<ul>
<li>Operationalize AI for Security: Take the lead in deploying and managing AI for Security use cases, such as integration security reviews, to automate and scale security operations.</li>
</ul>
<ul>
<li>Risk Analysis &amp; Documentation: Analyse and document API permissions and risk levels for major integrations (e.g., Salesforce, Slack, Google) to ensure they meet internal standards.</li>
</ul>
<ul>
<li>Develop Workflow Processes: Collaborate with stakeholders to design and implement repeatable security review workflows, such as the Salesforce API Integration Review.</li>
</ul>
<ul>
<li>Vulnerability &amp; Control Gap Mitigation: Identify potential vulnerabilities and security control gaps in connected apps and recommend technical mitigation strategies to stakeholders.</li>
</ul>
<ul>
<li>Report &amp; Visualize Posture: Contribute to and maintain metrics and dashboards that demonstrate the organisation&#39;s overall security posture for leadership.</li>
</ul>
<p><strong>What You Bring</strong></p>
<ul>
<li>Deep Technical Expertise: Proven experience in information security, specifically within application and enterprise security domains.</li>
</ul>
<ul>
<li>API &amp; Integration Specialist: Strong background in assessing and mitigating risks associated with third-party APIs and connected application ecosystems.</li>
</ul>
<ul>
<li>Advanced Security Principles: Understanding of &#39;secure-by-design&#39; principles and the &#39;least privilege&#39; model.</li>
</ul>
<ul>
<li>Practical Threat Modelling: Hands-on experience identifying attack vectors and conducting risk assessments for complex systems.</li>
</ul>
<ul>
<li>Tooling &amp; AI Proficiency: Experience working with security platforms for analysing application permissions and an interest or background in applying AI to streamline security tasks.</li>
</ul>
<ul>
<li>Collaborative Influencer: Exceptional communication skills with a track record of aligning multiple teams toward shared security goals.</li>
</ul>
<ul>
<li>Education: A Bachelor&#39;s degree in Computer Science, information security, or a related field.</li>
</ul>
<p><strong>Benefits</strong></p>
<p>In addition to the annual base salary range for this position, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$141,000-$193,000 CAD</Salaryrange>
      <Skills>information security, application security, enterprise security, API security, integration security, threat modelling, risk analysis, security review workflows, vulnerability mitigation, security control gap mitigation, security posture visualization</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a software company that provides identity and access management solutions. It has a global presence with over 20 offices worldwide.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7397934</Applyto>
      <Location>Toronto, Ontario, Canada</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>50280b6a-3d6</externalid>
      <Title>Penetration Tester - Engine by Starling</Title>
      <Description><![CDATA[<p>At Engine by Starling, we are seeking an experienced Penetration Tester to join our Information Security team. As a Penetration Tester, you will be responsible for conducting penetration tests on our core banking platform, focusing on Cloud and Application Security. You will also perform manual secure code reviews to identify logic flaws and security anti-patterns, participate in threat modelling sessions with different teams, and contextualise technical vulnerabilities into &#39;Real-World Risk&#39; scenarios to demonstrate business impact to non-technical executives and within Engine&#39;s risk management framework.</p>
<p>Key responsibilities include:</p>
<ul>
<li>Conducting end-to-end assessments of our core banking platform</li>
<li>Performing code reviews to identify logic flaws and security anti-patterns</li>
<li>Participating in threat modelling sessions with different teams</li>
<li>Contextualising technical vulnerabilities into &#39;Real-World Risk&#39; scenarios</li>
<li>Collaborating with Infrastructure teams to audit and secure cloud configurations</li>
<li>Acting as an independent operator within the team, managing your own testing scope and timelines across different business domains</li>
<li>Providing clear, actionable remediation advice that balances security requirements with engineering velocity</li>
</ul>
<p>Requirements include:</p>
<ul>
<li>5+ years experience in penetration testing with a focus on cloud native infrastructure, web applications, APIs</li>
<li>Expert-level proficiency with industry-standard tools and the ability to &#39;go manual&#39; when scanners fail</li>
<li>Experience with Cloud Security, specifically AWS/EKS</li>
<li>Ability to conduct code reviews in multiple languages, primarily Java and Go</li>
<li>Proven experience in threat modelling</li>
<li>SDLC knowledge</li>
<li>Scripting skills</li>
</ul>
<p>Soft skills include:</p>
<ul>
<li>Exceptional written and spoken communication skills</li>
<li>Self-starting nature</li>
<li>Ability to work independently while remaining a collaborative partner to the wider engineering team</li>
<li>Adaptability</li>
</ul>
<p>Benefits include:</p>
<ul>
<li>25 days holiday (plus take your public holiday allowance whenever works best for you)</li>
<li>An extra day&#39;s holiday for your birthday</li>
<li>Annual leave is increased with length of service, and you can choose to buy or sell up to five extra days off</li>
<li>16 hours paid volunteering time a year</li>
<li>Salary sacrifice, company enhanced pension scheme</li>
<li>Life insurance at 4x your salary &amp; group income protection</li>
<li>Private Medical Insurance with VitalityHealth including mental health support and cancer care</li>
</ul>
<p>About Us</p>
<p>You may be put off applying for a role because you don&#39;t tick every box. Forget that! While we can&#39;t accommodate every flexible working request, we&#39;re always open to discussion.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>penetration testing, cloud native infrastructure, web applications, APIs, industry-standard tools, AWS/EKS, Java, Go, threat modelling, SDLC, scripting</Skills>
      <Category>Engineering</Category>
      <Industry>Finance</Industry>
      <Employername>Engine by Starling</Employername>
      <Employerlogo>https://logos.yubhub.co/starlingbank.com.png</Employerlogo>
      <Employerdescription>Engine by Starling is a software-as-a-service (SaaS) business that provides technology to banks and financial institutions worldwide.</Employerdescription>
      <Employerwebsite>https://www.starlingbank.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/9587C75960</Applyto>
      <Location>Southampton</Location>
      <Country></Country>
      <Postedate>2026-03-20</Postedate>
    </job>
    <job>
      <externalid>c76d0c6d-ec7</externalid>
      <Title>Technical Policy Manager, Cyber Harms</Title>
      <Description><![CDATA[<p><strong>About the Role:</strong></p>
<p>We are looking for a cybersecurity expert to lead our efforts to prevent AI misuse in the cyber domain. As a Cyber Harms Technical Policy Manager, you will lead a team applying deep technical expertise to inform the design of safety systems that detect harmful cyber behaviours and prevent misuse by sophisticated threat actors.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Lead and grow a team of technical specialists focused on cyber threat modelling and evaluation frameworks</li>
<li>Design and oversee execution of capability evaluations (&#39;evals&#39;) to assess the cyber-relevant capabilities of new models</li>
<li>Create comprehensive cyber threat models, including attack vectors, exploit chains, precursor identification, and weaponization techniques</li>
<li>Develop and iterate on usage policies that govern responsible use of our models for emerging capabilities and use cases related to cyber harms</li>
<li>Serve as the primary domain expert on cyber harms, advising cross-functional teams on threat landscapes and mitigation strategies</li>
<li>Collaborate closely with internal and external threat modelling experts to develop training data for safety systems, and with ML engineers to train these systems, optimising for both robustness against adversarial attacks and low false-positive rates for legitimate security researchers</li>
<li>Analyse safety system performance in traffic, identifying gaps and proposing improvements</li>
<li>Conduct regular reviews of existing policies and enforcement systems to identify and address gaps and ambiguities related to cybersecurity risks</li>
<li>Develop rigorous stress-testing of safeguards against evolving cyber threats and product surfaces</li>
<li>Partner with Research, Product, Policy, Security Team, and Frontier Red Team to ensure cybersecurity safety is embedded throughout the model development lifecycle</li>
<li>Translate cybersecurity domain knowledge into actionable safety requirements and clearly articulated policies</li>
<li>Contribute to external communications, including model cards, blog posts, and policy documents related to cybersecurity safety</li>
<li>Monitor emerging technologies and threat landscapes for their potential to contribute to new risks and mitigation strategies, and strategically address these</li>
<li>Mentor and develop team members, fostering a culture of technical excellence and responsible AI development</li>
</ul>
<p><strong>You may be a good fit if you have:</strong></p>
<ul>
<li>An M.S. or PhD in Computer Science, Cybersecurity, or a related technical field, OR equivalent professional experience in offensive or defensive cybersecurity</li>
<li>5+ years of hands-on experience in cybersecurity, with deep expertise in areas such as vulnerability research, exploit development, network security, malware analysis, or penetration testing</li>
<li>2+ years of experience managing technical teams or leading complex technical projects with multiple stakeholders</li>
<li>Experience in scientific computing and data analysis, with proficiency in programming (Python preferred)</li>
<li>Deep expertise in modern cybersecurity, including both offensive techniques (vulnerability research, exploit development, penetration testing, malware analysis) and defensive measures (detection, monitoring, incident response)</li>
<li>Demonstrated ability to create threat models and translate technical cyber risks into policy frameworks</li>
<li>Familiarity with responsible disclosure practices, vulnerability coordination, and cybersecurity frameworks (e.g., MITRE ATT&amp;CK, NIST Cybersecurity Framework, CWE/CVE systems)</li>
<li>Strong analytical and writing skills, with the ability to navigate ambiguity and explain complex technical concepts to non-technical stakeholders</li>
<li>Experience developing policies or guidelines at scale, balancing safety concerns with enabling legitimate use cases</li>
<li>A passion for learning new skills and an ability to rapidly adapt to changing techniques and technologies</li>
<li>Comfort working in a fast-paced environment where priorities may shift as AI capabilities evolve</li>
<li>Track record of translating specialised technical knowledge into actionable safety policies or enforcement guidelines</li>
</ul>
<p><strong>Preferred Qualifications:</strong></p>
<ul>
<li>Background in AI/ML systems, particularly experience with large language models</li>
<li>Experience developing ML-based security systems or adversarial ML research</li>
<li>Experience working with defence, intelligence, or security organisations (e.g., NSA, CISA, national labs, security contractors)</li>
<li>Published security research, disclosed vulnerabilities, or participated in bug bounty programs</li>
<li>Understanding of Trust &amp; Safety operations and content moderation at scale</li>
<li>Certifications such as OSCP, OSCE, GXPN, or equivalent demonstrating technical depth</li>
<li>Understanding of dual-use security research concerns and ethical considerations in AI safety</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>The annual compensation for this role is not specified in the job posting.</Salaryrange>
      <Skills>cybersecurity, vulnerability research, exploit development, network security, malware analysis, penetration testing, scientific computing, data analysis, programming (Python), threat modelling, policy frameworks, responsible disclosure practices, vulnerability coordination, cybersecurity frameworks (e.g., MITRE ATT&amp;CK, NIST Cybersecurity Framework, CWE/CVE systems), AI/ML systems, large language models, ML-based security systems, adversarial ML research, defence, intelligence, or security organisations, NSA, CISA, national labs, security contractors, published security research, disclosed vulnerabilities, bug bounty programs, Trust &amp; Safety operations, content moderation at scale, OSCP, OSCE, GXPN, or equivalent certifications, dual-use security research concerns, ethical considerations in AI safety</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a quickly growing organisation with a mission to create reliable, interpretable, and steerable AI systems. The company&apos;s team consists of researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</Employerdescription>
      <Employerwebsite>https://job-boards.greenhouse.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/5066981008</Applyto>
      <Location>San Francisco, CA, Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
  </jobs>
</source>