{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/vulnerability-mitigation"},"x-facet":{"type":"skill","slug":"vulnerability-mitigation","display":"Vulnerability Mitigation","count":2},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_85f63ecb-5fc"},"title":"Staff Security Engineer","description":"<p>Secure Every Identity, from AI to Human</p>\n<p>Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.</p>\n<p>This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>\n<p><strong>Staff Security Engineer</strong></p>\n<p>Okta is The World’s Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.</p>\n<p>At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.</p>\n<p>Join our team! We’re building a world where Identity belongs to you.</p>\n<p><strong>Responsibilities</strong></p>\n<p>The Staff Security Engineer is a key role for strengthening the organisation&#39;s security posture. You&#39;ll be responsible for performing security assessments of third-party integrations and connected apps, with a focus on mitigating API-related security risks. This position is vital for ensuring a &#39;secure-by-design&#39; approach for critical systems within the organisation.</p>\n<p><strong>What You Will Do</strong></p>\n<ul>\n<li>Lead Technical Security Reviews: Perform in-depth security reviews and threat modelling for complex enterprise applications and third-party integrations.</li>\n</ul>\n<ul>\n<li>Operationalize AI for Security: Take the lead in deploying and managing AI for Security use cases, such as integration security reviews, to automate and scale security operations.</li>\n</ul>\n<ul>\n<li>Risk Analysis &amp; Documentation: Analyse and document API permissions and risk levels for major integrations (e.g., Salesforce, Slack, Google) to ensure they meet internal standards.</li>\n</ul>\n<ul>\n<li>Develop Workflow Processes: Collaborate with stakeholders to design and implement repeatable security review workflows, such as the Salesforce API Integration Review.</li>\n</ul>\n<ul>\n<li>Vulnerability &amp; Control Gap Mitigation: Identify potential vulnerabilities and security control gaps in connected apps and recommend technical mitigation strategies to stakeholders.</li>\n</ul>\n<ul>\n<li>Report &amp; Visualize Posture: Contribute to and maintain metrics and dashboards that demonstrate the organisation&#39;s overall security posture for leadership.</li>\n</ul>\n<p><strong>What You Bring</strong></p>\n<ul>\n<li>Deep Technical Expertise: Proven experience in information security, specifically within application and enterprise security domains.</li>\n</ul>\n<ul>\n<li>API &amp; Integration Specialist: Strong background in assessing and mitigating risks associated with third-party APIs and connected application ecosystems.</li>\n</ul>\n<ul>\n<li>Advanced Security Principles: Understanding of &#39;secure-by-design&#39; principles and the &#39;least privilege&#39; model.</li>\n</ul>\n<ul>\n<li>Practical Threat Modelling: Hands-on experience identifying attack vectors and conducting risk assessments for complex systems.</li>\n</ul>\n<ul>\n<li>Tooling &amp; AI Proficiency: Experience working with security platforms for analysing application permissions and an interest or background in applying AI to streamline security tasks.</li>\n</ul>\n<ul>\n<li>Collaborative Influencer: Exceptional communication skills with a track record of aligning multiple teams toward shared security goals.</li>\n</ul>\n<ul>\n<li>Education: A Bachelor&#39;s degree in Computer Science, information security, or a related field.</li>\n</ul>\n<p><strong>Benefits</strong></p>\n<p>In addition to the annual base salary range for this position, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_85f63ecb-5fc","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7397934","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$141,000-$193,000 CAD","x-skills-required":["information security","application security","enterprise security","API security","integration security","threat modelling","risk analysis","security review workflows","vulnerability mitigation","security control gap mitigation","security posture visualization"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:49:10.109Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Toronto, Ontario, Canada"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, application security, enterprise security, API security, integration security, threat modelling, risk analysis, security review workflows, vulnerability mitigation, security control gap mitigation, security posture visualization","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":141000,"maxValue":193000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_98802553-693"},"title":"Operating Systems Engineer | Consumer Devices","description":"<p><strong>Operating Systems Engineer | Consumer Devices</strong></p>\n<p><strong>About the Team</strong></p>\n<p>The Consumer Devices team at OpenAI builds end-to-end hardware and software systems that bring AI into the physical world. We work at the intersection of custom silicon, embedded systems, operating systems, and cloud services to deliver reliable, production-ready devices at scale.</p>\n<p><strong>About the role</strong></p>\n<p>We are looking for an Operating Systems Engineer to build and harden the OS foundations for OpenAI products. We are especially interested in experienced, passionate, and innovative operating systems developers who thrive on building foundational platform software and solving hard problems in security, privacy, performance, power, and reliability. You will work across the OS kernel, core OS services, security and privacy primitives, performance and power, and the frameworks that connect applications and UI to the system. This role emphasizes deep debugging and systems ownership from development through production.</p>\n<p><strong>Responsibilities</strong></p>\n<ul>\n<li>Work on end-to-end OS capabilities spanning the OS kernel, userspace services, application frameworks, UI toolkits, and application-facing APIs.</li>\n</ul>\n<ul>\n<li>Develop, integrate, and maintain OS components, both kernel-bound and in userspace, including scheduling, memory management, filesystems, drivers, IPC/RPC mechanisms, and security-relevant subsystems.</li>\n</ul>\n<ul>\n<li>Build and maintain core OS services and daemons (init, service management, device discovery, networking primitives, time, logging, update hooks, crash handling, and so on).</li>\n</ul>\n<ul>\n<li>Design and implement security and privacy mechanisms:</li>\n</ul>\n<ul>\n<li>Secure boot and measured boot integration points (where applicable).</li>\n</ul>\n<ul>\n<li>Mandatory access control and sandboxing.</li>\n</ul>\n<ul>\n<li>Secrets management, secure storage, key handling, and least-privilege service design.</li>\n</ul>\n<ul>\n<li>Establish a performance and power discipline:</li>\n</ul>\n<ul>\n<li>Instrumentation, profiling, and regression detection for boot time, latency, throughput, and memory.</li>\n</ul>\n<ul>\n<li>Power measurement workflows, battery and thermal aware tuning, and energy regression prevention.</li>\n</ul>\n<ul>\n<li>Build first-class debugging and observability for the OS:</li>\n</ul>\n<ul>\n<li>Tracing and profiling using tools such as ftrace, perf, eBPF, BPFtrace, LTTng, systemtap, flamegraphs.</li>\n</ul>\n<ul>\n<li>Crash triage and root cause analysis across kernel and userspace, including postmortem tooling and symbolication.</li>\n</ul>\n<ul>\n<li>Provide stable, well-documented platform interfaces for application frameworks and UI frameworks:</li>\n</ul>\n<ul>\n<li>Windowing/compositing primitives (e.g., Wayland), input pipelines, graphics stack integration (e.g., DRM/KMS), and UI performance.</li>\n</ul>\n<ul>\n<li>System APIs for permissions, notifications, background execution, storage, device access, and lifecycle management.</li>\n</ul>\n<ul>\n<li>Contribute to reliability and release readiness:</li>\n</ul>\n<ul>\n<li>Production hardening, incident response participation, and cross-team debugging.</li>\n</ul>\n<ul>\n<li>Test strategy across unit, integration, and hardware-in-the-loop environments; improve coverage and reduce flakiness.</li>\n</ul>\n<p><strong>Required qualifications</strong></p>\n<ul>\n<li>Strong experience with systems programming (such as with Linux, BSD, etc), including meaningful work in the kernel (drivers, core subsystems, or platform enablement) and operating systems.</li>\n</ul>\n<ul>\n<li>Professional proficiency in <strong>C, C++</strong> for low-level systems development.</li>\n</ul>\n<ul>\n<li>Experience building or maintaining <strong>core OS services</strong> and platform software (system services, daemons, init/service management, device management, logging/telemetry pipelines).</li>\n</ul>\n<ul>\n<li>Track record of debugging complex issues across kernel/userspace boundaries using tracing, profiling, and structured root cause analysis.</li>\n</ul>\n<ul>\n<li>Familiarity with security fundamentals in OS design: isolation boundaries, privilege separation, secure IPC, attack surface reduction, and vulnerability mitigation.</li>\n</ul>\n<p><strong>Benefits</strong></p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts.</li>\n</ul>\n<ul>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit).</li>\n</ul>\n<ul>\n<li>401(k) retirement plan with employer match.</li>\n</ul>\n<ul>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks).</li>\n</ul>\n<ul>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees.</li>\n</ul>\n<ul>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law).</li>\n</ul>\n<ul>\n<li>Mental health and wellness support.</li>\n</ul>\n<ul>\n<li>Employer-paid basic life and disability coverage.</li>\n</ul>\n<ul>\n<li>Annual learning and development stipend to fuel your professional growth.</li>\n</ul>\n<ul>\n<li>Daily meals in our offices, and meal delivery credits as eligible.</li>\n</ul>\n<ul>\n<li>Relocation support for eligible employees.</li>\n</ul>\n<ul>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p><strong>What we offer</strong></p>\n<ul>\n<li>Competitive salary and equity package.</li>\n</ul>\n<ul>\n<li>Opportunity to work on cutting-edge AI technology.</li>\n</ul>\n<ul>\n<li>Collaborative and dynamic work environment.</li>\n</ul>\n<ul>\n<li>Access to state-of-the-art hardware and software tools.</li>\n</ul>\n<ul>\n<li>Professional development opportunities.</li>\n</ul>\n<ul>\n<li>Flexible work arrangements.</li>\n</ul>\n<ul>\n<li>Comprehensive benefits package.</li>\n</ul>\n<p><strong>How to apply</strong></p>\n<p>If you are a motivated and talented individual who is passionate about building AI-powered products, please submit your application, including your resume and a cover letter, to [insert contact information]. We look forward to hearing from you!</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_98802553-693","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/efed424b-e025-400f-8ac3-73e962b85751","x-work-arrangement":"onsite","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$230K – $385K","x-skills-required":["C","C++","Linux","BSD","kernel","drivers","core subsystems","platform enablement","operating systems","core OS services","platform software","system services","daemons","init/service management","device management","logging/telemetry pipelines"],"x-skills-preferred":["security fundamentals","isolation boundaries","privilege separation","secure IPC","attack surface reduction","vulnerability mitigation"],"datePosted":"2026-03-06T18:23:53.449Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"C, C++, Linux, BSD, kernel, drivers, core subsystems, platform enablement, operating systems, core OS services, platform software, system services, daemons, init/service management, device management, logging/telemetry pipelines, security fundamentals, isolation boundaries, privilege separation, secure IPC, attack surface reduction, vulnerability mitigation","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":230000,"maxValue":385000,"unitText":"YEAR"}}}]}