- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 days ago
- Work mode
- Work from home
- Resume
- Required to apply
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
This position involves tackling complex security issues related to software services, such as API token trust flaws, tenant boundary escapes, and inappropriate build dependencies. You will work within a software supply chain company delivering a platform that manages how customers handle and distribute software packages.
Collaborating closely with engineering teams during design and development, you will review architectural plans, question underlying assumptions, analyze code, and implement necessary fixes.
Key Responsibilities
- Conduct threat modeling for APIs, identity management flows, and distributed systems.
- Identify vulnerabilities in authorization mechanisms, secrets management, and tenant isolation.
- Develop Python-based tools and reusable security modules.
- Assess vulnerabilities to determine exploitability and prioritize remediation efforts.
Expectations and Skills
The ideal candidate is someone who started as a software engineer and gravitated towards security challenges or an experienced application security professional with a coding background. Proficiency in Python, hands-on experience with AWS, and familiarity with code review processes are essential. Additional knowledge of Go, Rust, or TypeScript is advantageous. Experience or strong interest in software signing, provenance, and supply chain security is highly desirable.
Additional Information
- Position is remote-first across Ireland and the UK, with occasional travel for team meetings.
- Role includes equity, healthcare benefits, and a budget dedicated to learning and development.
- Applicants must have the right to work in the region without the need for sponsorship.