Job Closed

This listing is no longer active.

Open Society Foundations logo
Open Society Foundations

We work to build vibrant and inclusive democracies whose governments are accountable to their citizens.

Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000Since 1979H1B No SponsorCompany SiteLinkedIn

Location

Europe

Posted

103 days ago

Salary

€58K - €78K / year

Seniority

Senior

Professional Certificate3 yrs expEnglish

Job Description

Security Engineer

Open Society Foundations

• Own security issue intake and coordination by triaging reports submitted via our established channels (including private reports through GitHub Security Advisories and our security contact process), reproducing issues where needed, coordinating fixes with maintainers, and ensuring responsible disclosure practices. • Drive timely remediation by tracking SLAs, communicating status with reporters and internal stakeholders, and coordinating releases and backports when required. • Harden our CI/CD and release workflows by improving build pipeline security, secrets management, artifact integrity, and access controls; and by reducing exposure to supply chain attacks. • Strengthen supply chain defenses by improving dependency and artifact verification, provenance, signing, and monitoring; and by hardening the paths through which third-party code and integrations enter the ecosystem. • Build preventive security practices by introducing and continuously improving security testing and scanning in our engineering workflows; including SAST/DAST where appropriate, dependency and artifact scanning, and CI/workflow static analysis. • Coordinate external security work by scoping and managing third-party audits, pentests, and targeted reviews; and by ensuring findings are remediated effectively. • Create and maintain security processes and documentation that are clear, repeatable, and community-friendly, including runbooks for incident response and disclosure. • Collaborate with the community by supporting maintainers and contributors with guidance, reviewing security-relevant pull requests, and helping raise security awareness across the project.

Job Requirements

  • 5+ years preferred, or 3+ years with strong, demonstrated ownership in vulnerability management and CI/CD / supply-chain security.
  • Demonstrated experience triaging and coordinating vulnerability reports (e.g., CVEs, responsible disclosure workflows) and driving remediation across multiple stakeholders.
  • Strong understanding of software supply chain security (dependencies, build systems, artifacts, signing, provenance, CI/CD hardening).
  • Experience securing CI/CD pipelines (e.g., GitHub Actions), including secrets management, permissions, token scopes, and isolation.
  • Practical knowledge of secure software development practices and ability to perform risk assessments and security reviews.
  • Ability to work independently, with strong problem-solving skills and attention to detail.
  • Extensive proficiency with Git and GitHub workflows (pull requests, reviews, merging, etc.).
  • Professional fluency in English, excellent written and verbal communication skills in English.
  • European residency, you must be currently based in Europe and eligible to work within it.

Benefits

  • Five weeks (twenty-five days) of paid time off.
  • Fourteen days of paid sick leave if your country/laws treat them as unpaid.
  • Six weeks of paid and six weeks of unpaid parental leave to be used in the first year after birth. We will provide the missing days if your country/laws do not provide such compensation.
  • A budget for your work hardware once you start.
  • A 50% contribution to your internet connection fee at your home workspace.
  • If you are currently working on Home Assistant-related side projects, you can spend work time maintaining them.

Related Categories

Related Job Pages

More Security Engineer Jobs

Circle logo

Senior Principal Security Engineer, Cloud Security

Circle

Circle helps businesses and developers harness the power of stablecoins for payments and internet commerce worldwide.

Security Engineer103 days ago
OtherRemoteTeam 501-1,000Since 2013H1B Sponsor

• Actively partner with the Senior Director, Security Engineering on the Cloud Security strategy, implementation and operationalization • Evolve, fine tune and expand our current Cloud Security posture across multiple platforms, cloud providers and systems • Develop infrastructure requirements, security controls and delivery pipeline for third party validators running Arc nodes • Recommend and validate Security controls and improvements across our infrastructure stack • Produce data-based reports on technology risk for senior management • Drive continuous improvement in the tech stack

California + 2 moreAll locations: California | Pennsylvania | Texas
$250K - $320K / year
Job Closed
Mozilla logo

Staff Security Engineer

Mozilla

The Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the

Security Engineer103 days ago

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Mozilla is looking for an Incident Responder to monitor and mitigate attacks across Mozilla’s products and services. In this position, you will be a part of a flexible team responsible for handling security incidents. - Identify and respond to security incidents on a global scale. - Act as an incident commander to drive incidents through the entire response lifecycle. - Design and maintain a portfolio of security alerts, automated actions, playbooks and escalation workflows in support of a high-performing 24/7 incident response capability. - Conduct threat hunting activities, anticipate future threats, and maintain forward-thinking strategies for tools/technology/processes that combat sophisticated threat actors. - Research threat intelligence reports, triage and manage resulting workflows. - Partner with key stakeholders and communicate effectively to maintain a continuously improving feedback loop of preparation, identification, analysis, containment, and post mortem activities. - Participate in on-call rotation. Qualifications - 5+ years of demonstrated ability managing security incidents at a global scale and/or experience working in Security Operations Centers (SOC), Product Security Incident Response Teams (PSIRT), and Computer Security Incident Response Teams (CSIRT). - Expertise with security information and event management (SIEM) systems (eg. ELK, Google BigQuery, Splunk, etc.). Splunk proficiency is preferred. - Expertise with integrating and leveraging threat intelligence for detection engineering. - Expertise with security orchestration and automation (SOAR) platforms such as Tines or Splunk SOAR. - Superb communication and leadership capacity; ability to partner effectively with diverse company stakeholders. - Real-world experience in software development and/or engineering operations for consumer products and services; B.S. in a technology-focused field is helpful. - Practical experience working with cloud technologies (eg. Google Cloud Platform, Amazon Web Services, Heroku, Microsoft Azure, etc.). Competencies - Ownership and Accountability - Autonomy - High Level of Integrity - Clear Communication - Creative Problem Solver - Passionate about Security Benefits - Generous performance-based bonus plans to all eligible employees - we share in our success as one team. - Rich medical, dental, and vision coverage. - Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute). - Quarterly all-company wellness days where everyone takes a pause together. - Country specific holidays plus a day off for your birthday. - One-time home office stipend. - Annual professional development budget. - Quarterly well-being stipend. - Considerable paid parental leave. - Employee referral bonus program. - Other benefits (life/AD&D, disability, EAP, etc. - varies by country).

United States
Job Closed
Netflix logo

Group Product Manager, Security Platforms Engineering

Netflix

Described as the world's top internet television network, Netflix is a publicly-traded entertainment company offering video-on-demand and streaming media. As an

Security Engineer103 days ago

• Lead Security Product Experience & Design Engineering (SPEDE) • Drive product strategy and vision across security product offerings • Oversee end-to-end product operations and strategy • Champion product-driven thinking with engineering, design, and security • Actively coach, mentor, and grow the team

United States
$520K - $1,000K / year
Job Closed

Part-Time K–5 Teacher

Virtual Virginia

Virtual Virginia is an online educational portal and resource for middle school and high school students in the US. Virtual Virginia has a long history dating b

Security Engineer103 days ago

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Virtual Virginia (VVA) seeks a Virginia-certified part-time instructor for the K-5 program. The position requires: - Working with curriculum in the Canvas Learning Management System (LMS) - Conducting regular live sessions with students - Holding regular office hours - Maintaining open communication with parents, schools, students, and VVA administrators Qualifications - Bachelor's degree (B.A.) from a four-year college or university - Certification from the Commonwealth of Virginia with the appropriate endorsement - Experience working in an online educational environment is preferred - Experience with the Canvas Learning Management system preferred, but not required - Completion of a three-week teacher training course upon acceptance of the position if not already completed Requirements - Fluent in English - Ability to respond to common inquiries or complaints in a manner consistent with VVA policies and guidelines - Ability to work with mathematical concepts and apply concepts such as fractions, percentages, ratios, and proportions to practical situations - Valid Virginia teacher's license with an endorsement in the appropriate area - Completion of Teaching With Virtual Virginia course or agreement to complete during the next training cycle Physical Demands The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job: - Regularly required to sit - Frequently required to walk; use hands to finger, handle, or feel; and talk or hear - Occasionally required to stand - Frequently lift and/or move up to 10 pounds - Occasionally lift and/or move individual equipment 25 to 50 pounds - Specific vision abilities required include close vision, depth perception, and ability to adjust focus Work Environment The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job: - Noise level is usually quiet, but varies by work location Evaluation Performance of this job will be evaluated in accordance with Virtual Virginia policies and a timeline of evaluation of all program administration and support personnel.

United States
Job Closed