Who we're looking for- Risk-focused and pragmatic. You excel at identifying and reasoning about security risk in real-world contexts. You prioritize ruthlessly, always asking: what's the most effective way to reduce risk right now and in the long term?
- A builder who can break things. You're comfortable reading and writing code, and you have a passion for deeply understanding the products you secure. You think like an attacker to find subtle, high impact vulnerabilities and like a defender to design pragmatic, effective mitigations.
- A strong partner to engineering. You build trust with engineers by understanding their priorities, making security frictionless, and finding ways to make the secure path, the easiest path.
- Excited about AI. You're embracing AI and automation to scale security and reduce toil.
- Curious and humble. You ask the basic questions, enjoy untangling complex systems, and bring others along with you.
Responsibilities- Lead secure design efforts. Partner with engineering teams on secure design and code reviews. Identify and prioritize risks early in the product lifecycle.
- Build secure by default systems. Develop paved paths that systemically reduce risk and make secure development the easiest path for engineers.
- Perform offensive security testing. Conduct penetration tests and code audits on new and existing products from an adversarial lens.
- Improve our security tooling. Integrate and improve our static analysis, supply chain security, and vulnerability management capabilities across engineering pipelines.
- Operate our responsible disclosure program. Run and improve our program by furthering automation, validating submissions, and coordinating remediation.
- Improve our products. Write and ship code to remediate vulnerabilities in production systems and improve the security posture of WorkOS products.
- Work directly with customers. Help build our customers' trust by directly engaging with their security-related questions and concerns.
Qualifications- 5+ years of experience in a security engineering or security-focused software engineering role.
- Ability to execute across a wide range of security functions such as security assessments, penetration testing, responsible disclosure, security tooling integration, etc.
- Familiarity with and experience using common industry tooling.
- Proven ability to identify vulnerabilities in software, demonstrated through CVEs, bug bounty, blog posts, or prior work experience.
- Strong written and verbal communication skills, particularly in partnering with engineering teams.
- Comfortable reading and writing code, and able to effectively leverage AI during the process.
- Bonus: Experience in the authentication and identity domain.
- Bonus: Experience writing production level code, especially developing security features.
Benefits and Perks (
US Only) π
At WorkOS, we offer resources that emphasize personal and familial well-being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid-time off and fully remote working arrangements.
- 401k matching
- Competitive Equity
- Healthcare, dental and vision coverage
- FSA, ST/LT Disability, Voluntary Life
- Carrot fertility benefits
- 20 days paid vacation + 10 holidays + unlimited sick leave
- 12 weeks fully paid parental leave
- Fitness: Monthly stipend for gyms, yoga classes, race registrations or whatever keeps you active
- Wellness: Monthly stipend for a massage, meditations class, therapy, or activities that enhance your well-being
- Commuter benefits for hybrid employees in SF/NYC
- Unlimited token usage!
Please inquire directly with our recruiting team for benefits available to those working outside the US.