Accountabilities
- Analyse, investigate, fix, and test vulnerabilities affecting open source packages within the Ubuntu ecosystem.
- Monitor and track vulnerabilities as they are discovered, researched, patched, and released, using internal security tools and processes.
- Collaborate with internal engineering teams, upstream developers, and the wider open source community to develop, exchange, and validate effective security patches.
- Audit source code and software components to identify security weaknesses and potential vulnerabilities.
- Assess security risks and contribute to prioritising remediation efforts based on impact and urgency.
- Design and develop features, automation, and internal tools that help engineering teams improve the security of their products and infrastructure.
- Document security findings, remediation activities, and relevant technical information clearly and accurately.
- Contribute to security initiatives across the broader open source ecosystem and engage with industry communities where appropriate.
- Work effectively within a globally distributed team, taking ownership of projects and maintaining consistent progress with a high degree of autonomy.
Requirements
- Strong understanding of common software security vulnerabilities, attack techniques, and approaches to identifying and fixing them.
- Experience or familiarity with coordinated vulnerability disclosure practices and responsible security communication.
- Familiarity with open source development tools, workflows, and methodologies.
- Proficiency in at least one relevant programming language, such as C, Python, Go, Rust, Java, Ruby, PHP, JavaScript, or TypeScript.
- Experience with Linux, ideally Ubuntu or Debian-based environments.
- Strong analytical, logical reasoning, troubleshooting, and decision-making abilities.
- Excellent communication skills, with the ability to explain technical security issues clearly to engineering teams and open source contributors.
- Strong interpersonal and collaboration skills, with the ability to work effectively across cultures, countries, and distributed teams.
- Curiosity, adaptability, accountability, and a genuine interest in learning about emerging security threats and technologies.
- A self-motivated and thoughtful approach to work, with the ability to manage priorities and deliver against commitments independently.
- A bachelor’s degree or equivalent background in Computer Science, STEM, or a related technical discipline is preferred, although candidates with compelling alternative backgrounds are encouraged to apply.
- Candidates may be considered across multiple experience levels, from graduate to senior, depending on their technical capabilities, achievements, and relevant security experience.
Benefits
- Competitive compensation based on geographical location, experience, and performance.
- Performance-driven annual bonus or commission, depending on role and location.
- Annual compensation review.
- Personal learning and development budget of USD 2,000 per year.
- Recognition and rewards programs.
- Annual holiday leave.
- Maternity and paternity leave.
- Team Member Assistance Program and Wellness Platform.
- Fully distributed and remote working environment.
- Twice-yearly opportunities to meet colleagues in person through team sprints.
- Opportunities to travel internationally and collaborate with colleagues in new locations.
- Priority Pass and travel upgrades for eligible long-haul company events.
- Opportunities to contribute to open source security projects and participate in industry events, publications, and technical initiatives.
- Inclusive, multicultural working environment that values diverse perspectives and experiences.
🇧🇷 Essa vaga exige inglês. Você está pronto?
A DevSpeak Academy prepara desenvolvedores brasileiros para conquistar vagas internacionais. Domine o inglês técnico com professores que entendem o mundo dev.
Conheça a DevSpeak AcademyCandidaturas encerradasVer outras vagas
