Summary
Patreon is a media and community platform that helps creators build businesses and connect with fans. The Security Engineer will contribute to security projects, respond to investigations and incidents, develop security-focused software, and address application, infrastructure, and corporate security risks.
Responsibilities
- You'll split your time between contributing to security projects and responding to security investigations, vulnerabilities, or questions
- The work spans application security, infrastructure security, and internal/corporate security
- It includes both proactive and reactive security work
- You'll be part of an on-call rotation and help respond to security incidents and investigations
- You'll write code - both to support security work and to improve the security of the Patreon platform
- You'll work closely with other members of the security team, the wider Risk engineering org, and cross functional partners in engineering, legal, and IT
- Your work will help reduce known risks and will protect the security, privacy, and trust of Patreon creators and their fans
Skills
- You have two or more years of experience reducing security risks in the application, infrastructure, or corporate security spaces
- You can create a threat model and to explain why a given risk matters and what we might do to reduce it
- You have deeper knowledge (three or more years) in at least one security or security-adjacent domain (infrastructure security, application security, cloud security, corporate/IT security, cryptography, privacy, etc.)
- You can develop software (Python, Rust, Golang, or a similar language)
- You have experience working in a modern software development environment (git, CI/CD, LLM coding tools, etc.)
- You have experience using AI tools (LLMs, ML models, etc) to identify and address security issues (software vulnerabilities, detection and response, etc.)
- Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field, or the equivalent
- Experience working on large scale Internet platforms that allow users to upload content
- Past contributions to large scale, production code bases
- Experience responding to security incidents, investigating incident impact, and building out incident mitigations
Qualifications
Must Haves
- You have two or more years of experience reducing security risks in the application, infrastructure, or corporate security spaces
- You can create a threat model and to explain why a given risk matters and what we might do to reduce it
- You have deeper knowledge (three or more years) in at least one security or security-adjacent domain (infrastructure security, application security, cloud security, corporate/IT security, cryptography, privacy, etc.)
- You can develop software (Python, Rust, Golang, or a similar language)
- You have experience working in a modern software development environment (git, CI/CD, LLM coding tools, etc.)
- You have experience using AI tools (LLMs, ML models, etc) to identify and address security issues (software vulnerabilities, detection and response, etc.)
- Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field, or the equivalent
Nice to Haves
- Experience working on large scale Internet platforms that allow users to upload content
- Past contributions to large scale, production code bases
- Experience responding to security incidents, investigating incident impact, and building out incident mitigations
Benefits
- Equity plans
- Healthcare
- Flexible time off
- Company holidays and recharge days
- Commuter benefits
- Lifestyle stipends
- Learning and development stipends
- Patronage
- Parental leave
- 401k plan with matching
- Fully remote work for US-based employees
- Hybrid work in New York or San Francisco, with employees based in office locations expected to come into the office three days per week