Summary
Patreon is a media and community platform that helps creators build businesses and connect with their fans. The Security Engineer will contribute to security projects, respond to investigations and incidents, address vulnerabilities, write code, and collaborate with engineering, legal, IT, and Risk Engineering partners across application, infrastructure, and corporate security.
Responsibilities
- You’ll split your time between contributing to security projects and responding to security investigations, vulnerabilities, or questions
- The work spans application security, infrastructure security, and internal/corporate security
- It includes both proactive and reactive security work
- You’ll be part of an on-call rotation and help respond to security incidents and investigations
- You’ll write code – both to support security work and to improve the security of the Patreon platform
- You’ll work closely with other members of the security team, the wider Risk engineering org, and cross functional partners in engineering, legal, and IT
- Your work will help reduce known risks and will protect the security, privacy, and trust of Patreon creators and their fans
Skills
- You have two or more years of experience reducing security risks in the application, infrastructure, or corporate security spaces
- You can create a threat model and to explain why a given risk matters and what we might do to reduce it
- You have deeper knowledge (three or more years) in at least one security or security-adjacent domain (infrastructure security, application security, cloud security, corporate/IT security, cryptography, privacy, etc.)
- You can develop software (Python, Rust, Golang, or a similar language)
- You have experience working in a modern software development environment (git, CI/CD, LLM coding tools, etc.)
- You have experience using AI tools (LLMs, ML models, etc) to identify and address security issues (software vulnerabilities, detection and response, etc.)
- You're energized by fast iteration: shipping MVPs, testing hypotheses, and evolving products based on what creators and fans respond to
- You take pride in creating elegant solutions to messy, real-world problems and balancing pragmatic trade-offs between security risks and business needs
- You believe in Patreon's mission: giving creators control over their work and building communities that feel good to be in
- Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field, or the equivalent
- Experience working on large scale Internet platforms that allow users to upload content
- Past contributions to large scale, production code bases
- Experience responding to security incidents, investigating incident impact, and building out incident mitigations
Qualifications
Must Haves
- You have two or more years of experience reducing security risks in the application, infrastructure, or corporate security spaces
- You can create a threat model and to explain why a given risk matters and what we might do to reduce it
- You have deeper knowledge (three or more years) in at least one security or security-adjacent domain (infrastructure security, application security, cloud security, corporate/IT security, cryptography, privacy, etc.)
- You can develop software (Python, Rust, Golang, or a similar language)
- You have experience working in a modern software development environment (git, CI/CD, LLM coding tools, etc.)
- You have experience using AI tools (LLMs, ML models, etc) to identify and address security issues (software vulnerabilities, detection and response, etc.)
- You're energized by fast iteration: shipping MVPs, testing hypotheses, and evolving products based on what creators and fans respond to
- You take pride in creating elegant solutions to messy, real-world problems and balancing pragmatic trade-offs between security risks and business needs
- You believe in Patreon's mission: giving creators control over their work and building communities that feel good to be in
- Bachelor's or Master's degree in Computer Science, Computer Engineering, or a related field, or the equivalent
Nice to Haves
- Experience working on large scale Internet platforms that allow users to upload content
- Past contributions to large scale, production code bases
- Experience responding to security incidents, investigating incident impact, and building out incident mitigations
Benefits
- Equity plans
- Healthcare
- Flexible time off
- Company holidays
- Recharge days
- Commuter benefits
- Lifestyle stipends
- Learning and development stipends
- Patronage
- Parental leave
- 401k plan with matching
- Fully remote for US-based employees; employees based in New York or San Francisco may work on a hybrid model with three days per week in the office
- Paid leave