远程工作雷达

高级安全工程师

Senior Security Engineer

开发工程全球可投(远程优先企业)
公司Ghost
薪资$140,000 - $190,000/年
工作地点远程
地域资格全球可投(远程优先企业)
时区要求无特别要求
用工类型permanent
发布时间今天
数据来源4dayweek.io
前往 4dayweek.io 查看并投递 →
全球可投:该职位未限制候选人所在地区。仍需注意薪资可能按地区折算,以及实际签约方式(正式雇佣 / 独立合同)。

我们正在寻找一位高级安全工程师,负责Ghost发现、修复和预防安全问题的流程。

### 嗨!我们正在寻找一位新成员加入Ghost团队,也许就是你?

我们是一家非营利组织,致力于打造现代、独立的出版技术,以推动在线新闻的未来。

这不是一家快速扩张的公司。这里没有独角兽的光环或指数级增长曲线,而是一家真正可持续发展的公司,自成立以来每年都实现盈利,并且一直健康地增长。目前我们的年收入超过**1000万美元**。我们对使命和数据保持高度透明,你可以在这里了解更多信息。

Ghost是一个全栈网络应用,用于运营独立出版物。它是全球最受欢迎的现代开源项目之一,被数以万计的网站和公司实际使用。

你很可能已经访问过运行在Ghost上的网站!我们的用户包括知名媒体如**404 Media, Platformer, Tangle News**,以及知名科技公司如**YCombinator, First Round Review, Cloudflare** 和 **Kickstarter**,还有许多其他用户。

### 为拥有庞大受众的小型团队提供安全支持

Ghost运行着数以万计的出版物,运行它们的代码是开源的。任何人都可以阅读它,而且很多人确实如此——研究人员、爱好者,以及越来越多的针对我们仓库的AI工具。这是好事。这也意味着每个月都会不断收到安全报告。

到目前为止,这项工作由我们的团队共同承担。这有效,但Ghost的安全工作需要一个负责人:一个人能够全面掌握整个流程,从研究人员发送的第一封邮件到我们发布的安全公告,并利用他们看到的报告来减少下一类漏洞的出现可能性。

Ghost一直有意保持小规模,大约50人。因此我们不打算建立一个安全部门。相反,我们希望有一位高级工程师,能够系统性地思考安全问题——将报告队列视为关于我们的代码、工具和习惯的信号来源,并改变这些因素,而不仅仅是清空队列。

你将加入我们的平台团队,与每天构建和发布Ghost的工程师密切合作。你也将是研究人员社区联系的人,当团队其他成员不确定某些事情时,他们也会向你咨询。

查看英文原文

We're looking for a Senior Security Engineer to own how Ghost finds, fixes and prevents security issues.

### Hey there! We're looking for a new member to join the Ghost team, maybe that's you?

We're a non-profit organization on a mission to create modern, independent publishing technology to power the future of online journalism.

This is not a rocket-ship. You won't find any unicorn glitter or exponential curves around here, just a real company with a sustainable business which has been profitable from year 1 and has been growing healthily ever since. Currently our annual revenue is **$10,000,000+**. We're very transparent about our mission and our metrics, you can read all about us.

Ghost is a full stack web application for running independent publications. It’s one of the most popular modern open source projects in the world, and is used in production by tens of thousands of websites and companies.

Chances are you've already visited and read sites which run on Ghost! Our users range from renowned publications like **404 Media, Platformer,** **Tangle News**, to prominent tech companies like **YCombinator**, **First Round Review**, **Cloudflare** and **Kickstarter**, and many, many more.

### **Security for a small team with a very large audience**

Ghost runs tens of thousands of publications, and the code that runs them is open source. Anyone can read it, and plenty of people do — researchers, hobbyists, and increasingly, AI tools pointed at our repository. That's a good thing. It also means a steady stream of security reports arriving every month.

So far that work has been shared across our team. It's worked, but security at Ghost deserves an owner: one person who holds the whole picture, from the first email a researcher sends to the advisory we publish, and who uses what they see in the queue to make the next class of bug less likely to exist at all.

Ghost has always believed in staying intentionally small, around 50 people. So we don’t expect to build a security department. Instead we want one senior engineer who thinks about security systemically — who treats the report queue as a source of signal about our code, our tooling and our habits, and who changes those things rather than just clearing the queue.

You'll join our Platform team and work closely with the engineers who build and ship Ghost every day. You'll also be the person our researcher community talks to, and the person the rest of the team asks when they're not sure whether something is safe.

Six months in, we'd hope to see every report getting a real first response within a week, nothing sitting unresolved, at least one automated security check running on every pull request.

### What you'll be doing

🔍 **Own the disclosure lifecycle.** Every security report to Ghost lands with you. You'll triage it, reproduce it, decide whether it's real, and talk to the researcher who sent it. You'll write and publish our advisories, and maintain the policy and pages that tell researchers how to work with us.

🛠 **Fix things in the codebase.** When a report is real, you fix it. That means writing the patch yourself in Ghost's Node.js/TypeScript codebase, getting it reviewed, and shepherding it through to a release.

🧭 **Shift security left.** A growing share of the code at Ghost is written with AI agents, and pull requests are bigger and arrive faster than they used to. You'll design the checks that let that stay fast without becoming a liability: security scanning that runs on every PR, review steps that catch the bug classes we actually see, and threat modelling for the big architectural bets while they're still on the whiteboard.

🤖 **Use AI in the security process itself.** Triage, reproduction, first-pass classification, advisory drafting — you'll build tooling that takes the repetitive parts off your plate and leaves the judgement calls with you.

🎓 **Teach the team.** The best fix is one nobody has to write. You'll turn what you learn from the queue into guidance, examples and short sessions for our engineers, so the same category of bug doesn't keep coming back. You'll review the security side of new features before they ship, and help the rest of the team do that for themselves over time.

🏗 **Harden the platform.** Alongside the platform team, you'll work on the infrastructure that runs Ghost(Pro) — dependencies, supply chain, secrets, access. You'll take part in the on-call rotation.

### What we're looking for  🔎

We're looking for a senior individual contributor who has done this before: someone who has owned application security for a real product, and who is as comfortable writing a patch as writing a disclosure email. You'll be the only person at Ghost whose whole job is security, so you'll set the direction yourself and bring the rest of the team along with you.

You'll probably recognise yourself in most of these:

- **Deep in web application security.** You know the usual list, but more importantly you know how those bugs actually show up in a large Node.js application — XSS, SSRF, auth and session flaws, path traversal, injection, rate-limit and access-control bypasses. You've found them, fixed them, and explained them to people who hadn't heard of them.

- **A strong engineer in our stack.** Ghost is a full-stack JavaScript application. You've shipped production Node.js/TypeScript, and you can land a merge-ready fix in a large, unfamiliar codebase within your first few weeks.

- **A systems thinker.** You see the report queue as data about how code gets written, not just a list of things to fix. You look for the root cause behind the third instance of the same bug, and you'd rather change the process that produced it than fix it a fourth time.

- **Good with researchers.** You've been on one side or the other of coordinated disclosure, and you know how to keep it collaborative — acknowledge quickly, be honest about severity, credit people properly, and say no without being dismissive.

- **Practical about AI.** You've used AI tools in real security work and you have opinions — about where they help, where they produce convincing nonsense, and what it takes to review code that a machine wrote. You're curious about this rather than anxious about it.

- **A clear writer.** We're a remote team that runs on writing. Advisories, incident write-ups, PR descriptions, reviews, messages to researchers — it all needs to be clear, honest and short.

- **High ownership, low ego.** You're comfortable being the only person who owns a thing, and equally comfortable being told your idea isn't the right one. You make progress without waiting for permission, you close loops, and bad news travels from you faster than good news.

### Bonus points for 🎯

- Prior open source contributions, or public advisories with your name on them.

- Experience securing a hosting or multi-tenant SaaS product.

- Experience with the practical side of corporate security — device management, SSO, access reviews — for a small remote team.

- An interest in digital publishing and journalism. Our customers are writers, newsrooms and creators who depend on Ghost to make a living. Caring about what they do matters.

### Salary & benefits

The starting salary range for this position is **$140,000 to $190,000 USD**. Most offers we make fall somewhere in the middle of the range. The exact offer will be determined by a combination of your experience, and our interview process.

On top of that, we offer a range of benefits...

## All jobs at Ghost come with

💵 **Competitive salary** Based on role, skill, experience and location.

🌍 **Work from anywhere** Everything we do is online. As long as you have wifi, you're all set.

💻 **Hardware** A brand new MacBook Pro + a budget for office setup and the latest AI tools.

🏢 **Co-working** If you prefer to work from a co-working space, we'll help pay for it.

📚 **Continue your personal development** A budget for attending conferences, taking courses, and purchasing books.

✈️ **Worldwide team trips** The last few trips have taken us to the UK, Spain & Italy.

📅 **4-day work weeks** We close the office on Fridays. Enjoy!

🏝 **Generous paid vacation** We want everyone to have proper time off. We even shut down for two weeks over Christmas.

👶 **Paid parental leave** When the time comes to welcome a new member of the family, we offer generous and fully paid parental leave.

📈 **Pay reviews** Everyone at Ghost receives an annual pay review against market rates, so your compensation can grow alongside your experience and impact.

🐶 **Dog friendly office**...just kidding we literally don't have an office. So, um. Feel free to work with your dog. Cats are cool, too.

## Who you'll be working with

### **How to apply 🚀**

Our hiring process and timeline can vary from role to role, but typically you can expect:

**Step 1:** We'll review your application against the needs of team.

**Step 2:** A video call with a member of the operations team so we can get to know each other a little better. It's an informal call, there's nothing to prepare.

**Step 3:** A second video call, usually with the hiring manager. This call has a more technical focus and gives you the opportunity to find out what might be like to be a member of the Ghost team.

**Step 4:** A third video call will be with a member of our Leadership Team. During this call, we'd like you to share your screen and pair program with them.

**Step 5:** A paid trial project - typically 15 hours of work. This provides a great opportunity to understand what it's like to work at Ghost.

**Step 6:** A fourth video call to review your trial project.

**Step 7:** A final interview with one of our Leadership Team.

**Step 8:** An offer 🎉.

We receive a lot of applications for each position. A real human member of the Ghost team will review every one, so take your time - we care about the details. We especially encourage applications from women and people from underrepresented groups.

## Not the right position for you?

If this role isn't right for you, but you're interested in hearing about other roles that open up in future, you can subscribe to our careers mailing list! We never use this list for any promotional emails, marketing, or anything else.

本页面信息整理自 4dayweek.io,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

支持主管

Ghost远程$150,000 - $220,000/年permanent2026-08-06
职能支持全球可投(远程优先企业)

← 返回全部职位