安全工程师,应用安全
Security Engineer, Application Security
关于 Sentry
软件驱动世界,速度比以往任何时候都更快。Sentry 帮助开发者在用户察觉之前修复错误和性能问题,这样团队可以减少灭火时间,更多时间用于构建产品。
被 20 万+ 组织信赖,Sentry 是当今应用监控的标准,我们的团队正在打造其面向 AI 的未来。
关于该职位
安全团队负责保护所有与 Sentry 相关的内容:我们的客户、我们的代码以及两者之间的所有内容。我们是一个小型但不断壮大的团队,拥有广泛的职责范围、高度的信任以及自主解决复杂安全问题的自由。我们在一个具有强大开发者文化的公司工作,打造一款数百万开发者真正喜爱并依赖的产品。这种背景塑造了我们运作的方方面面。
作为该团队的安全工程师,你将跨应用和平台安全领域工作。你将为随着我们成长而保持 Sentry 安全的实践做出贡献:安全审查、威胁建模、漏洞管理,并将安全编码实践嵌入到一个注重正确做事的工程组织中。你将与产品和工程团队紧密合作,从一开始就影响功能的设计和构建。你将作为技术合作伙伴,帮助让安全路径成为显而易见的选择。随着 Sentry 扩展我们的代理产品功能和开发实践,你也将处于一组新的安全挑战的前沿。
在此职位中,你将:
- 支持并帮助完善 Sentry 的安全审查计划。从安全代码审查、架构审查到威胁建模。你将帮助建立流程、工具和文化,使安全成为我们交付和运营的自然组成部分。
- 为成熟的漏洞管理实践做出贡献。包括漏洞接收、分类、优先级排序、修复跟踪,以及对我们的漏洞赏金和负责任披露计划的支持。
- 推广以安全为设计原则。与工程和产品团队合作,将安全早期嵌入开发生命周期,并将安全工具集成到开发者和 CI/CD 流程中。
- 验证和复现应用和基础设施的安全发现结果。对 Sentry 的应用、SDK 和基于云的平台进行扫描、手动测试,以及支持渗透测试和漏洞验证。
- 协助评估和响应与应用程序相关的新兴威胁
查看英文原文
ABOUT SENTRY
Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building.
Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future.
ABOUT THE ROLE
The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate.
As a Security Engineer on this team, you'll work across application and platform security domains. You'll contribute to the practices that keep Sentry secure as we grow: security reviews, threat modeling, vulnerability management, and embedding secure coding practices into an engineering organization that cares about doing things right. You'll partner closely with product and engineering teams to influence how features are designed and built from the start. You will work as a technical collaborator who helps make the secure path the obvious one. As Sentry expands our agentic product capabilities and development practices, you'll also find yourself at the frontier of a new set of security challenges.
IN THIS ROLE, YOU WILL
- Support and help mature Sentry's security review program. From secure code review, to architecture review, and threat modeling. You'll help build the processes, tooling, and culture which make security a natural part of how we ship and operate.
- Contribute to mature vulnerability management practices. Intake, triage, prioritization, remediation tracking, and support of our bug bounty and responsible disclosure program.
- Advocate for secure-by-design principles. Partner with engineering and product teams to embed security early in the development lifecycle and integrate security tooling into developer and CI/CD workflows.
- Validate and reproduce application and infrastructure security findings. Scanning, manual testing, and supporting penetration testing and vulnerability validation across Sentry's application, SDKs and cloud-based platform.
- Help evaluate and respond to emerging threats relevant to application security at Sentry. We build and operate a complex application and cloud environment, including the novel attack surface introduced by Sentry's agentic product features and AI-assisted engineering practices.
YOU’LL THRIVE IN THIS ROLE IF YOU
- Enjoy operating cross-functionally, building relationships, and influencing with technical expertise as you grow into shaping how security gets done across a fast-moving engineering organization.
- Get excited when something new lands on your desk, be it an interesting vulnerability, a sweet exploit, a novel agentic architecture, an unfamiliar cloud primitive, or a bug class you haven't seen before.
- Love working in a developer-forward culture where your colleagues are builders who care deeply about code quality and customer satisfaction.
- Reach for automation first, you'd rather build a scalable, systematic solution to a security problem than solve it manually a hundred times.
- Thrive with ownership and want more of it, you prefer to drive work end-to-end, and you're energized by the autonomy — and the mentorship — that comes with being on a small, high-trust team.
QUALIFICATIONS
- 2+ years of industry experience designing, building, or securing complex applications and cloud systems
- Degree in Computer Science or a related field, equivalent training, or professional experience
- Hands-on experience with several of the following: security reviews, SDLC practices, secure CI/CD, architecture reviews, threat modeling, vulnerability management, bug bounty and responsible disclosure programs
- Experienced and comfortable programming in at least one language, and able to read and reason about code in Python, Typescript, Go, or Rust
- Familiarity with using distributed cloud technology (AWS, GCP, Azure, Kubernetes, Docker, Terraform, etc.) and an understanding of how those technologies are secured (cloud networking, IAM, etc.)
- A collaborative approach to problem solving paired with strong written and verbal communication
Not sure if you meet 100% of the qualifications? We encourage you to apply anyway. We're interested in people are excited about this opportunity and eager to grow.
The base salary range (or hourly wage range, if applicable) that Sentry reasonably expects to pay for this position is $155,000 to $400,000 USD. A successful candidate’s actual base salary (or hourly wage) amount will be determined by a variety of relevant factors including, without limitation, the candidate’s work location, education, work and other relevant experience, skills, and job-related knowledge. A successful candidate will be eligible to participate in Sentry’s employee benefit plans/programs applicable to the candidate’s position (including incentive compensation, equity grants, paid time off, and group health insurance coverage). See Sentry Benefits https://sentry.io/careers/ for more details about the Company’s benefit plans/programs.
EQUAL OPPORTUNITY AT SENTRY
Sentry is committed to providing equal employment opportunities to its employees and candidates for employment regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, or other legally-protected characteristic. This commitment includes the provision of reasonable accommodations to employees and candidates for employment with physical or mental disabilities who require such accommodations in order to (a) perform the essential functions of their jobs, or (b) seek employment with Sentry. We strive to build a diverse team, with an inclusive culture where every teammate can thrive. Sentry is an open-source company because we believe that everyone, everywhere, should have the ability and tools to make great software. Software should be accessible. That starts with making our industry accessible.
If you need assistance or an accommodation due to a disability, you may contact us at accommodations@sentry.io.
Want to learn more about how Sentry handles applicant data? Get the details in our Applicant Privacy Policy https://sentry.io/careers/applicantprivacy/.