> Markdown version of [/jobs/ext/3045764-backend-engineer-security](https://www.wearedevelopers.com/jobs/ext/3045764-backend-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Backend Engineer (Security) - **Company:** Postaladdress - **Location:** UK (Remote available) - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Programming Tools, Github, Intrusion Detection and Prevention, Node.Js, Open Source Technology, TypeScript, Software Vulnerability Management, Backend, Free and Open-Source Software, Discord, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://startup.jobs/backend-engineer-security-triggerdev-10164985 ## About the Role The ideal person here is a backend engineer with genuine offensive-security instincts - someone who naturally gravitates toward hacking, pen testing, and breaking things, and brings that curiosity into how they build. You'll pair strong backend/product instincts with a hacker's mindset., Real backend engineering experience. You can design and ship production backend systems, not just audit someone else's. Genuine offensive-security curiosity. Pen testing, CTFs, bug bounty hunting, or hacking as a hobby or discipline - this isn't a checklist role. Comfort owning ambiguous, product-shaped security problems. Sandboxing and runtime isolation are engineering problems as much as they are security ones. A proactive mindset. This role should take work off the team's plate, not create a queue for others - we're not looking for a security box-ticker. Comfortable being on call. Reliability and security response are shared responsibilities across the team. Open to in-person events throughout the year. If you're remote, we'll arrange these so the team gets real time together. You'll be an amazing fit if you have: * Experience building or hardening sandboxed/isolated execution environments (containers, microVMs, gVisor, Firecracker, WASM sandboxes, or similar). * A track record in pen testing, bug bounty programs, or CTFs. * Experience using AI-assisted tooling for security scanning or workflows. * A proven track record of contributing to open source projects. * Worked at a developer tools, infrastructure, or open source company. * Experience with Node.js and TypeScript, enough to read and review application code. ## Description Sandbox and runtime security. Designing and maintaining the secure execution environments that isolate untrusted user code - the core, product-shaped problem at the heart of this role. Threat detection and incident response. Building monitoring and alerting for suspicious activity, and leading the response when something needs investigating. Vulnerability management, end to end. Regular scanning and triage, plus AI-assisted security scans run on a quarterly cadence, and triaging incoming disclosures. Offensive security. Running internal, AI-assisted pen testing, and potentially bringing in external firms for deeper engagements. PR security review. Adding a security-specific review layer on top of our normal PR process. SOC 2 and compliance. Mostly done already - this is about ongoing maintenance, not standing it up from scratch. Vulnerability disclosure process. Owning our vulnerability disclosure program end to end. Security culture. Helping the wider engineering team build secure habits - reviews, documentation, and pragmatic guardrails rather than heavy process. Working at a Commercial Open Source Software company is more than just security work: * We have an active community on Discord and GitHub. Everyone on the team helps customers, reviews PRs, and creates issues. * Having great documentation is essential. Everyone writes docs. * We're a product-led growth company, so everyone is expected to get involved in creating content like code examples, blog articles, videos, and tweets. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Stop using Node.js like in 2020! What changed and what you can do today with Node.js](https://www.wearedevelopers.com/videos/100011-stop-using-node-js-like-in-2020-what-changed-and-what-you-can-do-today-with-node-js) - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)