
Proton · Geneva; Paris; Barcelona
Join Proton and build a better internet where privacy is the default At Proton, we believe that privacy is a fundamental human right and the cornerstone of dem...
Join Proton and build a better internet where privacy is the default
At Proton, we believe that privacy is a fundamental human right and the cornerstone of democracy. Since our inception in 2014,
founded by a team of scientists from CERN, we have dedicated ourselves to providing free and open-source technology to millions
worldwide, ensuring access to privacy, security, and freedom online.
Our journey began with Proton Mail, the largest secure email service globally, and has since expanded to include Proton VPN,
Proton Calendar, Proton Drive, and Proton Pass. These tools empower individuals and organizations to take control of their
personal data, break away from Big Tech’s invasive practices, and defeat censorship. Our work impacts hundreds of millions of
lives, from activists on the front lines defending freedom to leaders in governments protecting sensitive information. In some
cases, Proton’s services have even been instrumental in saving lives by enabling secure and private communications in high-risk
situations.
Proton is a profitable company that does not rely upon VC funding, supporting over 100 million user accounts with a growing team
of over 500 people from over 50 different countries, from the world's top companies and universities. We value intelligence,
learning potential, and ambition in our hiring process. Adaptability is key as we navigate uncharted territories and redefine how
business is conducted online.
Hiring at Proton is highly selective, with less than 1% of candidates hired. We believe smaller teams of exceptional talent will
always prevail over larger teams with lower talent density. You will have the opportunity work with many of the world's top minds
in their fields, ranging from former international math and science olympiad winners to chess champions.
We have a global mindset and big ambitions but remain a start-up at heart. We value empowerment and flexibility and keep our
structure flat to keep moving fast and avoid unnecessary politics. Tired of blending into the crowd? Join us and do work you can
truly be proud of. Check our open-source projects here!
We’re looking for a visionary security professional who combines deep expertise with genuine passion; to drive meaningful change
across our growing organisation. This role sits at the heart of what Proton stands for and fulfills the trust our users place in
us every day. You’ll be encouraged to challenge the status quo, innovate efficiently, and collaborate daily with some of the
brightest minds who truly care about protecting privacy and building secure products.
platforms, including Windows, MacOS, iOS and Linux.
You will be leading our efforts to ensure that Proton's applications are secure
security team
company, influencing strategy, design, and delivery.
risk-aware thinking into a habit.
secure without killing velocity.
into every release.
Even if you don’t meet all the requirements listed above, but feel you could still be a great fit, please still apply.
What We Offer
Barcelona, Paris, London, Vilnius, Skopje, and Taipei. You can also enjoy working from home up to 30% of the time, while
enjoying great company during our three core days in the office. Depending on the role, fully remote positions may also be
available.
disposal to achieve your goals.
parking spaces based on your office location.
training programs, conferences and events, and continual learning.
policies, and wellness programs.
community input. To this day, Proton’s only source of revenue is user subscriptions. Over 100 million people trust and support
Proton, and we put our users and community first in everything we do. Read more about our impact here.
Our Commitment to Diversity and Inclusion
At Proton, we believe diversity drives innovation and strengthens our mission to provide privacy as a default for all. We are
committed to fostering an inclusive environment where all individuals, regardless of race, ethnicity, gender, age, sexual
orientation, physical ability, or socio-economic background, feel valued and empowered. We strive to create equal opportunities,
promote open dialogue, and support continuous learning to ensure every voice is heard and respected.
If you need any extra support or reasonable adjustments during the hiring process, please let your talent partner know.
Candidate Privacy Notice
When you apply for a position, refer a candidate, or are considered for a role at Proton Technologies AG (Proton, we, us, or our),
your information is stored in Greenhouse, in accordance with their Service Privacy Policy. This information is used to evaluate
your suitability for the posted position. We also retain this information for consideration for future roles that you may apply
for or that we believe may align with your background and skills.
If we no longer have a legitimate business need to process your information, we will either delete or anonymize it. Should you
have any inquiries about how we use or manage your information, or if you wish to access, correct, or delete your data, please
contact our privacy team at careers@proton.ch.
Proton does not accept unsolicited resumes from any sources other than directly from candidates. We will not pay a fee for any
placement resulting from an unsolicited offer, even if the candidate is subsequently hired by Proton.
To learn more about our privacy policy, please visit our privacy policy page.
#LI-Onsite
Qube Research & Technologies (QRT) is a global quantitative and systematic investment manager, operating in all liquid asset classes across the world. We are a technology- and data-driven group implementing a scientific approach to investing. Combining data, research, technology, and trading expertise has shaped our collaborative mindset, which enables us to solve the most complex challenges. QRT’s culture of innovation continuously drives our ambition to deliver high-quality returns for our investors. You will join the Security team, working closely with Software Engineers and Infrastructure teams to embed security into the design, development, and operation of systems across cloud services, business applications, and core infrastructure. Your Future Role within QRT You will: * Support the implementation and operation of product security controls across cloud services, core infrastructure, and business applications on Windows and Linux platforms * Work with engineering teams to integrate security into system design and development, applying practical approaches suitable for fast-moving environments * Contribute to secure software development practices, including supporting security reviews across languages such as Python, C++, Rust, Go, and Kotlin/Java * Perform threat modelling, vulnerability assessments, and security code reviews with guidance from senior team members * Assist with integrating and operating security tooling (e.g., SAST, DAST, dependency scanning) within CI/CD pipelines and runtime environments * Identify security risks and contribute to remediation and mitigation plans with engineering teams * Perform vendor security reviews to assess third-party security practices against internal standards * Build your product security knowledge and share learnings with peers across engineering teams Your Present Skillset * 3–5 years of experience in product security, application security, software engineering, or a related role * Hands-on experience with secure coding practices and at least one of: Python, C++, Rust, Go, Kotlin/Java * Solid technical foundation in software development, system architecture, or infrastructure, with a strong interest in security * Working knowledge of security principles and common vulnerabilities affecting software, cloud platforms, and business applications * Experience securing Windows and/or Linux-based systems * Practical experience with at least one cloud platform (AWS or Microsoft Azure), ideally in hybrid environments * Familiarity with threat modelling, vulnerability management, and risk assessment concepts * Experience using or integrating security scanning tools into development workflows and/or CI/CD pipelines * Strong problem-solving skills, clear communication, and willingness to learn in a fast-paced environment * Exposure to low-latency or performance-sensitive systems * Experience in financial services and/or regulated environments * Interest in automation and security tooling development QRT is an equal opportunity employer. We welcome diversity as essential to our success. QRT empowers employees to work openly and respectfully to achieve collective success. In addition to professional achievement, we are offering initiatives and programs to enable employees achieve a healthy work-life balance.
AT A GLANCE Location: Cambridge In-office expectation: Flexible hybrid, once every two weeks Employment type: Permanent Salary: £60,000 to £75,000, depending on experience WHY THIS ROLE EXISTS As Redgate's products scale and AI adoption accelerates across our engineering teams, security needs to be built in from the start rather than checked at the end. This role gives our product teams a trusted security partner who can embed good practice into everyday delivery, strengthen how we detect and prevent issues, and help security keep pace with how quickly we build. ABOUT REDGATE Redgate brings together people who want to do their best work in an environment built on trust, accountability and collaboration. We build solutions that help data professionals securely manage the data and databases their organisations depend on, a space that's only becoming more critical as systems scale, data regulations increase and AI adoption accelerates. AI AT REDGATE By 2028, Redgate will operate as an expert plus agent company: domain experts amplified by AI, delivering customer value at a pace our peers can't match. AI handles the heavy lifting, and our people control the judgement. Everyone at Redgate works with Claude, giving you access to the best AI tools from day one. WHY JOIN OUR PRODUCT SECURITY TEAM? * You'll be one of the first people building out Redgate's product security function, with real influence over how it takes shape rather than joining something already set in stone. * This is specialist security work: you'll be defining standards, governance and practice for engineering teams to work with, not a general engineering delivery role. * Security carries real weight here: you'll have the backing to do the job properly, not just sign off on delivery timelines. As a Product Security Engineer, you'll embed security into the software development lifecycle across multiple product teams. You'll help teams build, ship and operate secure software by defining requirements, improving detection and prevention through SAST and DAST, supporting application security governance and running threat modelling. * Partner with engineering and product teams to define and operationalise security requirements across the full SDLC, from design through to release. * Own or co-own application security governance, including secure-by-default standards, patterns and risk acceptance processes. * Drive SAST and DAST adoption and quality, from tool tuning through to triage workflows and severity calibration. * Support threat modelling for new features, architectural changes and high-risk services, turning findings into actionable engineering work. * Provide product security guidance for cloud-native environments, including AWS and containerised workloads. WHAT MAKES YOU A GREAT FIT * Hands-on product or application security experience within a modern SDLC, including requirements, design review, secure coding guidance and release support. * Strong knowledge of the OWASP Top 10 and practical mitigation patterns, with experience implementing or improving SAST/DAST processes and reducing false positives. * Working understanding of cloud and container security in an AWS and Docker environment, and comfort reviewing code across a primarily C# ecosystem. * Ability to translate security risk into actionable engineering priorities, balancing risk, delivery timelines and operational realities. * Strong communication skills, with the ability to build trust and influence engineering teams without formal authority, including when requirements or ownership aren't yet fully defined. WHAT WE OFFER Salary range: £60,000 to £75,000, depending on experience Hybrid working: home and Cambridge office Monthly wellbeing allowance and generous paid time off Genuine investment in learning, development and career progression Private health insurance WHAT HAPPENS NEXT? * Your application will be reviewed by a person. We don't use AI or automated tools to assess applications, and every profile is read by one of our Talent Partners. * You'll hear back within a few days. Whether it's a next step or a no, we aim to respond promptly so you're not left wondering. * Our interview process is straightforward and consistent. Belonging at Redgate We believe that people do their best work in an environment built on respect, fairness and trust, and that diverse perspectives lead to better outcomes. Redgate is an equal opportunity employer, and we make hiring decisions based on skill, potential and alignment with our values.
ABOUT VERCEL: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience. Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents. We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next. ABOUT THE ROLE: Traditional product security teams work one report at a time: a person triages a bug bounty submission, validates it, reproduces it, and hands it off for a fix. That doesn't scale past a certain volume, and Vercel is well past it. Adding more triagers doesn't close that gap. Building the systems that triage at that scale does. This role is about building that system. Your core focus is tooling that triages and validates bug bounty and other externally reported security findings at scale, reasoning about validity, severity, and reproducibility the way a human triager would, but continuously and at volume. And we want to go beyond triage. The real leverage is in connecting a validated finding to its root cause and driving the fix, ideally with the remediation itself proposed or opened automatically for well-understood vulnerability classes. More broadly, this is a mandate to rethink traditional security tooling for how Vercel actually operates: agent-scale testing and automation in place of processes built for a much smaller company. This role also has real scope to build tooling that gives our customers their own security testing capabilities for what they build on Vercel, not just harden Vercel's own surface. Because of this, we're optimizing for someone who wants to build systems, not someone whose background is manual penetration testing. A software engineer with a strong desire to move into security, or a security engineer with a strong engineering background, is exactly who we're looking for. If you're based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you're located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team. WHAT YOU WILL DO: * Build tooling to triage and validate bug bounty and external findings at scale: Design and operate the systems that take in externally reported vulnerabilities and automatically assess validity, severity, and reproducibility, at a volume no manual triage process could match. * Push triage beyond pattern matching, into agentic analysis: Build and operate LLM/agent-based reasoning that can validate business logic, auth, and design-level findings, not just match against known signatures. * Go from validated finding to root cause: Trace validated findings back to the underlying pattern or class, so the team fixes the reason it happened, not just the one report that came in. * Build toward automated remediation, not just automated triage: Design systems that can propose, and increasingly open, the fix itself for well-understood vulnerability classes, with the right human review gates in place. * Rethink traditional security tooling for scale: Question which parts of the traditional product security toolkit (manual threat modeling, ad hoc code review, point-in-time pentests) still make sense at Vercel's scale, and build the agent-driven tooling that replaces or augments them. * Own and evolve the bug bounty program: Manage the researcher-facing side (scope, policy, engagement) as well as the internal tooling, so every report gets resolved and makes the automated triage smarter for the next one. * Build toward customer-facing security testing capabilities: Extend the tooling and automation you build for Vercel's own products into a capability customers can use to test the security of what they build and deploy on the platform. ABOUT YOU: * You're a builder first: Strong software engineering background is more important here than classic penetration testing experience. You'd rather build the system that triages a thousand reports than work through them one at a time. We're equally excited by a software engineer who wants to move into security and a security engineer with a strong engineering background; a manual pentesting background alone is not what this role is optimized for. * Understand vulnerability triage and validation, even if that's not your primary background: You know (or can quickly learn) how to assess an externally reported finding, reproduce it, and judge severity, and you understand what makes that process hard to scale. * Curious about, or already building with, agentic and LLM-based security tooling: You have a point of view on where AI agents can reliably validate, root-cause, and fix vulnerabilities today, and where they can't yet. * Root cause and systems thinking: You default to "how do I make this scale to the next ten thousand reports" and "why did this class of bug happen," rather than closing the one ticket in front of you. * Comfortable defining a new practice: Agent-scale product security isn't a mature discipline yet. You're excited to help define what it looks like at Vercel rather than inherit a playbook. * Web tech stack proficiency: Strong familiarity with JavaScript/TypeScript and Node.js runtime security, and modern web frameworks (ideally Next.js or React and Node-based frameworks), so you can read and validate the code your tooling is analyzing. BONUS IF YOU: * Have built or contributed to security automation used broadly across an engineering org, not just for your own team. * Have experience running or triaging a bug bounty / vulnerability disclosure program. * Have experience testing or securing multi-tenant platforms where customer-built applications run on shared infrastructure. * Have built systems that auto-generate or auto-propose code fixes, not just findings. * Have thought about what security testing as a product capability could look like for a platform's customers. * Hold relevant security certifications or recognitions (for example, OSCP, OSWE, CISSP, or notable bug bounty hall of fame entries). These demonstrate your depth of knowledge, though they are not required. BENEFITS: * Competitive compensation package, including equity. * Inclusive Healthcare Package. * Learn and Grow - we provide mentorship and send you to events that help you build your network and skills. * Flexible Time Off. * We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed. Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description. The San Francisco, CA base pay range for this role is $208,000.00 - $312,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.