Python Software Foundation
Posted 1mo ago

Security Developer

Python Software Foundation
United States or North America
$70k-$170k/yrRemoteFull Time
Responsibilities
  • triaging vulnerabilities
  • remediating malware
  • maintaining infrastructure
Requirements
  • 3+ years with Python or C
  • Knowledge of C memory-safety vulnerabilities
  • Asynchronous and written communication
  • Vulnerability coordination, and open source experience
Technical tools mentioned
PythonCOSS-FuzzCVE

Job description

Working with the Python Security Response Team, Python core team, and Python Package Index (PyPI) admins to ensure Python is secure for its global and diverse user base. The core mandate for this role is to drive vulnerability reports to remediations and advisories, mitigating malware on the PyPI, and developing solutions to scale our capacity to respond ahead of the growth curve.

You’ll be part of the small-but-mighty team at the Python Software Foundation, the US non-profit organization working every day to help Python and its community thrive. Most of your days will be time-boxing between day-to-day vulnerability coordination and malware handling work alongside long-term projects like documentation, tool development, and gathering and sharing metrics.

Core Responsibilities & Development
  • Triage and remediate vulnerabilities in CPython and related projects in coordination with the Python core team.
  • Remediate malware and supply-chain attacks for projects on the Python Package Index.
  • Maintain and operate infrastructure for the Python Security Response Team, PSF CVE Numbering Authority, and security tools in use by Python, like OSS-Fuzz.
  • Propose and develop improvements to the above workflows to scale the response to meet future demand. 
Standards, Documentation, Communications
  • Work with the Python Security Response Team and Python core team to develop and refine vulnerability and secure development practices.
  • Work with the Python core team to document the security and threat models for the Python programming language, standard library, and related projects.
  • Researching, authoring, and publishing public communications about metrics, impact, and potential future work for Python security.
Qualifications

3-5 years experience with Python or C programming languages. Knowledge about vulnerabilities affecting programs written in C, such as memory safety issues. Asynchronous and written communication skills with the ability to manage and prioritize multiple concurrent threads. Experience working with open source projects and communities is a plus.

Security certifications are not required. An ideal candidate will have a collaborative and flexible attitude suited to working with a community of passionate volunteers on small, mutually-supporting teams. Don’t worry if you don’t check all the boxes or aren’t a “security expert”, above all we’re looking for someone who is eager to learn while securing the many domains and users the Python language serves.

Desired Experience

Experience with secure development practices for Python and C programming languages. Experience with vulnerability disclosure, CVE, security teams, and threat models. Experience with code quality and security tools like fuzz-testing, address and memory sanitizers. Experience writing technical documentation. Experience working in public or with open source projects.

Details
  • Location: Global remote. Regular collaboration with US timezones will be required.
  • Compensation: $70-$170K (Based on experience and local employment package norms. US employees are eligible for healthcare and other benefits)
  • Term: 1 year, with possibility of renewal
  • Travel: One trip per year to PyCon US.

About Python Software Foundation

Promotes and advances the Python programming language and community.

Similar jobs

Security Developer roles
5h
Save
Mark Applied
Hide
Security Engineer
United States or Austin
RemoteFull Time
AlertMedia
AlertMedia: Provides emergency communication and threat intelligence software for organizations.
3+ YOERequires 3+ years in security engineering or related work, hands-on AWS security, cloud and application security, CI/CD integration, SOC 2 or ISO audits, incident response, and enterprise customer security reviews.
AWS, Identity and Access Management, Virtual Private Cloud, Key Management Service, Web Application Firewall, Security Hub, GuardDuty, Macie, CI/CD, SOC 2, ISO, Claude, ChatGPT
13h
Save
Mark Applied
Hide
Senior Staff Security Engineer
New York City, New York, United States
$167k-$275k/yr RemoteFull Time
Fanatics
Fanatics: Global digital sports platform for merchandise, collectibles, and betting.
12+ YOE12+ years in security engineering or related work, including 6+ years software engineering; Python, Java, or Go; application and AI security; AWS, WAF, Terraform or Ansible, identity protocols, secure CI/CD, and security strategy experience.
Python, Java, Go, SAST, DAST, IAST, AWS, CloudTrail, GuardDuty, CloudWatch, Security Hub, Cloudflare, Akamai, Fastly, AWS WAF, Terraform, Ansible, OAuth, SAML, OpenID Connect
14h
Save
Mark Applied
Hide
Journeyman Security Engineer
Aberdeen Proving Ground, Maryland, United States
$85k-$98k/yr OnsiteFull Time
Belcan
Belcan: Provides engineering and technical staffing solutions for global industries.
3+ YOERequires US citizenship, active interim Secret clearance, and 3+ years of security analyst or engineer experience. Must obtain IAT Level II certification within 90 days and IAT Level III within six months.
Firewalls (FW), Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), SIEM, Assured Compliance Assessment Solution (ACAS), Endpoint Security Solutions (HBSS), TCP/IP, VMware, Windows, Linux
17h
Save
Mark Applied
Hide
Security Engineer
Bellevue, Washington, United States
OnsiteFull Time
Golden Analytics
Golden Analytics: AI-native business intelligence platform for interactive data analysis.
3+ YOERequires 3+ years in security detection and remediation, security-focused product roles, full-stack development, AI technologies, and securing customer-facing products.
Vite, Node, TypeScript, React, Postgres, Vercel, Supabase
17h
Save
Mark Applied
Hide
Asset & Wealth Management – New York - Associate Security Engineering - 10415579
New York City, New York, United States
$132k-$184k/yr OnsiteFull Time
Goldman Sachs
Goldman SachsNYSE: GS: Global investment banking, securities, and investment management firm.
1+ YOEMaster’s in cybersecurity, computer science, computer engineering, or related field plus 1 year experience, or bachelor’s plus 3 years. Requires cloud, application security, threat assessment, code review, and risk assessment experience.
Java, React, Python, OWASP, CWE, Cloud
18h
Save
Mark Applied
Hide
Lead Security Engineer - Managed Services
United States
$133k-$193k/yr RemoteFull Time
CDW
CDWNasdaq: CDW: Sells and manages IT products and services for organizations.
8+ YOERequires 8+ years in cybersecurity or security engineering, enterprise hybrid/cloud security expertise, IAM, incident response, vulnerability management, secure engineering, and technical leadership. CISSP and other certifications are preferred.
Python, PowerShell, IAM, DevSecOps, Secure SDLC, PCI DSS, SOC 2, HIPAA, ISO 27001, NIST, CIS Controls
19h
Save
Mark Applied
Hide
Security Engineer
United States
$104k-$140k/yr RemoteFull Time
MeridianLink
MeridianLink: Cloud-based digital lending and account opening for financial institutions.
3+ YOEBachelor's degree or equivalent experience; 3+ years as a security engineer; experience in security operations, incident response, threat intelligence, AWS security, IAM, REST APIs, TypeScript or Python, and infrastructure as code.
AWS, WAF, IAM, KMS, GuardDuty, CloudWatch, CI/CD, SAML, OIDC/OAuth, REST APIs, TypeScript, Python, Pulumi, SST, Terraform
20h
Save
Mark Applied
Hide
Security Engineer, GKE
Seattle, Washington, United States
$174k-$252k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
5+ YOEBachelor’s degree or equivalent experience; 5 years in security engineering and distributed cloud computing, including containerization and orchestration; 3 years with GKE; strong cloud security expertise.
Google Kubernetes Engine (GKE), Google Cloud Platform (GCP), Kubernetes, AI/ML