Senior Security Engineer

Remote
Full Time
18 hours ago
Senior LevelEngineeringRemote
Over $120K

USD per year

Job Description

Senior Security Engineer We're looking for a Senior Security Engineer to own how Ghost finds, fixes and prevents security issues. Full-time · Remote · UTC-6 - UTC+2 Only Hey there! We're looking for a new member to join the Ghost team, maybe that's you? We're a non-profit organization on a mission to create modern, independent publishing technology to power the future of online journalism. This is not a rocket-ship. You won't find any unicorn glitter or exponential curves around here, just a real company with a sustainable business which has been profitable from year 1 and has been growing healthily ever since. Currently our annual revenue is $10,000,000+. We're very transparent about our mission and our metrics, you can read all about us. Ghost is a full stack web application for running independent publications. It’s one of the most popular modern open source projects in the world, and is used in production by tens of thousands of websites and companies. Chances are you've already visited and read sites which run on Ghost! Our users range from renowned publications like 404 Media, Platformer, Tangle News, to prominent tech companies like YCombinator, First Round Review, Cloudflare and Kickstarter, and many, many more. Security for a small team with a very large audience Ghost runs tens of thousands of publications, and the code that runs them is open source. Anyone can read it, and plenty of people do — researchers, hobbyists, and increasingly, AI tools pointed at our repository. That's a good thing. It also means a steady stream of security reports arriving every month. So far that work has been shared across our team. It's worked, but security at Ghost deserves an owner: one person who holds the whole picture, from the first email a researcher sends to the advisory we publish, and who uses what they see in the queue to make the next class of bug less likely to exist at all. Ghost has always believed in staying intentionally small, around 50 people. So we don’t expect to build a security department. Instead we want one senior engineer who thinks about security systemically — who treats the report queue as a source of signal about our code, our tooling and our habits, and who changes those things rather than just clearing the queue. You'll join our Platform team and work closely with the engineers who build and ship Ghost every day. You'll also be the person our researcher community talks to, and the person the rest of the team asks when they're not sure whether something is safe. Six months in, we'd hope to see every report getting a real first response within a week, nothing sitting unresolved, at least one automated security check running on every pull request. What you'll be doing

  • 🔍 Own the disclosure lifecycle. Every security report to Ghost lands with you. You'll triage it, reproduce it, decide whether it's real, and talk to the researcher who sent it. You'll write and publish our advisories, and maintain the policy and pages that tell researchers how to work with us.
  • 🛠 Fix things in the codebase. When a report is real, you fix it. That means writing the patch yourself in Ghost's Node.js/TypeScript codebase, getting it reviewed, and shepherding it through to a release.
  • 🧭 Shift security left. A growing share of the code at Ghost is written with AI agents, and pull requests are bigger and arrive faster than they used to. You'll design the checks that let that stay fast without becoming a liability: security scanning that runs on every PR, review steps that catch the bug classes we actually see, and threat modelling for the big architectural bets while they're still on the whiteboard.
  • 🤖 Use AI in the security process itself. Triage reproduction first-pass classification advisory drafting — you'll build tooling that takes repetitive parts off your plate leaving judgement calls with you.
  • 🎓 Teach the team. The best fix is one nobody has to write. You'll turn what you learn from queue into guidance examples short sessions for engineers so same category bug doesn't keep coming back. You'll review security side new features before they ship help rest do that themselves over time.
  • 🏗 Harden platform alongside platform team you'll work infrastructure runs Ghost(Pro) — dependencies supply chain secrets access take part on-call rotation.

What we're looking for 🔎 We're looking for senior individual contributor who has done this before: someone who owned application security real product comfortable writing patch disclosure email only person at Ghost whose whole job security set direction yourself bring rest team along. You'll probably recognise yourself most these:

  • Deep web application security: know XSS SSRF auth/session flaws path traversal injection rate-limit/access-control bypasses; found fixed explained them.
  • Strong engineer stack: shipped production Node.js/TypeScript; land merge-ready fix quickly large unfamiliar codebase.
  • Systems thinker: see report queue data how code gets written; look root cause behind repeated bugs; prefer changing process over fixing repeatedly.
  • Good researchers: Experienced coordinated disclosure; collaborative approach; acknowledge quickly; honest severity; credit properly; say no without dismissiveness.
  • Practical AI: Used AI tools real security work; opinions help/nonsense; curious not anxious reviewing machine-written code.
  • Clear writer: Advisories incident write-ups PR descriptions reviews messages need clarity honesty brevity.
  • High ownership low ego: Comfortable owning something alone open feedback; make progress without permission; close loops communicate bad news fast.

Bonus points 🎯

  • Prior open source contributions public advisories name on them.
  • Experience securing hosting multi-tenant SaaS product.
  • Experience practical corporate security (device management SSO access reviews) small remote team.
  • Interest digital publishing/journalism (customers writers newsrooms creators depending Ghost).

Salary & benefits Starting salary range position $140000 $190000 USD (most offers fall mid-range). Exact offer depends experience/interview process. Benefits include:

  • Competitive salary based role skill experience location
  • Work anywhere fully remote
  • Hardware new MacBook Pro + budget office setup latest AI tools
  • Co-working space support preferred
  • Personal development budget conferences courses books
  • Worldwide team trips recently UK Spain Italy
  • 4-day work weeks office closed Fridays
  • Generous paid vacation including 2-week Christmas shutdown
  • Paid parental leave
  • Annual pay reviews against market rates
  • Dog friendly office joke no physical office pets welcome virtually

Who you'll be working with Photos/names/titles shown Steve 🇺🇸 Engineering Hannah 🇬🇧 CTO Austin 🇺🇸 Engineering How apply 🚀 Typical hiring process: 1) Application review against team needs 2) Video call informal intro operations team member 3) Technical video call hiring manager 4) Video call Leadership Team including pair programming screen share 5) Paid trial project (~15 hours) 6) Video call review trial project 7) Final interview Leadership Team member 8) Offer Note Many applications received each reviewed human member encourage applications women/underrepresented groups Apply now link provided Subscribe careers mailing list future roles updates no promotional emails.

How to Apply
About Ghost

Ghost is a powerful app for professional publishers to create, share, and grow a business around their content. It provides modern tools to build websites, publish content, send newsletters, and offer paid subscriptions to members. Ghost is open source, independent, and funded 100% by its users with no investors.

View Company Profile