Senior Security Researcher Job at Truffle Security Co., Savannah, GA

bjVsRVRIOGJLWWxTZXhDaStmR1RiWVQ3Smc9PQ==
  • Truffle Security Co.
  • Savannah, GA

Job Description

TruffleHog is a popular open source tool used by security researchers all over the world to find leaky API keys and responsibly disclose them to affected companies. This provides income through bug bounty platforms like HackerOne to individuals that may otherwise have a hard time finding employment. This also prevents breaches from occurring, which can be very costly for companies to resolve. When we founded Truffle Security Co. in February of 2021, we committed to continue to grow a community with security researchers around the world, and continue to provide free and open resources to support those that make the world more secure. We have a strong commitment to open source and to the community. We’re looking for help supporting our mission to prevent leaking credentials and build the best products for machine identity protection. At Truffle, you’ll have the opportunity to join a fully remote, collaborative team contributing to meaningful advancements in cybersecurity. About the role In this highly visible, community-focused position, you will spearhead open-source security research projects and share your findings with the broader security community via blog posts, videos, webinars, conference talks, and open-source code contributions. By highlighting real-world security vulnerabilities, you’ll help amplify the Truffle Security brand and inspire organizations to better secure themselves. Working closely with our Security Research team lead, you'll have the opportunity to select and run research projects that align with industry trends, emerging threats, product features, and company goals. Your expertise in application security AND one other information security domain will drive the creation of engaging, credible content that resonates with both technical and non-technical audiences. What you'll be working on Conduct cutting-edge open-source security research in areas broadly related to secrets (application security, cloud security, DevSecOps, etc.) Create engaging content to showcase research findings, including blog posts, technical documentation, videos, and whitepapers. Present at conferences and industry events to share your discoveries, represent Truffle Security, and build community interest/trust. Build Proof-of-Concept tools to assist with research and then share them internally with engineering. Contribute to Truffle Security’s Open-Source Tools when research drives new improvements to TruffleHog or requires a new tool altogether. Serve as a security subject matter expert for engineering by helping track down the occasional security bug, providing insight on a new product/feature, and knowledge sharing. Maintain a positive, respectful, and ethical attitude in all external and internal interactions. There's no room for egos or “gotchas” when dealing with security research. What we're looking for Proven background in security research - Ideally, you have written/presented about security vulnerabilities in the past and can share some of these with us. Expertise in application security , plus experience in at least one other category: Cloud Security DevSecOps Data Analytics Blue Team ....Something else? Surprise us! Excellent technical writing skills that demonstrate clarity, depth, and accuracy. History of public speaking on security topics, with the ability to engage and educate technical and non-technical audiences. Intermediate programming skills - your code doesn’t need to be production-ready, but you should be highly comfortable prototyping and building proof-of-concept tools. We work primarily in Python and Golang. Familiarity with LLM tools and how to effectively incorporate them into research and programming workflows. Strong collaboration abilities - You’re equally good at respectfully asking for help and humbly providing it. Ability to juggle multiple long-term research projects - We often run 5 or 6 projects simultaneously without compromising quality or timelines. High ethical standards and integrity - We find many security vulnerabilities in our research, and it takes maturity to handle interactions with the organizations we disclose to. Attention to Detail - There are many moving parts during research projects, and this role requires patience and extreme attention to detail. Please note: At this time, we’re hiring in the United States only for this role as this role involves frequent opportunities to present at conferences and collaborate within US time zones. Salary range: The target salary range for this position is between $167,500 - $197,000. Starting salary will vary based on job-related skills, knowledge, and experience. Leveling will be determined during the interview process. You may also be offered a bonus, stock options, and benefits. These salary ranges are subject to change, and we encourage candidates outside of this salary range to apply. How we support our team Commitment to building a culture of mentorship, equity, and psychological safety. Competitive compensation and equity package. 401(k) with 6% company match. Flexible paid time off 14 paid holidays, including Thanksgiving and Winter break, and "Truffle Holidays" where the entire company takes a day off. Medical, dental, and vision coverage 80% Premium coverage for employees & their dependents. $800 new hire stipend, and $100/monthly thereafter. We want you to be comfortable working remotely. Health & wellness stipend

  • 1,200/year. Maintaining your physical, mental, and emotional well-being is foundational to doing your best work.
  • 2,000/year. Adopting a growth-mindset allows you to grow professionally and personally.
Company off-sites! We’re 100% remote with no office, but won’t let that stop us from working closely together. Past destinations have included Hawaii, Cabo, Chicago, Savannah, and the Rocky Mountains. We’re looking for folks who are interested in being part of the journey to make the internet more secure. The internet is for all, and we believe that diverse experiences and people from all walks of life can contribute to this mission. That said, if what we’re doing resonates with your values, we’d love to have you apply even if you don’t check all of the boxes or match the job description to a tee. Truffle strives to promote an equitable, inclusive, and psychologically-safe workplace for all who are interested in working with us. All job applicants will be considered throughout the employment process without regard to race, color, ethnicity, religion, sex, sexual orientation, gender perception/identity, age, pregnancy or parental status, disability status, or any other basis prohibited by law. If you are an individual with disabilities and reasonable accommodation is needed throughout the interview process, or to perform essential job functions, please let your recruiter know. Lastly, we ask that all applicants consider the opportunity to answer a few voluntary demographic questions on the job application. This helps us track the inclusivity of our recruiting initiatives. Answering these questions is entirely optional and your answers will not be shared with the hiring team and will not impact the hiring decision. Note: Our organization participates in the US federal E-Verify program. We will provide the Social Security Administration, and if necessary, the Department of Homeland Security, with information from each new employee’s Form I-9 to confirm work authorization. We do not use this information to pre-screen job applicants. Apply for this job * indicates a required field First Name * Last Name * Email * Phone * Resume/CV * Enter manually Accepted file types: pdf, doc, docx, txt, rtf Enter manually Accepted file types: pdf, doc, docx, txt, rtf Education School Select... Degree Select... Select... LinkedIn Profile * Work sample * Please provide a link or attachment to a work sample. This can be a link to a blog post, recording to a conference presentation, or your website. How did you hear about this opportunity? * Select... Let us know how you heard about this role. If you were referred, please ask your referral to submit you directly in our system. Are you legally authorized to work in the United States? * Select... All of our roles are currently based remotely throughout the U.S. Will you now (or in the future) require sponsorship for employment in the United States? * Select... #J-18808-Ljbffr Truffle Security Co.

Job Tags

Holiday work, Remote job, Flexible hours,

Similar Jobs

Lucky 7 Logistics

Step Van Delivery Driver Job at Lucky 7 Logistics

 ...Lucky 7 Logistics is a proud Amazon Delivery Service Partner (DSP), delivering excellence...  ...positive, rewarding environment for our drivers. With a focus on teamwork, growth, and reliability...  .... Job Description As a Step Van Delivery Driver, you will be provided... 

Crusoe

Incident Manager Job at Crusoe

 ...impact, and join a team thats setting the pace for responsible, transformative cloud infrastructure. About the Role: This Incident Manager role is critical for upholding service reliability and customer trust, directly impacting company success by minimizing... 

Lexington Fayette Urban Co Government

Treatment Plant Operator (Water Quality) Job at Lexington Fayette Urban Co Government

 ...FILING DEADLINE DATE Open until filled. GENERAL DESCRIPTION The purpose of this classification is to operate a wastewater treatment plant to ensure water discharged is in compliance with local, state, and federal laws and regulations related to health and... 

1 Hotels

Executive Chef Job at 1 Hotels

 ...sustainability, wellness, and social energy exist in thoughtful balance. The Opportunity: Were currently in search of an Executive Chef who shares these values and will champion them at 1 Hotel Austin and who is a proven, effective and natural leader, creates change... 

Pyramid Consulting, Inc

RN Supervisor Job at Pyramid Consulting, Inc

 ...Immediate need for a talented RN Supervisor. This is a 03+months contract opportunity with long-term potential and is located in...  ...for complete inpatient hospital setting case management in acute care looking after Utilization review, Discharge planning of the inpatient...