Data & Security
Security Engineer.
We secure what we build and prove it. You design security into a system from the start, then attack it to find what we missed, and you own the compliance and governance that let a client rely on the result. Trust is a deliverable here, not a checkbox.
What you’ll do
- Threat-model new systems and build the controls in from the start, authentication, authorization, secrets handling, and data isolation.
- Run application security across our builds, code review, dependency and supply-chain checks, and SAST and DAST wired into CI.
- Pentest our own systems and a client's, find the way in, write the finding up clearly, and confirm the fix.
- Own governance and compliance, map controls to frameworks like SOC 2 and ISO 27001, and produce the evidence a client's auditors and customers ask for.
- Write the incident runbook and lead the response when something happens.
What we look for
- You have done hands-on application security and offensive work, not just policy review.
- You can read code in the languages we ship (TypeScript, Python) and find the real vulnerability, not just run a scanner.
- You know OWASP, cloud IAM, and secrets management, and you have shipped against a compliance framework.
- You write a finding a developer can act on, with the severity honest and the fix concrete.
- You think like an attacker and a builder at the same time.
Why Goldberg
- You build security in and break it yourself, so you are never just signing off on someone else's work.
- Security here is funded and taken seriously, so you build it in rather than bolting it on after launch.
- You see the whole system, from the code to the controls to the audit.
- A small senior team where security has a seat from the first design call.
Not hiring right now
We are not currently hiring for this role.
This is a craft we hire for, but the seat is not open right now. Check back later, or if your work fits another craft, see the other disciplines . If you are early in your career, the apprentice seat may be the way in.