
Senior Security Engineer
Overview
We're looking for a Senior Security Engineer to own how Ghost finds, fixes and prevents security issues.
Job Description
Ghost is a non-profit organization on a mission to create modern, independent publishing technology to power the future of online journalism. This is not a rocket-ship. You won't find any unicorn glitter or exponential curves around here, just a real company with a sustainable business which has been profitable from year 1 and has been growing healthily ever since. Currently our annual revenue is $10,000,000+. Ghost is a full stack web application for running independent publications. It’s one of the most popular modern open source projects in the world, and is used in production by tens of thousands of websites and companies.
Responsibilities
- - Own the disclosure lifecycle. Every security report to Ghost lands with you. You'll triage it, reproduce it, decide whether it's real, and talk to the researcher who sent it.
- - Fix things in the codebase. When a report is real, you fix it. That means writing the patch yourself in Ghost's Node.js/TypeScript codebase, getting it reviewed, and shepherding it through to a release.
- - Shift security left. You'll design the checks that let that stay fast without becoming a liability: security scanning that runs on every PR, review steps that catch the bug classes we actually see, and threat modelling for the big architectural bets while they're still on the whiteboard.
- - Use AI in the security process itself. You'll build tooling that takes the repetitive parts off your plate and leaves the judgement calls with you.
- - Teach the team. You'll turn what you learn from the queue into guidance, examples and short sessions for our engineers.
- - Harden the platform. Alongside the platform team, you'll work on the infrastructure that runs Ghost(Pro) — dependencies, supply chain, secrets, access.
Required Skills
- - Deep in web application security. You know the usual list, but more importantly you know how those bugs actually show up in a large Node.js application — XSS, SSRF, auth and session flaws, path traversal, injection, rate-limit and access-control bypasses.
- - A strong engineer in our stack. You've shipped production Node.js/TypeScript, and you can land a merge-ready fix in a large, unfamiliar codebase within your first few weeks.
- - A systems thinker. You see the report queue as data about how code gets written, not just a list of things to fix.
- - Good with researchers. You've been on one side or the other of coordinated disclosure, and you know how to keep it collaborative.
- - Practical about AI. You've used AI tools in real security work and you have opinions about where they help.
- - A clear writer. Advisories, incident write-ups, PR descriptions, reviews, messages to researchers — it all needs to be clear, honest and short.
- - High ownership, low ego. You're comfortable being the only person who owns a thing, and equally comfortable being told your idea isn't the right one.
Benefits
- - Competitive salary based on role, skill, experience and location.
- - Work from anywhere. Everything we do is online.
- - A brand new MacBook Pro + a budget for office setup and the latest AI tools.
- - If you prefer to work from a co-working space, we'll help pay for it.
- - A budget for attending conferences, taking courses, and purchasing books.
- - Worldwide team trips.
- - 4-day work weeks. We close the office on Fridays.
- - Generous paid vacation.
- - Paid parental leave.
- - Annual pay reviews against market rates.
About the company
Ghost is a powerful app for professional publishers to create, share, and grow a business around their content. It comes with modern tools to build a website, publish content, send newsletters & offer paid subscriptions to members.
All Job Openings at Ghost