招聘
Bitwarden empowers enterprises, developers, and individuals to securely store and share sensitive data. With a transparent, open-source approach to password management, secrets management, and passwordless and passkey innovations, Bitwarden makes it easy for users to extend robust security practices across all online activities. Founded in 2016 with headquarters in Santa Barbara, California, Bitwarden is supported by a passionate global community of security experts and enthusiasts.
As a Senior Security Engineer at Bitwarden, you will be responsible for conducting purple team testing, including threat research and analysis, penetration testing, code audits, security validation testing, and cryptography reviews against Bitwarden’s products and services. In addition, you will be part of the security findings response team, and assist with external inquiry and report response, investigation, and triage. Additional responsibilities include assisting with remediation of any security issues that are identified during internal or external testing and assessments while working alongside our engineering and security operations team members to ensure Bitwarden platform and services are secure and resilient.
We’re looking for someone who is a self-starter with highly technical skills overlapping offensive and defensive capabilities. The right candidate will have experience using security and vulnerability management tools and solutions to detect and prevent cyber-related vulnerabilities in the company's services and networks as well as to any mobile and Internet-facing applications, systems and environments.
This is an all-remote team and we are looking for someone located in the U.S. We do not offer visa sponsorship at this time.
RESPONSIBILITIES
- Research emerging threats across the surface web, dark web, and deep web
- Build threat models, conduct threat hunts, and plan and execute purple team engagements
- Coordinate internal red team testing operations that emulate a threat actor
- Collaborate with application development teams, platform engineers, and Security Operations Center (SOC) engineers to improve our offensive and defensive security controls
- Contribute to vulnerability testing and analysis as well as incident response and analysis
- Include testing for web, mobile, CLI, and desktop application security issues across our multi-product portfolio, including Bitwarden Password Manager, Secrets Manager, and Passwordless.dev, our APIs, serverless functions, and database
- Participate in code reviews, learning and spreading technical knowledge about security posture
- Contribute to resolutions for security-related issues
- Coordinate technical validation and leadership review of purple team reports detailing testing results and potential areas of improvement
- Conduct internal penetration tests on systems and networks to determine realistic threat vectors
- Manage software tools for code scanning, vulnerability identification, and finding reporting
- Effectively communicate findings, attack paths, and recommendations to stakeholders
- Train others on the adversary simulation tactics and procedures used
- Stay informed on current security trends, publications, and advisories
- Assist to provide guidance and subject matter expertise as it pertains to all areas of security and technical operations, including analysis of our cloud environments, security testing and documentation, as well as investigations, software research, new technology, services and tools research, and vendor security analysis
WHAT YOU BRING TO BITWARDEN
- Experience with Penetration Testing Tools, such as Burp Suite, NMAP, Nessus, Metasploit, Kali Linux, SQLMap, Owasp ZAP, and manual testing tools
- In-depth knowledge of leading vulnerability management tools and strategies
- In-depth understanding and usage of application security testing technologies is a plus
- Understanding of authentication concepts, including OpenIDConnect, SAML, OAuth, and SSO flows
- Strong working knowledge of vulnerability management tools, data and network security technologies
- Collaborative and adaptable mindset
- Openness and authenticity combined with excellent communication skills
- Excitement and enthusiasm for open source and for better internet security
- Excellent problem-solving skills – you might not know all the answers, but you know how to find and communicate the solution
- Ability to maintain discretion, handle sensitive information, and maintain security best-practices
- Security purple team technocrat at heart, staying current with trends and new technologies
NICE-TO-HAVES
- User of Bitwarden
- Experience with C# and TypeScript, the core two languages used to build the Bitwarden platform
- Experience in the Sec Ops world and ability to apply security best practices across the organization
- Experience working in cloud-focused environments
WHAT TO EXPECT IN THE INTERVIEW PROCESS
Selected candidates will be invited to schedule an introduction call and potentially progress through the following stages:
- Interview with Principal Architect
- Interview with lead engineers
- Interview with CTO
- Reference calls
Successful candidates will be asked to authorize and complete a background check. We do not discriminate based on having a criminal record, and we encourage candidates to be open with us about anything that may come up on the report, so we can discuss in advance and determine impact on the role and company.
A FEW REASONS TO WORK WITH US
- Our user community loves us and we love them. Come to work each day with a sense of purpose as we bring a more secure internet experience to everyone––from our friends and family to the world’s largest organizations.
- Become an expert in a growing market. You’ll get immersed in the prominent technology markets of security and open source software.
- Learn and grow professionally. Embrace the opportunity to build up your demand generation and product-led growth expertise in a fast-growing startup.
- We are dedicated to building a diverse and talented team. Work remotely with motivated and supportive team members across the world.
In the United States, the starting base compensation range for this role is $140,000 - $180,000. Actual compensation may vary based on level, relevant experience, and skill set as assessed in the interview process, as well as market data by location. See our careers page for a list of benefits. Please note that compensation outside the U.S. will differ based on the market.
总浏览量
0
申请点击数
0
模拟申请者数
0
收藏
0
相似职位

Senior Systems Security Engineer, Programs
Anduril · Costa Mesa, California, United States

Senior Manager, Security Engineering
PagerDuty · Atlanta

Principal System Security Engineer - P4 (Onsite-Fullerton, CA)
Raytheon (RTX) · US-CA-FULLERTON-675 ~ 1801 Hughes Dr ~ BLDG 675

Senior Consultant _ Cyber Security _ Hanoi Office
EY ·

Sr Security Engineer, AFSS
Amazon · Seattle, WA, USA
关于Bitwarden

Bitwarden
Series BHosting company.
51-200
员工数
Melbourne
总部位置
$285M
企业估值
评价
3.6
30条评价
工作生活平衡
3.5
薪酬
3.8
企业文化
3.8
职业发展
3.6
管理层
3.4
80%
推荐给朋友
优点
Opportunity for career growth
Competitive compensation and benefits
Supportive team and management
缺点
Career progression could be clearer
Some organizational bureaucracy
Internal communication could improve
薪资范围
0个数据点
Junior/L3
L2
L3
L4
L5
L6
M3
M4
M5
M6
Mid/L4
Senior/L5
Junior/L3 · Software Engineer
0份报告
$146,000
年薪总额
基本工资
$146,000
股票
-
奖金
-
$124,100
$167,900
面试经验
53次面试
难度
3.1
/ 5
时长
14-28周
录用率
37%
体验
正面 66%
中性 16%
负面 18%
面试流程
1
Phone Screen
2
Technical Interview
3
Hiring Manager
4
Team Fit
常见问题
Technical skills
Past experience
Team collaboration
Problem solving
新闻动态
Bitwarden is increasing the price for grandfathered customers
It finally happened. They decided to increase the price for legacy/grandfathered customers. The first year will be $14.85 + tax. Afterwards we will pay the full price $19.80 + tax.
·
1w ago
·
160
·
107
Bitwarden is so broken on Android it's not even funny.
No matter the updates, the fucking thing won't appear above the keyboard. Go ahead and try to login to Reddit from the browser. I'm this close to jump ship.
·
2w ago
·
293
·
179
Prompt for building custom instructions.
I’ve been experimenting/building a prompt to help people build good custom instructions to improve the quality of responses and catering them to each persons preferences. Disable any custom instructions you have and then run this prompt and answer the questions as best as you can. I’d love some feedback on where this prompt could be improved. You are an expert prompt engineer specializing in custom instructions for AI assistants. Your goal is to conduct a precise, thorough intervi
·
3w ago
·
5
·
11
The 25+ OpenClaw Skills Worth Installing
**1. StartClaw (run in production)** where is your agent actually running? Most people start locally. That works until you close your laptop and your agent goes offline, or a skill with shell access does something unexpected on the same machine as your SSH keys and personal files. The blast radius of a misconfigured skill on a local setup is your entire environment. [StartClaw ](https://startclaw.com?atp=amyFKM)puts OpenClaw on a dedicated cloud instance, isolated from your personal machine.
·
3w ago
·
178
·
31