Security Researcher

🔥 27 minutes ago

🌏 Anywhere in the World

đź’µ $80 / hour

⏳ Contract/Temporary

🟡 Mid-level

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Freedom of the Press Foundation

Freedom of the Press Foundation

11 - 50 employees

Founded 2012

🤝 Non-profit

📱 Media

đź”’ Cybersecurity

đź’° $480k Grant - Freedom of the Press Foundation on 2013-12

Non-profit • Media • Cybersecurity

Freedom of the Press Foundation is a nonprofit organization that protects and defends press freedom by supporting journalists and whistleblowers. It publishes reporting on government secrecy, surveillance, and journalists' rights; develops and maintains open-source security tools for journalists and newsrooms (notably SecureDrop and Dangerzone); runs the U. S. Press Freedom Tracker database documenting press freedom incidents; and provides digital security training and resources. The organization also advocates on issues such as government surveillance and the legal rights of reporters, and solicits donations and public action to support its work.

đź“‹ Description

• Conduct application security reviews across SecureDrop components. • Assist in performing threat modeling for new features and architectural changes. • Review pull requests and design documents with a focus on the security properties of new features and the security implications of architectural changes. • Assist in preparing materials for and reviewing findings from third-party security audits. • Advise on hardening strategies for SecureDrop’s deployment environments. • Review and integrate security automation tooling, such as LLMs, static code analyzers, and other tools that can mitigate or discover security vulnerabilities.

🎯 Requirements

• At least three-plus years experience designing or attacking secure systems (threat modeling, penetration testing, security assessments, protocol design, etc.) • Production coding experience using at least two of the following: Python, Typescript, or Rust. • Strong working knowledge of Linux systems security (kernel hardening, AppArmor, SELinux, etc.) • Experience identifying and reasoning about browser/web vulnerabilities (XSS) and Electron-specific issues (file handling, IPC, etc.) • Comfort working with open source projects in a collaborative, distributed team environment. • One-plus year of professional experience with Qubes OS, Tails, or other high-security desktop environments (preferred). • One-plus year of professional incident response experience (preferred). • Using or developing security monitoring tools (e.g., intrusion detection systems, file integrity monitoring) (preferred). • Familiarity with Tor, onion services, OpenPGP, and other privacy-enhancing technologies (preferred).

Apply Now

Similar Jobs

đź•’ July 1

CENSUS

51 - 200

đź’Ľ Consulting

🏥 Healthcare

đź”’ Cybersecurity

Senior Product Security Consultant at CENSUS LABS evaluating software security and threats. Responsible for validating security compliance and reporting on risks in complex systems.