Wikimedia Security Engineering Project

New

Skills

Engineer Javascript Linux Php Security Software Engineering Web Application Development

Summary The Wikimedia Foundation is looking for a Staff Security Software Engineer to join the Product Security team to build new security technologies to protect Wikipedia and our other projects. This is a very hands-on engineering role working alongside our other security team members to design and code new features to protect and reassure our users and to ensure the platform remains resilient against attacks. YOU ARE ...a smart developer with experience building security features in large-scale systems. You understand the importance of testing and documentation, and common pitfalls in developing secure web applications. You have a passion for the WMF mission. We do (almost) everything publicly and the work we do touches thousands of editors every day. You will be working primarily on our MediaWiki platform which powers Wikipedia. As a top 10 website, we must meet stringent performance standards while addressing new security challenges such as supporting modern authentication technologies, detecting and preventing platform abuse from bots, and planning and rolling out improvements to our security architecture by defending against emerging security threats. You are responsible for: Help design and build MediaWiki security capabilities Mentor and lead a security development team Review and deploy security features developed by the Foundation and community members Work with other development teams to ensure that they make safe architectural and implementation choices Perform security maintenance and address technical debt in security-critical components Provide support for application security incidents and operations Skills and Experience: The right person is better than the right set of experiences, these are the traits we’ve identified that make great additions to our team so far. +8 years of experience in the software engineering area with a focus on security Ability to work effectively in a modern, object-oriented PHP code-base Experience developing client-side JavaScript Experience in developing secure software or security-related product features A strong interest in working with a talented security team and learning more specialist security skills such as exploiting and mitigating application-level vulnerabilities Patience in explaining security issues and their implications on privacy and risk to non-technical audiences Sensitivity to the security challenges faced by participants in a large, international project Experience using Linux at the command line for tasks related to web application development and deployment Ability to maintain focus when working remotely Additionally, we’d love it if you have: Experience working on anti-abuse mechanisms such as CAPTCHA and bot detection Previous experience building security countermeasures against attacks on technologies at the web, backend, and database level Experience finding and fixing security bugs and reviewing code for security gaps A working knowledge of threat modeling and secure design patterns About the Wikimedia Foundation The Wikimedia Foundation is the nonprofit organization that operates Wikipedia and the other Wikimedia free knowledge projects. Our vision is a world in which every single human can freely share in the sum of all knowledge. We believe that everyone has the potential to contribute something to our shared knowledge, and that everyone should be able to access that knowledge freely. We host Wikipedia and the Wikimedia projects, build software experiences for reading, contributing, and sharing Wikimedia content, support the volunteer communities and partners who make Wikimedia possible, and advocate for policies that enable Wikimedia and free knowledge to thrive. The Wikimedia Foundation is a charitable, not-for-profit organization that relies on donations. We receive donations from millions of individuals around the world, with an average donation of about $15. We also receive donations through institutional grants and gifts. The Wikimedia Foundation is a United States 501(c)(3) tax-exempt organization with offices in San Francisco, California, USA. As an equal opportunity employer, the Wikimedia Foundation values having a diverse workforce and continuously strives to maintain an inclusive and equitable workplace. We encourage people with a diverse range of backgrounds to apply. We do not discriminate against any person based upon their race, traits historically associated with race, religion, color, national origin, sex, pregnancy or related medical conditions, parental status, sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, or any other legally protected characteristics. The Wikimedia Foundation is a remote-first organization with staff members including contractors based 40+ countries*. Salaries at the Wikimedia Foundation are set in a way that is competitive, equitable, and consistent with our values and culture. The anticipated annual pay range of this position for applicants based within the United States is US$129,347 to US$ 200,823 with multiple individualized factors, including cost of living in the location, being the determinants of the offered pay. For applicants located outside of the US, the pay range will be adjusted to the country of hire. We neither ask for nor take into consideration the salary history of applicants. The compensation for a successful applicant will be based on their skills, experience and location. *Please note that we are currently able to hire in the following countries: Australia, Austria, Bangladesh, Belgium, Brazil, Canada, Colombia, Costa Rica, Croatia, Czech Republic, Denmark, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, India, Indonesia, Ireland, Israel, Italy, Kenya, Mexico, Netherlands, Nigeria, Peru, Poland, Singapore, South Africa, Spain, Sweden, Switzerland, Uganda, United Arab Emirates, United Kingdom, United States of America and Uruguay.  Our non-US employees are hired through a local third party Employer of Record (EOR). We periodically review this list to streamline to ensure alignment with our hiring requirements. All applicants can reach out to their recruiter to understand more about the specific pay range for their location during the interview process. If you are a qualified applicant requiring assistance or an accommodation to complete any step of the application process due to a disability, you may contact us at recruiting@wikimedia.org or +1 (415) 839-6885. More information U.S. Benefits & Perks Wikimedia Foundation Applicant Privacy Policy News from across the Wikimedia movement Blog Wikimedia 2030 Our Commitment to Equity This is Wikimedia Foundation  Facts Matter Our Projects Our Tech Stack

Job Type: Remote

Salary: Not Disclosed

Experience: Entry

Duration: 12 Months

Share this job:

Similar Jobs

Support Engineer

New

Provide timely and empathetic customer support.

Troubleshoot technical issues across cloud providers and systems.

AWS Ci/cd Pipelines Devops Engineer

Senior Java Full Stack Engineer

New

Lead the development of software solutions using Java technologies

Collaborate with cross-functional teams to meet project requirements

Angular Continuous deployment Continuous integration Engineer

Senior Analytics Engineer

New

Hiring a Senior Analytics Engineer remotely

Axios - Smart brevity

Collaboration Communication Data Analysis Data Analytics

Experienced Software Engineer

New

Seeking experienced software engineers globally

Focused on open-source contributions

Ai Continuous integration Engineer Gutenberg

Senior Systems Engineer

New

Ensure high availability, performance, and security of global infrastructure.

Optimize server-side and client-side interactions for speed.

Automation Engineer Monitoring Mysql

Seat Management Engineer

New

Optimize customers' GitLab investment through seat assignment and cost management

Collaborate with various teams to refine solutions and ship high-quality features

Engineer Git Grafana GraphQL

Principal AppSec Engineer

New

Drive resolution of systemic vulnerability classes and mitigations

Perform difficult and highly complex application security reviews and threat modeling

Communication Engineer Gitlab Go

Principal Software Engineer Role

Posted 3 days ago

Design and develop software applications

Optimize application performance

C# Css Engineer Front end

Senior Software Engineer - C#

Posted 3 days ago

Design, build, and maintain code efficiently

Suggest improvements to enhance client experience

AWS Azure C# Css

Senior DevOps Engineer - AI & Data Infrastructure

Posted 3 days ago

Transform education and productivity through AI technology

Build and maintain infrastructure for running end-to-end AI technology

AWS CircleCI Datadog Devops

Senior iOS Engineer

Posted 3 days ago

Hiring a Senior iOS Engineer for FullStory

Remote full-time position in the United States

Code reviews Cross-functional Collaboration Engineer Ios Development

C/C++ Data Recovery Engineer

Posted 4 days ago

Enhance data recovery tools through C/C++ development

Analyze and extract data from storage technologies

Engineer Python Rust Software Engineering

Junior Ubuntu Engineer

Posted 4 days ago

Hiring junior engineers for Ubuntu Engineering projects

Focusing on quality, performance, and resilience in software development

Devops Engineer Flutter Go

Networking Software Engineer

Posted 4 days ago

Develop cutting-edge open source networking software.

Optimize performance in collaboration with public clouds and silicon providers.

Devops eBPF Engineer Golang

Ubuntu Software Engineer

Posted 4 days ago

Hiring engineers to work on the Ubuntu platform

Seeking individuals with a passion for open source software

Architecture Build Systems Devops Engineer

Senior Security Engineer - Application Security

Posted 4 days ago

Conduct security-focused application design and architecture reviews

Propose and establish secure development practices and security standards

Architecture Cloud Engineer Go

DevRel Engineer - Mandarin Speaking

Posted 4 days ago

Support developers across APAC in integrating LI.FI

Create technical content in Chinese and English

Communication Engineer Erc-20 Javascript

Senior QA Engineer

Posted 6 days ago

Ensure highest product quality through testing strategies

Design and execute automation scripts for testing

Agile API Testing Asana Automation

Sr Software Engineer - Frontend

Posted 6 days ago

Design, develop, test, integrate, and support frontend solutions

Make design and technical decisions for applications

AngularJS Css Engineer Front end

Senior Backend Engineer (Ruby on Rails)

Posted 6 days ago

Lead improvements in CI pipeline execution reliability, performance, and scalability.

Design and iterate on features for faster software delivery.

Backend Services CI/CD Database Optimization Engineer

Remote Senior Software Engineer

Posted 6 days ago

Hiring a Senior Software Engineer remotely

Full-time position with no geographical restrictions

Communication Skills Engineer Java Problem-solving

Senior Data Engineer

Posted 7 days ago

Develop a reliable market data platform

Deliver historical and real-time pipelines

AWS Engineer Observability Python

Backend Engineer (Golang)

Posted 7 days ago

Build high-scale Golang backend services and data pipelines

Design and improve dashboards for actionable insights

AWS Ci/cd Pipelines Devops Engineer

Frontend Software Engineer (React)

Posted 8 days ago

Hiring experienced frontend engineers for high-impact AI collaborations.

Developing and validating coding benchmarks in React, TypeScript, or JavaScript.

Computer science Debugging Engineer Integration Testing

Embedded Linux Field Engineer

Posted 9 days ago

Seeking an Embedded Linux Field Engineer for mission-critical industries

Expanding reach in Automotive, Medical Devices, Robotics, and more

C C++ Debian Devops

Distributed Systems Testing Engineer

Posted 9 days ago

Developing CI pipelines for cloud integration testing

Enhancing continuous integration pipelines for deploying cloud products

Ci/cd Pipelines CircleCI Devops Engineer

MLOps Field Engineer

Posted 9 days ago

Design and deploy AI/ML infrastructures

Work directly with customers on cloud solutions

Big Data Devops Engineer Kubernetes

Senior Software Engineer - IoT Platform

Posted 10 days ago

Seeking a Senior Software Engineer with experience in edge software development for IoT platforms.

Require expertise in Python, C/C++, Rust, and Linux for designing resource-constrained software.

CI/CD Cross-functional Collaboration Devops Distributed systems

Senior MacOS Engineer

Posted 10 days ago

Build the best Mac desktop experience for notes capture and presentation

Collaborate with cross-functional teams to achieve the mission

CircleCI Computer science Engineer Github

Developer Relations Engineer

Posted 10 days ago

Engage with open source communities and developer-centric organizations

Communicate vision and products for improved open source development experiences

Cloud Community engagement Developer Advocacy Documentation

Commercial Solutions Engineer

Posted 10 days ago

Educate and enable potential and existing customers

Collaborate with Sales team to close opportunities

Devops Engineer Monitoring Open source technologies

Senior Cloud Operations Engineer

Posted 10 days ago

Manage and architect OpenStack, Kubernetes, and software-defined storage infrastructure

Enable devsecops practices for applications running on the infrastructure

Devops devsecops Engineer IOT

Senior Cloud Test Engineer

Posted 10 days ago

Develop scalable automated testing systems for cloud technologies

Work on integration testing of MariaDB products

Cloud Devops Docker Engineer

Senior Analytics Engineer

Posted 10 days ago

Delivering insights and analytics to uncover strategic opportunities

Driving faster user-centric decisions

Analytics Bi tools Collaboration Data Modeling

Senior Backend Engineer

Posted 10 days ago

Developing core authentication infrastructure for GitLab.

Optimizing authentication and authorization performance.

Architecture Engineer Go Golang

Senior Backend Engineer

Posted 10 days ago

Hiring a Senior Backend Engineer for Secfix to scale compliance automation products

Seeking experienced individuals with strong Java and database skills

Angular Architecture AWS Engineer

Senior Software Engineer - IoT Platform

Posted 10 days ago

Lead the productionalization of IoT platform software

Design and implement resource-constrained edge software

CI/CD Devops Docker Engineer

iOS Architecture Engineer

Posted 10 days ago

Define and evolve iOS app architecture

Partner with cross-functional teams

Architecture Code Quality Engineer Leadership

Senior Database Automation Engineer

Posted 10 days ago

Design and implement automation frameworks for database lifecycle management

Collaborate with infrastructure teams to integrate systems via APIs

Automation AWS Engineer Kubernetes

Senior Staff Engineer - Platform

Posted 10 days ago

Hiring a remote Senior Staff Engineer for platform development

Full-time position that can be done remotely in the UK

Cross-functional Collaboration Docker Engineer Java

Site Reliability Engineer

Posted 11 days ago

Provide enterprise infrastructure DevOps practices

Operate and manage private cloud, Kubernetes clusters, and applications

Automation Cloud Computing Devops Engineer

Senior Chaos Engineer

Posted 11 days ago

Define and implement a chaos engineering strategy at Goodnotes

Design and run fault injection experiments to surface hidden risks

Automation Chaos Engineering Engineer Strategy

Backend Engineer - Python/Postgres

Posted 11 days ago

Hiring for a backend engineer focused on Python and PostgreSQL.

Supporting large-scale data collection efforts for coffee farmers.

AWS Bash Scripting Devops Django

Technical Support Engineer 2

Posted 11 days ago

Deliver award-winning billing support to customers.

Provide product support via various channels.

Communication Skills Customer Service Customer Support Engineer

Forward Deployed Software Engineer

Posted 11 days ago

Lead technical implementation and optimization of data platform

Serve as primary technical contact for key accounts

Airflow AWS Azure Databricks

Senior AI Engineer

Posted 11 days ago

Develop and implement AI algorithms for fleet management software.

Collaborate with teams to integrate AI technologies.

Ai Analytical Skills Communication Cross-functional Collaboration

Staff Software Engineer - GTM Systems

Posted 11 days ago

Hiring a remote Staff Software Engineer

Work on GTM Systems

Collaboration Computer science Engineer Remote Work

Software Engineer - Sustaining Engineering

Posted 12 days ago

Resolve complex customer issues related to Ubuntu, Kernel, Ceph, OpenStack, or Kubernetes.

Collaborate with Canonical's teams and upstream communities for bug fixes and patches.

C C++ Devops Docker

Microservices Engineer

Posted 12 days ago

Develop back-end REST API microservices in Go and Python for Ubuntu platform

Collaborate with global teams on software architecture and design

Architecture Devops Distributed systems Docker

Python K8s Engineer

Posted 12 days ago

Transforming internal workloads onto a new, open-source codebase

Designing and delivering open source software operations code

Cloud Computing Devops Docker Engineer
overtime