Job detail for Senior Security Engineer
Use AI to assess how you fit
We're looking for a Senior Security Engineer to own how Ghost finds, fixes and prevents security issues.
Hey there! We're looking for a new member to join the Ghost team, maybe that's you?
We're a non-profit organization on a mission to create modern, independent publishing technology to power the future of online journalism.
This is not a rocket-ship. You won't find any unicorn glitter or exponential curves around here, just a real company with a sustainable business which has been profitable from year 1 and has been growing healthily ever since. Currently our annual revenue is $10,000,000+. We're very transparent about our mission and our metrics, you can read all about us.
Ghost is a full stack web application for running independent publications. It’s one of the most popular modern open source projects in the world, and is used in production by tens of thousands of websites and companies.
Chances are you've already visited and read sites which run on Ghost! Our users range from renowned publications like 404 Media, Platformer, Tangle News, to prominent tech companies like YCombinator, First Round Review, Cloudflare and Kickstarter, and many, many more.
Security for a small team with a very large audience
Ghost runs tens of thousands of publications, and the code that runs them is open source. Anyone can read it, and plenty of people do — researchers, hobbyists, and increasingly, AI tools pointed at our repository. That's a good thing. It also means a steady stream of security reports arriving every month.
So far that work has been shared across our team. It's worked, but security at Ghost deserves an owner: one person who holds the whole picture, from the first email a researcher sends to the advisory we publish, and who uses what they see in the queue to make the next class of bug less likely to exist at all.
Ghost has always believed in staying intentionally small, around 50 people. So we don’t expect to build a security department. Instead we want one senior engineer who thinks about security systemically — who treats the report queue as a source of signal about our code, our tooling and our habits, and who changes those things rather than just clearing the queue.
You'll join our Platform team and work closely with the engineers who build and ship Ghost every day. You'll also be the person our researcher community talks to, and the person the rest of the team asks when they're not sure whether something is safe.
Six months in, we'd hope to see every report getting a real first response within a week, nothing sitting unresolved, at least one automated security check running on every pull request.
What you'll be doing
🔍 Own the disclosure lifecycle. Every security report to Ghost lands with you. You'll triage it, reproduce it, decide whether it's real, and talk to the researcher who sent it. You'll write and publish our advisories, and maintain the policy and pages that tell researchers how to work with us.
🛠 Fix things in the codebase. When a report is real, you fix it. That means writing the patch yourself in Ghost's Node.js/TypeScript codebase, getting it reviewed, and shepherding it through to a release.
🧭 Shift security left. A growing share of the code at Ghost is written with AI agents, and pull requests are bigger and arrive faster than they used to. You'll design the checks that let that stay fast without becoming a liability: security scanning that runs on every PR, review steps that catch the bug classes we actually see, and threat modelling for the big architectural bets while they're still on the whiteboard.
🤖 Use AI in the security process itself. Triage, reproduction, first-pass classification, advisory drafting — you'll build tooling that takes the repetitive parts off your plate and leaves the judgement calls with you.
🎓 Teach the team. The best fix is one nobody has to write. You'll turn what you learn from the queue into guidance, examples and short sessions for our engineers, so the same category of bug doesn't keep coming back. You'll review the security side of new features before they ship, and help the rest of the team do that for themselves over time.
🏗 Harden the platform. Alongside the platform team, you'll work on the infrastructure that runs Ghost(Pro) — dependencies, supply chain, secrets, access. You'll take part in the on-call rotation.
What we're looking for 🔎
We're looking for a senior individual contributor who has done this before: someone who has owned application security for a real product, and who is as comfortable writing a patch as writing a disclosure email. You'll be the only person at Ghost whose whole job is security, so you'll set the direction yourself and bring the rest of the team along with you.
You'll probably recognise yourself in most of these:
-
Deep in web application security. You know the usual list, but more importantly you know how those bugs actually show up in a large Node.js application — XSS, SSRF, auth and session flaws, path traversal, injection, rate-limit and access-control bypasses. You've found them, fixed them, and explained them to people who hadn't heard of them.
-
A strong engineer in our stack. Ghost is a full-stack JavaScript application. You've shipped production Node.js/TypeScript, and you can land a merge-ready fix in a large, unfamiliar codebase within your first few weeks.
-
A systems thinker. You see the report queue as data about how code gets written, not just a list of things to fix. You look for the root cause behind the third instance of the same bug, and you'd rather change the process that produced it than fix it a fourth time.
-
Good with researchers. You've been on one side or the other of coordinated disclosure, and you know how to keep it collaborative — acknowledge quickly, be honest about severity, credit people properly, and say no without being dismissive.
-
Practical about AI. You've used AI tools in real security work and you have opinions — about where they help, where they produce convincing nonsense, and what it takes to review code that a machine wrote. You're curious about this rather than anxious about it.
-
A clear writer. We're a remote team that runs on writing. Advisories, incident write-ups, PR descriptions, reviews, messages to researchers — it all needs to be clear, honest and short.
-
High ownership, low ego. You're comfortable being the only person who owns a thing, and equally comfortable being told your idea isn't the right one. You make progress without waiting for permission, you close loops, and bad news travels from you faster than good news.
Bonus points for 🎯
-
Prior open source contributions, or public advisories with your name on them.
-
Experience securing a hosting or multi-tenant SaaS product.
-
Experience with the practical side of corporate security — device management, SSO, access reviews — for a small remote team.
-
An interest in digital publishing and journalism. Our customers are writers, newsrooms and creators who depend on Ghost to make a living. Caring about what they do matters.
Salary & benefits
The starting salary range for this position is $140,000 to $190,000 USD. Most offers we make fall somewhere in the middle of the range. The exact offer will be determined by a combination of your experience, and our interview process.
On top of that, we offer a range of benefits...
All jobs at Ghost come with
💵 Competitive salary Based on role, skill, experience and location.
🌍 Work from anywhere Everything we do is online. As long as you have wifi, you're all set.
💻 Hardware A brand new MacBook Pro + a budget for office setup and the latest AI tools.
🏢 Co-working If you prefer to work from a co-working space, we'll help pay for it.
📚 Continue your personal development A budget for attending conferences, taking courses, and purchasing books.
✈️ Worldwide team trips The last few trips have taken us to the UK, Spain & Italy.
📅 4-day work weeks We close the office on Fridays. Enjoy!
🏝 Generous paid vacation We want everyone to have proper time off. We even shut down for two weeks over Christmas.
👶 Paid parental leave When the time comes to welcome a new member of the family, we offer generous and fully paid parental leave.
📈 Pay reviews Everyone at Ghost receives an annual pay review against market rates, so your compensation can grow alongside your experience and impact.
🐶 Dog friendly office...just kidding we literally don't have an office. So, um. Feel free to work with your dog. Cats are cool, too.
Who you'll be working with
How to apply 🚀
Our hiring process and timeline can vary from role to role, but typically you can expect:
Step 1: We'll review your application against the needs of team.
Step 2: A video call with a member of the operations team so we can get to know each other a little better. It's an informal call, there's nothing to prepare.
Step 3: A second video call, usually with the hiring manager. This call has a more technical focus and gives you the opportunity to find out what might be like to be a member of the Ghost team.
Step 4: A third video call will be with a member of our Leadership Team. During this call, we'd like you to share your screen and pair program with them.
Step 5: A paid trial project - typically 15 hours of work. This provides a great opportunity to understand what it's like to work at Ghost.
Step 6: A fourth video call to review your trial project.
Step 7: A final interview with one of our Leadership Team.
Step 8: An offer 🎉.
We receive a lot of applications for each position. A real human member of the Ghost team will review every one, so take your time - we care about the details. We especially encourage applications from women and people from groups.
Not the right position for you?
If this role isn't right for you, but you're interested in hearing about other roles that open up in future, you can subscribe to our careers mailing list! We never use this list for any promotional emails, marketing, or anything else.