The opportunity
The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset.
What you'll do
Support and help mature Sentry's security review program. From secure code: review, to architecture review, and threat modeling. You'll help build the processes, tooling, and culture which make security a natural part of how we ship and operate.
Contribute to mature vulnerability management practices. Intake, triage,: prioritization, remediation tracking, and support of our bug bounty and responsible disclosure program.
Advocate for secure-by-design principles. Partner with engineering and: product teams to embed security early in the development lifecycle and integrate security tooling into developer and CI/CD workflows.
Validate and reproduce application and infrastructure security findings.: Scanning, manual testing, and supporting penetration testing and vulnerability validation across Sentry's application, SDKs and cloud-based platform.
Help evaluate and respond to emerging threats relevant to application: security at Sentry. We build and operate a complex application and cloud environment, including the novel attack surface introduced by Sentry's agentic product features and AI-assisted engineering practices.
Enjoy operating cross-functionally, building relationships, and influencing: with technical expertise as you grow into shaping how security gets done across a fast-moving engineering organization.
What they're looking for
- + years of industry experience designing, building, or securing complex applications and cloud systems
- Degree in Computer Science or a related field, equivalent training, or professional experience
- Hands-on experience with several of the following: security reviews, SDLC practices, secure CI/CD, architecture reviews, threat modeling, vulnerability management, bug bounty and responsible disclosure programs
- Experienced and comfortable programming in at least one language, and able to: read and reason about code in Python, Typescript, Go, or Rust
- Familiarity with using distributed cloud technology (AWS, GCP, Azure,: Kubernetes, Docker, Terraform, etc.) and an understanding of how those technologies are secured (cloud networking, IAM, etc.)
- A collaborative approach to problem solving paired with strong written and verbal communication