Corporate security is often perceived as a department of "no", where decisions are made by pointing out what is wrong, controls are designed to shift blame, and success is measured by checking boxes rather than reducing risk. At Oxide, security is understood to be an engineering discipline. When something is risky, the job is to say "yes, and here’s how it could be done," and the controls we operate exist regardless of whether a spreadsheet says it should.
We produce a product whose premise is that customers can trust what we ship. The security of our build pipeline, our signing infrastructure, and the systems we work on every day is critical to customer trust in Oxide. We’re looking for a security engineer to own security of how Oxide operates: the SaaS providers we depend on, the endpoints we work from, the internal services used for operations, our offices, the signing ceremonies that protect our most sensitive key material, and building automation to support the security of our operations.
As a corporate security engineer working at Oxide, you will:
Manage the security lifecycle of third-party SaaS providers: user provisioning, access control, configuration, security review and ongoing tracking for compliance commitments.
Manage endpoint security for corporate machines, including MDM, help reason about where management tooling makes sense and where it doesn’t.
Secure and help operate internal corporate services: access control, log forwarding, service hardening, vulnerability management, backup and recovery.
Build automation for compliance evidence gathering, turning audit requests into automatic or easily repeatable processes.
Participate in security incident response: triage events, investigations, report writing, and general process improvement.
Manage security controls of physical office spaces.
Support offline keystore operations: planning ceremonies, writing and maintaining the tooling, take role assignments as needed for ceremonies.
Design backup and recovery solutions and perform periodic recovery testing.
Work directly with auditors and compliance partners and finding the balance between workable systems and compliance requirements.
These responsibilities are just a starting place! We’re a small company, we don’t have rigid roles, and we have a lot to do - we can help you grow wherever your interests take you.
You will thrive in this role if you:
Believe security’s job is to say "yes, and here’s how", not "no, and here’s why". When something is risky, you respond with actionable recommendations for doing it safely, rather than focusing on why something wouldn’t work.
Are allergic to checkbox security. You care whether controls actually reduce risk, not whether it lets someone claim they weren’t responsible when things go wrong. You’re willing to own the outcomes of your recommendations, including those that don’t pan out.
Have an attacker’s instincts, ideally sharpened by hands-on offensive work. You ask "how could someone get around this?" before asking "does this satisfy the requirement?"
Treat compliance as an engineering problem. The compliance controls you manage are only those that you’d want anyway, regardless of compliance requirements. You would rather write tooling for compliance evidence gathering than periodically collect screenshots.
Believe in the importance of fully documenting your ideas, and you enjoy reading documentation produced by others.
Are eager to own cross-function initiatives across the company, working with various teams to design and implement solutions that work for everyone.
Look forward to running the MDM program at Oxide.
Are comfortable being a generalist.
Are proficient with Rust programming.
Are comfortable in Unix, Mac and Windows environments.
Before applying for this role, you should:
Browse our public Requests for Discussion to get a flavor for how we work. A few recommendations:
Listen to Hiring Processes with Gergely Orosz to familiarize yourself with the Oxide hiring process.