GTMGTM
← All roles

Security · 3 openings · Full-time

Junior Cybersecurity Engineer

Help secure a product that holds other people's inboxes and contact data. RLS, secrets handling, webhook signing, and the audit trail.

About the role

GTM uses customers' verified sending domains and connected LinkedIn accounts, which makes security the product, not a checklist. Row-level security ships in the first migration of every table, credentials make one hop and are never persisted, webhooks are signed, and personal data is kept out of logs by rule.

You will work on keeping those properties true as the surface grows, and on finding where they quietly stopped being true.

You will

  • Review new surfaces for authorization gaps, injection paths, and data leaks.
  • Work on secrets handling, token flows, and the signing on inbound and outbound webhooks.
  • Build checks that catch a policy regression in CI rather than in production.
  • Learn a real multi-tenant threat model from the inside.

You have

  • Foundations in web security. You can explain IDOR, SSRF, and why RLS beats WHERE clauses.
  • Some code: enough TypeScript, Python, or SQL to read a diff critically.
  • CTF, bug bounty, coursework, or homelab evidence that you actually do this.

Apply for Junior Cybersecurity Engineer

Everything here goes to a person, not a parser.

Your application and resume go to the hiring team by email and are used only to evaluate you for a role at TryGTM.

Not sure this is the one? Read what we shipped.

The changelog carries the arguments as well as the features, which tells you more about the work than a job description can.

Start with sales. $2,000 or $5,000 onboarding, then at least $250 monthly credit funding.