Security · 3 openings · Full-time
Junior Cybersecurity Engineer
Help secure a product that holds other people's inboxes and contact data. RLS, secrets handling, webhook signing, and the audit trail.
About the role
GTM uses customers' verified sending domains and connected LinkedIn accounts, which makes security the product, not a checklist. Row-level security ships in the first migration of every table, credentials make one hop and are never persisted, webhooks are signed, and personal data is kept out of logs by rule.
You will work on keeping those properties true as the surface grows, and on finding where they quietly stopped being true.
You will
- Review new surfaces for authorization gaps, injection paths, and data leaks.
- Work on secrets handling, token flows, and the signing on inbound and outbound webhooks.
- Build checks that catch a policy regression in CI rather than in production.
- Learn a real multi-tenant threat model from the inside.
You have
- Foundations in web security. You can explain IDOR, SSRF, and why RLS beats WHERE clauses.
- Some code: enough TypeScript, Python, or SQL to read a diff critically.
- CTF, bug bounty, coursework, or homelab evidence that you actually do this.
Not sure this is the one? Read what we shipped.
The changelog carries the arguments as well as the features, which tells you more about the work than a job description can.
Start with sales. $2,000 or $5,000 onboarding, then at least $250 monthly credit funding.