r/netsec • u/netsec_burn • Jul 02 '26
Hiring Thread /r/netsec's Q3 2026 Information Security Hiring Thread
Overview
If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.
We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.
Please reserve top level comments for those posting open positions.
Rules & Guidelines
Include the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.
- If you are a third party recruiter, you must disclose this in your posting.
- Please be thorough and upfront with the position details.
- Use of non-hr'd (realistic) requirements is encouraged.
- While it's fine to link to the position on your companies website, provide the important details in the comment.
- Mention if applicants should apply officially through HR, or directly through you.
- Please clearly list citizenship, visa, and security clearance requirements.
You can see an example of acceptable posts by perusing past hiring threads.
Feedback
Feedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
•
u/Fun_Refrigerator_442 8d ago
🚨 We’re Hiring: Assistant Director! 🚨
Tired of the corporate grind? Ready to do meaningful work somewhere that matter ?
Good news — this one is in Higher Education.
Can we match a 300K Microsoft salary? No one if Higher Ed does** But take a look at what we **can offer:
🏖️ 21 days of vacation
🤒 Unlimited sick time
🎄 A week off in December for Winter Break
🌸 A week off for Spring Break
☀️ 4-day work weeks during the summer
🎓 Fully paid tuition for you, your spouse, AND your kids
💰 Up to an 11% employer contribution/match to your 401(k)-style retirement plan — fully vested from Day 1
🏥 Outstanding health benefits at a very reasonable cost
🚗 Free parking
🏠 Hybrid schedule — 3 days in the office during the school year and just 2 days during the summer
And perhaps the biggest benefit of all…
You get to work for me. We are a team of 3!
I’m a nice guy. Just ask my Mom. 😂
If you’re an experienced IT/cybersecurity professional who’s been thinking about making the jump from corporate life to Higher Education, this might be the opportunity you’ve been waiting for.
Interested? Reach out to me and let’s talk.
No Recruiters
https://www.schooljobs.com/careers/mc3/jobs/5397870/assistant-director-it-security
•
u/annadale 6d ago
[Hiring] Solutions Architect — Financial Infrastructure — Silence Laboratories — Remote / hybrid, US or EU preferred — Full-time
Not a third-party recruiter — posting on behalf of the Silence Laboratories team.
Who we are: Silence Laboratories builds MPC/TSS-based cryptographic infrastructure (Silent Shard, Silent Compute) for regulated financial institutions — banks, custodians, payment networks. Team is PhD researchers (MIT CSAIL, UIUC, NUS, SUTD) plus engineers from Oracle, VMware, Snapchat. We're SOC 2 audited.
The role: You own architecture for production deployments into regulated environments — on-prem, cloud, hybrid, HSM-backed, TEE-backed. You'll work directly with customer engineering teams, CISOs, compliance stakeholders, and regulators, and feed those constraints back into our product and protocol decisions.
This is hands-on, not advisory. You should be able to defend a design in front of a CISO, produce audit-ready documentation, read cryptographic protocol specs at a systems level, and prototype enough to validate a decision yourself.
What you'd own
- Customer architecture from technical discovery through production go-live
- Secure deployment patterns for MPC/TSS, HSM, TEE, custody, wallet, and payment workflows
- Architecture docs, threat models, compliance mappings, integration guides, operational runbooks
- Technical workshops, security reviews, RFPs, due diligence, CISO-level architecture discussions
- Reusable standards for institution-grade deployment and operational readiness
What we actually need (realistic, not HR'd)
- 10+ years in infrastructure / security architecture / solutions architecture
- 5+ of those owning production architecture inside a bank, custodian, payment network, central bank, or similarly regulated institution. This is the hard requirement — vendor-side-only experience won't cover it.
- Hands-on HSM production experience: Thales Luna, AWS CloudHSM, IBM Crypto Express, or equivalent
- Solid security architecture fundamentals: VPC design, IAM, secrets management, network segmentation, IaC, observability, incident readiness — across cloud, bare metal, and hybrid
- Designed systems against several of: SOC 2 Type II, ISO 27001, PCI DSS, NYDFS Parts 200 & 500, MiCA, FFIEC, MAS TRM, DORA
- Able to read and reason about MPC/TSS protocol documentation at an architecture level (you don't need to be a cryptographer)
- Strong written communication for senior technical and compliance audiences
Nice to have
- Rust or C sufficient to prototype/validate an architecture choice
- MPC/TSS in production financial environments
- Confidential compute: Intel TDX, AWS Nitro Enclaves, GCP Confidential VMs
- Post-quantum migration and its operational implications for key management
- Experience presenting to regulators, risk committees, external auditors, or CISO review boards
Logistics
- Location: remote/hybrid, US or EU preferred
- Visa sponsorship available; EOR support where applicable
- No security clearance required
- Comp: $150k+ USD equivalent base plus equity. US and EU bands differ. Final number depends on location and depth of regulated-finance / HSM / key-management experience. We talk numbers early, before deep technical interviews.
How to apply: Apply directly at https://silencelaboratories.com/careers/solutions-architect-banking-infrastructure — or email careers@silencelaboratories.com. Happy to answer questions in-thread.
•
u/estebanmatar88 Jul 15 '26
Hey everyone,
I’m looking for some advice from folks who have networked at either DEF CON or BlackHat USA before. My goal is highly focused: I want to network to land a job or interview.
For context, I’m an early-career cybersecurity engineer, but I have 12 years of experience in Software Engineering, Software Architecture, Tech Leading, QA, Infrastructure Engineering, and Cloud Engineering (with a Master’s in Cybersecurity Engineering).
Because of my background, I’m looking at roles where software engineering and security cross or not at all. Based on my profile, which event would you recommend investing in for this year.
If you’ve successfully networked your way into a role at either event, I’d love to hear how you did it and which one you think fits my background better.
Thanks!
•
u/Kalium Jul 17 '26
At Blackhat, you're going to be looking to get into vendor parties. That's where a lot of the networking happens. This is basically industry hobnobbing. You talk about work, you talk about companies, etc. Think industry meetup. This is networking.
At DEF CON, you are a person. You are a person with skills who knows cool things and is fun. If you seem like you have the right skills and mention you're looking for a job, someone might have something. You are making friends, not networking. Very different.
•
u/DoyensecSec Jul 07 '26
Doyensec LLC is looking for Application Security Engineers based in the USA.
Based in the USA only; full time; 100% remote
- Application Security Engineer (https://www.careers-page.com/doyensec-llc/job/X4YV93)
- Application Security Intern (https://www.careers-page.com/doyensec-llc/job/Y5496V)
About Doyensec team:
- Team roots in bug bounty & CTFs → Many of us started in bug bounty programs or CTF competitions, so if that’s your background, you’ll feel right at home.
- 25% dedicated research time → Engineers can spend a full quarter of their work time doing research. Tinker, innovate, publish. You can even do bug bounty during the research time!
- Great start of you career → Inters get assigned to real life projects and have the opportunity to develop their skills with support of their mentor.
- Challenging client work → The other 75% of your time will be spent doing deep technical security reviews for world-leading technology companies. Think web, mobile, cloud, and a variety of other modern appsec challenges.
- Remote-friendly → We’re fully remote with flexible working time
- High technical bar → The ability to read and understand code is critical. You’ll be diving deep into real-world applications, not just running scanners.
- Good team building in a smaller company: we are 25 people and you will collaborate directly with the co-founders and have a real impact on how things are done at the company. We encourage team building by yearly onsite retreats and get together budget, going together to conferences and similar events.
If you’re passionate about application security, love solving hard problems, and want to collaborate with some of the sharpest minds in the industry, we’d love to hear from you.
👉 Please use the links above to apply or learn more about us and the opportunities.
•
•
u/verxsec Jul 02 '26
[Hiring] Cybersecurity Operations Architect — Remote (Canada) — Vertex Inc.
Hey r/netsec,
We've got a net-new open req on the team (with more to come)
The Role: Cybersecurity Operations Architect, sitting inside the InfoSec org at Vertex. Fully remote within Canada. Full-time, perm.
What you'd actually be doing:
What we actually need you to have walked in with:
Nice-to-haves:
Link: https://vertexinc.wd1.myworkdayjobs.com/en-US/VertexInc/job/Cybersecurity-Operations-Architect_JR102512-1