Senior Security Engineer at Ghost
- Company
- Ghost
- Employment type
- Full-Time
- Location
- Worldwide
- Posted
- 2026-10-06
About this role
Hey there! We're looking for a new member to join the Ghost team, maybe that's you? We're a non-profit organization on a mission to create modern, independent publishing technology to power the future of online journalism. This is not a rocket-ship. You won't find any unicorn glitter or exponential curves around here, just a real company with a sustainable business which has been profitable from year 1 and has been growing healthily ever since. Currently our annual revenue is $10,000,000+ . We're very transparent about our mission and our metrics, you can read all about us . Ghost is a full stack web application for running independent publications. It’s one of the most popular modern open source projects in the world, and is used in production by tens of thousands of websites and companies. Chances are you've already visited and read sites which run on Ghost! Our users range from renowned publications like 404 Media, Platformer, Tangle News , to prominent tech companies like YCombinator , First Round Review , Cloudflare and Kickstarter , and many, many more . Security for a small team with a very large audience Ghost runs tens of thousands of publications, and the code that runs them is open source. Anyone can read it, and plenty of people do — researchers, hobbyists, and increasingly, AI tools pointed at our repository. That's a good thing. It also means a steady stream of security reports arriving every month. So far that work has been shared across our team. It's worked, but security at Ghost deserves an owner: one person who holds the whole picture, from the first email a researcher sends to the advisory we publish, and who uses what they see in the queue to make the next class of bug less likely to exist at all. Ghost has always believed in staying intentionally small, around 50 people. So we don’t expect to build a security department. Instead we want one senior engineer who thinks about security systemically — who treats the report queue as a source of signal about our code, our tooling and our habits, and who changes those things rather than just clearing the queue. You'll join our Platform team and work closely with the engineers who build and ship Ghost every day. You'll also be the person our researcher community talks to, and the person the rest of the team asks when they're not sure whether something is safe. Six months in, we'd hope to see every report getting a real first response within a week, nothing sitting unresolved, at least one automated security check running on every pull request. What you'll be doing 🔍 Own the disclosure lifecycle. Every security report to Ghost lands with you. You'll triage it, reproduce it, decide whether it's real, and talk to the researcher who sent it. You'll write and publish our advisories, and maintain the policy and pages that tell researchers how to work with us. 🛠 Fix things in the codebase. When a report is real, you fix it. That means writing the patch yourself in Ghost's Node.js/TypeScript codebase, getting it reviewed, and shepherding it through to a release. 🧭 Shift security left. A growing share of the code at Ghost is written with AI agents, and pull requests are bigger and arrive faster than they used to. You'll design the checks that let that stay fast without becoming a liability: security scanning that runs on every PR, review steps that catch the bug classes we actually see, and threat modelling for the big architectural bets while they're still on the whiteboard. 🤖 Use AI in the security process itself. Triage, reproduction, first-pass classification, advisory drafting — you'll build tooling that takes the repetitive parts off your plate and leaves the judgement calls with you. 🎓 Teach the team. The best fix is one nobody has to write. You'll turn what you learn from the queue into guidance, examples and short sessions for our engineers, so the same category of bug doesn't keep coming back. You'll review the security side of new features before they ship…
Apply for this Senior Security Engineer role