{"id":1142809,"url":"https://alion.io/job/trigger-dev-back-end-engineer-security","title":"Backend Engineer (Security)","company":{"id":178239,"name":"Trigger.dev","domain":"trigger.dev","url":"https://alion.io/company/trigger-dev","size_band":null,"is_staffing_agency":false,"is_intermediary":false,"ats_vendor":"Ashby","truth_index":null},"role":"Backend","role_family":"Backend","seniority":null,"employment_type":"full_time","work_mode":"on_site","remote_scope":null,"hiring_geo_confidence":"structured","locations":["San Francisco, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":97000,"max_usd":232000,"period":"year","method":"role_country_seniority_unknown","sample_n":283},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Discord","optional":false},{"name":"GitHub","optional":false},{"name":"Node JS","optional":false},{"name":"SOC 2","optional":false},{"name":"TypeScript","optional":false},{"name":"WebAssembly","optional":false},{"name":"AI Agents","optional":true},{"name":"JavaScript","optional":true}],"status":"live","first_seen_at":"2026-09-23T12:47:00Z","employer_posted_date":"2026-09-23","last_verified_at":"2026-09-23T16:41:13Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"About us\nTrigger.dev is the platform for running reliable AI agents and workflows. Developers use it to build, deploy, and scale production systems with built-in tools for orchestration, scheduling, monitoring, and debugging.\nOur Cloud product is a managed service where we deploy our users' code and auto-scale from zero to millions of executions. Today, we serve thousands of teams building AI apps and agents, handling hundreds of millions of executions per month.\nAbout the position\nWe're looking for a backend product engineer who loves security - not a security box-ticker. You'll build and own the systems that let Trigger safely run massive volumes of untrusted user code inside our infrastructure, at scale.\nSome of our customers let their own users run untrusted code on top of Trigger - think coding agents executing arbitrary instructions. We have to guarantee that code can never break Trigger's systems, or our customers' systems. That makes this partly a product engineering role: building secure sandbox runtimes is a feature we ship, not something bolted on after the fact.\nThe ideal person here is a backend engineer with genuine offensive-security instincts - someone who naturally gravitates toward hacking, pen testing, and breaking things, and brings that curiosity into how they build. You'll pair strong backend/product instincts with a hacker's mindset.\nWhat you'll be doing\nYou'll do a variety of things including:\nSandbox and runtime security. Designing and maintaining the secure execution environments that isolate untrusted user code - the core, product-shaped problem at the heart of this role.\nThreat detection and incident response. Building monitoring and alerting for suspicious activity, and leading the response when something needs investigating.\nVulnerability management, end to end. Regular scanning and triage, plus AI-assisted security scans run on a quarterly cadence, and triaging incoming disclosures.\nOffensive security. Running internal, AI-assisted pen testing, and potentially bringing in external firms for deeper engagements.\nPR security review. Adding a security-specific review layer on top of our normal PR process.\nSOC 2 and compliance. Mostly done already - this is about ongoing maintenance, not standing it up from scratch.\nVulnerability disclosure process. Owning our vulnerability disclosure program end to end.\nSecurity culture. Helping the wider engineering team build secure habits - reviews, documentation, and pragmatic guardrails rather than heavy process.\nWorking at a Commercial Open Source Software company is more than just security work:\nWe have an active community on Discord and GitHub. Everyone on the team helps customers, reviews PRs, and creates issues.\n\nHaving great documentation is essential. Everyone writes docs.\n\nWe're a product-led growth company, so everyone is expected to get involved in creating content like code examples, blog articles, videos, and tweets.\n\nRequirements\nReal backend engineering experience. You can design and ship production backend systems, not just audit someone else's.\nGenuine offensive-security curiosity. Pen testing, CTFs, bug bounty hunting, or hacking as a hobby or discipline - this isn't a checklist role.\nComfort owning ambiguous, product-shaped security problems. Sandboxing and runtime isolation are engineering problems as much as they are security ones.\nA proactive mindset. This role should take work off the team's plate, not create a queue for others - we're not looking for a security box-ticker.\nComfortable being on call. Reliability and security response are shared responsibilities across the team.\nOpen to in-person events throughout the year. If you're remote, we'll arrange these so the team gets real time together.\nYou'll be an amazing fit if you have:\nExperience building or hardening sandboxed/isolated execution environments (containers, microVMs, gVisor, Firecracker, WASM sandboxes, or similar).\n\nA track record in pen testing, bug bounty programs, or CTFs.\n\nExperience using AI-assisted tooling for security scanning or workflows.\n\nA proven track record of contributing to open source projects.\n\nWorked at a developer tools, infrastructure, or open source company.\n\nExperience with Node.js and TypeScript, enough to read and review application code.\n\nBenefits\nGenerous, transparent compensation and equity - we hire the best talent and pay to reflect that. We also offer equity so everyone is invested in the company's success.\nAsync working - need a heads-down day or meeting-free days to stay productive? No problem!\nHome office - we help provide equipment for a comfortable setup so you're as productive at home as you are in the office.\nGenerous vacation - 25 days vacation excluding national holidays, plus sick leave and generous parental leave.\nTraining budget - an annual budget to contribute towards learning, such as books, an Audible subscription, or online courses.\nPension contributions - enroll in our company pension scheme, or we'll contribute directly to your private pension.\nOur values\nWe are proud to be open source - we believe in the open source community and building a great free-to-use product.\nWe ship uncomfortably fast - as a startup, moving fast is key. We are pragmatic about what we build, when we build it.\nWorking autonomously - we don't tell you what to do. We decide as a team what will have the biggest impact for our customers and prioritise from that.","description_format":"text","description_chars":5432,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity","Generous vacation","Home office","Parental leave"],"hiring_locations":[{"name":"United Kingdom","iso":"GB","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","LLM & Generative AI","AI Agents"],"lifecycle":[{"event":"open","at":"2026-09-23T13:09:09Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":21,"reasons":["conf:1","win:early"],"computed_at":"2026-09-23T18:29:24Z"},"pay":null,"html_url":"https://alion.io/job/trigger-dev-back-end-engineer-security","json_url":"https://alion.io/job/trigger-dev-back-end-engineer-security.json","meta":{"generated_at":"2026-09-23T18:29:24Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}