Trigger.dev logo

Trigger.dev

Backend Engineer (Security)

HybridNew today

Part remote, part office, you need to live within commuting distance of a named location.

Hybrid · Remote or Hybrid UK

Employer listed it 12h ago · Found 10h ago

First listed today.

Salary

Not stated

Location

Hybrid · Remote or Hybrid UK

Work style

Async

Contract

Full-time

Experience

Mid

Category

Software

This employer didn't state pay. Jobs like this usually pay around $160k–$250k a year, a typical range taken from 595 mid-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Hybrid

This role is only partly remote, the employer expects time in the office around Remote or Hybrid UK, Remote, so you need to live within commuting distance.

What the employer says

  • Source listing states candidate location: "Remote or Hybrid UK, Remote"
  • Listing mentions "Hybrid"

What Nomaders makes of it

  • Not suitable if you plan to move between countries

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About us

Trigger.dev is the platform for running reliable AI agents and workflows. Developers use it to build, deploy, and scale production systems with built-in tools for orchestration, scheduling, monitoring, and debugging.

Our Cloud product is a managed service where we deploy our users' code and auto-scale from zero to millions of executions. Today, we serve thousands of teams building AI apps and agents, handling hundreds of millions of executions per month.

About the position

We're looking for a backend product engineer who loves security - not a security box-ticker. You'll build and own the systems that let Trigger safely run massive volumes of untrusted user code inside our infrastructure, at scale.

Some of our customers let their own users run untrusted code on top of Trigger - think coding agents executing arbitrary instructions. We have to guarantee that code can never break Trigger's systems, or our customers' systems. That makes this partly a product engineering role: building secure sandbox runtimes is a feature we ship, not something bolted on after the fact.

The ideal person here is a backend engineer with genuine offensive-security instincts - someone who naturally gravitates toward hacking, pen testing, and breaking things, and brings that curiosity into how they build. You'll pair strong backend/product instincts with a hacker's mindset.

What you'll be doing

You'll do a variety of things including:

Sandbox and runtime security. Designing and maintaining the secure execution environments that isolate untrusted user code - the core, product-shaped problem at the heart of this role.

Threat detection and incident response. Building monitoring and alerting for suspicious activity, and leading the response when something needs investigating.

Vulnerability management, end to end. Regular scanning and triage, plus AI-assisted security scans run on a quarterly cadence, and triaging incoming disclosures.

Offensive security. Running internal, AI-assisted pen testing, and potentially bringing in external firms for deeper engagements.

PR security review. Adding a security-specific review layer on top of our normal PR process.

SOC 2 and compliance. Mostly done already - this is about ongoing maintenance, not standing it up from scratch.

Vulnerability disclosure process. Owning our vulnerability disclosure program end to end.

Security culture. Helping the wider engineering team build secure habits - reviews, documentation, and pragmatic guardrails rather than heavy process.

Working at a Commercial Open Source Software company is more than just security work:

We have an active community on Discord and GitHub. Everyone on the team helps customers, reviews PRs, and creates issues.

Having great documentation is essential. Everyone writes docs.

We're a product-led growth company, so everyone is expected to get involved in creating content like code examples, blog articles, videos, and tweets.

Requirements

Real backend engineering experience. You can design and ship production backend systems, not just audit someone else's.

Genuine offensive-security curiosity. Pen testing, CTFs, bug bounty hunting, or hacking as a hobby or discipline - this isn't a checklist role.

Requirements

  • ·Real backend engineering experience. You can design and ship production backend systems, not just audit someone else's.
  • ·Genuine offensive-security curiosity. Pen testing, CTFs, bug bounty hunting, or hacking as a hobby or discipline - this isn't a checklist role.
  • ·Comfort owning ambiguous, product-shaped security problems. Sandboxing and runtime isolation are engineering problems as much as they are security ones.
  • ·A proactive mindset. This role should take work off the team's plate, not create a queue for others - we're not looking for a security box-ticker.
  • ·Comfortable being on call. Reliability and security response are shared responsibilities across the team.

Benefits

  • ·Generous, transparent compensation and equity - we hire the best talent and pay to reflect that. We also offer equity so everyone is invested in the company's success.
  • ·Async working - need a heads-down day or meeting-free days to stay productive? No problem!
  • ·Home office - we help provide equipment for a comfortable setup so you're as productive at home as you are in the office.
  • ·Generous vacation - 25 days vacation excluding national holidays, plus sick leave and generous parental leave.
  • ·Training budget - an annual budget to contribute towards learning, such as books, an Audible subscription, or online courses.

How to apply

  1. 1Check the flexibility label above, hybrid, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Trigger.dev, mentioning your remote working experience and working hours (Async).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 10h ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $160k to $250k per year · You'll be taken to the employer's careers page.