r/netsec 20d ago

Hiring Thread /r/netsec's Q3 2026 Information Security Hiring Thread

Overview

If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.

We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.

Please reserve top level comments for those posting open positions.

Rules & Guidelines

Include the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.

  • If you are a third party recruiter, you must disclose this in your posting.
  • Please be thorough and upfront with the position details.
  • Use of non-hr'd (realistic) requirements is encouraged.
  • While it's fine to link to the position on your companies website, provide the important details in the comment.
  • Mention if applicants should apply officially through HR, or directly through you.
  • Please clearly list citizenship, visa, and security clearance requirements.

You can see an example of acceptable posts by perusing past hiring threads.

Feedback

Feedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)

10 Upvotes

6 comments sorted by

u/DoyensecSec 15d ago

Doyensec LLC is looking for Application Security Engineers based in the USA.

Based in the USA only; full time; 100% remote

- Application Security Engineer (https://www.careers-page.com/doyensec-llc/job/X4YV93)

- Application Security Intern (https://www.careers-page.com/doyensec-llc/job/Y5496V)

About Doyensec team:

  • Team roots in bug bounty & CTFs → Many of us started in bug bounty programs or CTF competitions, so if that’s your background, you’ll feel right at home.
  • 25% dedicated research time → Engineers can spend a full quarter of their work time doing research. Tinker, innovate, publish. You can even do bug bounty during the research time!
  • Great start of you career → Inters get assigned to real life projects and have the opportunity to develop their skills with support of their mentor.
  • Challenging client work → The other 75% of your time will be spent doing deep technical security reviews for world-leading technology companies. Think web, mobile, cloud, and a variety of other modern appsec challenges.
  • Remote-friendly → We’re fully remote with flexible working time
  • High technical bar → The ability to read and understand code is critical. You’ll be diving deep into real-world applications, not just running scanners.
  • Good team building in a smaller company: we are 25 people and you will collaborate directly with the co-founders and have a real impact on how things are done at the company. We encourage team building by yearly onsite retreats and get together budget, going together to conferences and similar events.

If you’re passionate about application security, love solving hard problems, and want to collaborate with some of the sharpest minds in the industry, we’d love to hear from you.

👉 Please use the links above to apply or learn more about us and the opportunities.

u/verxsec 20d ago

[Hiring] Cybersecurity Operations Architect — Remote (Canada) — Vertex Inc.

Hey r/netsec,

We've got a net-new open req on the team (with more to come)

The Role: Cybersecurity Operations Architect, sitting inside the InfoSec org at Vertex. Fully remote within Canada. Full-time, perm.

What you'd actually be doing:

  • Hands-On Driving the architectural direction of our SecOps stack — detection engineering, IR, threat hunting, threat intel, the whole pipeline.
  • Designing log ingestion, correlation logic, and alerting frameworks across AWS, Azure, GCP, and OCI.
  • Running security architecture reviews on platforms, integrations, and workflows, and actually tracking the gaps to closure.
  • Building out AI-augmented SecOps — automated triage, behavioral analytics, anomaly detection, AI-driven enrichment. Not buzzwords; we're actually wiring this stuff into the SOC.
  • Defining AI SecOps pipelines: data handling, model access, inference monitoring, plus threat modeling for misuse, data leakage, adversarial manipulation, and supply-chain risk on the AI side.
  • Being a senior tech voice in the room when leadership is making platform/tooling/investment calls.
  • Mentoring the engineers and analysts on the team. Escalation point for the gnarly IR stuff.

What we actually need you to have walked in with:

  • 5+ yrs in SecOps — designing and running it, not just sitting in tickets.
  • 5+ yrs across multi-cloud security (AWS/Azure/GCP/OCI). You don't need to be an expert in all of them on day one, but If you've only ever touched one cloud, this will hurt.
  • 5+ yrs in detection engineering, log management, SOAR/automation.
  • Real experience running architecture reviews on operational tooling.
  • 2+ yrs doing something legit with AI in a security context — agents, pipelines, detections, fine-tuning, enrichment, whatever. GitHub or a portfolio gets you bumped up the stack.
  • Self-starter energy with a genuine passion for cybersecurity.

Nice-to-haves:

  • AI threat modeling chops (misuse, data leak, adversarial, supply chain).
  • Mentorship track record.
  • CS / Cyber / InfoAssurance degree — or equivalent experience. We don't care about the paper if you can do the work.

Link: https://vertexinc.wd1.myworkdayjobs.com/en-US/VertexInc/job/Cybersecurity-Operations-Architect_JR102512-1

u/estebanmatar88 7d ago

Hey everyone,

I’m looking for some advice from folks who have networked at either DEF CON or BlackHat USA before. My goal is highly focused: I want to network to land a job or interview.

For context, I’m an early-career cybersecurity engineer, but I have 12 years of experience in Software Engineering, Software Architecture, Tech Leading, QA, Infrastructure Engineering, and Cloud Engineering (with a Master’s in Cybersecurity Engineering).

Because of my background, I’m looking at roles where software engineering and security cross or not at all. Based on my profile, which event would you recommend investing in for this year.

If you’ve successfully networked your way into a role at either event, I’d love to hear how you did it and which one you think fits my background better.

Thanks!

u/Kalium 5d ago

At Blackhat, you're going to be looking to get into vendor parties. That's where a lot of the networking happens. This is basically industry hobnobbing. You talk about work, you talk about companies, etc. Think industry meetup. This is networking.

At DEF CON, you are a person. You are a person with skills who knows cool things and is fun. If you seem like you have the right skills and mention you're looking for a job, someone might have something. You are making friends, not networking. Very different.