SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Trigger.dev is a platform for running reliable AI agents and workflows at scale. The company provides a managed cloud service where developers deploy and scale production systems with built-in orchestration, scheduling, monitoring, and debugging. They currently serve thousands of teams building AI applications, handling hundreds of millions of executions monthly.
You will join as a Backend Engineer focused on security, building and owning the systems that allow Trigger to safely run massive volumes of untrusted user code within their infrastructure. This is a product engineering role where secure sandbox runtimes are a shipped feature, not an afterthought. The ideal candidate combines strong backend/product engineering instincts with genuine offensive-security mindset—someone who naturally gravitates toward hacking, pen testing, and breaking things.
Key responsibilities include:
- Designing and maintaining secure execution environments that isolate untrusted user code, the core product problem of this role
- Building threat detection and incident response systems, including monitoring, alerting, and leading investigations
- Managing vulnerability lifecycle end-to-end: scanning, triage, AI-assisted security scans (quarterly), and incoming disclosure triage
- Running internal AI-assisted pen testing and coordinating external security engagements
- Adding security-specific review layers to the PR process
- Maintaining SOC 2 compliance and ongoing regulatory requirements
- Owning the vulnerability disclosure program end-to-end
- Fostering security culture across the engineering team through reviews, documentation, and pragmatic guardrails
As a commercial open-source software company, you'll also participate in community support on Discord and GitHub, contribute to documentation, and help create content (code examples, blog articles, videos, tweets) as part of product-led growth efforts.
REQUIREMENTS:
Must-have:
- Real backend engineering experience: ability to design and ship production backend systems independently
- Genuine offensive-security curiosity demonstrated through pen testing, CTFs, bug bounty hunting, or hacking as hobby or discipline
- Comfort owning ambiguous, product-shaped security problems (sandboxing and runtime isolation are engineering problems as much as security ones)
- Proactive mindset that takes work off the team's plate rather than creating queues
- Willingness to be on-call for reliability and security response
- Open to in-person team events throughout the year
Highly valued:
- Experience building or hardening sandboxed/isolated execution environments (containers, microVMs, gVisor, Firecracker, WASM sandboxes, or similar)
- Track record in pen testing, bug bounty programs, or CTFs
- Experience with AI-assisted tooling for security scanning or workflows
- Proven open-source contribution history
- Background at developer tools, infrastructure, or open-source companies
- Node.js and TypeScript proficiency sufficient to read and review application code