Senior/Staff Security Engineer

  • Engineering
  • Employee - FT
  • San Francisco, USA or Victoria, Canada or Paris, France
Apply now

Change.org is seeking a Senior or Staff Security Engineer who will be part of the team responsible for the security of our global infrastructure and applications. As a member of our team, you’ll ensure that activists all over the world can securely participate in Change.org actions and truly help make a positive impact on the world. In this role you’ll work primarily on application and cloud security, collaborate with our IT and engineering teams, establish security monitoring and incident procedures, and help to foster a culture of security across the organization. The security and privacy of our employees and users are paramount, and you will help achieve it. This position reports to the Director of Engineering who oversees infrastructure, security, and site integrity.

A Senior Security Engineer at Change is someone who can work effectively at scale, manage their own priorities and make appropriate progress with minimal supervision. Typically, Senior Security Engineers have 4-5 years of relevant engineering experience as well as a mastery of one skill, such as penetration testing, application or cloud security, or security monitoring and response.

A Staff Security Engineer at Change is not only able to work effectively and efficiently at scale, but they also set direction and priorities for a small number of adjacent engineers. 

When we get busy, it’s likely that we’re making headline news somewhere. It is a distinct pleasure to know we are providing a safe site that is empowering people all over the world. Our team takes great pride in using our powers for good.


As a member of the team you will:

  • Influence our overall security roadmap
  • Collaborate with engineering teams in building out a secure global service-oriented architecture
  • Schedule and execute automated security audits on applications and infrastructure
  • Manage penetration tests for applications and services
  • Setup security monitoring and participate in security-related incident response
  • Document current and future security procedures and policies
  • Remediate and write post-mortem reports on security-related issues
  • Train and socialize security best practices across the company  

  • We’re happy to help you learn what you need to know; we encourage and support each other’s growth and we are open to any candidate with expertise across these areas.

This describes you:

  • 4+ years of software development with a recent focus on security
  • Ability to efficiently evaluate and communicate security risks and related defensive techniques with any audience
  • Ability to design, implement and test new security features and controls
  • Experience with Linux/UNIX systems and familiarity with cloud platforms such as AWS

Nice to have skills:

  • Familiarity with OWASP Top 10, WASC, and/or CWE 25
  • Experience with SOC-2, PCI, or other compliance frameworks
  • Experience with data privacy requirements
  • Experience with device management using JAMF
  • Experience with security monitoring and incident response
  • Proficient in shell scripting and either Ruby or Python
  • Experience with configuration tools such as Terraform, Chef, Ansible, or Puppet
  • Understanding of network protocols such as HTTP and SSL/TLS

Location: Victoria, BC, Canada (preferred); San Francisco, CA; Paris, France

Change.org is committed to being a diverse and inclusive workplace. We strongly encourage applicants of different backgrounds, cultures, genders, experiences, abilities and perspectives to apply.

All qualified applicants will receive consideration for employment without regard to race, color, national origin, religion, sexual orientation, gender, gender identity, age, physical disability, or length of time spent unemployed.
Change.org Careers

Outsized impact

Change.org is the fastest growing social change organization in the world, empowering more than 200 million people to create change in their communities.

Amazing people

We are building a world-class team of technologists and creatives along with the most accomplished team of social movement creators in the world.

Extraordinary benefits

Plenty of vacation

Personal growth