Skip to content
Webcrab

Full-time · Security & Care

Security Engineer

Protect client websites and servers: harden them, detect attacks, clean up hacked sites and improve our free security scanner.

Our clients run businesses on their websites, and attackers target them every day. You will be the person who keeps those sites safe and who steps in when something goes wrong. The work mixes proactive hardening, incident response and building the security tools we offer to the public.

Type
Full-time
Level
Junior to mid-level
Work style
Hybrid

Pay is discussed openly in the interview process.

What you will do

  • Harden WordPress, Next.js and server setups: TLS, security headers, firewalls, access control and backups.
  • Investigate hacked websites, remove malware, find how the attacker got in and close it.
  • Review client sites for vulnerabilities and write clear, prioritised reports with fixes.
  • Monitor uptime and alerts for sites on our care plans, and respond to incidents.
  • Improve our free website security scanner and add new checks.

What we are looking for

  • Good understanding of web security: the OWASP Top 10, TLS, authentication, sessions and common attacks.
  • Comfortable on Linux and the command line, and with reading logs.
  • Experience with at least one of WordPress/PHP, Node.js or cloud hosting.
  • Careful and ethical in how you test and report, with clear written communication.

Nice to have

  • Security certifications (Security+, CEH, OSCP) or CTF experience
  • Cloudflare, WAF or SIEM experience
  • Malware analysis or incident response experience

Tools you will use

  • Linux
  • Cloudflare
  • WordPress
  • Nginx and Apache
  • Burp Suite
  • Node.js
  • TypeScript

Your first 90 days

  • Month 1: learn our hardening standard and shadow incident handling.
  • Month 2: run client security reviews and clean up a hacked site with support.
  • Month 3: own on-call response for care-plan clients and ship a new scanner check.

What you will learn

  • Live incident response
  • Building security tooling used by real visitors
  • Advising businesses on risk in plain language
All open roles

Apply for this role

e.g. github.com/yourname

What you have built or learned, and what you want to work on. A few lines is enough.

We use your details only to consider your application and keep them for up to 12 months. Email [email protected] to have them removed.

Get a quote