Meet Yubico: the creator of the most secure passkeys and leading provider of hardware authentication security keys. Our company’s mission is to make secure login easy and available for everyone. Yubico was founded in 2007 by Stina and Jakob Ehrensvard, and is public on Nasdaq Stockholm Main Market: YUBICO. Our customers include Fortune 500 companies, hundreds of government agencies and millions of individuals in over 160 countries that rely on Yubico technology to secure access to computers, online services and mobile apps. Our global customer base includes organizations of varying sizes, from large corporations such as Google, Amazon, Microsoft and Hyatt, to companies like Dyson. We are a global company with a strong company culture and employees located in over 14 countries. Yubico’s headquarters are based in Stockholm, Sweden and Santa Clara, CA. Aligned with our mission to make the internet more secure for everyone, Yubico donates YubiKeys to organizations helping at-risk individuals through our philanthropic initiative, Secure it Forward.
At Yubico, we offer:
Freedom and Flexibility: At Yubico, we want you to be your most productive selves whether you decide to work 100% from home or choose to work hybrid/onsite. The way we balance the fast-paced demands of a high-growth company and sustainability is making rest a priority.
Yubico Values: We work to ensure that our employees have an open space to have their voices amplified to create a workplace where everyone feels like they belong. In support of this, our employees have created some pretty cool Employee Resource Groups that foster inclusion, help build community and connection across Yubico. Additionally, Yubico donates YubiKeys to organizations in need all over the world (you can read more about our work here).
Social Connection: Relationships and connectedness matter, and we love spending time with our team! Our virtual workspace keeps us connected day-to-day whether it's through Yubico celebrating wins or our buzzing Slack communities. Check out ourLife at Yubico Page on LinkedIn and our awards here.
The Role:
The Product Security team is responsible for ensuring Yubico develops and maintains secure products and services. As part of the Product Security team, your primary responsibility will be to collaborate with the firmware and software teams to design and integrate solutions that support secure design and development practices. You will also employ a combination of static and dynamic analysis methodologies to identify and remedy complex vulnerabilities across our products.
If you are looking for a fun challenge, are passionate about security, and want to work at a security-oriented company, this opportunity is for you.
Define and evangelize requirements and guidance for secure by design and secure by default principlesImplement automation to prevent and detect security flaws in all phases of developmentConduct design reviews and manual security assessmentsLead training and awareness sessionsDefine and implement metrics to provide visibility into the impact of your workDefine, lead, and influence processes to secure products and servicesIdentify and advocate for new and novel uses of Yubico’s technologyAbility to travel to Yubico’s other offices two times per year
3+ years in a product security role3+ years of software developmentProficiency in threat modelingProficiency in CKnowledge of common vulnerability classesExperience in static code analysis
Knowledge of WebAuthn, OATH HOTP, OATH TOTP, U2F, PIV, or OpenPGPProficiency in .NET or C++Experience developing for ARMExperience in targeted fuzzing