Full-Time

Senior Software Security Engineer

Confirmed live in the last 24 hours

Wikimedia Foundation

Wikimedia Foundation

501-1,000 employees

Operates Wikipedia and free knowledge projects

Compensation Overview

$105.3k - $163.6kAnnually

Senior

Remote in USA + 2 more

More locations: Remote in UK | Remote in Canada

The Wikimedia Foundation is a remote-first organization and is currently able to hire in the following countries: Australia, Austria, Bangladesh, Belgium, Brazil, Canada, Colombia, Costa Rica, Croatia, Czech Republic, Denmark, Egypt, Estonia, Finland, France, Germany, Ghana, Greece, India, Indonesia, Ireland, Israel, Italy, Kenya, Mexico, Netherlands, Nigeria, Peru, Poland, Singapore, South Africa, Spain, Sweden, Switzerland, Uganda, United Arab Emirates, United Kingdom, United States of America, and Uruguay.

Category
Cybersecurity
IT & Security
Required Skills
PHP
JavaScript
Linux/Unix
Requirements
  • Strong software engineering experience with a focus on security
  • Ability to work effectively in a modern, object-oriented PHP code-base
  • Experience developing client-side JavaScript
  • Experience in developing secure software or security-related product features
  • A strong interest in working with a talented security team and learning more specialist security skills such as exploiting and mitigating application-level vulnerabilities
  • Patience in explaining security issues and their implications on privacy and risk to non-technical audiences
  • Sensitivity to the security challenges faced by participants in a large, international project
  • Experience using Linux at the command line for tasks related to web application development and deployment
  • Ability to maintain focus when working remotely
Responsibilities
  • Help design and build MediaWiki security capabilities
  • Review and deploy security features developed by the Foundation and community members
  • Work with other development teams to ensure that they make safe architectural and implementation choices
  • Perform security maintenance and address technical debt in security-critical components
  • Provide support for application security incidents and operations
Desired Qualifications
  • Experience working on anti-abuse mechanisms such as CAPTCHA and bot detection
  • Previous experience building security countermeasures against attacks on technologies at the web, backend and database level
  • Experience finding and fixing security bugs and reviewing code for security gaps
  • A working knowledge of threat modeling and secure design patterns

The Wikimedia Foundation operates Wikipedia and other free knowledge projects, aiming to create a world where everyone can freely access and share knowledge. It provides a platform for users to read, contribute, and share content, while also supporting the volunteer communities that help maintain these projects. The foundation is different from competitors because it is a nonprofit organization that relies on donations from individuals and institutions, rather than advertising or commercial interests. Its goal is to ensure that all knowledge is freely available to everyone, fostering a collaborative environment for knowledge sharing.

Company Size

501-1,000

Company Stage

Grant

Total Funding

$145.9M

Headquarters

San Francisco, California

Founded

2003

Simplify Jobs

Simplify's Take

What believers are saying

  • Integration of AI technology enhances content moderation and curation efficiency.
  • Successful compliance audits improve user trust and platform integrity.
  • Collaborations combat misinformation, strengthening Wikimedia's global information role.

What critics are saying

  • Reliance on donations makes it vulnerable to economic downturns.
  • Generative AI use may lead to misinformation challenges.
  • New regulations pose compliance risks for large online platforms.

What makes Wikimedia Foundation unique

  • Wikimedia Foundation operates the world's largest free knowledge platform, Wikipedia.
  • It supports a global volunteer community to create and maintain educational content.
  • The Foundation is committed to free access to knowledge for everyone worldwide.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Remote Work Options

Company News

Vipasho
Mar 1st, 2025
On International Women's Day, the Wikimedia Foundation celebrates contributors closing gender gaps on Wikipedia

The Wikimedia Foundation, the nonprofit that hosts Wikipedia and other Wikimedia projects, today announced the launch of its "Knowledge is Human.

VentureBeat
Dec 17th, 2024
Nvidia And Datastax Just Made Generative Ai Smarter And Leaner — Here’S How

Join our daily and weekly newsletters for the latest updates and exclusive content on industry-leading AI coverage. Learn More. Nvidia and DataStax launched new technology today that dramatically reduces storage requirements for companies deploying generative AI systems, while enabling faster and more accurate information retrieval across multiple languages.The new Nvidia NeMo Retriever microservices, integrated with DataStax’s AI platform, cuts data storage volume by 35 times compared to traditional approaches — a crucial capability as enterprise data is projected to reach more than 20 zettabytes by 2027.“Today’s enterprise unstructured data is at 11 zettabytes, roughly equal to 800,000 copies of the Library of Congress, and 83% of that is unstructured with 50% being audio and video,” said Kari Briski, VP of product management for AI at Nvidia, in an interview with VentureBeat. “Significantly reducing these storage costs while enabling companies to effectively embed and retrieve information becomes a game changer.”Nvidia’s NeMo Retriever technology delivers a 35x improvement in data storage efficiency, as illustrated in a comparison of raw text storage, baseline vector embeddings, and reduced embedding dimensions. This breakthrough underpins the scalability of generative AI across enterprise applications. (Credit: Nvidia)The technology is already proving transformative for Wikimedia Foundation, which used the integrated solution to reduce processing time for 10 million Wikipedia entries from 30 days to under three days

Business Wire
Dec 16th, 2024
Holistic AI Completes World-First Independent Audit of Wikipedia Under the Digital Services Act

By partnering with the Wikimedia Foundation to conduct the first-ever audit of Wikipedia under the DSA, Holistic AI is also helping VLOPs assess and mitigate the risks of online platforms and implement best practices that prioritize innovation, safety, and accountability.

BeInCrypto
Nov 29th, 2024
¿Pueden Las Redes Sociales Descentralizadas Garantizar Realmente La Libertad De Expresión?

En un mundo donde las plataformas de redes sociales tradicionales dominan la conversación digital, ¿están surgiendo alternativas descentralizadas como un contrapunto prometedor a la censura o como un caldo de cultivo para el discurso de odio?BeInCrypto habla con Anurag Arjun, cofundador de Avail, un pionero en infraestructura blockchain que está apasionado por cómo la descentralización puede potencialmente transformar el discurso y la gobernanza en línea.Las redes sociales descentralizadas enfrentan desafíosEn octubre, X (anteriormente Twitter) suspendió la cuenta en hebreo del líder supremo iraní Ali Khamenei por “violar las reglas de la plataforma”. La publicación en cuestión comentaba sobre el ataque de represalia de Israel en Teherán, reavivando debates globales sobre el poder que las plataformas centralizadas tienen sobre el discurso público.Muchos preguntaron: ¿Puede ser que al líder supremo de una nación no se le permita comentar sobre ataques aéreos que ocurren dentro de sus propias fronteras? Dejando de lado la sensibilidad política, lo mismo sucede todo el tiempo con creadores cotidianos en contextos de menor importancia. Leer más: ¿Qué son las DeFi o finanzas descentralizadas?En el segundo trimestre de 2024, el sistema de marcado automático de YouTube eliminó aproximadamente 8,19 millones de videos, mientras que el marcado generado por usuarios eliminó solo alrededor de 238,000 videos.En respuesta, plataformas descentralizadas como Mastodon y Lens Protocol están ganando popularidad. Mastodon, por ejemplo, vio un aumento de 2,5 millones de usuarios activos desde la adquisición de Twitter por Elon Musk en noviembre de 2022. Estas plataformas prometen redistribuir el control, pero esto plantea preguntas complejas sobre moderación, responsabilidad y escalabilidad:. “La descentralización no significa la ausencia de moderación, se trata de trasladar el control a las comunidades de usuarios mientras se mantiene la transparencia y la responsabilidad”, Anurag Arjun, cofundador de Avail, dijo a BeInCrypto en una entrevista

Modern Ghana
Nov 20th, 2024
Open Foundation West Africa engages journalists to combat misinformation ahead of December polls

Open Foundation West Africa (OFWA), in collaboration with the Wikimedia Foundation and Code for Africa, has organized a one-day forum to equip journalists with the tools to combat misinformation and disinformation during the upcoming December elections in Ghana.