Hacker Newsnew | past | comments | ask | show | jobs | submit | d0ublespeak's commentslogin

Zepto | Senior Security Engineer (product security) | REMOTE (AUS) | https://zepto.bamboohr.com/careers/104

As a Senior Security Engineer (Product Security), you will play a significant role in keeping our product safe and secure by building on and maturing Zepto's product security practices. You will work hands-on and shoulder-to-shoulder with Engineering and Product teams, providing guidance and coaching across the software development life cycle while continuing to raise the bar on our security expectations and capability.

This is a security role at its core, but not a gatekeeping one. We are builders – we expect you to read and write production-level code, build tooling and automation, and contribute paved-road solutions that engineers actually want to use. Reporting to the Security Engineering Lead, you will work closely with them to develop and build Zepto's product security strategy and approach. You will apply a consultative and advisory approach when working with the wider Zepto team, empowering them to work confidently and to use the self-service capabilities you help establish.

We have excellent working relationships with our developers and we need to keep it that way. We are not the team of no. We are the team that helps make things better.

Zepto is moving quickly towards an AI-native way of building and operating. You will be someone who is already experimenting with AI and agentic tooling, or is genuinely keen to, and who is open to developing the skills to secure these systems as we adopt them. Within the Security team, you are the go-to person for:

Secure development practices Vulnerability management Security architecture advice

Working in a scale-up, means you get the opportunity to flex your skills in a variety of ways. We are agile and always willing to roll up our sleeves to get things done. You can, however, expect your day to day to be involved in the following:

Coach engineering teams and collaborate to ensure every step of the software development life cycle follows security best practices Design, build and maintain security tooling, automation and paved-road controls as production-quality software Conduct security assessments and architecture reviews of Zepto's applications and services Embed within project teams to ensure they are effectively considering information security risk and prioritising security controls Establish and document security architecture and practices in collaboration with the Security Engineering Lead, Product and Engineering teams Work with the Security Engineering Lead to support Zepto's adoption of AI and agentic systems, and experiment with AI tooling to improve how the Security team works Help manage application security incidents in collaboration with the rest of the Security team


Honestly, you could sub the other big Bug Bounty platform for H1 in this post and you’d be still extremely accurate.


Hashes or it didn’t happen.


Heaps, most recent is just a little applet that stops my Mac from going to sleep with the lid closed: https://transitivedev.gumroad.com/l/doppio-app

Bunch of security tools: Some are at https://diffsec.dev others:

https://github.com/diffsec/quokka

https://github.com/ihavespoons/hooksy


This is such a nothing burger corporate ad. They purchased a cheap cable and it sucks. So let’s X-ray it and make a thought piece post about implants…



It can be less/more than 2 percent too dependent on income. But yes we are extremely blessed in this country with a healthcare system that isn’t perfect but is extremely affordable.


With seeing a doctor we have two main systems that you can use and each will have a different waiting time. Bulk-billing and the fully public option has longer waiting times because there aren’t enough clinics/specialists or doctors, The reasons for this are complex but they stem from an unwillingness from prior governments to raise the amount the government pays for each service to adequately to support this system meaning less doctors and practices being willing to support it.

You’ve then got practices/specialists etc… that charge copays and they tend to have less waiting times because less people are willing to pay copays. A lot of these practices will also do outright private billing which is what you’re experiencing.


Got it. In India, I am used to the concept of Government hospitals vs Private hospitals. Things are pretty clear on how they work. Insurance was introduced a couple of decades or so back in my home state, which allows people to use private hospitals at govt expenses (premiums paid by govt), but it’s still heavily govt (free) vs private (paid). Here it seems like there are no “govt hospitals” if I understand correctly. So things are a little more complicated.


This isn’t an inherent flaw of public health care. A lot of the health care problems in this country (Australia) stem from a continued disinvestment in the public system after a decade (prior to the current government) of conservative mismanagement. Most state funding here comes from the federal governments standard sales tax. They intentionally gimped our public system to fund a private system that isn’t financially viable. Reversing that is going to take time. The problem exists it’s just important to attribute it to the correct sources. Medicare (our public insurer) is an incredible privilege that we should protect and hold our leaders accountable for managing.


I don't understand where you got that I am saying public health care systems are flawed. Both systems have pros and cons. And I have seen the "going to take time" phrase for quite a long time now and so don't think it holds any value anymore.

In terms of affordability which you also referenced in a separate comment, I disagree. Compared to some prices I've seen in the US, it is cheaper. Compared to other countries I've experienced, it is more expensive. Comparing private and public systems is not straight forward and I don't think this adds any value to the discussion.

In terms of attributing failure to correct sources, Victoria hasn't had a "they"(who you're claiming gimped our public system) for many years now but I am not interested in a discussion about politics.


I think it is mostly just a problem with Victoria - and they are are hardly conservative. Hospitals and ambulance service is a state issue and other states fair much better.


I just don’t see why Joe Public will ever care about decentralisation as a concept.

We tend to hand wring about principles within the tech sphere, when the bulk of people just want a place that won’t make them feel immediately (longer term doesn’t matter) crappy when they use it, whatever that means for them. That tends towards centralisation because decentralised services have awful moderation and tend to create an even stronger strain of groupthink.


I think Bluesky exists to demonstrate that people want the features that come with centralization without the oppressive platform lock-in. If Bluesky's moderation, TOS, UI, default feeds, etc. are intolerable to you, then you should be free to move your content and your network to an app with different moderation, TOS, feeds, etc.

Bluesky isn't marketing itself as a decentralized platform because it's not. It's an opinionated view of a decentralized network, and others are free to use differently opinionated views or make their own.


> I just don’t see why Joe Public will ever care about decentralisation as a concept.

IME they do care, but they have no patience to deal with the hurdles that decentralisation imposes upon your user experience. So ease-of-use and convenience always win.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: