Avatar for Ennote Security
Ennote Security
Actively Hiring
Post-quantum, zero-persistence secrets manager for human teams and machine workloads
  • Top 1% of responders
    Ennote Security is in the top 1% of companies in terms of response time to applications
  • Responds within a day
    Based on past data, Ennote Security usually responds to incoming applications within a day
  • Growing fast
    Showed strong hiring growth in the past month

Security Engineer

Posted: 2 weeks ago• Recruiter recently active
Hires remotely in
Remote Work Policy

Remote only

Company Location
Visa Sponsorship

Not Available

RelocationNot Allowed

About the job

About Ennote

Ennote Security is the identity-driven secret manager unifying human collaboration and machine automation. Our platform centralizes governance for passwords, environment variables, API keys, and infrastructure certificates - replacing scattered .env files and legacy vaults with a single, hardware-backed source of truth.
Ennote is live in production and used by engineering teams to manage secrets across their Kubernetes infrastructure, with real-time sync, native SSO/RBAC, and immutable audit logging. Our architecture is built on a strict zero-persistence principle: plaintext secrets are never written to disk. Every credential is encrypted client-side, encapsulated using post-quantum cryptography, and decapsulated only transiently in volatile memory inside a hardware-backed enclave before being re-wrapped for the requesting identity.
We're building toward SOC 2 Type II and ISO 27001 certification, and we're growing our customer base among engineering teams who depend on us to protect their most sensitive infrastructure credentials.

The Role

We're hiring a Security Engineer to own offensive security at Ennote - someone who will treat our platform the way a real attacker would, and who takes ownership of finding what we've missed before someone else does.
This isn't a theoretical audit of a whiteboard architecture. You'll be testing a system that active customers rely on today: our CLI and client-side encryption flow, our real-time gRPC synchronization layer, our Kubernetes-native agents, and our BYOK integrations with customer-managed KMS. Because all cryptographic operations happen client-side by design - we deliberately avoid exposing a server-side API as an attack surface - your testing will focus heavily on the client, the sync protocol, and the enclave boundary rather than a traditional API perimeter. You'll be working directly against production-grade code and logic; high-impact or potentially disruptive exploitation attempts will run in a dedicated staging cluster that mirrors production, so we can protect customer SLAs while you push as hard as you need to. Your job is to break our security assumptions, document exactly how, and work directly with engineering to close the gap.

Responsibilities

  • Adversarial testing: Design and execute structured, documented penetration tests against the Ennote CLI, our client-side encryption flow, our gRPC sync streams, and our Kubernetes Smart Agents.
  • Identity and access testing: Attempt to defeat our ephemeral identity and bootstrap token model; probe for privilege escalation paths across SSO, RBAC, and workspace isolation boundaries.
  • Memory and enclave auditing: Verify that our transient key re-wrapping process holds up under adversarial conditions - confirming no plaintext or key material persists outside volatile memory.
  • Cloud KMS / BYOK review: Audit our AWS/GCP KMS integrations and customer-owned key flows for misconfiguration or exploitable trust boundaries.
  • Audit log validation: Confirm our immutable audit logs hold up under attack - if you bypass an RBAC boundary, the logs need to capture exactly how and under which identity. This evidence is required for our SOC 2 Type II and ISO 27001 work.
  • Reporting and remediation: Deliver clear, prioritized findings to engineering leadership, and work collaboratively through remediation and re-testing.
  • Compliance readiness: Support our SOC 2 Type II and ISO 27001 preparation with evidence from real testing, not just checklist review.

What We're Looking For

  • You've pentested real production systems before - SaaS platforms, cloud infrastructure, cryptographic systems - not just labs, CTFs, or certs.
  • You know Kubernetes security well, and you're comfortable around hardware-backed enclaves (Intel TDX or similar) and HSM/KMS key management.
  • You've worked with multi-tenant systems and ideally streaming protocols like gRPC.
  • You default to assuming something's broken until you've proven otherwise.
  • You'll tell us what's wrong directly, even if it's not what we want to hear.

Compensation

We have paying customers and a live product, and we're currently closing institutional funding to grow the team properly. Until that round closes, this role is equity-only - no salary. We're offering a meaningful stake because this function matters to us and we want the right person to have real skin in the game. Once we close funding or hit sustainable revenue, our plan is to move this into a paid position.

If getting in early and owning security at a company that's already proving itself in the market sounds interesting to you, let's talk.

About the company

Ennote Security company logo

Ennote Security

Actively Hiring
Post-quantum, zero-persistence secrets manager for human teams and machine workloads1-10 Employees
  • Top 1% of responders
    Ennote Security is in the top 1% of companies in terms of response time to applications
  • Responds within a day
    Based on past data, Ennote Security usually responds to incoming applications within a day
  • Growing fast
    Showed strong hiring growth in the past month
Learn more about Ennote Security image

Founders

Serge Zhuravel
Founder
Vancouver
image
View the team image

Similar Jobs

Source company logo
Source
Developer data management for edge-first software