HN user

volker48

207 karma

[ my public key: https://keybase.io/marcusmccurdy; my proof: https://keybase.io/marcusmccurdy/sigs/9Pjz5ola4oQoSJW-j3T4YFwc4SZFUvvcN_2Oeh4OvSQ ]

My Bitrated profile: https://www.bitrated.com/volker48/

Contact me: earn.com/volker48

Posts3
Comments90
View on HN

Obsidian Security | Staff Software Engineer | Philadelphia or Palo Alto | Full-time | $176k-$196k + equity + 401k | https://job-boards.greenhouse.io/obsidiansecurity/jobs/51527...

We secure the SaaS apps companies actually run on: M365, Salesforce, and hundreds more. You’d be on the Threat product team working full-stack. That means browser extension code (content/background scripts, manifest v3, message passing), backend services chewing through millions of events, and the data pipelines feeding our detection engine. One day you’re in TypeScript debugging why a content script won’t capture form submissions on some vendor’s weird SPA. The next you’re in Python fixing a Kafka consumer that’s falling behind. Sometimes you’re in Rust optimizing a hot path in the telemetry collector.

Big current focus is shadow AI, i.e. catching when employees paste sensitive data into ChatGPT, Claude, or whatever LLM showed up this week. You’d build the systems that detect it.

Looking for ~8+ yrs experience, real browser knowledge (DOM, event loop, SPA routing, CORS, not just “I used React”), prior browser extension work, strong TypeScript, comfortable in Python, willing to write Rust, plus data-at-scale chops (event streaming, Postgres, Elasticsearch, Kafka). Bonus: AI security (prompt injection, exfiltration), detection engineering/SIEM, or security tooling.

Apply via the link above, or see all our open roles at https://www.obsidiansecurity.com/careers

Obsidian Security | Staff Software Engineer | REMOTE (US) | Full-time | $176k-$196k + equity + 401k | https://job-boards.greenhouse.io/obsidiansecurity/jobs/51527...

We secure the SaaS apps companies actually run on: M365, Salesforce, and hundreds more. You’d be on the Threat product team working full-stack. That means browser extension code (content/background scripts, manifest v3, message passing), backend services chewing through millions of events, and the data pipelines feeding our detection engine. One day you’re in TypeScript debugging why a content script won’t capture form submissions on some vendor’s weird SPA. The next you’re in Python fixing a Kafka consumer that’s falling behind. Sometimes you’re in Rust optimizing a hot path in the telemetry collector.

Big current focus is shadow AI, i.e. catching when employees paste sensitive data into ChatGPT, Claude, or whatever LLM showed up this week. You’d build the systems that detect it.

Looking for ~8+ yrs experience, real browser knowledge (DOM, event loop, SPA routing, CORS, not just “I used React”), prior browser extension work, strong TypeScript, comfortable in Python, willing to write Rust, plus data-at-scale chops (event streaming, Postgres, Elasticsearch, Kafka). Bonus: AI security (prompt injection, exfiltration), detection engineering/SIEM, or security tooling.

Apply via the link above, or see all our open roles at https://www.obsidiansecurity.com/careers

Obsidian Security | REMOTE (US-Eastern hours ideal) or ONSITE (Palo Alto / Newport Beach) | Full-Time | VISA OK | Salary $149k–$208k + equity

We secure the SaaS apps—Microsoft 365, Salesforce, and hundreds more—where modern business happens, blocking breaches *in real time*.

Why Obsidian?

  - Founded 2017; backed by Greylock, Norwest, IVP, and others, now scaling toward IPO.  
  - Trusted by Snowflake, T-Mobile, Pure Storage & 200+ enterprises on five continents.  
  - Momentum: $90 M Series C, new AI-driven defenses, expanding partner ecosystem.
Senior Threat Backend Engineer

Own the APIs, event pipelines, and extension logic that power our browser-native security product. Ship to prod the day you merge.

You will:

  - Build & refine threat detections with our security research team.  
  - Stream and enrich event data through Kafka → Postgres/Elasticsearch.  
  - Extend our Chromium-based browser extension (WXT).  
  - Add new SaaS services to the platform; optimize data stores for scale.
Stack highlights:
  - Python + FastAPI / asyncio  
  - TypeScript + WXT 
  - Rust micro-services
  - Kafka
  - Docker/K8s
  - Postgres & Elasticsearch
You bring:
  - 4–6 yrs software engineering (cyber-security a plus).  
  - Deep Python async skills; Kafka & K8s in production.  
  - DB mastery (Postgres + Elastic).  
  - Clear communication & bias toward ownership.
Apply here: https://grnh.se/a646066d8us

Obsidian Security | Threat Backend Engineer | Newport Beach, Palo Alto, Philadelphia | Onsite or Remote | Full-Time

Obsidian Security is at the forefront of SaaS security, dedicated to detecting and mitigating threats effectively. We are hiring for multiple roles. With our advanced threat detection solution, we visualize user activity, identify employee compromise, and mitigate insider threats, ensuring data security before a material breach occurs.

Skills:

  - Python (specifically experience with asyncio)
  - Rust a plus
  - SqlAlchemy
  - Fastapi
  - Scylla DB a plus
  - Go
Apply here: https://grnh.se/a646066d8us

Same for me. Many times I would have an idea, but I would think ahead of all the mundane and tedious things I would need to complete to implement it and not even get started. Now I work with the LLM to do those more tedious and mechanical parts and frankly the LLM is generating pretty similar code to what I would have written anyway and if not I just rewrite it. A few times I've even been pleasantly surprised when the LLM took an approach I wouldn't have considered and I actually liked it better.

Thanks I didn't see that before!

  you can't use latest:20 in a .tool-versions file or many other places
This has always bugged me in asdf where I just want to say something like python:3.11.* where I don't care about the patch version number just that some 3.11 version is used.

Obsidian Security | Principal Backend Engineer | Philadelphia, Newport Beach, Palo Alto | REMOTE | Full-Time

Obsidian Security is at the forefront of SaaS security, dedicated to detecting and mitigating threats effectively.

With our advanced threat detection solution, we visualize user activity, identify employee compromise, and mitigate insider threats, ensuring data security before a material breach occurs.

Skills:

  - Python (specifically experience with asyncio)
  - SQL
  - Rust a plus 
  - SQLAlchemy 
  - Fastapi 
  - Scylla DB a plus 
  - Go
Principal Backend Engineer: https://grnh.se/08bd2ac38us

Obsidian Security | Threat Backend Engineer | Newport Beach, Palo Alto, Philadelphia | Onsite or Remote | Full-Time

Obsidian Security is at the forefront of SaaS security, dedicated to detecting and mitigating threats effectively.

We are hiring for multiple roles.

Threat Detection Team:

With our advanced threat detection solution, we visualize user activity, identify employee compromise, and mitigate insider threats, ensuring data security before a material breach occurs.

Skills: - Python (specifically experience with asyncio) - Rust a plus - SqlAlchemy - Fastapi - Scylla DB a plus - Go

Threat Backend Engineer: https://obsidiansecurity.applytojob.com/apply/wK0pJCTaKO/Thr...

See all our open positions here https://www.obsidiansecurity.com/careers/

Obsidian Security | Threat Team Engineer | Newport Beach, Palo Alto, Philadelphia | Onsite or Remote | Full-Time

Obsidian Security is at the forefront of SaaS security, dedicated to detecting and mitigating threats effectively.

We are hiring for multiple roles.

Threat Detection Team:

With our advanced threat detection solution, we visualize user activity, identify employee compromise, and mitigate insider threats, ensuring data security before a material breach occurs.

Threat Backend Engineer: https://obsidiansecurity.applytojob.com/apply/wK0pJCTaKO/Thr...

SaaS Posture Security & Compliance Team:

Ensuring SaaS applications are robust and compliant with industry standards. You'll focus on real-time monitoring, proactive vulnerability mitigation, and managing sensitive data access for optimal security and continuous compliance.

Skills:

  - Python (specifically experience with asyncio)
  - SqlAlchemy
  - Fastapi
  - Dagster
  - Duckdb / Postgres
For posture team email delston@obsidiansecurity.com.

See all our open positions here https://www.obsidiansecurity.com/careers/

Obsidian Security | Threat Backend Engineer | Newport Beach, Palo Alto, Philadelphia | Onsite or Remote | Full-Time

Obsidian Security is at the forefront of SaaS security, dedicated to detecting and mitigating threats effectively.

We are hiring for multiple roles.

Threat Detection Team:

With our advanced threat detection solution, we visualize user activity, identify employee compromise, and mitigate insider threats, ensuring data security before a material breach occurs.

Threat Backend Engineer: https://obsidiansecurity.applytojob.com/apply/wK0pJCTaKO/Thr...

SaaS Posture Security & Compliance Team:

Ensuring SaaS applications are robust and compliant with industry standards. You'll focus on real-time monitoring, proactive vulnerability mitigation, and managing sensitive data access for optimal security and continuous compliance.

Skills:

  - Python (specifically experience with asyncio)
  - SqlAlchemy
  - Fastapi
  - Dagster
  - Duckdb / Postgres
For posture team email delston@obsidiansecurity.com.

See all our open positions here https://www.obsidiansecurity.com/careers/

Obsidian Security | Threat Backend Engineer | Newport Beach, Palo Alto, Philadelphia | Onsite or Remote | Full-Time

Obsidian Security is at the forefront of SaaS security, dedicated to detecting and mitigating threats effectively.

We are hiring for multiple roles.

Threat Detection Team:

With our advanced threat detection solution, we visualize user activity, identify employee compromise, and mitigate insider threats, ensuring data security before a material breach occurs.

Threat Backend Engineer: https://obsidiansecurity.applytojob.com/apply/wK0pJCTaKO/Thr...

SaaS Posture Security & Compliance Team:

Ensuring SaaS applications are robust and compliant with industry standards. You'll focus on real-time monitoring, proactive vulnerability mitigation, and managing sensitive data access for optimal security and continuous compliance.

Skills:

  - Python (specifically experience with asyncio)
  - SqlAlchemy
  - Fastapi
  - Dagster
  - Duckdb / Postgres
For posture team email delston@obsidiansecurity.com.

See all our open positions here https://www.obsidiansecurity.com/careers/

There can definitely be some downsides to this approach. For example, let me see what the CI script does to deploy. "make deploy", ok let me checkout the Makefile. Ok, that calls some python module "deploy.py". I tend to get frustrated with all the indirection and would prefer to just see the deploy steps in the CI script itself.

I switched from installing Python with Homebrew to using asdf and I've been very pleased with the results. With Homebrew, every significant macOS update would break all my virtual environments. With asdf this is no longer an issue. The ability to set local versions of Python for different projects is very nice as well.

Classic garbage in garbage out. If all the tests are bad then how could they possible help anything. That doesn't mean unit tests or other automated tests are worthless though.

Seems like vaccine antibodies target a broader range of variants https://directorsblog.nih.gov/2021/06/22/how-immunity-genera...

Antibody titers are higher from vaccines as well. "After the second dose of the vaccine, antibody titers were up to 10 times higher than those of patients who had recovered from natural COVID-19 infection, suggesting that even those with prior exposure could benefit from vaccination."

https://www.contagionlive.com/view/immune-response-from-mrna...

Besides a sore arm for about 24 hours I really had no other side effects from Pfizer. After the second shot my arm got sore a bit closer to the time of injection, but overall pain was lower.

I felt worse the day after my yearly flu shot in 2020.