Instabug jobs
5 Jobs Found
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><span>What this role is</span></p><br>
<p><span>You own a slice of Luciq end to end: the problem, the design calls, the code, the rollout, and customer value. Engineers bring a lot of value to driving product decisions and we innovate on the implementation layer to create differentiating solutions.</span></p><br>
<p><span>The stack is Ruby on Rails and Golang hosted on Kubernetes clusters on AWS, with ClickHouse, Kafka, and Flink behind ingestion and query. You will hand-write less of it than engineers did two years ago. We expect you to work with coding agents the way a strong engineer works with a capable junior: delegate hard, review harder, stay accountable for what ships.</span></p><br>
<p><span>Half the job is judgment about what to build. Luciq is repositioning around agentic mobile observability and experience. We are a broad mobile platform with large enterprise customers who get a lot of value from the different capabilities and signals we capture and innovate on.<br></span></p><br>
<p><span>What you'll do</span></p><br>
<ul>
<li><span>Ship a product area end to end: scope it, build it, launch it, then watch the usage numbers and make sure customers get a lot of value.</span></li>
<li><span>Build the agentic parts of the product.</span></li>
<li><span>Use agents on your own work. Codegen, migrations, test coverage, spec-to-PR. Bring what works back to the rest of engineering.</span></li>
<li><span>Talk to customers directly. Join escalations, read session replays, sit on calls.</span></li>
<li><span>As you gain knowledge of the product and customer space, participate actively in driving scope and work in iterations to deliver.</span></li>
<li><span>Instrument what you ship. You should know your feature's adoption, p95 and infrastructure cost. We invest in helping our Product Engineers get to this level of detail and want them engaged in evolving it, creating efficiencies and making decisions to drive further improvements.</span></li>
<li><span>Operate what you build. On-call responsibility is part of the role and more importantly, share the learnings, implement the preventative measures and continue to iterate.</span></li>
<li><span>Make the rest of the company faster. We all share in the success of our customers, we win together.</span></li>
<li><span>Raise the floor on quality and security in the code you touch, and leave the codebase easier to work in than you found it.<br></span></li>
</ul>
<p><span>What we're looking for</span></p><br>
<p><span>We do not screen on years or degrees. Tell us what you built, who used it, and what changed because of it.</span></p><br>
<p><span>Required</span></p><br>
<ul>
<li><span>A track record of shipping products that real users depended on, with your fingerprints on the product decisions, not only the implementation.<br></span></li>
<li><span>Minimum of 5 years of experience shipping production software, ideally in a fast-moving product engineering environment.</span></li>
<li><span>Deep production experience in Golang, or enough depth in another server language.</span></li>
<li><span>AWS at production scale: compute, storage, networking, CI/CD, and a working sense of what things cost.</span></li>
<li><span>Shipped something built on LLMs. You can talk about retrieval, tool calling, evals, latency and failure modes from experience, not from reading.</span></li>
<li><span>A daily agent-assisted workflow, and an opinion about where it breaks down. Taking full ownership of the work generated, the quality and the approach to the implementation. We love simple solutions to complex problems and we value engineers and the high leverage they bring. AI is a tool in the toolbox.</span></li>
<li><span>Solid API design, and comfort with MySQL, Redis and a messaging system such as Kafka.</span></li>
<li><span>You test where tests pay and skip where they don't, and you apply a pragmatic approach to building guardrails.</span></li>
<li><span>You write clearly. Design notes, incident writeups, release notes.</span> <br></li>
</ul>
<p><span>Helps</span></p><br>
<ul>
<li><span>Mobile experience: iOS or Android, SDK work, or debugging someone else's app in production.</span></li>
<li><span>Columnar and streaming infrastructure: ClickHouse, Flink, or similar at volume.</span></li>
<li><span>Developer tools or observability as a product domain.</span></li>
<li><span>Open source work.<br></span><br></li>
</ul>
<p><span>How we work</span></p><br>
<ul>
<li><span>Pods own customer outcomes, not services. Your scope follows the problem across the SDK, the pipeline, the API, and the dashboard.</span></li>
<li><span>Decisions happen in the open, in writing, and fast. If you need three meetings to change a schema, this will frustrate you.</span></li>
<li><span>You will be in the room when pricing, packaging, and positioning touch your area, and your objections count.</span></li>
<li><span>We deploy continuously, and we watch what we deploy.</span></li>
<li><span>There is no queue of pre-chewed tickets waiting for you. There is a roadmap, a lot of customer signals, and room to drive high-impact work.</span></li>
</ul> </div>
<p>What this role is You own a slice of Luciq end to end: the problem, the design calls, the code, the rollout, and customer value. Engineers bring a lot of value to driving product decisions and we innovate on the implementation layer to create differentiating solutions. The stack is Ruby on Rails and Golang hosted on Kubernetes clusters on AWS, with ClickHouse, Kafka, and Flink behind ingestion and query. You will hand-write less of it than engineers did two years ago. We expect you to work with coding agents the way a strong engineer works with a capable junior: delegate hard, review harder, stay accountable for what ships. Half the job is judgment about what to build. Luciq is repositioning around agentic mobile observability and experience. We are a broad mobile platform with large enterprise customers who get a lot of value from the different capabilities and signals we capture and innovate on.</p><p>What you'll do Ship a product area end to end: scope it, build it, launch it, then watch the usage numbers and make sure customers get a lot of value. Build the agentic parts of the product. Use agents on your own work. Codegen, migrations, test coverage, spec-to-PR. Bring what works back to the rest of engineering. Talk to customers directly. Join escalations, read session replays, sit on calls. As you gain knowledge of the product and customer space, participate actively in driving scope and work in iterations to deliver. Instrument what you ship. You should know your feature's adoption, p95 and infrastructure cost. We invest in helping our Product Engineers get to this level of detail and want them engaged in evolving it, creating efficiencies and making decisions to drive further improvements. Operate what you build. On-call responsibility is part of the role and more importantly, share the learnings, implement the preventative measures and continue to iterate. Make the rest of the company faster. We all share in the success of our customers, we win together. Raise the floor on quality and security in the code you touch, and leave the codebase easier to work in than you found it.</p><p>How we work Pods own customer outcomes, not services. Your scope follows the problem across the SDK, the pipeline, the API, and the dashboard. Decisions happen in the open, in writing, and fast. If you need three meetings to change a schema, this will frustrate you. You will be in the room when pricing, packaging, and positioning touch your area, and your objections count. We deploy continuously, and we watch what we deploy. There is no queue of pre-chewed tickets waiting for you. There is a roadmap, a lot of customer signals, and room to drive high-impact work.</p><p><strong>Desired Candidate Profile</strong></p><ul><li>A track record of shipping products that real users depended on, with your fingerprints on the product decisions, not only the implementation.</li><li>Deep production experience in Golang, or enough depth in another server language.</li><li>AWS at production scale: compute, storage, networking, CI/CD, and a working sense of what things cost.</li><li>Shipped something built on LLMs. You can talk about retrieval, tool calling, evals, latency and failure modes from experience, not from reading.</li><li>A daily agent-assisted workflow, and an opinion about where it breaks down.</li><li>Taking full ownership of the work generated, the quality and the approach to the implementation.</li><li>We love simple solutions to complex problems and we value engineers and the high leverage they bring. AI is a tool in the toolbox.</li><li>Solid API design, and comfort with MySQL, Redis and a messaging system such as Kafka.</li><li>You test where tests pay and skip where they don't, and you apply a pragmatic approach to building guardrails.</li><li>You write clearly. Design notes, incident writeups, release notes.</li><li>Helps Mobile experience: iOS or Android, SDK work, or debugging someone else's app in production.</li><li>Columnar and streaming infrastructure: ClickHouse, Flink, or similar at volume.</li><li>Developer tools or observability as a product domain.</li><li>Open source work.</li></ul>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<span>About the Role: Flat6Labs Junior Financial Controller will be responsible for supporting the Financial Controller & the wider Finance team in maintaining accurate and timely financial reporting and control processes across the organization.<br> As a Financial Control & Reporting Officer, you will play a pivotal role in gathering & validating financial information, identifying and flagging discrepancies and ensuring financial matters are appropriately escalated for review and decision making.<br> About Flat6Labs: Flat6Labs is the leading entrepreneurship platform in emerging markets, empowering entrepreneurs to build, launch, and grow transformative ideas through acceleration programs, ecosystem development, and tailored innovation services.<br> For more information, visit www.<br>flat6labs.com. Key Responsibilities: - Financial Control & Reporting: Assist in reviewing monthly & quarterly financial reports, including income statements, balance sheets, and cash flow statements Prepare timely and detailed reports on financial performance on a quarterly and annual basis Assist in reconciliations & pre-close checks to identify timing and booking errors prior to Controller sign-off, including VAT and revenue recognition timing across reporting periods Monitor intercompany & cross-border transactions, including tax treaty requirements and withholding tax considerations Perform first-line review of financial transactions & reports, proactively identifying and flagging anomalies prior to Controller sign-off Support the preparation of statutory financial statements for subsidiary entities, including Arabic/English reporting where required - Budgeting and Forecasting: Support in developing budgets, providing variance analysis and recommendations across the region Assist in the preparation of financial forecasts and projections Prepare variance analysis and cost breakdowns for donor-funded or grant-based programs - Financial & Contractual Support: Assist in reviewing financial terms and implications of contracts and agreements, including settlements, termination clauses, and refund obligations, in coordination with Legal - Cross-Functional Collaboration: Work closely with departments across the organization to gather financial information and provide insights Coordinate and assist other accounting and finance personnel in the organization Bachelor's degree in Accounting or Finance 1 - 3 years of experience in financial analysis, or a related field, preferably in the startup ecosystem Relevant professional certification is a plus: CMA, CPA, CFA, or ACCA will be preferred but not required Experience with multi-entity and multi-currency financial consolidation Ability to work independently and collaboratively in a fast-paced, entrepreneurial environment Advanced proficiency in Excel, with experience using ERP and accounting systems Exposure to MENA and emerging-market regulatory requirements, including VAT, tax treaties, and donor compliance, is a plus Detail-oriented with a high level of accuracy and integrity Thorough knowledge of basic accounting procedures</span> </div>
<p>As an Application Security Engineer at Luciq, you will help shape and build our application security program alongside the wider team. This is a hands-on, high-ownership role where you will work closely with product and development teams across the full software development lifecycle reviewing designs before code is written, identifying risks as features take shape, and ensuring security is embedded into how we build and ship software, not bolted on after the fact. Our stack runs on Ruby on Rails, Go, and Python, deployed on AWS with Terraform managing infrastructure as code and Jenkins powering CI/CD. You will read and review code in these languages not just rely on scanner output and work with AWS security services (SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront) to provide visibility and protection across our infrastructure. The role spans web applications, APIs, our mobile SDK (iOS and Android), cloud, and CI/CD partnering with engineers, PMs, Platform, and the Security team to make the secure path the default path. This role can be filled at mid-level with a clear growth path to senior-level as you grow into shaping our application security program, or at senior-level if you're already operating at that scope. You will join a lean Security team, which entails stepping beyond core AppSec for incident triage, addressing customer security questionnaires, or supporting cross-functional cloud and compliance reviews. We value this variety as a core facet of the role; if you are seeking hyper-specialized work restricted strictly to application security, this may not be the right fit.</p><p><strong>Desired Candidate Profile</strong></p><p><strong>Must-Haves</strong></p><ul><li><strong>Experience:</strong> 3-6 years in application security, or security engineering</li><li><strong>Education:</strong> Bachelor's degree in Computer Science, Information Security, or equivalent practical experience</li><li>Secure code review in at least one of: Python, Ruby, Go can read code and reason about vulnerabilities, not rely on scanner output</li><li>OWASP Top 10 (Web and API) as root-cause patterns, not a memorized checklist including SSRF, insecure deserialization, injection classes, and access-control flaws</li><li>Threat modeling: practical experience with STRIDE and data flow diagrams; can lead a session with a product team and produce actionable output</li><li>Auth and identity: working depth in session management, RBAC/ABAC models</li><li>CI/CD security automation: hands-on experience integrating SAST, SCA, and secret scanning into pipelines and tuning for actionable signal</li><li>Proactive and ownership-driven does not wait to be told what to secure</li><li>Comfortable working cross-functionally with product engineers, platform engineers, and the wider team</li><li>Strong analytical and problem-solving abilities</li><li>Fluent in English, with strong written and verbal communication</li><li>Communication: clear written and verbal communication can explain a vulnerability to an engineer, a PM, or a VP</li></ul><p><strong>Strong Plus</strong></p><p>We expect strong candidates to have some of these not all. The more, the better.</p><ul><li>Mobile SDK security: OWASP Mobile Top 10 and MASVS/MASTG; Android (Kotlin) or iOS (Swift); experience with Frida, objection, or MobSF</li><li>AWS security service depth: SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront beyond IAM</li><li>Container and Kubernetes security fundamentals</li><li>Supply chain depth: SLSA framework, SBOM</li><li>AI/LLM security: prompt injection mitigations, OWASP LLM Top 10, securing agentic architectures and tool-use boundaries</li><li>Familiarity with ISO 27001 or SOC 2.</li></ul><p><strong>Nice to Have</strong></p><ul><li>Terraform and policy-as-code: tfsec, Checkov, OPA/Conftest</li><li>Experience building or bootstrapping a security program</li><li>Bug bounty participation, published CVEs, or documented security research</li><li>Hands-on certifications: OSCP, OSWE, eMAPT</li><li>Incident response experience triage, containment, root-cause analysis</li><li>Red teaming or purple teaming experience</li></ul>
<h2 class="h5">Job description</h2>
<div class="t-break" data-jb-field="description">
<p><span>Job Purpose<br></span></p><br>
<p><span>As an Application Security Engineer at Luciq, you will help shape and build our application security program alongside the wider team. This is a hands-on, high-ownership role where you will work closely with product and development teams across the full software development lifecycle — reviewing designs before code is written, identifying risks as features take shape, and ensuring security is embedded into how we build and ship software, not bolted on after the fact. Our stack runs on Ruby on Rails, Go, and Python, deployed on AWS with Terraform managing infrastructure as code and Jenkins powering CI/CD. You will read and review code in these languages — not just rely on scanner output — and work with AWS security services (SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront) to provide visibility and protection across our infrastructure. The role spans web applications, APIs, our mobile SDK (iOS and Android), cloud, and CI/CD — partnering with engineers, PMs, Platform, and the Security team to make the secure path the default path. This role can be filled at mid-level with a clear growth path to senior-level as you grow into shaping our application security program, or at senior-level if you're already operating at that scope.</span></p><br>
<p><span>You will join a lean Security team, which entails stepping beyond core AppSec for incident triage, addressing customer security questionnaires, or supporting cross-functional cloud and compliance reviews. We value this variety as a core facet of the role; if you are seeking hyper-specialized work restricted strictly to application security, this may not be the right fit.</span></p><br> <p><span>Job Responsibilities</span></p><br>
<ul>
<li><span>Secure Design & Code Review</span></li>
</ul>
<ul>
<li>
<ul>
<li><span>Run and lead threat modeling sessions with product and engineering teams during feature design. This is a hands-on role with expectations to deliver fixes in the product as needed while enabling other engineers.</span></li>
<li><span>Conduct security code reviews and architecture reviews across web applications, APIs, and services in Ruby, Go, and Python</span></li>
<li><span>Leverage AI and make sure that we enable engineers to adhere to security acceptance criteria. Provide guidance to engineers on secure design as we iterate and build the product.</span></li>
</ul>
</li>
</ul>
<ul>
<li><span>Vulnerability Management</span></li>
</ul>
<ul>
<li>
<ul>
<li><span>Validate, triage, and drive remediation of vulnerabilities — partner with engineering teams across the full lifecycle from discovery through SLA support</span></li>
<li><span>Coordinate with engineering teams on fix verification and root-cause prevention</span></li>
</ul>
</li>
</ul>
<ul>
<li><span>Security Automation in CI/CD</span></li>
</ul>
<ul>
<li>
<ul>
<li><span>Build and maintain automated security testing in CI/CD — SAST, SCA, secret scanning</span></li>
<li><span>Tune tooling for signal over noise; integrate findings into developer workflows</span></li>
<li><span>Operate secret-scanning and leaked-credential response workflows</span></li>
</ul>
</li>
</ul>
<ul>
<li><span>Cloud & Infrastructure Security</span></li>
</ul>
<ul>
<li>
<ul>
<li><span>Support cloud security reviews — IAM policies, network segmentation, container/Kubernetes configurations, and Terraform policy-as-code</span></li>
<li><span>Work with AWS security services (SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront) to maintain visibility and detection across our infrastructure</span></li>
</ul>
</li>
</ul>
<ul>
<li><span>Supply Chain & Build Security</span></li>
</ul>
<ul>
<li>
<ul>
<li><span>Own dependency risk via SCA, lockfiles, and pinning</span></li>
<li><span>Drive CI/CD pipeline hardening — build runners, OIDC-to-cloud, artifact signing, SBOM standards</span></li>
</ul>
</li>
</ul>
<ul>
<li><span>Cross-functional Security Enablement</span></li>
</ul>
<ul>
<li>
<ul>
<li><span>Develop secure coding guidelines and reusable patterns that make the secure path the default</span></li>
<li><span>Drive S-SDLC adoption across engineering teams</span></li>
<li><span>Review security posture of our mobile SDK across iOS and Android — data handling, transport security, local storage, IPC, encryption, third-party dependency risk, and SDK consumer-facing security defaults</span></li>
<li><span>Assess security risks in AI/LLM integrations — prompt injection, insecure output handling, trust boundaries in agentic architectures</span></li>
<li><span>Support compliance initiatives (SOC 2, ISO 27001) — translate control requirements into engineering practices and assist with audit evidence collection</span></li>
<li><span>Use AI tooling actively in your own workflow AI-assisted code review, threat modeling drafts, vulnerability research, and security artifact generation and help shape how the rest of engineering uses AI safely</span></li>
</ul>
</li>
</ul> <p><span>Job Requirements</span></p><br> <p><span>Must-Haves</span></p><br>
<ul>
<li><span>Experience</span><span>: 3-6 years in application security, or security engineering</span></li>
<li><span>Education</span><span>: Bachelor's degree in Computer Science, Information Security, or equivalent practical experience</span></li>
<li><span>Secure code review</span><span>in at least one of: Python, Ruby, Go — can read code and reason about vulnerabilities, not rely on scanner output</span></li>
<li><span>OWASP Top 10 (Web and API)</span><span>as root-cause patterns, not a memorized checklist — including SSRF, insecure deserialization, injection classes, and access-control flaws</span></li>
<li><span>Threat modeling</span><span>: practical experience with STRIDE and data flow diagrams; can lead a session with a product team and produce actionable output</span></li>
<li><span>Auth and identity</span><span>: working depth in session management, RBAC/ABAC models</span></li>
<li><span>CI/CD security automation</span><span>: hands-on experience integrating SAST, SCA, and secret scanning into pipelines and tuning for actionable signal</span></li>
<li><span>Proactive and ownership-driven</span><span>— does not wait to be told what to secure</span></li>
<li><span>Comfortable working</span><span>cross-functionally</span><span>with product engineers, platform engineers, and the wider team</span></li>
<li><span>Strong</span><span>analytical and problem-solving</span><span>abilities</span></li>
<li><span>Fluent in</span><span>English</span><span>, with strong written and verbal communication</span><br></li>
<li><span>Communication</span><span>: clear written and verbal communication can explain a vulnerability to an engineer, a PM, or a VP<br></span></li>
</ul>
<p><span>Strong Plus</span></p><br>
<p><span>We expect strong candidates to have</span><span>some</span><span>of these not all. The more, the better.</span></p><br>
<ul>
<li><span>Mobile SDK security</span><span>: OWASP Mobile Top 10 and MASVS/MASTG; Android (Kotlin) or iOS (Swift); experience with Frida, objection, or MobSF</span></li>
<li><span>AWS security service depth</span><span>: SecurityHub, Inspector, GuardDuty, CloudTrail, CloudFront beyond IAM</span></li>
<li><span>Container and Kubernetes</span><span>security fundamentals</span></li>
<li><span>Supply chain depth</span><span>: SLSA framework, SBOM</span><span>AI/LLM security</span><span>: prompt injection mitigations, OWASP LLM Top 10, securing agentic architectures and tool-use boundaries</span></li>
<li><span>Familiarity with</span><span>ISO 27001 or SOC 2</span><span>.<br></span></li>
</ul>
<p><span>Nice to Have</span></p><br>
<ul>
<li><span>Terraform and policy-as-code: tfsec, Checkov, OPA/Conftest</span></li>
<li><span>Experience building or bootstrapping a security program</span></li>
<li><span>Bug bounty participation, published CVEs, or documented security research</span></li>
<li><span>Hands-on certifications: OSCP, OSWE, eMAPT</span></li>
<li><span>Incident response experience — triage, containment, root-cause analysis</span></li>
<li><span>Red teaming or purple teaming experience</span></li>
</ul> </div>