Security Engineer
Enregistrez cette offre et organisez votre recherche
Créez un compte gratuit pour enregistrer des offres d'emploi, créer des alertes et revenir à cette liste depuis votre tableau de bord.
En continuant, vous acceptez nos Conditions d’utilisation & Politique de confidentialité.
RealityFoundation is a non-profit, based in Brussels, Belgium, building the authenticity layerfor digital media.
We certify photos and videos at the moment of capture. The raw media and its metadataare hashed, signed, and anchored to a public blockchain before anything can touch them— so a media record can be proven authentic, not merely believed. Ourwork is open source, built on the C2PA standard, and runs on infrastructure Europecontrols.
We do this because the alternative is already arriving. Once synthetic media isindistinguishable from real media, everything unproven becomes deniable — insuranceclaims, court evidence, journalism, public accountability. Detection is a losing race:it will always be one model behind. Provenance at the origin is the only thing thatholds.
We are small, early, and public about our work. The people who join now decide what this becomes.
Must-have technical skills
- Strong foundations in applied cryptography: hashing, digital signatures, and public-key infrastructure
- Experience with threat modeling (STRIDE or equivalent), ideally for mobile-to-backend or mobile-to-blockchain systems
- Familiarity with GDPR-by-design and data minimization principles
- Knowledge of secure mobile environments (TEE, Secure Enclave, hardware-backed key storage)
- Experience conducting or supporting security audits of software systems
- Familiarity with zero-trust architecture principles is a plus
- Knowledge of C2PA or content credential standards is a plus
What you bring
- You are proactive and identify what can fail before it does
- You translate technical risk into clear language for non-technical stakeholders
- You are comfortable owning security decisions in a lean engineering environment
- You believe privacy and user sovereignty are non-negotiable design requirements
What you’ll do
- Define and own the cryptographic architecture of the RealityCheck pipeline
- Conduct end-to-end threat modeling across device, app, backend, blockchain, and storage layers
- Ensure GDPR compliance is embedded in system design from day one
- Review code for security vulnerabilities and support remediation with engineering
- Document security assumptions transparently in support of open-source trust
- Advise on blockchain choices and smart contract security where relevant
What we offer
- €38,000 – €55,000 / year gross on a Belgian permanent contract. We publish the band because you should not have to negotiate blind
- Brussels or remote Our base is Brussels, Belgium, and we can hire anywhere in the EU. We also bring the team together 2 times a year, on us
- Tools and learning budget A real budget for equipment, training, and relevant conferences
- Your work is public What you build here stays in the open, under your name
- Growth, impact, and ownership You can grow into the role and shape how it evolves, while working with a small dynamic team on a mission that protects trust in digital media and lets you be part of meaningful change
The selection process
Four steps, about three weeks. You will know where you stand at every one of them.
- Application review A person reads it — no model screens you out.You hear back within 7 working days either way
- Intro call (30 minutes) With the founding team. What you want,what we're building, whether the shapes match
- Working session In a threat-modeling session, we walk through our device-to-certificate flow and you identify attack surfaces, priorities, and first controls
- Team call (45 minutes) With the people you'd actually workwith, then references
Decision within 7 working days of the last step. If it's a no, we tellyou why. We know that's rare. It shouldn't be.