Full-Stack Engineers (Cybersecurity): Feedback on CI/CD Workflows
Remote — United States
Special Referral gives your application an enhanced referral route, helping it stand out and potentially improving your chances of being considered.
About the role
What We're Researching: We're running a paid study on the intersection of full-stack development and cybersecurity practices. Our goal is to understand how engineering teams integrate vulnerability verification directly into their CI/CD pipelines. This feedback will help shape future developer tools designed to streamline secure application feature ownership.
How It Works: During a remote video session, you will walk us through a recent project where you owned both application development and vulnerability verification. You will be asked to describe your current CI/CD setup, highlighting the specific steps you take to ensure secure deployments. We will then show you a few conceptual workflows and ask for your candid feedback on their practicality. The conversation flows as a standard technical interview, focusing on your day-to-day security routines.
Who This Is For: We welcome full-stack engineers who have a dedicated focus or strong background in cybersecurity. You should have hands-on experience managing application features, configuring CI/CD pipelines, and verifying vulnerabilities prior to production. We also welcome DevSecOps engineers and security-focused backend developers who handle similar deployment pipelines.
Scope of Work
- Walk us through your process for integrating vulnerability verification into CI/CD pipelines
- Discuss how you balance application feature development with rigorous security requirements
- React to new concepts for managing and deploying secure full-stack applications
- Describe a recent challenge you faced while securing a production pipeline
What you’ll bring
- Professional experience as a full-stack engineer, DevSecOps engineer, or similar role
- Strong background in cybersecurity and application security practices
- Hands-on experience configuring and maintaining CI/CD pipelines
- Comfortable discussing vulnerability verification and secure deployment workflows
- Located in the United States and 18+ years old
- Fluent in English
- Has found and reported vulnerabilities (bug bounty, red team, research) or reviewed raw scanner/pen test output to identify genuine findings
- Has personally built and run in production a web frontend and a backend service
- Has built a GitHub App/Action for external organizations or built a team's CI and release pipeline from scratch
- Has deployed machine learning models to a serving platform
- Able to work United States business hours, own bug fixes end-to-end, and turn customer-reported issues around within days
Benefits
Not provided in the source listing.
Schedule and availability
Must be able to work United States business hours. The supplied screening description estimates about 15 minutes.
Contract & Payment Terms
- You will be engaged as an independent contractor.
- This is a fully remote opportunity that can be completed on your own schedule.
- Opportunities can be extended, shortened, or concluded early depending on needs and performance.
- Your participation will not involve access to confidential or proprietary information from any employer, client, or institution.
- Payments are processed weekly based on services rendered.
- We are unable to support H1-B or STEM OPT candidates at this time.
Where you can work
Location eligibility: United States. Terac cannot support H1-B or STEM OPT candidates at this time.
This role is open to people based in: United States.
Remote does not always mean work from any country. Always check the employer’s location and working-hour requirements.

