Careers

Work at SubRosa

We have no open roles at the moment. That changes without much notice, and we would rather hear from good people early than advertise late.

Open roles

Nothing open right now

When a role opens it is listed here first. If you would rather not wait, tell us what you work on and we will keep it on file.

Disciplines

Where we usually hire

01

Offensive security

Penetration testing across network, web, cloud, wireless and physical, plus red team work. OSCP, GPEN, GXPN or equivalent evidence of hands-on capability.

02

Security operations

Detection engineering and analysis in a managed SOC. SIEM and EDR depth matters more than the specific vendor on your CV.

03

Incident response

Containment, forensics and recovery under time pressure, and the readiness work that happens before any of it: playbooks, tabletops, retainers.

04

Governance, risk and compliance

Assessments against NIST, HIPAA, HITRUST and SOC 2, third-party assurance, and virtual CISO engagements.

The work

Small team, real ownership

We are deliberately small and work across several continents and time zones. That means owning engagements rather than a narrow slice of one, and it means the work is client-facing. You will explain your findings to the people who have to act on them.

Speculative applications

Get in touch anyway

Send us what you have worked on and what you want to work on next. We read everything that arrives and keep good applications on file rather than starting from scratch each time a role opens.

SubRosa is an equal opportunity employer. We assess applicants on capability and judgement, and we will make reasonable adjustments to our process on request.