Platform Integrity Engineer
Springfield, Hampden County, Massachusetts, 01119, USA
Listed on 2026-10-07
-
Software Development
Backend Developer, DevOps, Software Engineer
Open Review is a nonprofit that builds and operates open peer review infrastructure for the world's leading AI and machine learning conferences — NeurIPS, ICLR, ICML, CVPR, AAAI, and more than 4,700 other venues. Our platform manages submissions, reviews, and decisions for hundreds of thousands of researchers worldwide, built on an intentionally open API. Author and reviewer anonymity is the foundation of trust in peer review;
protecting it is central to our mission of advancing science through open, rigorous, and fair evaluation.
The ideal candidate:
The ideal candidate has a passion for building the application security function of a mission-driven peer review platform used by the global research community. They are excited about wearing multiple hats and introducing security review processes into a small engineering team without slowing delivery to a halt. They have built production APIs themselves — a builder, not only an auditor — in addition to their application security experience, and they treat AI tooling as a daily working method for finding vulnerabilities before anyone else does.
This is a remote position which can be based anywhere in the United States.
Job Summary:
The Platform Integrity Engineer is Open Review's application security specialist: the role ensures that every change to the Open Review API enforces the correct permissions on data access, protecting the anonymity guarantees at the heart of the peer review process. Open Review operates an intentionally open API serving the global research community; its most sensitive asset is not the data itself but the authorization rules that determine who may see what, and when.
This role is the platform's dedicated security function: it reviews every authorization-relevant change before it ships, builds the automated testing that catches permission regressions, audits the platform's anonymity guarantees, safeguards the venue workflow configurations that define who may read what at each stage of peer review and operates the vulnerability disclosure and incident process.
Effective review requires a working command of the API's data model and permission semantics, and building that depth is the first priority of the role; as it deepens, the role is expected to also implement new API features. The role works in close partnership with the Engineering Lead, who implements the API features, and with the Cloud Infrastructure Engineer, with whom it shares security monitoring.
AI tooling — LLM-based code analysis, adversarial test generation, AI-assisted penetration testing — is a core working method across all of these responsibilities. The role's scope covers all Open Review repositories — the API, the web client, the Python client library, and supporting services — with the API as the primary focus, since that is where permission enforcement lives; fixes routinely require companion changes across repositories, and the role owns the security outcome across all of them.
Duties/Responsibilities:
1. Security Review & Secure Development
Serve as the required security reviewer, across all Open Review repositories and with the API as first priority, for every change touching authorization-relevant paths — permission evaluation, query filtering, authentication, server-side automation, and file handling — at both the design stage and code review, with primary focus on authorization logic, object-level permission checks, and the protection of anonymous identities; apply AI-assisted code analysis to every pull request in scope.
Define and maintain the trigger list for what requires security review, so that routine changes are not blocked.
For the authorization architecture, the edit validation and schema pipeline, and input handling at the data…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).