Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Careers

    Careers FAQ

    Everything candidates ask us: how to apply, how the interview process runs, what we pay for, and what the work is actually like day to day.

    Back to careers

    Applying

    What to send, how we read it, and what happens to your application afterwards.

    How do I apply?
    Use the application form on this site. Pick the role, attach your resume as a PDF or Word document, add links to anything that shows your work, and write a few honest paragraphs about why the role fits. If you would rather email, careers@bluegoatcyber.com works too, with the role in the subject line.
    What makes an application stand out?
    Specifics. Name the devices, submissions, engagements, or projects you actually worked on and what you personally did on them. A short note that shows you understand what this role involves beats a long formal cover letter every time. Clear writing matters here because writing is a core part of all three roles.
    Do you want a cover letter?
    Not a formal one. The note field on the application form is enough. Three or four paragraphs in your own voice tell us more than a page of templated language.
    I do not see a role that fits. Can I still apply?
    Yes. Choose the open application option on the form and tell us what you do best and the kind of work you want. We keep applications on file and open roles as client demand grows, so a strong open application often gets picked up months later.
    Can I reapply if I was turned down before?
    Yes. Roles change, and so does experience. If something material has changed since last time, say what it is in your note.

    The interview process and timeline

    Six steps, no take-home projects, and roughly three to four weeks start to finish.

    What are the steps?
    Application review, a 30-minute intro conversation, a 60 to 90 minute working conversation with the team you would join, a career walkthrough, a final conversation with leadership plus reference calls, then an offer. That is the whole process. We do not add surprise rounds.
    How long does it take?
    We review applications within about five business days and usually get from first conversation to decision in two to three weeks. Total time from applying to an offer is typically three to four weeks, faster when schedules line up.
    What is the career walkthrough?
    We go through your jobs in order, oldest first, and ask the same five questions about each one: what you were hired to do, what you are proud of, what went badly, who you reported to, and why you left. Nothing is a trick question. We are looking at the pattern across your career rather than judging any single job, and it gives you room to explain the parts a resume flattens.
    Do you give take-home projects?
    No. We do not ask candidates to do unpaid work. The working conversation covers the same ground live: a device you would threat model, a document you would restructure, a project you would rescue. Talking through your reasoning tells us more than a graded exercise. For some roles we will put a short, invented sample in front of you during that conversation and talk through what you notice. It takes about fifteen minutes and you never take it home.
    How should I prepare?
    Read the role page and skim a couple of our guides so you know the depth we work at. Be ready to walk through one piece of work end to end, including what went wrong and what you did about it. Bring questions; the intro call is as much yours as ours.
    When do you check references?
    Late in the process, and never without telling you first. We say it out loud at the very first call: we will ask you to arrange short conversations with your former managers, and we ask them the same questions we asked you. You set the calls up, so nobody is contacted behind your back.
    Will I hear back if the answer is no?
    We reply to everyone we speak with. For applications we do not move forward, if you have not heard from us within two weeks the answer is no for now, and we keep your application on file for future openings.

    Pay, benefits, and equipment

    What the package looks like, and how we talk about money.

    What does compensation look like?
    Competitive and commensurate with experience. We discuss specific numbers in the first conversation rather than posting a wide range, and we do not lowball people we want to hire.
    How often is payroll?
    Every two weeks by direct deposit.
    What benefits do you offer?
    Health, dental, and vision coverage, a 401(k), an educational allowance for training and credentials, paid time off, and flexible scheduling around team and client commitments. Pay runs every two weeks.
    What equipment do you provide?
    These are bring-your-own-device roles. You work on your own laptop and setup, and we supply the project-specific test hardware and lab gear device work requires.
    Do you pay for certifications and conferences?
    Yes. Employees have an educational allowance covering training and certifications relevant to your track, and we fund lab equipment when a project needs it, conference and research time, and bylines on what we publish.

    What the work is really like

    An honest description of the day to day, including the parts people find hard.

    What does a normal week look like?
    Deep focused work on a small number of client engagements, punctuated by scoping, kickoff, and debrief calls. Most days are a mix of hands-on work and writing it up. There is no standing meeting culture and nobody watches your calendar; we judge outcomes, not hours visible online.
    How much of the work is manual versus automated?
    Tooling handles discovery, scanning, SBOM generation, and known-CVE triage. The majority of every engagement is manual, because automation cannot find business logic flaws, authorization bypasses, clinical workflow abuse, or chained exploits. If you want to run a scanner and ship the report, this is the wrong place.
    How much writing is involved?
    More than most people expect, in every role. Our deliverables are read by regulators and reviewers, so clear, structured, technically accurate writing is a core skill here rather than something handed off to someone else.
    What is hard about working here?
    Ownership is real. You hold your deliverables, dates, and client relationships, and nobody chases you for status. The regulatory context is unforgiving of hand-waving, so you have to be comfortable saying what you do not know and then going and finding out. Client timelines occasionally compress and the work still has to be right.
    Do I need medical device experience?
    Not always. We care most about depth in your own discipline plus the ability to learn the regulatory context quickly. The Regulatory Affairs Technical Writer role does ask for medical device industry experience or education in regulatory affairs or cybersecurity.
    What does success look like in the first 90 days?
    Each role page has a 30, 60, and 90 day breakdown. Broadly: learn our operating system and the regulatory context in the first month, carry real client work with support in the second, and own your engagements end to end by the third.

    Working here

    Location, travel, employment status, and how we use AI.

    Where can I work from?
    All of our roles are remote within the United States. We cannot sponsor visas or hire outside the US at this time. The Project Manager role asks for overlap with 9 to 5 Eastern; the other roles are flexible as long as you make team and client meetings.
    Is there travel?
    It depends on the role. The Penetration Tester role can reach up to 40 percent travel for onsite device testing. Business Development travels regularly to medtech events. Sales Engineer and Social Media Manager travel occasionally. Regulatory Affairs Technical Writer and Project Manager are minimal.
    Are these full-time roles?
    Yes. Every open role is a full-time position with benefits, paid every two weeks.
    What is your policy on AI tools?
    We use AI every day and we want you to. It is good at research, first drafts, summarizing public documents, writing scripts, and getting you unstuck, and using it is not cheating here. Use the company accounts we give you: we run enterprise accounts on ChatGPT and Claude configured so your inputs are not used to train anyone's model and nothing is retained. A personal login, a free account, a browser extension, or a tool you found last week is not an approved place for work. Client material never leaves those accounts, meaning device firmware, source code, submission documents, findings, vulnerability details, and client names, and if you are unsure whether something counts, assume it does and ask. You own what you send out, not the model: AI gets regulatory citations, recognition numbers, standard clause references, and test conclusions wrong in ways that read perfectly well, so check every one against the source before it reaches a client or a submission. Never let it invent evidence, because a finding we did not observe, a test we did not run, and a statistic with no source are the three things that end careers in this industry, and a confident paragraph from a model is exactly how they get in. Tell us when it helped. We would rather hear what worked than pretend the drafts wrote themselves.
    How big is the team, and who would I work with?
    We are a small, senior, distributed team, which is why ownership matters so much. You would work directly with the leadership named on our team page rather than through layers of management.

    The process at a glance

    Five steps, typically three to four weeks from application to offer.

    1. 1

      Apply

      Fill out the application form on this site with your resume, links to your work, and a short note about why the role fits. We read every one.

      Reviewed within 5 business days

    2. 2

      Intro conversation

      A 30-minute call about your background, what you want to work on, and how we operate. Bring questions.

      About 30 minutes

    3. 3

      Working conversation

      A deeper session with the team you would join. Expect to talk through real problems: a device you would threat model, a document you would restructure, a project you would rescue.

      60 to 90 minutes

    4. 4

      Career walkthrough

      We go through your jobs in order, oldest first, with the same questions each time: what you were hired to do, what went well, what went badly, who you reported to, and why you left. It is the longest conversation in the process and the most useful one. We will also ask you to arrange short calls with your former managers, and we will ask them the same questions we asked you.

      60 to 90 minutes

    5. 5

      Final conversation and references

      A call with leadership on fit, expectations, and compensation, plus the reference calls you arranged.

      About 45 minutes

    6. 6

      Offer

      We move quickly once we decide. Start dates are flexible for the right person.

      Usually within a week of the final call

    Still have a question?

    Ask it before you apply. We would rather answer it than have you guess.

    Not looking for a role?

    Need help with a device submission instead?

    Our team supports medical device manufacturers through premarket cybersecurity, threat modeling, and penetration testing.