Wikimedia Foundation | Lead Product Manager, Security | REMOTE (US + 18 countries) | Full-time
I lead the security and safety team for Wikipedia, at the Wikimedia Foundation. I’m hiring a product manager to lead our security roadmap and steer the priorities of our security engineering team.
It’s a high-pace, shipping-heavy time for the whole project right now, as we are dedicating ourselves to surviving all the ways AI is messing with us and the internet, and getting to the other side of it. I joined myself about a year ago, and have found it to be a great time and place to swing big and surprise people.
This is a PM role and PM background is certainly helpful, but it’s not strictly required (everyone has the first PM job at some point). A technical background and security expertise are a must for this role, so we’re also open to people in engineering roles, who have demonstrated PM-relevant skills and are interested in making a pivot.
Working for Wikimedia would make me actually consider moving back to the USA for the opportunity.(I'm in Japan for reference.) I previous contributed to Mediawiki and the extensions ecosystem for about a decade.
I‘ve been considering applying at WikiMedia for a while now, but [my country] is not in the listed countries. Is there a chance you‘ll expand this list in the future?
Ah, that is too bad. It's certainly always possible the countries list could expand in future, but it's not something I have insight into and unfortunately can't give you too much to go on.
The document distinguishes between enterprise-facing and public-facing systems. For enterprise-facing (government employees, contractors, etc.), it's talking about discontinuing use of TOTP. For public-facing systems, it doesn't impose any restrictions, since (as you're saying) the general public really needs options.
In those 5 years, HTTPS has gone from being the minority of traffic to being ~90% of the connections observed by most Chrome clients (scroll down a few graphs for the Chrome-observed one):
https://transparencyreport.google.com/https/overview
That doesn't mean that HTTP is banned, but given the magnitude of the change and the size of the web, I think it's fair to say that it's being deprecated.
More practically, anyone who wanted to build a product (or a government process) on intercepting or modifying people's unencrypted web traffic would find their dataset to be an order of magnitude smaller, and orders of magnitude less useful (since so much of the remaining HTTP traffic is in the long tail of small/older sites).
There's not federalism within states in a legal sense the way there is between states and the feds, but cities value their independence too and prefer to have their own infrastructure. I would expect the city, rather than the state, to be the reason they don't use a subdomain of the state's .gov domain.
CLAs are frowned upon by some, but they don't completely kill contribution from 3rd parties. I've signed plenty, and I've encountered plenty of projects that use them that continue to have a good community of outside unaffiliated contributors.
I wouldn't use the word "illegal" - it's a directive of OMB (the White House's management and budget office), not a law or a regulation or an executive order. The only true enforcers are OMB themselves.
But to answer your other question, as part of the Department of Commerce, a "CFO Act" agency, USPTO would not be exempt.
Thank you for clearing that up. Are you aware of what kind of consequences might be incurred at the expense of disobeying the OMB as a government entity?
Cloud Foundry doesn't have a problem injecting headers, as HTTP traffic is plaintext inside the system itself. It's once it starts traveling across the public internet that encryption is needed. This does make it harder for network edge caches and for middleboxes, but that's not totally a bad thing either.
I lead the security and safety team for Wikipedia, at the Wikimedia Foundation. I’m hiring a product manager to lead our security roadmap and steer the priorities of our security engineering team.
It’s a high-pace, shipping-heavy time for the whole project right now, as we are dedicating ourselves to surviving all the ways AI is messing with us and the internet, and getting to the other side of it. I joined myself about a year ago, and have found it to be a great time and place to swing big and surprise people.
This is a PM role and PM background is certainly helpful, but it’s not strictly required (everyone has the first PM job at some point). A technical background and security expertise are a must for this role, so we’re also open to people in engineering roles, who have demonstrated PM-relevant skills and are interested in making a pivot.
You can apply at https://job-boards.greenhouse.io/wikimedia/jobs/8140060?gh_s... - we don’t auto-filter based on AI or anything like that, I will personally see your resume.
reply