Open role · Publisher operations

Listing Reviewer

About forty flagged releases a week, and a verdict on each one that a publisher can act on without writing back.

Publisher operations Mid Remote — UTC+0 to UTC+3
The job

When the scanner flags a release, a person decides. You would read the finding, the declared scope and the code that produced both, and reach one of three verdicts: it ships, it ships with the scope corrected, or it does not ship and here is exactly why. Roughly forty a week, plus the security reports that arrive with a listing already frozen and a four-hour clock running. It is careful reading rather than paperwork, and the quality of this catalogue depends more on this queue than on anything else we do.


Your first six months

Three things that are true by then

Not a list of duties. These are the outcomes we would judge the hire on, and they are the ones we would expect you to hold us to if they turn out to be impossible for reasons nobody mentioned in an interview.

1
Reviewing unsupervised
Inside six weeks, with your verdicts agreeing with a second reader at or above the team average.
2
A rule with your name on it
You have written up the findings that keep recurring, and at least one of them has become a scanner rule that stops reaching you at all.
3
You own a category
The reviewer everybody asks about database servers, or about anything that touches a credential.

The work

What you would actually work on

Flagged releases

The diff, the manifest, and the gap between the two. Most of the queue is one of about nine shapes, and the interesting part is the tenth.

Tool descriptions

The best part of the queue. Text written to be obeyed by a model, and occasionally written to be obeyed against the buyer’s interest.

Writing the verdict

It goes to the publisher unedited, so it has to be specific enough to act on and short enough to be read at five in the afternoon.

The four-hour clock

Security reports, alongside whoever is on the rota that week. The listing is already frozen when you open it.

Telling the scanner team what is wasting your week

You are the only person who can, and it is treated as data rather than as a complaint.


Fit

What we are looking for, and what we are not

The right-hand column is not a formality. Each line is something a candidate has apologised for in an interview for this role, and none of it has ever decided one.

We are looking for
  • You can read Python and TypeScript well enough to follow where an argument goes. You do not have to be able to write either.
  • You are unhurried in the right places. Forty a week is a real rate, and the wrong way to hit it is to skim the tenth shape.
  • You write clearly under mild time pressure.
  • You are comfortable saying “I am not sure” and escalating. That is the entire reason the second read exists.
We are not asking for
  • A security background. Most of this team came from support, QA or engineering-adjacent work.
  • A degree in anything.
  • Odd hours. The four-hour clock is covered by a rota, not by everybody being available.

Interviews

The loop for this role

Four conversations, 3 h 15 m of them in total, scheduled inside your working hours rather than ours. Two to three weeks end to end if diaries cooperate. What we do not do is on the openings page and applies to every role here.

1
Intro call 30 min
With the publisher operations lead. What you have read closely, and what you do when you are unsure.
2
Review session 90 min, paid
Five real cases. Your verdicts in writing, in the form they would go to the publisher.
3
The team 45 min
Two reviewers, one of whom will disagree with one of your verdicts on purpose.
4
Close 30 min
Back with the lead: the offer, and your questions about the first six weeks.

Applying

How to apply

Four fields. No cover letter, no portal account, no form that asks you to retype a CV it has already parsed. If the last field is the only one you fill in properly, that is the one we read first.

Apply
What happens next

This lands in hiring/pubops-reviewer and is read by the publisher operations lead — not by a screen, not by a keyword filter and not by anyone outside the team you would join. A reply either way inside 5 working days, and a no that says which part it was.