Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Cyber Security Engineer / Information Systems Security Engineer (ISSE) at OpenTeams

Leads cybersecurity architecture, RMF activities, and compliance for government systems while designing supply chain security controls and integrating security into CI/CD pipelines.

Senior Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

Who We Are

We exist to unlock human potential.

Too often, AI drains it—drains budgets, drains energy resources, drains ownership of data. OpenTeams was founded to change that. We build AI that empowers. Our models are energy-efficient, cost-effective, and fully yours.

Our ethos is open source. That means freedom, trust, and accountability are built into every line of code. We reinvest 3% of our profits back into the open-source community, because we believe tech is most powerful when it serves everyone.

At our core, we value freedom, teamwork, accountability, and uncompromising quality. If you want to challenge the status quo, and shape tools that set people free, OpenTeams is the place to do it.

Location: Remote (US) with travel to customer sites as required (Washington Metro Area preferred)

Employment Type: Full-time

Clearance: Active TS/SCI required

Role Summary

The Cyber Security Engineer / ISSE owns the security architecture and accreditation posture of the depot. This role leads RMF activities, embeds security controls into engineering workflows, and serves as the primary security interface with government assessors and authorizing officials.

Responsibilities

  • Lead RMF activities: control selection, implementation evidence, POA&M management, and ATO support
  • Design and implement supply chain security controls: SBOM generation, artifact signing, vulnerability scanning, and provenance attestation
  • Perform threat modeling and security reviews of depot architecture and workflows
  • Integrate security tooling into CI/CD pipelines and enforce policy gates
  • Support cross-domain and classified environment requirements, including secure transfer procedures
  • Interface with government ISSMs, assessors, and authorizing officials

Required Qualifications

  • Active TS/SCI clearance
  • Experience with Xacta, eMASS, or CSAM
  • 6+ years in cyber security or ISSE roles supporting DoD or IC systems
  • Hands-on experience with RMF, NIST 800-53, and eMASS or equivalent
  • Experience with DevSecOps tooling: container scanning, SAST/DAST, signing, and policy enforcement
  • IAT/IAM Level II or III certification per DoD 8140 (for example Security+, CISSP, or CISM)

Preferred Qualifications

  • Experience securing AI/ML systems or software supply chains at scale
  • Familiarity with cATO approaches and continuous monitoring
  • Experience with IL5/IL6 or cross-domain solutions

Grow With Us

At OpenTeams, growth isn’t just about the company—it’s about you.

We believe the best careers are built at the edge of your potential. That is where new tools, ideas, and technologies change the world. Here, you’ll work alongside pioneers of AI, solving problems that matter: making AI more transparent, more ethical, and more empowering. As your skills grow, our career framework provides a pathway and recognition of that increased impact.

Opportunities aren’t limited by geography. You’ll collaborate with global experts, contribute to open source projects that power the world’s technology, and stretch your skills daily.  That global perspective and diversity makes our solution more universal and robust.  We are committed to continuing to celebrate diversity on our team.

Supported people are successful people.  We offer 100% employer paid medical premiums for employees and self-managed PTO with a minimum time off requirement, so that our teams are able to do their best work.

We invest  in curiosity, creativity, and ownership. That means you’ll be trusted to boldly innovate, supported to learn fast, and celebrated for successful collaboration.

Commitment to diversity, equity, inclusion, and belonging

OpenTeams understands that valuing diverse creative practices and forms of knowledge is crucial to and enriches the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, disabled people, persons of all sexual orientations, gender identities and expressions.

We are an equal opportunity employer - all qualified applicants will receive equal consideration for recruitment, interviews, employment, training, compensation, promotion, and related activities. We do not discriminate based on race, religion, gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. OpenTeams will not tolerate discrimination or harassment based on these characteristics or any other unlawful behavior, conduct, or purpose.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Design and harden cloud infrastructure, identity systems, and security automation pipelines while evaluating AI-assisted tools and responding to security incidents.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Designs and hardens cloud infrastructure, builds security automation pipelines, and secures AI-assisted tooling across AWS and identity systems.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Designs and hardens cloud infrastructure, builds security automation pipelines, and secures AI-assisted tooling across AWS, identity systems, and internal platforms.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Compliance and Security Lead at ada CX

Leads Ada's security compliance program end-to-end, managing audits, vendor risk, vulnerability management, and serving as the internal/external authority on compliance and security posture.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure,  Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Security and Infrastructure Engineer at ada CX

Owns cloud and platform security end-to-end across AWS and Azure, builds automated security capabilities, and sets security standards for an AI customer service platform.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Engineering at Ada

As an Ada engineer, you’ll have the autonomy to make a huge impact and the opportunity to work alongside talented peers who challenge and inspire you. We move fast, take ownership, and always strive to improve, both as individuals and as a team. As a Security Infrastructure Engineer on Ada’s Security Operations team, your work will have a fundamental impact on Ada’s growth: our customers put an AI agent in front of their customers, and it has to be trustworthy by construction.

Our Role

We are looking for a Security Infrastructure Engineer to own cloud and platform security end to end, architecture, detection and response, and platform enablement across AWS and Azure, including the security of our agentic AI platform. This role is not focused on ticket-driven security work: you will replace manual security work with platform capabilities, build guardrails into the product itself, and set the security bar across Product Development. You will operate with a high degree of autonomy, set technical direction that other senior engineers follow, mentor security engineers, and act as the senior technical counterpart to engineering and security leadership translating risk and compliance requirements into concrete engineering solutions.

About You

  • 8+ years of experience in cloud, infrastructure, or security engineering roles, including experience setting technical direction across multiple teams, not just executing within one.
  • Deep hands-on experience with at least one major cloud provider, preferably AWS; Azure experience is a plus.
  • Strong experience designing and securing cloud IAM, networking, secrets management, and distributed systems at scale.
  • Extensive experience with infrastructure as code (Terraform or CloudFormation) and policy as code; you default to automation and preventative controls over manual review.
  • Experience building or operating detection and response systems including SIEM, CSPM/CIEM, and cloud security monitoring.
  • Experience with or a strong point of view on securing LLM and agentic AI systems: guardrails, safe tool use, and failure isolation.
  • A track record of turning recurring security and infrastructure requests into self-serve tooling, retiring ticket queues rather than staffing them.
  • Proven ability to translate compliance and risk requirements into technical implementations.
  • Strong communicator who can influence architecture and engineering decisions across teams, and mentor senior engineers through design reviews and hands-on guidance.
  • Comfortable operating independently, owning long-term technical initiatives, and carrying a share of security-relevant on-call.

What You Will Do

Cloud Security Architecture & Engineering

  • Architect, design, and operate security technologies across cloud, network, identity, endpoint, and application layers in public, private, and hybrid environments.
  • Define cloud security reference architectures, threat models, and guardrails aligned with zero trust and least privilege principles.
  • Own the technical lifecycle of security tooling including cloud-native security services, SIEM, CSPM, CIEM, EDR, DLP, and vulnerability management platforms.

Agentic Platform Security

  • Build safety guardrails into the platform itself so failures like an agent bypassing a playbook safeguard cannot reach a customer.
  • Partner with the Reasoning Engine and Playbooks teams on agent behavior that is safe by construction.
  • Set the security bar inside Product Development: secure-coding standards, review practice, and threat modeling for new agentic features.

Detection, Response & Automation

  • Stand up security observability: detection, alerting, and response for the platform, wired into Datadog and Sentry alongside the wider observability push.
  • Engineer automated response and remediation workflows using cloud-native automation, SOAR, and infrastructure as code.
  • Lead cloud security incident investigations, carry a share of security-relevant on-call, and feed every incident back into tooling so it does not recur.

Self-Serve Security Enablement

  • Turn recurring security and infra requests (access provisioning, environment setup) into self-serve tooling — retire the ticket queue rather than staff it.
  • Embed security into CI/CD pipelines, platform tooling, and deployment workflows using policy as code and automated guardrails, so engineering teams ship faster without compromising security.

Governance, Risk & Compliance Enablement

  • Translate security and regulatory frameworks (NIST SP 800-53, PCI DSS, CIS Benchmarks, AWS Well-Architected) into enforceable technical controls.
  • Lead the engineering side of vendor and dependency security: reviews, least-privilege access, and cutting overlapping tools from the stack.
  • Support audits, risk assessments, and evidence collection with internal compliance and external assessors.

Technical Leadership

  • Serve as the subject matter expert for cloud and platform security and its relationship to Ada’s business-critical systems.
  • Mentor security and platform engineers through documentation, design reviews, and hands-on guidance.
  • Operate with high autonomy, making architectural decisions that shape long-term security posture and platform scalability.

Outcomes

  • Own secure-by-default infrastructure for the agentic platform across AWS and Azure: identity, secrets management, network boundaries, and access control.
  • Establish a secure-by-default cloud security architecture that scales with Ada’s growth, reducing risk through automation and preventative controls.
  • Close the guardrail gaps that could let unauthorized agent actions reach a customer.
  • Improve detection, response, and incident readiness across cloud environments.
  • Enable engineering teams to ship faster without compromising security, and raise the bar for security engineering maturity across the organization.
  • First 90 days: map the current attack surface and access model, ship one self-serve replacement for a high-volume manual security request, and close the guardrail gap that let unauthorized actions through.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Compliance and Security Lead at ada CX

Own Ada's security compliance program end-to-end, managing audits, vendor risk, vulnerability management, and serving as internal/external compliance authority for enterprise customers.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure,  Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Compliance and Security Lead at ada CX

Lead Ada's security compliance program end-to-end, managing audits, vendor risk, vulnerability management, and serving as internal/external compliance authority.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure,  Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Security and Infrastructure Engineer at ada CX

Designs and implements cloud security infrastructure, detection systems, and platform controls across AWS/Azure to secure Ada's AI customer service platform.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Engineering at Ada

As an Ada engineer, you’ll have the autonomy to make a huge impact and the opportunity to work alongside talented peers who challenge and inspire you. We move fast, take ownership, and always strive to improve, both as individuals and as a team. As a Security Infrastructure Engineer on Ada’s Security Operations team, your work will have a fundamental impact on Ada’s growth: our customers put an AI agent in front of their customers, and it has to be trustworthy by construction.

Our Role

We are looking for a Security Infrastructure Engineer to own cloud and platform security end to end, architecture, detection and response, and platform enablement across AWS and Azure, including the security of our agentic AI platform. This role is not focused on ticket-driven security work: you will replace manual security work with platform capabilities, build guardrails into the product itself, and set the security bar across Product Development. You will operate with a high degree of autonomy, set technical direction that other senior engineers follow, mentor security engineers, and act as the senior technical counterpart to engineering and security leadership translating risk and compliance requirements into concrete engineering solutions.

About You

  • 8+ years of experience in cloud, infrastructure, or security engineering roles, including experience setting technical direction across multiple teams, not just executing within one.
  • Deep hands-on experience with at least one major cloud provider, preferably AWS; Azure experience is a plus.
  • Strong experience designing and securing cloud IAM, networking, secrets management, and distributed systems at scale.
  • Extensive experience with infrastructure as code (Terraform or CloudFormation) and policy as code; you default to automation and preventative controls over manual review.
  • Experience building or operating detection and response systems including SIEM, CSPM/CIEM, and cloud security monitoring.
  • Experience with or a strong point of view on securing LLM and agentic AI systems: guardrails, safe tool use, and failure isolation.
  • A track record of turning recurring security and infrastructure requests into self-serve tooling, retiring ticket queues rather than staffing them.
  • Proven ability to translate compliance and risk requirements into technical implementations.
  • Strong communicator who can influence architecture and engineering decisions across teams, and mentor senior engineers through design reviews and hands-on guidance.
  • Comfortable operating independently, owning long-term technical initiatives, and carrying a share of security-relevant on-call.

What You Will Do

Cloud Security Architecture & Engineering

  • Architect, design, and operate security technologies across cloud, network, identity, endpoint, and application layers in public, private, and hybrid environments.
  • Define cloud security reference architectures, threat models, and guardrails aligned with zero trust and least privilege principles.
  • Own the technical lifecycle of security tooling including cloud-native security services, SIEM, CSPM, CIEM, EDR, DLP, and vulnerability management platforms.

Agentic Platform Security

  • Build safety guardrails into the platform itself so failures like an agent bypassing a playbook safeguard cannot reach a customer.
  • Partner with the Reasoning Engine and Playbooks teams on agent behavior that is safe by construction.
  • Set the security bar inside Product Development: secure-coding standards, review practice, and threat modeling for new agentic features.

Detection, Response & Automation

  • Stand up security observability: detection, alerting, and response for the platform, wired into Datadog and Sentry alongside the wider observability push.
  • Engineer automated response and remediation workflows using cloud-native automation, SOAR, and infrastructure as code.
  • Lead cloud security incident investigations, carry a share of security-relevant on-call, and feed every incident back into tooling so it does not recur.

Self-Serve Security Enablement

  • Turn recurring security and infra requests (access provisioning, environment setup) into self-serve tooling — retire the ticket queue rather than staff it.
  • Embed security into CI/CD pipelines, platform tooling, and deployment workflows using policy as code and automated guardrails, so engineering teams ship faster without compromising security.

Governance, Risk & Compliance Enablement

  • Translate security and regulatory frameworks (NIST SP 800-53, PCI DSS, CIS Benchmarks, AWS Well-Architected) into enforceable technical controls.
  • Lead the engineering side of vendor and dependency security: reviews, least-privilege access, and cutting overlapping tools from the stack.
  • Support audits, risk assessments, and evidence collection with internal compliance and external assessors.

Technical Leadership

  • Serve as the subject matter expert for cloud and platform security and its relationship to Ada’s business-critical systems.
  • Mentor security and platform engineers through documentation, design reviews, and hands-on guidance.
  • Operate with high autonomy, making architectural decisions that shape long-term security posture and platform scalability.

Outcomes

  • Own secure-by-default infrastructure for the agentic platform across AWS and Azure: identity, secrets management, network boundaries, and access control.
  • Establish a secure-by-default cloud security architecture that scales with Ada’s growth, reducing risk through automation and preventative controls.
  • Close the guardrail gaps that could let unauthorized agent actions reach a customer.
  • Improve detection, response, and incident readiness across cloud environments.
  • Enable engineering teams to ship faster without compromising security, and raise the bar for security engineering maturity across the organization.
  • First 90 days: map the current attack surface and access model, ship one self-serve replacement for a high-volume manual security request, and close the guardrail gap that let unauthorized actions through.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security DevSecOps Lead

Leads DevSecOps initiatives, integrating security practices into development and operations workflows for federal technology solutions.

Lead Posted 3 days ago Himalayas
What this role involves
About Concept Plus Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies.
Read the full description
Security Cyber Ark Integration Engineer

Design and implement CyberArk integrations with enterprise applications, identity platforms, and cloud services to strengthen security infrastructure.

Mid Posted 3 days ago Himalayas
What this role involves
CyberArk Integration EngineerExperience: 6–10 Years Job SummaryDesign and implement integrations between CyberArk and enterprise applications, identity platforms, cloud services, and DevSecOps tools.
Read the full description
Security Application Security Engineer II at Abnormal AI

Application security engineer secures AI-powered cloud systems by leading threat modeling, building security tooling, designing automated testing, and coaching developers on secure practices.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

About the Role

Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You’ll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You’ll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering.

What you will do

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.

Must Haves

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.

Nice to Have

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

#LI-PP1

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.

In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:

$130,100—$187,000 USD

AI and our hiring process

Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Read the full description
Security Senior Information System Security Officer (Senior ISSO) (R-00185)

Senior ISSO oversees information security policies, compliance, risk management, and security posture across organizational systems and infrastructure.

Senior Posted 4 days ago Himalayas
What this role involves
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes.
Read the full description
Security Field CISO at Sprinto

Field CISO builds market-facing security and compliance thought leadership, speaking engagements, and practitioner credibility for a compliance automation platform.

Lead Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers.

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable trust posture without draining operational bandwidth and resources on repetitive tasks.

Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we’ve raised $31.8M in funding to fuel our mission. Trusted by over 4,000 organizations across 75 countries, Sprinto helps organizations stay audit-ready, manage real-time risks, and scale fearlessly. With 300+ native integrations and AI-driven automation, Sprinto supports 200+ global security standards natively, including SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and more. Sprinto’s extensible architecture enables organizations to build and support an infinite number of custom integrations and frameworks.

Founded in 2020 by second-time founders Girish Redekar and Raghuveer Kancherla, Sprinto powers compliance for organizations like Whatfix, Encora, Anaconda, Whatnot, Ultrahuman, WeWork, Everstage, AI Foundation, HackerRank, and many more.

Life as a Sprinter -

Nobody succeeds at Sprinto by staying in their lane.

We are organized around problems, not job titles. Sprinters take ownership beyond their role, solve hard problems, and care deeply about the impact they create. If something can be improved, fixed, or built, we don’t wait for permission; we step in.

Being remote means we rely less on proximity and more on trust. We write things down, communicate openly, and move quickly because great teams aren’t built by sitting together, they’re built by pulling in the same direction.

We believe progress beats perfection, feedback is a gift, and doing the right thing matters, even when nobody is watching.

And while we move with urgency, we never move alone.

The mission -

This is Sprinto’s first dedicated Field CISO hire in the US. You are not walking into a built function. You are building the market-facing security and compliance voice from scratch - with full access to the founders, the GTM team, and the product roadmap.

This is a marketing and thought leadership role. You make every Sprinto channel more credible, more attended, and more influential - because the voice behind it is a practitioner, not a vendor. Every roundtable you run, every stage you speak from, every webinar you anchor - you own the prospect experience.

The scope runs from the first piece of content to the narratives & depth in all Sprinto content.

Where you’ll leave your mark?

  • Take the Autonomous Trust thesis to market - together - Sprinto has built the product and defined the category. You bring the platform to carry the thesis publicly - at events, in content, on stage, in every conversation that shapes how enterprise CISOs think about compliance. We build the narrative. You carry it into rooms we cannot reach alone.
  • Show up at the industry’s biggest stages as Sprinto’s practitioner voice - When we walk into RSA, ISACA, or a regional CISO summit, we walk in as participants in the conversation - not vendors looking for a slot. Your point of view on stage is how we earn that position. Together we make sure Sprinto is never just a name on a booth.
  • Build the rooms where CISOs talk openly - Webinars and roundtables only work when the right person anchors them. You bring the practitioner credibility that makes a CISO clear their calendar. We bring the platform and the agenda. Together we create conversations where CISOs share what they actually need - and the pipeline follows naturally.
  • Put a practitioner’s fingerprint on everything we publish - Our content team has the reach and the production. You have the voice that turns good content into content CISOs forward. We write together, you shape the thinking, and you push it through channels we do not own - your newsletter, your LinkedIn, your podcast. The audience you bring is the distribution we cannot manufacture from scratch.
  • Deepen the advisory board into a real community - We have built relationships with some of the most respected security leaders in the market. You deepen them - not as a coordinator, but as a peer. The more substantively you engage, the more the advisory board compounds into events, content, and deals none of us could run alone.
  • Walk into deals at different stages where needed - Early in a prospect conversation, you help them see what their compliance program could look like when the detection-remediation gap closes. You are not pitching - you are workshopping. You sit with their reality, map it against the Autonomous Trust model, and help them arrive at the vision themselves.

By the time a deal reaches the final room, you have already shaped how they think about the problem. When a CISO-level objection surfaces late, you walk back in as a peer and move it. Sales closes. The work you did upstream is why it lands.

The kind of builder we’re looking for -

  • 10+ years in security leadership; you have held a CISO, Deputy CISO, or senior advisory role and know what that job actually demands

  • Savvy with Compliance implementations for frameworks like SOC 2, ISO 27001, NIST CSF, HIPAA, and FedRAMP - you use these in conversation, not on slides

  • A track record of engaging enterprise CISOs as a peer, not as a vendor representative

  • Comfort with commercial accountability - you have owned numbers before or you are ready to

  • Simplify complex thesis and ideas into simpler and readable chunks.

  • You are not a vendor with a blog. You are a practitioner with a thesis. Bring original thinking on where the CISO’s office is headed - Autonomous Trust is part of that story, not the whole of it

  • Operate independently across multiple channels with rest of the team at your disposal to enable and unlock where needed.

We are open to structuring this as a full-time role or an advisory and consulting engagement - depending on what works best for everyone involved. If the fit is right, the arrangement is a conversation.

How we care for our Sprinters?

  • 100% remote

  • Health, dental, and vision insurance

  • Annual learning and development reimbursement

  • Home office setup stipend

  • Device reimbursement

Inclusion & Diversity -

At Sprinto, talent, curiosity, and ownership matter more than where you come from. We hire people for the problems they can solve, the impact they create, and the way they help others succeed—not their background, identity, or personal circumstances. We believe the best teams are built when people with different perspectives come together around a shared ambition to build something meaningful.

We’re proud to be an equal opportunity employer and are committed to creating a fair, inclusive, and accessible hiring process for everyone.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Director, Enterprise Risk Management & IT SOX Risk Advisory at HubSpot

Leads enterprise risk management and IT SOX compliance initiatives, manages risk professionals, and advises stakeholders on regulatory and technology risk across the organization.

Lead Posted 5 days ago RemoteFirstJobs Product
What this role involves

POS-7385

Director, Enterprise Risk Management & IT SOX Risk Advisory

Role Summary

Our mission at HubSpot is to help millions of organizations grow better.

HubSpot’s Risk and Internal Audit function is growing in scope and complexity. This Director role owns two of the function’s most strategic portfolios: Enterprise Risk Management and IT SOX Risk Advisory, including the expansion of SOX coverage and transformation initiatives.

In this role, you’ll lead Enterprise Risk Management (ERM) facilitation across the business, own the risk advisory relationship with Engineering and Finance stakeholders, and provide director-level oversight of IT SOX readiness as HubSpot scales. You’ll manage a team of risk professionals and serve as a key voice in executive reporting on technology risk.

What You’ll Do

  • Lead execution of the enterprise risk assessment, including surveys, interviews, and cross-functional facilitation.
  • Maintain the enterprise risk register and Key Risk Indicator (KRI) reporting cadence.
  • Synthesize risk inputs from risk owners into executive-ready reporting and recommendations.
  • Track mitigation plan progress and escalate stalled items to leadership.
  • Monitor emerging risks—including AI, regulatory, cybersecurity, and macroeconomic trends—and integrate them into the Enterprise Risk Assessment cycle.
  • Partner with the Head of Risk and Internal Audit to connect Enterprise Risk Assessment outputs to the annual audit plan.
  • Lead the SOX Risk Advisory portfolio, including pre-implementation reviews, control design guidance, and readiness assessments across key business initiatives.
  • Own director-level relationships with Finance and Engineering stakeholders across SOX-relevant system changes.
  • Lead implementations requiring IT audit scoping, control design, and readiness validation.
  • Apply IT SOX expertise to assess ITGC impacts of system migrations, API changes, and platform builds.
  • Partner with the IT Internal Audit team and external auditors on scoping and reliance where advisory work intersects.
  • Manage and develop a team of business and IT risk professionals.
  • Set quality standards for advisory deliverables and risk documentation.
  • Allocate team capacity across concurrent advisory workstreams.
  • Coach advisors on stakeholder management, technical writing, and control design thinking.

What You’ll Bring

Required Qualifications

  • 10+ years of experience across IT audit, risk, or advisory.
  • Bachelor’s degree or equivalent experience in Information Systems, Accounting Information Systems, Management Information Systems, Computer Science, or a related field.
  • Experience facilitating Enterprise Risk Management processes, including leading risk assessments, synthesizing outputs, and presenting findings to leadership.
  • Deep IT SOX experience, including ITGC design, operating effectiveness testing, deficiency assessment, and external auditor coordination.
  • Hands-on experience supporting SOX readiness for new systems, ERP implementations, or product features in a technology or SaaS environment.
  • Track record of managing or mentoring teams in a high-volume, multi-stakeholder environment.
  • Ability to translate technical IT and SOX observations into business risk language for non-technical executive audiences.
  • Strong control design expertise with the ability to advise Engineering and Finance stakeholders before implementation, not just after.
  • Comfortable managing ambiguity across concurrent, fast-moving workstreams.
  • Collaborative approach that builds credibility with Engineering, Finance, Legal, and Product stakeholders while maintaining appropriate independence.
  • Executive presence with the ability to deliver leadership updates on risk and advisory themes.

Nice-to-Have Qualifications

  • Certified Information Systems Auditor (CISA).
  • Certified Internal Auditor (CIA).
  • Additional professional certifications related to risk management, governance, or internal audit.

Where You’ll Work

  • Location: Anywhere within the United States
  • Work location preference: Remote (United States)
  • Posting: Internal and External
  • Travel: Minimal travel as needed.

Pay & Benefits

The cash compensation below includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are tailored to your skills, experience, qualifications, and other job-related reasons.

This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.

Benefits are also an important piece of your total compensation package. Explore the benefits and perks HubSpot offers to help employees grow better.

At HubSpot, fair compensation practices aren’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.

Annual Cash Compensation Range:

$209,400—$335,000 USD

We know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.

If you need accommodations or assistance due to a disability, please reach out to us using this form.

At HubSpot, we value both flexibility and connection. Whether you’re a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you’ll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.

If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Germany Applicants: (m/f/d) - link to HubSpot’s Career Diversity page here.

India Applicants: link to HubSpot India’s equal opportunity policy here.

About HubSpot

HubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot’s connected platform enables businesses to grow faster by focusing on what matters most: customers.

At HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.

We’re building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.

Recognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.

Explore more:

  • HubSpot Careers
  • Life at HubSpot on Instagram

HubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. We may use CLEAR ID Verification during the hiring process to confirm your identity and help maintain a safe, secure, and trusted experience for all candidates. Refer to HubSpot’s Recruiting Privacy Notice for details on data processing and your rights.

Read the full description
Security Director of Information Security Engineering

Leads information security engineering strategy, manages security infrastructure, and oversees a team protecting the organization's systems and data.

Lead Posted 5 days ago Himalayas
What this role involves
Southern New Hampshire University is a team of innovators.
Read the full description
Security Senior Cloud Security Engineer at Iterable

Leads cloud security initiatives across development lifecycle, implementing automated security measures and vulnerability assessments to protect customer data and systems.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Iterable is the leading AI-powered customer engagement platform that helps leading brands like Redfin, SeatGeek, Priceline, Calm, and Box create dynamic, individualized experiences at scale. Our platform empowers organizations to activate customer data, design seamless cross-channel interactions, and optimize engagement—all with enterprise-grade security and compliance. Today, nearly 1,200 brands across 50+ countries rely on Iterable to drive growth, deepen customer relationships, and deliver joyful customer experiences.

Our success is powered by extraordinary people who bring our core values—Be an Owner, Growth Mindset, Run as One, Transparency —to life. We foster a culture of innovation, collaboration, and inclusion, where ideas are valued and individuals are empowered to do their best work. That’s why we’ve been recognized as one of Inc’s Best Workplaces and Fastest Growing Companies, and were recognized on Forbes’ list of America’s Best Startup Employers in 2022. Notably, Iterable has also been listed on Wealthfront’s Career Launching Companies List and has held a top 10 ranking on the Top 25 Companies Where Women Want to Work.

With a global presence—including offices in San Francisco, Denver, London, Sydney, and Lisbon, plus remote employees worldwide—we are committed to building a diverse and inclusive workplace. We welcome candidates from all backgrounds and encourage you to apply. Learn more about our story and mission on our Culture and About Us pages. Let’s shape the future of customer engagement together!

How you will make an impact:

Customers trust Iterable with sensitive information, expecting us to safeguard their data. Iterable’s Security team leads a cross-functional effort across the company to ensure that all systems remain secure in support of Iterable’s core values, and to provide assurance to our customers that we will be good stewards of their valued data. The Security team actively leads the effort to improve Iterable’s security posture in concert with other groups as they develop or launch new features and services. As Engineers, we believe in security through automation, assessments, technical reviews and vulnerability evaluation. Our footprint spans across the entire company at all levels, throughout the complete development lifecycle.

We aim to create a compelling, well-documented, and holistically managed security program. We are looking for individuals to join our vibrant Security Engineering team to move the current state of security to the next level. We strive to improve our cloud security capabilities, and support our peers in building an amazing product through creating an environment which fosters security by design. To summarize, we want you to share and be a part of our grand plan!

One of our core values is “Growth Mindset,” and Iterable is a company where everyone can grow. If this is a role that excites you, please apply as we value applicants for the skills they bring beyond a job description.

In this role you’ll get to:

  • Review system designs and implementations, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices, document and ensure security issues are appropriately remediated
  • Leverage subject matter expertise of systems and infrastructure to propose solutions and drive architectural improvements which address classes of security vulnerabilities
  • Develop and implement cloud and infrastructure security architecture and contribute to overall strategy and roadmap plans
  • Participate in the selection, design, development, implementation, and management of automated security testing tools, such as cloud security posture management and image vulnerability scanners
  • Implement solutions that integrate into CI pipelines to shift security as far left as possible and raise concerns early to engineering teams.
  • Promote DevSecOps principles and implement Infrastructure as Code (IaC) scanning and policy enforcement to ensure deployments via Terraform, AWS CloudFormation, or similar, are secure and compliant with standards and guidelines
  • Coordinate and participate in penetration tests of our cloud services

We are looking for people who have:

  • 5+ years hands-on-keyboard in Cloud Security, SRE, DevOps, DevSecOps, or Infra Engineering.
  • Strong working knowledge of Kubernetes and ecosystem tools such as helm, ArgoCD.
  • Production experience with AWS services, particularly AWS Organizations, AWS Identity (SSO), Identity and Access Management (IAM), Service Control Policies (SCPs), Virtual Private Clouds, Elastic Load Balancers, AWS CloudTrail, and Security Groups.
  • Proficiency with Terraform.
  • Experience developing custom actions or workflows in Github or Gitlab.
  • Solid understanding of cloud security vulnerabilities defense techniques and security best practices, including AWS security practices and present-day threats
  • Proficiency in a high level programming language, such as Python or Go
  • Familiarity with policy management tools such as OPA or Kyverno

Bonus points:

  • SRE Experience
  • Scala or JVM ecosystem experience
  • Familiarity with common observability tools such as Datadog, Prometheus/Grafana
  • Experience with AWS EKS
  • Experience with Panther SIEM
  • Hands on work standing up Jupyter notebook instances, using Jupyter operationally.

Perks & Benefits:

  • Competitive salaries, meaningful equity, & 401(k) plan
  • Medical, dental, vision, & life insurance
  • Balance Days (additional paid holidays)
  • Fertility & Adoption Assistance
  • Paid Sabbatical
  • Flexible PTO
  • Monthly Employee Wellness allowance
  • Monthly Professional Development allowance
  • Pre-tax commuter benefits
  • Complete laptop workstation

The US base salary range for this position at the start of employment is $141,000 - $221,000. Within this range, individual pay is determined by specific US work location, as well as additional factors, including job-related skills, experience, relevant education or training, and internal equity considerations.

Please note that the range listed above reflects only base salary. The total compensation package includes variable pay (where applicable), equity, plus a range of benefits, including medical, dental, vision, and financial. In addition, we offer perks such as generous stipends for health & fitness and learning & development, among others.

Recruitment Disclaimer:

Please be aware that Iterable, Inc. (“Iterable”) and our official professional recruiting agencies and platforms do not:

  • Send job offers from free email services like Gmail, Yahoo mail, Hotmail, etc.
  • Request money, fees, or payment of any kind from prospective candidates to apply to Iterable, for employment, or for the recruitment process (e.g. for home office supplies, or training, etc.).
  • Request or require personal documents like bank account details, tax forms, or credit card information as part of the recruitment process prior to the candidate signing an engagement letter or an employment contract with Iterable.

You may see all job vacancies on our official Iterable channels:

  • Official Iterable website, Careers page: https://iterable.com/careers/
  • Official LinkedIn Jobs page: https://www.linkedin.com/company/iterable/jobs/

Iterable is not affiliated in any way to these impostors and we hereby confirm that such individuals/entities are not authorized, encouraged, or sponsored to act on behalf of Iterable. Such job opportunities are entirely fake and not valid. Therefore, please disregard any written or oral request for a job offer or an interview that you believe is or might be fraudulent or suspicious and immediately reach out to us via email at talent-ops@iterable.com upon receiving a suspicious job offer.

Criminal and/or civil liabilities may arise from such actions, and Iterable expressly reserves the right to take legal action, including criminal action, against such individuals/entities whenever such phenomena occur. In any case, please note that under no circumstances shall Iterable and any of its affiliates be held liable or responsible for any claims, losses, damages, expenses or other inconvenience resulting from or in any way connected to the actions of these impostors.

Iterable is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. Iterable does not make hiring or employment decisions on the basis of race, color, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender-identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws or prohibited by Company policy. Iterable also strives for a healthy and safe workplace and strictly prohibits harassment of any kind. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Iterable will also consider for employment qualified applicants with arrest and conviction records.

Read the full description
Security Quality & Compliance Analyst at Domino Data Lab

Manages compliance frameworks (SOC 2, ISO 27001, etc.) and responds to security questionnaires from enterprise customers and regulated organizations.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility — all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.ai

What we are building

The Quality & Compliance team at Domino is…

  • Building the assurance layer that lets the world’s most regulated organizations put Domino at the center of their AI work. Our customers include global pharmaceutical companies, major financial institutions, and government agencies, organizations that cannot adopt a platform they can’t evidence and defend to their own auditors.
  • Running a genuinely multi-framework program under one roof: SOC 2, ISO 9001, ISO 27001, and CMMC. That combination means the work spans information security, quality management, and federal compliance.
  • Small, senior, and deliberately non-bureaucratic. We would rather have a small set of controls people actually follow than a large set nobody reads. Every SOP and policy we publish has to be clear enough to be used, not just clear enough to pass.
  • A team that sits directly in the revenue path. When an enterprise prospect sends a 400-question security questionnaire or a regulated customer asks how we manage change control, we are the answer, and how fast and how credibly we answer changes deal outcomes.
  • At an inflection point. We’re moving from standing programs up to running them well and at scale, which means investing in tooling, reusable answer libraries, and a reliable operating rhythm instead of heroics.

What your impact will be

In your first year, you will:

  • First 90 days: You’ll take over inbound security and quality questionnaires, learn our answer library and response tooling, and start returning routine questionnaires independently. You’ll pick up the master audit and compliance activities schedule and begin giving the team real lead time on what’s coming.
  • By six months: You’ll own day-to-day QMS operations, new-hire team and training assignments, training content, and records for change orders, suppliers, and computer systems, with data accurate enough that we can report on it any day of the week, not just before an audit. GRC program status will be visible in Jira and Confluence without anyone assembling it by hand.
  • By twelve months: You’ll be a trusted reviewer of our control statements across SOC 2, ISO 9001, ISO 27001, and CMMC, catching drift between what a control claims and what our evidence actually shows before an auditor does. Our SOPs and policies will be current and readable because you’ve worked through them. Questionnaire turnaround will be measurably faster, with a larger share answered from the library instead of from scratch.

What we look for in this role

  • 2–5 years in GRC, compliance operations, quality assurance, or audit support, in a role where you did the hands-on work yourself.
  • Direct experience responding to security or quality questionnaires at volume, and comfort owning the shared tooling and answer library behind those responses.
  • Hands-on involvement in at least one audit or certification cycle end to end, SOC 2, ISO 9001, ISO 27001, CMMC, or a comparable framework, including evidence collection and findings follow-up.
  • Experience as the day-to-day administrator or power user of a compliance system of record (eQMS, GRC platform, or equivalent), with real accountability for data accuracy.
  • Strong technical writing and editing. You can turn a vague requirement into a clear, correct SOP, and a hard customer question into a precise answer.
  • Fluency in Jira and Confluence, and the discipline to keep them current without being reminded.
  • Real fluency with agentic AI tooling and frameworks, you’ve built custom skills, agents, or prompt-driven workflows to take repetitive work off your own plate, and you know where model output has to be human-verified.
  • Meticulous attention to detail and calendar discipline. Other people’s deadlines depend on your tracking, and you treat that as a commitment.
  • Sound judgment about the limits of your own knowledge, you know when to answer, when to pull in an SME, and when to escalate. You never invent an answer to a customer-facing security question.
  • A collaborative, low-ego approach to working across Security, Engineering, Legal, People, and Sales.
  • Nice to have: experience in a regulated life-sciences, medical device, or pharmaceutical environment, GxP, 21 CFR Part 11, computer system validation, or supplier qualification.

What we value

  • We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
  • We believe in individuals who seek truth and speak the truth and can be their whole selves at work
  • We value all of you that believe improving is always possible At Domino Everything is a work in progress – we can do better at everything
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply

#LI-Remote

Read the full description
Security Senior Security Engineer at SmarterDx

Owns detection engineering and security operations, writing/tuning SIEM detections in Panther, investigating alerts, running cloud security operations in AWS, and executing incident response.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at smarterdx.com/careers.

Role

SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. This role is our hands-on owner of detection engineering and security operations. You will turn our detection platform into real coverage: writing and tuning detections in Panther, keeping alerts high-signal, running the SIEM as it grows, and being on point when an alert turns into an investigation. You will also handle the day-to-day work of cloud security operations and help run incident response.

You will work closely with our Staff Security Engineer, who sets detection and AI-security strategy. Your job is to make that strategy real in production and keep it sharp. There is room to grow into deeper detection engineering, cloud security, and security automation, on a team that invests in leveling people up.

**This role is fully remote within the US**

What You’ll Do

  • Write, tune, and maintain detections in our SIEM (Panther) across cloud, container, and SaaS log sources, keeping coverage broad and alerts high-signal.
  • Run the SIEM day to day: onboard log sources, manage detection quality, and reduce false positives so real signals stand out.
  • Triage and investigate security alerts from raw log to conclusion, and help execute our incident-response playbooks.
  • Run cloud security operations in AWS: investigate GuardDuty and Wiz findings, tighten configurations, and close cloud misconfigurations.
  • Own and improve GitHub organization security controls as code.
  • Partner on network and infrastructure security: help onboard network telemetry, support egress monitoring, and provide backup depth alongside our infrastructure security engineer.
  • Help build and extend the team’s security-automation tooling.
  • Write runbooks so detection and response are repeatable rather than tribal knowledge.
  • Contribute to security design reviews and RFCs, and give substantive security feedback on pull requests.
  • Support the Vulnerability Management program with triage and exploitability assessment as volume requires.

What You Bring

  • 4+ years in security engineering, with solid hands-on experience in AWS and cloud-native infrastructure.
  • Direct experience writing and tuning detections in a modern SIEM (Panther or similar) and reasoning about detection coverage.
  • Experience investigating security alerts from raw log to a defensible conclusion.
  • The ability to design and deliver medium-complexity security work independently.
  • Code fluency in Python or TypeScript to automate your work.
  • Familiarity with cloud logging and observability (CloudTrail, VPC Flow Logs) and AWS security services (GuardDuty, AWS Config).
  • Solid AWS network security fundamentals (VPC, security groups, egress controls) and Terraform, enough to partner on and back up our network and infrastructure security work.
  • Clear writing; you leave behind runbooks and tickets others can follow.
  • Design detections and operational tooling for maintainability, so the work stays reliable and easy for the team to extend.
  • An ownership mindset: you close loops rather than drop them.

Nice To Haves

  • Startup experience, especially in health tech or another regulated, data-sensitive environment.
  • Incident-response experience, or a strong interest in growing into it.
  • Network security depth beyond fundamentals (VPC design, segmentation, Transit Gateway, firewall/egress architecture).
  • Kubernetes (EKS) and container security exposure.
  • Interest in AI and agentic security and in building security automation.

Our Tech Stack

  • Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
  • Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
  • Languages: Python, TypeScript, Go
  • AI and automation: Claude, MCP, and agentic tooling used across engineering

Compensation

$190k to 220k base salary

#LI-Remote

#LI-DNP

Benefits

  • Medical, Dental & Vision – Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
  • Paid Parental Leave – Generous paid leave to support families through birth or adoption: Up to 12 weeks for parents.
  • Remote-First Team – Work from anywhere in the U.S.
  • Unlimited PTO & 10 Holidays – So you can relax and recharge.
  • 401(k) with Traditional & Roth Options– Tax-advantaged retirement savings through Fidelity with a 4% match.
  • Minimal Bureaucracy – A fast-moving, high-impact environment where you can focus on what matters.
  • Incredible Teammates! – Work alongside smart, supportive, and mission-driven colleagues.
Read the full description
Security Manager, Detection Engineering (Rapid Response Team) at SentinelOne

Lead a rapid response detection engineering team building security rules and detection coverage for emerging threats while managing team health and technical direction.

Lead Posted 6 days ago RemoteFirstJobs Product
What this role involves

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Manager, Detection Engineering, you will be tasked with leading our Rapid Response Team (RRT), responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps surfaced through every avenue, from customer escalations to internal research and threat intelligence. This is a hands-on, technical leadership role where you will lead from the front, personally contributing to detection engineering work and setting the technical bar through your own rule development and code review, while owning the health, throughput, and direction of a specialized detection engineering team and protecting its focus in a fast-moving, reactive environment. You will partner closely with cross-functional teams and detection leadership to ensure RRT delivers consistent, timely detection coverage.

What Will You Do?

Primary responsibilities include:

  • Stay hands-on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against.
  • Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations.
  • Own RRT’s operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats.
  • Protect the team’s focus and capacity, shielding engineers from unscoped demand while ensuring high-priority work is met within target turnaround times.
  • Grow the cross-functional partnerships that extend RRT’s reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.
  • Own and evolve the team’s roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible.
  • Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team’s needs.
  • Drive proactive, transparent communication of RRT’s work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

  • Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team. Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical.
  • Current, hands-on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops.
  • Strong, hands-on experience with GitHub and detection-as-code pipelines, including fluency in pull requests, code review, and merge-to-release workflows.
  • Hands-on experience developing detections across more than one engine (endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based across multiple data sources), or the ability to ramp quickly across engines.
  • Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization.
  • Strong understanding of adversary behavior, MITRE ATT&CK, and real-world threats such as ransomware and in-the-wild campaigns.
  • A track record in fast-moving, SLO-driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day.
  • Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams.
  • Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.
  • Familiarity with intake and triage workflows and detection automation tooling is a strong plus.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave

Insurance & Financial Security

  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance

Work Perks & Flexibility

  • Home office allowance
  • Mobile phone reimbursement

Wellness & Lifestyle

  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement

This U.S. role has a base pay range that will vary based on the location of the candidate. For some locations, a different pay range may apply.  If so, this range will be provided to you during the recruiting process. You can also reach out to the recruiter with any questions.

Base Salary Range

$164,000—$226,000 USD

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Read the full description