Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Security Controls Assessor (Part time & Remote) at TestPros, Inc.

Conducts security assessments and compliance evaluations using NIST frameworks, develops security documentation (SSPs, SARs, POA&Ms), and verifies implementation of security controls for federal and commercial clients.

Mid Remote Posted 7 minutes ago RemoteFirstJobs Product
What this role involves

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world.  We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.

TestPros is looking for Security Controls Assessors with experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks.

Start: Future projects late 2026 or 2027 (not an immediate job opening)

Type: Part-time consulting

Overview

Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.

Responsibilities and Duties:

You should be able to deliver on the following expertly and consistently:

  • Develop NIST 800-53 Rev5 based System Security Plan (SSP).
  • Create/Update the applicable documents identified by NIST 800-53 Rev 5, specifically the Security Assessment Report (SAR).
  • Create/Update the associated Plan of Actions and Milestones (POA&M).
  • Provide detailed security-related reports including data, analyses, and conclusions upon completion of tests, scans, and assessments, including mitigations and, if indicated, appropriate escalation of identified risks and vulnerabilities.
  • Verify and document the implementation of security controls necessary to achieve compliance.
  • Keep management apprised of impending areas of concern, verbally and in writing.
  • Review and develop System Security Plans (SSPs), Plans of Actions and Milestones (POA&Ms), and as well as other necessary artifacts.
  • Facilitate the Plan of Actions and Milestones (POA&M) program to ensure customer systems have accurately and fully provided information for POA&M activities to include valid remediation of findings.
  • Develop various policy documents (SOPs/CONOPs) as required. This may include policies regarding Configuration Management, IS Sanitization, Media Security, Password Policy, Business Continuity, Continuity of Operations, Incident Response, Disaster Recover, and Security Assessments.
  • Develop new, and mature existing information security and risk policies.
  • Initiate, and lead on-going information security maturity assessment processes and training, using industry accepted frameworks and implement into the overall cyber security posture.
  • Produce and review key performance indicators for implemented security measures and distribute KPIs.
  • Maintain knowledge of threat landscape by monitoring threat intelligence, and other related sources.

Qualifications and Skills:

  • 5+ years of directly related experience in IT security compliance, including recent experience with NIST 800-53 Rev 5 “Security and Privacy Controls for Federal Information Systems and Organizations”
  • Cloud computing security
  • Security governance and policy
  • Security risk analysis
  • Auditing and monitoring systems
  • Scanning and vulnerability management systems
  • Advanced Malware Protection
  • Threat Intelligence
  • Incident Management - analysis, detection, and handling of security events
  • Penetration testing and associated tools (e.g., nmap, Metasploit, etc.)
  • Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience (preferred)
  • Military and/or practical job experience may be considered in-lieu of formal education, with significant industry certifications

Rate: $50-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.

Equal Opportunity Employer

TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.

Offer Considerations

TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.

Federal Compliance

As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Read the full description
Security Cyber Security Engineer / Information Systems Security Engineer (ISSE) at OpenTeams

Leads cybersecurity architecture, RMF activities, and compliance for government systems while designing supply chain security controls and integrating security into CI/CD pipelines.

Senior Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

Who We Are

We exist to unlock human potential.

Too often, AI drains it—drains budgets, drains energy resources, drains ownership of data. OpenTeams was founded to change that. We build AI that empowers. Our models are energy-efficient, cost-effective, and fully yours.

Our ethos is open source. That means freedom, trust, and accountability are built into every line of code. We reinvest 3% of our profits back into the open-source community, because we believe tech is most powerful when it serves everyone.

At our core, we value freedom, teamwork, accountability, and uncompromising quality. If you want to challenge the status quo, and shape tools that set people free, OpenTeams is the place to do it.

Location: Remote (US) with travel to customer sites as required (Washington Metro Area preferred)

Employment Type: Full-time

Clearance: Active TS/SCI required

Role Summary

The Cyber Security Engineer / ISSE owns the security architecture and accreditation posture of the depot. This role leads RMF activities, embeds security controls into engineering workflows, and serves as the primary security interface with government assessors and authorizing officials.

Responsibilities

  • Lead RMF activities: control selection, implementation evidence, POA&M management, and ATO support
  • Design and implement supply chain security controls: SBOM generation, artifact signing, vulnerability scanning, and provenance attestation
  • Perform threat modeling and security reviews of depot architecture and workflows
  • Integrate security tooling into CI/CD pipelines and enforce policy gates
  • Support cross-domain and classified environment requirements, including secure transfer procedures
  • Interface with government ISSMs, assessors, and authorizing officials

Required Qualifications

  • Active TS/SCI clearance
  • Experience with Xacta, eMASS, or CSAM
  • 6+ years in cyber security or ISSE roles supporting DoD or IC systems
  • Hands-on experience with RMF, NIST 800-53, and eMASS or equivalent
  • Experience with DevSecOps tooling: container scanning, SAST/DAST, signing, and policy enforcement
  • IAT/IAM Level II or III certification per DoD 8140 (for example Security+, CISSP, or CISM)

Preferred Qualifications

  • Experience securing AI/ML systems or software supply chains at scale
  • Familiarity with cATO approaches and continuous monitoring
  • Experience with IL5/IL6 or cross-domain solutions

Grow With Us

At OpenTeams, growth isn’t just about the company—it’s about you.

We believe the best careers are built at the edge of your potential. That is where new tools, ideas, and technologies change the world. Here, you’ll work alongside pioneers of AI, solving problems that matter: making AI more transparent, more ethical, and more empowering. As your skills grow, our career framework provides a pathway and recognition of that increased impact.

Opportunities aren’t limited by geography. You’ll collaborate with global experts, contribute to open source projects that power the world’s technology, and stretch your skills daily.  That global perspective and diversity makes our solution more universal and robust.  We are committed to continuing to celebrate diversity on our team.

Supported people are successful people.  We offer 100% employer paid medical premiums for employees and self-managed PTO with a minimum time off requirement, so that our teams are able to do their best work.

We invest  in curiosity, creativity, and ownership. That means you’ll be trusted to boldly innovate, supported to learn fast, and celebrated for successful collaboration.

Commitment to diversity, equity, inclusion, and belonging

OpenTeams understands that valuing diverse creative practices and forms of knowledge is crucial to and enriches the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, disabled people, persons of all sexual orientations, gender identities and expressions.

We are an equal opportunity employer - all qualified applicants will receive equal consideration for recruitment, interviews, employment, training, compensation, promotion, and related activities. We do not discriminate based on race, religion, gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. OpenTeams will not tolerate discrimination or harassment based on these characteristics or any other unlawful behavior, conduct, or purpose.

Read the full description
Security Field CISO at Sprinto

Field CISO builds market-facing security and compliance thought leadership, speaking engagements, and practitioner credibility for a compliance automation platform.

Lead Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers.

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable trust posture without draining operational bandwidth and resources on repetitive tasks.

Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we’ve raised $31.8M in funding to fuel our mission. Trusted by over 4,000 organizations across 75 countries, Sprinto helps organizations stay audit-ready, manage real-time risks, and scale fearlessly. With 300+ native integrations and AI-driven automation, Sprinto supports 200+ global security standards natively, including SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and more. Sprinto’s extensible architecture enables organizations to build and support an infinite number of custom integrations and frameworks.

Founded in 2020 by second-time founders Girish Redekar and Raghuveer Kancherla, Sprinto powers compliance for organizations like Whatfix, Encora, Anaconda, Whatnot, Ultrahuman, WeWork, Everstage, AI Foundation, HackerRank, and many more.

Life as a Sprinter -

Nobody succeeds at Sprinto by staying in their lane.

We are organized around problems, not job titles. Sprinters take ownership beyond their role, solve hard problems, and care deeply about the impact they create. If something can be improved, fixed, or built, we don’t wait for permission; we step in.

Being remote means we rely less on proximity and more on trust. We write things down, communicate openly, and move quickly because great teams aren’t built by sitting together, they’re built by pulling in the same direction.

We believe progress beats perfection, feedback is a gift, and doing the right thing matters, even when nobody is watching.

And while we move with urgency, we never move alone.

The mission -

This is Sprinto’s first dedicated Field CISO hire in the US. You are not walking into a built function. You are building the market-facing security and compliance voice from scratch - with full access to the founders, the GTM team, and the product roadmap.

This is a marketing and thought leadership role. You make every Sprinto channel more credible, more attended, and more influential - because the voice behind it is a practitioner, not a vendor. Every roundtable you run, every stage you speak from, every webinar you anchor - you own the prospect experience.

The scope runs from the first piece of content to the narratives & depth in all Sprinto content.

Where you’ll leave your mark?

  • Take the Autonomous Trust thesis to market - together - Sprinto has built the product and defined the category. You bring the platform to carry the thesis publicly - at events, in content, on stage, in every conversation that shapes how enterprise CISOs think about compliance. We build the narrative. You carry it into rooms we cannot reach alone.
  • Show up at the industry’s biggest stages as Sprinto’s practitioner voice - When we walk into RSA, ISACA, or a regional CISO summit, we walk in as participants in the conversation - not vendors looking for a slot. Your point of view on stage is how we earn that position. Together we make sure Sprinto is never just a name on a booth.
  • Build the rooms where CISOs talk openly - Webinars and roundtables only work when the right person anchors them. You bring the practitioner credibility that makes a CISO clear their calendar. We bring the platform and the agenda. Together we create conversations where CISOs share what they actually need - and the pipeline follows naturally.
  • Put a practitioner’s fingerprint on everything we publish - Our content team has the reach and the production. You have the voice that turns good content into content CISOs forward. We write together, you shape the thinking, and you push it through channels we do not own - your newsletter, your LinkedIn, your podcast. The audience you bring is the distribution we cannot manufacture from scratch.
  • Deepen the advisory board into a real community - We have built relationships with some of the most respected security leaders in the market. You deepen them - not as a coordinator, but as a peer. The more substantively you engage, the more the advisory board compounds into events, content, and deals none of us could run alone.
  • Walk into deals at different stages where needed - Early in a prospect conversation, you help them see what their compliance program could look like when the detection-remediation gap closes. You are not pitching - you are workshopping. You sit with their reality, map it against the Autonomous Trust model, and help them arrive at the vision themselves.

By the time a deal reaches the final room, you have already shaped how they think about the problem. When a CISO-level objection surfaces late, you walk back in as a peer and move it. Sales closes. The work you did upstream is why it lands.

The kind of builder we’re looking for -

  • 10+ years in security leadership; you have held a CISO, Deputy CISO, or senior advisory role and know what that job actually demands

  • Savvy with Compliance implementations for frameworks like SOC 2, ISO 27001, NIST CSF, HIPAA, and FedRAMP - you use these in conversation, not on slides

  • A track record of engaging enterprise CISOs as a peer, not as a vendor representative

  • Comfort with commercial accountability - you have owned numbers before or you are ready to

  • Simplify complex thesis and ideas into simpler and readable chunks.

  • You are not a vendor with a blog. You are a practitioner with a thesis. Bring original thinking on where the CISO’s office is headed - Autonomous Trust is part of that story, not the whole of it

  • Operate independently across multiple channels with rest of the team at your disposal to enable and unlock where needed.

We are open to structuring this as a full-time role or an advisory and consulting engagement - depending on what works best for everyone involved. If the fit is right, the arrangement is a conversation.

How we care for our Sprinters?

  • 100% remote

  • Health, dental, and vision insurance

  • Annual learning and development reimbursement

  • Home office setup stipend

  • Device reimbursement

Inclusion & Diversity -

At Sprinto, talent, curiosity, and ownership matter more than where you come from. We hire people for the problems they can solve, the impact they create, and the way they help others succeed—not their background, identity, or personal circumstances. We believe the best teams are built when people with different perspectives come together around a shared ambition to build something meaningful.

We’re proud to be an equal opportunity employer and are committed to creating a fair, inclusive, and accessible hiring process for everyone.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Cloud Security Engineer at Iterable

Leads cloud security initiatives across development lifecycle, implementing automated security measures and vulnerability assessments to protect customer data and systems.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Iterable is the leading AI-powered customer engagement platform that helps leading brands like Redfin, SeatGeek, Priceline, Calm, and Box create dynamic, individualized experiences at scale. Our platform empowers organizations to activate customer data, design seamless cross-channel interactions, and optimize engagement—all with enterprise-grade security and compliance. Today, nearly 1,200 brands across 50+ countries rely on Iterable to drive growth, deepen customer relationships, and deliver joyful customer experiences.

Our success is powered by extraordinary people who bring our core values—Be an Owner, Growth Mindset, Run as One, Transparency —to life. We foster a culture of innovation, collaboration, and inclusion, where ideas are valued and individuals are empowered to do their best work. That’s why we’ve been recognized as one of Inc’s Best Workplaces and Fastest Growing Companies, and were recognized on Forbes’ list of America’s Best Startup Employers in 2022. Notably, Iterable has also been listed on Wealthfront’s Career Launching Companies List and has held a top 10 ranking on the Top 25 Companies Where Women Want to Work.

With a global presence—including offices in San Francisco, Denver, London, Sydney, and Lisbon, plus remote employees worldwide—we are committed to building a diverse and inclusive workplace. We welcome candidates from all backgrounds and encourage you to apply. Learn more about our story and mission on our Culture and About Us pages. Let’s shape the future of customer engagement together!

How you will make an impact:

Customers trust Iterable with sensitive information, expecting us to safeguard their data. Iterable’s Security team leads a cross-functional effort across the company to ensure that all systems remain secure in support of Iterable’s core values, and to provide assurance to our customers that we will be good stewards of their valued data. The Security team actively leads the effort to improve Iterable’s security posture in concert with other groups as they develop or launch new features and services. As Engineers, we believe in security through automation, assessments, technical reviews and vulnerability evaluation. Our footprint spans across the entire company at all levels, throughout the complete development lifecycle.

We aim to create a compelling, well-documented, and holistically managed security program. We are looking for individuals to join our vibrant Security Engineering team to move the current state of security to the next level. We strive to improve our cloud security capabilities, and support our peers in building an amazing product through creating an environment which fosters security by design. To summarize, we want you to share and be a part of our grand plan!

One of our core values is “Growth Mindset,” and Iterable is a company where everyone can grow. If this is a role that excites you, please apply as we value applicants for the skills they bring beyond a job description.

In this role you’ll get to:

  • Review system designs and implementations, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices, document and ensure security issues are appropriately remediated
  • Leverage subject matter expertise of systems and infrastructure to propose solutions and drive architectural improvements which address classes of security vulnerabilities
  • Develop and implement cloud and infrastructure security architecture and contribute to overall strategy and roadmap plans
  • Participate in the selection, design, development, implementation, and management of automated security testing tools, such as cloud security posture management and image vulnerability scanners
  • Implement solutions that integrate into CI pipelines to shift security as far left as possible and raise concerns early to engineering teams.
  • Promote DevSecOps principles and implement Infrastructure as Code (IaC) scanning and policy enforcement to ensure deployments via Terraform, AWS CloudFormation, or similar, are secure and compliant with standards and guidelines
  • Coordinate and participate in penetration tests of our cloud services

We are looking for people who have:

  • 5+ years hands-on-keyboard in Cloud Security, SRE, DevOps, DevSecOps, or Infra Engineering.
  • Strong working knowledge of Kubernetes and ecosystem tools such as helm, ArgoCD.
  • Production experience with AWS services, particularly AWS Organizations, AWS Identity (SSO), Identity and Access Management (IAM), Service Control Policies (SCPs), Virtual Private Clouds, Elastic Load Balancers, AWS CloudTrail, and Security Groups.
  • Proficiency with Terraform.
  • Experience developing custom actions or workflows in Github or Gitlab.
  • Solid understanding of cloud security vulnerabilities defense techniques and security best practices, including AWS security practices and present-day threats
  • Proficiency in a high level programming language, such as Python or Go
  • Familiarity with policy management tools such as OPA or Kyverno

Bonus points:

  • SRE Experience
  • Scala or JVM ecosystem experience
  • Familiarity with common observability tools such as Datadog, Prometheus/Grafana
  • Experience with AWS EKS
  • Experience with Panther SIEM
  • Hands on work standing up Jupyter notebook instances, using Jupyter operationally.

Perks & Benefits:

  • Competitive salaries, meaningful equity, & 401(k) plan
  • Medical, dental, vision, & life insurance
  • Balance Days (additional paid holidays)
  • Fertility & Adoption Assistance
  • Paid Sabbatical
  • Flexible PTO
  • Monthly Employee Wellness allowance
  • Monthly Professional Development allowance
  • Pre-tax commuter benefits
  • Complete laptop workstation

The US base salary range for this position at the start of employment is $141,000 - $221,000. Within this range, individual pay is determined by specific US work location, as well as additional factors, including job-related skills, experience, relevant education or training, and internal equity considerations.

Please note that the range listed above reflects only base salary. The total compensation package includes variable pay (where applicable), equity, plus a range of benefits, including medical, dental, vision, and financial. In addition, we offer perks such as generous stipends for health & fitness and learning & development, among others.

Recruitment Disclaimer:

Please be aware that Iterable, Inc. (“Iterable”) and our official professional recruiting agencies and platforms do not:

  • Send job offers from free email services like Gmail, Yahoo mail, Hotmail, etc.
  • Request money, fees, or payment of any kind from prospective candidates to apply to Iterable, for employment, or for the recruitment process (e.g. for home office supplies, or training, etc.).
  • Request or require personal documents like bank account details, tax forms, or credit card information as part of the recruitment process prior to the candidate signing an engagement letter or an employment contract with Iterable.

You may see all job vacancies on our official Iterable channels:

  • Official Iterable website, Careers page: https://iterable.com/careers/
  • Official LinkedIn Jobs page: https://www.linkedin.com/company/iterable/jobs/

Iterable is not affiliated in any way to these impostors and we hereby confirm that such individuals/entities are not authorized, encouraged, or sponsored to act on behalf of Iterable. Such job opportunities are entirely fake and not valid. Therefore, please disregard any written or oral request for a job offer or an interview that you believe is or might be fraudulent or suspicious and immediately reach out to us via email at talent-ops@iterable.com upon receiving a suspicious job offer.

Criminal and/or civil liabilities may arise from such actions, and Iterable expressly reserves the right to take legal action, including criminal action, against such individuals/entities whenever such phenomena occur. In any case, please note that under no circumstances shall Iterable and any of its affiliates be held liable or responsible for any claims, losses, damages, expenses or other inconvenience resulting from or in any way connected to the actions of these impostors.

Iterable is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. Iterable does not make hiring or employment decisions on the basis of race, color, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender-identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws or prohibited by Company policy. Iterable also strives for a healthy and safe workplace and strictly prohibits harassment of any kind. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Iterable will also consider for employment qualified applicants with arrest and conviction records.

Read the full description
Security Senior Security Engineer at SmarterDx

Owns detection engineering and security operations, writing/tuning SIEM detections in Panther, investigating alerts, running cloud security operations in AWS, and executing incident response.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at smarterdx.com/careers.

Role

SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. This role is our hands-on owner of detection engineering and security operations. You will turn our detection platform into real coverage: writing and tuning detections in Panther, keeping alerts high-signal, running the SIEM as it grows, and being on point when an alert turns into an investigation. You will also handle the day-to-day work of cloud security operations and help run incident response.

You will work closely with our Staff Security Engineer, who sets detection and AI-security strategy. Your job is to make that strategy real in production and keep it sharp. There is room to grow into deeper detection engineering, cloud security, and security automation, on a team that invests in leveling people up.

**This role is fully remote within the US**

What You’ll Do

  • Write, tune, and maintain detections in our SIEM (Panther) across cloud, container, and SaaS log sources, keeping coverage broad and alerts high-signal.
  • Run the SIEM day to day: onboard log sources, manage detection quality, and reduce false positives so real signals stand out.
  • Triage and investigate security alerts from raw log to conclusion, and help execute our incident-response playbooks.
  • Run cloud security operations in AWS: investigate GuardDuty and Wiz findings, tighten configurations, and close cloud misconfigurations.
  • Own and improve GitHub organization security controls as code.
  • Partner on network and infrastructure security: help onboard network telemetry, support egress monitoring, and provide backup depth alongside our infrastructure security engineer.
  • Help build and extend the team’s security-automation tooling.
  • Write runbooks so detection and response are repeatable rather than tribal knowledge.
  • Contribute to security design reviews and RFCs, and give substantive security feedback on pull requests.
  • Support the Vulnerability Management program with triage and exploitability assessment as volume requires.

What You Bring

  • 4+ years in security engineering, with solid hands-on experience in AWS and cloud-native infrastructure.
  • Direct experience writing and tuning detections in a modern SIEM (Panther or similar) and reasoning about detection coverage.
  • Experience investigating security alerts from raw log to a defensible conclusion.
  • The ability to design and deliver medium-complexity security work independently.
  • Code fluency in Python or TypeScript to automate your work.
  • Familiarity with cloud logging and observability (CloudTrail, VPC Flow Logs) and AWS security services (GuardDuty, AWS Config).
  • Solid AWS network security fundamentals (VPC, security groups, egress controls) and Terraform, enough to partner on and back up our network and infrastructure security work.
  • Clear writing; you leave behind runbooks and tickets others can follow.
  • Design detections and operational tooling for maintainability, so the work stays reliable and easy for the team to extend.
  • An ownership mindset: you close loops rather than drop them.

Nice To Haves

  • Startup experience, especially in health tech or another regulated, data-sensitive environment.
  • Incident-response experience, or a strong interest in growing into it.
  • Network security depth beyond fundamentals (VPC design, segmentation, Transit Gateway, firewall/egress architecture).
  • Kubernetes (EKS) and container security exposure.
  • Interest in AI and agentic security and in building security automation.

Our Tech Stack

  • Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
  • Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
  • Languages: Python, TypeScript, Go
  • AI and automation: Claude, MCP, and agentic tooling used across engineering

Compensation

$190k to 220k base salary

#LI-Remote

#LI-DNP

Benefits

  • Medical, Dental & Vision – Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
  • Paid Parental Leave – Generous paid leave to support families through birth or adoption: Up to 12 weeks for parents.
  • Remote-First Team – Work from anywhere in the U.S.
  • Unlimited PTO & 10 Holidays – So you can relax and recharge.
  • 401(k) with Traditional & Roth Options– Tax-advantaged retirement savings through Fidelity with a 4% match.
  • Minimal Bureaucracy – A fast-moving, high-impact environment where you can focus on what matters.
  • Incredible Teammates! – Work alongside smart, supportive, and mission-driven colleagues.
Read the full description
Security HQ - Senior Application Security Engineer (Remote) at Job&Talent

Senior Application Security Engineer drives security by design across the SDLC, leading threat modeling, code reviews, security automation, and developer enablement initiatives.

Senior Remote Posted 7 days ago RemoteFirstJobs Product
What this role involves

We are looking for a proactive and experienced Senior Application Security Engineer to help build secure products at scale. As a trusted partner to Engineering and Product teams, you will drive security by design across the Software Development Lifecycle (SDLC), leading initiatives such as threat modelling, secure code reviews, security automation, and developer enablement.

You will play a key role in shaping our Application Security strategy, helping us build secure, resilient products while enabling engineering teams to move fast with confidence.

This is a fully remote position with flexibility within ±1 hour of CET.

Responsibilities

  • Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC.

  • Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks.

  • Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling.

  • Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation.

  • Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management.

  • Mentor Security Champions and junior engineers, promoting a strong security culture across development teams.

  • Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness.

A successful candidate will have

  •  3-4 years of experience in Information Security, including at least 2 years in Application Security.

  • Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews.

  • Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines.

  • Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices.

  • Experience implementing and managing WAF solutions, as well as conducting internal penetration testing (including APIs using Burp Suite).

  • Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP).

  • Basic scripting or development experience, preferably in Python.

  • Excellent communication skills, with the ability to influence engineering teams and explain complex security concepts to technical and non-technical stakeholders.

About us

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. We help companies boost productivity and efficiency at scale, while giving workers the tools they need to thrive. Our mission is simple: to empower the people who make the world go round.

Built on deep industry expertise, cutting-edge technology, and smart AI agents, our end-to-end platform covers the entire workforce lifecycle — from recruitment and planning to time and attendance, performance, cost management, and communication.

It delivers measurable improvements in the areas that matter most: fulfilment, attendance, retention, and workforce quality. Our platform strength is rooted in unique experience: placing millions of workers over the years and serving thousands of blue-chip clients across delivery, logistics, manufacturing, e-commerce, retail, and hospitality.

Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America and is backed by leading investors including Atomico, Goldman Sachs, Kinnevik, BlackRock, and SoftBank.

Join our community and make an impact

Innovation, high standards, and analytical thinking are in our DNA. Everyone has a voice here, and that voice matters. It’s how we stay sharp, move fast, and make decisions that keep us ahead of the curve.

You’ll take full ownership of your work, collaborate across borders, and grow by doing. Around here, you’ll hear a lot about 10x experiences, human-centered design, and the power of AI. But what truly sets us apart is our people: Our diverse team brings unique perspectives, deep commitment and real-world experience to the table.

We champion empathy, honesty, and inclusion. Because when people can be their authentic selves, incredible things happen—for our workers, our clients, and for each other.

And we reward that impact—with competitive pay, meaningful benefits, and the opportunity to shape what work looks like for millions around the globe.

If you’re ready to make a real impact at scale, you’re in the right place.

Proud to champion equality

At Job&Talent we value diversity and we’re an Equal Opportunity Employer. We welcome applications from all suitably qualified people regardless of national origin, race, disability, religious beliefs or sexual orientation. Come join us. We look forward to your application.

#LI-ML2

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Engineer at Oddball

Embeds security into federal software delivery by conducting risk assessments, supporting ATO compliance efforts, and maintaining FISMA/FedRAMP security postures for VA systems.

Mid Remote Posted 8 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Security Engineer at Oddball

Embed security into federal software delivery by integrating security requirements into development workflows, supporting ATO processes, and conducting risk assessments aligned with NIST and VA standards.

Mid Remote Posted 8 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Red Team Lead (Offensive Cybersecurity)

Leads offensive cybersecurity red team operations, conducting penetration testing and vulnerability assessments for critical infrastructure projects.

Lead Remote Posted 8 days ago Himalayas
What this role involves
Role Title: Red Team Lead (Offensive Cybersecurity) Role Type: Contractor Location: Remote micro1 is engaging Red Team Leads (Offensive Cybersecurity) to contribute expertise to a customer's critical cybersecurity project.
Read the full description
Security Senior Security Engineer I, Customer Trust EMEA (Remote Eligible in the UK)

Leads security initiatives and trust operations for Smartsheet's EMEA region, protecting customer data and platform integrity.

Senior Remote Posted 8 days ago Jobicy AI
What this role involves
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI...
Read the full description
Security Lithic: Senior AML Analyst

Senior AML Analyst owns financial crime monitoring program, manages investigation tooling, and handles compliance escalations for card issuing platform.

Senior Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Lithic is the modern card issuing and processing platform empowering ambitious financial companies to build the future of payments.

Our infrastructure powers card programs for 100+ innovative clients, from fintechs reimagining credit and digital banking to platforms transforming disbursements and spend management. Companies like Mercury, Flex, and Novo rely on Lithic's developer-friendly APIs, direct network connections, and flawless reconciliation to launch and scale card programs in weeks, not years.

We're building a future where access to better financial products materially improves people's lives, free from the constraints of 30-year-old mainframes and legacy processors. We're proud to be backed by world-class investors who share that vision, including Bessemer Venture Partners, Index Ventures, Spark Capital, Stripes, and Mastercard, along with many others. 

We're a team of 170+ across 26 states and 7 countries, headquartered in New York City. 

Lithic is the modern card issuing and processing platform empowering ambitious financial companies to build the future of payments.

Our infrastructure powers card programs for 100+ innovative clients, from fintechs reimagining credit and digital banking to platforms transforming disbursements and spend management. Companies like Mercury, Flex, and Novo rely on Lithic's developer-friendly APIs, direct network connections, and flawless reconciliation to launch and scale card programs in weeks, not years.

We're building a future where access to better financial products materially improves people's lives, free from the constraints of 30-year-old mainframes and legacy processors. We're proud to be backed by world-class investors who share that vision, including Bessemer Venture Partners, Index Ventures, Spark Capital, Stripes, and Mastercard, along with many others.

We're a team of 170+ across 26 states and 7 countries, headquartered in New York City.

Our Risk & Compliance team is hiring a Senior AML Analyst who will improve the effectiveness, resilience, and scalability of our financial monitoring program. You will own Lithic's AML and financial crime monitoring program at the SOP and monitoring-engine level, and you will be the person who turns our agentic monitoring and investigation tooling into realized, defensible capacity. This is an ownership role, not purely a queue-based execution role: you’ll certainly handle escalations, exceptions, and perform population sampling, but the goal is routine, documented volume is increasingly absorbed by automation, and you own the design, tuning, and exception handling that sit around it.

What You’ll Do

  • Own and continuously improve the AML and financial crime transaction monitoring SOPs, keeping them aligned to current regulatory requirements, evolving typologies, and operational reality
  • Own the feedback loop into Lithic's monitoring engine: partner with your Analytics, Engineering, and Product peers to evaluate alert logic, assess rule and scenario effectiveness, and tune thresholds to reduce false positives while preserving coverage
  • Lead the testing, deployment, and tuning of agentic transaction monitoring and investigation solutions, including documenting the investigative context the tooling needs to produce repeatable, examiner-ready output
  • Investigate complex suspicious activity independently and prepare high-quality SARs and UARs; own escalations and the judgment-heavy cases automation cannot close unattended
  • Supervise and quality-check alert review and investigative output, including AI-assisted output, so decisions hold up to bank partner and regulatory scrutiny
  • Synthesize monitoring performance data, operational trends, and emerging financial crime risks into actionable program insights, and define and influence AML KPIs and KRIs
  • Lead governance preparation for relevant oversight forums and support bank partner and exam-readiness deliverables
  • Train and mentor analysts on investigations, money laundering typologies, and the agentic tooling, so program knowledge scales beyond any one person

What You'll Need

  • 3+ years of AML/BSA and transaction monitoring experience in fintech, payments, or a bank-partnered environment
  • Demonstrated ownership of end-to-end AML programs or work streams with limited guidance, including authoring and maintaining SOPs and preparing governance materials
  • Deep knowledge of money laundering typologies and emerging financial crime trends, with the ability to investigate complex activity and prepare high-quality SARs and UARs independently
  • Hands-on experience evaluating alert logic and assessing or tuning transaction monitoring rules and scenarios for effectiveness
  • Comfort working with AI-assisted or agentic tooling, including how to test, tune, document, and defend AI-assisted decisions to bank partners and regulators
  • Self-starter who can create structure where none exists and knows when to escalate and collaborate
  • Strong written and verbal communication
  • Solid grasp of the BSA/AML regulatory framework (USA PATRIOT Act, OFAC and sanctions, SAR requirements)

Nice to Have

  • CAMS or CFE (preferred, or willing to obtain)
  • Experience deploying or tuning AI, automation, or agentic tooling in a compliance or investigations context
  • Experience with OSINT tooling and SQL or Snowflake for investigative data retrieval
  • Card issuing, payments, or fintech experience with exposure to sponsor bank relationships
  • Background in high-risk verticals (MRBs, crypto-adjacent businesses, or similar)

Base Salary: $65,000 - $110,000

This is a remote position. However, candidates must be located in the United States. We do not offer visa sponsorship or assistance.

Benefits for Full-Time US Employees:

  • Unlimited PTO
  • 12-weeks fully paid parental leave
  • 4-Week Fully Paid Sabbatical (earned at your 5-year anniversary)
  • Work From Anywhere: work from anywhere in the world 4-weeks each year
  • 3% cashback on card purchases with your complimentary Privacy.com employee account
  • Health, vision, and dental insurance; HSA Contribution Match
  • 401(k) match
  • Voluntary Life Insurance and STD/LTD

NYC-based employees work from our SoHo office three days a week. Tuesdays and Thursdays are our core days, and you'll choose a third day that works for your schedule and team needs.

In-office employees receive: 

  • Commuter benefit
  • Catered lunch every Tuesday and Thursday

To apply: https://weworkremotely.com/remote-jobs/lithic-senior-aml-analyst

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at DEF CON

Lead DevSecOps engineer designs, builds, and operates secure CI/CD pipelines and infrastructure for government cloud environments while directing a team of platform and security engineers.

Lead Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your rĂ©sumĂ©, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;
  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contactrecruiting@defconai.com.

Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice .

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at Red Cell Partners

Leads DevSecOps platform design and deployment for government cloud environments, building CI/CD pipelines with embedded security controls and directing a small engineering team.

Lead Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits:

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your rĂ©sumĂ©, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security Security Engineer - Full Remote (France) or Hybrid at Voyage Privé

Embeds security practices across product development, builds CI/CD security guardrails, designs secure architectures, and enables engineering teams to adopt secure-by-design practices.

Mid Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

Company Description

✹ About Voyage PrivĂ©

Born in France in 2006, Voyage PrivĂ© has grown from an ambitious startup into becoming the Europe’s leading travel tech platform. Operating across 9 markets with tens of millions of users, we’re not just another e-commerce success story - we’re a tech powerhouse revolutionizing online travel.

What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.

We’re now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.

Job Description

🎯 Your Mission

As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform.

You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.

You’ll have the opportunity to build many security foundations from scratch — from internal tooling to CI/CD guardrails — and influence key architectural and technical decisions as we redesign our platform for scale.

Your key responsibilities will include:

  • Strengthen the security posture across products, data and infrastructure: secure coding practices, code reviews, threat modeling, vulnerability remediation, cloud, and network hardening.
  • Develop automated security guardrails integrated into CI/CD pipelines (SAST, SCA, secrets scanning).
  • Design secure architectures for applications, APIs, data flows, and integrations in partnership with engineering teams.
  • Secure hybrid environments combining virtual machines, containerized workloads, and cloud-native services, ensuring consistent security standards across the entire platform.
  • Drive proactive risk identification through continuous scanning, threat modeling sessions, risk assessments, and architecture reviews.
  • Enable engineering teams to build secure-by-design practices by acting as a trusted advisor, developing internal tools, and leading security awareness sessions.
  • Operational security & incident readiness: participate in on-call rotations, investigate security events, and improve incident response workflows.
  • Lead security improvement projects: build automation, enhance tools, optimize processes, and foster a culture of security ownership.

Qualifications

💡 What We’re Looking For

We’re looking for builders who move fast, think big, and care deeply about creating impact that lasts

Your profile:

  • 5–7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles.
  • Strong development background (Python, Node.js, Java, Go, PhP or similar).
  • Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins).
  • Solid understanding of cloud security principles (AWS, GCP, Azure).
  • Experience securing both virtualized systems (VMs) and containerized workloads.
  • Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals.
  • Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management.
  • Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints.
  • Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders.
  • Proactive, autonomous, critical thinker with a continuous improvement mindset.
  • Nice to have: previous experience or knowledge of compliance requirements (GDPR, PCI-DSS
)
  • Fluent in French and English.

Additional Information

⚡ Our Recruitment Process

We believe in a fast, transparent, and human recruitment process.

Here’s what you can expect:

  • Intro Call with a Talent Acquisition Partner (30–45 min) – Get to know each other! We’ll share more about the role, the team, and our culture.
  • Manager Interview (60 min) – Deep dive into your experience, missions, and ways of working.
  • Take-Home Task – Practical exercise to showcase your strategic thinking and approach to security.
  • Task Debrief (60 min) – Discuss your task with members of the team
  • On-Site Interview (60 min) – Meet the VP of Engineering to align on expectations, culture, and long-term impact.

📍Location : Aix en Provence or remote, France

📅 Start Date : The sooner, the better

📄 Contract Type : Full-time / Permanent

❀ You’ll Love Joining Us

Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.

🌮 Prefer flexibility?  We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.

đŸ€Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.

đŸ’Ș Forget your gym subscription! Access our large on-site fitness center morning, noon, and night - or challenge your colleagues to a padel match on our private court.

🎉 Live to the rhythm of Voyage Privé’s signature mix of business and fun: Company Breaks, Carnival, Annual Convention, meetups and talks
 plus free tickets to every Provence Rugby home match and live music nights at the Dalida Institute.

✈ And because travel is in our DNA : enjoy up to 20% off our exclusive getaway offers.

Join us and make your next career move a journey worth taking. 🌍

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at DEF CON

Leads DevSecOps platform architecture and delivery for government AI systems, building CI/CD pipelines with embedded security controls while directing a small engineering team.

Lead Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your rĂ©sumĂ©, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;
  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contactrecruiting@defconai.com.

Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice .

Read the full description
Security ISO 27001 Internal Auditor (German-speaking) at Secfix

Conducts ISO 27001 internal audits for customers, reviews compliance evidence, identifies non-conformities, and delivers actionable audit reports.

Junior Remote Posted 11 days ago RemoteFirstJobs Product
What this role involves

Remote (+/- 2hrs from Germany GMT+1). C2 German Language is essential

At Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work.

Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader.

We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital.

About the Role

We’re hiring an ISO 27001 Internal Auditor to own our internal audits end to end. You stay independent from the implementation work. You audit what a customer has built, review their evidence on the Secfix platform, and give them a clear report before their external audit. You assess, you find what is missing, and you tell them in plain language exactly what to do about it. This is a hands-on individual contributor role with full ownership of a function customers trust us with.

What You’ll Do:

You will own internal audits to make our customers ready for their certification. We give you full context and best practices, and you own how you deliver the results. You will:

  • Own internal audits for our customers end to end, from kickoff through to the final report they take into their external audit

  • Review and sample evidence on the Secfix platform and assess it against the relevant ISO 27001 controls

  • Run the customer calls and walk customers through your findings and any non-conformities

  • Catch the non-conformities that matter, including the easy ones, so nothing avoidable surfaces later in an external audit

  • Write findings a non-technical founder can act on: what is missing, why it matters, and what to do next

  • Keep several audits moving at once and keep every one on schedule

  • Stay neutral to the implementation and hold a clean line between auditing and helping

  • Learn our other frameworks (TISAX, ISO 42001) and help build a repeatable audit structure for them

  • Help improve framework content on the platform, including evidence examples and guidance

  • Share structured product feedback when you spot recurring issues in the platform

About You:

  • German (C1/C2) and English (fluent) are a must for this role

  • Up to 2 years of information security background

  • Hands-on ISO 27001 internal audit experience, with at least 10+ internal audits you have personally run

  • A PECB ISO 27001 Lead Auditor certification or a direct equivalent

  • Direct experience auditing inside a modern GRC platform

  • Clear, concrete written and spoken English, with the ability to explain complex requirements simply

Nice-to-have:

  • Experience auditing or implementing TISAX, ISO 42001, NIS2 or SOC 2

  • Experience at an early-stage startup (Seed to Series B)

  • Exposure to a modern SaaS product and cross-functional work with product teams

What we offer

  • Remote Work: 100% remote work with a virtual office in Gather.

  • Competitive Salary: Industry-competitive local salaries.We pay local rates that are at or above the market. We share this philosophy with GitLab.

  • Equity: Generous equity package – we’re all owners of Secfix and beneficiaries of our collective success.

  • Mentorship: We are backed by top VCs and accelerators and have direct access to world-class mentors.

  • Development Budget: €1,000 annual personal development budget.

  • Home office Budget: Home office budget and access to co-working spaces.

  • Holidays: 26 days holiday + local public holidays.

  • Health Insurance: Comprehensive health coverage.

  • Annual Retreat: Annual retreat to build connections and inspire ideas (this year we’re headed to Alicante!).

  • Company Events: Company-wide events to build relationships and have some fun!

  • Tech Equipment: Latest tech equipment (MacBook, monitors, headphones).

Interview Process:

  • 45 min - Intro call with Talent team

  • Take-home Assessment

  • 1.5hr Assessment review and interview with Compliance Team

  • 45 min - Final Founder Interview with CTO

Please note: We are an equal-opportunity employer and a remote-only company. At this time, we can support hiring only within EU time zones. We work in sync using Gather as our virtual office. As a small fast-growing company, we believe in the need for an in-sync component of daily communication and therefore cannot support 100% asynchronous work. Read more about our Remote Culture here .

Read the full description
Security AppSec Engineer

Develops and implements application security practices, conducts security assessments, and manages vulnerability remediation within the software development lifecycle.

Mid Remote Posted 12 days ago Himalayas
What this role involves
AppSec Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description
Security Azure Cloud Security Engineer - 100% Remote at CENSUS

Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.

Mid Remote Posted 13 days ago RemoteFirstJobs Product
What this role involves

CENSUS’ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.

We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.

Key Responsibilities

  • Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.

  • Design and support the implementation of secure Azure cloud architectures.

  • Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.

  • Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.

  • Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.

  • Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).

  • Ensure that the implemented solutions align with the product’s security architecture, requirements and threat model.

  • Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.

  • Document and present product security risks in both technical and business contexts.

Minimum Qualifications

  • MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.

  • 3 + years of experience in IT or Cybersecurity

  • 2 + years of experience in cloud applications or cloud security related roles – preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.

  • Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).

  • Problem solving skills, analytical thinking and willingness to learn/grow.

  • Proficient in English.

Required Skills

Experience with:

  • Designing, implementing and auditing cloud platform security architecture and engaged technologies.

  • The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).

  • Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.

  • Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.

  • DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.

  • Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.

  • Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.

  • Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).

  • Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.

Nice-to-Have Skills

  • Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.

  • Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.

  • Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).

  • Familiarity with debugging, instrumenting and profiling software running on cloud platforms.

  • Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.

  • Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.

  • Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.

  • Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.

  • Experienced in working with international teams in other regions and time zones worldwide.

#LI-Remote

Read the full description
Security Senior Security Advisor - Access Management (Remote in the US) at GuidePoint Security

Senior advisor who leads IAM assessment discovery sessions, designs access management solutions, and guides clients through vendor selection and presales processes.

Senior Remote Posted 13 days ago RemoteFirstJobs Product
What this role involves

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

Duties and Responsibilities:

  • Responsible for creating new solutions to help provide customers with more advisory value
  • Leads IAM assessment discovery sessions in order to deep dive into custom Access Management solutions
  • Use discovery session information to build assessments containing recommendations and roadmaps
  • Help clients through the vendor selection process
  • Acts as trusted advisor for clients through the presales process in order to help figure out what services best fit with client needs

Qualifications:

  • The ideal candidate will have deep experience in Access Management, spanning both Workforce IAM and Customer Identity (CIAM)
  • Seven plus years of hands-on experience with designing, architecting & building Access Management solutions across various technologies (Okta or Ping)
  • Strong verbal and writing skills to develop technical documentation and presentations
  • Experience in leading technical architecture and security design discussions
  • Experience with consultative and complex technical deployment projects, managing various stakeholder relationships
  • 4-5 year’s experienced in scoping and sizing complex projects
  • 4-5 years’ experience in responding to RFPs and developing statement of work
  • Understanding of common IAM industry standards and best practices

Preferred:

  • Okta, Ping or similar IAM vendor certifications

Educational/Certifications Qualifications Desired:

  • Bachelors or Master’s Degree in Computer Science, Computer Engineering, MIS or related field

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don’t miss updates on your application.

Why GuidePoint? GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks
.

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option
Read the full description
Security Azure Cloud Security Engineer - 100% Remote at CENSUS

Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.

Mid Remote Posted 13 days ago RemoteFirstJobs Product
What this role involves

CENSUS’ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.

We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.

Key Responsibilities

  • Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.

  • Design and support the implementation of secure Azure cloud architectures.

  • Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.

  • Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.

  • Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.

  • Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).

  • Ensure that the implemented solutions align with the product’s security architecture, requirements and threat model.

  • Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.

  • Document and present product security risks in both technical and business contexts.

Minimum Qualifications

  • MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.

  • 3 + years of experience in IT or Cybersecurity

  • 2 + years of experience in cloud applications or cloud security related roles – preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.

  • Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).

  • Problem solving skills, analytical thinking and willingness to learn/grow.

  • Proficient in English.

Required Skills

Experience with:

  • Designing, implementing and auditing cloud platform security architecture and engaged technologies.

  • The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).

  • Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.

  • Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.

  • DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.

  • Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.

  • Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.

  • Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).

  • Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.

Nice-to-Have Skills

  • Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.

  • Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.

  • Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).

  • Familiarity with debugging, instrumenting and profiling software running on cloud platforms.

  • Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.

  • Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.

  • Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.

  • Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.

  • Experienced in working with international teams in other regions and time zones worldwide.

#LI-Remote

Read the full description