Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Security Controls Assessor (Part time & Remote) at TestPros, Inc.

Conducts security assessments and compliance evaluations using NIST frameworks, develops security documentation (SSPs, SARs, POA&Ms), and verifies implementation of security controls for federal and commercial clients.

Mid Remote Posted 7 minutes ago RemoteFirstJobs Product
What this role involves

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world.  We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.

TestPros is looking for Security Controls Assessors with experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks.

Start: Future projects late 2026 or 2027 (not an immediate job opening)

Type: Part-time consulting

Overview

Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.

Responsibilities and Duties:

You should be able to deliver on the following expertly and consistently:

  • Develop NIST 800-53 Rev5 based System Security Plan (SSP).
  • Create/Update the applicable documents identified by NIST 800-53 Rev 5, specifically the Security Assessment Report (SAR).
  • Create/Update the associated Plan of Actions and Milestones (POA&M).
  • Provide detailed security-related reports including data, analyses, and conclusions upon completion of tests, scans, and assessments, including mitigations and, if indicated, appropriate escalation of identified risks and vulnerabilities.
  • Verify and document the implementation of security controls necessary to achieve compliance.
  • Keep management apprised of impending areas of concern, verbally and in writing.
  • Review and develop System Security Plans (SSPs), Plans of Actions and Milestones (POA&Ms), and as well as other necessary artifacts.
  • Facilitate the Plan of Actions and Milestones (POA&M) program to ensure customer systems have accurately and fully provided information for POA&M activities to include valid remediation of findings.
  • Develop various policy documents (SOPs/CONOPs) as required. This may include policies regarding Configuration Management, IS Sanitization, Media Security, Password Policy, Business Continuity, Continuity of Operations, Incident Response, Disaster Recover, and Security Assessments.
  • Develop new, and mature existing information security and risk policies.
  • Initiate, and lead on-going information security maturity assessment processes and training, using industry accepted frameworks and implement into the overall cyber security posture.
  • Produce and review key performance indicators for implemented security measures and distribute KPIs.
  • Maintain knowledge of threat landscape by monitoring threat intelligence, and other related sources.

Qualifications and Skills:

  • 5+ years of directly related experience in IT security compliance, including recent experience with NIST 800-53 Rev 5 “Security and Privacy Controls for Federal Information Systems and Organizations”
  • Cloud computing security
  • Security governance and policy
  • Security risk analysis
  • Auditing and monitoring systems
  • Scanning and vulnerability management systems
  • Advanced Malware Protection
  • Threat Intelligence
  • Incident Management - analysis, detection, and handling of security events
  • Penetration testing and associated tools (e.g., nmap, Metasploit, etc.)
  • Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience (preferred)
  • Military and/or practical job experience may be considered in-lieu of formal education, with significant industry certifications

Rate: $50-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.

Equal Opportunity Employer

TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.

Offer Considerations

TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.

Federal Compliance

As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Read the full description
Security Cyber Ark Integration Engineer

Design and implement CyberArk integrations with enterprise applications, identity platforms, and cloud services to strengthen security infrastructure.

Mid Posted 3 days ago Himalayas
What this role involves
CyberArk Integration EngineerExperience: 6–10 Years Job SummaryDesign and implement integrations between CyberArk and enterprise applications, identity platforms, cloud services, and DevSecOps tools.
Read the full description
Security Quality & Compliance Analyst at Domino Data Lab

Manages compliance frameworks (SOC 2, ISO 27001, etc.) and responds to security questionnaires from enterprise customers and regulated organizations.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility — all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.ai

What we are building

The Quality & Compliance team at Domino is…

  • Building the assurance layer that lets the world’s most regulated organizations put Domino at the center of their AI work. Our customers include global pharmaceutical companies, major financial institutions, and government agencies, organizations that cannot adopt a platform they can’t evidence and defend to their own auditors.
  • Running a genuinely multi-framework program under one roof: SOC 2, ISO 9001, ISO 27001, and CMMC. That combination means the work spans information security, quality management, and federal compliance.
  • Small, senior, and deliberately non-bureaucratic. We would rather have a small set of controls people actually follow than a large set nobody reads. Every SOP and policy we publish has to be clear enough to be used, not just clear enough to pass.
  • A team that sits directly in the revenue path. When an enterprise prospect sends a 400-question security questionnaire or a regulated customer asks how we manage change control, we are the answer, and how fast and how credibly we answer changes deal outcomes.
  • At an inflection point. We’re moving from standing programs up to running them well and at scale, which means investing in tooling, reusable answer libraries, and a reliable operating rhythm instead of heroics.

What your impact will be

In your first year, you will:

  • First 90 days: You’ll take over inbound security and quality questionnaires, learn our answer library and response tooling, and start returning routine questionnaires independently. You’ll pick up the master audit and compliance activities schedule and begin giving the team real lead time on what’s coming.
  • By six months: You’ll own day-to-day QMS operations, new-hire team and training assignments, training content, and records for change orders, suppliers, and computer systems, with data accurate enough that we can report on it any day of the week, not just before an audit. GRC program status will be visible in Jira and Confluence without anyone assembling it by hand.
  • By twelve months: You’ll be a trusted reviewer of our control statements across SOC 2, ISO 9001, ISO 27001, and CMMC, catching drift between what a control claims and what our evidence actually shows before an auditor does. Our SOPs and policies will be current and readable because you’ve worked through them. Questionnaire turnaround will be measurably faster, with a larger share answered from the library instead of from scratch.

What we look for in this role

  • 2–5 years in GRC, compliance operations, quality assurance, or audit support, in a role where you did the hands-on work yourself.
  • Direct experience responding to security or quality questionnaires at volume, and comfort owning the shared tooling and answer library behind those responses.
  • Hands-on involvement in at least one audit or certification cycle end to end, SOC 2, ISO 9001, ISO 27001, CMMC, or a comparable framework, including evidence collection and findings follow-up.
  • Experience as the day-to-day administrator or power user of a compliance system of record (eQMS, GRC platform, or equivalent), with real accountability for data accuracy.
  • Strong technical writing and editing. You can turn a vague requirement into a clear, correct SOP, and a hard customer question into a precise answer.
  • Fluency in Jira and Confluence, and the discipline to keep them current without being reminded.
  • Real fluency with agentic AI tooling and frameworks, you’ve built custom skills, agents, or prompt-driven workflows to take repetitive work off your own plate, and you know where model output has to be human-verified.
  • Meticulous attention to detail and calendar discipline. Other people’s deadlines depend on your tracking, and you treat that as a commitment.
  • Sound judgment about the limits of your own knowledge, you know when to answer, when to pull in an SME, and when to escalate. You never invent an answer to a customer-facing security question.
  • A collaborative, low-ego approach to working across Security, Engineering, Legal, People, and Sales.
  • Nice to have: experience in a regulated life-sciences, medical device, or pharmaceutical environment, GxP, 21 CFR Part 11, computer system validation, or supplier qualification.

What we value

  • We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
  • We believe in individuals who seek truth and speak the truth and can be their whole selves at work
  • We value all of you that believe improving is always possible At Domino Everything is a work in progress – we can do better at everything
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply

#LI-Remote

Read the full description
Security Product Security Engineer at Cloudflare

Conducts security assessments, triages vulnerabilities, and builds AI-powered automation tools to streamline security operations for Cloudflare's products.

Mid Onsite Posted 7 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations: Austin, TX

Role Summary

As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.

On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.

Responsibilities

  • Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to help automate code analysis, optimize triage, and streamline Product Security workflows.
  • Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling sessions (e.g., STRIDE) across product features, defining security requirements early in the development lifecycle.
  • Product Vulnerability Management: Manage the operational lifecycle of product security findings. Ensure vulnerabilities are verified, mapped to the correct engineering owner, and tracked to mitigation in alignment with established SLAs.
  • Bug Bounty Triage: Perform the technical triage and validation of Cloudflare’s external Bug Bounty submissions, verifying exploitability and evaluating business risk.
  • Pentest Coordination: Support internal and external penetration testing engagements by reviewing findings, clarifying technical context, and assisting development teams with remediation strategies.
  • Engineering Collaboration: Partner closely with DevOps and product teams, acting as a reliable security point of contact and helping developers implement secure coding practices.

Desirable Skills, Knowledge, and Experience

  • Product/AppSec Expertise: 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Threat Modeling & Risk Analysis: Competency in threat modeling methodologies and the ability to evaluate code flaws to determine their actual engineering and security impact.
  • Vulnerability Lifecycle Operations: Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups while working against defined SLAs.
  • Strong Collaboration & Communication: Ability to collaborate effectively across teams, clearly communicating technical security risks to software engineers and resolving ownership ambiguity constructively.

Bonus points

  • Offensive Security Tooling: Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities.
  • Program Management Experience: Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family.  Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun!  The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security Security Engineer at Oddball

Embeds security into federal software delivery by conducting risk assessments, supporting ATO compliance efforts, and maintaining FISMA/FedRAMP security postures for VA systems.

Mid Remote Posted 8 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Security Engineer at Oddball

Embed security into federal software delivery by integrating security requirements into development workflows, supporting ATO processes, and conducting risk assessments aligned with NIST and VA standards.

Mid Remote Posted 8 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Solvd: Security Engineer II – IAM & SaaS Governance

Security engineer designs and manages IAM infrastructure, Okta environments, and SaaS data governance while enforcing least privilege access controls.

Mid Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Argentina
URL: http://solvd.com

Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes.

Following the acquisition of Tooploox, a premier AI and product development company, Solvd now offers true end-to-end delivery—from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively.

We are looking for a Mid-Tier Security Engineer specializing in Identity and Access Management (IAM) and Data Governance to join our Cyber Security team. In this role, you won't just be managing user tickets; you will be the engineer designing, implementing, and securing our identity perimeter and SaaS ecosystem.

You will own our Okta environment and drive data governance strategies across our core SaaS applications (e.g., Google Workspace, Microsoft 365, Slack, Salesforce, GitHub). Your goal is to ensure seamless user lifecycle management while aggressively enforcing the principle of least privilege and monitoring data exposure.

What you'll do

Identity & Access Management (IAM) Engineering

  • Okta Architecture & Admin: Act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies.

  • Lifecycle Automation: Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts to eliminate manual provisioning errors.

  • Federation & Protocols: Standardize and implement SSO integrations utilizing SAML 2.0, OIDC, and OAuth 2.0, ensuring secure token exchange and scoping.

Data Governance & SaaS Security

  • Least Privilege Enforcement: Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across all enterprise SaaS platforms.

  • Data Exposure Mitigation: Monitor and remediate unauthorized data sharing, public file exposure, and "shadow IT" API integrations within our SaaS ecosystem.

  • Access Reviews & Compliance: Lead quarterly user access reviews (UARs) and provide evidentiary support for security frameworks such as SOC 2 Type II, ISO 27001, and GDPR.

  • SaaS Security Posture Management (SSPM): Leverage SSPM tools or native security centers to continuously audit and harden SaaS application configurations.

Monitoring & Incident Response

  • Threat Detection: Analyze Okta System Logs and SaaS audit logs to detect anomalous behavior (e.g., impossible travel, credential stuffing, unauthorized data exfiltration).

  • SIEM Integration: Collaborate with the SOC team to ensure critical IAM and SaaS logs are correctly ingested into our SIEM for real-time alerting.

What you bring

  • Experience: 3–5 years of dedicated experience in a Security Engineering, IAM, or Systems Engineering role with a heavy security focus.

  • Okta Mastery: Strong engineering-level knowledge of Okta (Okta Certified Administrator or Certified Consultant preferred).

  • Security Mindset: Proven track record of implementing data governance principles, data loss prevention (DLP), and zero-trust access models.

  • Core Protocols: Deep understanding of networking and identity protocols: TCP/IP, HTTP, SAML, OAuth, OIDC, and SCIM.

  • Scripting: Proficiency in Python, PowerShell, or Bash to interact with REST APIs for custom security tooling and automation.

  • Log Analysis: Experience querying logs (Splunk, ELK, SQL, or cloud-native SIEMs) to investigate identity-related security incidents.

When you join Solvd, you'll…

  • Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.

  • Be part of a global team with equal opportunities for collaboration across continents and cultures.

  • Thrive in an inclusive environment that prioritizes continuous learning, innovation, and ethical AI standards.

Ready to make an impact?

If you're excited to build things that matter, champion responsible AI, and grow with some of the industry’s sharpest minds. Apply today and let’s innovate together.

Solvd is an equal opportunity employer.

To apply: https://weworkremotely.com/remote-jobs/solvd-security-engineer-ii-iam-saas-governance

Read the full description
Security Security Engineer - Full Remote (France) or Hybrid at Voyage PrivĂŠ

Embeds security practices across product development, builds CI/CD security guardrails, designs secure architectures, and enables engineering teams to adopt secure-by-design practices.

Mid Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

Company Description

✨ About Voyage Privé

Born in France in 2006, Voyage Privé has grown from an ambitious startup into becoming the Europe’s leading travel tech platform. Operating across 9 markets with tens of millions of users, we’re not just another e-commerce success story - we’re a tech powerhouse revolutionizing online travel.

What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.

We’re now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.

Job Description

🎯 Your Mission

As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform.

You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.

You’ll have the opportunity to build many security foundations from scratch — from internal tooling to CI/CD guardrails — and influence key architectural and technical decisions as we redesign our platform for scale.

Your key responsibilities will include:

  • Strengthen the security posture across products, data and infrastructure: secure coding practices, code reviews, threat modeling, vulnerability remediation, cloud, and network hardening.
  • Develop automated security guardrails integrated into CI/CD pipelines (SAST, SCA, secrets scanning).
  • Design secure architectures for applications, APIs, data flows, and integrations in partnership with engineering teams.
  • Secure hybrid environments combining virtual machines, containerized workloads, and cloud-native services, ensuring consistent security standards across the entire platform.
  • Drive proactive risk identification through continuous scanning, threat modeling sessions, risk assessments, and architecture reviews.
  • Enable engineering teams to build secure-by-design practices by acting as a trusted advisor, developing internal tools, and leading security awareness sessions.
  • Operational security & incident readiness: participate in on-call rotations, investigate security events, and improve incident response workflows.
  • Lead security improvement projects: build automation, enhance tools, optimize processes, and foster a culture of security ownership.

Qualifications

💡 What We’re Looking For

We’re looking for builders who move fast, think big, and care deeply about creating impact that lasts

Your profile:

  • 5–7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles.
  • Strong development background (Python, Node.js, Java, Go, PhP or similar).
  • Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins).
  • Solid understanding of cloud security principles (AWS, GCP, Azure).
  • Experience securing both virtualized systems (VMs) and containerized workloads.
  • Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals.
  • Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management.
  • Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints.
  • Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders.
  • Proactive, autonomous, critical thinker with a continuous improvement mindset.
  • Nice to have: previous experience or knowledge of compliance requirements (GDPR, PCI-DSS…)
  • Fluent in French and English.

Additional Information

⚡ Our Recruitment Process

We believe in a fast, transparent, and human recruitment process.

Here’s what you can expect:

  • Intro Call with a Talent Acquisition Partner (30–45 min) – Get to know each other! We’ll share more about the role, the team, and our culture.
  • Manager Interview (60 min) – Deep dive into your experience, missions, and ways of working.
  • Take-Home Task – Practical exercise to showcase your strategic thinking and approach to security.
  • Task Debrief (60 min) – Discuss your task with members of the team
  • On-Site Interview (60 min) – Meet the VP of Engineering to align on expectations, culture, and long-term impact.

📍Location : Aix en Provence or remote, France

📅 Start Date : The sooner, the better

📄 Contract Type : Full-time / Permanent

❤️ You’ll Love Joining Us

Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.

🌴 Prefer flexibility?  We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.

🤝Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.

💪 Forget your gym subscription! Access our large on-site fitness center morning, noon, and night - or challenge your colleagues to a padel match on our private court.

🎉 Live to the rhythm of Voyage Privé’s signature mix of business and fun: Company Breaks, Carnival, Annual Convention, meetups and talks… plus free tickets to every Provence Rugby home match and live music nights at the Dalida Institute.

✈️ And because travel is in our DNA : enjoy up to 20% off our exclusive getaway offers.

Join us and make your next career move a journey worth taking. 🌍

Read the full description
Security AppSec Engineer

Develops and implements application security practices, conducts security assessments, and manages vulnerability remediation within the software development lifecycle.

Mid Remote Posted 12 days ago Himalayas
What this role involves
AppSec Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description
Security Application Security Engineer at FareHarbor

Conducts application security reviews, implements secure SDLC initiatives, and supports security monitoring across the company's software development lifecycle.

Mid Posted 13 days ago RemoteFirstJobs Product
What this role involves

About FareHarbor

At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.

With over 20,000 clients across 90+ countries—we’re the largest in our industry and shaping the future of travel, together.

Our team is an ‘Ohana of 700+ people around the world. We’re passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.

FareHarbor Core Values:

  • Think Client First
  • We Are One ‘Ohana
  • Be Curious and Learn
  • Own It.
  • Act With Integrity
  • Embrace the Challenge

Why FareHarbor?

Founding FareHarbor required unwavering passion. Turning a start-up into the world’s leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, we’ve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.

And since day one, we’ve known that our real success lies in our people—the Ohana.

With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to  work—to  believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.

From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we can’t wait to see all that’s to come.

About the Role

FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.

What you will do:

  • Work closely with product, platform, and security teams to ensure security is an integral part of our SDLC
  • Perform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teams
  • Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls
  • Support assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidence
  • Work with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns
  • Support security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation
  • Participate in security alert triage, investigation, and incident response activities when needed
  • Participate in the security on-call rotation

Required Skills and Experience:

Technical skills:

  • Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10.
  • Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits.
  • Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc.
  • Proficiency in Python or other high-level language such as Go, Java, or similar
  • Good understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as code
  • Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning
  • Pentesting experience is a plus
  • Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities
  • Familiarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similar
  • Good understanding of incident response, security investigations, and technical incident management
  • Experience with API security, microservices security, and distributed application architectures
  • Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar.

Soft skills:

  • Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholders
  • Able to work effectively with product, engineering, platform, infrastructure, and security teams
  • Proactive attitude, always on the look-out for improving your and our way of working
  • Strong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practices
  • Strong relationship building skills across diverse cross-functional teams
  • Comfortable operating independently and taking ownership of security initiatives from discovery through implementation
  • Able to provide practical security guidance that enables teams to move quickly and securely

Nice to Haves:

  • Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similar
  • Experience with bug bounty programs and coordinating vulnerability remediation with third party
  • Experience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworks
  • Experience building internal security tooling or developer-facing security automation
  • Contributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures

This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..

Benefits

  • Global leave benefit
    • 22 weeks paid parental leave
    • 2 weeks paid grandparent leave
    • Extended care and bereavement leave
  • Life insurance policy
  • Pension Plan
  • Central Amsterdam Location
  • Discount CZ insurance
  • Working in a multicultural environment - 45 different nationalities
  • Commuting allowance for public transport & subsidized lunch
  • Wellness benefits (Headspace subscription & wellness webinars)
  • Hybrid friendly
  • Work-from-home assistance
  • Educational Opportunities
    • Individual skill development & growth programming
  • Social hours & events and team-building
  • 26 vacation days per year

FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.

To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.

Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.

Read the full description
Security Azure Cloud Security Engineer - 100% Remote at CENSUS

Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.

Mid Remote Posted 13 days ago RemoteFirstJobs Product
What this role involves

CENSUS’ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.

We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.

Key Responsibilities

  • Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.

  • Design and support the implementation of secure Azure cloud architectures.

  • Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.

  • Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.

  • Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.

  • Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).

  • Ensure that the implemented solutions align with the product’s security architecture, requirements and threat model.

  • Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.

  • Document and present product security risks in both technical and business contexts.

Minimum Qualifications

  • MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.

  • 3 + years of experience in IT or Cybersecurity

  • 2 + years of experience in cloud applications or cloud security related roles – preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.

  • Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).

  • Problem solving skills, analytical thinking and willingness to learn/grow.

  • Proficient in English.

Required Skills

Experience with:

  • Designing, implementing and auditing cloud platform security architecture and engaged technologies.

  • The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).

  • Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.

  • Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.

  • DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.

  • Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.

  • Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.

  • Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).

  • Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.

Nice-to-Have Skills

  • Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.

  • Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.

  • Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).

  • Familiarity with debugging, instrumenting and profiling software running on cloud platforms.

  • Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.

  • Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.

  • Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.

  • Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.

  • Experienced in working with international teams in other regions and time zones worldwide.

#LI-Remote

Read the full description
Security Application Security Engineer at FareHarbor

Application Security Engineer who conducts security reviews, implements secure SDLC practices, and supports security monitoring across the platform.

Mid Posted 13 days ago RemoteFirstJobs Product
What this role involves

About FareHarbor

At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.

With over 20,000 clients across 90+ countries—we’re the largest in our industry and shaping the future of travel, together.

Our team is an ‘Ohana of 700+ people around the world. We’re passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.

FareHarbor Core Values:

  • Think Client First
  • We Are One ‘Ohana
  • Be Curious and Learn
  • Own It.
  • Act With Integrity
  • Embrace the Challenge

Why FareHarbor?

Founding FareHarbor required unwavering passion. Turning a start-up into the world’s leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, we’ve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.

And since day one, we’ve known that our real success lies in our people—the Ohana.

With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to  work—to  believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.

From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we can’t wait to see all that’s to come.

About the Role

FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.

What you will do:

  • Work closely with product, platform, and security teams to ensure security is an integral part of our SDLC
  • Perform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teams
  • Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls
  • Support assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidence
  • Work with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns
  • Support security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation
  • Participate in security alert triage, investigation, and incident response activities when needed
  • Participate in the security on-call rotation

Required Skills and Experience:

Technical skills:

  • Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10.
  • Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits.
  • Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc.
  • Proficiency in Python or other high-level language such as Go, Java, or similar
  • Good understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as code
  • Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning
  • Pentesting experience is a plus
  • Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities
  • Familiarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similar
  • Good understanding of incident response, security investigations, and technical incident management
  • Experience with API security, microservices security, and distributed application architectures
  • Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar.

Soft skills:

  • Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholders
  • Able to work effectively with product, engineering, platform, infrastructure, and security teams
  • Proactive attitude, always on the look-out for improving your and our way of working
  • Strong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practices
  • Strong relationship building skills across diverse cross-functional teams
  • Comfortable operating independently and taking ownership of security initiatives from discovery through implementation
  • Able to provide practical security guidance that enables teams to move quickly and securely

Nice to Haves:

  • Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similar
  • Experience with bug bounty programs and coordinating vulnerability remediation with third party
  • Experience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworks
  • Experience building internal security tooling or developer-facing security automation
  • Contributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures

This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..

Benefits

  • Global leave benefit
    • 22 weeks paid parental leave
    • 2 weeks paid grandparent leave
    • Extended care and bereavement leave
  • Life insurance policy
  • Pension Plan
  • Central Amsterdam Location
  • Discount CZ insurance
  • Working in a multicultural environment - 45 different nationalities
  • Commuting allowance for public transport & subsidized lunch
  • Wellness benefits (Headspace subscription & wellness webinars)
  • Hybrid friendly
  • Work-from-home assistance
  • Educational Opportunities
    • Individual skill development & growth programming
  • Social hours & events and team-building
  • 26 vacation days per year

FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.

To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.

Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.

Read the full description
Security Azure Cloud Security Engineer - 100% Remote at CENSUS

Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.

Mid Remote Posted 13 days ago RemoteFirstJobs Product
What this role involves

CENSUS’ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.

We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.

Key Responsibilities

  • Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.

  • Design and support the implementation of secure Azure cloud architectures.

  • Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.

  • Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.

  • Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.

  • Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).

  • Ensure that the implemented solutions align with the product’s security architecture, requirements and threat model.

  • Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.

  • Document and present product security risks in both technical and business contexts.

Minimum Qualifications

  • MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.

  • 3 + years of experience in IT or Cybersecurity

  • 2 + years of experience in cloud applications or cloud security related roles – preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.

  • Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).

  • Problem solving skills, analytical thinking and willingness to learn/grow.

  • Proficient in English.

Required Skills

Experience with:

  • Designing, implementing and auditing cloud platform security architecture and engaged technologies.

  • The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).

  • Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.

  • Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.

  • DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.

  • Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.

  • Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.

  • Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).

  • Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.

Nice-to-Have Skills

  • Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.

  • Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.

  • Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).

  • Familiarity with debugging, instrumenting and profiling software running on cloud platforms.

  • Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.

  • Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.

  • Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.

  • Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.

  • Experienced in working with international teams in other regions and time zones worldwide.

#LI-Remote

Read the full description
Security Cyber Security Engineer (Compliance, Cloud Security & IT Security)

Designs and implements security controls across compliance, cloud infrastructure, and IT systems to strengthen organizational security posture.

Mid Posted 13 days ago Himalayas
What this role involves
We’re hiring a hands-on Cyber Security Engineer to own and elevate the security posture of our organization end-to-end.
Read the full description
Security Active Directory Services / Entra Engineer (Hybrid) at AbbVie

Designs, deploys, and maintains Microsoft Entra ID and Active Directory solutions for enterprise identity and access management across a global workforce.

Mid Hybrid Posted 14 days ago RemoteFirstJobs Product
What this role involves

Company Description

About AbbVie

AbbVie’s mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people’s lives across several key therapeutic areas including immunology, oncology, and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.

Job Description

Join AbbVie’s Information Security & Risk Management (ISRM) team as an IAM Directory Services Engineer, where we empower our partners to succeed by delivering the knowledge, tools, and support needed to leverage data and technology securely and effectively. As part of our Identity & Access Management (IAM) team, you will play a pivotal role in shaping and executing our enterprise-wide IAM strategy.

The ideal candidate will have deep expertise in Microsoft Entra ID (formerly Azure AD), Active Directory, Certificate Services, supporting related authentication tools, and PowerShell scripting experience to design, implement, and manage Directory and Authentication solutions for our global workforce of 80,000 users.

Responsibilities:

  • Designing, deploying, and maintaining Microsoft Entra ID (formerly Azure AD) solutions, including conditional access policies, application integrations, multi-factor authentication (MFA), single sign-on (SSO), and Zero Trust.
  • Designing and managing custom roles and RBAC (Role-Based Access Control) in Entra ID for granular access management across hybrid and multi-cloud environments.
  • Developing and maintaining PowerShell scripts to automate identity management tasks, streamline processes, and enhance operational efficiency.
  • Aligning Entra ID and hybrid identity controls with security best practices through ongoing configuration hardening, policy tuning, and operational guardrails (e.g., Zero Trust patterns, privileged access controls).
  • Collaborating with cross-functional teams to integrate enterprise applications and cloud platforms with Directory and Authentication Services.
  • Performing advanced troubleshooting and root cause analysis of complex Entra ID and Active Directory authentication and authorization issues.
  • Administering and supporting certificate lifecycle management and authentication infrastructure, including Active Directory Certificate Services (AD CS), SCEP/NDES configurations, and endpoint credential and password management tools such as SpecOps and LastPass.
  • Staying current with industry trends and emerging technologies in IAM, AD, Azure, and related fields.

Qualifications

  • Bachelor Degree with 5 years’ experience OR Master’s Degree with 4 years’ experience
  • Respective years of demonstrated experience with a focus on Entra ID/Azure AD and Active Directory.
  • Advanced proficiency in PowerShell scripting for automation and management of identity systems.
  • Hands-on experience with Active Directory, Entra ID features, including conditional access, MFA, SSO, and Entra ID Connect.
  • Experience supporting certificate and authentication services, including Active Directory Certificate Services (AD CS).
  • Excellent problem-solving skills and ability to work in a fast-paced, global environment.
  • Strong collaboration skills across engineering, security, and operations teams
  • In-depth knowledge of securing identity platforms and hybrid directory environments, including threat modeling and control design
  • Strong communication skills with the ability to document designs, drive implementation plans, and coordinate deliverables with stakeholders

Preferred:

  • 5 years’ experience with a focus on Entra ID/Azure AD and Active Directory.
  • Microsoft certifications such as Microsoft Certified: Identity and Access Administrator Associate or Microsoft Certified: Azure Solutions Architect Expert.
  • Experience supporting large-scale environments (10,000+ users; 80,000+ users preferred).
  • Familiarity with cloud platforms like AWS or Google Cloud for hybrid identity solutions.
  • Knowledge of security best practices and compliance frameworks (e.g., NIST, ISO 27001).
  • Experience with Active Directory (AD) environments, including group policies, user provisioning, directory synchronization, and Certificate Services.
  • Familiarity with PKI and certificate services administration (AD CS, SCEP/NDES) for issuing and managing device and user certificates supporting authentication use cases.

Additional Information

​Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: ​

  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. ​
  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.​
  • This job is eligible to participate in our short-term incentive programs. ​

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of  any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company’s sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law. ​

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.  Equal Opportunity Employer/Veterans/Disabled.

US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

Read the full description
Security Toptal: Network Security Engineer — Aruba & HPE | Remote

Designs, implements, and secures enterprise network infrastructure using Aruba and HPE technologies while managing firewalls, VPNs, and security controls.

Mid Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote
URL: https://www.toptal.com/

About the Role

We're looking for a Network Security Engineer to design, implement, and secure enterprise network infrastructure built on Aruba and HPE technologies. This is a hands-on role spanning both network engineering and security — you'll be responsible for building reliable network architecture while ensuring it's hardened against modern threats. If you can move fluidly between network design and security enforcement, this role is built for that.

What You'll Do

  • Design, configure, and maintain enterprise network infrastructure using Aruba and HPE hardware and platforms

  • Implement and manage network security controls, including firewalls, VPNs, and access control policies

  • Monitor network traffic and security events to identify and respond to potential threats

  • Conduct network security assessments and vulnerability analysis

  • Design and enforce network segmentation, VLANs, and wireless security architecture

  • Troubleshoot network performance, connectivity, and security incidents

  • Maintain documentation for network architecture, configurations, and security policies

  • Collaborate with IT and security teams to align network infrastructure with broader security standards

  • Support compliance efforts related to network and IT security requirements

  • Stay current on emerging network security threats and Aruba/HPE platform capabilities

What You Bring

  • Strong hands-on experience with Aruba networking and security products

  • Experience with HP Enterprise (HPE) infrastructure and platforms

  • Solid background in IT security, including threat identification and mitigation

  • Strong network engineering skills, including routing, switching, and wireless architecture

  • Practical experience implementing network security best practices and controls

  • Ability to troubleshoot complex network and security issues independently

  • Strong documentation and communication skills for cross-functional collaboration

Nice to Have

  • Relevant certifications (e.g., Aruba Certified, HPE certifications, Security+, CCNA/CCNP Security)

  • Experience with network access control (NAC) solutions

  • Familiarity with SIEM tools and security monitoring platforms

  • Experience supporting compliance frameworks (e.g., PCI-DSS, HIPAA, ISO 27001)

To apply: https://weworkremotely.com/remote-jobs/toptal-network-security-engineer-aruba-hpe-remote

Read the full description
Security Security Engineer / Analyst at Ladder

Security Engineer who manages vulnerability lifecycle, conducts code reviews, monitors cloud infrastructure, and supports compliance audits across development teams.

Mid Remote Posted 15 days ago RemoteFirstJobs Product
What this role involves

Security Engineer / Analyst

Please note, this is a remote role based in one of the 23 States Ladder is currently hiring in - AZ, CA, CO, CT, FL, GA, IA, KS, MA, MD, MN, NC, NH, NJ, NV, NY, OH, OR, PA, TX, VA, WA, WI with the exception of the following cities: SF Bay Area, New York City, and Seattle.

About Ladder

We saw a problem within the life insurance industry: getting covered took too long, involved too much paperwork, and required too many in-person meetings with sales agents. Having lost his father at a young age, our CEO, Jamie, was determined to make it easier for people to get the coverage they needed to provide for their families. So, we got to work. We developed a method of real-time underwriting leveraging AI and, in doing so, reduced the months-long process of applying for life insurance to minutes. Our digital experience is quick (instant decisions!), loved by users (check out our Trustpilot or Google reviews) and prolific ($74 billion+ in coverage provided).

About the Role

We are looking for a cybersecurity unicorn. A Security Engineer / Analyst who brings a rare blend of application security engineering and risk management maturity. In this role, you will be the driving force behind our vulnerability management lifecycle, balancing day-to-day security operations with development-facing vulnerability management and compliance.

Your primary mission will be embedded within our development lifecycles, taking ownership of application security vulnerability management for our engineering teams. Because our backend infrastructure runs heavily on Clojure, you won’t just be running automated scanners, you will actively look at code and leverage your functional programming experience to strengthen our shift-left security philosophy. Beyond AppSec, you will wear multiple hats: monitoring our cloud infrastructure and responding to alerts, conducting security risk reviews, supporting compliance audits, and ensuring our day-to-day workspace remains locked down.

The ideal candidate is well-rounded and has the ability to interact with all levels of management and external auditors, and operate effectively in a rapidly scaling, dynamic environment.We are looking for someone who is organized, self-motivated, has excellent problem-solving and writing skills, and enjoys working with people in a challenging and fast-paced environment. In this role, you will have the opportunity to drive innovation within the reporting function and help build out the accounting function.

Please note, Ladder is not currently sponsoring or transferring OPT or H1-B visa’s.

What You’ll Do

  • Secure the Code (Primary): Partner directly with development teams to champion application security vulnerability management. You will triage vulnerabilities within a high-scale Clojure ecosystem and assist with remediation code fixes.
  • Security Ops: Configure, fine-tune, and monitor our cloud security posture leveraging Security Operations tools (SIEM, SOAR, CSP, CNAPP) to detect and respond to threats in real time.
  • Champion Governance & Risk: Conduct thorough Security Reviews and risk assessments on internal architecture, third-party vendors, and APIs to ensure alignment with our corporate risk tolerance and compliance standards.
  • Protect the Workspace: Maintain and optimize our day-to-day corporate workspace security, ensuring identity access management, device compliance, and productivity tools are highly secure yet frictionless for the team.
  • Drive Technical Excellence: Act as a security advocate across teams. Mentor engineers on secure coding practices, establish secure defaults, and make practical risk decisions that scale with our growth

Experience Required

  • An Experienced Security Professional: 4+ years of software engineering and/or cybersecurity experience, backed by a strong foundation in Computer Science, Cyber Security, or a related field.
  • Clojure-Capable: Hands-on experience coding in Clojure and working within the JVM environment. You are comfortable reading functional code, understanding immutable data structures, and collaborating directly with backend engineers on code-level fixes.
  • A Cloud SecOps Practitioner: Hands-on experience securing modern cloud infrastructures, as well as experience working incident response.
  • An Autonomous Systems Thinker: Thrive in dynamic environments. You don’t just clear alerts; you look for the root cause of issues to design security frameworks that prevent entire classes of vulnerabilities from happening in the first place.
  • Certified Professional: Hold baseline certifications such as CompTIA Security+ or equivalents. Having an advanced credential like the CISSP is highly preferred and considered a major plus.

Technologies Used

  • Backend & Code: Clojure, JVM, TypeScript, JavaScript
  • Cloud & Infrastructure: GCP, Kubernetes, Docker, Terraform, GraphQL
  • Security & Data Operations: Google Security Command Center, Chronicle, Datomic, BigQuery, Kafka

What we Offer

Ladder is highly collaborative and fun. To support you in your role, we offer fantastic perks and benefits that reflect our mission of care and support, including:

  • Excellent medical, dental, and vision coverage | We offer competitive healthcare, dental and vision plans for you and your family.
  • Flexible paid time off | Take the time that you need to rest and recharge, including our week-long winter holiday closure.
  • Stock options | We offer competitive stock option packages to participate in the success of building Ladder.
  • A rewarding 401k match program | We’ll match up to 4% of your contributions as you save for your retirement goals.
  • Ladder Fit Program | Your health matters. That’s why Ladder provides a monthly stipend for wellness-related expenses.
  • Paid parental leave |We think it’s crucial that new parents have time to adjust to their new lives without worrying about work, so we provide all parents inclusive of birthing, adoption, or fostering ten weeks of paid baby bonding.
  • Work-from-home flexibility and support | We recognize that everyone’s homelife is different and support remote work. Upon joining, we provide a one-time remote office stipend for all team members and then a monthly stipend to cover WFH costs such as the internet.
  • Fun company-wide events | We genuinely enjoy spending time together. That’s why we plan fun virtual events to let loose and laugh.

Base pay for this role is determined by the location where the work will be performed and is aligned with the two compensation tiers, as indicated below. Base pay may vary depending on job-related knowledge, skills, experience, and business needs. In addition to the base pay range listed below, this role is also eligible for equity and benefits as shared above.

Tier 1 (San Francisco, New York)

$122,000 - $144,000

Tier 2 & Tier 3 (All other locations that Ladder hires)

$109,000 - $130,000

Ladder is building a diverse team of talented and enthusiastic people. We are an equal opportunity workplace. At Ladder, differences are celebrated and supported to benefit our people, product, and community. Let us know why you’re interested in this position and what unique contributions you can make to the Ladder team. We look forward to hearing from you.

Research shows that candidates from underrepresented backgrounds often don’t apply for roles if they don’t meet all the criteria – unlike majority candidates meeting significantly fewer requirements. We strongly encourage you to apply if you’re interested: we’d love to know how you can elevate our team with your unique experience!

By clicking “Submit Application,” you acknowledge that you have read and agree to the Ladder Job Applicant Privacy Policy and Notice at Collection.

Read the full description
Security Cyber & AI Risk Analyst at Alpaca

Identifies, assesses, and documents cybersecurity and AI-related risks while supporting risk management frameworks and AI governance controls across infrastructure and products.

Mid Remote Posted 16 days ago RemoteFirstJobs Product
What this role involves

Who We Are:

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24⁄5 trading, and more.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We’re deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.

Our Team Members:

We’re a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!

We’re searching for passionate individuals eager to contribute to Alpaca’s rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role:

As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca’s security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of  cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.

You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.

This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. You’ll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.

We’re looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the group up - then this role is for you. Prior GRC experience is a plus, but not required, we’re happy to invest in the right candidate.

Things You Get To Do:

  • Support the execution of Alpaca’s cybersecurity risk management program
  • Conduct cyber risk assessments across cloud infrastructure , APIs, trading systems, and internal platforms
  • Assist in identifying, documenting, and evaluating AI-related risks (model risk, data privacy, bias, explainability, adversarial threats, model misuse)
  • Help develop and maintain AI governance controls aligned with evolving regulatory expectations such as the EU AI Act
  • Perform third-party/vendor security and AI risk assessments
  • Contribute to control testing across frameworks such as SOC 2, ISO 27001, CSA Star, NIST CSF, and emerging AI governance standards
  • Track remediation efforts and maintain risk registers and reporting dashboards
  • Support internal and external audits by preparing documentation and evidence
  • Monitor regulatory developments related to cybersecurity, financial services, and AI governance
  • Help mature policies, standards, and procedures for both cyber and AI domains
  • Support the development of a repeatable AI tool/model evaluation process (intake → review → decision) for new and in-use AI tools
  • Support Alpaca’s AI usage guidance and standards, including safe use of AI-enabled developer tools and assistants
  • Help maintain AI logging/monitoring standards (audit logging, evidence) for AI systems
  • Use AI tools in day-to-day work and help test how well AI-related controls are working

Who You Are (Must-Haves):

  • 1+  years of experience in cybersecurity, risk management, IT audit, GRC, or a related field - internships, coursework, or equivalent experience is welcome
  • Foundational understanding of cybersecurity principles (network security, cloud security, IAM, application security, vulnerability management)
  • Familiarity with common frameworks such as NIST CSF, ISO 27001, SOC 2, or similar
  • Understanding of AI/ML concepts and associated risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.) - you don’t need to be an expert, just curious
  • Strong written communication and documentation skills
  • Ability to assess technical risks and clearly communicate them to non-technical stakeholders
  • Experience working cross-functionally with engineering and product teams
  • Highly organized with strong attention to detail
  • Comfort working in a fast-paced environment
  • Genuine curiosity about AI and a strong desire to learn, actively experiments with AI tools, and wants to grow AI fluency as the field evolves
  • Comfort using AI tools daily and willingness to learn newer agentic / assistant-based tooling

Who You Might Be (Nice-to-Haves):

  • Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms
  • Exposure to AI governance, model risk management, or responsible AI programs
  • Familiarity with emerging AI regulatory frameworks (e.g., NIST AI RMF, EU AI Act concepts, model governance practices)
  • Experience with GCP or other major cloud platforms
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
  • Security certifications (e.g., Security+, SSCP) or early-stage GRC certifications
  • Interest in pursuing advanced certifications (CISA, CRISC, CISSP, or AI governance certifications)
  • Experience working remotely or in distributed teams
  • Hands-on experience with AI/agentic tooling (e.g., AI coding assistants, LLM apps, or similar)
  • Personal projects or self-study in AI/ML that show initiative and interest

How We Take Care of You:

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

Read the full description
Security Cyber & AI Risk Analyst at Alpaca

Identifies, assesses, and documents cybersecurity and AI-related risks across infrastructure, products, and trading systems while establishing AI governance controls.

Mid Remote Posted 16 days ago RemoteFirstJobs Product
What this role involves

Who We Are:

Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24⁄5 trading, and more.

Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.

Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. We’re deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.

Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.

Our Team Members:

We’re a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!

We’re searching for passionate individuals eager to contribute to Alpaca’s rapid growth. If you align with our core values—Stay Curious, Have Empathy, and Be Accountable—and are ready to make a significant impact, we encourage you to apply.

Your Role:

As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca’s security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of  cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.

You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.

This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. You’ll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.

We’re looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the group up - then this role is for you. Prior GRC experience is a plus, but not required, we’re happy to invest in the right candidate.

Things You Get To Do:

  • Support the execution of Alpaca’s cybersecurity risk management program
  • Conduct cyber risk assessments across cloud infrastructure , APIs, trading systems, and internal platforms
  • Assist in identifying, documenting, and evaluating AI-related risks (model risk, data privacy, bias, explainability, adversarial threats, model misuse)
  • Help develop and maintain AI governance controls aligned with evolving regulatory expectations such as the EU AI Act
  • Perform third-party/vendor security and AI risk assessments
  • Contribute to control testing across frameworks such as SOC 2, ISO 27001, CSA Star, NIST CSF, and emerging AI governance standards
  • Track remediation efforts and maintain risk registers and reporting dashboards
  • Support internal and external audits by preparing documentation and evidence
  • Monitor regulatory developments related to cybersecurity, financial services, and AI governance
  • Help mature policies, standards, and procedures for both cyber and AI domains
  • Support the development of a repeatable AI tool/model evaluation process (intake → review → decision) for new and in-use AI tools
  • Support Alpaca’s AI usage guidance and standards, including safe use of AI-enabled developer tools and assistants
  • Help maintain AI logging/monitoring standards (audit logging, evidence) for AI systems
  • Use AI tools in day-to-day work and help test how well AI-related controls are working

Who You Are (Must-Haves):

  • 1+  years of experience in cybersecurity, risk management, IT audit, GRC, or a related field - internships, coursework, or equivalent experience is welcome
  • Foundational understanding of cybersecurity principles (network security, cloud security, IAM, application security, vulnerability management)
  • Familiarity with common frameworks such as NIST CSF, ISO 27001, SOC 2, or similar
  • Understanding of AI/ML concepts and associated risks (data governance, model bias, hallucinations, prompt injection, model misuse, etc.) - you don’t need to be an expert, just curious
  • Strong written communication and documentation skills
  • Ability to assess technical risks and clearly communicate them to non-technical stakeholders
  • Experience working cross-functionally with engineering and product teams
  • Highly organized with strong attention to detail
  • Comfort working in a fast-paced environment
  • Genuine curiosity about AI and a strong desire to learn, actively experiments with AI tools, and wants to grow AI fluency as the field evolves
  • Comfort using AI tools daily and willingness to learn newer agentic / assistant-based tooling

Who You Might Be (Nice-to-Haves):

  • Academic background, personal interest, or real world experience in fintech, financial services, or trading platforms
  • Exposure to AI governance, model risk management, or responsible AI programs
  • Familiarity with emerging AI regulatory frameworks (e.g., NIST AI RMF, EU AI Act concepts, model governance practices)
  • Experience with GCP or other major cloud platforms
  • Experience supporting or observing SOC 2, ISO 27001, or regulatory audits
  • Security certifications (e.g., Security+, SSCP) or early-stage GRC certifications
  • Interest in pursuing advanced certifications (CISA, CRISC, CISSP, or AI governance certifications)
  • Experience working remotely or in distributed teams
  • Hands-on experience with AI/agentic tooling (e.g., AI coding assistants, LLM apps, or similar)
  • Personal projects or self-study in AI/ML that show initiative and interest

How We Take Care of You:

  • Competitive Salary & Stock Options
  • Health Benefits
  • New Hire Home-Office Setup: One-time USD $500
  • Monthly Stipend: USD $150 per month via a Brex Card

Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.

Recruitment Privacy Policy

Read the full description
Security Oracle Cybersecurity Engineer

Designs, implements, and maintains Oracle database security infrastructure, vulnerability assessments, and access controls for enterprise systems.

Mid Remote Posted 16 days ago Himalayas
What this role involves
Oracle Cybersecurity Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description