Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Cyber Security Engineer / Information Systems Security Engineer (ISSE) at OpenTeams

Leads cybersecurity architecture, RMF activities, and compliance for government systems while designing supply chain security controls and integrating security into CI/CD pipelines.

Senior Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

Who We Are

We exist to unlock human potential.

Too often, AI drains it—drains budgets, drains energy resources, drains ownership of data. OpenTeams was founded to change that. We build AI that empowers. Our models are energy-efficient, cost-effective, and fully yours.

Our ethos is open source. That means freedom, trust, and accountability are built into every line of code. We reinvest 3% of our profits back into the open-source community, because we believe tech is most powerful when it serves everyone.

At our core, we value freedom, teamwork, accountability, and uncompromising quality. If you want to challenge the status quo, and shape tools that set people free, OpenTeams is the place to do it.

Location: Remote (US) with travel to customer sites as required (Washington Metro Area preferred)

Employment Type: Full-time

Clearance: Active TS/SCI required

Role Summary

The Cyber Security Engineer / ISSE owns the security architecture and accreditation posture of the depot. This role leads RMF activities, embeds security controls into engineering workflows, and serves as the primary security interface with government assessors and authorizing officials.

Responsibilities

  • Lead RMF activities: control selection, implementation evidence, POA&M management, and ATO support
  • Design and implement supply chain security controls: SBOM generation, artifact signing, vulnerability scanning, and provenance attestation
  • Perform threat modeling and security reviews of depot architecture and workflows
  • Integrate security tooling into CI/CD pipelines and enforce policy gates
  • Support cross-domain and classified environment requirements, including secure transfer procedures
  • Interface with government ISSMs, assessors, and authorizing officials

Required Qualifications

  • Active TS/SCI clearance
  • Experience with Xacta, eMASS, or CSAM
  • 6+ years in cyber security or ISSE roles supporting DoD or IC systems
  • Hands-on experience with RMF, NIST 800-53, and eMASS or equivalent
  • Experience with DevSecOps tooling: container scanning, SAST/DAST, signing, and policy enforcement
  • IAT/IAM Level II or III certification per DoD 8140 (for example Security+, CISSP, or CISM)

Preferred Qualifications

  • Experience securing AI/ML systems or software supply chains at scale
  • Familiarity with cATO approaches and continuous monitoring
  • Experience with IL5/IL6 or cross-domain solutions

Grow With Us

At OpenTeams, growth isn’t just about the company—it’s about you.

We believe the best careers are built at the edge of your potential. That is where new tools, ideas, and technologies change the world. Here, you’ll work alongside pioneers of AI, solving problems that matter: making AI more transparent, more ethical, and more empowering. As your skills grow, our career framework provides a pathway and recognition of that increased impact.

Opportunities aren’t limited by geography. You’ll collaborate with global experts, contribute to open source projects that power the world’s technology, and stretch your skills daily.  That global perspective and diversity makes our solution more universal and robust.  We are committed to continuing to celebrate diversity on our team.

Supported people are successful people.  We offer 100% employer paid medical premiums for employees and self-managed PTO with a minimum time off requirement, so that our teams are able to do their best work.

We invest  in curiosity, creativity, and ownership. That means you’ll be trusted to boldly innovate, supported to learn fast, and celebrated for successful collaboration.

Commitment to diversity, equity, inclusion, and belonging

OpenTeams understands that valuing diverse creative practices and forms of knowledge is crucial to and enriches the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, disabled people, persons of all sexual orientations, gender identities and expressions.

We are an equal opportunity employer - all qualified applicants will receive equal consideration for recruitment, interviews, employment, training, compensation, promotion, and related activities. We do not discriminate based on race, religion, gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. OpenTeams will not tolerate discrimination or harassment based on these characteristics or any other unlawful behavior, conduct, or purpose.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Design and harden cloud infrastructure, identity systems, and security automation pipelines while evaluating AI-assisted tools and responding to security incidents.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Designs and hardens cloud infrastructure, builds security automation pipelines, and secures AI-assisted tooling across AWS and identity systems.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Senior Cloud Security Engineer at Rescale

Designs and hardens cloud infrastructure, builds security automation pipelines, and secures AI-assisted tooling across AWS, identity systems, and internal platforms.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Rescale

Rescale is pioneering the future of engineering and scientific discovery. As the leader in digital engineering, we’re transforming how products are developed—through intelligent automation, applied AI, data management, and the integration of the world’s largest network of engineering and R&D applications. Joining Rescale means becoming part of a diverse, collaborative, and mission-driven team that’s unlocking faster innovation across industries like aerospace, energy, life sciences, and manufacturing. We’re solving complex challenges that traditional HPC can’t—and we’re seeking passionate, curious minds to help build the next wave of breakthroughs.

We’re hiring a Senior Cloud Security Engineer to help secure the cloud infrastructure, identity systems, and internal tooling that our platform and our company run on. You’ll work across AWS, Okta, GitHub Enterprise, and increasingly AI-assisted and agentic tooling our employees use daily. This is a hands-on role: you’ll be writing Terraform, querying logs, and designing IAM policy, not just reviewing other people’s work.

What you’ll work on:

  • Design, build, and harden cloud infrastructure and identity systems

  • Build and maintain security automation and detection pipelines

  • Evaluate and help secure the growing set of AI-assisted and agentic tools used internally (e.g., Claude Code, MCP servers, LLM-driven automation)

  • Investigate and respond to security findings, including triaging authentication anomalies, reviewing access logs, and querying data via tools like Athena, CloudTrail Lake, or Superset.

  • Contribute to Infrastructure-as-Code (Terraform) for security controls, identity provisioning, and compliance-relevant configuration and monitoring.

  • Support secure network and cloud deployment designs for enterprise customer environments, partnering with engineering and customer-facing teams on requirements.

  • Research emerging cloud-native and AI security capabilities (including AI-enabled attack techniques) and translate findings into practical controls and internal guidance.

  • Write internal documentation, runbooks, and playbooks to scale security practices across the team.

What we’re looking for:

  • 5+ years of experience in cloud-native security or DevSecOps.

  • 3+ years of experience with Bash or Python.

  • Deep, hands-on experience with a major cloud provider (AWS, Azure, GCP, or OCI.

  • Experience with Infrastructure-as-Code (Terraform or similar) and identity/access management platforms (Okta, Azure AD, or similar).

  • Real exposure to at least one of: OAuth/token architecture, AI/LLM-assisted tooling security, or agentic workflow design

  • Solid understanding of operating systems and networking fundamentals.

  • Bachelor’s degree in Computer Science or related field, or equivalent practical experience, but not required if you have the experience above.

Rescale is an equal opportunities employer and welcomes applications from all qualified persons regardless of their race, sex, disability, religion/belief, sexual orientation or age. As part of our standard hiring process for new employees, employment with Rescale will be contingent upon successful completion of a comprehensive background check. Here at Rescale, we are committed to being transparent in our policies around candidate privacy. For more details on the information Rescale collects in your application, please view the Rescale Applicant Privacy Policy here.

Read the full description
Security Security and Infrastructure Engineer at ada CX

Owns cloud and platform security end-to-end across AWS and Azure, builds automated security capabilities, and sets security standards for an AI customer service platform.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Engineering at Ada

As an Ada engineer, you’ll have the autonomy to make a huge impact and the opportunity to work alongside talented peers who challenge and inspire you. We move fast, take ownership, and always strive to improve, both as individuals and as a team. As a Security Infrastructure Engineer on Ada’s Security Operations team, your work will have a fundamental impact on Ada’s growth: our customers put an AI agent in front of their customers, and it has to be trustworthy by construction.

Our Role

We are looking for a Security Infrastructure Engineer to own cloud and platform security end to end, architecture, detection and response, and platform enablement across AWS and Azure, including the security of our agentic AI platform. This role is not focused on ticket-driven security work: you will replace manual security work with platform capabilities, build guardrails into the product itself, and set the security bar across Product Development. You will operate with a high degree of autonomy, set technical direction that other senior engineers follow, mentor security engineers, and act as the senior technical counterpart to engineering and security leadership translating risk and compliance requirements into concrete engineering solutions.

About You

  • 8+ years of experience in cloud, infrastructure, or security engineering roles, including experience setting technical direction across multiple teams, not just executing within one.
  • Deep hands-on experience with at least one major cloud provider, preferably AWS; Azure experience is a plus.
  • Strong experience designing and securing cloud IAM, networking, secrets management, and distributed systems at scale.
  • Extensive experience with infrastructure as code (Terraform or CloudFormation) and policy as code; you default to automation and preventative controls over manual review.
  • Experience building or operating detection and response systems including SIEM, CSPM/CIEM, and cloud security monitoring.
  • Experience with or a strong point of view on securing LLM and agentic AI systems: guardrails, safe tool use, and failure isolation.
  • A track record of turning recurring security and infrastructure requests into self-serve tooling, retiring ticket queues rather than staffing them.
  • Proven ability to translate compliance and risk requirements into technical implementations.
  • Strong communicator who can influence architecture and engineering decisions across teams, and mentor senior engineers through design reviews and hands-on guidance.
  • Comfortable operating independently, owning long-term technical initiatives, and carrying a share of security-relevant on-call.

What You Will Do

Cloud Security Architecture & Engineering

  • Architect, design, and operate security technologies across cloud, network, identity, endpoint, and application layers in public, private, and hybrid environments.
  • Define cloud security reference architectures, threat models, and guardrails aligned with zero trust and least privilege principles.
  • Own the technical lifecycle of security tooling including cloud-native security services, SIEM, CSPM, CIEM, EDR, DLP, and vulnerability management platforms.

Agentic Platform Security

  • Build safety guardrails into the platform itself so failures like an agent bypassing a playbook safeguard cannot reach a customer.
  • Partner with the Reasoning Engine and Playbooks teams on agent behavior that is safe by construction.
  • Set the security bar inside Product Development: secure-coding standards, review practice, and threat modeling for new agentic features.

Detection, Response & Automation

  • Stand up security observability: detection, alerting, and response for the platform, wired into Datadog and Sentry alongside the wider observability push.
  • Engineer automated response and remediation workflows using cloud-native automation, SOAR, and infrastructure as code.
  • Lead cloud security incident investigations, carry a share of security-relevant on-call, and feed every incident back into tooling so it does not recur.

Self-Serve Security Enablement

  • Turn recurring security and infra requests (access provisioning, environment setup) into self-serve tooling — retire the ticket queue rather than staff it.
  • Embed security into CI/CD pipelines, platform tooling, and deployment workflows using policy as code and automated guardrails, so engineering teams ship faster without compromising security.

Governance, Risk & Compliance Enablement

  • Translate security and regulatory frameworks (NIST SP 800-53, PCI DSS, CIS Benchmarks, AWS Well-Architected) into enforceable technical controls.
  • Lead the engineering side of vendor and dependency security: reviews, least-privilege access, and cutting overlapping tools from the stack.
  • Support audits, risk assessments, and evidence collection with internal compliance and external assessors.

Technical Leadership

  • Serve as the subject matter expert for cloud and platform security and its relationship to Ada’s business-critical systems.
  • Mentor security and platform engineers through documentation, design reviews, and hands-on guidance.
  • Operate with high autonomy, making architectural decisions that shape long-term security posture and platform scalability.

Outcomes

  • Own secure-by-default infrastructure for the agentic platform across AWS and Azure: identity, secrets management, network boundaries, and access control.
  • Establish a secure-by-default cloud security architecture that scales with Ada’s growth, reducing risk through automation and preventative controls.
  • Close the guardrail gaps that could let unauthorized agent actions reach a customer.
  • Improve detection, response, and incident readiness across cloud environments.
  • Enable engineering teams to ship faster without compromising security, and raise the bar for security engineering maturity across the organization.
  • First 90 days: map the current attack surface and access model, ship one self-serve replacement for a high-volume manual security request, and close the guardrail gap that let unauthorized actions through.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Security and Infrastructure Engineer at ada CX

Designs and implements cloud security infrastructure, detection systems, and platform controls across AWS/Azure to secure Ada's AI customer service platform.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Engineering at Ada

As an Ada engineer, you’ll have the autonomy to make a huge impact and the opportunity to work alongside talented peers who challenge and inspire you. We move fast, take ownership, and always strive to improve, both as individuals and as a team. As a Security Infrastructure Engineer on Ada’s Security Operations team, your work will have a fundamental impact on Ada’s growth: our customers put an AI agent in front of their customers, and it has to be trustworthy by construction.

Our Role

We are looking for a Security Infrastructure Engineer to own cloud and platform security end to end, architecture, detection and response, and platform enablement across AWS and Azure, including the security of our agentic AI platform. This role is not focused on ticket-driven security work: you will replace manual security work with platform capabilities, build guardrails into the product itself, and set the security bar across Product Development. You will operate with a high degree of autonomy, set technical direction that other senior engineers follow, mentor security engineers, and act as the senior technical counterpart to engineering and security leadership translating risk and compliance requirements into concrete engineering solutions.

About You

  • 8+ years of experience in cloud, infrastructure, or security engineering roles, including experience setting technical direction across multiple teams, not just executing within one.
  • Deep hands-on experience with at least one major cloud provider, preferably AWS; Azure experience is a plus.
  • Strong experience designing and securing cloud IAM, networking, secrets management, and distributed systems at scale.
  • Extensive experience with infrastructure as code (Terraform or CloudFormation) and policy as code; you default to automation and preventative controls over manual review.
  • Experience building or operating detection and response systems including SIEM, CSPM/CIEM, and cloud security monitoring.
  • Experience with or a strong point of view on securing LLM and agentic AI systems: guardrails, safe tool use, and failure isolation.
  • A track record of turning recurring security and infrastructure requests into self-serve tooling, retiring ticket queues rather than staffing them.
  • Proven ability to translate compliance and risk requirements into technical implementations.
  • Strong communicator who can influence architecture and engineering decisions across teams, and mentor senior engineers through design reviews and hands-on guidance.
  • Comfortable operating independently, owning long-term technical initiatives, and carrying a share of security-relevant on-call.

What You Will Do

Cloud Security Architecture & Engineering

  • Architect, design, and operate security technologies across cloud, network, identity, endpoint, and application layers in public, private, and hybrid environments.
  • Define cloud security reference architectures, threat models, and guardrails aligned with zero trust and least privilege principles.
  • Own the technical lifecycle of security tooling including cloud-native security services, SIEM, CSPM, CIEM, EDR, DLP, and vulnerability management platforms.

Agentic Platform Security

  • Build safety guardrails into the platform itself so failures like an agent bypassing a playbook safeguard cannot reach a customer.
  • Partner with the Reasoning Engine and Playbooks teams on agent behavior that is safe by construction.
  • Set the security bar inside Product Development: secure-coding standards, review practice, and threat modeling for new agentic features.

Detection, Response & Automation

  • Stand up security observability: detection, alerting, and response for the platform, wired into Datadog and Sentry alongside the wider observability push.
  • Engineer automated response and remediation workflows using cloud-native automation, SOAR, and infrastructure as code.
  • Lead cloud security incident investigations, carry a share of security-relevant on-call, and feed every incident back into tooling so it does not recur.

Self-Serve Security Enablement

  • Turn recurring security and infra requests (access provisioning, environment setup) into self-serve tooling — retire the ticket queue rather than staff it.
  • Embed security into CI/CD pipelines, platform tooling, and deployment workflows using policy as code and automated guardrails, so engineering teams ship faster without compromising security.

Governance, Risk & Compliance Enablement

  • Translate security and regulatory frameworks (NIST SP 800-53, PCI DSS, CIS Benchmarks, AWS Well-Architected) into enforceable technical controls.
  • Lead the engineering side of vendor and dependency security: reviews, least-privilege access, and cutting overlapping tools from the stack.
  • Support audits, risk assessments, and evidence collection with internal compliance and external assessors.

Technical Leadership

  • Serve as the subject matter expert for cloud and platform security and its relationship to Ada’s business-critical systems.
  • Mentor security and platform engineers through documentation, design reviews, and hands-on guidance.
  • Operate with high autonomy, making architectural decisions that shape long-term security posture and platform scalability.

Outcomes

  • Own secure-by-default infrastructure for the agentic platform across AWS and Azure: identity, secrets management, network boundaries, and access control.
  • Establish a secure-by-default cloud security architecture that scales with Ada’s growth, reducing risk through automation and preventative controls.
  • Close the guardrail gaps that could let unauthorized agent actions reach a customer.
  • Improve detection, response, and incident readiness across cloud environments.
  • Enable engineering teams to ship faster without compromising security, and raise the bar for security engineering maturity across the organization.
  • First 90 days: map the current attack surface and access model, ship one self-serve replacement for a high-volume manual security request, and close the guardrail gap that let unauthorized actions through.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Application Security Engineer II at Abnormal AI

Application security engineer secures AI-powered cloud systems by leading threat modeling, building security tooling, designing automated testing, and coaching developers on secure practices.

Senior Posted 4 days ago RemoteFirstJobs Product
What this role involves

About the Role

Abnormal AI is looking for an Application Security Engineer II to secure the AI-powered systems at the core of our AWS-based platform (LLM-integrated features, agentic workflows, MCP connectors, and the model supply chain) against threats like prompt injection at production scale. This is an individual contributor role that blends deep application security expertise with strong engineering fundamentals. You’ll focus on integrating security into every phase of our software development lifecycle, conducting comprehensive security reviews, and partnering with engineering teams to build defensible architectures.

You will own the security architecture and development of secure coding practices while ensuring security is a foundational partner to our engineering stakeholders. You’ll coach developers across the engineering organization on application security principles, act as a technical liaison across teams, and contribute directly to keeping our applications and customers secure. This role reports to the Director of Security Engineering.

What you will do

  • Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions, with particular focus on AI-powered features (LLM integrations, agentic workflows, MCP connectors).
  • Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
  • Design and deploy automated security testing to identify vulnerabilities early in the development process.
  • Serve as a hands-on technical contributor during security incidents by analyzing application-level behavior and enhancing response processes.
  • Coach developers on secure coding, security architecture, and threat modeling for AI-native systems.
  • Define and track key security posture metrics, building dashboards or reports to visualize security coverage and vulnerability trends.

Must Haves

  • 5+ years of experience in application security engineering roles, ideally securing AWS or comparable cloud-native environments with modern development practices.
  • Experience securing AI/ML-powered systems, or a clear ability to ramp fast on prompt injection, model supply chain, and agentic-workflow risks.
  • Strong programming skills in Python, Go, Java, or JavaScript/TypeScript. You write and read production code, not just review it.
  • Expertise in web application security including OWASP Top 10, authentication/authorization, cryptography, and secure API design, including securing modern architectures (microservices, containers, cloud-native).
  • Hands-on experience threat modeling and running security architecture reviews.
  • Proven ability to influence and collaborate cross-functionally with engineering, DevOps, and product teams, with strong written communication.

Nice to Have

  • Experience working in fast-paced or startup environments, comfortable defining scope in a growing security program.
  • Hands-on experience with commercial security tools (Veracode, Checkmarx, SonarQube, Wiz, Semgrep, Burp Suite)
  • Prior experience building security telemetry pipelines or vulnerability management frameworks.
  • Exposure to compliance frameworks (SOC 2, ISO 27001) and how development decisions affect auditability.
  • Familiarity with bug bounty programs and vulnerability disclosure processes.

#LI-PP1

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.

In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:

$130,100—$187,000 USD

AI and our hiring process

Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and identify areas for the interviewer to explore. They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Read the full description
Security Senior Information System Security Officer (Senior ISSO) (R-00185)

Senior ISSO oversees information security policies, compliance, risk management, and security posture across organizational systems and infrastructure.

Senior Posted 4 days ago Himalayas
What this role involves
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes.
Read the full description
Security Senior Cloud Security Engineer at Iterable

Leads cloud security initiatives across development lifecycle, implementing automated security measures and vulnerability assessments to protect customer data and systems.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Iterable is the leading AI-powered customer engagement platform that helps leading brands like Redfin, SeatGeek, Priceline, Calm, and Box create dynamic, individualized experiences at scale. Our platform empowers organizations to activate customer data, design seamless cross-channel interactions, and optimize engagement—all with enterprise-grade security and compliance. Today, nearly 1,200 brands across 50+ countries rely on Iterable to drive growth, deepen customer relationships, and deliver joyful customer experiences.

Our success is powered by extraordinary people who bring our core values—Be an Owner, Growth Mindset, Run as One, Transparency —to life. We foster a culture of innovation, collaboration, and inclusion, where ideas are valued and individuals are empowered to do their best work. That’s why we’ve been recognized as one of Inc’s Best Workplaces and Fastest Growing Companies, and were recognized on Forbes’ list of America’s Best Startup Employers in 2022. Notably, Iterable has also been listed on Wealthfront’s Career Launching Companies List and has held a top 10 ranking on the Top 25 Companies Where Women Want to Work.

With a global presence—including offices in San Francisco, Denver, London, Sydney, and Lisbon, plus remote employees worldwide—we are committed to building a diverse and inclusive workplace. We welcome candidates from all backgrounds and encourage you to apply. Learn more about our story and mission on our Culture and About Us pages. Let’s shape the future of customer engagement together!

How you will make an impact:

Customers trust Iterable with sensitive information, expecting us to safeguard their data. Iterable’s Security team leads a cross-functional effort across the company to ensure that all systems remain secure in support of Iterable’s core values, and to provide assurance to our customers that we will be good stewards of their valued data. The Security team actively leads the effort to improve Iterable’s security posture in concert with other groups as they develop or launch new features and services. As Engineers, we believe in security through automation, assessments, technical reviews and vulnerability evaluation. Our footprint spans across the entire company at all levels, throughout the complete development lifecycle.

We aim to create a compelling, well-documented, and holistically managed security program. We are looking for individuals to join our vibrant Security Engineering team to move the current state of security to the next level. We strive to improve our cloud security capabilities, and support our peers in building an amazing product through creating an environment which fosters security by design. To summarize, we want you to share and be a part of our grand plan!

One of our core values is “Growth Mindset,” and Iterable is a company where everyone can grow. If this is a role that excites you, please apply as we value applicants for the skills they bring beyond a job description.

In this role you’ll get to:

  • Review system designs and implementations, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices, document and ensure security issues are appropriately remediated
  • Leverage subject matter expertise of systems and infrastructure to propose solutions and drive architectural improvements which address classes of security vulnerabilities
  • Develop and implement cloud and infrastructure security architecture and contribute to overall strategy and roadmap plans
  • Participate in the selection, design, development, implementation, and management of automated security testing tools, such as cloud security posture management and image vulnerability scanners
  • Implement solutions that integrate into CI pipelines to shift security as far left as possible and raise concerns early to engineering teams.
  • Promote DevSecOps principles and implement Infrastructure as Code (IaC) scanning and policy enforcement to ensure deployments via Terraform, AWS CloudFormation, or similar, are secure and compliant with standards and guidelines
  • Coordinate and participate in penetration tests of our cloud services

We are looking for people who have:

  • 5+ years hands-on-keyboard in Cloud Security, SRE, DevOps, DevSecOps, or Infra Engineering.
  • Strong working knowledge of Kubernetes and ecosystem tools such as helm, ArgoCD.
  • Production experience with AWS services, particularly AWS Organizations, AWS Identity (SSO), Identity and Access Management (IAM), Service Control Policies (SCPs), Virtual Private Clouds, Elastic Load Balancers, AWS CloudTrail, and Security Groups.
  • Proficiency with Terraform.
  • Experience developing custom actions or workflows in Github or Gitlab.
  • Solid understanding of cloud security vulnerabilities defense techniques and security best practices, including AWS security practices and present-day threats
  • Proficiency in a high level programming language, such as Python or Go
  • Familiarity with policy management tools such as OPA or Kyverno

Bonus points:

  • SRE Experience
  • Scala or JVM ecosystem experience
  • Familiarity with common observability tools such as Datadog, Prometheus/Grafana
  • Experience with AWS EKS
  • Experience with Panther SIEM
  • Hands on work standing up Jupyter notebook instances, using Jupyter operationally.

Perks & Benefits:

  • Competitive salaries, meaningful equity, & 401(k) plan
  • Medical, dental, vision, & life insurance
  • Balance Days (additional paid holidays)
  • Fertility & Adoption Assistance
  • Paid Sabbatical
  • Flexible PTO
  • Monthly Employee Wellness allowance
  • Monthly Professional Development allowance
  • Pre-tax commuter benefits
  • Complete laptop workstation

The US base salary range for this position at the start of employment is $141,000 - $221,000. Within this range, individual pay is determined by specific US work location, as well as additional factors, including job-related skills, experience, relevant education or training, and internal equity considerations.

Please note that the range listed above reflects only base salary. The total compensation package includes variable pay (where applicable), equity, plus a range of benefits, including medical, dental, vision, and financial. In addition, we offer perks such as generous stipends for health & fitness and learning & development, among others.

Recruitment Disclaimer:

Please be aware that Iterable, Inc. (“Iterable”) and our official professional recruiting agencies and platforms do not:

  • Send job offers from free email services like Gmail, Yahoo mail, Hotmail, etc.
  • Request money, fees, or payment of any kind from prospective candidates to apply to Iterable, for employment, or for the recruitment process (e.g. for home office supplies, or training, etc.).
  • Request or require personal documents like bank account details, tax forms, or credit card information as part of the recruitment process prior to the candidate signing an engagement letter or an employment contract with Iterable.

You may see all job vacancies on our official Iterable channels:

  • Official Iterable website, Careers page: https://iterable.com/careers/
  • Official LinkedIn Jobs page: https://www.linkedin.com/company/iterable/jobs/

Iterable is not affiliated in any way to these impostors and we hereby confirm that such individuals/entities are not authorized, encouraged, or sponsored to act on behalf of Iterable. Such job opportunities are entirely fake and not valid. Therefore, please disregard any written or oral request for a job offer or an interview that you believe is or might be fraudulent or suspicious and immediately reach out to us via email at talent-ops@iterable.com upon receiving a suspicious job offer.

Criminal and/or civil liabilities may arise from such actions, and Iterable expressly reserves the right to take legal action, including criminal action, against such individuals/entities whenever such phenomena occur. In any case, please note that under no circumstances shall Iterable and any of its affiliates be held liable or responsible for any claims, losses, damages, expenses or other inconvenience resulting from or in any way connected to the actions of these impostors.

Iterable is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. Iterable does not make hiring or employment decisions on the basis of race, color, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender-identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws or prohibited by Company policy. Iterable also strives for a healthy and safe workplace and strictly prohibits harassment of any kind. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Iterable will also consider for employment qualified applicants with arrest and conviction records.

Read the full description
Security Senior Security Engineer at SmarterDx

Owns detection engineering and security operations, writing/tuning SIEM detections in Panther, investigating alerts, running cloud security operations in AWS, and executing incident response.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at smarterdx.com/careers.

Role

SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. This role is our hands-on owner of detection engineering and security operations. You will turn our detection platform into real coverage: writing and tuning detections in Panther, keeping alerts high-signal, running the SIEM as it grows, and being on point when an alert turns into an investigation. You will also handle the day-to-day work of cloud security operations and help run incident response.

You will work closely with our Staff Security Engineer, who sets detection and AI-security strategy. Your job is to make that strategy real in production and keep it sharp. There is room to grow into deeper detection engineering, cloud security, and security automation, on a team that invests in leveling people up.

**This role is fully remote within the US**

What You’ll Do

  • Write, tune, and maintain detections in our SIEM (Panther) across cloud, container, and SaaS log sources, keeping coverage broad and alerts high-signal.
  • Run the SIEM day to day: onboard log sources, manage detection quality, and reduce false positives so real signals stand out.
  • Triage and investigate security alerts from raw log to conclusion, and help execute our incident-response playbooks.
  • Run cloud security operations in AWS: investigate GuardDuty and Wiz findings, tighten configurations, and close cloud misconfigurations.
  • Own and improve GitHub organization security controls as code.
  • Partner on network and infrastructure security: help onboard network telemetry, support egress monitoring, and provide backup depth alongside our infrastructure security engineer.
  • Help build and extend the team’s security-automation tooling.
  • Write runbooks so detection and response are repeatable rather than tribal knowledge.
  • Contribute to security design reviews and RFCs, and give substantive security feedback on pull requests.
  • Support the Vulnerability Management program with triage and exploitability assessment as volume requires.

What You Bring

  • 4+ years in security engineering, with solid hands-on experience in AWS and cloud-native infrastructure.
  • Direct experience writing and tuning detections in a modern SIEM (Panther or similar) and reasoning about detection coverage.
  • Experience investigating security alerts from raw log to a defensible conclusion.
  • The ability to design and deliver medium-complexity security work independently.
  • Code fluency in Python or TypeScript to automate your work.
  • Familiarity with cloud logging and observability (CloudTrail, VPC Flow Logs) and AWS security services (GuardDuty, AWS Config).
  • Solid AWS network security fundamentals (VPC, security groups, egress controls) and Terraform, enough to partner on and back up our network and infrastructure security work.
  • Clear writing; you leave behind runbooks and tickets others can follow.
  • Design detections and operational tooling for maintainability, so the work stays reliable and easy for the team to extend.
  • An ownership mindset: you close loops rather than drop them.

Nice To Haves

  • Startup experience, especially in health tech or another regulated, data-sensitive environment.
  • Incident-response experience, or a strong interest in growing into it.
  • Network security depth beyond fundamentals (VPC design, segmentation, Transit Gateway, firewall/egress architecture).
  • Kubernetes (EKS) and container security exposure.
  • Interest in AI and agentic security and in building security automation.

Our Tech Stack

  • Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
  • Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
  • Languages: Python, TypeScript, Go
  • AI and automation: Claude, MCP, and agentic tooling used across engineering

Compensation

$190k to 220k base salary

#LI-Remote

#LI-DNP

Benefits

  • Medical, Dental & Vision – Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
  • Paid Parental Leave – Generous paid leave to support families through birth or adoption: Up to 12 weeks for parents.
  • Remote-First Team – Work from anywhere in the U.S.
  • Unlimited PTO & 10 Holidays – So you can relax and recharge.
  • 401(k) with Traditional & Roth Options– Tax-advantaged retirement savings through Fidelity with a 4% match.
  • Minimal Bureaucracy – A fast-moving, high-impact environment where you can focus on what matters.
  • Incredible Teammates! – Work alongside smart, supportive, and mission-driven colleagues.
Read the full description
Security HQ - Senior Application Security Engineer (Remote) at Job&Talent

Senior Application Security Engineer drives security by design across the SDLC, leading threat modeling, code reviews, security automation, and developer enablement initiatives.

Senior Remote Posted 7 days ago RemoteFirstJobs Product
What this role involves

We are looking for a proactive and experienced Senior Application Security Engineer to help build secure products at scale. As a trusted partner to Engineering and Product teams, you will drive security by design across the Software Development Lifecycle (SDLC), leading initiatives such as threat modelling, secure code reviews, security automation, and developer enablement.

You will play a key role in shaping our Application Security strategy, helping us build secure, resilient products while enabling engineering teams to move fast with confidence.

This is a fully remote position with flexibility within ±1 hour of CET.

Responsibilities

  • Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC.

  • Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks.

  • Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling.

  • Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation.

  • Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management.

  • Mentor Security Champions and junior engineers, promoting a strong security culture across development teams.

  • Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness.

A successful candidate will have

  •  3-4 years of experience in Information Security, including at least 2 years in Application Security.

  • Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews.

  • Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines.

  • Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices.

  • Experience implementing and managing WAF solutions, as well as conducting internal penetration testing (including APIs using Burp Suite).

  • Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP).

  • Basic scripting or development experience, preferably in Python.

  • Excellent communication skills, with the ability to influence engineering teams and explain complex security concepts to technical and non-technical stakeholders.

About us

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. We help companies boost productivity and efficiency at scale, while giving workers the tools they need to thrive. Our mission is simple: to empower the people who make the world go round.

Built on deep industry expertise, cutting-edge technology, and smart AI agents, our end-to-end platform covers the entire workforce lifecycle — from recruitment and planning to time and attendance, performance, cost management, and communication.

It delivers measurable improvements in the areas that matter most: fulfilment, attendance, retention, and workforce quality. Our platform strength is rooted in unique experience: placing millions of workers over the years and serving thousands of blue-chip clients across delivery, logistics, manufacturing, e-commerce, retail, and hospitality.

Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America and is backed by leading investors including Atomico, Goldman Sachs, Kinnevik, BlackRock, and SoftBank.

Join our community and make an impact

Innovation, high standards, and analytical thinking are in our DNA. Everyone has a voice here, and that voice matters. It’s how we stay sharp, move fast, and make decisions that keep us ahead of the curve.

You’ll take full ownership of your work, collaborate across borders, and grow by doing. Around here, you’ll hear a lot about 10x experiences, human-centered design, and the power of AI. But what truly sets us apart is our people: Our diverse team brings unique perspectives, deep commitment and real-world experience to the table.

We champion empathy, honesty, and inclusion. Because when people can be their authentic selves, incredible things happen—for our workers, our clients, and for each other.

And we reward that impact—with competitive pay, meaningful benefits, and the opportunity to shape what work looks like for millions around the globe.

If you’re ready to make a real impact at scale, you’re in the right place.

Proud to champion equality

At Job&Talent we value diversity and we’re an Equal Opportunity Employer. We welcome applications from all suitably qualified people regardless of national origin, race, disability, religious beliefs or sexual orientation. Come join us. We look forward to your application.

#LI-ML2

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Threat Intelligence Analyst at Expel

Analyzes threat intelligence from multiple sources and incidents to provide actionable security guidance for analysts, engineers, and customers.

Senior Posted 7 days ago RemoteFirstJobs Product
What this role involves

You’re the kind of person who sees a new threat campaign and immediately wants to know how it works, who it’s targeting, and what defenders can do about it.

You know strong threat intelligence is more than collecting indicators or summarizing external reports. It means connecting intelligence from multiple sources, understanding how threat actors operate, and turning that information into something useful for analysts, detection engineers, customers, and business leaders.

You enjoy digging into real incidents, identifying root causes and attacker behavior, and helping others understand what matters. You’re equally comfortable working through IOCs and TTPs with security practitioners or translating the same findings into clear guidance for a less technical audience.

At Expel, you’ll serve as a senior contributor and subject matter expert helping mature our threat intelligence capabilities. You’ll analyze threats observed across our Security Operations Center alongside external intelligence sources, help prioritize the intelligence that creates the greatest operational value, and partner with teams across the business to strengthen how we protect our customers.

Does that sound like the kind of work you’d love to own? We’d like to hear from you.

What Expel can do for you

  • Give you direct exposure to real-world incidents and threat activity observed through our Managed Detection and Response service.
  • Provide the opportunity to shape and mature Expel’s threat intelligence practices, tooling, and methodologies.
  • Connect you with collaborative teams across the SOC, Threat Hunting, Detection Engineering, Product, Engineering, and Marketing.
  • Give you a platform to share meaningful threat intelligence with customers, practitioners, and the broader security community.
  • Surround you with curious security professionals who value thoughtful analysis, continuous learning, and practical outcomes.
  • Give you the opportunity to mentor developing analysts and help raise the technical bar across the organization.

What you can do for Expel

  • Monitor and curate intelligence from open-source reporting, dark web communities, proprietary feeds, internal incidents, and other relevant sources.
  • Evaluate threat intelligence for credibility, relevance, likelihood, and operational value before translating it into actionable guidance.
  • Review security incidents identified through Expel’s MDR service to uncover root causes, attacker TTPs, and exploited vulnerabilities.
  • Use internal incident data alongside external intelligence to identify emerging patterns and understand which threats are actively affecting customers.
  • Produce clear threat intelligence reports containing IOCs, TTPs, potential impact, and recommended mitigation strategies.
  • Communicate findings effectively to technical practitioners, customers, executive audiences, and cross-functional stakeholders.
  • Keep Expel’s curated intelligence current by regularly processing internal incidents and external feeds through a Threat Intelligence Platform.
  • Partner closely with SOC, Threat Hunting, and Detection Engineering teams to support the tactical application of intelligence.
  • Research new technologies, techniques, and data sources that could strengthen Expel’s threat intelligence capabilities.
  • Participate in intelligence-sharing communities and help build a positive reputation for Expel within the broader threat intelligence ecosystem.
  • Support strategic customer conversations and inquiries involving advanced threats and emerging attacker behavior.
  • Improve the processes, tools, and methodologies used to collect, assess, distribute, and operationalize threat intelligence.
  • Mentor junior and staff-level colleagues while serving as a trusted subject matter expert during complex incident reviews.

What you should bring with you

  • Approximately 5 to 8 years of professional experience across threat intelligence, security operations, incident response, detection engineering, or a closely related discipline.
  • A strong understanding of common cyberattack vectors and the tools, techniques, and procedures used by threat actors.
  • Experience performing detailed incident reviews to identify root causes, exploited vulnerabilities, and attacker behavior.
  • The ability to evaluate intelligence from multiple sources and determine what is credible, relevant, and actionable.
  • Familiarity with malware analysis reports generated by automated sandboxing tools, along with the ability to perform basic manual inspection.
  • Strong technical writing skills and the ability to adapt your communication for technical, executive, customer, and public audiences.
  • Strong capability in at least one technical area such as data analysis, network protocols, operating systems, security controls, or programming.
  • Experience mentoring colleagues and sharing technical expertise in a constructive, collaborative way.
  • Strong analytical, project-management, and time-management skills.
  • The ability to manage multiple priorities while maintaining sound judgment and attention to detail.
  • Confidence partnering across Marketing, Engineering, Product, SOC, Threat Hunting, and Detection Engineering teams.
  • Clear written and verbal communication skills, including the ability to navigate disagreement and technical ambiguity constructively.

Additional notes

While the full salary band reflects our long-term compensation framework, we’re primarily targeting candidates between $135,000 and $170,000 based on experience, skills, internal equity, and market data. This role is also eligible for bonus and equity.

This is a fully remote position open to candidates residing in the United States.

Applicants must be authorized to work in the United States. The source job description does not specify whether immigration sponsorship is available, so that detail should be confirmed before posting.

Expel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or disability.

We’ll ensure individuals with disabilities are provided reasonable accommodation throughout the application and interview process, while performing essential job functions, and when accessing employment benefits and privileges.

#LI-Remote

Salary Range

$126,500—$183,400 USD

Read the full description
Security Senior Threat Intelligence Analyst at Expel

Analyzes threat campaigns and security incidents to develop actionable intelligence for SOC teams, detection engineers, and customers.

Senior Posted 7 days ago RemoteFirstJobs Product
What this role involves

You’re the kind of person who sees a new threat campaign and immediately wants to know how it works, who it’s targeting, and what defenders can do about it.

You know strong threat intelligence is more than collecting indicators or summarizing external reports. It means connecting intelligence from multiple sources, understanding how threat actors operate, and turning that information into something useful for analysts, detection engineers, customers, and business leaders.

You enjoy digging into real incidents, identifying root causes and attacker behavior, and helping others understand what matters. You’re equally comfortable working through IOCs and TTPs with security practitioners or translating the same findings into clear guidance for a less technical audience.

At Expel, you’ll serve as a senior contributor and subject matter expert helping mature our threat intelligence capabilities. You’ll analyze threats observed across our Security Operations Center alongside external intelligence sources, help prioritize the intelligence that creates the greatest operational value, and partner with teams across the business to strengthen how we protect our customers.

Does that sound like the kind of work you’d love to own? We’d like to hear from you.

What Expel can do for you

  • Give you direct exposure to real-world incidents and threat activity observed through our Managed Detection and Response service.
  • Provide the opportunity to shape and mature Expel’s threat intelligence practices, tooling, and methodologies.
  • Connect you with collaborative teams across the SOC, Threat Hunting, Detection Engineering, Product, Engineering, and Marketing.
  • Give you a platform to share meaningful threat intelligence with customers, practitioners, and the broader security community.
  • Surround you with curious security professionals who value thoughtful analysis, continuous learning, and practical outcomes.
  • Give you the opportunity to mentor developing analysts and help raise the technical bar across the organization.

What you can do for Expel

  • Monitor and curate intelligence from open-source reporting, dark web communities, proprietary feeds, internal incidents, and other relevant sources.
  • Evaluate threat intelligence for credibility, relevance, likelihood, and operational value before translating it into actionable guidance.
  • Review security incidents identified through Expel’s MDR service to uncover root causes, attacker TTPs, and exploited vulnerabilities.
  • Use internal incident data alongside external intelligence to identify emerging patterns and understand which threats are actively affecting customers.
  • Produce clear threat intelligence reports containing IOCs, TTPs, potential impact, and recommended mitigation strategies.
  • Communicate findings effectively to technical practitioners, customers, executive audiences, and cross-functional stakeholders.
  • Keep Expel’s curated intelligence current by regularly processing internal incidents and external feeds through a Threat Intelligence Platform.
  • Partner closely with SOC, Threat Hunting, and Detection Engineering teams to support the tactical application of intelligence.
  • Research new technologies, techniques, and data sources that could strengthen Expel’s threat intelligence capabilities.
  • Participate in intelligence-sharing communities and help build a positive reputation for Expel within the broader threat intelligence ecosystem.
  • Support strategic customer conversations and inquiries involving advanced threats and emerging attacker behavior.
  • Improve the processes, tools, and methodologies used to collect, assess, distribute, and operationalize threat intelligence.
  • Mentor junior and staff-level colleagues while serving as a trusted subject matter expert during complex incident reviews.

What you should bring with you

  • Approximately 5 to 8 years of professional experience across threat intelligence, security operations, incident response, detection engineering, or a closely related discipline.
  • A strong understanding of common cyberattack vectors and the tools, techniques, and procedures used by threat actors.
  • Experience performing detailed incident reviews to identify root causes, exploited vulnerabilities, and attacker behavior.
  • The ability to evaluate intelligence from multiple sources and determine what is credible, relevant, and actionable.
  • Familiarity with malware analysis reports generated by automated sandboxing tools, along with the ability to perform basic manual inspection.
  • Strong technical writing skills and the ability to adapt your communication for technical, executive, customer, and public audiences.
  • Strong capability in at least one technical area such as data analysis, network protocols, operating systems, security controls, or programming.
  • Experience mentoring colleagues and sharing technical expertise in a constructive, collaborative way.
  • Strong analytical, project-management, and time-management skills.
  • The ability to manage multiple priorities while maintaining sound judgment and attention to detail.
  • Confidence partnering across Marketing, Engineering, Product, SOC, Threat Hunting, and Detection Engineering teams.
  • Clear written and verbal communication skills, including the ability to navigate disagreement and technical ambiguity constructively.

Additional notes

While the full salary band reflects our long-term compensation framework, we’re primarily targeting candidates between $135,000 and $170,000 based on experience, skills, internal equity, and market data. This role is also eligible for bonus and equity.

This is a fully remote position open to candidates residing in the United States.

Applicants must be authorized to work in the United States. The source job description does not specify whether immigration sponsorship is available, so that detail should be confirmed before posting.

Expel is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or disability.

We’ll ensure individuals with disabilities are provided reasonable accommodation throughout the application and interview process, while performing essential job functions, and when accessing employment benefits and privileges.

#LI-Remote

Salary Range

$126,500—$183,400 USD

Read the full description
Security Senior Security Engineer I, Customer Trust EMEA (Remote Eligible in the UK)

Leads security initiatives and trust operations for Smartsheet's EMEA region, protecting customer data and platform integrity.

Senior Remote Posted 8 days ago Jobicy AI
What this role involves
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI...
Read the full description
Security Lithic: Senior AML Analyst

Senior AML Analyst owns financial crime monitoring program, manages investigation tooling, and handles compliance escalations for card issuing platform.

Senior Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Lithic is the modern card issuing and processing platform empowering ambitious financial companies to build the future of payments.

Our infrastructure powers card programs for 100+ innovative clients, from fintechs reimagining credit and digital banking to platforms transforming disbursements and spend management. Companies like Mercury, Flex, and Novo rely on Lithic's developer-friendly APIs, direct network connections, and flawless reconciliation to launch and scale card programs in weeks, not years.

We're building a future where access to better financial products materially improves people's lives, free from the constraints of 30-year-old mainframes and legacy processors. We're proud to be backed by world-class investors who share that vision, including Bessemer Venture Partners, Index Ventures, Spark Capital, Stripes, and Mastercard, along with many others. 

We're a team of 170+ across 26 states and 7 countries, headquartered in New York City. 

Lithic is the modern card issuing and processing platform empowering ambitious financial companies to build the future of payments.

Our infrastructure powers card programs for 100+ innovative clients, from fintechs reimagining credit and digital banking to platforms transforming disbursements and spend management. Companies like Mercury, Flex, and Novo rely on Lithic's developer-friendly APIs, direct network connections, and flawless reconciliation to launch and scale card programs in weeks, not years.

We're building a future where access to better financial products materially improves people's lives, free from the constraints of 30-year-old mainframes and legacy processors. We're proud to be backed by world-class investors who share that vision, including Bessemer Venture Partners, Index Ventures, Spark Capital, Stripes, and Mastercard, along with many others.

We're a team of 170+ across 26 states and 7 countries, headquartered in New York City.

Our Risk & Compliance team is hiring a Senior AML Analyst who will improve the effectiveness, resilience, and scalability of our financial monitoring program. You will own Lithic's AML and financial crime monitoring program at the SOP and monitoring-engine level, and you will be the person who turns our agentic monitoring and investigation tooling into realized, defensible capacity. This is an ownership role, not purely a queue-based execution role: you’ll certainly handle escalations, exceptions, and perform population sampling, but the goal is routine, documented volume is increasingly absorbed by automation, and you own the design, tuning, and exception handling that sit around it.

What You’ll Do

  • Own and continuously improve the AML and financial crime transaction monitoring SOPs, keeping them aligned to current regulatory requirements, evolving typologies, and operational reality
  • Own the feedback loop into Lithic's monitoring engine: partner with your Analytics, Engineering, and Product peers to evaluate alert logic, assess rule and scenario effectiveness, and tune thresholds to reduce false positives while preserving coverage
  • Lead the testing, deployment, and tuning of agentic transaction monitoring and investigation solutions, including documenting the investigative context the tooling needs to produce repeatable, examiner-ready output
  • Investigate complex suspicious activity independently and prepare high-quality SARs and UARs; own escalations and the judgment-heavy cases automation cannot close unattended
  • Supervise and quality-check alert review and investigative output, including AI-assisted output, so decisions hold up to bank partner and regulatory scrutiny
  • Synthesize monitoring performance data, operational trends, and emerging financial crime risks into actionable program insights, and define and influence AML KPIs and KRIs
  • Lead governance preparation for relevant oversight forums and support bank partner and exam-readiness deliverables
  • Train and mentor analysts on investigations, money laundering typologies, and the agentic tooling, so program knowledge scales beyond any one person

What You'll Need

  • 3+ years of AML/BSA and transaction monitoring experience in fintech, payments, or a bank-partnered environment
  • Demonstrated ownership of end-to-end AML programs or work streams with limited guidance, including authoring and maintaining SOPs and preparing governance materials
  • Deep knowledge of money laundering typologies and emerging financial crime trends, with the ability to investigate complex activity and prepare high-quality SARs and UARs independently
  • Hands-on experience evaluating alert logic and assessing or tuning transaction monitoring rules and scenarios for effectiveness
  • Comfort working with AI-assisted or agentic tooling, including how to test, tune, document, and defend AI-assisted decisions to bank partners and regulators
  • Self-starter who can create structure where none exists and knows when to escalate and collaborate
  • Strong written and verbal communication
  • Solid grasp of the BSA/AML regulatory framework (USA PATRIOT Act, OFAC and sanctions, SAR requirements)

Nice to Have

  • CAMS or CFE (preferred, or willing to obtain)
  • Experience deploying or tuning AI, automation, or agentic tooling in a compliance or investigations context
  • Experience with OSINT tooling and SQL or Snowflake for investigative data retrieval
  • Card issuing, payments, or fintech experience with exposure to sponsor bank relationships
  • Background in high-risk verticals (MRBs, crypto-adjacent businesses, or similar)

Base Salary: $65,000 - $110,000

This is a remote position. However, candidates must be located in the United States. We do not offer visa sponsorship or assistance.

Benefits for Full-Time US Employees:

  • Unlimited PTO
  • 12-weeks fully paid parental leave
  • 4-Week Fully Paid Sabbatical (earned at your 5-year anniversary)
  • Work From Anywhere: work from anywhere in the world 4-weeks each year
  • 3% cashback on card purchases with your complimentary Privacy.com employee account
  • Health, vision, and dental insurance; HSA Contribution Match
  • 401(k) match
  • Voluntary Life Insurance and STD/LTD

NYC-based employees work from our SoHo office three days a week. Tuesdays and Thursdays are our core days, and you'll choose a third day that works for your schedule and team needs.

In-office employees receive: 

  • Commuter benefit
  • Catered lunch every Tuesday and Thursday

To apply: https://weworkremotely.com/remote-jobs/lithic-senior-aml-analyst

Read the full description
Security Offensive Security Engineer at ClickHouse Japan

Offensive security engineer identifies vulnerabilities, conducts pentests and red team assessments, and builds AI-assisted tooling to test ClickHouse's security posture.

Senior Posted 9 days ago RemoteFirstJobs Product
What this role involves

About ClickHouse

Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 4,000 customers and ARR that has grown over 250 percent year over year, ClickHouse leads the market in real-time analytics, data warehousing, observability, and AI workloads.

The company’s sustained, accelerating momentum was recently validated by a $400M Series D financing round. Over the past three months, customers including Capital One, Lovable, Decagon, Polymarket, and Airwallex have adopted the platform or expanded existing deployments. These customers join an established base of AI innovators and global brands such as Meta, Cursor, Sony, and Tesla.

We’re on a mission to transform how companies use data. Come be a part of our journey!

About the team

The Security Team is responsible for providing key security capabilities covering application, cloud and enterprise security, incident response, detection and GRC. Our team is looking for an experienced, hands-on security practitioner, who will drive the adoption of modern security processes and tooling, with focus on supporting our engineering and product teams in improving the security posture of our platforms and services.

What you will do:

  • Identify security gaps and vulnerabilities in all ClickHouse offerings triage a wide range of vulnerabilities reported via our bug bounty program, responsible disclosure, GitHub Issues covering web, API and server - client assets including low level memory issues like heap or buffer overflows
  • Improve and develop security assurance activities - pentests, vulnerability assessments, bug bounty programs, fuzzing
  • Plan and execute internal red team assessments and penetration tests against ClickHouse infrastructure, cloud environments, designing realistic adversary scenarios to test detection, response and control effectiveness
  • Assess AI/LLM-specific attack surface across ClickHouse’s own AI-powered features and internal AI tooling, including prompt injection, model/data exfiltration, and unsafe agentic tool-use patterns
  • Build and operate agentic tooling for reconnaissance, exploit-chaining and attack-path discovery, and apply LLM-assisted fuzzing to accelerate vulnerability discovery across ClickHouse’s products and infrastructure
  • Partner with detection engineering to validate and improve detection coverage during red team exercises, measuring and reporting on control effectiveness and time to detect/respond
  • Handle information security events and incidents across ClickHouse products and services
  • Develop processes, tooling and automation to scale security processes and mitigate risks to the business

What you bring along:

  • 7+ years of experience in pentesting, red teaming and product security
  • Experience supporting engineering and product implementation efforts by performing threat assessments, assurance activities, advisory as well as, in some cases, implementation work across distributed systems covering web, API, client/server assets
  • Hands-on experience conducting offensive security engagements - internal red teaming, penetration testing and adversary simulation - across cloud, network and application environments
  • Ability to design adversary scenarios grounded in real threat intelligence (e.g. ransomware operators, supply chain attackers, insider threat) tailored to ClickHouse’s risk profile as a multi-tenant cloud data platform
  • Strong written and verbal communication skills, with ability to translate attack chains into clear, actionable findings for engineering and leadership
  • Experience building or adapting agentic and LLM-assisted tooling for offensive security use cases (recon automation, exploit chaining, fuzzing harnesses), with judgment on where AI genuinely speeds up an engagement versus adds noise
  • Familiarity with AI/LLM-specific vulnerability classes and testing methodology
  • Strong knowledge of and experience with one or more cloud service providers (e.g. AWS, GCP, Azure), Kubernetes, Cilium
  • Experience implementing and operating engineering security tools and processes (e.g. static / dynamic code analysis, software composition analysis, SBOM, OWASP SAMM, client and network fuzzing tools)
  • Security as code mindset, with focus on solving problems with automation and scale in mind

Bonus Points:

  • BS, MS, or PhD in Computer Science or related field
  • Previous contributions to open source projects
  • Security or cloud related certifications (AWS, GCP, Azure)
  • Previous experience in using AI security harnesses for pentesting purposes
  • Experience building or operating internal red team tooling and infrastructure from scratch, rather than relying solely on off-the-shelf frameworks
  • Offensive security certifications (e.g. OSCP, OSCE, OSEP, OSWE)

Compensation

For roles based in the United States, the typical starting salary range for this position is listed above. In certain locations, such as the San Francisco Bay Area and the New York City Metro Area, a premium market range may apply, as listed.

These salary ranges reflect what we reasonably and in good faith believe to be the minimum and maximum pay for this role at the time of posting. The actual compensation may be higher or lower than the amounts listed, and the ranges may be subject to future adjustments.

An individual’s placement within the range will depend on various factors, including (but not limited to) education, qualifications, certifications, experience, skills, location, performance, and the needs of the business or organization.

If you have any questions or comments about compensation as a candidate, please get in touch with us at paytransparency@clickhouse.com.

Perks

  • Flexible work environment - ClickHouse is a globally distributed company and remote-friendly. We currently operate in over 20 countries.
  • Healthcare - Employer contributions towards your healthcare.
  • Equity in the company - Every new team member who joins our company receives stock options.
  • Time off - Flexible time off in the US, generous entitlement in other countries.
  • A $500 Home office setup if you’re a remote employee.
  • Global Gatherings– We believe in the power of in-person connection and offer opportunities to engage with colleagues at company-wide offsites.

Culture - We All Shape It

As part of a rapidly scaling start up, you will be instrumental in shaping our culture.

Are you interested in finding out more about our culture?  Learn more about our values here.  Check out our blog posts or follow us on LinkedIn to find out more about what’s happening at ClickHouse.

Equal Opportunity & Privacy

ClickHouse provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any type based on factors such as race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

Please see here for our Privacy Statement.

Read the full description
Security Senior IT Auditor at Mercury

Conducts IT and security audits, assesses technology risks and controls, and collaborates on remediation across Mercury's fintech platform.

Senior Posted 10 days ago RemoteFirstJobs Product
What this role involves

Mercury is building a complete finance stack for startups. We work hard to create the easiest and safest banking* experience possible to simplify entrepreneurs’ and business owners’ financial lives. To accomplish this mission, not only do we have to build/maintain a magical banking platform but must also develop and uphold the trust and safety of our customers and the financial industry. To contribute to this effort, we’re looking to hire a Senior IT Auditor to support the efforts of our Internal Audit function at Mercury in the execution of our audit plan. You’ll help drive audits internally within Mercury as well as support audits being conducted externally by partners and third parties. In this role, you’ll perform hands-on IT and security audits, assess Mercury’s technology risks and controls, and work cross-functionally to improve Mercury’s control environment.

*Mercury is a fintech company, not an FDIC-insured bank. Banking services provided through Choice Financial Group and Column N.A., Members FDIC.

As part of the journey, we would expect you to:

  • Assist in identifying, analyzing, and assessing risk, specifically IT, cybersecurity, and data security related, throughout Mercury
  • Scope and plan multiple audits across Mercury products and operations
  • Conduct process walkthroughs and execute audit testing to confirm the design and operational effectiveness of internal controls
  • Assess compliance with Mercury’s compliance obligations
  • Socialize, document, and report audit issues identified
  • Collaborate with teams to develop appropriate action plans, track audit issue remediation, and conduct issue follow up testing
  • Other duties as assigned

Some things that might make you successful in a role like this:

  • Have experience scoping and planning new, complex audits
  • Be comfortable conducting walkthroughs, creating audit test plans, and executing internal controls testing
  • Be comfortable using AI tools (Claude, ChatGPT, etc.) to support your day to day workflows
  • Have experience working with financial services companies, and have a working knowledge of laws, regulations and risk management standards for financial services
  • Familiarity with IT control frameworks (e.g., NIST, ISO 27001, COBIT)
  • Have exposure to cloud environments (e.g., AWS) and related security controls
  • Experience with security and threat assessments
  • Have the ability to quickly grasp and understand complex business processes
  • Be able to build relationships/partnerships and work cross-functionally to drive time-sensitive deliverables, issues tracking, and reporting
  • Have excellent written and verbal communication skills
  • Be able to manage their own schedule to ensure deadlines are met
  • Be a self-starter, someone who likes to innovate and think about how we can do things differently to be more efficient and effective

The total rewards package at Mercury includes base salary, equity (stock options/RSUs), and benefits.

Our salary and equity ranges are highly competitive within the SaaS and fintech industry and are updated regularly using the most reliable compensation survey data for our industry. New hire offers are made based on a candidate’s experience, expertise, geographic location, and internal pay equity relative to peers.

Our target new hire base salary ranges for this role are the following:

  • US employees in New York City, Los Angeles, Seattle, or the San Francisco Bay Area: $132,400 - $165,500 USD
  • US employees outside of New York City, Los Angeles, Seattle, or the San Francisco Bay Area: $119,200 - $149,000 USD
  • Canadian employees (any location): CAD $125,100 - $156,400

Mercury values diversity & belonging and is proud to be an Equal Employment Opportunity employer. All individuals seeking employment at Mercury are considered without regard to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, sexual orientation, or any other legally protected characteristic. We are committed to providing reasonable accommodations throughout the recruitment process for applicants with disabilities or special needs. If you need assistance, or an accommodation, please let your recruiter know once you are contacted about a role.

#LI-AR1

Read the full description
Security Asana: Senior Privacy Engineer

Senior Privacy Engineer leads technical privacy-by-design reviews, builds privacy frameworks, evaluates AI/ML privacy risks, and implements privacy-enhancing technologies across the organization.

Senior Hybrid Posted 10 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

The Security team at Asana is responsible for protecting Asana’s employees, users, and customers. We build innovative safeguards to ensure that our data is protected against threats and that we comply with legal, regulatory, and customer requirements while collaborating closely with teams across the organization. Reporting to Asana’s Head of Global Privacy, Data Protection, and Compliance, as a founding member of the Privacy Engineering team, you will shape how we build privacy into our products from the ground up—bridging the legal, regulatory, and technical dimensions of privacy across the company.

This role can either be fully remote depending on which US state you live in, or based in our San Francisco office with an office-centric hybrid schedule. If based in-office: The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements.

What you’ll achieve

  • Lead technical privacy-by-design reviews for new features and major architectural changes, embedding privacy controls early in the development lifecycle across our business, data, and product infrastructure.

  • Help drive compliance with global privacy regulations (such as GDPR and CCPA) by translating legal requirements into concrete engineering standards, frameworks, and tooling that facilitate velocity.

  • Evaluate and mitigate privacy risks in AI/ML systems, including training data pipelines and model outputs.

  • Build and operate systems that enable data rights for our users and privacy-enhancing technologies (PETs), such as data minimization and de-identification frameworks.

  • Conduct privacy impact assessments and threat modeling for high-risk data processing activities.

  • Advocate for privacy-preserving solutions, serve as a trusted technical advisor across the business, and identify new opportunities to improve our overall privacy posture.

  • Partner cross-functionally to ensure our privacy policies and notices accurately reflect our underlying technology.

  • Develop customer-facing trust documentation on privacy and support privacy incident response efforts.

  • Design and implement privacy-preserving analytics and measurement systems that provide actionable insights while protecting individual user privacy.

About you

  • Demonstrates curiosity about AI tools and emerging technologies, with a willingness to learn and leverage them to enhance productivity, collaboration, or decision-making.

  • 6+ years of software engineering experience, with 3+ years focused on privacy or data protection.

  • Passion for privacy and data protection with a deep understanding of GDPR, CCPA, and emerging global privacy frameworks.

  • Proven experience building technical controls for data governance, including classification, lineage, retention, and deletion at scale.

  • Familiarity with privacy risks in ML systems, such as training data sourcing, model memorization, and inference privacy.

  • Strong foundation in privacy-by-design principles and hands-on experience applying them throughout product development.

  • Demonstrated ability to translate complex regulatory and legal requirements into clear engineering specifications.

  • Experience with cryptographic techniques, anonymization, and de-identification frameworks.

  • Strong communication and collaboration skills, with a track record of partnering effectively with legal, policy, and non-technical stakeholders.

At Asana, we're committed to building teams that include a variety of backgrounds, perspectives, and skills, as this is critical to helping us achieve our mission. If you're interested in this role and don't meet every listed requirement, we still encourage you to apply.

What we’ll offer Our comprehensive compensation package plays a big part in how we recognize you for the impact you have on our path to achieving our mission. We believe that compensation should be reflective of the value you create relative to the market value of your role. To ensure pay is fair and not impacted by biases, we're committed to looking at market value which is why we check ourselves and conduct a yearly pay equity audit.

For this role, the estimated base salary range will vary based on your location. Locations in the US are categorized into one of three geographic pay zones, and the ranges for the zones are as follows: Zone A: $235,000 - $267,000
Zone B: $211,000 - $240,000
Zone C: $189,000 - $216,000

For more information about which locations fall into each pay zone, please visit https://asana.com/usa-pay-zones. Please also consult your recruiter to confirm the applicable pay zone for your specific location.

The actual base salary will vary based on various factors, including market and individual qualifications objectively assessed during the interview process. The listed ranges above are a guideline, and the base salary range for this role may be modified.

In addition to base salary, your compensation package may include additional components such as equity, sales incentive pay (for most sales roles), and benefits. If you're interviewing for this role, speak with your recruiter to learn more about the total compensation and benefits for this role.

We strive to provide equitable and competitive benefits packages that support our employees worldwide and include:

  • Mental health, wellness & fitness benefits

  • Career coaching & support

  • Inclusive family building benefits

  • Long-term savings or retirement plans

  • In-office culinary options to cater to your dietary preferences

These are just some of the benefits we offer, and benefits may vary based on role, country, and local regulations. If you're interviewing for this role, speak with your Talent Acquisition Partner to learn more about the total compensation and benefits for this role.

About us

Asana is a leading platform for human + AI collaboration. Millions of teams around the world rely on Asana to achieve their most important goals, faster. Asana has been named to Fortune's Best Workplaces for 7+ years and recognized by Fast Company, Forbes, and Gartner for excellence in workplace culture and innovation. We offer an exceptional office-centric culture while adopting the best elements of hybrid models to ensure that every one of our global team members can work together effortlessly. With 13+ offices all over the world, we are always looking for individuals who care about building technology that drives positive change in the world and a culture where everyone feels that they belong.

Join Asana’s Talent Network to stay up to date on job opportunities and life at Asana.

To apply: https://weworkremotely.com/remote-jobs/asana-senior-privacy-engineer

Read the full description
Security Security Analyst - Governance, Risk, and Compliance

Develops and operates security and privacy programs, managing governance, risk, and compliance initiatives across the organization.

Senior Posted 11 days ago Himalayas
What this role involves
About the Job:LaunchDarkly's Governance, Risk, and Compliance team is hiring a Security Analyst III to facilitate the definition, implementation, and operation of security and privacy programs at LaunchDarkly.
Read the full description
Security Hardware Platform Security Architect at OpenAI

Architect and deploy secure hardware systems, cryptographic infrastructure, and trusted computing platforms at scale across silicon, hardware, and system layers.

Senior Posted 12 days ago RemoteFirstJobs Product
What this role involves

About the Team

Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

Trusted Computing and Cryptography is a core security team at OpenAI focused on deploying high-performance cryptography at scale, secure key management, and trusted hardware enclaves—from boot measurements to GPU confidential computation. As a Hardware Platform Security Architect, you’ll own hardware platform security at OpenAI.

In this role, you will:

  • Co-Architect Secure Silicon: Collaborate with cross-functional silicon teams (Silicon Design, DV, FW) and silicon partners (silicon test facilities, foundries) to develop secure silicon that meets the end-to-end system requirements.

  • Co-Architect Secure Hardware: Collaborate with hardware vendors and cross-functional teams (kernel, compiler, infra) to design secure hardware that meets performance and security needs.

  • Co-Architect Secure Systems: Architect and deploy systems using TPM2, Secure Boot, Nitro Enclaves, Intel SGX, AMD-SEV, and other secure hardware technologies.

  • Drive Innovation: Engage with internal and external partners to align hardware innovations with OpenAI’s trusted computing and cryptographic requirements.

You might thrive in this role if you have:

  • 10+ years of industry experience in hardware security or hardware–software co-design.

  • Proven expertise in deploying secure hardware systems at scale and integrating secure hardware primitives.

  • Strong coding skills in Rust and/or C/C++, with proficiency in Python.

  • Proven ability to collaborate across teams, architect solutions, and debug complex production systems.

  • A proactive, ownership-driven mindset with a focus on end-to-end problem solving.

Nice to Have

  • Advanced degree in Computer Architecture, Electrical Engineering, or related fields.

  • Familiarity with HPC, low-precision computing, and SIMD architectures.

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Read the full description