Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Physical Security Architect at New Era Technology

Design and validate physical security systems including access control, video surveillance, and intrusion detection for enterprise customers like Walgreens.

Senior Posted about 9 hours ago RemoteFirstJobs Product
What this role involves

Join New Era Technology, where People First is at the heart of everything we do. With a global team of over 3,000 professionals, we’re committed to creating a workplace where everyone feels valued, empowered, and inspired to grow. Our mission is to securely connect people, places, and information with end-to-end technology solutions at scale.

At New Era, you’ll join a team-oriented culture that prioritizes your personal and professional development. Work alongside industry-certified experts, access continuous training, and enjoy competitive benefits. Guided by our core attributes — putting people first, embracing continuous learning, and thriving through collaboration and inclusion — we nurture our people to deliver exceptional customer service.

If you want to make an impact in a supportive, growth-oriented environment, New Era is the place for you. Apply today and help us shape the future of work—together

New Era Technology offers:

· Full Benefits

· Medical

· Dental

· Vision

· 401K match

· 28 PTO Days including company holidays

SUMMARY:

The Physical Security Architect is a hands-on subject matter expert on physical security design, covering access control, video surveillance, intrusion detection, and intercom systems. This role works directly with project teams, Solutions and Design engineers, Sales, manufacturer partners, and customer stakeholders to validate designs, review scope, and support projects through execution.

Walgreens is the initial focus for this role, given the size of the account and its ongoing physical security needs. The Physical Security Architect will also support other strategic enterprise customers over time. This role helps build deeper bench strength on Walgreens physical security standards and design expectations so that account knowledge is documented and shared across the team rather than held by one person.

PRIMARY DUTIES:

Design Support and Validation

  • Conduct site assessments, construction reviews, and design coordination meetings for active physical security projects.
  • Review and validate project scope, system requirements, and bills of materials against customer
  • Provide technical guidance on access control, video surveillance, intrusion detection, intercom, and integrated security systems.
  • Support development of reference designs, configuration standards, and deployment

Walgreens Program Support

  • Serve as a technical resource for Walgreens’ physical security standards, design expectations, and site
  • Support knowledge transfer so Walgreens specific technical knowledge is documented and shared across the physical security team.
  • Review Walgreens project deliverables and support proactive communication on design questions, open issues, and escalations.
  • Coordinate with manufacturer partners on platform requirements used on the account, including

Project Support and Escalation

  • Support project managers, project coordinators, and implementation teams throughout the project
  • Review network architectures, device configurations, communication paths, and integration
  • Act as a liaison between project teams and manufacturer technical resources on hardware, firmware, or integration issues.
  • Support troubleshooting and escalation handling technical issues on active

Testing and Technical Evaluation

  • Use New Era’s physical security lab to test new products, validate designs, and troubleshoot field
  • Evaluate new products, platforms, and integrations for use in customer
  • Run test plans and document results to support design

Standards and Documentation

  • Support the development and maintenance of configuration standards, implementation guides, and design templates.
  • Capture deployment feedback and lessons learned and share them with the broader physical security
  • Maintain client specific technical documentation, including Walgreens design standards and site

Technical Writing and Customer Communication

  • Prepare assessment reports, technical findings, and design recommendations for internal and customer
  • Develop customer facing documentation that explains technical concepts clearly to non-technical
  • Present technical reviews, design updates, and project status to customers and internal stakeholders as

REQUIRED EDUCATION:

  • Bachelor’s degree in information technology, security management, engineering, computer science, or a related field, or equivalent work experience.
  • 5 or more years of experience in physical security technologies, systems integration, or security
  • Experience designing, implementing, or supporting enterprise access control, video surveillance, and intrusion detection systems.
  • Experience coordinating technical work across project teams, manufacturers, and customer
  • Experience conducting technical assessments, design validation, and
  • Experience preparing technical documentation, reports, and

Core Competencies:

  • Physical security technical expertise
  • Design validation and quality review
  • Troubleshooting and issue resolution
  • Manufacturer and partner coordination
  • Technical documentation and reporting
  • Communication with technical and non-technical audiences
  • Attention to detail
  • Ownership of assigned accounts and projects

QUALIFICATIONS:

  • Experience supporting large enterprise retail security programs, such as Walgreens or similar
  • Experience with platforms such as Genetec or comparable access control and video management
  • Industry certifications from major security
  • Experience developing technical standards or design documentation for enterprise

EXPERIENCE: 5 or more years of experience in physical security technologies, systems integration, or security consulting

LANGUAGE SKILLS: English

PHYSICAL DEMANDS :

  • Regular use of hands and fingers to operate a computer keyboard, mouse, and other office equipment.
  • Regular, repetitive movements such as typing, mouse movements, and scrolling. Ability to hear and understand spoken communications, both in person and via remote communication tools (e.g., phone, video conferencing).
  • Ability to see and read computer screens and printed documents, as well as adjust focus. This includes prolonged periods of looking at a computer screen.

WORK ENVIRONMENT:

This role works in a hybrid environment, including home offices, customer sites, New Era facilities, and the physical security lab. The role requires frequent coordination with Sales, Solutions, the Project Management Office (PMO), the Project Coordination Office (PCO), Operations, field teams, manufacturers, and customer stakeholders.

Availability to support active project issues and time sensitive customer requests is required

EXPECTED HOURS OF WORK: Monday – Friday 8am – 5pm. May vary due to project assignment.

TRAVEL: Travel is expected to run up to 25 percent, depending on active projects and customer needs.

QUALIFICATIONS: To perform the job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed above are representative of the knowledge, skill and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Other duties, responsibilities and activities may change or be assigned at any time with or without notice.

EEO/AA Statement

New Era Technology provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, national origin, religion, pregnancy, marital status, gender identity, age, physical or mental disability, or covered veteran status.

In addition to federal law requirements, New Era Technology complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Below is the pay range of this position for considered candidates based on qualifications and experience.

Pay Range

$105,000—$110,000 USD

New Era Technology, LLC., and its subsidiaries (“New Era” “we”, “us”, or “our”) in its operating regions worldwide are committed to respecting your privacy and recognize the need for appropriate protection and management of any Personal Data that you may provide us. In this, we are also committed to providing you with a positive experience on our websites and while using our products, services and solutions (“Solutions”).

View our Privacy Policy here https://www.neweratech.com/us/privacy-policy/

We never ask candidates to pay any fees at any point in our hiring process. If you are ever asked to provide payment for training, certification, equipment, or any other purpose, it is not from our company. Only communications from our official company channels should be trusted. Please note our official email domain is @neweratech.com. If you suspect fraudulent activity, please contact us immediately at privacy@neweratech.com .

Read the full description
Security Security Operations Analyst at Unqork

Monitors security alerts and threats across SIEM/EDR/XDR tools, triages incidents, implements automations, and partners cross-functionally to protect company assets.

Mid Posted about 14 hours ago RemoteFirstJobs Product
What this role involves

Unqork empowers enterprises to accelerate growth by rapidly building, testing, and running AI-powered applications that embody the future of enterprise development. Trusted by the world’s largest organizations in highly regulated industries, these applications become more secure over time while significantly reducing technical debt—allowing businesses to focus on innovation rather than maintenance. Unqork’s customers include Goldman Sachs, Marsh, BlackRock, and the U.S. Department of Health and Human Services.

At Unqork, we value inclusive and innovative thinkers who boldly challenge the status quo. We encourage you to apply!

The Impact U will make:

As a Security Operations Analyst, you will be an analytical and thorough individual contributor reporting to the Director of Security Operations. You will play a role in Threat Detection & Response, Threat Intelligence and Hunting, Technical Security Architecture, IT Operations, and SIEM and SOAR engineering. Your primary focus will be to proactively and reactively protect and defend our critical assets against an evolving threat landscape.

  • Security Monitoring & Alert Triage Actively monitor SIEM, EDR/XDR, and other security tools to detect, analyze, and triage security alerts. Follow established playbooks to ensure timely and accurate initial response to potential threats.
  • Process Efficiency & Automation Utilize existing Security Orchestration, Automation, and Response (SOAR) platforms to handle alerts efficiently. Identify repetitive manual tasks and implement automations.
  • SIEM & Detection Engineering Integrate and set up the ingestion of log sources to a SIEM tool, including the normalization of fields and data. Create timely monitoring solutions for relevant threats based on active threat intelligence. Share responsibility for detection and log lifecycle / maintenance.
  • Threat Intelligence Consume and review daily threat intelligence feeds, security advisories, and industry alerts to ensure the company is protected against known Indicators of Compromise (IoCs) and emerging threat trends.
  • IT Operations & Asset Security Work closely with IT Operations to maintain accurate hardware and software asset inventories. Assist in deploying and troubleshooting endpoint security agents to ensure a secure baseline for all employee devices.
  • Cross-Functional Technical Partnership: Collaborate extensively with resources in Engineering, Product, IT, and other departments to embed operational security requirements, influence architectural decisions for detectability, and foster a strong security culture. Serve as the primary security technical expert for these partnerships.
  • Compliance & Operational Reporting: Assist in generating routine security metrics and operational reports. Help gather technical evidence to support adherence to security policies and compliance audits (e.g., SOC 2, ISO 27001).

What U bring:

  • 3+ years of progressive experience in Security Operations, with at least 2  years in a role contributing to a Security Operations Center (SOC), Managed Detection Response Service, or Incident Response team.
  • Proven track record as an engineer, having designed, implemented, and managed mature SOC processes and automations.
  • Proven hands-on Python experience.
  • Proven hands-on technical expertise in threat detection, incident response, vulnerability management, and the use of SIEM, EDR/XDR, other security monitoring platforms, IAM solutions and processes.
  • Strong understanding of modern security threats, attack vectors, and defensive strategies.
  • Expertise in security frameworks (e.g., NIST, MITRE ATT&CK) and their practical application in threat detection, analysis, and incident response.
  • Exceptional communication and interpersonal skills, with the ability to influence and effectively collaborate with technical and non-technical stakeholders at all levels, including executive leadership.
  • Demonstrated ability to translate complex operational security incidents and risks into clear, actionable strategies and communicate effectively to diverse audiences.
  • Relevant industry certifications highly preferred (e.g., CISSP, CISM, GCIH, GCIA, or OSCP).
  • Bachelor’s degree in Computer Science, Information Security, or a related technical field; Master’s degree a plus.

Compensation, Benefits, & Perks

đź’» Work from home with a remote-first community

🏝 Unlimited PTO (and the encouragement to use it)

📝 Student loan payback program

🏥 100% employer-covered medical, dental, and vision options available to you and your dependents

đź’¸ Flexible Spending Account (FSA)

🏠 Monthly stipend toward your WFH setup, vacation, development and more

đź’° Employer-sponsored 401(k) with contribution match

🏋🏻‍♀️ Subsidized ClassPass Membership

🍼 Generous Paid Parental Leave

đź’˛ Hiring Ranges:

  • Tier 1: $80,000 - $100,000
  • Tier 2: $70,000 - $90,000

Unqork employs a market-driven approach to establish compensation ranges. In addition to a base salary, employees may also be eligible to receive a target incentive and company equity in the form of stock options.

An employee’s compensation within the range provided above depends on a variety of factors including, but not limited to, their location, role, skillset, level of experience, and similar peer salaries. As a remote-first company, Unqork incorporates a geographic differential into our compensation structure, depending on the candidate’s location. We utilize a tiered system—Tier 1 and Tier 2—to accurately reflect local market rates and ensure our compensation packages are both fair and competitive.

Our geographic tiers are defined as follows:

  • Tier 1: New York Metro, Seattle Metro, San Francisco Bay Area
  • Tier 2: All other US and US territory locations

Unqork embraces a culture of security and privacy awareness by consistently safeguarding sensitive information, adhering to company policies, and actively participating in training and initiatives to protect our data and the privacy of our stakeholders.

Unqork is an equal opportunity employer. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.

Read the full description
Security Security Risk Management Specialist II at Affirm

Evaluates third-party vendor security risks, builds automation workflows to scale GRC processes, and partners cross-functionally on security governance decisions.

Mid Posted about 14 hours ago RemoteFirstJobs Product
What this role involves

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

About the Team

Affirm values security as being critical to the company’s continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.

About the Role

The ideal candidate will evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable applying security policy to real-world vendor decisions and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will develop deep expertise across the security risk domain, partner closely with business and engineering stakeholders, and play an active role in Affirm’s transformation of Security Risk Management from a compliance-oriented function into a security engineering discipline.

What You’ll Do

We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm’s Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.

  • You will conduct third-party security assessments, reviewing vendor questionnaires, evaluating security controls, and documenting risk findings as a core contributor to Affirm’s TPRM program.
  • You will build and maintain automation to reduce manual GRC workflows, using Python, low-code platforms, and agentic coding tools to improve program efficiency and scale.
  • You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent and repeatable workflow execution.
  • You will partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
  • You will help develop and maintain dashboards, metrics, and reporting that give stakeholders clear visibility into third-party risk posture.
  • You will contribute to process improvements and program documentation that mature Affirm’s security governance over time.

What We Look For

  • You have 3+ years of experience in Information Security, Risk Management, Compliance, or a related field.
  • You are comfortable using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and have working knowledge of Python for scripting or automation.
  • You have familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
  • You have working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
  • You communicate clearly in writing and verbally, and can translate security risk concepts for both technical and non-technical audiences.
  • You hold (or are working toward) a professional certification such as CISSP, CISM, CISA, or CRISC or bring equivalent practical experience. A BA/BS in a relevant field, or equivalent experience, is preferred.

Compensation & Benefits

Base Pay Grade - 3

Equity Grade - 4

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $130,000 - 180,000

USA Sapphire base pay range (all other U.S. states) per year: $115,000 - 165,000

Please note that visa sponsorship is not available for this position.

#LI-Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:

  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking “Submit Application,” you acknowledge that you have read Affirm’s Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Read the full description
Security Insider Risk Analyst (Remote, GBR)

Analyzes and monitors insider threats and suspicious user behavior to mitigate security risks within an organization.

Mid Remote Posted about 14 hours ago Himalayas
What this role involves
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations.
Read the full description
Security Product Security Engineer

Conducts comprehensive security assessments across mobile apps, IoT devices, firmware, compiled software, and browser extensions.

Mid Posted about 14 hours ago Himalayas
What this role involves
The Product Security Engineer is responsible for conducting comprehensive security assessments on various products, including mobile applications, IoT hardware/firmware, compiled software, and browser extensions.
Read the full description
Security Security Specialist – EMEA (location flexible)

Manages security operations, incident response, and compliance for a cloud infrastructure company serving enterprise customers across EMEA regions.

Mid Remote Posted about 21 hours ago Jobicy AI
What this role involves
About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 4,000 customers and ARR that...
Read the full description
Security Associate Offensive Security Consultant at SpecterOps

Conducts offensive security assessments, penetration tests, and red team operations for enterprise clients while developing tools and training materials.

Junior Remote Posted about 22 hours ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for an Associate Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Associate Consultant - $100,000 - $125,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Associate Consultant:

As an Associate Consultant, your primary responsibility will be to learn. You will engage in, participate in, and contribute to the execution of various services and projects. In doing so, you will develop a foundational understanding of the SpecterOps Adversary Simulation service line and enhance your skills in one or more technical areas.

Desired Qualifications:

  • Foundational knowledge of offensive security concepts and assessments
  • Foundational knowledge of security principles, policies, and industry best practices
  • Working knowledge of Windows and *NIX-based operating systems
  • Working knowledge of networking concepts
  • Working knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Proficient written/verbal communication and interpersonal skills
  • A strong determination to improve both personal skills and the overall information security community through research efforts, including blog posts, conference presentations, open-source tool releases, and white paper publications
  • Willingness to support the delivery of public and private training offerings (e.g. providing lab support, addressing student questions, etc.)

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and quarterly bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $150 monthly cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Offensive Security Consultant at SpecterOps

Conducts offensive security assessments, penetration tests, and red team operations for enterprise clients while developing tools, training team members, and communicating findings to stakeholders.

Mid Remote Posted about 22 hours ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for an Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Consultant - $120,000 - $150,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Desired Qualifications:

  • Working knowledge of offensive security concepts and assessments
  • Working knowledge of security principles, policies, and industry best practices
  • Working knowledge of Windows and *NIX-based operating systems
  • Working knowledge of networking concepts
  • Working knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Proficient written/verbal communication and interpersonal skills
  • Independently contribute to significant services and projects
  • Ability to lead small teams and engagements
  • Ability to manage multiple projects at once
  • Ability to effectively communicate with clients, team members, and management for project delivery
  • Ability to manage client projects with limited supervision
  • Willingness to lead and execute offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, offensive maturity assessment, etc.)
  • Willingness to develop and deliver training content as a lead course instructor
  • Willingness to mentor and train fellow consultants

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and quarterly bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $150 monthly cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Senior Offensive Security Consultant at SpecterOps

Senior consultant conducting offensive security assessments, red team operations, penetration tests, and training team members on adversary tactics and tools.

Senior Remote Posted about 22 hours ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for a Senior Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Senior Consultant - $145,000 - $170,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Desired Qualifications:

  • Proficient knowledge of offensive security concepts and assessments
  • Proficient knowledge of security principles, policies, and industry best practices
  • Proficient knowledge of Windows and *NIX-based operating systems
  • Proficient knowledge of networking concepts
  • Proficient knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Strong written/verbal communication and interpersonal skills
  • A clear expert in one or more service lines and/or technical areas
  • Experience leading small teams and engagements
  • Experience managing multiple projects at once
  • Experience communicating with clients and delivering presentations
  • Experience independently managing client projects
  • Ability to lead and execute majority of offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, offensive maturity assessment, etc.)
  • Willingness to develop and deliver training content as a lead course instructor
  • Willingness to mentor and train fellow consultants

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $1800 annual cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Managed SIEM Detection Engineer at Expel

Detection engineer who authors and tunes SIEM detection rules, closes security coverage gaps, and optimizes customer SIEM platforms for cost and performance.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel’s professional services practice is just getting started, and we’re looking for the technical expert who’ll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You’ll bring hands-on skill to a team that’s finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here’s the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You’re the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won’t stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel’s professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor’s degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we’re primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You’ll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We’re only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We’ll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range

$111,900—$162,300 USD

Read the full description
Security Cyber Threat Intel Analyst at Wiz

Analyzes cyber threats targeting cloud environments, synthesizes threat intelligence from multiple sources, and produces detailed threat research reporting.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we’re now powered by Google, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.

Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!

SUMMARY

Wiz is looking for a Cyber Threat Analyst to join the Threat Research team and spread the power of Wiz. In this role, you will track, analyze and report on the most advanced threats targeting cloud environments.

WHAT YOU’LL DO

  • Synthesize data from a wide range of internal and external sources do help develop a comprehensive picture of the threats affecting cloud, AI and developers.
  • Analyze and track the state-backed and financially motivated attackers that target cloud ecosystems.
  • Communicate novel findings and in depth analyses of cyber threat activity to multiple audiences and in multiple formats.
  • Leverage open and closed data to track the infrastructure and malware used by advanced actors
  • Investigate and attribute incidents, campaigns and actors to understand who is targeting customers and what motivates them.

WHAT YOU’LL BRING

  • 3+ years of experience in security or threat research, with a proven track record of producing detailed and novel analysis and reporting.
  • Ability to bring together multiple independent data sources to develop a comprehensive picture of a campaign.
  • Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis or cloud log analysis.
  • Excellent analytic judgement and familiarity with attribution and making complex, evidence based assessments.
  • Ability to write quickly and clearly about technical topics.

ADVANTAGE

  • Familiarity working with large-scale telemetry, especially infrastructure hunting and pivoting through query languages and scripting
  • Knowledge of the major cloud and identity providers (AWS, GCP, Azure), Kubernetes, and modern cloud-native architectures.
  • Experience writing finished intelligence reports for multiple audiences.
  • Track record of public communication of novel and newsworthy findings

Compensation + Benefits

Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

The US base salary range for this full-time position is listed below.

US Base Pay Range

$160,000—$220,000 USD

Applicants must have the legal right to work in the country where the position is based, without the need forvisa sponsorship.This role does not offervisasponsorship.

Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz’s Privacy Policy.

Read the full description
Security Freelancer - OSINT/WEBINT Experts

Conducts open-source and web-based intelligence research to identify security threats and risks for trust and safety operations.

Remote Posted 1 day ago Himalayas
What this role involves
DescriptionAlice. io (formerly known as ActiveFence) is a leading trust, safety, and security company.
Read the full description
Security Senior Security Engineer

Designs and implements security systems, manages vulnerabilities, and protects company infrastructure and customer data.

Senior Posted 1 day ago Himalayas
What this role involves
Root is on a mission to unbreak insurance by creating experiences people love at prices they can't believe.
Read the full description
Security Security Developer at Python Software Foundation

Triages and remediates vulnerabilities in CPython and PyPI, handles malware/supply-chain attacks, and develops security tooling and infrastructure for the Python ecosystem.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

Working with the Python Security Response Team, Python core team, and Python Package Index (PyPI) admins to ensure Python is secure for its global and diverse user base. The core mandate for this role is to drive vulnerability reports to remediations and advisories, mitigating malware on the PyPI, and developing solutions to scale our capacity to respond ahead of the growth curve.

You’ll be part of the small-but-mighty team at the Python Software Foundation, the US non-profit organization working every day to help Python and its community thrive. Most of your days will be time-boxing between day-to-day vulnerability coordination and malware handling work alongside long-term projects like documentation, tool development, and gathering and sharing metrics.

Core Responsibilities & Development

  • Triage and remediate vulnerabilities in CPython and related projects in coordination with the Python core team.
  • Remediate malware and supply-chain attacks for projects on the Python Package Index.
  • Maintain and operate infrastructure for the Python Security Response Team, PSF CVE Numbering Authority, and security tools in use by Python, like OSS-Fuzz.
  • Propose and develop improvements to the above workflows to scale the response to meet future demand.

Standards, Documentation, Communications

  • Work with the Python Security Response Team and Python core team to develop and refine vulnerability and secure development practices.
  • Work with the Python core team to document the security and threat models for the Python programming language, standard library, and related projects.
  • Researching, authoring, and publishing public communications about metrics, impact, and potential future work for Python security.

Qualifications

3-5 years experience with Python or C programming languages. Knowledge about vulnerabilities affecting programs written in C, such as memory safety issues. Asynchronous and written communication skills with the ability to manage and prioritize multiple concurrent threads. Experience working with open source projects and communities is a plus.

Security certifications are not required. An ideal candidate will have a collaborative and flexible attitude suited to working with a community of passionate volunteers on small, mutually-supporting teams. Don’t worry if you don’t check all the boxes or aren’t a “security expert”, above all we’re looking for someone who is eager to learn while securing the many domains and users the Python language serves.

Desired Experience

Experience with secure development practices for Python and C programming languages. Experience with vulnerability disclosure, CVE, security teams, and threat models. Experience with code quality and security tools like fuzz-testing, address and memory sanitizers. Experience writing technical documentation. Experience working in public or with open source projects.

Details

  • Location: Remote. US-based candidates strongly preferred; regular collaboration with US timezones required. Exceptional international candidates may be considered under a contractor arrangement.
  • Compensation: $70K–$170K for US employees (based on experience), or a comparable contractor rate for international candidates. US employees are eligible for healthcare and other benefits; contractor engagements do not include benefits.
  • Term: 1 year, with possibility of renewal
  • Travel: One trip per year to PyCon US.

The Python Software Foundation is a US 501©(3) non-profit corporation that holds the intellectual property rights behind the Python programming language. We also run the PyCon US conference annually, support other Python conferences/workshops around the world, and fund Python-related development with our grants program. To see more info about the PSF, check out our Annual Impact Report and public records.

We believe that the future of open source must include everyone. We welcome all job-seekers regardless of race, color, ethnicity, religion, age, sexual orientation, gender identity or expression, national origin, physical appearance, body size, socio-economic, veteran or disability status. Python is a global community and the PSF aims to support a safe environment for all. More information can be found on our Code of Conduct page.

Read the full description
Security Product Security Engineer III at Carolinas Investment Consulting

Builds secure infrastructure and tools for engineers, combining software development with application security expertise to enable safe healthcare platform scaling.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Our healthcare system is the leading cause of personal bankruptcy in the U.S. Every year, over 50 million Americans suffer adverse financial consequences as a result of seeking care, from lower credit scores to garnished wages. The challenge is only getting worse, as high deductible health plans are the fastest growing plan design in the U.S.

Cedar’s mission is to leverage data science, smart product design and personalization to make healthcare more affordable and accessible. Today, healthcare providers still engage with its consumers in a “one-size-fits-all” approach; and Cedar is excited to leverage consumer best practices to deliver a superior experience.

Location: Remote

Our healthcare system is the leading cause of personal bankruptcy in the U.S. Every year, over 50 million Americans suffer adverse financial consequences as a result of seeking care, from lower credit scores to garnished wages. The challenge is only getting worse, as high deductible health plans are the fastest growing plan design in the U.S.

Cedar’s mission is to leverage data science, smart product design and personalization to securely make healthcare more affordable and accessible. Today, healthcare providers still engage with its consumers in a “one-size-fits-all” approach; and Cedar is excited to leverage consumer best practices to deliver a superior experience.

The Role

The Product Security team at Cedar combines software development with deep application security expertise in order to help build our patient-focused solutions efficiently and safely. As a Product Security Engineer at Cedar, you will work with an inquisitive, diverse, and experienced team on a platform that is rapidly scaling. You’ll help solve problems that matter, affecting tens of millions of patients annually.

Our core tenets include using good judgment and having the autonomy to be successful. Your role will be to build secure, supportable secure paths for other engineers to follow and help accelerate Cedar Engineering’s mission. Whether it’s an improvement on single sign on experience, a smoother UI for credential management, or multi-tenant encrypted vault solutions, Cedar Product Security Engineers build the security tools others need to do their work more safely and more efficiently.

At Cedar, we don’t require experience with particular languages, but deep familiarity with modern and industry-standard technologies, like Python, Go, and Kotlin are a plus.

About You

  • You’re an application security engineer who prioritizes addressing security challenges with technology, not process
  • You love building services and tools that help product and platform engineers build, deploy, and maintain products that help hundreds of millions of people
  • You have experience with security code review, threat modeling or security architecture reviews.
  • You’re proficient in Python, Go, or Kotlin

Bonus Points if you have

  • Familiarity with HIPAA, PCI, and the unique considerations around securing health and payments data
  • Experience creating developer focused security tooling or libraries
  • Participation in security capture-the-flag events

Responsibilities

  • Create and extend services and tools that help product and platform engineers build, deploy, and maintain Cedar products safely and efficiently.
  • Serve as a Security Partner for multiple engineering teams across the SSDLC, evangelizing security and helping threat model features, bake security into designs, and review code and implementations
  • Contribute to security automation projects, such as static analysis, vulnerability management, and asset inventory

What do we offer to the ideal candidate?

  • A chance to improve the U.S. healthcare system at a fast-moving company! Our leading healthcare financial platform is scaling rapidly, helping millions of patients per year
  • Flexibility to work from home or in the office, depending on what works best for you
  • Unlimited PTO for vacation, sick and mental health days–we encourage everyone to take at least 20 days of vacation per year to ensure dedicated time to spend with loved ones, explore, rest and recharge
  • 16 weeks paid parental leave with health benefits for all parents, plus flexible re-entry schedules for returning to work
  • Diversity initiatives that encourage Cedarians to bring their whole selves to work, including three employee resource groups: be@cedar (for BIPOC-identifying Cedarians and their allies), Pridecones (for LGBTQIA+ Cedarians and their allies) and Cedar Women+ (for female-identifying Cedarians)
  • Competitive pay, equity (for qualifying roles) and health benefits that start on your first day
  • 401k plan with 3% employer non-election contribution
  • Access to hands-on mentorship, employee and management coaching, and a stipend for learning and development resources to help you grow both professionally and personally

About us

Cedar was co-founded by Florian Otto and Arel Lidow in 2016 after a negative medical billing experience inspired them to help improve our healthcare system. With a commitment to solving billing and patient experience issues, Cedar has become a leading healthcare technology company fueled by remarkable growth. “Over the past several years, we’ve raised more than $350 million in funding & have the active support of Thrive and Andreessen Horowitz (a16z).

Compensation Range and Benefits

  • Salary/Hourly Rate Range: $157,250-$185,000
  • This role is also bonus and equity eligible
  • This role offers a competitive benefits and wellness package

*Subject to location, experience, and education

What do we offer to the ideal candidate?

  • A chance to improve the U.S. healthcare system at a high-growth company! Our leading healthcare financial platform is scaling rapidly, helping millions of patients per year
  • Unless stated otherwise, most roles have flexibility to work from home or in the office, depending on what works best for you
  • For exempt employees: Unlimited PTO for vacation, sick and mental health days–we encourage everyone to take at least 20 days of vacation per year to ensure dedicated time to spend with loved ones, explore, rest and recharge
  • 16 weeks paid parental leave with health benefits for all parents, plus flexible re-entry schedules for returning to work
  • Diversity initiatives that encourage Cedarians to bring their whole selves to work, including three employee resource groups: be@cedar (for BIPOC-identifying Cedarians and their allies), Pridecones (for LGBTQIA+ Cedarians and their allies) and Cedar Women+ (for female-identifying Cedarians)
  • Competitive pay, equity (for qualifying roles), and health benefits, including fertility & adoption assistance, that start on the first of the month following your start date (or on your start date if your start date coincides with the first of the month)
  • Cedar matches 100% of your 401(k) contributions, up to 3% of your annual compensation
  • Access to hands-on mentorship, employee and management coaching, and a team discretionary budget for learning and development resources to help you grow both professionally and personally

About us

Cedar was co-founded by Florian Otto and Arel Lidow in 2016 after a negative medical billing experience inspired them to help improve our healthcare system. With a commitment to solving billing and patient experience issues, Cedar has become a leading healthcare technology company fueled by remarkable growth. “Over the past several years, we’ve raised more than $350 million in funding & have the active support of Thrive and Andreessen Horowitz (a16z).

As of November 2024, Cedar is engaging with 26 million patients annually and is on target to process $3.5 billion in patient payments annually. Cedar partners with more than 55 leading healthcare providers and payers including Highmark Inc., Allegheny Health Network, Novant Health, Allina Health and Providence.

Read the full description
Security Regional Director - Cybersecurity | Remote, South Central Enterprise

Leads regional cybersecurity strategy and operations for enterprise clients across the South Central US.

Lead Remote Posted 3 days ago Himalayas
What this role involves
This position is Remote and must be based in Texas with a strong preference for candidates located in the Houston or Dallas-Fort Worth Area.
Read the full description
Security Senior Application Security Engineer

Senior application security engineer secures blockchain and web3 applications by identifying vulnerabilities, designing security controls, and protecting against threats.

Senior Posted 3 days ago Jobicy AI
What this role involves
Consensys is the leading blockchain and web3 software company. Founded by Joe Lubin, CEO of Consensys and Co-Founder of Ethereum in 2014, Consensys has been at the forefront of innovation,...
Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer leads application security, vulnerability management, and detection engineering across a global wellness platform, embedding security practices into product development.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer drives application security, vulnerability management, and detection engineering across a global wellness platform, embedding security into product development and owning security controls end-to-end.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Staff Security Engineer | AppSec at Gympass

Staff Security Engineer leads application security initiatives across multiple domains including vulnerability management, threat modeling, pentesting, and incident response.

Lead Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Staff Security Engineer | AppSec to our Information Security team in Brazil! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our subscription-based product serving millions of users globally. As a Staff Security Engineer, you will own multiple security domains end-to-end — with your center of gravity in software security (secure SDLC, vulnerability management, threat modeling, pentesting, and red teaming) while reaching across incident response, threat intelligence, cloud security, and compliance as the team’s mandate requires.

You will become the organization’s go-to authority for the hardest, cross-domain security trade-offs — the ones without an obvious owner. By connecting pentest findings, incident root causes, compliance requirements, and cloud misconfigurations into a unified risk strategy, you will shape baseline security standards, mentor engineering teams, and drive medium-to-large strategic initiatives that scale with our growth.

YOUR IMPACT

  • Own multiple security domains end-to-end, serving as the technical authority for complex, cross-service security challenges across the entire organization.
  • Establish secure-by-design architectural standards, lead threat modeling sessions, and set the secure-coding benchmarks that other engineers follow.
  • Drive complex, cross-service incident responses and post-mortems, converting critical findings into systemic guardrails and platform-level preventions.
  • Lead offensive and defensive strategy initiatives—including Red Team exercises and pentest engagements—driving root-cause remediation directly with engineering teams.
  • Ensure organization-wide security posture by setting SLAs, SLOs, and KPIs (remediation windows, response times, posture drift), building the monitoring needed to hold teams accountable.
  • Partner with cross-functional leadership (Engineering, Product, Legal) to align threat intelligence, compliance needs, and long-term security investments with business priorities.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life wellness.

WHO YOU ARE

  • A seasoned security specialist with extensive experience in Security Engineering (or software engineering with high security impact) and a proven track record of scaling security in complex cloud environments.
  • An adaptable professional with a willingness to step outside your primary focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A strategic technical partner with expert knowledge in secure architecture design, threat modeling, and setting engineering-wide secure coding standards.
  • An influential communicator with fluency in English and Portuguese, able to translate intricate security tradeoffs into clear risk statements for executive leadership and product partners.
  • A pragmatic risk navigator with the ability to balance long-term risk reduction against business velocity, making high-stakes decisions independently.
  • A forward-thinking specialist with a deep understanding of attacker TTPs, modern cloud ecosystems (AWS/EKS, GCP/GKE, Istio, ArgoCD), and regulatory frameworks (SOC 2, ISO 27001, LGPD, GDPR).
  • A dedicated mentor with prior work experience guiding and uplifting engineering teams to foster a security-minded engineering culture.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement.

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

Want to see what it’s really like to work here? Follow us on Instagram @lifeatwellhub and watch our team video on YouTube !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description