Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Security Operations Analyst at Unqork

Monitors security alerts and threats across SIEM/EDR/XDR tools, triages incidents, implements automations, and partners cross-functionally to protect company assets.

Mid Posted about 16 hours ago RemoteFirstJobs Product
What this role involves

Unqork empowers enterprises to accelerate growth by rapidly building, testing, and running AI-powered applications that embody the future of enterprise development. Trusted by the world’s largest organizations in highly regulated industries, these applications become more secure over time while significantly reducing technical debt—allowing businesses to focus on innovation rather than maintenance. Unqork’s customers include Goldman Sachs, Marsh, BlackRock, and the U.S. Department of Health and Human Services.

At Unqork, we value inclusive and innovative thinkers who boldly challenge the status quo. We encourage you to apply!

The Impact U will make:

As a Security Operations Analyst, you will be an analytical and thorough individual contributor reporting to the Director of Security Operations. You will play a role in Threat Detection & Response, Threat Intelligence and Hunting, Technical Security Architecture, IT Operations, and SIEM and SOAR engineering. Your primary focus will be to proactively and reactively protect and defend our critical assets against an evolving threat landscape.

  • Security Monitoring & Alert Triage Actively monitor SIEM, EDR/XDR, and other security tools to detect, analyze, and triage security alerts. Follow established playbooks to ensure timely and accurate initial response to potential threats.
  • Process Efficiency & Automation Utilize existing Security Orchestration, Automation, and Response (SOAR) platforms to handle alerts efficiently. Identify repetitive manual tasks and implement automations.
  • SIEM & Detection Engineering Integrate and set up the ingestion of log sources to a SIEM tool, including the normalization of fields and data. Create timely monitoring solutions for relevant threats based on active threat intelligence. Share responsibility for detection and log lifecycle / maintenance.
  • Threat Intelligence Consume and review daily threat intelligence feeds, security advisories, and industry alerts to ensure the company is protected against known Indicators of Compromise (IoCs) and emerging threat trends.
  • IT Operations & Asset Security Work closely with IT Operations to maintain accurate hardware and software asset inventories. Assist in deploying and troubleshooting endpoint security agents to ensure a secure baseline for all employee devices.
  • Cross-Functional Technical Partnership: Collaborate extensively with resources in Engineering, Product, IT, and other departments to embed operational security requirements, influence architectural decisions for detectability, and foster a strong security culture. Serve as the primary security technical expert for these partnerships.
  • Compliance & Operational Reporting: Assist in generating routine security metrics and operational reports. Help gather technical evidence to support adherence to security policies and compliance audits (e.g., SOC 2, ISO 27001).

What U bring:

  • 3+ years of progressive experience in Security Operations, with at least 2  years in a role contributing to a Security Operations Center (SOC), Managed Detection Response Service, or Incident Response team.
  • Proven track record as an engineer, having designed, implemented, and managed mature SOC processes and automations.
  • Proven hands-on Python experience.
  • Proven hands-on technical expertise in threat detection, incident response, vulnerability management, and the use of SIEM, EDR/XDR, other security monitoring platforms, IAM solutions and processes.
  • Strong understanding of modern security threats, attack vectors, and defensive strategies.
  • Expertise in security frameworks (e.g., NIST, MITRE ATT&CK) and their practical application in threat detection, analysis, and incident response.
  • Exceptional communication and interpersonal skills, with the ability to influence and effectively collaborate with technical and non-technical stakeholders at all levels, including executive leadership.
  • Demonstrated ability to translate complex operational security incidents and risks into clear, actionable strategies and communicate effectively to diverse audiences.
  • Relevant industry certifications highly preferred (e.g., CISSP, CISM, GCIH, GCIA, or OSCP).
  • Bachelor’s degree in Computer Science, Information Security, or a related technical field; Master’s degree a plus.

Compensation, Benefits, & Perks

đź’» Work from home with a remote-first community

🏝 Unlimited PTO (and the encouragement to use it)

📝 Student loan payback program

🏥 100% employer-covered medical, dental, and vision options available to you and your dependents

đź’¸ Flexible Spending Account (FSA)

🏠 Monthly stipend toward your WFH setup, vacation, development and more

đź’° Employer-sponsored 401(k) with contribution match

🏋🏻‍♀️ Subsidized ClassPass Membership

🍼 Generous Paid Parental Leave

đź’˛ Hiring Ranges:

  • Tier 1: $80,000 - $100,000
  • Tier 2: $70,000 - $90,000

Unqork employs a market-driven approach to establish compensation ranges. In addition to a base salary, employees may also be eligible to receive a target incentive and company equity in the form of stock options.

An employee’s compensation within the range provided above depends on a variety of factors including, but not limited to, their location, role, skillset, level of experience, and similar peer salaries. As a remote-first company, Unqork incorporates a geographic differential into our compensation structure, depending on the candidate’s location. We utilize a tiered system—Tier 1 and Tier 2—to accurately reflect local market rates and ensure our compensation packages are both fair and competitive.

Our geographic tiers are defined as follows:

  • Tier 1: New York Metro, Seattle Metro, San Francisco Bay Area
  • Tier 2: All other US and US territory locations

Unqork embraces a culture of security and privacy awareness by consistently safeguarding sensitive information, adhering to company policies, and actively participating in training and initiatives to protect our data and the privacy of our stakeholders.

Unqork is an equal opportunity employer. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.

Read the full description
Security Security Risk Management Specialist II at Affirm

Evaluates third-party vendor security risks, builds automation workflows to scale GRC processes, and partners cross-functionally on security governance decisions.

Mid Posted about 16 hours ago RemoteFirstJobs Product
What this role involves

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.

About the Team

Affirm values security as being critical to the company’s continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.

About the Role

The ideal candidate will evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable applying security policy to real-world vendor decisions and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will develop deep expertise across the security risk domain, partner closely with business and engineering stakeholders, and play an active role in Affirm’s transformation of Security Risk Management from a compliance-oriented function into a security engineering discipline.

What You’ll Do

We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm’s Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.

  • You will conduct third-party security assessments, reviewing vendor questionnaires, evaluating security controls, and documenting risk findings as a core contributor to Affirm’s TPRM program.
  • You will build and maintain automation to reduce manual GRC workflows, using Python, low-code platforms, and agentic coding tools to improve program efficiency and scale.
  • You will configure and maintain integrations across ticketing, GRC, and vendor management platforms to support consistent and repeatable workflow execution.
  • You will partner with Procurement, Legal, Engineering, IT, Compliance, and Privacy on third-party risk reviews, follow-up actions, and risk-informed decisions.
  • You will help develop and maintain dashboards, metrics, and reporting that give stakeholders clear visibility into third-party risk posture.
  • You will contribute to process improvements and program documentation that mature Affirm’s security governance over time.

What We Look For

  • You have 3+ years of experience in Information Security, Risk Management, Compliance, or a related field.
  • You are comfortable using agentic coding tools (e.g., Cursor, Claude Code, Copilot) and have working knowledge of Python for scripting or automation.
  • You have familiarity with cloud environments (AWS, GCP, or Azure) and common cloud security concepts.
  • You have working knowledge of security frameworks and standards such as NIST, ISO 27001, SOC 2, and PCI DSS.
  • You communicate clearly in writing and verbally, and can translate security risk concepts for both technical and non-technical audiences.
  • You hold (or are working toward) a professional certification such as CISSP, CISM, CISA, or CRISC or bring equivalent practical experience. A BA/BS in a relevant field, or equivalent experience, is preferred.

Compensation & Benefits

Base Pay Grade - 3

Equity Grade - 4

Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)

USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $130,000 - 180,000

USA Sapphire base pay range (all other U.S. states) per year: $115,000 - 165,000

Please note that visa sponsorship is not available for this position.

#LI-Remote

Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.

We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:

  • Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents
  • Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses
  • Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge
  • ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount

We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.

By clicking “Submit Application,” you acknowledge that you have read Affirm’s Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.

Read the full description
Security Insider Risk Analyst (Remote, GBR)

Analyzes and monitors insider threats and suspicious user behavior to mitigate security risks within an organization.

Mid Remote Posted about 16 hours ago Himalayas
What this role involves
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations.
Read the full description
Security Product Security Engineer

Conducts comprehensive security assessments across mobile apps, IoT devices, firmware, compiled software, and browser extensions.

Mid Posted about 16 hours ago Himalayas
What this role involves
The Product Security Engineer is responsible for conducting comprehensive security assessments on various products, including mobile applications, IoT hardware/firmware, compiled software, and browser extensions.
Read the full description
Security Security Specialist – EMEA (location flexible)

Manages security operations, incident response, and compliance for a cloud infrastructure company serving enterprise customers across EMEA regions.

Mid Remote Posted about 23 hours ago Jobicy AI
What this role involves
About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 4,000 customers and ARR that...
Read the full description
Security Offensive Security Consultant at SpecterOps

Conducts offensive security assessments, penetration tests, and red team operations for enterprise clients while developing tools, training team members, and communicating findings to stakeholders.

Mid Remote Posted about 24 hours ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for an Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Consultant - $120,000 - $150,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Desired Qualifications:

  • Working knowledge of offensive security concepts and assessments
  • Working knowledge of security principles, policies, and industry best practices
  • Working knowledge of Windows and *NIX-based operating systems
  • Working knowledge of networking concepts
  • Working knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Proficient written/verbal communication and interpersonal skills
  • Independently contribute to significant services and projects
  • Ability to lead small teams and engagements
  • Ability to manage multiple projects at once
  • Ability to effectively communicate with clients, team members, and management for project delivery
  • Ability to manage client projects with limited supervision
  • Willingness to lead and execute offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, offensive maturity assessment, etc.)
  • Willingness to develop and deliver training content as a lead course instructor
  • Willingness to mentor and train fellow consultants

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and quarterly bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $150 monthly cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Managed SIEM Detection Engineer at Expel

Detection engineer who authors and tunes SIEM detection rules, closes security coverage gaps, and optimizes customer SIEM platforms for cost and performance.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel’s professional services practice is just getting started, and we’re looking for the technical expert who’ll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You’ll bring hands-on skill to a team that’s finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here’s the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You’re the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won’t stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel’s professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor’s degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we’re primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You’ll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We’re only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We’ll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range

$111,900—$162,300 USD

Read the full description
Security Cyber Threat Intel Analyst at Wiz

Analyzes cyber threats targeting cloud environments, synthesizes threat intelligence from multiple sources, and produces detailed threat research reporting.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we’re now powered by Google, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.

Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!

SUMMARY

Wiz is looking for a Cyber Threat Analyst to join the Threat Research team and spread the power of Wiz. In this role, you will track, analyze and report on the most advanced threats targeting cloud environments.

WHAT YOU’LL DO

  • Synthesize data from a wide range of internal and external sources do help develop a comprehensive picture of the threats affecting cloud, AI and developers.
  • Analyze and track the state-backed and financially motivated attackers that target cloud ecosystems.
  • Communicate novel findings and in depth analyses of cyber threat activity to multiple audiences and in multiple formats.
  • Leverage open and closed data to track the infrastructure and malware used by advanced actors
  • Investigate and attribute incidents, campaigns and actors to understand who is targeting customers and what motivates them.

WHAT YOU’LL BRING

  • 3+ years of experience in security or threat research, with a proven track record of producing detailed and novel analysis and reporting.
  • Ability to bring together multiple independent data sources to develop a comprehensive picture of a campaign.
  • Basic to intermediate technical analysis skills such as infrastructure analysis, malware analysis or cloud log analysis.
  • Excellent analytic judgement and familiarity with attribution and making complex, evidence based assessments.
  • Ability to write quickly and clearly about technical topics.

ADVANTAGE

  • Familiarity working with large-scale telemetry, especially infrastructure hunting and pivoting through query languages and scripting
  • Knowledge of the major cloud and identity providers (AWS, GCP, Azure), Kubernetes, and modern cloud-native architectures.
  • Experience writing finished intelligence reports for multiple audiences.
  • Track record of public communication of novel and newsworthy findings

Compensation + Benefits

Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

The US base salary range for this full-time position is listed below.

US Base Pay Range

$160,000—$220,000 USD

Applicants must have the legal right to work in the country where the position is based, without the need forvisa sponsorship.This role does not offervisasponsorship.

Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz’s Privacy Policy.

Read the full description
Security Security Developer at Python Software Foundation

Triages and remediates vulnerabilities in CPython and PyPI, handles malware/supply-chain attacks, and develops security tooling and infrastructure for the Python ecosystem.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

Working with the Python Security Response Team, Python core team, and Python Package Index (PyPI) admins to ensure Python is secure for its global and diverse user base. The core mandate for this role is to drive vulnerability reports to remediations and advisories, mitigating malware on the PyPI, and developing solutions to scale our capacity to respond ahead of the growth curve.

You’ll be part of the small-but-mighty team at the Python Software Foundation, the US non-profit organization working every day to help Python and its community thrive. Most of your days will be time-boxing between day-to-day vulnerability coordination and malware handling work alongside long-term projects like documentation, tool development, and gathering and sharing metrics.

Core Responsibilities & Development

  • Triage and remediate vulnerabilities in CPython and related projects in coordination with the Python core team.
  • Remediate malware and supply-chain attacks for projects on the Python Package Index.
  • Maintain and operate infrastructure for the Python Security Response Team, PSF CVE Numbering Authority, and security tools in use by Python, like OSS-Fuzz.
  • Propose and develop improvements to the above workflows to scale the response to meet future demand.

Standards, Documentation, Communications

  • Work with the Python Security Response Team and Python core team to develop and refine vulnerability and secure development practices.
  • Work with the Python core team to document the security and threat models for the Python programming language, standard library, and related projects.
  • Researching, authoring, and publishing public communications about metrics, impact, and potential future work for Python security.

Qualifications

3-5 years experience with Python or C programming languages. Knowledge about vulnerabilities affecting programs written in C, such as memory safety issues. Asynchronous and written communication skills with the ability to manage and prioritize multiple concurrent threads. Experience working with open source projects and communities is a plus.

Security certifications are not required. An ideal candidate will have a collaborative and flexible attitude suited to working with a community of passionate volunteers on small, mutually-supporting teams. Don’t worry if you don’t check all the boxes or aren’t a “security expert”, above all we’re looking for someone who is eager to learn while securing the many domains and users the Python language serves.

Desired Experience

Experience with secure development practices for Python and C programming languages. Experience with vulnerability disclosure, CVE, security teams, and threat models. Experience with code quality and security tools like fuzz-testing, address and memory sanitizers. Experience writing technical documentation. Experience working in public or with open source projects.

Details

  • Location: Remote. US-based candidates strongly preferred; regular collaboration with US timezones required. Exceptional international candidates may be considered under a contractor arrangement.
  • Compensation: $70K–$170K for US employees (based on experience), or a comparable contractor rate for international candidates. US employees are eligible for healthcare and other benefits; contractor engagements do not include benefits.
  • Term: 1 year, with possibility of renewal
  • Travel: One trip per year to PyCon US.

The Python Software Foundation is a US 501©(3) non-profit corporation that holds the intellectual property rights behind the Python programming language. We also run the PyCon US conference annually, support other Python conferences/workshops around the world, and fund Python-related development with our grants program. To see more info about the PSF, check out our Annual Impact Report and public records.

We believe that the future of open source must include everyone. We welcome all job-seekers regardless of race, color, ethnicity, religion, age, sexual orientation, gender identity or expression, national origin, physical appearance, body size, socio-economic, veteran or disability status. Python is a global community and the PSF aims to support a safe environment for all. More information can be found on our Code of Conduct page.

Read the full description
Security Backend Engineer, Security at Eneba

Security Engineer performs hands-on coding, incident response, threat-hunting, and policy development to secure backend systems and infrastructure.

Mid Posted 5 days ago RemoteFirstJobs Product
What this role involves

About Eneba

At Eneba, we’re building an open, safe and sustainable marketplace for the gamers of today and tomorrow. Our marketplace supports close to 20m+ active users (and growing fast!), provides a level of trust, safety and market accessibility unparalleled to none. We’re proud of what we’ve accomplished in such a short time and look forward to sharing this journey with you. Join us as we continue to scale, diversify our portfolio, and grow with the evolving community of gamers.

About your team

You will join a growing security team where you can take meaningful ownership of the practices and policies you help develop. You will work closely with backend engineering and other departments to integrate practical security requirements across the company.

About the role

As a Security Engineer, you’ll cover a broad range of operational and strategic security work rather than a single narrow specialty. In your first few months, you’ll focus on learning Eneba’s tech stack and understanding how our services and systems fit together. That foundation is essential before you can secure those systems effectively.

Day-to-day, you can expect to:

  • Hands-on coding and security implementation work make up the largest part of the role today, alongside incident response and threat-hunting responsibilities.

  • Review and triage security submissions and incident reports.

  • Evaluate and respond to bug bounty reports, including remediation follow-through

  • Build, operate, and improve incident response and remediation processes.

  • Write and maintain security policies and documentation.

  • Communicate security requirements and risks clearly to non-technical departments

  • Review application monitoring and logs to catch and investigate anomalies

  • Support access governance and permission-management processes.

About the tech

The tech stack is the same one our backend teams work with. You’re not expected to know all of it on day one, but you should expect to be learning how to use most of it within your first 3 months, and you’ll also be working across other languages and systems used throughout the company as your role demands.

Code

  • PHP/Symfony

  • Golang

  • GraphQL

  • gRPC

  • CQRS, commands via saga/temporal, queries via GraphQL

  • Microservices architecture

  • Service orchestration withSaga /temporal.io

Databases

  • InfluxDB

  • Redis

  • ElasticSearch

  • MariaDB

  • MySQL

Infrastructure

  • Kubernetes

  • Helm

  • AWS

  • Terraform

  • Prometheus

What we’re looking for

  • Strong written and verbal communication skills - this is our highest priority, since you’ll regularly need to explain technical risk to non-technical audiences

  • Solid PHP knowledge

  • Security knowledge, or a clearly demonstrated interest in security (bug bounties, CTFs, security blogs, following the security community)

  • A background in IT, backend engineering, or a related technical field

  • Self-sufficiency - comfort taking ownership of tasks and making progress without constant guidance.

  • Ownership mentality and strong problem-solving skills

  • Openness to learning and working across multiple systems, languages, and technologies rather than staying in one lane

Nice to have

  • Experience with monitoring tools and application monitoring

  • Familiarity with the OWASP Top 10

€58,000 - €69,000 a year

What it’s like to work at Eneba

*Opportunity to join our Employee Stock Options program.

*Opportunity to help scale a unique product.

*Various bonus systems: performance-based, referral, additional paid leave, personal learning budget.

*Paid volunteering opportunities.

*Work location of your choice: office, remote, opportunity to work and travel.

*Personal and professional growth at an exponential rate supported by well-defined feedback and promotion processes.

*Please attach CV’s in English.

*To find out about how we handle your personal data, make sure to check out our Candidate Privacy Notice https://www.eneba.com/candidate-privacy-notice

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Application Security Engineer (West Coast)

Develops and implements security measures to protect applications from vulnerabilities and threats throughout the software development lifecycle.

Mid Posted 6 days ago Himalayas
What this role involves
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity.
Read the full description
Security Identity & PAM Security Engineer

Manages identity and privileged access management systems, monitors security risks, and ensures infrastructure stability and scalability.

Mid Posted 6 days ago Jobicy AI
What this role involves
About the roleThis team is responsible for the security, stability, and scalability of the company’s software systems and infrastructure. We monitor system performance, identify and mitigate risks, and ensure our...
Read the full description
Security Manager, Cyber Compliance, Deloitte Global Technology

Manages cyber compliance programs and governance frameworks to ensure organizational adherence to security standards and regulatory requirements.

Mid Remote Posted 7 days ago Jobicy AI
What this role involves
Job Type: Permanent Work Model: Remote Reference code: 134501 Primary Location: Toronto, ON All Available Locations: Toronto, ON   Our Purpose   At Deloitte, our Purpose is to make an impact that matters. We exist to inspire...
Read the full description
Security Security Controls Assessor (Part time & Remote) at TestPros, Inc.

Conducts security assessments and compliance evaluations using NIST frameworks, develops security documentation (SSPs, SARs, POA&Ms), and verifies implementation of security controls for federal and commercial clients.

Mid Remote Posted 7 days ago RemoteFirstJobs Product
What this role involves

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world.  We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.

TestPros is looking for Security Controls Assessors with experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks.

Start: Future projects late 2026 or 2027 (not an immediate job opening)

Type: Part-time consulting

Overview

Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.

Responsibilities and Duties:

You should be able to deliver on the following expertly and consistently:

  • Develop NIST 800-53 Rev5 based System Security Plan (SSP).
  • Create/Update the applicable documents identified by NIST 800-53 Rev 5, specifically the Security Assessment Report (SAR).
  • Create/Update the associated Plan of Actions and Milestones (POA&M).
  • Provide detailed security-related reports including data, analyses, and conclusions upon completion of tests, scans, and assessments, including mitigations and, if indicated, appropriate escalation of identified risks and vulnerabilities.
  • Verify and document the implementation of security controls necessary to achieve compliance.
  • Keep management apprised of impending areas of concern, verbally and in writing.
  • Review and develop System Security Plans (SSPs), Plans of Actions and Milestones (POA&Ms), and as well as other necessary artifacts.
  • Facilitate the Plan of Actions and Milestones (POA&M) program to ensure customer systems have accurately and fully provided information for POA&M activities to include valid remediation of findings.
  • Develop various policy documents (SOPs/CONOPs) as required. This may include policies regarding Configuration Management, IS Sanitization, Media Security, Password Policy, Business Continuity, Continuity of Operations, Incident Response, Disaster Recover, and Security Assessments.
  • Develop new, and mature existing information security and risk policies.
  • Initiate, and lead on-going information security maturity assessment processes and training, using industry accepted frameworks and implement into the overall cyber security posture.
  • Produce and review key performance indicators for implemented security measures and distribute KPIs.
  • Maintain knowledge of threat landscape by monitoring threat intelligence, and other related sources.

Qualifications and Skills:

  • 5+ years of directly related experience in IT security compliance, including recent experience with NIST 800-53 Rev 5 “Security and Privacy Controls for Federal Information Systems and Organizations”
  • Cloud computing security
  • Security governance and policy
  • Security risk analysis
  • Auditing and monitoring systems
  • Scanning and vulnerability management systems
  • Advanced Malware Protection
  • Threat Intelligence
  • Incident Management - analysis, detection, and handling of security events
  • Penetration testing and associated tools (e.g., nmap, Metasploit, etc.)
  • Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience (preferred)
  • Military and/or practical job experience may be considered in-lieu of formal education, with significant industry certifications

Rate: $50-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.

Equal Opportunity Employer

TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.

Offer Considerations

TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.

Federal Compliance

As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Read the full description
Security Cyber Ark Integration Engineer

Design and implement CyberArk integrations with enterprise applications, identity platforms, and cloud services to strengthen security infrastructure.

Mid Posted 10 days ago Himalayas
What this role involves
CyberArk Integration EngineerExperience: 6–10 Years Job SummaryDesign and implement integrations between CyberArk and enterprise applications, identity platforms, cloud services, and DevSecOps tools.
Read the full description
Security Quality & Compliance Analyst at Domino Data Lab

Manages compliance frameworks (SOC 2, ISO 27001, etc.) and responds to security questionnaires from enterprise customers and regulated organizations.

Mid Posted 13 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility — all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.ai

What we are building

The Quality & Compliance team at Domino is…

  • Building the assurance layer that lets the world’s most regulated organizations put Domino at the center of their AI work. Our customers include global pharmaceutical companies, major financial institutions, and government agencies, organizations that cannot adopt a platform they can’t evidence and defend to their own auditors.
  • Running a genuinely multi-framework program under one roof: SOC 2, ISO 9001, ISO 27001, and CMMC. That combination means the work spans information security, quality management, and federal compliance.
  • Small, senior, and deliberately non-bureaucratic. We would rather have a small set of controls people actually follow than a large set nobody reads. Every SOP and policy we publish has to be clear enough to be used, not just clear enough to pass.
  • A team that sits directly in the revenue path. When an enterprise prospect sends a 400-question security questionnaire or a regulated customer asks how we manage change control, we are the answer, and how fast and how credibly we answer changes deal outcomes.
  • At an inflection point. We’re moving from standing programs up to running them well and at scale, which means investing in tooling, reusable answer libraries, and a reliable operating rhythm instead of heroics.

What your impact will be

In your first year, you will:

  • First 90 days: You’ll take over inbound security and quality questionnaires, learn our answer library and response tooling, and start returning routine questionnaires independently. You’ll pick up the master audit and compliance activities schedule and begin giving the team real lead time on what’s coming.
  • By six months: You’ll own day-to-day QMS operations, new-hire team and training assignments, training content, and records for change orders, suppliers, and computer systems, with data accurate enough that we can report on it any day of the week, not just before an audit. GRC program status will be visible in Jira and Confluence without anyone assembling it by hand.
  • By twelve months: You’ll be a trusted reviewer of our control statements across SOC 2, ISO 9001, ISO 27001, and CMMC, catching drift between what a control claims and what our evidence actually shows before an auditor does. Our SOPs and policies will be current and readable because you’ve worked through them. Questionnaire turnaround will be measurably faster, with a larger share answered from the library instead of from scratch.

What we look for in this role

  • 2–5 years in GRC, compliance operations, quality assurance, or audit support, in a role where you did the hands-on work yourself.
  • Direct experience responding to security or quality questionnaires at volume, and comfort owning the shared tooling and answer library behind those responses.
  • Hands-on involvement in at least one audit or certification cycle end to end, SOC 2, ISO 9001, ISO 27001, CMMC, or a comparable framework, including evidence collection and findings follow-up.
  • Experience as the day-to-day administrator or power user of a compliance system of record (eQMS, GRC platform, or equivalent), with real accountability for data accuracy.
  • Strong technical writing and editing. You can turn a vague requirement into a clear, correct SOP, and a hard customer question into a precise answer.
  • Fluency in Jira and Confluence, and the discipline to keep them current without being reminded.
  • Real fluency with agentic AI tooling and frameworks, you’ve built custom skills, agents, or prompt-driven workflows to take repetitive work off your own plate, and you know where model output has to be human-verified.
  • Meticulous attention to detail and calendar discipline. Other people’s deadlines depend on your tracking, and you treat that as a commitment.
  • Sound judgment about the limits of your own knowledge, you know when to answer, when to pull in an SME, and when to escalate. You never invent an answer to a customer-facing security question.
  • A collaborative, low-ego approach to working across Security, Engineering, Legal, People, and Sales.
  • Nice to have: experience in a regulated life-sciences, medical device, or pharmaceutical environment, GxP, 21 CFR Part 11, computer system validation, or supplier qualification.

What we value

  • We value a growth mindset. High-performing creative individuals who dig into problems and see the opportunities for success
  • We believe in individuals who seek truth and speak the truth and can be their whole selves at work
  • We value all of you that believe improving is always possible At Domino Everything is a work in progress – we can do better at everything
  • We emphasize an environment of teaching and learning to equip employees with the tools needed to be successful in their function and the company
  • We strongly believe in the value of growing a diverse team and encourage people of all backgrounds, genders, ethnicities, abilities, and sexual orientations to apply

#LI-Remote

Read the full description
Security Product Security Engineer at Cloudflare

Conducts security assessments, triages vulnerabilities, and builds AI-powered automation tools to streamline security operations for Cloudflare's products.

Mid Onsite Posted 14 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations: Austin, TX

Role Summary

As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.

On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.

Responsibilities

  • Implement AI Security Solutions: Identify process bottlenecks and build AI-driven tools or scripts to help automate code analysis, optimize triage, and streamline Product Security workflows.
  • Security Reviews & Threat Modeling: Conduct structured security reviews and threat modeling sessions (e.g., STRIDE) across product features, defining security requirements early in the development lifecycle.
  • Product Vulnerability Management: Manage the operational lifecycle of product security findings. Ensure vulnerabilities are verified, mapped to the correct engineering owner, and tracked to mitigation in alignment with established SLAs.
  • Bug Bounty Triage: Perform the technical triage and validation of Cloudflare’s external Bug Bounty submissions, verifying exploitability and evaluating business risk.
  • Pentest Coordination: Support internal and external penetration testing engagements by reviewing findings, clarifying technical context, and assisting development teams with remediation strategies.
  • Engineering Collaboration: Partner closely with DevOps and product teams, acting as a reliable security point of contact and helping developers implement secure coding practices.

Desirable Skills, Knowledge, and Experience

  • Product/AppSec Expertise: 5+ years of experience in Product or Application Security within large-scale distributed cloud environments or SaaS platforms.
  • Practical AI & Automation Engineering: Demonstrated ability to build production-grade automation scripts and tools. Must possess hands-on engineering experience leveraging AI/LLMs to solve operational or technical challenges.
  • Threat Modeling & Risk Analysis: Competency in threat modeling methodologies and the ability to evaluate code flaws to determine their actual engineering and security impact.
  • Vulnerability Lifecycle Operations: Experience tracking, routing, and driving the remediation of software vulnerabilities across engineering groups while working against defined SLAs.
  • Strong Collaboration & Communication: Ability to collaborate effectively across teams, clearly communicating technical security risks to software engineers and resolving ownership ambiguity constructively.

Bonus points

  • Offensive Security Tooling: Familiarity with modern exploitation techniques, fuzzing frameworks, or automated scanning utilities.
  • Program Management Experience: Experience scaling crowdsourced security programs (e.g., HackerOne, Bugcrowd) or optimizing agile project management workflows within JIRA.
  • Experience in integrating hardware security features into production code bases

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family.  Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun!  The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security Security Engineer at Oddball

Embeds security into federal software delivery by conducting risk assessments, supporting ATO compliance efforts, and maintaining FISMA/FedRAMP security postures for VA systems.

Mid Remote Posted 15 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Security Engineer at Oddball

Embed security into federal software delivery by integrating security requirements into development workflows, supporting ATO processes, and conducting risk assessments aligned with NIST and VA standards.

Mid Remote Posted 15 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Solvd: Security Engineer II – IAM & SaaS Governance

Security engineer designs and manages IAM infrastructure, Okta environments, and SaaS data governance while enforcing least privilege access controls.

Mid Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Argentina
URL: http://solvd.com

Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes.

Following the acquisition of Tooploox, a premier AI and product development company, Solvd now offers true end-to-end delivery—from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively.

We are looking for a Mid-Tier Security Engineer specializing in Identity and Access Management (IAM) and Data Governance to join our Cyber Security team. In this role, you won't just be managing user tickets; you will be the engineer designing, implementing, and securing our identity perimeter and SaaS ecosystem.

You will own our Okta environment and drive data governance strategies across our core SaaS applications (e.g., Google Workspace, Microsoft 365, Slack, Salesforce, GitHub). Your goal is to ensure seamless user lifecycle management while aggressively enforcing the principle of least privilege and monitoring data exposure.

What you'll do

Identity & Access Management (IAM) Engineering

  • Okta Architecture & Admin: Act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies.

  • Lifecycle Automation: Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts to eliminate manual provisioning errors.

  • Federation & Protocols: Standardize and implement SSO integrations utilizing SAML 2.0, OIDC, and OAuth 2.0, ensuring secure token exchange and scoping.

Data Governance & SaaS Security

  • Least Privilege Enforcement: Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across all enterprise SaaS platforms.

  • Data Exposure Mitigation: Monitor and remediate unauthorized data sharing, public file exposure, and "shadow IT" API integrations within our SaaS ecosystem.

  • Access Reviews & Compliance: Lead quarterly user access reviews (UARs) and provide evidentiary support for security frameworks such as SOC 2 Type II, ISO 27001, and GDPR.

  • SaaS Security Posture Management (SSPM): Leverage SSPM tools or native security centers to continuously audit and harden SaaS application configurations.

Monitoring & Incident Response

  • Threat Detection: Analyze Okta System Logs and SaaS audit logs to detect anomalous behavior (e.g., impossible travel, credential stuffing, unauthorized data exfiltration).

  • SIEM Integration: Collaborate with the SOC team to ensure critical IAM and SaaS logs are correctly ingested into our SIEM for real-time alerting.

What you bring

  • Experience: 3–5 years of dedicated experience in a Security Engineering, IAM, or Systems Engineering role with a heavy security focus.

  • Okta Mastery: Strong engineering-level knowledge of Okta (Okta Certified Administrator or Certified Consultant preferred).

  • Security Mindset: Proven track record of implementing data governance principles, data loss prevention (DLP), and zero-trust access models.

  • Core Protocols: Deep understanding of networking and identity protocols: TCP/IP, HTTP, SAML, OAuth, OIDC, and SCIM.

  • Scripting: Proficiency in Python, PowerShell, or Bash to interact with REST APIs for custom security tooling and automation.

  • Log Analysis: Experience querying logs (Splunk, ELK, SQL, or cloud-native SIEMs) to investigate identity-related security incidents.

When you join Solvd, you'll…

  • Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.

  • Be part of a global team with equal opportunities for collaboration across continents and cultures.

  • Thrive in an inclusive environment that prioritizes continuous learning, innovation, and ethical AI standards.

Ready to make an impact?

If you're excited to build things that matter, champion responsible AI, and grow with some of the industry’s sharpest minds. Apply today and let’s innovate together.

Solvd is an equal opportunity employer.

To apply: https://weworkremotely.com/remote-jobs/solvd-security-engineer-ii-iam-saas-governance

Read the full description