Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Hightouch: Application Security Lead

Leads application security strategy end-to-end, securing multi-tenant systems, APIs, and infrastructure while working hands-on in the codebase to solve complex security challenges at scale.

Lead Remote Posted 1 day ago We Work Remotely — Programming
What this role involves

Headquarters: Remote (North America)

About Hightouch

Hightouch is an Agentic Marketing Platform powered by the industry-leading Composable CDP. With complete brand context, customer data, and performance history in one place, every marketer finally has the power to build and ship end-to-end campaigns themselves. Teams move faster, stay on brand, and get AI marketing that actually works.

Founded in 2019 and headquartered in San Francisco, Hightouch enables marketing teams to analyze performance, brainstorm ideas, and generate creative at a speed and quality that wasn't previously possible.

Named a Leader in the 2026 Gartner® Magic Quadrant™ for Customer Data Platforms, Hightouch is trusted by leading enterprises like Domino's, Spotify, Aritzia, Cars.com, Ramp, and PetSmart.

At Hightouch, our mission is to help our customers leverage data and AI to grow their businesses. The team is ambitious, impact-driven, efficient — and we believe humility, kindness, and compassion are essential to our success. If you're energized by velocity, obsessed with raising the bar, and want to build alongside people who care deeply about each other and our customers, we'd love to meet you.

About the Role

This is our first dedicated security hire, and it's a rare chance to define the function from the ground up. You'll own Hightouch's application security posture end-to-end. We have strong engineering fundamentals and a solid foundation; now you'll shape what security looks like here as we scale from 70 to 140+ engineers.

This is a hands-on, high-autonomy role. You'll spend most of your time in the codebase, not in meetings. You’ll be solving hard problems at the intersection of security and distributed systems:

  • Multi-tenant isolation on a system running ~1M data syncs per day and ingesting 100K+ events/sec
  • Sub-tenant access control - for multi-team and multi-brand use cases, requiring differentiated access to configuration and data
  • Security architecture - Build and refine our frameworks for compute isolation and perform threat modeling and hardening of new products
  • Internet-facing APIs - Our high-throughput, internet-facing architecture services customer data at scale. You’ll improve our rate limiting, abuse detection, and granularity of access control
  • Multi-Region and Multi-Cloud - Supporting our multi-region and multi-cloud backend, including extending it to launch Hightouch on in new regions to support data residency requirements of our global customer base

You'll own your roadmap. We're not looking for someone to run a checklist — we're looking for someone who can look at our architecture, identify the highest-leverage problems, and go fix them.

We are looking for talented, intellectually curious, and motivated individuals who are interested in tackling the problems above. This is a senior role, but we focus on impact and potential for growth more than years of experience. The salary range for this position is $180,000 - $400,000 USD per year, which is location independent in accordance with our remote-first policy. We also offer meaningful equity compensation in the form of ISO options, and offer early exercise and a 10 year post-termination exercise window.

About You

You’ve been an early security hire at a SaaS company before and moved the needle on how they approach security. You can read application code, threat model a distributed system, and ship production fixes. You have significant distributed systems expertise so that you can understand and influence what is being built by the product teams and influence from a place of trust.

Experience that's relevant:

  • Being an early security hire (first 1-3) at a SaaS or data infrastructure company
  • Securing multi-tenant platforms: tenant isolation, authorization models, etc
  • Cloud security on systems that span more than one cloud and operate against customer-owned accounts
  • Design and build of data infrastructure as an early engineer, not just a user. You helped secure it from early design or during major redesigns. You understand how it scales and how it’s secured
  • Privacy-adjacent security (PII handling, data residency, GDPR/CCPA technical controls)

We don't care about certifications. We care about what you've built.

Interview Process

  1. Recruiter Screen [30m] - Introductory mutual fit assessment

  2. Security Architecture Interview [60m] - Threat model discussion of a real-ish system, followed by a systems design exercise

  3. Core interview [90m] - deep dive on distributed systems knowledge

  4. Hiring Manager Interview [60m] - What you've built in the past, how you work

  5. Security Program Interview [60m] with Head of Engineering — How you've run security programs in practice: bug bounty, pentest engagements, working with external researchers, and partnering across engineering to drive adoption.

E-Verify Statement

Hightouch participates in E-Verify. After you join the team, we'll verify your eligibility to work in the U.S. by submitting information from your Form I-9 to the Social Security Administration and, if needed, the Department of Homeland Security. This process happens post-hire only — we never use E-Verify to pre-screen applicants.


E-Verify Notice
E-Verify Notice (Spanish)
Right to Work Notice
Right to Work Notice (Spanish)

To apply: https://weworkremotely.com/remote-jobs/hightouch-application-security-lead

Read the full description
Security Microsoft Sentinel Security Consultant at Quisitive

Analyzes Microsoft Sentinel security data to provide advisory guidance, interprets incidents and trends, and coaches customers on improving their security posture.

Mid Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

Spyglass is Quisitive’s Security-as-a-Service offering — a modern, insight-driven approach to managed security that goes beyond alerts and tickets. In this role, you’ll help customers turn Microsoft Sentinel insights into better decisions and measurable risk reduction.

This is a remote position and can be based anywhere in the continental US.

About the Role

The Microsoft Sentinel Security Consultant is a customer-facing, advisory role focused on translating Microsoft Sentinel telemetry into clear, actionable security guidance. This is not a traditional SOC role. Instead, it’s designed for professionals who enjoy analyzing patterns, explaining security findings, and coaching customers on how to improve their security posture over time.

You’ll work closely with Spyglass Security Coaches, SecOps teams, and Customer Success Managers to help customers understand what Sentinel is telling them, why it matters, and what to do next.

What You’ll Do

Microsoft Sentinel Advisory (Primary Focus)

  • Review and interpret Microsoft Sentinel incidents, analytics rules, detections, and trends for assigned customers
  • Analyze recurring security signals to identify attack patterns, control gaps, and risk trends over time
  • Develop, read, and explain KQL queries, workbooks, and Sentinel dashboards
  • Partner with MDR and SecOps teams to validate detections, distinguish real risk from noise, and convert findings into advisory recommendations
  • Guide customers on how to act on Sentinel insights, not just respond to alerts

Security Coaching & Advisory

  • Support and contribute to monthly Spyglass security coaching sessions
  • Translate technical Sentinel outputs into clear, business-relevant narratives
  • Participate in executive and technical security advisory discussions
  • Contribute to customer security roadmaps informed by Sentinel-driven insights

Platform & Control Alignment

  • Assess customer security posture across Microsoft Sentinel, Microsoft Defender XDR, and Entra ID
  • Map Sentinel findings to security frameworks such as NIST CSF and CIS Controls
  • Identify gaps in telemetry, detection coverage, and control effectiveness

Delivery & Collaboration

  • Support Spyglass flex work by helping scope, estimate, and validate customer security engagements
  • Develop customer-facing materials such as security narratives, coaching decks, and Sentinel-backed summaries
  • Collaborate closely with Security Coaches, Customer Success Managers, and SecOps teams

What We’re Looking For

Required Qualifications

  • Hands-on experience with Microsoft Sentinel, including incident review, analytics rules, workbooks, and KQL
  • Working knowledge of Microsoft Defender for Endpoint, Identity, Office 365, Cloud Apps, and Entra ID
  • Ability to communicate security insights clearly to non-SOC and business audiences
  • Experience in a consultative or advisory security role
  • Strong ownership mindset and customer-focused communication skills
  • Ability to work with and balance workload with multiple customers

Preferred Qualifications

  • Experience delivering recurring security coaching or advisory services
  • Familiarity with NIST CSF and CIS Controls
  • Experience supporting regulated industries such as healthcare or financial services
  • Microsoft security certifications (SC-200, SC-300, SC-400, AZ-500)

​

US Citizens, Green Card holders and those authorized to work in the US are encouraged to apply.  We are unable to offer sponsorship at this time.

About Quisitive ​

With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description
Security Security Consultant (Microsoft Azure & M365) at Quisitive

Azure Security Consultant designs, implements, and optimizes Microsoft security solutions including identity, endpoint protection, and compliance across cloud environments for enterprise clients.

Mid Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

We’re looking for an Azure Security Consultant who enjoys solving complex challenges, working directly with clients, and staying current with Microsoft’s rapidly evolving security ecosystem. This role is ideal for someone who combines technical expertise with a consultative mindset and wants to make a meaningful impact on customer environments.

This is a remote position and can be based anywhere in the United States.  Prefer Central or Eastern time zones.

What You’ll Do

As an Azure Security Consultant, you’ll work with clients and fellow Quisitive consultants to design, implement, and optimize Microsoft security solutions across cloud, identity, endpoint, and data protection platforms.

  • Partner with clients to understand security challenges, business objectives, and compliance requirements
  • Configure and support Microsoft Entra ID, identity governance, and privileged access solutions
  • Design and implement Conditional Access and Privileged Identity Management (PIM) strategies
  • Deploy and optimize Microsoft Defender security solutions across identity, endpoint, email, and Microsoft 365 environments
  • Assist organizations with security posture improvements using Microsoft security best practices
  • Support endpoint protection, compliance, and device management initiatives through Microsoft Intune and Endpoint Manager
  • Configure and support Microsoft Purview solutions for information protection, governance, and compliance
  • Leverage Azure Log Analytics and security insights to monitor, investigate, and improve customer environments
  • Develop and maintain PowerShell automation to improve efficiency and consistency
  • Collaborate with architects, consultants, and customer stakeholders throughout project delivery

What We’re Looking For

We’re seeking someone who is passionate about technology, enjoys working with customers, and thrives in a collaborative consulting environment.

  • 2-5 years of experience in Azure security engineering, including configuring security controls, monitoring environments, and responding to incidents
  • Experience implementing and managing Microsoft security controls, monitoring solutions, and security best practices
  • Hands-on experience with Microsoft Entra ID, identity governance, Conditional Access, MFA, and self-service password reset (SSPR)
  • Experience with Microsoft Purview and information governance initiatives
  • Knowledge of Microsoft Defender solutions, including Defender for Microsoft 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud and Cloud Security Posture Management (CSPM)
  • Strong communication and consulting skills with the ability to engage directly with customers
  • Ability to understand business requirements and translate them into practical technical solutions
  • Strong organizational and time management skills
  • Experience working in customer-facing consulting engagements
  • Ability to travel occasionally as required

Preferred Qualifications

  • Experience working for a Microsoft-focused consulting or systems integration organization
  • Knowledge of Exchange Online, Active Directory, and hybrid identity environments
  • Experience with Microsoft Sentinel
  • PowerShell, Azure Automation, and Kusto Query Language (KQL)
  • Data Loss Prevention (DLP) and Microsoft Information Protection (MIP) solutions
  • Network security experience
  • Microsoft security certifications such as SC-100, SC-200, SC-300, SC-400, or AZ-500

​US Citizens and those authorized to work in the US are encouraged to apply.  We are unable to offer sponsorship at this time.

About Quisitive ​

​With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description
Security Security Engineer (REMOTE) at EnableComp

Security Engineer embeds security controls across applications, data pipelines, and AI systems while translating security policies into practical, deployable technical solutions.

Mid Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise and its unified E360 RCM™ intelligent automation platform to improve financial sustainability for hospitals, health systems, and ambulatory surgery centers (ASCs) nationwide. Powered by proprietary algorithms, iterative intelligence from 10M+ processed claims, and expert human-in-the-loop integration, EnableComp provides solutions across the revenue lifecycle for Veterans Administration, Workers’ Compensation, Motor Vehicle Accidents, and Out-of-State Medicaid claims as well as denials for all payer classes. By partnering with clients to supercharge the reimbursement process, EnableComp removes the burden of payment from patients and provider organizations while enabling accelerated cash, higher and more accurate yield, clean AR management, reduced denials, and data-rich performance management. EnableComp is a multi-year recipient the Top Workplaces award and was recognized as Black Book’s #1 Specialty Revenue Cycle Management Solution provider in 2024 and is among the top one percent of companies to make the Inc. 5000 list of the fastest-growing private companies in the United States for the last eleven years.

POSITION SUMMARY

The Security Engineer serves as the technical bridge between the security policy team and development operations, ensuring that security principles are not only defined but effectively implemented. Embedded within development teams, this role writes code, configures systems, and operationalizes security controls across applications, databases, and AI systems. As a key contributor to the organization’s Agentic AI platform transformation, the Security Engineer will design and embed secure-by-design practices, enabling innovation while maintaining the highest standards of data protection and compliance.

THE JOB RESPONSIBILITIES INCLUDE

  • Bridge security policy and technical execution by translating organizational security requirements into practical, deployable solutions across applications, data environments, and AI systems.
  • Design, build, and deploy security controls across web applications, data pipelines, APIs, and Agentic AI systems to ensure confidentiality, integrity, and availability.
  • Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations, configuration hardening, and secure infrastructure deployment.
  • Develop automation scripts and infrastructure-as-code to integrate security into CI/CD pipelines, enabling continuous compliance, secrets management, vulnerability scanning, and environment hardening.
  • Implement and operationalize AI-specific security frameworks by building guardrails for agentic models, securing data flows, and integrating AI security tooling into development workflows.
  • Perform hands-on technical security assessments, including penetration testing, threat modeling, and code reviews, and directly remediate identified vulnerabilities.
  • Collaborate with cloud and DevOps teams to deploy monitoring and detection controls and ensure secure configuration baselines across environments.
  • Provide practical security guidance and training to developers and engineers during architecture reviews, sprint planning, and project delivery.
  • Continuously evaluate and improve the organization’s security posture through testing, feedback loops, and adoption of emerging best practices for AI and distributed systems.
  • Document security architectures, configurations, and implementation patterns to support ongoing operations, compliance, and knowledge sharing.
  • Other duties as required

REQUIREMENTS AND QUALIFICATIONS

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field required

  • 3+ years in hands-on application security, DevSecOps, or security engineering roles.

  • Proven experience building and configuring secure CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, Azure DevOps).

  • Equivalent combination of education and experience will be considered.

  • Deep proficiency with cloud security in AWS, Azure, or GCP environments.

  • Strong implementation experience with infrastructure as code (Terraform, CloudFormation) and container security (Docker, Kubernetes).

  • Strong scripting and automation skills (Python, Bash, PowerShell) for security tooling.

  • Versatility across web/API security, data pipeline security, microservices, and database security.

  • Understanding of security frameworks (NIST, ISO 27001, SOC 2) and compliance requirements (GDPR, HIPAA, PCI-DSS).

  • Hands-on experience deploying and configuring security scanning tools (SAST, DAST, SCA).

  • Excellent communication skills—ability to translate security requirements into working technical implementations.

  • Experience working embedded within cross-functional development teams.

  • Proven track record of hands-on problem-solving in fast-paced development environments

  • Regular and predictable attendance

  • Equivalent combination of education and experience will be considered

  • Must have strong computer proficiency and understand how to use basic office applications, including MS Office (Word, Excel, and Outlook)

  • To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodation may be made to enable qualified individuals with disabilities to perform the essential functions.

SPECIAL CONSIDERATIONS & PREREQUISITES

  • Practices and adheres to EnableComp’s Core Values, Vision and Mission

  • Hands-on experience with AI/ML security, model security, and data governance

  • Technical knowledge of LLM security, prompt injection prevention, and AI agent safety

  • Security certifications (CISSP, CEH, OSCP, CSSLP, or cloud security certifications)

  • Strong coding background in Python, Go, or similar languages.

  • Background in software development or engineering transitioning to security.

  • Direct experience implementing secrets management solutions (HashiCorp Vault, AWS Secrets Manager).

  • Practical experience with zero trust architecture implementation.

  • Familiarity with data security, ETL processes, and data warehouse security.

  • Experience with microservices architectures and distributed systems security

EnableComp is an Equal Opportunity Employer M/F/D/V. All applicants will be considered for this position based upon experience and knowledge, without regard to race, color, religion, national origin, sexual orientation, ancestry, marital, disabled or veteran status. We are committed to creating and maintaining a workforce environment that is free from any form of discrimination or harassment.

EnableComp recruits, develops and retains the industry’s top talent.  As the employer of choice in the complex claims industry, EnableComp takes pride in our continuous commitment to building and maintaining a culture centered around fostering the professional growth and development of our people.  We believe that investing in our employees is the key to our success, and we are dedicated to providing them with the tools, resources, and support they need to thrive and grow their career here. At EnableComp, we are committed to living up to our core values each and every day, and we believe that this commitment is what sets us apart from other companies.  If you are looking for a company that values its employees and is dedicated to helping them achieve their full potential, then EnableComp is the place for you.

Don’t just take our word for it!  Hear what our people are saying:

“I love my job because everyone shares the same vision and is determined and dedicated. People care about you as a person and your professional growth. There is a genuine spirit of cooperation and shared goals all revolving around helping each other.” – Revenue Specialist

“I enjoy working for EnableComp because of the Core Values we believe in. EnableComp stands true to these values from empowering employees to ecstatic clients. This company is family oriented and flexible, along with understanding the balance of work, life, and fun.” – Supervisor, Operations

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Cybersecurity Engineer / RMF Specialist at Dark Wolf Solutions

Leads security authorization processes, conducts risk assessments, and ensures NIST/DoD compliance for systems and applications.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Dark Wolf Solutions is seeking a Senior Cybersecurity Engineer / Risk Management Framework (RMF) Specialist to will lead and execute the security authorization process for our systems and applications in compliance with NIST guidelines and DoD regulations. This individual will be responsible for navigating the RMF lifecycle, developing security documentation, conducting risk assessments, and ensuring that our systems meet the highest standards of security and compliance. This position offers a critical opportunity for a motivated and detail-oriented security professional to leverage their RMF expertise, contribute to the protection of sensitive information, and play a vital role in securing our nation’s critical infrastructure.

Key Responsibilities:

  • Responsible for concentrating on overall technical and operational effectiveness of capabilities in coordination with the COTR and Sponsor Staff management.
  • Cyber Security teams are responsible for providing recommendations on continuous improvement of the processes and architectures supporting the overall Cyber Defense operational activities including, but not limited to: analysis, incident handling and reporting products, and the reporting lifecycle.
  • Ensures the effective operations of Agency IT systems and network defenses, providing effective incident response capabilities, usable and effective reports that address overall situational awareness.
  • This individual works to maximize the use of existing tools to correlate information and synthesize data into usable and actionable events.
  • Identifies and provides an agile approach to the automation of any manual and inefficient processes that exist across the cyber defense program and to work with the Sponsor to recommend and implement technical solutions designed to return time to mission.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical field
  • 8 years minimum of relevant experience
  • Experience in security risk assessment and management in cloud environments (GCP preferred)
  • Experience building authorization packages
  • US Citizenship required with an active Secret clearance or interim Secret clearance

This role is primarily remote. The compensation for this role is estimated to be between $150,000-$170,000, commensurate on experience.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

Read the full description
Security Cloud / Network / Cybersecurity Engineer

Designs, deploys, and secures cloud infrastructure while managing network systems and implementing cybersecurity protocols.

Remote Posted 4 days ago Himalayas
What this role involves
Cloud / Network / Cybersecurity Engineer – Infrastructure & Security | RemotePosition Type: Full-Time, Remote Working Hours: U.
Read the full description
Security AI Security Analyst at LawPay

Monitors and secures AI deployments, assesses AI-specific risks like prompt injection and model misuse, and governs agentic systems across internal and customer-facing platforms.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Sr. Information Security Manager at LawPay

Leads a technical security team, manages security operations platforms, drives incident response and compliance programs, and operationalizes security capabilities aligned with business priorities.

Senior Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

As we evolve our security posture to meet growth and regulatory expectations, we are seeking a transformational Senior Information Security Manager to lead our technical security team and operationalize security capabilities that are measurable, effective, and aligned with business priorities. This is a hands-on leadership role: you will lead the day-to-day execution of the security program and directly manage the security engineering and analyst team, while partnering closely with the U.S.-based VP of Information Security and the compliance and privacy operations team.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • Team leadership: Lead and develop the security engineering/analyst team — delivery, prioritization, coaching, performance
  • Security operations: Own security platforms (EDR, SIEM, compliance automation, vulnerability management, CSPM) and detection/response workflows
  • Metrics & reporting: Own security metrics pipeline (remediation velocity, control assurance, coverage) for quarterly business reviews
  • AI security: Drive AI adoption in tooling for better detection, and define/enforce security standards for AI/agentic systems (LLM integrations, orchestration, governance)
  • Incident & compliance leadership: Lead incident response (EU hours, US coordination), post-incident reviews, and partner on compliance audits (SOC 2, PCI DSS, EU regs)
  • Security design reviews: Lead design reviews across product lines with risk ratings, SLAs, and documented standards
  • Threat intel & detection engineering: Monitor relevant threat intel and convert into actionable detections
  • Fraud/attack investigation: Partner cross-functionally to investigate attacks (card testing, fraud, abuse), turning findings into detections and hardening recommendations

About you:

  • 7+ years in information security, including 2+ years leading technical security staff.

  • Hands-on depth in cloud security operations (AWS preferred), SIEM/log analytics, EDR platforms, and vulnerability management programs.

  • Track record of building measurable, metrics-driven security programs in a compliance-heavy environment (PCI DSS, SOC 2, or equivalent).

  • Experience operating in distributed, cross-timezone teams; excellent written communication.

  • Fluent professional English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience securing or governing AI/LLM systems and agentic tooling.
  • Familiarity with EU regulatory landscape (GDPR) and fintech or legal-tech domains.

Additional Information

The monthly gross salary range for this position is CZK 95,000 to CZK 175,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Information Security Engineer at LawPay

Operates cloud security stack, leads incident response and detection engineering, and manages vulnerability remediation across AWS infrastructure.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AWS security operations: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams
  • Detection engineering: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity
  • Incident response & forensics: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews
  • Vulnerability management: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage
  • Security awareness & internal ops: Manage KnowBe4 phishing tests/training with Compliance
  • Platform security: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment
  • Data privacy & compliance support: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)
  • Product security & documentation: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate

About you:

  • 4+ years in security engineering or security operations, with real incident response experience.
  • Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).
  • Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python

preferred).

  • Experience with vulnerability management tooling and remediation SLA programs.

  • Comfortable operating independently in a distributed team; strong written English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • PCI DSS or SOC 2 environment experience; ASV scan operations.
  • Terraform/IaC security review experience.
  • Exposure to securing AI-assisted development or agentic tooling.

Additional Information

The monthly gross salary range for this position is CZK 90,000 to CZK 160,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security AI Security Analyst at LawPay

Monitors AI security risks, assesses generative AI deployments for threats, and ensures governance compliance for agentic systems and third-party AI vendors.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security AI Security Analyst at LawPay

Monitors AI security risks, assesses AI use cases for threats, and supports governance of generative AI and agentic systems while performing traditional security operations.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Sr. Information Security Manager at LawPay

Leads a security engineering team, manages security operations platforms, oversees incident response and compliance programs, and drives AI security adoption and governance.

Lead Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

As we evolve our security posture to meet growth and regulatory expectations, we are seeking a transformational Senior Information Security Manager to lead our technical security team and operationalize security capabilities that are measurable, effective, and aligned with business priorities. This is a hands-on leadership role: you will lead the day-to-day execution of the security program and directly manage the security engineering and analyst team, while partnering closely with the U.S.-based VP of Information Security and the compliance and privacy operations team.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • Team leadership: Lead and develop the security engineering/analyst team — delivery, prioritization, coaching, performance
  • Security operations: Own security platforms (EDR, SIEM, compliance automation, vulnerability management, CSPM) and detection/response workflows
  • Metrics & reporting: Own security metrics pipeline (remediation velocity, control assurance, coverage) for quarterly business reviews
  • AI security: Drive AI adoption in tooling for better detection, and define/enforce security standards for AI/agentic systems (LLM integrations, orchestration, governance)
  • Incident & compliance leadership: Lead incident response (EU hours, US coordination), post-incident reviews, and partner on compliance audits (SOC 2, PCI DSS, EU regs)
  • Security design reviews: Lead design reviews across product lines with risk ratings, SLAs, and documented standards
  • Threat intel & detection engineering: Monitor relevant threat intel and convert into actionable detections
  • Fraud/attack investigation: Partner cross-functionally to investigate attacks (card testing, fraud, abuse), turning findings into detections and hardening recommendations

About you:

  • 7+ years in information security, including 2+ years leading technical security staff.

  • Hands-on depth in cloud security operations (AWS preferred), SIEM/log analytics, EDR platforms, and vulnerability management programs.

  • Track record of building measurable, metrics-driven security programs in a compliance-heavy environment (PCI DSS, SOC 2, or equivalent).

  • Experience operating in distributed, cross-timezone teams; excellent written communication.

  • Fluent professional English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience securing or governing AI/LLM systems and agentic tooling.
  • Familiarity with EU regulatory landscape (GDPR) and fintech or legal-tech domains.

Additional Information

The monthly gross salary range for this position is CZK 95,000 to CZK 175,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Information Security Engineer at LawPay

Operates AWS security stack, performs detection engineering, leads incident response investigations, and manages vulnerability operations for a payments/compliance software platform.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AWS security operations: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams
  • Detection engineering: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity
  • Incident response & forensics: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews
  • Vulnerability management: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage
  • Security awareness & internal ops: Manage KnowBe4 phishing tests/training with Compliance
  • Platform security: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment
  • Data privacy & compliance support: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)
  • Product security & documentation: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate

About you:

  • 4+ years in security engineering or security operations, with real incident response experience.
  • Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).
  • Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python

preferred).

  • Experience with vulnerability management tooling and remediation SLA programs.

  • Comfortable operating independently in a distributed team; strong written English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • PCI DSS or SOC 2 environment experience; ASV scan operations.
  • Terraform/IaC security review experience.
  • Exposure to securing AI-assisted development or agentic tooling.

Additional Information

The monthly gross salary range for this position is CZK 90,000 to CZK 160,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Lead threat assessment and case management for a region, conducting behavioral threat evaluations and coordinating security response across organizational stakeholders.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Australia

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$200,900—$200,900 AUD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases for employees and facilities, conducts behavioral threat analysis, and coordinates security incident response across regional operations.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - EMEA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):£95,490—£106,100 GBP
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-1

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases end-to-end, conducts behavioral threat assessments, coordinates incident response, and partners cross-functionally to mitigate security risks to employees, executives, and facilities.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Singapore

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$212,200—$212,200 SGD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-2

Read the full description
Security Stripe: Risk Strategist - Screening (Financial Crimes)

Develops and manages global financial crimes screening programs, setting standards for AML/sanctions controls and driving risk management strategy across Stripe's payment infrastructure.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: US-Chicago; US-Atlanta; US-Remote; Canada-Toronto; Canada-Remote

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Financial Crimes Risk Strategy team owns our first-line AML and sanctions programs globally. We own the end-to-end lifecycle of financial crime controls. We set the global standards that govern how risk is managed across our programs, design and drive the development of controls, infrastructure, and tooling with Engineering, Product, and Data Science, and maintain their effectiveness as our products and the regulatory landscape evolve. We build fast, with data, and with AI integrated into how financial crime risk is detected, managed, and monitored across everything Stripe builds.

What you'll do

As a Risk Strategist on the Financial Crimes Risk Strategy team, you'll own our global screening programs — spanning sanctions, PEP, and negative news — setting the standards that govern how screening risk is managed, designing and driving the controls that operationalize those standards, and ensuring they remain effective as our products and the regulatory landscape evolve. Being effective in this role means going deep on both the domain and the data — we don't separate the two.

You'll partner closely with Product, Engineering, Data Science, Compliance, Legal, other Risk Strategy functions, and Operations to ensure screening considerations are embedded in every product and market decision. Beyond protecting against risk, you'll drive innovation in how Stripe approaches screening — staying ahead of regulatory change and pushing the boundaries of what effective, scalable financial crime risk management looks like at a global payments company.

Responsibilities

  • Lead our global sanctions and AML screening strategy — setting the standards that drive screening control design and infrastructure development, and translating requirements across OFAC, EU, UN, OFSI, and other applicable regimes, PEP screening, and negative news screening into actionable first-line programs and controls
  • Own the design and ongoing improvement of financial crime controls — including sanctions screening, PEP screening, negative news screening, and digital asset-related safeguards — while continuously improving detection coverage and control performance as our products and the threat landscape evolve
  • Embed screening risk requirements into product and infrastructure roadmaps — ensuring financial crime considerations drive product launches, market expansions, and platform decisions across Product, Engineering, Data Science, Compliance, Legal, and Operations
  • Drive screening infrastructure and tooling forward by owning requirements, leading execution, and maintaining effectiveness metrics for screening systems and controls — building with observability by design and ensuring key performance indicators, key risk indicators, and monitoring thresholds are defined from inception
  • Continuously assess and improve screening controls and systems — identifying gaps, recommending enhancements that strengthen detection effectiveness and anticipate regulatory or ecosystem changes, and leading delivery of those enhancements end-to-end
  • Champion a technology-forward approach to financial crime risk management — leveraging AI tools, self-serve data analytics, and model governance best practices to improve how risk is detected, monitored, and managed at Stripe
  • Stay informed on industry practices and regulatory developments and represent our sanctions and AML programs to regulators, bank and network partners, and external auditors

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 7+ years of professional experience in financial services, payments, or fintech, with at least 5 years in a related role (risk, compliance, or product enablement)
  • Deep subject matter expertise in global sanctions compliance, including hands-on experience with OFAC, EU sanctions regimes, UN Security Council designations, OFSI, and other major global frameworks
  • Demonstrated strong understanding of screening program design and control execution
  • Strong AML screening expertise — proven ability to design, implement, and operationalize PEP screening and negative news screening programs in complex, multi-jurisdiction environments
  • Proven ability to design, implement, and operationalize financial crime standards and controls in complex, global organizations
  • Familiarity with model governance concepts — including model documentation, performance monitoring, and validation — and experience leading or contributing to model governance activities

Preferred qualifications

  • Experience leading transformative AML, Sanctions, or Transaction Monitoring initiatives, including global screening program design or transformations (e.g., vendor selection, watchlist management, false positive tuning)
  • Proficiency with SQL and ability to independently mine and analyze data to develop risk insights and inform strategy
  • Experience with crypto or digital asset products and their associated financial crime risk and regulatory considerations
  • Advanced degree or professional certifications (e.g., CAMS, CGSS, CFCS)

To apply: https://weworkremotely.com/remote-jobs/stripe-risk-strategist-screening-financial-crimes

Read the full description
Security Coinbase: Senior Manager, Internal Audit IT

Lead Coinbase's global IT and security audit program, managing audits across cloud infrastructure, security operations, and risk management while overseeing a distributed team of auditors.

Lead Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - USA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

As the Senior Manager, Internal IT & Security Audit, you'll lead Coinbase's global IT and security audit program. Reporting to the Head of Internal Audit, you will operate within an independent third line of defense that maintains functional accountability to the Audit Committee. You'll own the multi-year IT and security audit roadmap, ensuring coordinated coverage across all regions (US, EMEA, UK, APAC) and alignment with Coinbase's enterprise risk profile and regulatory expectations. Your leadership will directly strengthen how Coinbase identifies, evaluates, and mitigates technology and security risks across the organization.

What you'll do:

  • Own the end-to-end delivery of complex, cross-functional IT and security audits covering cloud infrastructure, security operations, identity and access management, data protection, vendor/third-party risk, and key products and services.
  • Lead and develop a high-performing global team of internal auditors and co-sourced resources, setting goals, coaching talent, managing performance, and building succession pipelines across regions.
  • Drive integrated assurance across the three lines of defense by partnering with first and second line risk, compliance, security, and technology teams to rationalize testing and maximize control coverage.
  • Shape executive-level reporting on technology and security control effectiveness, distilling key themes, emerging risks, and root causes into clear materials for senior management, the Head of Internal Audit, and the Audit Committee.
  • Partner with technology and security leadership across Engineering, Security, Infrastructure, and Product to provide independent challenge on major initiatives (e.g., cloud migrations, new product launches, architecture changes) without compromising third-line independence.
  • Build continuous improvement into the audit function by driving adoption of data analytics, automation, and generative AI to modernize IT and security audit execution, including continuous monitoring and automated evidence retrieval.

Required Skills and Experience:

  • 12+ years of experience in internal audit with deep focus on IT and information security, or in first-line / second-line technology/security roles with significant controls and audit exposure.
  • Demonstrated success leading global, cross-functional IT audit portfolios spanning cloud, infrastructure, cybersecurity, and third-party risk across multiple regulatory jurisdictions (US, EMEA, APAC).
  • Deep technical knowledge of cloud-based technology stacks, software development lifecycles, cloud security configurations, and enterprise IT operations risks and controls.
  • Relevant professional certifications (e.g., CISA, CISSP, CIA, CPA) and working fluency with frameworks such as NIST, COBIT, and ITIL.
  • Proven leadership experience building, mentoring, and managing global audit teams, including co-sourced resources and indirect reports across time zones.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Req ID: #P76564

#LI-Remote

 

 

Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)). 

 

Annual base salary range (excluding equity and bonus):$201,365—$236,900 USD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-senior-manager-internal-audit-it

Read the full description
Security Oracle Cloud Security Engineer

Implements and maintains security infrastructure on Oracle Cloud Platform, managing access controls, compliance, and threat detection.

Mid Remote Posted 15 days ago Himalayas
What this role involves
Oracle Cloud Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description
Security Security Engineer at Corbalt

Integrates security into the software development lifecycle, identifies vulnerabilities, and builds automation tools to improve security practices across engineering teams.

Mid Remote Posted 16 days ago RemoteFirstJobs Product
What this role involves

About Corbalt

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems. We build shared platforms, engineering foundations, and reusable services that enable mission teams to deliver software faster, operate more efficiently, and scale with confidence.

Our roots trace back to the Healthcare.gov recovery effort, where we saw firsthand what talented, mission-driven teams could accomplish together. That experience shaped how we work today: solving complex technical challenges through collaboration, pragmatic engineering, and a relentless focus on delivering value.

Today, we support critical healthcare modernization efforts at the Centers for Medicare & Medicaid Services (CMS), helping build and operate the platforms, tools, and services that enable teams across Medicare and Medicaid to deliver secure, resilient digital experiences.

We’re a remote-first team that values curiosity, kindness, ownership, and continuous learning. We enjoy solving hard technical problems, partnering closely with our clients, and building technology that makes government work better for the people who rely on it.

Contingent Position: This position is contingent upon Corbalt’s successful contract award. Employment offers and start dates are dependent on the award of the associated government contract.

Security Engineer

We’re looking for a Security Engineer who enjoys building secure software, improving engineering platforms, and helping teams deliver with confidence. You’ll work closely with software engineers to integrate security into the development lifecycle, automate security practices, and build resilient cloud-native systems that support critical government services.

Responsibilities

  • Integrate security into the software development lifecycle through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform that improve security, developer productivity, and operational visibility (it’s not important that you know these languages).
  • Support security assessments, compliance activities, and continuous monitoring.
  • Contribute to security best practices across engineering teams.

Skills

  • Strong software engineering fundamentals and experience writing production code.
  • Experience with application security, DevSecOps, or cloud security.
  • Understanding of secure software design, authentication/authorization, and common application vulnerabilities.
  • Familiarity with at least one commonly used programming language and one infrastructure-as-code language.
  • Strong communication and collaboration skills with engineering and technical stakeholders.

Experience

  • 3+ years of engineering experience
  • Demonstrated ability to operate independently and ramp quickly in complex environments
  • Experience supporting security assessments, compliance, or continuous monitoring in regulated environments
  • Familiarity with federal cloud and security requirements (e.g., FISMA)
  • Demonstrated experience operating and analyzing systems in AWS, Azure, or Google Cloud.

Values

  • Growth-oriented mindset
  • Intrinsic motivation to learn, grow, and do great work
  • Kindness
  • Grit / perseverance / resilience

Compensation & Benefits

The base salary range for this position is: $138,677 - $182,296 per year.

In addition to the base salary, Corbalt offers:

  • Medical, dental, vision benefits
  • Profit sharing and discretionary bonuses
  • A company 401(k) contribution equal to 3% of your salary
  • Paid vacation, sick time, and company holidays
  • Reimbursement for reasonable expenses that are helpful for work
  • In-person company retreats

Hiring Process

  • The first stage is an informal conversation to learn more about each other, answer questions, and discuss the role.
  • The second stage is a mini-project based on something we’ve actually worked on. The goal of this is to get an idea of what working together is like.
  • The last stage is: a 10-20 minute presentation to the team describing what you did on a previous project and two 30 minute conversations with other people on the team to get an additional perspective on what our work is like.

Other Requirements

  • Due to contractual requirements applicants must:
    • Be authorized to work in the United States
    • Currently reside in the United States or its territories
    • Have resided in the United States or its territories for three of the last five years
    • Have at least three years of professional experience
  • Due to contractual and security requirements, all work must be performed while physically present within the United States or its territories. Work performed while outside the U.S. or its territories is strictly forbidden.
  • Corbalt participates in E-Verify. Upon hire, your Form I-9 information will be provided to the federal government to confirm you are authorized to work in the United States.

Corbalt is an Equal Opportunity Employer, including disability and protected veteran status.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description