Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Vercel: GRC Analyst

Manages compliance with security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS), maintains internal controls, and collaborates across teams to ensure regulatory adherence.

Mid Hybrid Posted 1 day ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - United States

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role:

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.

You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

What you will do:

  • Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.

About you:

  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.

Bonus if you have :

  • Strong experience with cloud infrastructure (e.g., Azure, AWS)
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
  • Experience with frontend development and open source components
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

 

To apply: https://weworkremotely.com/remote-jobs/vercel-grc-analyst

Read the full description
Security Microsoft Sentinel Security Consultant at Quisitive

Analyzes Microsoft Sentinel security data to provide advisory guidance, interprets incidents and trends, and coaches customers on improving their security posture.

Mid Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

Spyglass is Quisitive’s Security-as-a-Service offering — a modern, insight-driven approach to managed security that goes beyond alerts and tickets. In this role, you’ll help customers turn Microsoft Sentinel insights into better decisions and measurable risk reduction.

This is a remote position and can be based anywhere in the continental US.

About the Role

The Microsoft Sentinel Security Consultant is a customer-facing, advisory role focused on translating Microsoft Sentinel telemetry into clear, actionable security guidance. This is not a traditional SOC role. Instead, it’s designed for professionals who enjoy analyzing patterns, explaining security findings, and coaching customers on how to improve their security posture over time.

You’ll work closely with Spyglass Security Coaches, SecOps teams, and Customer Success Managers to help customers understand what Sentinel is telling them, why it matters, and what to do next.

What You’ll Do

Microsoft Sentinel Advisory (Primary Focus)

  • Review and interpret Microsoft Sentinel incidents, analytics rules, detections, and trends for assigned customers
  • Analyze recurring security signals to identify attack patterns, control gaps, and risk trends over time
  • Develop, read, and explain KQL queries, workbooks, and Sentinel dashboards
  • Partner with MDR and SecOps teams to validate detections, distinguish real risk from noise, and convert findings into advisory recommendations
  • Guide customers on how to act on Sentinel insights, not just respond to alerts

Security Coaching & Advisory

  • Support and contribute to monthly Spyglass security coaching sessions
  • Translate technical Sentinel outputs into clear, business-relevant narratives
  • Participate in executive and technical security advisory discussions
  • Contribute to customer security roadmaps informed by Sentinel-driven insights

Platform & Control Alignment

  • Assess customer security posture across Microsoft Sentinel, Microsoft Defender XDR, and Entra ID
  • Map Sentinel findings to security frameworks such as NIST CSF and CIS Controls
  • Identify gaps in telemetry, detection coverage, and control effectiveness

Delivery & Collaboration

  • Support Spyglass flex work by helping scope, estimate, and validate customer security engagements
  • Develop customer-facing materials such as security narratives, coaching decks, and Sentinel-backed summaries
  • Collaborate closely with Security Coaches, Customer Success Managers, and SecOps teams

What We’re Looking For

Required Qualifications

  • Hands-on experience with Microsoft Sentinel, including incident review, analytics rules, workbooks, and KQL
  • Working knowledge of Microsoft Defender for Endpoint, Identity, Office 365, Cloud Apps, and Entra ID
  • Ability to communicate security insights clearly to non-SOC and business audiences
  • Experience in a consultative or advisory security role
  • Strong ownership mindset and customer-focused communication skills
  • Ability to work with and balance workload with multiple customers

Preferred Qualifications

  • Experience delivering recurring security coaching or advisory services
  • Familiarity with NIST CSF and CIS Controls
  • Experience supporting regulated industries such as healthcare or financial services
  • Microsoft security certifications (SC-200, SC-300, SC-400, AZ-500)

​

US Citizens, Green Card holders and those authorized to work in the US are encouraged to apply.  We are unable to offer sponsorship at this time.

About Quisitive ​

With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description
Security Security Consultant (Microsoft Azure & M365) at Quisitive

Azure Security Consultant designs, implements, and optimizes Microsoft security solutions including identity, endpoint protection, and compliance across cloud environments for enterprise clients.

Mid Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

We’re looking for an Azure Security Consultant who enjoys solving complex challenges, working directly with clients, and staying current with Microsoft’s rapidly evolving security ecosystem. This role is ideal for someone who combines technical expertise with a consultative mindset and wants to make a meaningful impact on customer environments.

This is a remote position and can be based anywhere in the United States.  Prefer Central or Eastern time zones.

What You’ll Do

As an Azure Security Consultant, you’ll work with clients and fellow Quisitive consultants to design, implement, and optimize Microsoft security solutions across cloud, identity, endpoint, and data protection platforms.

  • Partner with clients to understand security challenges, business objectives, and compliance requirements
  • Configure and support Microsoft Entra ID, identity governance, and privileged access solutions
  • Design and implement Conditional Access and Privileged Identity Management (PIM) strategies
  • Deploy and optimize Microsoft Defender security solutions across identity, endpoint, email, and Microsoft 365 environments
  • Assist organizations with security posture improvements using Microsoft security best practices
  • Support endpoint protection, compliance, and device management initiatives through Microsoft Intune and Endpoint Manager
  • Configure and support Microsoft Purview solutions for information protection, governance, and compliance
  • Leverage Azure Log Analytics and security insights to monitor, investigate, and improve customer environments
  • Develop and maintain PowerShell automation to improve efficiency and consistency
  • Collaborate with architects, consultants, and customer stakeholders throughout project delivery

What We’re Looking For

We’re seeking someone who is passionate about technology, enjoys working with customers, and thrives in a collaborative consulting environment.

  • 2-5 years of experience in Azure security engineering, including configuring security controls, monitoring environments, and responding to incidents
  • Experience implementing and managing Microsoft security controls, monitoring solutions, and security best practices
  • Hands-on experience with Microsoft Entra ID, identity governance, Conditional Access, MFA, and self-service password reset (SSPR)
  • Experience with Microsoft Purview and information governance initiatives
  • Knowledge of Microsoft Defender solutions, including Defender for Microsoft 365, Defender for Endpoint, Defender for Identity, and Defender for Cloud and Cloud Security Posture Management (CSPM)
  • Strong communication and consulting skills with the ability to engage directly with customers
  • Ability to understand business requirements and translate them into practical technical solutions
  • Strong organizational and time management skills
  • Experience working in customer-facing consulting engagements
  • Ability to travel occasionally as required

Preferred Qualifications

  • Experience working for a Microsoft-focused consulting or systems integration organization
  • Knowledge of Exchange Online, Active Directory, and hybrid identity environments
  • Experience with Microsoft Sentinel
  • PowerShell, Azure Automation, and Kusto Query Language (KQL)
  • Data Loss Prevention (DLP) and Microsoft Information Protection (MIP) solutions
  • Network security experience
  • Microsoft security certifications such as SC-100, SC-200, SC-300, SC-400, or AZ-500

​US Citizens and those authorized to work in the US are encouraged to apply.  We are unable to offer sponsorship at this time.

About Quisitive ​

​With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description
Security Microsoft Security Coach at Quisitive

Security advisor who coaches clients on improving security posture through reviews, roadmap planning, and actionable recommendations aligned with business goals.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

About the Role

The Security Coach is a client-facing security advisor responsible for helping customers improve their security posture through recurring coaching, tactical deep-dives, roadmap planning, and practical guidance. In this role, you will partner closely with customers, Quisitive MDR/SecOps teams, Customer Success, and technical consultants to translate security insights, Microsoft telemetry, compliance requirements, and threat trends into clear, actionable recommendations.

This role supports Quisitive’s Spyglass managed security service offering by helping customers understand their current security state, prioritize improvements, and drive adoption of Microsoft security capabilities in a way that aligns with their business goals, risk profile, licensing, and operational needs.

As Microsoft continues to expand AI-powered capabilities across the security and productivity landscape, this role will also help customers understand emerging AI security and governance considerations related to Microsoft Copilot, AI-enabled workloads, and agent-based technologies. While AI security is not the primary focus of the role, the Security Coach will help customers balance innovation, security, compliance, and risk as they adopt these solutions.

What You’ll Do

  • Lead recurring customer security coaching sessions, including tactical reviews, advisement sessions, and executive-level security discussions.
  • Review threats, incidents, posture trends, identity risks, compliance insights, and Microsoft security telemetry to identify meaningful areas for improvement.
  • Translate technical findings into clear, business-focused recommendations, roadmaps, and next steps.
  • Partner with MDR/SecOps, Customer Success Managers, consultants, and analysts to align customer priorities, risks, workstreams, and communication plans.
  • Help customers improve their understanding of their security environment and the effectiveness of their tools, processes, and controls.
  • Review and provide guidance across Microsoft security capabilities, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Conditional Access, MFA, PIM, email security, insider risk, and cloud app governance.
  • Provide guidance on emerging AI security and governance practices related to Microsoft Copilot, AI-powered workloads, and agent-based technologies.
  • Build and maintain customer-specific security roadmaps tied to licensing, budget, risk priorities, compliance drivers, and measurable outcomes.
  • Conduct security architecture and adoption planning to help customers optimize the value of their Microsoft tools and licenses.
  • Analyze security trends and make recommendations related to external and internal threats, including malware, identity-based risk, data leakage, attack surface reduction, and emerging AI-related security risks.
  • Prepare advisement materials, tactical decks, quarterly executive summaries, and customer-facing recommendations using evidence from dashboards, analytics tools, KQL queries, reports, and telemetry trends.
  • Guide client conversations toward additional security enhancements, roadmap initiatives, and continuous improvement opportunities.
  • Monitor customer security issues, escalations, and requests, validating context and converting learnings into repeatable guidance.
  • Contribute to playbooks, best practices, and coaching materials while mentoring supporting consultants or analysts as needed.
  • Develop foundational knowledge of Microsoft Agent 365 and related agent governance capabilities to support future customer discussions, assessments, and service offerings.

What You’ll Bring

  • 8+ years of cybersecurity, cloud security, managed security services, or related technical advisory experience.
  • Strong client-facing consulting experience. Must have advisory skills with the ability to build trust, lead conversations, and influence business and technical stakeholders.
  • Experience working with Microsoft security products and capabilities, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview.
  • Experience reviewing security telemetry, dashboards, reports, incidents, identity risks, and compliance-related insights.
  • Strong understanding of security frameworks and compliance drivers such as NIST CSF, CIS Controls, PCI, HIPAA, or similar standards.
  • Ability to translate complex security data into practical, actionable recommendations for both technical teams and executive audiences.
  • Strong business acumen with the ability to connect security priorities to customer goals, operational needs, and risk reduction.
  • Excellent written, verbal, presentation, and executive storytelling skills.
  • Strong problem-solving, decision-making, time management, and organizational skills.
  • Ability to manage multiple customers, priorities, and workstreams in a fast-paced environment.
  • A collaborative mindset with the ability to work across functional teams, including MDR/SecOps, Customer Success, consulting, and customer stakeholders.
  • A high level of professionalism, ownership, and composure when managing deadlines, changing priorities, and customer-facing situations.
  • A growth mindset, curiosity, and desire to continuously learn and adapt as the security landscape evolves.
  • Familiarity with AI security, AI governance, Microsoft Copilot, or emerging security considerations related to generative AI, including data protection, identity governance, and responsible AI practices.
  • Understanding of Microsoft security architecture principles including identity, data protection, compliance, Zero Trust, and cloud security governance.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience.
  • Ability to travel periodically, up to approximately 10-15%.

What Would Set You Apart

  • Microsoft security certifications such as SC-100, AZ-500, or related Microsoft Security, Compliance, and Identity certifications.
  • Experience working in or alongside MDR, SOC, SecOps, or managed services teams.
  • Experience with Enterprise Mobility + Security, Office 365 security features, Microsoft Defender for Endpoint, Defender for Cloud Apps, email security, and identity protection.
  • Experience mapping compliance and security requirements to technical controls.
  • Experience building customer roadmaps, executive security summaries, adoption plans, or measurable KPI-based improvement plans.
  • Experience with Microsoft Copilot, Copilot Studio, AI governance initiatives, or security assessments related to AI-enabled workloads.
  • Experience with Microsoft Entra Identity Governance, Privileged Identity Management (PIM), Microsoft Purview Information Protection, Data Loss Prevention (DLP), or related technologies used to secure AI and agent-based solutions.
  • Relevant industry certifications such as CompTIA Security+, CEH, GSEC, CISSP, or CISM.

Why This Role Matters

Security Coaches are a critical connection point between our customers, Quisitive security teams, and the Microsoft security ecosystem. You will help customers move from insight to action by turning telemetry, threat trends, compliance needs, and technical findings into practical steps that improve security outcomes over time.

This is a role for someone who enjoys being both strategic and hands-on, someone who can lead customer conversations, interpret complex security data, build trust with stakeholders, and help customers make meaningful progress in protecting their business.

As our customers increasingly adopt Microsoft Copilot, AI-powered workloads, and agent-based technologies, you will also help them navigate emerging security and governance considerations while building your expertise in Microsoft Agent 365 and the evolving AI security landscape.

​

About Quisitive ​

​With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description
Security FedRamp Compliance Analyst at Abnormal AI

Manages FedRAMP compliance requirements, evidence collection, and security control implementation across technical teams while building compliance-as-code capabilities.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

About the Role

Abnormal AI is looking for a Federal Security and Compliance Analyst who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company.

You will work at the intersection of security engineering, cloud operations, security, and federal compliance, helping Abnormal Gov scale its FedRAMP High/Class D security and compliance program. You will own security requirement implementation and evidence, work directly with technical teams to drive risk and remediation to closure, and help build our compliance as code capabilities in alignment with FedRAMP 20x.

You’ll have meaningful ownership early, with the opportunity to improve processes rather than simply inherit them. The strongest candidate will be technically curious, highly organized, comfortable navigating ambiguity, and motivated by making compliance more accurate, automated, measurable, and operationally useful.

What you will do

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, remediation, and review readiness.
  • Drive recurring continuous monitoring and evidence workflows, coordinating across Security, FedOps, Engineering, IT, People Operations, GRC, and other control performers to ensure evidence is current, complete, traceable, and retained correctly.
  • Support vulnerability detection and response, including reconciling findings from tools such as Wiz, Nessus, and Burp; risk-based triage; Jira routing; SLA tracking; remediation follow-through; validation; and audit-ready evidence.
  • Partner with technical teams on security and compliance impact, supporting Security Impact Assessments, Significant Change Requests, control implementation decisions, and other change-management activities before changes reach production.
  • Help build Abnormal’s compliance-as-code program, including structured control content, JSON/YAML or other machine-readable artifacts, schema validation, evidence indexing, automation, deterministic document generation, and reusable workflows.
  • Maintain accurate control, evidence, remediation, risk, and ownership records, proactively identifying gaps, aging items, dependencies, and decisions requiring escalation.
  • Contribute to federal authorization and assessment artifacts, including control documentation, Security Decision Records, certification-package content, assessor requests, and continuous monitoring deliverables.
  • Support federal customer assurance by providing clear, accurate compliance guidance and artifacts for customer onboarding, POVs, DDQs, RFPs, and other government or regulated customer requests.

Must Haves

  • 2+ years of experience in security, compliance, GRC, risk, audit, security operations, or a related discipline, preferably in a cloud, SaaS, government, or highly regulated environment.
  • Working knowledge of NIST SP 800-53 and an understanding of how security controls translate into technical implementation, operational processes, and audit evidence.
  • Experience with one or more core compliance operations such as evidence collection, control documentation, vulnerability remediation, risk tracking, audit support, or continuous monitoring.
  • Technical curiosity and the ability to read architecture diagrams, security documentation, vulnerability findings, Jira tickets, logs, or engineering materials and turn them into clear compliance actions.
  • Ability to work effectively with Security, Engineering, Infrastructure/Operations, IT, and other technical teams without needing every problem or requirement to be fully defined in advance.
  • Strong written communication skills and the ability to produce documentation that is precise enough for assessors and technical teams while remaining understandable to non-technical stakeholders.
  • Strong operational discipline: you can manage multiple workstreams, dependencies, owners, and deadlines while identifying problems and escalating risk early.
  • A demonstrated tendency to improve the way work gets done through automation, better processes, clearer documentation, reusable templates, better data, or simpler workflows.

.

Nice to Have

  • Experience with FedRAMP High, FedRAMP Moderate, FISMA, CMMC, GovRAMP, or other U.S. government security frameworks.
  • Exposure to compliance-as-code, OSCAL, JSON/YAML schemas, Git-based workflows, automated validation, Markdown/PDF generation, or machine-readable authorization artifacts.
  • Familiarity with tools or environments such as AWS GovCloud, Wiz, Splunk, Okta, Jira, GitLab, Nessus, Burp, or cloud-native vulnerability-management platforms.
  • Experience supporting Security Impact Assessments, Significant Change Requests, POA&M/ConMon workflows, 3PAO assessments, or federal authorization packages.
  • Basic scripting or automation experience—such as Python, APIs, CI/CD workflows, or data transformation—or a strong interest in developing those skills.

#LI-PP1

Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.

In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.

Base salary range:

$114,800—$173,250 USD

A note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AI’s policies relevant to our security and privacy standards.

Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.

Read the full description
Security Microsoft Security Coach at Quisitive

Client-facing security advisor who conducts recurring coaching sessions, reviews security telemetry and threats, and translates findings into actionable recommendations for customers.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

About the Role

The Security Coach is a client-facing security advisor responsible for helping customers improve their security posture through recurring coaching, tactical deep-dives, roadmap planning, and practical guidance. In this role, you will partner closely with customers, Quisitive MDR/SecOps teams, Customer Success, and technical consultants to translate security insights, Microsoft telemetry, compliance requirements, and threat trends into clear, actionable recommendations.

This role supports Quisitive’s Spyglass managed security service offering by helping customers understand their current security state, prioritize improvements, and drive adoption of Microsoft security capabilities in a way that aligns with their business goals, risk profile, licensing, and operational needs.

As Microsoft continues to expand AI-powered capabilities across the security and productivity landscape, this role will also help customers understand emerging AI security and governance considerations related to Microsoft Copilot, AI-enabled workloads, and agent-based technologies. While AI security is not the primary focus of the role, the Security Coach will help customers balance innovation, security, compliance, and risk as they adopt these solutions.

What You’ll Do

  • Lead recurring customer security coaching sessions, including tactical reviews, advisement sessions, and executive-level security discussions.
  • Review threats, incidents, posture trends, identity risks, compliance insights, and Microsoft security telemetry to identify meaningful areas for improvement.
  • Translate technical findings into clear, business-focused recommendations, roadmaps, and next steps.
  • Partner with MDR/SecOps, Customer Success Managers, consultants, and analysts to align customer priorities, risks, workstreams, and communication plans.
  • Help customers improve their understanding of their security environment and the effectiveness of their tools, processes, and controls.
  • Review and provide guidance across Microsoft security capabilities, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Conditional Access, MFA, PIM, email security, insider risk, and cloud app governance.
  • Provide guidance on emerging AI security and governance practices related to Microsoft Copilot, AI-powered workloads, and agent-based technologies.
  • Build and maintain customer-specific security roadmaps tied to licensing, budget, risk priorities, compliance drivers, and measurable outcomes.
  • Conduct security architecture and adoption planning to help customers optimize the value of their Microsoft tools and licenses.
  • Analyze security trends and make recommendations related to external and internal threats, including malware, identity-based risk, data leakage, attack surface reduction, and emerging AI-related security risks.
  • Prepare advisement materials, tactical decks, quarterly executive summaries, and customer-facing recommendations using evidence from dashboards, analytics tools, KQL queries, reports, and telemetry trends.
  • Guide client conversations toward additional security enhancements, roadmap initiatives, and continuous improvement opportunities.
  • Monitor customer security issues, escalations, and requests, validating context and converting learnings into repeatable guidance.
  • Contribute to playbooks, best practices, and coaching materials while mentoring supporting consultants or analysts as needed.
  • Develop foundational knowledge of Microsoft Agent 365 and related agent governance capabilities to support future customer discussions, assessments, and service offerings.

What You’ll Bring

  • 8+ years of cybersecurity, cloud security, managed security services, or related technical advisory experience.
  • Strong client-facing consulting experience. Must have advisory skills with the ability to build trust, lead conversations, and influence business and technical stakeholders.
  • Experience working with Microsoft security products and capabilities, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, and Microsoft Purview.
  • Experience reviewing security telemetry, dashboards, reports, incidents, identity risks, and compliance-related insights.
  • Strong understanding of security frameworks and compliance drivers such as NIST CSF, CIS Controls, PCI, HIPAA, or similar standards.
  • Ability to translate complex security data into practical, actionable recommendations for both technical teams and executive audiences.
  • Strong business acumen with the ability to connect security priorities to customer goals, operational needs, and risk reduction.
  • Excellent written, verbal, presentation, and executive storytelling skills.
  • Strong problem-solving, decision-making, time management, and organizational skills.
  • Ability to manage multiple customers, priorities, and workstreams in a fast-paced environment.
  • A collaborative mindset with the ability to work across functional teams, including MDR/SecOps, Customer Success, consulting, and customer stakeholders.
  • A high level of professionalism, ownership, and composure when managing deadlines, changing priorities, and customer-facing situations.
  • A growth mindset, curiosity, and desire to continuously learn and adapt as the security landscape evolves.
  • Familiarity with AI security, AI governance, Microsoft Copilot, or emerging security considerations related to generative AI, including data protection, identity governance, and responsible AI practices.
  • Understanding of Microsoft security architecture principles including identity, data protection, compliance, Zero Trust, and cloud security governance.
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or equivalent experience.
  • Ability to travel periodically, up to approximately 10-15%.

What Would Set You Apart

  • Microsoft security certifications such as SC-100, AZ-500, or related Microsoft Security, Compliance, and Identity certifications.
  • Experience working in or alongside MDR, SOC, SecOps, or managed services teams.
  • Experience with Enterprise Mobility + Security, Office 365 security features, Microsoft Defender for Endpoint, Defender for Cloud Apps, email security, and identity protection.
  • Experience mapping compliance and security requirements to technical controls.
  • Experience building customer roadmaps, executive security summaries, adoption plans, or measurable KPI-based improvement plans.
  • Experience with Microsoft Copilot, Copilot Studio, AI governance initiatives, or security assessments related to AI-enabled workloads.
  • Experience with Microsoft Entra Identity Governance, Privileged Identity Management (PIM), Microsoft Purview Information Protection, Data Loss Prevention (DLP), or related technologies used to secure AI and agent-based solutions.
  • Relevant industry certifications such as CompTIA Security+, CEH, GSEC, CISSP, or CISM.

Why This Role Matters

Security Coaches are a critical connection point between our customers, Quisitive security teams, and the Microsoft security ecosystem. You will help customers move from insight to action by turning telemetry, threat trends, compliance needs, and technical findings into practical steps that improve security outcomes over time.

This is a role for someone who enjoys being both strategic and hands-on, someone who can lead customer conversations, interpret complex security data, build trust with stakeholders, and help customers make meaningful progress in protecting their business.

As our customers increasingly adopt Microsoft Copilot, AI-powered workloads, and agent-based technologies, you will also help them navigate emerging security and governance considerations while building your expertise in Microsoft Agent 365 and the evolving AI security landscape.

​

About Quisitive ​

​With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description
Security Security Engineer (REMOTE) at EnableComp

Security Engineer embeds security controls across applications, data pipelines, and AI systems while translating security policies into practical, deployable technical solutions.

Mid Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise and its unified E360 RCM™ intelligent automation platform to improve financial sustainability for hospitals, health systems, and ambulatory surgery centers (ASCs) nationwide. Powered by proprietary algorithms, iterative intelligence from 10M+ processed claims, and expert human-in-the-loop integration, EnableComp provides solutions across the revenue lifecycle for Veterans Administration, Workers’ Compensation, Motor Vehicle Accidents, and Out-of-State Medicaid claims as well as denials for all payer classes. By partnering with clients to supercharge the reimbursement process, EnableComp removes the burden of payment from patients and provider organizations while enabling accelerated cash, higher and more accurate yield, clean AR management, reduced denials, and data-rich performance management. EnableComp is a multi-year recipient the Top Workplaces award and was recognized as Black Book’s #1 Specialty Revenue Cycle Management Solution provider in 2024 and is among the top one percent of companies to make the Inc. 5000 list of the fastest-growing private companies in the United States for the last eleven years.

POSITION SUMMARY

The Security Engineer serves as the technical bridge between the security policy team and development operations, ensuring that security principles are not only defined but effectively implemented. Embedded within development teams, this role writes code, configures systems, and operationalizes security controls across applications, databases, and AI systems. As a key contributor to the organization’s Agentic AI platform transformation, the Security Engineer will design and embed secure-by-design practices, enabling innovation while maintaining the highest standards of data protection and compliance.

THE JOB RESPONSIBILITIES INCLUDE

  • Bridge security policy and technical execution by translating organizational security requirements into practical, deployable solutions across applications, data environments, and AI systems.
  • Design, build, and deploy security controls across web applications, data pipelines, APIs, and Agentic AI systems to ensure confidentiality, integrity, and availability.
  • Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations, configuration hardening, and secure infrastructure deployment.
  • Develop automation scripts and infrastructure-as-code to integrate security into CI/CD pipelines, enabling continuous compliance, secrets management, vulnerability scanning, and environment hardening.
  • Implement and operationalize AI-specific security frameworks by building guardrails for agentic models, securing data flows, and integrating AI security tooling into development workflows.
  • Perform hands-on technical security assessments, including penetration testing, threat modeling, and code reviews, and directly remediate identified vulnerabilities.
  • Collaborate with cloud and DevOps teams to deploy monitoring and detection controls and ensure secure configuration baselines across environments.
  • Provide practical security guidance and training to developers and engineers during architecture reviews, sprint planning, and project delivery.
  • Continuously evaluate and improve the organization’s security posture through testing, feedback loops, and adoption of emerging best practices for AI and distributed systems.
  • Document security architectures, configurations, and implementation patterns to support ongoing operations, compliance, and knowledge sharing.
  • Other duties as required

REQUIREMENTS AND QUALIFICATIONS

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field required

  • 3+ years in hands-on application security, DevSecOps, or security engineering roles.

  • Proven experience building and configuring secure CI/CD pipelines (Jenkins, GitLab CI, GitHub Actions, Azure DevOps).

  • Equivalent combination of education and experience will be considered.

  • Deep proficiency with cloud security in AWS, Azure, or GCP environments.

  • Strong implementation experience with infrastructure as code (Terraform, CloudFormation) and container security (Docker, Kubernetes).

  • Strong scripting and automation skills (Python, Bash, PowerShell) for security tooling.

  • Versatility across web/API security, data pipeline security, microservices, and database security.

  • Understanding of security frameworks (NIST, ISO 27001, SOC 2) and compliance requirements (GDPR, HIPAA, PCI-DSS).

  • Hands-on experience deploying and configuring security scanning tools (SAST, DAST, SCA).

  • Excellent communication skills—ability to translate security requirements into working technical implementations.

  • Experience working embedded within cross-functional development teams.

  • Proven track record of hands-on problem-solving in fast-paced development environments

  • Regular and predictable attendance

  • Equivalent combination of education and experience will be considered

  • Must have strong computer proficiency and understand how to use basic office applications, including MS Office (Word, Excel, and Outlook)

  • To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodation may be made to enable qualified individuals with disabilities to perform the essential functions.

SPECIAL CONSIDERATIONS & PREREQUISITES

  • Practices and adheres to EnableComp’s Core Values, Vision and Mission

  • Hands-on experience with AI/ML security, model security, and data governance

  • Technical knowledge of LLM security, prompt injection prevention, and AI agent safety

  • Security certifications (CISSP, CEH, OSCP, CSSLP, or cloud security certifications)

  • Strong coding background in Python, Go, or similar languages.

  • Background in software development or engineering transitioning to security.

  • Direct experience implementing secrets management solutions (HashiCorp Vault, AWS Secrets Manager).

  • Practical experience with zero trust architecture implementation.

  • Familiarity with data security, ETL processes, and data warehouse security.

  • Experience with microservices architectures and distributed systems security

EnableComp is an Equal Opportunity Employer M/F/D/V. All applicants will be considered for this position based upon experience and knowledge, without regard to race, color, religion, national origin, sexual orientation, ancestry, marital, disabled or veteran status. We are committed to creating and maintaining a workforce environment that is free from any form of discrimination or harassment.

EnableComp recruits, develops and retains the industry’s top talent.  As the employer of choice in the complex claims industry, EnableComp takes pride in our continuous commitment to building and maintaining a culture centered around fostering the professional growth and development of our people.  We believe that investing in our employees is the key to our success, and we are dedicated to providing them with the tools, resources, and support they need to thrive and grow their career here. At EnableComp, we are committed to living up to our core values each and every day, and we believe that this commitment is what sets us apart from other companies.  If you are looking for a company that values its employees and is dedicated to helping them achieve their full potential, then EnableComp is the place for you.

Don’t just take our word for it!  Hear what our people are saying:

“I love my job because everyone shares the same vision and is determined and dedicated. People care about you as a person and your professional growth. There is a genuine spirit of cooperation and shared goals all revolving around helping each other.” – Revenue Specialist

“I enjoy working for EnableComp because of the Core Values we believe in. EnableComp stands true to these values from empowering employees to ecstatic clients. This company is family oriented and flexible, along with understanding the balance of work, life, and fun.” – Supervisor, Operations

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Information Security Engineer

Designs and implements security infrastructure solutions to protect enterprise systems, machines, and AI platforms from threats.

Mid Posted 3 days ago Jobicy AI
What this role involves
About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world’s largest enterprises...
Read the full description
Security DevSecOps Engineer at Casa Inc.

DevSecOps engineer manages security controls, access management, vulnerability triage, and infrastructure automation while developing security processes and training across the organization.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

MEET CASA

Casa is the secure home for your bitcoin. We’re the leading provider of Bitcoin self-custody solutions, the ultimate blend of security, privacy, and control. Our team combines deep security expertise, human-focused design, and exceptional customer service to empower our clients and build lifelong relationships.

THE ROLE

Casa is looking for a DevSecOps Engineer to help secure our customers, their data, and our company. As a member of our Security team, you will report to our Chief Security Officer and play a crucial role in overseeing our security architecture and culture. It will also be a unique opportunity to help develop an evolving security program consisting of efficient processes, training materials, and methodologies for all employees.

The successful candidate has experience developing scalable security controls and approaches in accordance with industry standards.

Compensation: $125,000-155,000 USD

WHAT YOU’LL DO:

  • Handle internal security requests and make sure employees have the tools and access they need without over-provisioning
  • Ensure that employees have access to the tools and systems they need while maintaining least privilege access principles
  • Onboard and offboard employees across internal systems
  • Oversee our MDM system and stay on top of alerts
  • Review and assess new technologies (tools, code frameworks, third-party providers, internal apps) through a security lens
  • Help shape and refine security best practices across the org
  • Triage and work through vulnerabilities surfaced by pen testing, static analysis, responsible disclosures, and automated alerts
  • Keep security documentation and training materials fresh and useful
  • Automate security processes and alerts wherever you can find the leverage
  • Participate in a shared on-call rotation for critical production security issues
  • Stay abreast of the latest security events and trends
  • Participate in regular security training and certification acquisition
  • Ensure our software development lifecycle remains secure as we continue to evolve its processes.
  • Write infrastructure-as-code to automate deployment and management using Terraform, Ansible, or similar tools
  • Stay current on emerging threats, security trends, and what’s happening across our stack and industry
  • Investigate and resolve infrastructure incidents to keep things running smoothly

WHO YOU ARE:

  • You have security certifications or equivalent real-world experience
  • You think like an attacker, and a hacker mindset is genuinely how you approach problems
  • Deep background across multiple facets of security
  • 5+ years implementing security in Linux-based infrastructures, AWS, and code
  • Comfortable with open-source tooling, cloud environments, and multiple operating systems
  • Experience building security solutions that actually scale
  • Hands-on with one or more of: penetration testing, threat modeling, code analysis, system hardening, distributed patching, vulnerability scanning
  • Familiar with hardening AI tooling to prevent security incidents
  • Strong communicator who can present findings to both technical and non-technical audiences
  • Bonus points for experience or genuine interest in cryptocurrency / cryptography

WHY CASA?

At Casa, our mission is to empower individuals to secure their digital sovereignty, and we empower our employees to do their best work.

  • Ownership. Private key management is the beginning of a future you can truly own, and at Casa, everyone has a role. We offer equity opportunities so our employees can benefit from what we are building together
  • Community. Inclusivity is important to us.We value each other and our contributions. Our team, known as the Casa Space Fleet, brings out the best in everyone while having plenty of fun along the way
  • Rest and Relaxation. We believe in the power of personal time, so we offer as much flexible time as you need. We encourage you to take at least 3 weeks off a year
  • Health Benefits. We provide medical coverage with FSA options, dental, vision, and access to mental health providers
  • Setup for Remote Success. Our team is both decentralized and effective. We reimburse up to $400 for anything you need to set up your home office
  • Investment Avenues. We partner with resources so you can invest a portion of your paycheck in Bitcoin, and we also have the more traditional 401(k) option
  • Maternity/Paternity Leave. We provide 12 weeks for maternity / 4 weeks for paternity

*As Casa is a fully remote company hiring candidates around the world, our perks and benefit packages may adjust based on your location

Casa is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, veteran status, genetic data, or other legally protected status

Read the full description
Security DevSecOps Engineer at Casa Inc.

DevSecOps engineer manages security infrastructure, access controls, vulnerability triage, and security automation while maintaining least privilege principles across the organization.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

MEET CASA

Casa is the secure home for your bitcoin. We’re the leading provider of Bitcoin self-custody solutions, the ultimate blend of security, privacy, and control. Our team combines deep security expertise, human-focused design, and exceptional customer service to empower our clients and build lifelong relationships.

THE ROLE

Casa is looking for a DevSecOps Engineer to help secure our customers, their data, and our company. As a member of our Security team, you will report to our Chief Security Officer and play a crucial role in overseeing our security architecture and culture. It will also be a unique opportunity to help develop an evolving security program consisting of efficient processes, training materials, and methodologies for all employees.

The successful candidate has experience developing scalable security controls and approaches in accordance with industry standards.

Compensation: $125,000-155,000 USD

WHAT YOU’LL DO:

  • Handle internal security requests and make sure employees have the tools and access they need without over-provisioning
  • Ensure that employees have access to the tools and systems they need while maintaining least privilege access principles
  • Onboard and offboard employees across internal systems
  • Oversee our MDM system and stay on top of alerts
  • Review and assess new technologies (tools, code frameworks, third-party providers, internal apps) through a security lens
  • Help shape and refine security best practices across the org
  • Triage and work through vulnerabilities surfaced by pen testing, static analysis, responsible disclosures, and automated alerts
  • Keep security documentation and training materials fresh and useful
  • Automate security processes and alerts wherever you can find the leverage
  • Participate in a shared on-call rotation for critical production security issues
  • Stay abreast of the latest security events and trends
  • Participate in regular security training and certification acquisition
  • Ensure our software development lifecycle remains secure as we continue to evolve its processes.
  • Write infrastructure-as-code to automate deployment and management using Terraform, Ansible, or similar tools
  • Stay current on emerging threats, security trends, and what’s happening across our stack and industry
  • Investigate and resolve infrastructure incidents to keep things running smoothly

WHO YOU ARE:

  • You have security certifications or equivalent real-world experience
  • You think like an attacker, and a hacker mindset is genuinely how you approach problems
  • Deep background across multiple facets of security
  • 5+ years implementing security in Linux-based infrastructures, AWS, and code
  • Comfortable with open-source tooling, cloud environments, and multiple operating systems
  • Experience building security solutions that actually scale
  • Hands-on with one or more of: penetration testing, threat modeling, code analysis, system hardening, distributed patching, vulnerability scanning
  • Familiar with hardening AI tooling to prevent security incidents
  • Strong communicator who can present findings to both technical and non-technical audiences
  • Bonus points for experience or genuine interest in cryptocurrency / cryptography

WHY CASA?

At Casa, our mission is to empower individuals to secure their digital sovereignty, and we empower our employees to do their best work.

  • Ownership. Private key management is the beginning of a future you can truly own, and at Casa, everyone has a role. We offer equity opportunities so our employees can benefit from what we are building together
  • Community. Inclusivity is important to us.We value each other and our contributions. Our team, known as the Casa Space Fleet, brings out the best in everyone while having plenty of fun along the way
  • Rest and Relaxation. We believe in the power of personal time, so we offer as much flexible time as you need. We encourage you to take at least 3 weeks off a year
  • Health Benefits. We provide medical coverage with FSA options, dental, vision, and access to mental health providers
  • Setup for Remote Success. Our team is both decentralized and effective. We reimburse up to $400 for anything you need to set up your home office
  • Investment Avenues. We partner with resources so you can invest a portion of your paycheck in Bitcoin, and we also have the more traditional 401(k) option
  • Maternity/Paternity Leave. We provide 12 weeks for maternity / 4 weeks for paternity

*As Casa is a fully remote company hiring candidates around the world, our perks and benefit packages may adjust based on your location

Casa is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard to race, sex, color, religion, national origin, age, disability, veteran status, genetic data, or other legally protected status

Read the full description
Security Application Security Engineer II at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity and accuracy, and communicates findings with clients and security researchers across managed bug bounty programs.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security Application Security Engineer II at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates findings to clients and researchers across diverse applications.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security AI Security Analyst at LawPay

Monitors and secures AI deployments, assesses AI-specific risks like prompt injection and model misuse, and governs agentic systems across internal and customer-facing platforms.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Information Security Engineer at LawPay

Operates cloud security stack, leads incident response and detection engineering, and manages vulnerability remediation across AWS infrastructure.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AWS security operations: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams
  • Detection engineering: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity
  • Incident response & forensics: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews
  • Vulnerability management: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage
  • Security awareness & internal ops: Manage KnowBe4 phishing tests/training with Compliance
  • Platform security: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment
  • Data privacy & compliance support: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)
  • Product security & documentation: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate

About you:

  • 4+ years in security engineering or security operations, with real incident response experience.
  • Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).
  • Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python

preferred).

  • Experience with vulnerability management tooling and remediation SLA programs.

  • Comfortable operating independently in a distributed team; strong written English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • PCI DSS or SOC 2 environment experience; ASV scan operations.
  • Terraform/IaC security review experience.
  • Exposure to securing AI-assisted development or agentic tooling.

Additional Information

The monthly gross salary range for this position is CZK 90,000 to CZK 160,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security AI Security Analyst at LawPay

Monitors AI security risks, assesses generative AI deployments for threats, and ensures governance compliance for agentic systems and third-party AI vendors.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security AI Security Analyst at LawPay

Monitors AI security risks, assesses AI use cases for threats, and supports governance of generative AI and agentic systems while performing traditional security operations.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Information Security Engineer at LawPay

Operates AWS security stack, performs detection engineering, leads incident response investigations, and manages vulnerability operations for a payments/compliance software platform.

Mid Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AWS security operations: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams
  • Detection engineering: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity
  • Incident response & forensics: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews
  • Vulnerability management: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage
  • Security awareness & internal ops: Manage KnowBe4 phishing tests/training with Compliance
  • Platform security: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment
  • Data privacy & compliance support: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)
  • Product security & documentation: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate

About you:

  • 4+ years in security engineering or security operations, with real incident response experience.
  • Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).
  • Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python

preferred).

  • Experience with vulnerability management tooling and remediation SLA programs.

  • Comfortable operating independently in a distributed team; strong written English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • PCI DSS or SOC 2 environment experience; ASV scan operations.
  • Terraform/IaC security review experience.
  • Exposure to securing AI-assisted development or agentic tooling.

Additional Information

The monthly gross salary range for this position is CZK 90,000 to CZK 160,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Software Engineer, Infrastructure Security

Builds and maintains infrastructure security systems to protect OpenAI's technology, people, and products from threats.

Mid Posted 5 days ago Jobicy AI
What this role involves
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products....
Read the full description
Security Vulnerability Management Engineer

Identifies, assesses, and remediates security vulnerabilities across systems and infrastructure.

Mid Posted 6 days ago Himalayas
What this role involves
What You'll Do We are looking for apassionate and drivenVulnerability Engineerto join our Vulnerability Management team.
Read the full description
Security Applied AI Security Engineer at Waabi

Designs and implements AI security controls, guardrails, and sandboxing patterns across company systems while auditing AI tool usage and training users on secure practices.

Mid Posted 7 days ago RemoteFirstJobs Product
What this role involves

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.

With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai

Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.

You will…

- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.

- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.

- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.

- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.

- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.

- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.

- Document guidance and patterns that a non-security audience can actually follow without needing a security background.

Qualifications:

- Bachelor’s degree in Computer Science or a related field.

- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.

- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.

- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.

- Strong communication skills - you work with engineers as a partner.

Bonus:

- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.

- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.

- Background in autonomous vehicles, robotics, or other safety-critical systems

The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations.  Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.

Perks/Benefits:

Waabi provides a competitive benefits package that includes:

- Competitive compensation and equity awards.

- Health and Wellness benefits that include Medical, Vision and Dental coverage.

- Unlimited Vacation.

- Flexible hours and Work from Home support.

- Daily drinks, snacks and catered meals (when in office).

- Regularly scheduled team building activities and social events.

- As we grow, this list continues to evolve!

Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!

Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description