Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security DevSecOps Engineer (DoD Secret | Hybrid) at Rackner

Configures and maintains CI/CD pipelines and DevSecOps tools to ensure compliance with DoD security controls while supporting software development teams.

Senior Hybrid Posted about 23 hours ago RemoteFirstJobs Product
What this role involves

Senior DevSecOps Engineer

Location: Hybrid. ( 2 days/week in College Park, MD)

Clearance: Active DoD Secret Clearance

Employment Type: Full-time

What You’ll Do:

  • You will work on the Forge DevSecOps (DSO) Tools Team as a DevSecOps Engineer.
  • You will configure Pipelines and DevSecOps tools to be compliant with technical controls as defined by the Forge Cyber Guild to receive authorizations.
  • You will work with Software Product teams to help resolve CI/CD Pipeline issues that are reported by Developers.

Required Qualifications and Skillsets

  • Experience designing, administering, and troubleshooting CI/CD pipelines using GitLab CI/CD.
  • Hands-on experience installing, configuring, securing, scaling, and maintaining GitLab Runners across Linux-based and/or containerized environments.
  • Experience building and maintaining applications using common build/package tools, such as Maven, Gradle, npm, pip, NuGet, Make, or similar tools appropriate to supported development languages.
  • Experience integrating containerized applications and services is Kubernetes.

Desired Qualifications and Skillsets

  • Experience with the NAVSEA Afloat Software Authorization Pathway (ASAP) process
  • Experience working on Gov Cloud infrastructure with Accredited DOD (Unclassified and Classified) Networks
  • Experience administering instances of: Gitlab, SonarQube, Anchore, and Artifactory

Who We Are:

  • Rackner is a cloud-native software consultancy delivering solutions for startups, enterprises, and the public sector.
  • We enable digital transformation through DevSecOps, AI/ML, and cloud-first innovation.
  • Join a team that thrives on solving high-impact problems and delivering secure, scalable solutions for the Department of Defense and federal health programs.

Why You’ll Love Working Here:

  • Weekly Pay & Hybrid (2 days/week)
  • Professional Growth – Paid certifications and training for relevant technologies
  • Comprehensive Benefits – 401k (100% match up to 6%), PTO, medical/dental/vision, life & disability insurance
  • Work-Life Perks – Gym/fitness membership, home office setup, swag, snacks, and social events

Hashtags for Visibility

#DevSecOps #Kubernetes #Terraform #AWSGovCloud  #ClearanceJobs #RacknerCareers #FederalTech #CloudEngineering #hybrid

Read the full description
Security Senior Security Engineer at Pair Team

Implements security controls across cloud infrastructure, AI systems, and compliance initiatives for a HIPAA-regulated healthcare platform.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Pair Team

Pair Team is building a new kind of healthcare system across Medicaid, Medicare, and public assistance programs: one that recognizes that access to housing, nutritious food, and reliable transportation are just as critical to health as having the right medications or seeing a doctor.

As a public benefit corporation and AI-enabled medical group, we partner with shelters, food pantries, and community organizations to deliver “whole-person” care to the 115 million Americans who rely on the safety net. We are currently the largest complex care provider in California with over 500 employees and are expanding nationally. Our model replaces fragmented healthcare and social services systems with one trusted relationship for all medical, behavioral, and social needs.  We improve access, build trust, and dramatically lower costs (52% fewer ER visits, 26% fewer hospitalizations). Our model is a rare combination of saving tax payer dollars ($150B annually at scale) while putting people on an upward life trajectory. At national scale, this approach would save taxpayers.

These outcomes are driven by the AI-first, whole-person infrastructure we are building — a platform that connects healthcare and social-service organizations into a unified network. Leveraging our vast data and years of operational experience, we are building the agentic infrastructure for the safety net to coordinate care, automate operations, and learn from every patient interaction to continuously improve outcomes.

Read more about the AI-First Medicaid System we are building here .

  • Forbes: For Pair Team, Accessibility Is About Delivering Healthcare To Those Who Need It The Most
  • TechCrunch: Building for Medicaid’s regulatory moment with Neil Batlivala from Pair Team
  • Journal of General Internal Medicine: A Novel Intervention for Medicaid Beneficiaries with Complex Needs

About the Opportunity

As a HIPAA-regulated, AI-native company, security is foundational to our ability to serve patients. As our platform, AI capabilities, and regulatory footprint continue to grow, we’re looking for our first dedicated Security Engineer to help scale our security posture alongside the business.

This is a highly hands-on engineering role. You’ll own the implementation of security controls across applications, cloud infrastructure, AI systems, and compliance-driven initiatives. You’ll help secure patient-facing voice agents, LLM-powered workflows, internal developer tooling, and a growing ecosystem of vendors and integrations. You’ll partner closely with Engineering and IT to remediate findings, improve our security foundations, and build systems that enable the company to move quickly and safely.

This role is ideal for someone who enjoys building—an engineer who wants to write code, automate workflows, strengthen infrastructure, and help shape security at a company using AI to improve healthcare access for underserved communities.

This is a fully remote position reporting up to the IT Lead.

What You’ll Do

  • Own vulnerability management, dependency security, threat modeling, security code reviews, and remediation of penetration test findings.
  • Strengthen our AWS security posture, identity and access management (IAM, SSO, SAML, SCIM), endpoint security, threat detection, and incident response capabilities.
  • Design and implement security controls for AI-powered products and workflows, including protections against prompt injection, data leakage, and other AI-specific risks.
  • Build technical safeguards that enable the secure use of PHI and sensitive data within LLM-powered systems.
  • Implement and maintain the technical controls, evidence, and security practices required to support HIPAA, SOC 2, and other compliance programs.
  • Leverage AI-powered tooling, automation, and modern security platforms to scale security impact across the organization.
  • Build self-service security solutions, paved roads, and runbooks that help engineers move quickly while maintaining strong security standards.
  • Partner closely with Engineering and IT to deliver pragmatic, scalable security solutions that support product velocity and business growth.
  • Be a force multiplier for the Pod-Infra team

What You’ll Need

  • 2+ years of Security Engineering experience, with significant depth in either application security or infrastructure/cloud security and working proficiency in the other
  • Strong AWS and cloud security expertise, including IAM, identity management (SSO, SAML, SCIM), network security, secrets management, and cloud-native security tooling
  • Hands-on software engineering experience with the ability to read, review, and ship production code in Python and/or TypeScript. Ruby experience is a plus
  • Experience implementing technical controls in regulated environments such as HIPAA, SOC 2, HITRUST, PCI, or similar compliance frameworks
  • Demonstrated fluency with AI and LLM-powered tools, including practical experience incorporating them into day-to-day engineering workflows
  • Strong understanding of AI security concepts, including prompt injection, AI agent guardrails, data governance, PHI handling, and AI vendor risk
  • Builder mindset with a bias toward execution, ownership, and practical problem-solving.
  • Ownership mindset – own driving results for the mission, business, and customer experience
  • Strong collaboration skills with thought partners from engineering, product, and legal
  • Strong desire to work in an early stage startup environment that is fast paced, complex, and has minimal barriers to make decisions (no “red tape”)
  • Passion for helping individuals experiencing complex chronic needs such as homelessness, severe mental illness, and substance use disorder

Bonus Points for the following:

  • A consulting or advisory background
  • Experience as an early security hire at a startup, particularly as the first or early security engineer
  • Experience securing consumer-facing or patient-facing AI products and applications
  • Contributions to open-source security projects, security tooling, and/or published security research
  • CISSP, OSCP, AWS Security Specialty, or similar certifications

Our Values

  • Lead with integrity: We keep our commitments and take responsibility for our actions. We are dependable and choose authenticity over perfection.
  • Embrace challenges: We leave our egos at the door and step forward into discomfort instead of back into safety. We help each other to learn and provide feedback using candor and kindness.
  • Break through walls: We go the extra mile for our patients, partners and one another, and we run toward hard things. We are resilient in our push for consistent improvement and challenge the status quo.
  • Act beyond yourself: We build each other up and respect boundaries. We seek first to understand and assume positive intent.
  • Care comes first: We hold ourselves to the highest standards for our patients. We are relentless in the pursuit of our mission, and ensure that we are taking care of ourselves in order to care for others.

Because We Value You

  • Competitive salary: $170,000 - $190,000 (depending on experience)
  • Equity compensation package
  • Flexible vacation policy – take the time you need to recharge
  • Comprehensive medical, dental, and vision coverage
  • 401(k)
  • 100% company-sponsored short and long-term disability and life insurance
  • Subsidized backup childcare and caregiver supports through Wellthy
  • Work entirely from the comfort of your own home
  • Monthly $100 work from home expense stipend
  • We provide the equipment needed for the role
  • Opportunity for rapid career progression with plenty of room for personal growth!

Pair Team is an Equal Opportunity Employer. At Pair Team, we value diversity and strive to provide an inclusive environment for all applicants and employees. All applicants will be considered without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, marital status, age, disability, political affiliation, military service, genetic information, or any other characteristic covered by federal, state, or local law.

Pair Team participates in E-Verify to verify employment eligibility for new hires.

Any offer of employment at Pair Team is conditioned upon passing a pre-employment background check. Following a conditional job offer, candidates will undergo comprehensive employment background checks, including; criminal history, reference checks, and driving records if a role requires vehicle use.

We do not conduct any TA business outside of our @pairteam.com emails. If you’re ever concerned about spam or fraudulent activity, please reach out to recruiting@pairteam.com.

Note: Please be aware that while we sincerely appreciate your interest, due to the high volume of requests, we’re unable to respond to general position inquiries via email. To apply for a position with us, please submit your application for the role you are interested in. Our team regularly reviews applications and will reach out to candidates whose qualifications align with our current openings listed below. Thank you!

Read the full description
Security Senior Security Engineer at Pair Team

Implement security controls across healthcare applications, cloud infrastructure, AI systems, and compliance initiatives in a HIPAA-regulated environment.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Pair Team

Pair Team is building a new kind of healthcare system across Medicaid, Medicare, and public assistance programs: one that recognizes that access to housing, nutritious food, and reliable transportation are just as critical to health as having the right medications or seeing a doctor.

As a public benefit corporation and AI-enabled medical group, we partner with shelters, food pantries, and community organizations to deliver “whole-person” care to the 115 million Americans who rely on the safety net. We are currently the largest complex care provider in California with over 500 employees and are expanding nationally. Our model replaces fragmented healthcare and social services systems with one trusted relationship for all medical, behavioral, and social needs.  We improve access, build trust, and dramatically lower costs (52% fewer ER visits, 26% fewer hospitalizations). Our model is a rare combination of saving tax payer dollars ($150B annually at scale) while putting people on an upward life trajectory. At national scale, this approach would save taxpayers.

These outcomes are driven by the AI-first, whole-person infrastructure we are building — a platform that connects healthcare and social-service organizations into a unified network. Leveraging our vast data and years of operational experience, we are building the agentic infrastructure for the safety net to coordinate care, automate operations, and learn from every patient interaction to continuously improve outcomes.

Read more about the AI-First Medicaid System we are building here .

  • Forbes: For Pair Team, Accessibility Is About Delivering Healthcare To Those Who Need It The Most
  • TechCrunch: Building for Medicaid’s regulatory moment with Neil Batlivala from Pair Team
  • Journal of General Internal Medicine: A Novel Intervention for Medicaid Beneficiaries with Complex Needs

About the Opportunity

As a HIPAA-regulated, AI-native company, security is foundational to our ability to serve patients. As our platform, AI capabilities, and regulatory footprint continue to grow, we’re looking for our first dedicated Security Engineer to help scale our security posture alongside the business.

This is a highly hands-on engineering role. You’ll own the implementation of security controls across applications, cloud infrastructure, AI systems, and compliance-driven initiatives. You’ll help secure patient-facing voice agents, LLM-powered workflows, internal developer tooling, and a growing ecosystem of vendors and integrations. You’ll partner closely with Engineering and IT to remediate findings, improve our security foundations, and build systems that enable the company to move quickly and safely.

This role is ideal for someone who enjoys building—an engineer who wants to write code, automate workflows, strengthen infrastructure, and help shape security at a company using AI to improve healthcare access for underserved communities.

This is a fully remote position reporting up to the IT Lead.

What You’ll Do

  • Own vulnerability management, dependency security, threat modeling, security code reviews, and remediation of penetration test findings.
  • Strengthen our AWS security posture, identity and access management (IAM, SSO, SAML, SCIM), endpoint security, threat detection, and incident response capabilities.
  • Design and implement security controls for AI-powered products and workflows, including protections against prompt injection, data leakage, and other AI-specific risks.
  • Build technical safeguards that enable the secure use of PHI and sensitive data within LLM-powered systems.
  • Implement and maintain the technical controls, evidence, and security practices required to support HIPAA, SOC 2, and other compliance programs.
  • Leverage AI-powered tooling, automation, and modern security platforms to scale security impact across the organization.
  • Build self-service security solutions, paved roads, and runbooks that help engineers move quickly while maintaining strong security standards.
  • Partner closely with Engineering and IT to deliver pragmatic, scalable security solutions that support product velocity and business growth.
  • Be a force multiplier for the Pod-Infra team

What You’ll Need

  • 2+ years of Security Engineering experience, with significant depth in either application security or infrastructure/cloud security and working proficiency in the other
  • Strong AWS and cloud security expertise, including IAM, identity management (SSO, SAML, SCIM), network security, secrets management, and cloud-native security tooling
  • Hands-on software engineering experience with the ability to read, review, and ship production code in Python and/or TypeScript. Ruby experience is a plus
  • Experience implementing technical controls in regulated environments such as HIPAA, SOC 2, HITRUST, PCI, or similar compliance frameworks
  • Demonstrated fluency with AI and LLM-powered tools, including practical experience incorporating them into day-to-day engineering workflows
  • Strong understanding of AI security concepts, including prompt injection, AI agent guardrails, data governance, PHI handling, and AI vendor risk
  • Builder mindset with a bias toward execution, ownership, and practical problem-solving.
  • Ownership mindset – own driving results for the mission, business, and customer experience
  • Strong collaboration skills with thought partners from engineering, product, and legal
  • Strong desire to work in an early stage startup environment that is fast paced, complex, and has minimal barriers to make decisions (no “red tape”)
  • Passion for helping individuals experiencing complex chronic needs such as homelessness, severe mental illness, and substance use disorder

Bonus Points for the following:

  • A consulting or advisory background
  • Experience as an early security hire at a startup, particularly as the first or early security engineer
  • Experience securing consumer-facing or patient-facing AI products and applications
  • Contributions to open-source security projects, security tooling, and/or published security research
  • CISSP, OSCP, AWS Security Specialty, or similar certifications

Our Values

  • Lead with integrity: We keep our commitments and take responsibility for our actions. We are dependable and choose authenticity over perfection.
  • Embrace challenges: We leave our egos at the door and step forward into discomfort instead of back into safety. We help each other to learn and provide feedback using candor and kindness.
  • Break through walls: We go the extra mile for our patients, partners and one another, and we run toward hard things. We are resilient in our push for consistent improvement and challenge the status quo.
  • Act beyond yourself: We build each other up and respect boundaries. We seek first to understand and assume positive intent.
  • Care comes first: We hold ourselves to the highest standards for our patients. We are relentless in the pursuit of our mission, and ensure that we are taking care of ourselves in order to care for others.

Because We Value You

  • Competitive salary: $170,000 - $190,000 (depending on experience)
  • Equity compensation package
  • Flexible vacation policy – take the time you need to recharge
  • Comprehensive medical, dental, and vision coverage
  • 401(k)
  • 100% company-sponsored short and long-term disability and life insurance
  • Subsidized backup childcare and caregiver supports through Wellthy
  • Work entirely from the comfort of your own home
  • Monthly $100 work from home expense stipend
  • We provide the equipment needed for the role
  • Opportunity for rapid career progression with plenty of room for personal growth!

Pair Team is an Equal Opportunity Employer. At Pair Team, we value diversity and strive to provide an inclusive environment for all applicants and employees. All applicants will be considered without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, marital status, age, disability, political affiliation, military service, genetic information, or any other characteristic covered by federal, state, or local law.

Pair Team participates in E-Verify to verify employment eligibility for new hires.

Any offer of employment at Pair Team is conditioned upon passing a pre-employment background check. Following a conditional job offer, candidates will undergo comprehensive employment background checks, including; criminal history, reference checks, and driving records if a role requires vehicle use.

We do not conduct any TA business outside of our @pairteam.com emails. If you’re ever concerned about spam or fraudulent activity, please reach out to recruiting@pairteam.com.

Note: Please be aware that while we sincerely appreciate your interest, due to the high volume of requests, we’re unable to respond to general position inquiries via email. To apply for a position with us, please submit your application for the role you are interested in. Our team regularly reviews applications and will reach out to candidates whose qualifications align with our current openings listed below. Thank you!

Read the full description
Security Senior Security Engineer at Pair Team

Implements security controls across applications, cloud infrastructure, AI systems, and compliance initiatives for a healthcare AI platform.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Pair Team

Pair Team is building a new kind of healthcare system across Medicaid, Medicare, and public assistance programs: one that recognizes that access to housing, nutritious food, and reliable transportation are just as critical to health as having the right medications or seeing a doctor.

As a public benefit corporation and AI-enabled medical group, we partner with shelters, food pantries, and community organizations to deliver “whole-person” care to the 115 million Americans who rely on the safety net. We are currently the largest complex care provider in California with over 500 employees and are expanding nationally. Our model replaces fragmented healthcare and social services systems with one trusted relationship for all medical, behavioral, and social needs.  We improve access, build trust, and dramatically lower costs (52% fewer ER visits, 26% fewer hospitalizations). Our model is a rare combination of saving tax payer dollars ($150B annually at scale) while putting people on an upward life trajectory. At national scale, this approach would save taxpayers.

These outcomes are driven by the AI-first, whole-person infrastructure we are building — a platform that connects healthcare and social-service organizations into a unified network. Leveraging our vast data and years of operational experience, we are building the agentic infrastructure for the safety net to coordinate care, automate operations, and learn from every patient interaction to continuously improve outcomes.

Read more about the AI-First Medicaid System we are building here .

  • Forbes: For Pair Team, Accessibility Is About Delivering Healthcare To Those Who Need It The Most
  • TechCrunch: Building for Medicaid’s regulatory moment with Neil Batlivala from Pair Team
  • Journal of General Internal Medicine: A Novel Intervention for Medicaid Beneficiaries with Complex Needs

About the Opportunity

As a HIPAA-regulated, AI-native company, security is foundational to our ability to serve patients. As our platform, AI capabilities, and regulatory footprint continue to grow, we’re looking for our first dedicated Security Engineer to help scale our security posture alongside the business.

This is a highly hands-on engineering role. You’ll own the implementation of security controls across applications, cloud infrastructure, AI systems, and compliance-driven initiatives. You’ll help secure patient-facing voice agents, LLM-powered workflows, internal developer tooling, and a growing ecosystem of vendors and integrations. You’ll partner closely with Engineering and IT to remediate findings, improve our security foundations, and build systems that enable the company to move quickly and safely.

This role is ideal for someone who enjoys building—an engineer who wants to write code, automate workflows, strengthen infrastructure, and help shape security at a company using AI to improve healthcare access for underserved communities.

This is a fully remote position reporting up to the IT Lead.

What You’ll Do

  • Own vulnerability management, dependency security, threat modeling, security code reviews, and remediation of penetration test findings.
  • Strengthen our AWS security posture, identity and access management (IAM, SSO, SAML, SCIM), endpoint security, threat detection, and incident response capabilities.
  • Design and implement security controls for AI-powered products and workflows, including protections against prompt injection, data leakage, and other AI-specific risks.
  • Build technical safeguards that enable the secure use of PHI and sensitive data within LLM-powered systems.
  • Implement and maintain the technical controls, evidence, and security practices required to support HIPAA, SOC 2, and other compliance programs.
  • Leverage AI-powered tooling, automation, and modern security platforms to scale security impact across the organization.
  • Build self-service security solutions, paved roads, and runbooks that help engineers move quickly while maintaining strong security standards.
  • Partner closely with Engineering and IT to deliver pragmatic, scalable security solutions that support product velocity and business growth.
  • Be a force multiplier for the Pod-Infra team

What You’ll Need

  • 2+ years of Security Engineering experience, with significant depth in either application security or infrastructure/cloud security and working proficiency in the other
  • Strong AWS and cloud security expertise, including IAM, identity management (SSO, SAML, SCIM), network security, secrets management, and cloud-native security tooling
  • Hands-on software engineering experience with the ability to read, review, and ship production code in Python and/or TypeScript. Ruby experience is a plus
  • Experience implementing technical controls in regulated environments such as HIPAA, SOC 2, HITRUST, PCI, or similar compliance frameworks
  • Demonstrated fluency with AI and LLM-powered tools, including practical experience incorporating them into day-to-day engineering workflows
  • Strong understanding of AI security concepts, including prompt injection, AI agent guardrails, data governance, PHI handling, and AI vendor risk
  • Builder mindset with a bias toward execution, ownership, and practical problem-solving.
  • Ownership mindset – own driving results for the mission, business, and customer experience
  • Strong collaboration skills with thought partners from engineering, product, and legal
  • Strong desire to work in an early stage startup environment that is fast paced, complex, and has minimal barriers to make decisions (no “red tape”)
  • Passion for helping individuals experiencing complex chronic needs such as homelessness, severe mental illness, and substance use disorder

Bonus Points for the following:

  • A consulting or advisory background
  • Experience as an early security hire at a startup, particularly as the first or early security engineer
  • Experience securing consumer-facing or patient-facing AI products and applications
  • Contributions to open-source security projects, security tooling, and/or published security research
  • CISSP, OSCP, AWS Security Specialty, or similar certifications

Our Values

  • Lead with integrity: We keep our commitments and take responsibility for our actions. We are dependable and choose authenticity over perfection.
  • Embrace challenges: We leave our egos at the door and step forward into discomfort instead of back into safety. We help each other to learn and provide feedback using candor and kindness.
  • Break through walls: We go the extra mile for our patients, partners and one another, and we run toward hard things. We are resilient in our push for consistent improvement and challenge the status quo.
  • Act beyond yourself: We build each other up and respect boundaries. We seek first to understand and assume positive intent.
  • Care comes first: We hold ourselves to the highest standards for our patients. We are relentless in the pursuit of our mission, and ensure that we are taking care of ourselves in order to care for others.

Because We Value You

  • Competitive salary: $170,000 - $190,000 (depending on experience)
  • Equity compensation package
  • Flexible vacation policy – take the time you need to recharge
  • Comprehensive medical, dental, and vision coverage
  • 401(k)
  • 100% company-sponsored short and long-term disability and life insurance
  • Subsidized backup childcare and caregiver supports through Wellthy
  • Work entirely from the comfort of your own home
  • Monthly $100 work from home expense stipend
  • We provide the equipment needed for the role
  • Opportunity for rapid career progression with plenty of room for personal growth!

Pair Team is an Equal Opportunity Employer. At Pair Team, we value diversity and strive to provide an inclusive environment for all applicants and employees. All applicants will be considered without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, marital status, age, disability, political affiliation, military service, genetic information, or any other characteristic covered by federal, state, or local law.

Pair Team participates in E-Verify to verify employment eligibility for new hires.

Any offer of employment at Pair Team is conditioned upon passing a pre-employment background check. Following a conditional job offer, candidates will undergo comprehensive employment background checks, including; criminal history, reference checks, and driving records if a role requires vehicle use.

We do not conduct any TA business outside of our @pairteam.com emails. If you’re ever concerned about spam or fraudulent activity, please reach out to recruiting@pairteam.com.

Note: Please be aware that while we sincerely appreciate your interest, due to the high volume of requests, we’re unable to respond to general position inquiries via email. To apply for a position with us, please submit your application for the role you are interested in. Our team regularly reviews applications and will reach out to candidates whose qualifications align with our current openings listed below. Thank you!

Read the full description
Security Senior SecDevOps Engineer at Re:Build Manufacturing

Designs and operates secure, scalable cloud-native infrastructure, CI/CD pipelines, and observability systems for a hardware product development platform.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Re:Build

At Re:Build, our mission is to ensure the next generation of important products are made, at scale, in America. We are laying the foundation for a better future for our customers, employees, and communities by revitalizing America’s manufacturing base and creating meaningful jobs across the country, including in historically deindustrialized regions.

We operate an advanced, end-to-end manufacturing platform that partners with industrial companies and innovators to take products from first concept to full-scale production in critical verticals including aerospace and defense, electrification, medical, energy and environment, and robotics and automation.

The way we operate is as important as the work we do. It’s guided by The Re:Build Way, 16 principles that shape how we collaborate with each other, partner with our customers and vendors, and contribute to the communities where we operate. (link to The Re:Build Way principles )

The Opportunity

If you’ve worked alongside hardware teams, you know the damage that results from a missed change request or critical context that was never relayed to the right person. Reflow exists to close that gap. We’re building the first AI-powered platform purpose-built for hardware product development, one that listens across the tools teams already use, maintains a structured picture of every program, and proactively coordinates across disciplines when things inevitably change.

This is a ground-floor opportunity for a hands-on SecDevOps engineer to define the infrastructure, delivery pipelines, and operational foundation of a high-potential product with the support of a parent company leading innovation in engineering and manufacturing.

Who We’re Looking For

We’re seeking a SecDevOps engineer who cares deeply about building infrastructure that is reliable, secure, and scalable. The ideal candidate has designed and operated cloud-native production environments, has strong opinions on CI/CD pipeline design and infrastructure-as-code, and treats observability as a first-class concern. You should already be using AI coding tools like Cursor, Copilot, or Claude to accelerate your work, with excitement about supporting the platform that finally replaces the spreadsheets and status meetings that hardware teams have been stuck with for decades.

This senior engineer will work alongside our engineering team and head of product to build and maintain the infrastructure that powers our platform—including deployment pipelines, cloud environments, monitoring systems, and the operational tooling that keeps AI agents and real-time data flows running reliably at scale. The role is hands-on - you will be writing code and configuration daily while contributing to infrastructure architecture decisions and helping establish operational best practices as we scale.

What You’ll Do

Your day-to-day responsibilities will include:

  • Designing, building, and maintaining cloud infrastructure on GCP, AWS and third-party providers using Terraform
  • Building and optimizing CI/CD pipelines for rapid, reliable deployments across multiple services and environments
  • Implementing comprehensive observability—monitoring, logging, alerting, and distributed tracing—to ensure platform health and fast incident response
  • Establishing and enforcing security best practices including secrets management, network policies, vulnerability scanning, and compliance automation
  • Supporting AI/ML infrastructure including model serving and the data pipelines that power our ambient AI agents
  • Building developer experience tooling—local development environments, preview deployments, and self-service infrastructure provisioning
  • Collaborating with backend and frontend engineers to ensure seamless integration between application code and infrastructure

Technical Requirements

Must Have:

  • 5+ years of experience in SecDevOps, SRE, or platform engineering roles
  • Demonstrated proficiency using AI coding tools (Cursor, Copilot, Claude, etc.) to accelerate development
  • Expert-level experience with at least one major cloud provider (GCP preferred; AWS or Azure also accepted)
  • Strong proficiency with Terraform
  • Deep experience with Docker
  • Proven track record designing and maintaining CI/CD pipelines (GitHub Actions, GitLab CI, or similar)
  • Solid understanding of networking fundamentals, DNS, load balancing, and CDN configuration
  • Proficiency in Python for automation and tooling
  • Ability to balance rapid iteration with reliable, well-documented infrastructure

Highly Valuable:

  • Experience supporting AI/ML workloads in production (model serving, GPU scheduling, streaming inference)
  • Familiarity with database operations and optimization (PostgreSQL, Redis, or similar)
  • Background in observability platforms (Datadog, Grafana, Prometheus, OpenTelemetry)
  • Understanding of authentication/authorization infrastructure (OIDC, OAuth2, JWT, SSO)
  • Experience with cost optimization and FinOps practices in cloud environments
  • Background in B2B SaaS platforms, particularly multi-tenant architectures
  • Familiarity with SOC 2, FedRAMP, or ITAR compliance requirements relevant to hardware and defense industries

What We Offer

Real Impact: The opportunity to build purpose-built tooling for an entire industry that has never had it

Customer Access: Direct exposure to hundreds of real hardware projects annually through Re:Build’s engineering and manufacturing companies

Technical Growth: Hands-on work with cutting-edge AI technologies solving novel infrastructure challenges

Autonomy: Backed by Re:Build while operating with startup independence

Benefits: Full health/dental/vision, bonus program, generous 401K, paid time off, annual learning stipend

Equity & Growth: Participation in Re:Build’s LTIP equity program and opportunity for founder equity in potential spin-out

Compensation & Location

Location: Remote-first, with preference for candidates in Boston, Seattle, Los Angeles, or other cities with Re:Build offices

Compensation: The base salary range for this position is $165,000 – $200,000 per year. This range represents the Company’s good faith estimate of the base compensation for this role at the time of posting.  Actual compensation will be determined based on several factors, including but not limited to relevant experience, skills, qualifications, internal equity, and geographic location. In addition to base salary, this role may be eligible for annual incentive compensation and/or long-term incentives, subject to Company plans. The Company offers a comprehensive benefits package including medical, dental, vision, retirement, paid time off, and other benefits. Potential equity stake under independent spinout scenario.

Export Control Requirement: Due to applicable export control laws and regulations, candidates must be a U.S. citizen or national, U.S. permanent resident (i.e., current Green Card holder), or lawfully admitted into the U.S. as a refugee or granted asylum.

The BIG payoff

We are a company who is going to make a difference in the industries and the communities in which we choose to operate.  Every employee of Re:Build will share ownership in the company and will share in the financial rewards of the success we achieve together, at all levels of the company!

We want to work with people that reflect the communities in which we operate

Re:Build Manufacturing is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, marital status, parental status, cultural background, organizational level, work styles, tenure and life experiences. Or for any other reason.

Re:Build is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at accommodations.ta@ReBuildmanufacturing.com or you may call us at 617.909.6275.

Read the full description
Security Incident Response Senior Consultant

Responds to and manages security incidents, investigates threats, and implements remediation strategies for client organizations.

Senior Posted 3 days ago Himalayas
What this role involves
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations.
Read the full description
Security #61 - Arquitecto Sase

Designs and implements SASE/SSE security architectures for enterprise clients at a specialized infrastructure and cybersecurity consulting firm.

Senior Posted 4 days ago Himalayas
What this role involves
Overall del rolBuscamos un/a Arquitecto/a SASE/SSE con fuerte orientaciĂłn a cliente para incorporarse a consultora especialista en infraestructura, networking, cloud y ciberseguridad (partner de Cisco y Microsoft, reconocida como Cybersecurity Partner of the Year 2023 y Partner of the Year 2024).
Read the full description
Security Senior Cybersecurity Engineer / RMF Specialist at Dark Wolf Solutions

Leads security authorization processes, conducts risk assessments, and ensures NIST/DoD compliance for systems and applications.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Dark Wolf Solutions is seeking a Senior Cybersecurity Engineer / Risk Management Framework (RMF) Specialist to will lead and execute the security authorization process for our systems and applications in compliance with NIST guidelines and DoD regulations. This individual will be responsible for navigating the RMF lifecycle, developing security documentation, conducting risk assessments, and ensuring that our systems meet the highest standards of security and compliance. This position offers a critical opportunity for a motivated and detail-oriented security professional to leverage their RMF expertise, contribute to the protection of sensitive information, and play a vital role in securing our nation’s critical infrastructure.

Key Responsibilities:

  • Responsible for concentrating on overall technical and operational effectiveness of capabilities in coordination with the COTR and Sponsor Staff management.
  • Cyber Security teams are responsible for providing recommendations on continuous improvement of the processes and architectures supporting the overall Cyber Defense operational activities including, but not limited to: analysis, incident handling and reporting products, and the reporting lifecycle.
  • Ensures the effective operations of Agency IT systems and network defenses, providing effective incident response capabilities, usable and effective reports that address overall situational awareness.
  • This individual works to maximize the use of existing tools to correlate information and synthesize data into usable and actionable events.
  • Identifies and provides an agile approach to the automation of any manual and inefficient processes that exist across the cyber defense program and to work with the Sponsor to recommend and implement technical solutions designed to return time to mission.

Required Qualifications:

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related technical field
  • 8 years minimum of relevant experience
  • Experience in security risk assessment and management in cloud environments (GCP preferred)
  • Experience building authorization packages
  • US Citizenship required with an active Secret clearance or interim Secret clearance

This role is primarily remote. The compensation for this role is estimated to be between $150,000-$170,000, commensurate on experience.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire.

Read the full description
Security Sr. Information Security Manager at LawPay

Leads a technical security team, manages security operations platforms, drives incident response and compliance programs, and operationalizes security capabilities aligned with business priorities.

Senior Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

As we evolve our security posture to meet growth and regulatory expectations, we are seeking a transformational Senior Information Security Manager to lead our technical security team and operationalize security capabilities that are measurable, effective, and aligned with business priorities. This is a hands-on leadership role: you will lead the day-to-day execution of the security program and directly manage the security engineering and analyst team, while partnering closely with the U.S.-based VP of Information Security and the compliance and privacy operations team.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • Team leadership: Lead and develop the security engineering/analyst team — delivery, prioritization, coaching, performance
  • Security operations: Own security platforms (EDR, SIEM, compliance automation, vulnerability management, CSPM) and detection/response workflows
  • Metrics & reporting: Own security metrics pipeline (remediation velocity, control assurance, coverage) for quarterly business reviews
  • AI security: Drive AI adoption in tooling for better detection, and define/enforce security standards for AI/agentic systems (LLM integrations, orchestration, governance)
  • Incident & compliance leadership: Lead incident response (EU hours, US coordination), post-incident reviews, and partner on compliance audits (SOC 2, PCI DSS, EU regs)
  • Security design reviews: Lead design reviews across product lines with risk ratings, SLAs, and documented standards
  • Threat intel & detection engineering: Monitor relevant threat intel and convert into actionable detections
  • Fraud/attack investigation: Partner cross-functionally to investigate attacks (card testing, fraud, abuse), turning findings into detections and hardening recommendations

About you:

  • 7+ years in information security, including 2+ years leading technical security staff.

  • Hands-on depth in cloud security operations (AWS preferred), SIEM/log analytics, EDR platforms, and vulnerability management programs.

  • Track record of building measurable, metrics-driven security programs in a compliance-heavy environment (PCI DSS, SOC 2, or equivalent).

  • Experience operating in distributed, cross-timezone teams; excellent written communication.

  • Fluent professional English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience securing or governing AI/LLM systems and agentic tooling.
  • Familiarity with EU regulatory landscape (GDPR) and fintech or legal-tech domains.

Additional Information

The monthly gross salary range for this position is CZK 95,000 to CZK 175,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Senior Security Engineer, Product Security at GoodLeap

Senior security engineer who reviews product designs and code, builds security services, and adversarially tests AI/LLM systems to ensure safe product launches.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

About GoodLeap:

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.

GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.

GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.

GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch” is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.

Essential Job Duties and Responsibilities

  • Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
  • Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
  • Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
  • Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
  • Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
  • Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
  • Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
  • Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
  • Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
  • Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
  • Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.

Required Skills, Knowledge, and Abilities

  • You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, HTTP APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your rĂ©sumĂ©.
  • You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
  • You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
  • You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
  • Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
  • Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
  • Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
  • Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
  • You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.

Preferred:

  • Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
  • Running structured vendor evaluations or proofs of concept
  • Contributing to security policy or standards, including for AI systems
  • Delivering security training or building hands-on learning environments
  • Depth in cryptography and key management
  • Detection engineering, incident response, or threat hunting exposure
  • An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.

$146,000 - $185,000 a year

In addition to the above salary, this role may be eligible for a bonus.

Additional Information Regarding Job Duties and Job Descriptions:

Job duties include additional responsibilities as assigned by one’s supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.

If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you!  Apply today!

We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer, Product Security at GoodLeap

Senior Product Security Engineer who partners with product and engineering teams to build secure systems, review designs and code for vulnerabilities, and adversarially test AI/LLM features in a consumer finance platform.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

About GoodLeap:

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.

GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.

GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.

GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch” is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.

Essential Job Duties and Responsibilities

  • Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
  • Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
  • Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
  • Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
  • Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
  • Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
  • Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
  • Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
  • Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
  • Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
  • Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.

Required Skills, Knowledge, and Abilities

  • You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, HTTP APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your rĂ©sumĂ©.
  • You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
  • You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
  • You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
  • Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
  • Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
  • Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
  • Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
  • You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.

Preferred:

  • Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
  • Running structured vendor evaluations or proofs of concept
  • Contributing to security policy or standards, including for AI systems
  • Delivering security training or building hands-on learning environments
  • Depth in cryptography and key management
  • Detection engineering, incident response, or threat hunting exposure
  • An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.

$146,000 - $185,000 a year

In addition to the above salary, this role may be eligible for a bonus.

Additional Information Regarding Job Duties and Job Descriptions:

Job duties include additional responsibilities as assigned by one’s supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.

If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you!  Apply today!

We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer, Product Security at GoodLeap

Senior Security Engineer partners with product teams to build secure systems, review designs and code, and adversarially test AI/LLM features in a consumer-finance platform.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

About GoodLeap:

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $30 billion in financing for sustainable solutions since 2018.

GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.

GoodLeap’s security team safeguards the organization’s information assets while enabling the business — spanning product safety and resilience, security paved roads, customer and regulatory trust, and technology governance. As a Senior Product Security Engineer, you’ll partner with product and engineering teams to make what we ship safe by default, splitting your time between building production security services and reviewing what other teams build: designs before code exists, pull requests before merge, and running systems before someone else finds the problem. You’ll be the primary security partner for one or more business units — GRC, security operations, and monitoring carry their own parts of the mandate, but you own the product security outcome.

GoodLeap builds in TypeScript, Node.js, .NET, and Python, and you’ll work across all of it — we care that you can move between stacks, not that you’ve spent your career in one. We’re also shipping LLM-backed and agentic features into a regulated consumer-finance product; adversarially testing those systems (prompt injection, jailbreaks, tool abuse, exfiltration) and helping define what’s “safe enough to launch” is core to this role. You don’t need years of AI security experience — you need to show you can take an unfamiliar system, reason about how it fails, and produce findings a product team will act on.

Essential Job Duties and Responsibilities

  • Adversarially test our AI and LLM-backed features. Design and run attacks against LLM-backed applications and agents — prompt injection, jailbreaks, tool abuse, data exfiltration — and turn findings into pass/fail criteria product teams will act on.
  • Build and operate production security services. Backend services and internal tooling — APIs, streaming transports, proxy/CLI/chat interfaces — in whichever of TypeScript, Node.js, .NET, or Python fits the problem, held to the same bar as any other production service: test coverage, CI, dependency management.
  • Find new ways to automate the work. Notice when something we do by hand has become automatable, prototype it, and make the case— even when it means replacing a tool we bought last year.
  • Review pull request vulnerability findings. Triage what scanning and AI-assisted review surface across our stacks, separating real findings from noise. Go deep by hand on auth paths and high-risk changes, and feed what you learn back into the tooling.
  • Threat model from product designs. Review PRDs and technical designs before code exists, infer trust boundaries and data flows in unfamiliar domains, and raise security questions while the design is still cheap to change.
  • Test by hand and validate what you find. Manual testing of web applications and APIs, triage for real exploitability, and retest fixes. Support the red team’s bug bounty and continuous penetration testing programs.
  • Keep the AppSec tooling estate running and low-friction. SAST/dependency scanning tuning, finding triage and routing, SSO and access management, and automating the repetitive parts so the program scales without headcount.
  • Secure the infrastructure your tooling runs on. IAM least-privilege scoping, secrets management, and container/network lifecycle — as infrastructure as code, with automated drift checks.
  • Enable engineers to do the right thing. Build security training and documentation engineers will actually use.
  • Evaluate tools and help set the AI bar. Run structured bake-offs of security products against defined requirements and help set the standards AI/agent systems must satisfy before reaching production.
  • Back up the rest of the security team. Support investigations, threat hunting, and incident response for the products you cover, and contribute to the vulnerability management lifecycle and security analytics platform.

Required Skills, Knowledge, and Abilities

  • You ship production code. Strong backend engineering in at least one modern language, with at least one service you built that others depend on — async patterns, HTTP APIs, and streaming transports are familiar ground. We work across TypeScript, Node.js, .NET, and Python; depth in one plus the willingness to move between them matters more than any particular stack on your rĂ©sumĂ©.
  • You can read code you didn’t write, across more than one language and stack, well enough to judge whether a reported finding is real, catch the ones tooling missed, and propose a fix the engineer can act on.
  • You know how identity and authorization actually fail: token exchange and scope handling, session lifetime and revocation, request signing, OAuth pitfalls, and network-layer issues like SSRF and DNS rebinding. We’re looking for reasoning that finds real bugs, not checklist recall.
  • You understand API standards and how to secure them: REST and GraphQL in practice, OpenAPI and schema contracts, input validation, rate limiting, gateway-level auth, and webhook and service-to-service verification.
  • Hands-on testing of web applications and APIs — manual, not just scanner-driven — plus the triage, the clear write-up, and the retest.
  • Threat modeling from written designs. You can read a PRD in an unfamiliar domain, infer trust boundaries and data flows, and ask the right questions while the answer is still cheap.
  • Working AWS and infrastructure-as-code competence: IAM scoping, secrets management, container/compute lifecycle, network egress control, and infrastructure defined as code.
  • Practical exposure to AI/LLM security. You have attacked an LLM-backed application or agent — at work, in a CTF, in published research, or in your own lab — and can tell us what you found and why it worked.
  • You write and speak for people who are not in security. Findings engineers act on, documentation they use, and explanations that hold up in front of a product manager, an executive, or Legal.

Preferred:

  • Having owned an AppSec tooling estate: SAST/SCA tuning, finding routing, false-positive reduction
  • Running structured vendor evaluations or proofs of concept
  • Contributing to security policy or standards, including for AI systems
  • Delivering security training or building hands-on learning environments
  • Depth in cryptography and key management
  • Detection engineering, incident response, or threat hunting exposure
  • An understanding of how SaaS products get built — roadmaps, prioritization, why the ship date exists. Prior product or engineering management experience is a plus, not an expectation.

$146,000 - $185,000 a year

In addition to the above salary, this role may be eligible for a bonus.

Additional Information Regarding Job Duties and Job Descriptions:

Job duties include additional responsibilities as assigned by one’s supervisor or other managers related to the position/department. This job description is meant to describe the general nature and level of work being performed; it is not intended to be construed as an exhaustive list of all responsibilities, duties and other skills required for the position. The Company reserves the right at any time with or without notice to alter or change job responsibilities, reassign or transfer job position or assign additional job responsibilities, subject to applicable law. The Company shall provide reasonable accommodations of known disabilities to enable a qualified applicant or employee to apply for employment, perform the essential functions of the job, or enjoy the benefits and privileges of employment as required by the law.

If you are an extraordinary professional who thrives in a collaborative work culture and values a rewarding career, then we want to work with you!  Apply today!

We are committed to protecting your privacy. To learn more about how we collect, use, and safeguard your personal information during the application process, please review our Employment Privacy Policy and Recruiting Policy on AI.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security XTN-254B552 | SENIOR IT INTERNAL AUDIT

Conducts internal IT audits and compliance reviews for a satellite Earth observation company's systems and operations.

Senior Posted 6 days ago Himalayas
What this role involves
About the ClientOur client is a global Earth observation company that operates one of the world's largest fleets of satellites, providing daily imagery and data that help organizations make informed decisions about our planet.
Read the full description
Security Sr. Crowdstrike Engineer (R-00220) at True Zero Technologies

Deploys, manages, and optimizes CrowdStrike security platform for enterprise customers while providing operational support and cybersecurity advisory services.

Senior Posted 8 days ago RemoteFirstJobs Product
What this role involves

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

Job Description

As the Crowdstrike Engineer you will possess solid industry experience, certifications, with proven experience planning, deployment, field and operational support of the CrowdStrike platform and related applications and solutions in a distributed and complex enterprise.   The Sr. Crowdstrike Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation, optimization/utility and follow-on customer support for the CrowdStrike platform and applications. You will also be involved in customer advisement regarding best practices and identifying areas to add value to their cybersecurity and cyber-adjacent solution deployments.  This role has the potential to develop into a practice lead of a product or capability focused practice.

Qualifications

  • 3+years of implementing, managing, and expanding Crowdstrike and related use cases for customers in a variety of public sector and commercial customers.
  • Bachelor’s degree in Computer Science, Information Technology, Computer Engineering, or related discipline, and 5 years of experience performing IT deployments or in an end user/customer environment
  • Deep understanding of software deployment technologies, and understanding of security operations, practices, and methodologies
  • Highly knowledgeable on Windows, Mac, and Linux platforms
  • Working knowledge of Microsoft Office applications, Word, Excel, Access, PowerPoint, etc.
  • Good communication and collaboration skills
  • Solid analytical/problem solving skills with capability to identify solutions to unusual and complex problems
  • High level of motivation; self-starter; results driven
  • Ability to travel as needed on-site to customers

Additional skills and experience that are highly valued

  • Serve as primary engineering resource responsible for end-to-end integration and operational optimization.
  • Strong background in Crowdstrike Falcon, EDR, ITP, and various other related modules
  • Directly support and mature SOC capibilities
  • Experience deploying and operating prominent enterprise EDR platforms such as Tanium, FireEye HX, Cylance, Carbon Black, Microsoft Defender, and SentinelOne in large and complex environments
  • Knowledge of cloud platforms and technologies, such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)
  • Ability to gain secret clearance if needed

Responsibilities

  •  Provide technical implementation, configuration, and troubleshooting assistance with the deployment of the CrowdStrike platform and associated applications
  • Install CrowdStrike software both remotely and physically
  • Utilize and engineer native and 3rd party software deployment technologies
  • Develop scripts and processes around software deployment
  • Plan and report software deployment status
  • Work closely and collaboratively with customer information technology teams
  • Leveraging CrowdStrike applications (for example, but not limited to, Spotlight and Discover) provide support to customers in vulnerability and asset management
  • Assist customers with the integration of CrowdStrike into existing tools
  • Troubleshoot customer deployment issues across small to large enterprises
  • Establish roadmap and iterative improvement of endpoint detection capabilities and tooling integrations and use of Crowdstrike with maturity model approach
  • Identify opportunities to expand Crowdstrike and other tools to reduce security related enterprise risk
  • Create, enhance, and continuously update documentation and knowledge base (e.g., user guides, quick starts, documentation, demos)
  • Interview additional candidates applying to True Zero Technologies

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Compliance Engineer - Public Sector at Wiz

Develops security engineering processes and infrastructure-as-code solutions to ensure FedRAMP and NIST compliance for government cloud environments.

Senior Posted 8 days ago RemoteFirstJobs Product
What this role involves

Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we’re now powered by Google, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.

Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!

Minimum qualifications

  • 6+ years of experience in security engineering, DevOps, and systems engineering, with a proven ability developing processes and writing code to solve security/compliance problems.

  • 4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, with a proven ability to assess risk, reduce risk, and build engineering solutions that enable compliance.

  • Deep understanding of the differences between FR 20x and CR26 ruleset for Rev5 authorizations and the impacts these rule changes have on Cloud Service Providers (CSPs).

  • Experience working in a cloud-native environment with DevSecOps technologies, specifically including CI/CD, Containers, and Kubernetes.

  • Strong proficiency in scripting and Infrastructure as Code (IaC), with specific requirements for Shell Scripting, Python, Terraform or OpenTofu, and Preferred AI Harness (Claude Code, OpenAI Codex).

  • Experience with cloud platforms in government spaces.

Preferred qualifications

  • Experience with AWS GovCloud.

  • Experience in Azure Government, Google Cloud for Government (Assured Workloads), or equivalent and associated security services.

  • Experience with DevSecOps technologies including Microservices, GitOps, and Observability / Logging / SIEM / Platforms.

  • Experience with Packer, other Configuration as Code tools, and Policy as Code tools.

  • Experience automating compliance validation using cloud-native tools.

About the job

The Public Sector Compliance Operations Team aims to accelerate Wiz’s growth by developing a comprehensive strategy, in tight partnership with all other organizations, to drive customer value and adoption. As we continue to grow at an incredible speed, we work to ensure each sales team member is set up for success at every phase. We take both a bird’s eye view and dive into the weeds to solve problems as a team to drive employee success and revenue.

We are seeking an experienced Compliance Engineer to serve as the strategic technical lead for Wiz’s FedRAMP CR26 initiative. You will define the long-term technical roadmap by architecting comprehensive compliance-as-code solutions, utilizing both Wiz’s native features and custom-developed automations outside the platform to efficiently address CR26 Class D rule changes. This individual contributor role bridges complex regulatory requirements with scalable engineering practices, ensuring our cloud services meet stringent federal and defense standards while maintaining high availability, security, and audit-readiness.

You will be asked to quickly learn the challenges of the business and find ways to simplify processes within our compliance operations to increase productivity and efficiency. More importantly, the role requires a personality that promotes collaboration and unity.

Responsibilities

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to an automated, real-time telemetry model.

  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.

  • Engineer evidence generation frameworks, significantly reducing manual effort required for 3PAO assessments and automating compliance validation for control implementation verification.

  • Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments.

  • Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).

  • Collaborate cross-functionally with legal, product, engineering, devops, architecture, security, and federal customer teams to scope technical compliance verification and validation requirements for new features and services.

  • Mentor others on FedRAMP/DoW compliance best practices and contribute to internal training programs.

Candidates must meet EAR part 772 and ITAR 120.15 definition of a U.S. person (Any individual who is granted U.S. citizenship; or any individual who is granted U.S. permanent residence (green card holder); or any individual who is granted status as a “protected person”) and that they reside in the contiguous United States.

Compensation + Benefits

Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

The US base salary range for this full-time position is listed below.

US Base Pay Range

$174,000—$238,000 USD

Applicants must have the legal right to work in the country where the position is based, without the need forvisa sponsorship.This role does not offervisasponsorship.

Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz’s Privacy Policy.

Read the full description
Security Sr. Crowdstrike Engineer (R-00220) at True Zero Technologies

Designs, deploys, and manages CrowdStrike security platform implementations for enterprise customers while providing technical guidance on cybersecurity best practices.

Senior Posted 8 days ago RemoteFirstJobs Product
What this role involves

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

Job Description

As the Crowdstrike Engineer you will possess solid industry experience, certifications, with proven experience planning, deployment, field and operational support of the CrowdStrike platform and related applications and solutions in a distributed and complex enterprise.   The Sr. Crowdstrike Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation, optimization/utility and follow-on customer support for the CrowdStrike platform and applications. You will also be involved in customer advisement regarding best practices and identifying areas to add value to their cybersecurity and cyber-adjacent solution deployments.  This role has the potential to develop into a practice lead of a product or capability focused practice.

Qualifications

  • 3+years of implementing, managing, and expanding Crowdstrike and related use cases for customers in a variety of public sector and commercial customers.
  • Bachelor’s degree in Computer Science, Information Technology, Computer Engineering, or related discipline, and 5 years of experience performing IT deployments or in an end user/customer environment
  • Deep understanding of software deployment technologies, and understanding of security operations, practices, and methodologies
  • Highly knowledgeable on Windows, Mac, and Linux platforms
  • Working knowledge of Microsoft Office applications, Word, Excel, Access, PowerPoint, etc.
  • Good communication and collaboration skills
  • Solid analytical/problem solving skills with capability to identify solutions to unusual and complex problems
  • High level of motivation; self-starter; results driven
  • Ability to travel as needed on-site to customers

Additional skills and experience that are highly valued

  • Serve as primary engineering resource responsible for end-to-end integration and operational optimization.
  • Strong background in Crowdstrike Falcon, EDR, ITP, and various other related modules
  • Directly support and mature SOC capibilities
  • Experience deploying and operating prominent enterprise EDR platforms such as Tanium, FireEye HX, Cylance, Carbon Black, Microsoft Defender, and SentinelOne in large and complex environments
  • Knowledge of cloud platforms and technologies, such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)
  • Ability to gain secret clearance if needed

Responsibilities

  •  Provide technical implementation, configuration, and troubleshooting assistance with the deployment of the CrowdStrike platform and associated applications
  • Install CrowdStrike software both remotely and physically
  • Utilize and engineer native and 3rd party software deployment technologies
  • Develop scripts and processes around software deployment
  • Plan and report software deployment status
  • Work closely and collaboratively with customer information technology teams
  • Leveraging CrowdStrike applications (for example, but not limited to, Spotlight and Discover) provide support to customers in vulnerability and asset management
  • Assist customers with the integration of CrowdStrike into existing tools
  • Troubleshoot customer deployment issues across small to large enterprises
  • Establish roadmap and iterative improvement of endpoint detection capabilities and tooling integrations and use of Crowdstrike with maturity model approach
  • Identify opportunities to expand Crowdstrike and other tools to reduce security related enterprise risk
  • Create, enhance, and continuously update documentation and knowledge base (e.g., user guides, quick starts, documentation, demos)
  • Interview additional candidates applying to True Zero Technologies

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Lead threat assessment and case management for a region, conducting behavioral threat evaluations and coordinating security response across organizational stakeholders.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Australia

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$200,900—$200,900 AUD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases for employees and facilities, conducts behavioral threat analysis, and coordinates security incident response across regional operations.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - EMEA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):£95,490—£106,100 GBP
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-1

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases end-to-end, conducts behavioral threat assessments, coordinates incident response, and partners cross-functionally to mitigate security risks to employees, executives, and facilities.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Singapore

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$212,200—$212,200 SGD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-2

Read the full description
Security Stripe: Risk Strategist - Screening (Financial Crimes)

Develops and manages global financial crimes screening programs, setting standards for AML/sanctions controls and driving risk management strategy across Stripe's payment infrastructure.

Senior Remote Posted 15 days ago We Work Remotely — Programming
What this role involves

Headquarters: US-Chicago; US-Atlanta; US-Remote; Canada-Toronto; Canada-Remote

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Financial Crimes Risk Strategy team owns our first-line AML and sanctions programs globally. We own the end-to-end lifecycle of financial crime controls. We set the global standards that govern how risk is managed across our programs, design and drive the development of controls, infrastructure, and tooling with Engineering, Product, and Data Science, and maintain their effectiveness as our products and the regulatory landscape evolve. We build fast, with data, and with AI integrated into how financial crime risk is detected, managed, and monitored across everything Stripe builds.

What you'll do

As a Risk Strategist on the Financial Crimes Risk Strategy team, you'll own our global screening programs — spanning sanctions, PEP, and negative news — setting the standards that govern how screening risk is managed, designing and driving the controls that operationalize those standards, and ensuring they remain effective as our products and the regulatory landscape evolve. Being effective in this role means going deep on both the domain and the data — we don't separate the two.

You'll partner closely with Product, Engineering, Data Science, Compliance, Legal, other Risk Strategy functions, and Operations to ensure screening considerations are embedded in every product and market decision. Beyond protecting against risk, you'll drive innovation in how Stripe approaches screening — staying ahead of regulatory change and pushing the boundaries of what effective, scalable financial crime risk management looks like at a global payments company.

Responsibilities

  • Lead our global sanctions and AML screening strategy — setting the standards that drive screening control design and infrastructure development, and translating requirements across OFAC, EU, UN, OFSI, and other applicable regimes, PEP screening, and negative news screening into actionable first-line programs and controls
  • Own the design and ongoing improvement of financial crime controls — including sanctions screening, PEP screening, negative news screening, and digital asset-related safeguards — while continuously improving detection coverage and control performance as our products and the threat landscape evolve
  • Embed screening risk requirements into product and infrastructure roadmaps — ensuring financial crime considerations drive product launches, market expansions, and platform decisions across Product, Engineering, Data Science, Compliance, Legal, and Operations
  • Drive screening infrastructure and tooling forward by owning requirements, leading execution, and maintaining effectiveness metrics for screening systems and controls — building with observability by design and ensuring key performance indicators, key risk indicators, and monitoring thresholds are defined from inception
  • Continuously assess and improve screening controls and systems — identifying gaps, recommending enhancements that strengthen detection effectiveness and anticipate regulatory or ecosystem changes, and leading delivery of those enhancements end-to-end
  • Champion a technology-forward approach to financial crime risk management — leveraging AI tools, self-serve data analytics, and model governance best practices to improve how risk is detected, monitored, and managed at Stripe
  • Stay informed on industry practices and regulatory developments and represent our sanctions and AML programs to regulators, bank and network partners, and external auditors

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 7+ years of professional experience in financial services, payments, or fintech, with at least 5 years in a related role (risk, compliance, or product enablement)
  • Deep subject matter expertise in global sanctions compliance, including hands-on experience with OFAC, EU sanctions regimes, UN Security Council designations, OFSI, and other major global frameworks
  • Demonstrated strong understanding of screening program design and control execution
  • Strong AML screening expertise — proven ability to design, implement, and operationalize PEP screening and negative news screening programs in complex, multi-jurisdiction environments
  • Proven ability to design, implement, and operationalize financial crime standards and controls in complex, global organizations
  • Familiarity with model governance concepts — including model documentation, performance monitoring, and validation — and experience leading or contributing to model governance activities

Preferred qualifications

  • Experience leading transformative AML, Sanctions, or Transaction Monitoring initiatives, including global screening program design or transformations (e.g., vendor selection, watchlist management, false positive tuning)
  • Proficiency with SQL and ability to independently mine and analyze data to develop risk insights and inform strategy
  • Experience with crypto or digital asset products and their associated financial crime risk and regulatory considerations
  • Advanced degree or professional certifications (e.g., CAMS, CGSS, CFCS)

To apply: https://weworkremotely.com/remote-jobs/stripe-risk-strategist-screening-financial-crimes

Read the full description