Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer leads application security, vulnerability management, and detection engineering across a global wellness platform, embedding security practices into product development.

Senior Remote Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer drives application security, vulnerability management, and detection engineering across a global wellness platform, embedding security into product development and owning security controls end-to-end.

Senior Remote Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Staff Security Engineer | AppSec at Gympass

Staff Security Engineer leads application security initiatives across multiple domains including vulnerability management, threat modeling, pentesting, and incident response.

Lead Remote Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Staff Security Engineer | AppSec to our Information Security team in Brazil! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our subscription-based product serving millions of users globally. As a Staff Security Engineer, you will own multiple security domains end-to-end — with your center of gravity in software security (secure SDLC, vulnerability management, threat modeling, pentesting, and red teaming) while reaching across incident response, threat intelligence, cloud security, and compliance as the team’s mandate requires.

You will become the organization’s go-to authority for the hardest, cross-domain security trade-offs — the ones without an obvious owner. By connecting pentest findings, incident root causes, compliance requirements, and cloud misconfigurations into a unified risk strategy, you will shape baseline security standards, mentor engineering teams, and drive medium-to-large strategic initiatives that scale with our growth.

YOUR IMPACT

  • Own multiple security domains end-to-end, serving as the technical authority for complex, cross-service security challenges across the entire organization.
  • Establish secure-by-design architectural standards, lead threat modeling sessions, and set the secure-coding benchmarks that other engineers follow.
  • Drive complex, cross-service incident responses and post-mortems, converting critical findings into systemic guardrails and platform-level preventions.
  • Lead offensive and defensive strategy initiatives—including Red Team exercises and pentest engagements—driving root-cause remediation directly with engineering teams.
  • Ensure organization-wide security posture by setting SLAs, SLOs, and KPIs (remediation windows, response times, posture drift), building the monitoring needed to hold teams accountable.
  • Partner with cross-functional leadership (Engineering, Product, Legal) to align threat intelligence, compliance needs, and long-term security investments with business priorities.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life wellness.

WHO YOU ARE

  • A seasoned security specialist with extensive experience in Security Engineering (or software engineering with high security impact) and a proven track record of scaling security in complex cloud environments.
  • An adaptable professional with a willingness to step outside your primary focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A strategic technical partner with expert knowledge in secure architecture design, threat modeling, and setting engineering-wide secure coding standards.
  • An influential communicator with fluency in English and Portuguese, able to translate intricate security tradeoffs into clear risk statements for executive leadership and product partners.
  • A pragmatic risk navigator with the ability to balance long-term risk reduction against business velocity, making high-stakes decisions independently.
  • A forward-thinking specialist with a deep understanding of attacker TTPs, modern cloud ecosystems (AWS/EKS, GCP/GKE, Istio, ArgoCD), and regulatory frameworks (SOC 2, ISO 27001, LGPD, GDPR).
  • A dedicated mentor with prior work experience guiding and uplifting engineering teams to foster a security-minded engineering culture.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement.

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

Want to see what it’s really like to work here? Follow us on Instagram @lifeatwellhub and watch our team video on YouTube !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Senior Security Engineer, Security Incident Response Team (SIRT) – EMEA

Responds to and investigates security incidents, manages incident response workflows, and leads security investigations for the EMEA region.

Senior Remote Posted 1 day ago Jobicy AI
What this role involves
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50...
Read the full description
Security Workforce Identity and Access Management (WIAM) Manager

Leads a global cybersecurity team managing workforce identity and access governance, products, service delivery, and risk reduction.

Lead Remote Posted 3 days ago Himalayas
What this role involves
Workforce Identity and Access Management (WIAM) Manager Wilmington, DEMonday – Friday 8:00 – 5:00 EDT + On-CallRemoteAs a Workforce Identity and Access Management (WIAM) Manager within Enterprise Technology (ET), you will lead a global cybersecurity team responsible for WIAM governance, products, service delivery, audit readiness, risk reduction, user experience, and alignment with cyber security, technology, and business priorities.
Read the full description
Security Senior Engineering Manager, Security & IT at Fingerprint

Senior manager unifies security, IT operations, and compliance functions, leading a team of 4 while establishing strategic security posture for enterprise fraud detection platform.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Fingerprint empowers developers to stop online fraud at the source.

We work on turning radical new ideas in the fraud detection space into reality. Our products are developer-focused and our clients range from solo developers to publicly traded companies. We are a globally dispersed, 100% remote company with a strong open-source focus. Our flagship open-source project is FingerprintJS (27K stars on GitHub).

We have raised $77M and are backed by Craft Ventures (previously invested in Tesla, Facebook, Airbnb ), Nexus Venture Partners (previously invested in Postman, Apollo.io, MinIO, Druva) and Uncorrelated Ventures (previously invested in Redis, Rollbar & Gradle).

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates’ personal and financial information through fake interviews and offers. All Fingerprint recruiting email communications will always come from the @fingerprint.com domain. Any outreach claiming to be from Fingerprint via other sources should be ignored.

The Role in Context

Fingerprint’s security, IT, and compliance function is more mature than most companies of this size: SOC 2 Type 2 + HIPAA achieved, a comprehensive policy suite in place, and solid IT operations running globally. What the function now needs is strategic leadership: someone who can unify security posture, IT operations, and compliance under a coherent strategy, mature each discipline to the next level, and be the credible voice of security and compliance to the rest of the engineering org and to enterprise customers.

We’re looking for a Senior Manager, Security & IT to own this function end-to-end, reporting directly to the VP of Engineering. You will manage 4 people across three disciplines: application security, IT operations, and compliance.

This is a VP-direct role with high autonomy and high visibility. Enterprise customers — many of whom are financial institutions and large-scale fraud prevention operators — regularly ask about Fingerprint’s security posture. You’ll be the person who owns that answer.

Your Mission

  • Unify and mature the function — Security, IT, and compliance have operated as separate workstreams. You create a coherent strategy across all three, with shared standards, shared risk language, and a roadmap that scales with the business
  • Own the security posture — Application security, zero-trust principles, vulnerability management, and security-by-default practices across the engineering org — you set the standard, you hold it, and you work across teams to embed it
  • Scale the compliance program — The next horizon is expanding scope, maturing evidence collection, and positioning Fingerprint for compliance requirements as enterprise deals grow
  • Run reliable IT operations — 100% remote, globally distributed engineering org. IT operations is a critical function that serves every Fingerprint employee. You own the tooling, the processes, and the reliability of those systems
  • Be the security voice to customers and leadership — Enterprise customers, prospects, and partners regularly evaluate Fingerprint’s security posture. You represent it credibly, own the security questionnaire process, and communicate risk and posture to the VP and leadership team

What You’ll Do

Security Strategy & Application Security

  • Define and own Fingerprint’s application security roadmap: vulnerability management, penetration testing program, security review process for new features and architectural changes
  • Build security-by-default practices into engineering workflows — not as a gate, but as a capability every engineering team has
  • Own the vendor security assessment process — Fingerprint handles sensitive customer data for major enterprise customers; you ensure third parties meet the bar
  • Define zero-trust security principles and ensure they’re embedded in the Cloud Platform and engineering org

Compliance & GRC

  • Own the SOC 2 Type 2 annual audit cycle — evidence collection, auditor management, control maturation
  • Drive the roadmap for compliance expansion: evaluate and prioritize future frameworks (ISO 27001, GDPR, customer-specific requirements from enterprise deals)
  • Manage the Compliance Lead — support their growth while giving them the leadership context that makes their technical compliance work more impactful
  • Be the compliance voice in enterprise sales cycles — security questionnaires, customer due diligence calls, contractual security requirements
  • Own the policy framework: ensure Fingerprint’s policy suite (already well-established) stays current, complete, and actually embedded in how teams work

IT Operations

  • Manage the Lead IT Engineer — they run day-to-day IT operations for a globally distributed engineering org; your job is to give them strategic direction and organizational context
  • Own IT strategy: tooling decisions, access management (Okta, SCIM/SAML provisioning), endpoint management, identity governance
  • Ensure IT operations scales with engineering headcount growth — proactive capacity planning, not reactive ticket-handling
  • Define IT security policies and enforce them: device management, access reviews, offboarding rigor

Cross-functional Leadership & Communication

  • Proactively communicate security posture, compliance status, and IT health to the VP Engineering — come with recommendations, not status updates
  • Partner with the Cloud Platform Sr. Manager on infrastructure security: network security, IAM standards, security logging and alerting
  • Work with Engineering leadership to embed security practices across product teams — not as a compliance checkpoint but as a capability they value
  • Represent Fingerprint’s security and compliance posture to enterprise customers, prospects, and auditors

What We’re Looking For

Required

  • 7+ years in security, IT, or GRC with at least 3 years managing a team — you’ve led people, made hard calls, and developed practitioners
  • Breadth across the three disciplines: Genuine fluency across application security, IT operations, and compliance/GRC
  • Application security depth: OWASP familiarity, vulnerability management programs (Snyk or equivalent), security review processes for engineering teams — you’re credible in a room with senior engineers talking about AppSec
  • IT operations leadership: Identity and access management (Okta or equivalent), endpoint management, remote workforce IT at scale
  • Strategic communicator: You translate security and compliance complexity into business language for leadership and customers — risk framing, not technical jargon

Preferred

  • SOC 2 ownership experience: You’ve run or been the primary owner of a SOC 2 audit cycle — not just participated in one. You understand what good evidence looks like, how to manage auditor relationships, and how to build sustainable control operations vs. annual scramble mode
  • Additional compliance frameworks: ISO 27001, GDPR, HIPAA experience — particularly relevant given Fingerprint’s enterprise customer base in financial services and healthcare
  • Security tooling stack familiarity: Snyk (vulnerability management), Wiz (cloud security posture), Cloudflare (WAF/edge), Okta — these are live in Fingerprint’s environment
  • Enterprise security questionnaire experience: You’ve answered rigorous due diligence questionnaires from financial institution InfoSec teams and know what “good” looks like on both sides of that process
  • Experience in a high-growth SaaS company where security had to keep pace with rapid product and customer growth without becoming a bottleneck

The Unique Shape of This Role

This role deliberately spans three disciplines that are often separated at larger companies. At Fingerprint’s scale, that breadth is a feature, not a bug: the person who owns compliance also owns the security posture that makes compliance meaningful, and the person who owns IT operations also owns the identity and access foundation that security depends on. You won’t have the luxury of optimizing one function at the expense of the others.

What this means in practice: you need to be comfortable setting direction across domains where your team members have more operational depth than you do. We don’t expect you to be the deepest technical expert in AppSec, IT operations, and GRC simultaneously — your team covers that depth. What we do expect is that you understand each domain well enough to set direction, evaluate the work, and make hard prioritization calls across all three. The judgment to know when to rely on your team vs. when to drive the decision yourself is what distinguishes the right candidate from someone who is simply strong in one area.

This isn’t a role for someone who wants to be a player-coach in one discipline. It’s a role for someone who has moved past that — who leads through strategy, communication, and people development, not through personal technical execution.

Why This Role?

  • VP direct line with genuine autonomy: You own the function. You come to the VP with recommendations, not requests for direction
  • A strong team already in place: The Lead IT Engineer and Compliance Lead are capable, experienced practitioners. You’re not building from scratch — you’re giving them strategic leadership and maturing what they’ve already built
  • High customer visibility: Fingerprint serves major enterprise customers in financial services, fraud prevention, and beyond. Security posture is a real differentiator in enterprise sales, and you’re the person who owns it
  • Compliance maturity to build on: SOC 2 Type 2 + HIPAA is already achieved. The next horizon — expanded frameworks, deeper enterprise compliance requirements — is yours to define
  • A function that’s finally getting its own leadership: Security and IT have been embedded in a larger infrastructure group without dedicated management. This role exists because Fingerprint recognizes these functions need focused, strategic leadership to reach the next level

Compensation Range

For US-based employees, the cash compensation range for this role is $177,000 – $240,000. We set standard ranges for all US roles based on function, level, and geographic location, benchmarked against similar stage growth companies. To comply with local legislation and provide greater transparency, we share salary ranges on all job postings. However, these ranges are specific to the hiring location and may differ within or outside the US.

We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates’ personal and financial information through fake interviews and offers. All Fingerprint recruiting email communications will always come from the @fingerprint.com domain. Any outreach claiming to be from Fingerprint via other sources should be ignored.

Offers vary depending on, but not limited to, relevant experience, education, certifications/licenses, skills, training, and market conditions.

Due to regulatory and security reasons, there’s a small number of countries where we cannot have Fingerprint teammates based. Additionally, because Fingerprint is an all-remote company and people can join our workforce from almost any country, we do not sponsor visas. Fingerprint teammates need to be authorized to work from their home location.

We are dedicated to creating an inclusive work environment for everyone. We embrace and celebrate the unique experiences, perspectives and cultural backgrounds that each employee brings to our workplace. Fingerprint strives to foster an environment where our employees feel respected, valued and empowered, and our team members are at the forefront in helping us promote and sustain an inclusive workplace. We highly encourage people from underrepresented groups in tech to apply.

If you are applying as a resident of California, please read our CCPA notice here

If you are applying as a resident of the EU, please read our GDPR notice here

Read the full description
Security Manager, Cyber Compliance, Deloitte Global Technology

Manages cyber compliance programs and governance frameworks to ensure organizational adherence to security standards and regulatory requirements.

Mid Remote Posted 4 days ago Jobicy AI
What this role involves
Job Type: Permanent Work Model: Remote Reference code: 134501 Primary Location: Toronto, ON All Available Locations: Toronto, ON   Our Purpose   At Deloitte, our Purpose is to make an impact that matters. We exist to inspire...
Read the full description
Security Security Controls Assessor (Part time & Remote) at TestPros, Inc.

Conducts security assessments and compliance evaluations using NIST frameworks, develops security documentation (SSPs, SARs, POA&Ms), and verifies implementation of security controls for federal and commercial clients.

Mid Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world.  We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.

TestPros is looking for Security Controls Assessors with experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks.

Start: Future projects late 2026 or 2027 (not an immediate job opening)

Type: Part-time consulting

Overview

Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.

Responsibilities and Duties:

You should be able to deliver on the following expertly and consistently:

  • Develop NIST 800-53 Rev5 based System Security Plan (SSP).
  • Create/Update the applicable documents identified by NIST 800-53 Rev 5, specifically the Security Assessment Report (SAR).
  • Create/Update the associated Plan of Actions and Milestones (POA&M).
  • Provide detailed security-related reports including data, analyses, and conclusions upon completion of tests, scans, and assessments, including mitigations and, if indicated, appropriate escalation of identified risks and vulnerabilities.
  • Verify and document the implementation of security controls necessary to achieve compliance.
  • Keep management apprised of impending areas of concern, verbally and in writing.
  • Review and develop System Security Plans (SSPs), Plans of Actions and Milestones (POA&Ms), and as well as other necessary artifacts.
  • Facilitate the Plan of Actions and Milestones (POA&M) program to ensure customer systems have accurately and fully provided information for POA&M activities to include valid remediation of findings.
  • Develop various policy documents (SOPs/CONOPs) as required. This may include policies regarding Configuration Management, IS Sanitization, Media Security, Password Policy, Business Continuity, Continuity of Operations, Incident Response, Disaster Recover, and Security Assessments.
  • Develop new, and mature existing information security and risk policies.
  • Initiate, and lead on-going information security maturity assessment processes and training, using industry accepted frameworks and implement into the overall cyber security posture.
  • Produce and review key performance indicators for implemented security measures and distribute KPIs.
  • Maintain knowledge of threat landscape by monitoring threat intelligence, and other related sources.

Qualifications and Skills:

  • 5+ years of directly related experience in IT security compliance, including recent experience with NIST 800-53 Rev 5 “Security and Privacy Controls for Federal Information Systems and Organizations”
  • Cloud computing security
  • Security governance and policy
  • Security risk analysis
  • Auditing and monitoring systems
  • Scanning and vulnerability management systems
  • Advanced Malware Protection
  • Threat Intelligence
  • Incident Management - analysis, detection, and handling of security events
  • Penetration testing and associated tools (e.g., nmap, Metasploit, etc.)
  • Bachelor’s Degree in Computer Science or a related technical discipline, or the equivalent combination of education, professional training, or work experience (preferred)
  • Military and/or practical job experience may be considered in-lieu of formal education, with significant industry certifications

Rate: $50-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.

Equal Opportunity Employer

TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.

Offer Considerations

TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.

Federal Compliance

As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.

Read the full description
Security Cyber Security Engineer / Information Systems Security Engineer (ISSE) at OpenTeams

Leads cybersecurity architecture, RMF activities, and compliance for government systems while designing supply chain security controls and integrating security into CI/CD pipelines.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Who We Are

We exist to unlock human potential.

Too often, AI drains it—drains budgets, drains energy resources, drains ownership of data. OpenTeams was founded to change that. We build AI that empowers. Our models are energy-efficient, cost-effective, and fully yours.

Our ethos is open source. That means freedom, trust, and accountability are built into every line of code. We reinvest 3% of our profits back into the open-source community, because we believe tech is most powerful when it serves everyone.

At our core, we value freedom, teamwork, accountability, and uncompromising quality. If you want to challenge the status quo, and shape tools that set people free, OpenTeams is the place to do it.

Location: Remote (US) with travel to customer sites as required (Washington Metro Area preferred)

Employment Type: Full-time

Clearance: Active TS/SCI required

Role Summary

The Cyber Security Engineer / ISSE owns the security architecture and accreditation posture of the depot. This role leads RMF activities, embeds security controls into engineering workflows, and serves as the primary security interface with government assessors and authorizing officials.

Responsibilities

  • Lead RMF activities: control selection, implementation evidence, POA&M management, and ATO support
  • Design and implement supply chain security controls: SBOM generation, artifact signing, vulnerability scanning, and provenance attestation
  • Perform threat modeling and security reviews of depot architecture and workflows
  • Integrate security tooling into CI/CD pipelines and enforce policy gates
  • Support cross-domain and classified environment requirements, including secure transfer procedures
  • Interface with government ISSMs, assessors, and authorizing officials

Required Qualifications

  • Active TS/SCI clearance
  • Experience with Xacta, eMASS, or CSAM
  • 6+ years in cyber security or ISSE roles supporting DoD or IC systems
  • Hands-on experience with RMF, NIST 800-53, and eMASS or equivalent
  • Experience with DevSecOps tooling: container scanning, SAST/DAST, signing, and policy enforcement
  • IAT/IAM Level II or III certification per DoD 8140 (for example Security+, CISSP, or CISM)

Preferred Qualifications

  • Experience securing AI/ML systems or software supply chains at scale
  • Familiarity with cATO approaches and continuous monitoring
  • Experience with IL5/IL6 or cross-domain solutions

Grow With Us

At OpenTeams, growth isn’t just about the company—it’s about you.

We believe the best careers are built at the edge of your potential. That is where new tools, ideas, and technologies change the world. Here, you’ll work alongside pioneers of AI, solving problems that matter: making AI more transparent, more ethical, and more empowering. As your skills grow, our career framework provides a pathway and recognition of that increased impact.

Opportunities aren’t limited by geography. You’ll collaborate with global experts, contribute to open source projects that power the world’s technology, and stretch your skills daily.  That global perspective and diversity makes our solution more universal and robust.  We are committed to continuing to celebrate diversity on our team.

Supported people are successful people.  We offer 100% employer paid medical premiums for employees and self-managed PTO with a minimum time off requirement, so that our teams are able to do their best work.

We invest  in curiosity, creativity, and ownership. That means you’ll be trusted to boldly innovate, supported to learn fast, and celebrated for successful collaboration.

Commitment to diversity, equity, inclusion, and belonging

OpenTeams understands that valuing diverse creative practices and forms of knowledge is crucial to and enriches the company’s core mission. We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, disabled people, persons of all sexual orientations, gender identities and expressions.

We are an equal opportunity employer - all qualified applicants will receive equal consideration for recruitment, interviews, employment, training, compensation, promotion, and related activities. We do not discriminate based on race, religion, gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws. OpenTeams will not tolerate discrimination or harassment based on these characteristics or any other unlawful behavior, conduct, or purpose.

Read the full description
Security Field CISO at Sprinto

Field CISO builds market-facing security and compliance thought leadership, speaking engagements, and practitioner credibility for a compliance automation platform.

Lead Remote Posted 9 days ago RemoteFirstJobs Product
What this role involves

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers.

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable trust posture without draining operational bandwidth and resources on repetitive tasks.

Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we’ve raised $31.8M in funding to fuel our mission. Trusted by over 4,000 organizations across 75 countries, Sprinto helps organizations stay audit-ready, manage real-time risks, and scale fearlessly. With 300+ native integrations and AI-driven automation, Sprinto supports 200+ global security standards natively, including SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and more. Sprinto’s extensible architecture enables organizations to build and support an infinite number of custom integrations and frameworks.

Founded in 2020 by second-time founders Girish Redekar and Raghuveer Kancherla, Sprinto powers compliance for organizations like Whatfix, Encora, Anaconda, Whatnot, Ultrahuman, WeWork, Everstage, AI Foundation, HackerRank, and many more.

Life as a Sprinter -

Nobody succeeds at Sprinto by staying in their lane.

We are organized around problems, not job titles. Sprinters take ownership beyond their role, solve hard problems, and care deeply about the impact they create. If something can be improved, fixed, or built, we don’t wait for permission; we step in.

Being remote means we rely less on proximity and more on trust. We write things down, communicate openly, and move quickly because great teams aren’t built by sitting together, they’re built by pulling in the same direction.

We believe progress beats perfection, feedback is a gift, and doing the right thing matters, even when nobody is watching.

And while we move with urgency, we never move alone.

The mission -

This is Sprinto’s first dedicated Field CISO hire in the US. You are not walking into a built function. You are building the market-facing security and compliance voice from scratch - with full access to the founders, the GTM team, and the product roadmap.

This is a marketing and thought leadership role. You make every Sprinto channel more credible, more attended, and more influential - because the voice behind it is a practitioner, not a vendor. Every roundtable you run, every stage you speak from, every webinar you anchor - you own the prospect experience.

The scope runs from the first piece of content to the narratives & depth in all Sprinto content.

Where you’ll leave your mark?

  • Take the Autonomous Trust thesis to market - together - Sprinto has built the product and defined the category. You bring the platform to carry the thesis publicly - at events, in content, on stage, in every conversation that shapes how enterprise CISOs think about compliance. We build the narrative. You carry it into rooms we cannot reach alone.
  • Show up at the industry’s biggest stages as Sprinto’s practitioner voice - When we walk into RSA, ISACA, or a regional CISO summit, we walk in as participants in the conversation - not vendors looking for a slot. Your point of view on stage is how we earn that position. Together we make sure Sprinto is never just a name on a booth.
  • Build the rooms where CISOs talk openly - Webinars and roundtables only work when the right person anchors them. You bring the practitioner credibility that makes a CISO clear their calendar. We bring the platform and the agenda. Together we create conversations where CISOs share what they actually need - and the pipeline follows naturally.
  • Put a practitioner’s fingerprint on everything we publish - Our content team has the reach and the production. You have the voice that turns good content into content CISOs forward. We write together, you shape the thinking, and you push it through channels we do not own - your newsletter, your LinkedIn, your podcast. The audience you bring is the distribution we cannot manufacture from scratch.
  • Deepen the advisory board into a real community - We have built relationships with some of the most respected security leaders in the market. You deepen them - not as a coordinator, but as a peer. The more substantively you engage, the more the advisory board compounds into events, content, and deals none of us could run alone.
  • Walk into deals at different stages where needed - Early in a prospect conversation, you help them see what their compliance program could look like when the detection-remediation gap closes. You are not pitching - you are workshopping. You sit with their reality, map it against the Autonomous Trust model, and help them arrive at the vision themselves.

By the time a deal reaches the final room, you have already shaped how they think about the problem. When a CISO-level objection surfaces late, you walk back in as a peer and move it. Sales closes. The work you did upstream is why it lands.

The kind of builder we’re looking for -

  • 10+ years in security leadership; you have held a CISO, Deputy CISO, or senior advisory role and know what that job actually demands

  • Savvy with Compliance implementations for frameworks like SOC 2, ISO 27001, NIST CSF, HIPAA, and FedRAMP - you use these in conversation, not on slides

  • A track record of engaging enterprise CISOs as a peer, not as a vendor representative

  • Comfort with commercial accountability - you have owned numbers before or you are ready to

  • Simplify complex thesis and ideas into simpler and readable chunks.

  • You are not a vendor with a blog. You are a practitioner with a thesis. Bring original thinking on where the CISO’s office is headed - Autonomous Trust is part of that story, not the whole of it

  • Operate independently across multiple channels with rest of the team at your disposal to enable and unlock where needed.

We are open to structuring this as a full-time role or an advisory and consulting engagement - depending on what works best for everyone involved. If the fit is right, the arrangement is a conversation.

How we care for our Sprinters?

  • 100% remote

  • Health, dental, and vision insurance

  • Annual learning and development reimbursement

  • Home office setup stipend

  • Device reimbursement

Inclusion & Diversity -

At Sprinto, talent, curiosity, and ownership matter more than where you come from. We hire people for the problems they can solve, the impact they create, and the way they help others succeed—not their background, identity, or personal circumstances. We believe the best teams are built when people with different perspectives come together around a shared ambition to build something meaningful.

We’re proud to be an equal opportunity employer and are committed to creating a fair, inclusive, and accessible hiring process for everyone.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Cloud Security Engineer at Iterable

Leads cloud security initiatives across development lifecycle, implementing automated security measures and vulnerability assessments to protect customer data and systems.

Senior Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

Iterable is the leading AI-powered customer engagement platform that helps leading brands like Redfin, SeatGeek, Priceline, Calm, and Box create dynamic, individualized experiences at scale. Our platform empowers organizations to activate customer data, design seamless cross-channel interactions, and optimize engagement—all with enterprise-grade security and compliance. Today, nearly 1,200 brands across 50+ countries rely on Iterable to drive growth, deepen customer relationships, and deliver joyful customer experiences.

Our success is powered by extraordinary people who bring our core values—Be an Owner, Growth Mindset, Run as One, Transparency —to life. We foster a culture of innovation, collaboration, and inclusion, where ideas are valued and individuals are empowered to do their best work. That’s why we’ve been recognized as one of Inc’s Best Workplaces and Fastest Growing Companies, and were recognized on Forbes’ list of America’s Best Startup Employers in 2022. Notably, Iterable has also been listed on Wealthfront’s Career Launching Companies List and has held a top 10 ranking on the Top 25 Companies Where Women Want to Work.

With a global presence—including offices in San Francisco, Denver, London, Sydney, and Lisbon, plus remote employees worldwide—we are committed to building a diverse and inclusive workplace. We welcome candidates from all backgrounds and encourage you to apply. Learn more about our story and mission on our Culture and About Us pages. Let’s shape the future of customer engagement together!

How you will make an impact:

Customers trust Iterable with sensitive information, expecting us to safeguard their data. Iterable’s Security team leads a cross-functional effort across the company to ensure that all systems remain secure in support of Iterable’s core values, and to provide assurance to our customers that we will be good stewards of their valued data. The Security team actively leads the effort to improve Iterable’s security posture in concert with other groups as they develop or launch new features and services. As Engineers, we believe in security through automation, assessments, technical reviews and vulnerability evaluation. Our footprint spans across the entire company at all levels, throughout the complete development lifecycle.

We aim to create a compelling, well-documented, and holistically managed security program. We are looking for individuals to join our vibrant Security Engineering team to move the current state of security to the next level. We strive to improve our cloud security capabilities, and support our peers in building an amazing product through creating an environment which fosters security by design. To summarize, we want you to share and be a part of our grand plan!

One of our core values is “Growth Mindset,” and Iterable is a company where everyone can grow. If this is a role that excites you, please apply as we value applicants for the skills they bring beyond a job description.

In this role you’ll get to:

  • Review system designs and implementations, and consult with engineers across the organization to identify and/or avoid security issues through alignment with security standards and best practices, document and ensure security issues are appropriately remediated
  • Leverage subject matter expertise of systems and infrastructure to propose solutions and drive architectural improvements which address classes of security vulnerabilities
  • Develop and implement cloud and infrastructure security architecture and contribute to overall strategy and roadmap plans
  • Participate in the selection, design, development, implementation, and management of automated security testing tools, such as cloud security posture management and image vulnerability scanners
  • Implement solutions that integrate into CI pipelines to shift security as far left as possible and raise concerns early to engineering teams.
  • Promote DevSecOps principles and implement Infrastructure as Code (IaC) scanning and policy enforcement to ensure deployments via Terraform, AWS CloudFormation, or similar, are secure and compliant with standards and guidelines
  • Coordinate and participate in penetration tests of our cloud services

We are looking for people who have:

  • 5+ years hands-on-keyboard in Cloud Security, SRE, DevOps, DevSecOps, or Infra Engineering.
  • Strong working knowledge of Kubernetes and ecosystem tools such as helm, ArgoCD.
  • Production experience with AWS services, particularly AWS Organizations, AWS Identity (SSO), Identity and Access Management (IAM), Service Control Policies (SCPs), Virtual Private Clouds, Elastic Load Balancers, AWS CloudTrail, and Security Groups.
  • Proficiency with Terraform.
  • Experience developing custom actions or workflows in Github or Gitlab.
  • Solid understanding of cloud security vulnerabilities defense techniques and security best practices, including AWS security practices and present-day threats
  • Proficiency in a high level programming language, such as Python or Go
  • Familiarity with policy management tools such as OPA or Kyverno

Bonus points:

  • SRE Experience
  • Scala or JVM ecosystem experience
  • Familiarity with common observability tools such as Datadog, Prometheus/Grafana
  • Experience with AWS EKS
  • Experience with Panther SIEM
  • Hands on work standing up Jupyter notebook instances, using Jupyter operationally.

Perks & Benefits:

  • Competitive salaries, meaningful equity, & 401(k) plan
  • Medical, dental, vision, & life insurance
  • Balance Days (additional paid holidays)
  • Fertility & Adoption Assistance
  • Paid Sabbatical
  • Flexible PTO
  • Monthly Employee Wellness allowance
  • Monthly Professional Development allowance
  • Pre-tax commuter benefits
  • Complete laptop workstation

The US base salary range for this position at the start of employment is $141,000 - $221,000. Within this range, individual pay is determined by specific US work location, as well as additional factors, including job-related skills, experience, relevant education or training, and internal equity considerations.

Please note that the range listed above reflects only base salary. The total compensation package includes variable pay (where applicable), equity, plus a range of benefits, including medical, dental, vision, and financial. In addition, we offer perks such as generous stipends for health & fitness and learning & development, among others.

Recruitment Disclaimer:

Please be aware that Iterable, Inc. (“Iterable”) and our official professional recruiting agencies and platforms do not:

  • Send job offers from free email services like Gmail, Yahoo mail, Hotmail, etc.
  • Request money, fees, or payment of any kind from prospective candidates to apply to Iterable, for employment, or for the recruitment process (e.g. for home office supplies, or training, etc.).
  • Request or require personal documents like bank account details, tax forms, or credit card information as part of the recruitment process prior to the candidate signing an engagement letter or an employment contract with Iterable.

You may see all job vacancies on our official Iterable channels:

  • Official Iterable website, Careers page: https://iterable.com/careers/
  • Official LinkedIn Jobs page: https://www.linkedin.com/company/iterable/jobs/

Iterable is not affiliated in any way to these impostors and we hereby confirm that such individuals/entities are not authorized, encouraged, or sponsored to act on behalf of Iterable. Such job opportunities are entirely fake and not valid. Therefore, please disregard any written or oral request for a job offer or an interview that you believe is or might be fraudulent or suspicious and immediately reach out to us via email at talent-ops@iterable.com upon receiving a suspicious job offer.

Criminal and/or civil liabilities may arise from such actions, and Iterable expressly reserves the right to take legal action, including criminal action, against such individuals/entities whenever such phenomena occur. In any case, please note that under no circumstances shall Iterable and any of its affiliates be held liable or responsible for any claims, losses, damages, expenses or other inconvenience resulting from or in any way connected to the actions of these impostors.

Iterable is an Equal Employment Opportunity employer that proudly pursues and hires a diverse workforce. Iterable does not make hiring or employment decisions on the basis of race, color, religion or religious belief, ethnic or national origin, nationality, sex, gender, gender-identity, sexual orientation, disability, age, military or veteran status, or any other basis protected by applicable local, state, or federal laws or prohibited by Company policy. Iterable also strives for a healthy and safe workplace and strictly prohibits harassment of any kind. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Iterable will also consider for employment qualified applicants with arrest and conviction records.

Read the full description
Security Senior Security Engineer at SmarterDx

Owns detection engineering and security operations, writing/tuning SIEM detections in Panther, investigating alerts, running cloud security operations in AWS, and executing incident response.

Senior Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

SmarterDx is transforming how health systems use clinical AI to capture the full value of patient care delivered. Built by physician-data scientists and trained on clinically-validated EHR data, our clinical AI platform interprets the nuances behind every patient story and makes clinically-sound recommendations for revenue cycle teams — helping hospitals recover earned revenue, improve quality metrics, reduce denials, and streamline revenue cycle operations. As a Smartian, you’ll help build technology that makes healthcare more accurate, sustainable, and effective for everyone. Learn more at smarterdx.com/careers.

Role

SmarterDx Security Engineering has a broad scope: AI, cloud, and enterprise security, plus reviews of new designs and code across the company. This role is our hands-on owner of detection engineering and security operations. You will turn our detection platform into real coverage: writing and tuning detections in Panther, keeping alerts high-signal, running the SIEM as it grows, and being on point when an alert turns into an investigation. You will also handle the day-to-day work of cloud security operations and help run incident response.

You will work closely with our Staff Security Engineer, who sets detection and AI-security strategy. Your job is to make that strategy real in production and keep it sharp. There is room to grow into deeper detection engineering, cloud security, and security automation, on a team that invests in leveling people up.

**This role is fully remote within the US**

What You’ll Do

  • Write, tune, and maintain detections in our SIEM (Panther) across cloud, container, and SaaS log sources, keeping coverage broad and alerts high-signal.
  • Run the SIEM day to day: onboard log sources, manage detection quality, and reduce false positives so real signals stand out.
  • Triage and investigate security alerts from raw log to conclusion, and help execute our incident-response playbooks.
  • Run cloud security operations in AWS: investigate GuardDuty and Wiz findings, tighten configurations, and close cloud misconfigurations.
  • Own and improve GitHub organization security controls as code.
  • Partner on network and infrastructure security: help onboard network telemetry, support egress monitoring, and provide backup depth alongside our infrastructure security engineer.
  • Help build and extend the team’s security-automation tooling.
  • Write runbooks so detection and response are repeatable rather than tribal knowledge.
  • Contribute to security design reviews and RFCs, and give substantive security feedback on pull requests.
  • Support the Vulnerability Management program with triage and exploitability assessment as volume requires.

What You Bring

  • 4+ years in security engineering, with solid hands-on experience in AWS and cloud-native infrastructure.
  • Direct experience writing and tuning detections in a modern SIEM (Panther or similar) and reasoning about detection coverage.
  • Experience investigating security alerts from raw log to a defensible conclusion.
  • The ability to design and deliver medium-complexity security work independently.
  • Code fluency in Python or TypeScript to automate your work.
  • Familiarity with cloud logging and observability (CloudTrail, VPC Flow Logs) and AWS security services (GuardDuty, AWS Config).
  • Solid AWS network security fundamentals (VPC, security groups, egress controls) and Terraform, enough to partner on and back up our network and infrastructure security work.
  • Clear writing; you leave behind runbooks and tickets others can follow.
  • Design detections and operational tooling for maintainability, so the work stays reliable and easy for the team to extend.
  • An ownership mindset: you close loops rather than drop them.

Nice To Haves

  • Startup experience, especially in health tech or another regulated, data-sensitive environment.
  • Incident-response experience, or a strong interest in growing into it.
  • Network security depth beyond fundamentals (VPC design, segmentation, Transit Gateway, firewall/egress architecture).
  • Kubernetes (EKS) and container security exposure.
  • Interest in AI and agentic security and in building security automation.

Our Tech Stack

  • Cloud and infrastructure: AWS, Kubernetes (EKS), Terraform, Postgres
  • Detection and security tooling: Panther (SIEM), GuardDuty, AWS Config, Wiz, Snyk, GitHub Advanced Security, CrowdStrike, Nightfall, Drata
  • Languages: Python, TypeScript, Go
  • AI and automation: Claude, MCP, and agentic tooling used across engineering

Compensation

$190k to 220k base salary

#LI-Remote

#LI-DNP

Benefits

  • Medical, Dental & Vision – Comprehensive plans with leading insurance providers, covering 75% of your premiums, depending on the plan.
  • Paid Parental Leave – Generous paid leave to support families through birth or adoption: Up to 12 weeks for parents.
  • Remote-First Team – Work from anywhere in the U.S.
  • Unlimited PTO & 10 Holidays – So you can relax and recharge.
  • 401(k) with Traditional & Roth Options– Tax-advantaged retirement savings through Fidelity with a 4% match.
  • Minimal Bureaucracy – A fast-moving, high-impact environment where you can focus on what matters.
  • Incredible Teammates! – Work alongside smart, supportive, and mission-driven colleagues.
Read the full description
Security HQ - Senior Application Security Engineer (Remote) at Job&Talent

Senior Application Security Engineer drives security by design across the SDLC, leading threat modeling, code reviews, security automation, and developer enablement initiatives.

Senior Remote Posted 11 days ago RemoteFirstJobs Product
What this role involves

We are looking for a proactive and experienced Senior Application Security Engineer to help build secure products at scale. As a trusted partner to Engineering and Product teams, you will drive security by design across the Software Development Lifecycle (SDLC), leading initiatives such as threat modelling, secure code reviews, security automation, and developer enablement.

You will play a key role in shaping our Application Security strategy, helping us build secure, resilient products while enabling engineering teams to move fast with confidence.

This is a fully remote position with flexibility within ±1 hour of CET.

Responsibilities

  • Act as the Application Security Subject Matter Expert (SME), partnering with Engineering and Product teams to embed security throughout the SDLC.

  • Lead application security reviews, threat modelling, code reviews and penetration testing to identify and mitigate security risks.

  • Design, implement and automate security controls across CI/CD pipelines, including SAST, SCA and other AppSec tooling.

  • Drive the technical roadmap of the Application Security program, improving secure development practices and scaling security initiatives across the organisation.

  • Improve and manage application security controls, including WAF, Kubernetes security and vulnerability management.

  • Mentor Security Champions and junior engineers, promoting a strong security culture across development teams.

  • Define and communicate meaningful Application Security metrics to measure risk reduction and program effectiveness.

A successful candidate will have

  •  3-4 years of experience in Information Security, including at least 2 years in Application Security.

  • Strong experience with Secure SDLC, threat modelling, application security reviews and secure code reviews.

  • Hands-on experience with SAST, SCA and automated security testing integrated into CI/CD pipelines.

  • Strong knowledge of OWASP Top 10, OWASP ASVS, API Security and secure coding best practices.

  • Experience implementing and managing WAF solutions, as well as conducting internal penetration testing (including APIs using Burp Suite).

  • Solid understanding of Kubernetes security, cloud-native applications and networking fundamentals (HTTP, HTTPS, TCP/IP).

  • Basic scripting or development experience, preferably in Python.

  • Excellent communication skills, with the ability to influence engineering teams and explain complex security concepts to technical and non-technical stakeholders.

About us

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. We help companies boost productivity and efficiency at scale, while giving workers the tools they need to thrive. Our mission is simple: to empower the people who make the world go round.

Built on deep industry expertise, cutting-edge technology, and smart AI agents, our end-to-end platform covers the entire workforce lifecycle — from recruitment and planning to time and attendance, performance, cost management, and communication.

It delivers measurable improvements in the areas that matter most: fulfilment, attendance, retention, and workforce quality. Our platform strength is rooted in unique experience: placing millions of workers over the years and serving thousands of blue-chip clients across delivery, logistics, manufacturing, e-commerce, retail, and hospitality.

Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America and is backed by leading investors including Atomico, Goldman Sachs, Kinnevik, BlackRock, and SoftBank.

Join our community and make an impact

Innovation, high standards, and analytical thinking are in our DNA. Everyone has a voice here, and that voice matters. It’s how we stay sharp, move fast, and make decisions that keep us ahead of the curve.

You’ll take full ownership of your work, collaborate across borders, and grow by doing. Around here, you’ll hear a lot about 10x experiences, human-centered design, and the power of AI. But what truly sets us apart is our people: Our diverse team brings unique perspectives, deep commitment and real-world experience to the table.

We champion empathy, honesty, and inclusion. Because when people can be their authentic selves, incredible things happen—for our workers, our clients, and for each other.

And we reward that impact—with competitive pay, meaningful benefits, and the opportunity to shape what work looks like for millions around the globe.

If you’re ready to make a real impact at scale, you’re in the right place.

Proud to champion equality

At Job&Talent we value diversity and we’re an Equal Opportunity Employer. We welcome applications from all suitably qualified people regardless of national origin, race, disability, religious beliefs or sexual orientation. Come join us. We look forward to your application.

#LI-ML2

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Engineer at Oddball

Embeds security into federal software delivery by conducting risk assessments, supporting ATO compliance efforts, and maintaining FISMA/FedRAMP security postures for VA systems.

Mid Remote Posted 12 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Security Engineer at Oddball

Embed security into federal software delivery by integrating security requirements into development workflows, supporting ATO processes, and conducting risk assessments aligned with NIST and VA standards.

Mid Remote Posted 12 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.

What you’ll be doing:

  • Partner with application development teams to integrate security requirements into design, development, and deployment workflows
  • Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation
  • Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards
  • Participate in Agile/DevSecOps pipelines to ensure security is applied throughout the CI/CD lifecycle
  • Monitor and respond to security incidents, anomalies, and findings in coordination with stakeholders
  • Implement and maintain monitoring tools such as Splunk, ACAS, or Nessus
  • Ensure systems comply with FISMA, HIPAA, FedRAMP, and VA-specific security requirements

What you’ll bring:

  • Experience supporting ATO and RMF processes including documentation and continuous monitoring

  • Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks

  • Experience securing cloud environments such as AWS GovCloud or Azure Government

  • Familiarity with vulnerability scanning tools such as Nessus or ACAS

  • Familiarity with SIEM platforms such as Splunk or ELK Stack

  • Some scripting or automation experience in Python, Bash, or PowerShell is a plus

  • CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s Degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io

The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $110,000 – $145,000

Read the full description
Security Red Team Lead (Offensive Cybersecurity)

Leads offensive cybersecurity red team operations, conducting penetration testing and vulnerability assessments for critical infrastructure projects.

Lead Remote Posted 12 days ago Himalayas
What this role involves
Role Title: Red Team Lead (Offensive Cybersecurity) Role Type: Contractor Location: Remote micro1 is engaging Red Team Leads (Offensive Cybersecurity) to contribute expertise to a customer's critical cybersecurity project.
Read the full description
Security Senior Security Engineer I, Customer Trust EMEA (Remote Eligible in the UK)

Leads security initiatives and trust operations for Smartsheet's EMEA region, protecting customer data and platform integrity.

Senior Remote Posted 12 days ago Jobicy AI
What this role involves
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI...
Read the full description
Security Lithic: Senior AML Analyst

Senior AML Analyst owns financial crime monitoring program, manages investigation tooling, and handles compliance escalations for card issuing platform.

Senior Remote Posted 12 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Lithic is the modern card issuing and processing platform empowering ambitious financial companies to build the future of payments.

Our infrastructure powers card programs for 100+ innovative clients, from fintechs reimagining credit and digital banking to platforms transforming disbursements and spend management. Companies like Mercury, Flex, and Novo rely on Lithic's developer-friendly APIs, direct network connections, and flawless reconciliation to launch and scale card programs in weeks, not years.

We're building a future where access to better financial products materially improves people's lives, free from the constraints of 30-year-old mainframes and legacy processors. We're proud to be backed by world-class investors who share that vision, including Bessemer Venture Partners, Index Ventures, Spark Capital, Stripes, and Mastercard, along with many others. 

We're a team of 170+ across 26 states and 7 countries, headquartered in New York City. 

Lithic is the modern card issuing and processing platform empowering ambitious financial companies to build the future of payments.

Our infrastructure powers card programs for 100+ innovative clients, from fintechs reimagining credit and digital banking to platforms transforming disbursements and spend management. Companies like Mercury, Flex, and Novo rely on Lithic's developer-friendly APIs, direct network connections, and flawless reconciliation to launch and scale card programs in weeks, not years.

We're building a future where access to better financial products materially improves people's lives, free from the constraints of 30-year-old mainframes and legacy processors. We're proud to be backed by world-class investors who share that vision, including Bessemer Venture Partners, Index Ventures, Spark Capital, Stripes, and Mastercard, along with many others.

We're a team of 170+ across 26 states and 7 countries, headquartered in New York City.

Our Risk & Compliance team is hiring a Senior AML Analyst who will improve the effectiveness, resilience, and scalability of our financial monitoring program. You will own Lithic's AML and financial crime monitoring program at the SOP and monitoring-engine level, and you will be the person who turns our agentic monitoring and investigation tooling into realized, defensible capacity. This is an ownership role, not purely a queue-based execution role: you’ll certainly handle escalations, exceptions, and perform population sampling, but the goal is routine, documented volume is increasingly absorbed by automation, and you own the design, tuning, and exception handling that sit around it.

What You’ll Do

  • Own and continuously improve the AML and financial crime transaction monitoring SOPs, keeping them aligned to current regulatory requirements, evolving typologies, and operational reality
  • Own the feedback loop into Lithic's monitoring engine: partner with your Analytics, Engineering, and Product peers to evaluate alert logic, assess rule and scenario effectiveness, and tune thresholds to reduce false positives while preserving coverage
  • Lead the testing, deployment, and tuning of agentic transaction monitoring and investigation solutions, including documenting the investigative context the tooling needs to produce repeatable, examiner-ready output
  • Investigate complex suspicious activity independently and prepare high-quality SARs and UARs; own escalations and the judgment-heavy cases automation cannot close unattended
  • Supervise and quality-check alert review and investigative output, including AI-assisted output, so decisions hold up to bank partner and regulatory scrutiny
  • Synthesize monitoring performance data, operational trends, and emerging financial crime risks into actionable program insights, and define and influence AML KPIs and KRIs
  • Lead governance preparation for relevant oversight forums and support bank partner and exam-readiness deliverables
  • Train and mentor analysts on investigations, money laundering typologies, and the agentic tooling, so program knowledge scales beyond any one person

What You'll Need

  • 3+ years of AML/BSA and transaction monitoring experience in fintech, payments, or a bank-partnered environment
  • Demonstrated ownership of end-to-end AML programs or work streams with limited guidance, including authoring and maintaining SOPs and preparing governance materials
  • Deep knowledge of money laundering typologies and emerging financial crime trends, with the ability to investigate complex activity and prepare high-quality SARs and UARs independently
  • Hands-on experience evaluating alert logic and assessing or tuning transaction monitoring rules and scenarios for effectiveness
  • Comfort working with AI-assisted or agentic tooling, including how to test, tune, document, and defend AI-assisted decisions to bank partners and regulators
  • Self-starter who can create structure where none exists and knows when to escalate and collaborate
  • Strong written and verbal communication
  • Solid grasp of the BSA/AML regulatory framework (USA PATRIOT Act, OFAC and sanctions, SAR requirements)

Nice to Have

  • CAMS or CFE (preferred, or willing to obtain)
  • Experience deploying or tuning AI, automation, or agentic tooling in a compliance or investigations context
  • Experience with OSINT tooling and SQL or Snowflake for investigative data retrieval
  • Card issuing, payments, or fintech experience with exposure to sponsor bank relationships
  • Background in high-risk verticals (MRBs, crypto-adjacent businesses, or similar)

Base Salary: $65,000 - $110,000

This is a remote position. However, candidates must be located in the United States. We do not offer visa sponsorship or assistance.

Benefits for Full-Time US Employees:

  • Unlimited PTO
  • 12-weeks fully paid parental leave
  • 4-Week Fully Paid Sabbatical (earned at your 5-year anniversary)
  • Work From Anywhere: work from anywhere in the world 4-weeks each year
  • 3% cashback on card purchases with your complimentary Privacy.com employee account
  • Health, vision, and dental insurance; HSA Contribution Match
  • 401(k) match
  • Voluntary Life Insurance and STD/LTD

NYC-based employees work from our SoHo office three days a week. Tuesdays and Thursdays are our core days, and you'll choose a third day that works for your schedule and team needs.

In-office employees receive: 

  • Commuter benefit
  • Catered lunch every Tuesday and Thursday

To apply: https://weworkremotely.com/remote-jobs/lithic-senior-aml-analyst

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at DEF CON

Lead DevSecOps engineer designs, builds, and operates secure CI/CD pipelines and infrastructure for government cloud environments while directing a team of platform and security engineers.

Lead Remote Posted 14 days ago RemoteFirstJobs Product
What this role involves

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;
  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contactrecruiting@defconai.com.

Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice .

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at Red Cell Partners

Leads DevSecOps platform design and deployment for government cloud environments, building CI/CD pipelines with embedded security controls and directing a small engineering team.

Lead Remote Posted 14 days ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits:

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description