Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. đ
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
Leads privacy and security compliance program, develops policies and controls, manages vendor risk assessments, and embeds privacy/security best practices across products and operations.
About Nanit:
Welcome to Nanit, the high-growth baby tech company that is changing the way parents experience parenthood through the worldâs most advanced baby monitor and parenting products. In 2016, the Nanit baby monitor revolutionized the industry with computer-vision and machine-learning capabilities that helped parents understand their babyâs sleep patterns and allowed them to achieve better sleep quality. Now, the company has become the leader in the connected parenting space, with an incredible customer base of highly-engaged parents who look to Nanit as a source of information and expertise on their parenting journey.
About the Role:
Weâre seeking a highly motivated and detail-oriented privacy and security professional to lead and evolve Nanitâs privacy and security compliance program. Reporting directly to the Chief Legal & Administrative Officer, you will build and operationalize the policies, controls, and processes that protect our customersâ data and keep Nanit ahead of an evolving regulatory landscape. Youâll partner closely with Legal, Product, Engineering, and business teams to embed privacy and security best practices into how Nanit builds and operates.
What Youâll Be Doing:
Who You Are:
Why Youâll Love Working Here:
EEO, Salary and Location:
This role can be offered as either hybrid or fully remote, with a preference for East Coast candidates.
Salary Range: $130,000 to $150,000 targeted salary plus equity, benefits and unlimited PTO. Nanitâs total compensation package includes access to healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, and basic life insurance. Ultimately, in determining your pay, weâll consider your location, experience, and other job-related factors.
We are proud to be an equal opportunity employer. We provide employment opportunities without regard to age, race, color, ancestry, national origin, religion, disability, sex, gender identity or expression, sexual orientation, veteran status, or any other protected class.
Builds detections and monitoring workflows, analyzes threat patterns, and develops automation to protect fintech infrastructure and respond to security incidents.
OnePay is the consumer fintech trusted by millions of Americans to make money better.
Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. Weâre fixing it. And weâre moving fast.
Weâre an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.
Weâre backed by Walmart, the worldâs largest retailer, and Ribbit Capital, one of fintechâs most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.
But what really sets OnePay apart is how we move. Our customers donât have time to wait⌠and neither do we. This place moves fast, and weâre looking for people who are:
Ready to run
Hungry and driven by urgency
Exceptional at what they do, with low ego
Comfortable operating in motion
As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePayâs products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:
Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.
Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.
Help operate OnePayâs vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.
Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.
Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.
Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.
Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.
Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.
5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.
Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.
Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.
Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.
Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.
Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.
Experience with at least one major cloud provider, preferably AWS.
Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.
Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.
Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.
Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.
Drive and proactivity - everyone here is a builder and executor
We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you donât need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.
Competitive base salary, stock options, and health benefits from Day 1
401(k) plan with company match
Remote-friendly (US), flexible time off (FTO), and opportunities for growth
A high-growth, mission-driven, inclusive culture where your work has real impact
Our process varies by role. Most candidates go through:
AI-assisted initial screen
Interview with Talent Partner
Technical or Hiring Manager Interview
Team Interview
Executive Interview
Offer!
To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.
Builds detections and monitoring workflows, reviews security telemetry for malicious activity, and develops automation tools to protect fintech infrastructure and customer data.
OnePay is the consumer fintech trusted by millions of Americans to make money better.
Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. Weâre fixing it. And weâre moving fast.
Weâre an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.
Weâre backed by Walmart, the worldâs largest retailer, and Ribbit Capital, one of fintechâs most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.
But what really sets OnePay apart is how we move. Our customers donât have time to wait⌠and neither do we. This place moves fast, and weâre looking for people who are:
Ready to run
Hungry and driven by urgency
Exceptional at what they do, with low ego
Comfortable operating in motion
As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePayâs products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:
Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.
Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.
Help operate OnePayâs vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.
Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.
Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.
Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.
Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.
Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.
5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.
Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.
Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.
Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.
Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.
Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.
Experience with at least one major cloud provider, preferably AWS.
Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.
Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.
Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.
Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.
Drive and proactivity - everyone here is a builder and executor
We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you donât need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.
Competitive base salary, stock options, and health benefits from Day 1
401(k) plan with company match
Remote-friendly (US), flexible time off (FTO), and opportunities for growth
A high-growth, mission-driven, inclusive culture where your work has real impact
Our process varies by role. Most candidates go through:
AI-assisted initial screen
Interview with Talent Partner
Technical or Hiring Manager Interview
Team Interview
Executive Interview
Offer!
To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.
Builds detections and monitoring workflows, analyzes threat patterns, and develops automation tooling to identify and respond to security threats across fintech infrastructure.
OnePay is the consumer fintech trusted by millions of Americans to make money better.
Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. Weâre fixing it. And weâre moving fast.
Weâre an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.
Weâre backed by Walmart, the worldâs largest retailer, and Ribbit Capital, one of fintechâs most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.
But what really sets OnePay apart is how we move. Our customers donât have time to wait⌠and neither do we. This place moves fast, and weâre looking for people who are:
Ready to run
Hungry and driven by urgency
Exceptional at what they do, with low ego
Comfortable operating in motion
As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePayâs products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:
Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.
Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.
Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.
Help operate OnePayâs vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.
Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.
Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.
Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.
Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.
Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.
5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.
Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.
Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.
Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.
Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.
Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.
Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.
Experience with at least one major cloud provider, preferably AWS.
Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.
Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.
Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.
Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.
Drive and proactivity - everyone here is a builder and executor
We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you donât need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.
Competitive base salary, stock options, and health benefits from Day 1
401(k) plan with company match
Remote-friendly (US), flexible time off (FTO), and opportunities for growth
A high-growth, mission-driven, inclusive culture where your work has real impact
Our process varies by role. Most candidates go through:
AI-assisted initial screen
Interview with Talent Partner
Technical or Hiring Manager Interview
Team Interview
Executive Interview
Offer!
To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.
Monitor and analyze customer security threats, detect attacks like account takeovers and bot attacks, and provide SOC support for cloud security incidents.
Headquarters: Australia (Remote)
Fastly helps people stay better connected with the things they love. Fastlyâs edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customersâ applications as close to their end-users as possible â at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastlyâs customers include many of the worldâs most prominent companies, including GitHub, Yelp, Paramount, and JetBlue.
We're building a more trustworthy Internet. Come join us.
Threat Detection Analyst - APAC (Japanese Speaking)
Leveraging our growing security product suite, the Threat Detection Analyst role contributes real world security insights to Fastly and our customers as we address Internet-scale threats. Cloud security solutions enable our customers to benefit from extra visibility across the world and expertise from a central team.Â
The Fastly Customer Security Operations Center team at Fastly focuses on operational support of Fastlyâs security products and services. The Threat Detection Analyst role within this team focuses on delivering outstanding security services to our customers, specifically as it pertains to integrating and supporting agent software installed on customer systems. The team works with the security, operations and customer organizations internally to deliver support solutions for security threats faced on the Internet today.
As a 24 x 7 team, SOC analysts are expected to work Friday - Tuesday, with the daily shift being 0000 - 0800 UTC - (9am - 6pm AEST)
What You'll Do
This role within the Fastly Customer Security Operations Center (CSOC) will be responsible for monitoring and analyzing customer activity, with added emphasis on security functions, like identifying account-takeover or Bot Attacks and WAF administration. Much of the focus will be on security and attacks around the application layer working with different web technologies. You will have the opportunity to work on some of the worldâs most scalable distributed systems that handle around 10 million requests per second, as well as the world-class engineers who developed these systems.
In this position, security engineers will be responsible for the following duties:
What We're Looking For
Work Hours:
Work Location(s) & Travel RequirementsÂ
This position is a remote position based out of (locality), with the possibility of becoming a hybrid position as Fastly expands its presence in the region.Â
This position will require travel to the US and Internationally, as required by your role or requested by your manager.
Benefits:
We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too. We support our teams with great benefits that start on the first day of your employment with Fastly. Curious about our offerings?Â
We offer a comprehensive benefits package designed to meet your needs. Our offerings may vary depending on the country where you work and are subject to change.
Why Fastly?
Weâre always looking for humble, sharp, and creative folks to join the Fastly team.
If you think you might be a fit please apply, we would love to hear from you.
Why Fastly?
We have a huge impact. Fastly is a small company with a big reach. Not only do our customers have a tremendous user base, but we also support a growing number of open source projects and initiatives. Outside of code, employees are encouraged to share causes close to their heart with others so we can help lend a supportive hand.
We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful -- every day.
We are passionate. Fastly is chock full of passionate people and weâre not âone size fits allâ. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.
Weâre always looking for humble, sharp, and creative folks to join the Fastly team. If you think you might be a fit please apply! A fully completed application and resume or CV are required when applying.
All job applications must be submitted through our official careers site at www.fastly.com/about/careers. We will never request sensitive information, such as your Social Security number, bank account or credit card information during the application process. All official communication will come from an @fastly.com or @recruiting.fastly.com email address.
Fastly is committed to ensuring equal employment opportunity and to providing employees with a safe and welcoming work environment free of discrimination and harassment. Our employment decisions are based on business needs, job requirements and individual qualifications. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, family or parental status, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.
Consistent with the Americans with Disabilities Act (ADA) and federal or state disability laws, Fastly will provide reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact your Recruiter, or the Fastly Employee Relations team at candidateaccommodations@fastly.com or 501-287-4901.Â
Fastly collects and processes personal data submitted by job applicants in accordance with our Privacy Policy. Please see our privacy notice for job applicants.
To apply: https://weworkremotely.com/remote-jobs/fastly-threat-detection-analyst-japanese-english-speaking
Manages technical execution of government compliance programs including FedRAMP, maintains security documentation, and automates compliance monitoring for a cybersecurity SaaS company.
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.
Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.
The Role
The Government Compliance Technical Specialist is a full-time individual contributor on BeyondTrustâs Trust & Assurance team, reporting to the Director of Trust & Assurance. This role owns day-to-day technical execution of BeyondTrustâs government compliance programs, including FedRAMP Moderate, TX-RAMP, IRAP, and other emerging public-sector frameworks. Responsibilities include continuous monitoring, writing and maintaining compliance documentation, POA&M management, and building automation to support compliance modernization, including FedRAMP 20x. The ability to interpret, define, and design automation for Key Security Indicators (KSIs) is required.
The ideal candidate has run a FedRAMP program end-to-end and can operate with a high degree of autonomy in a fast-paced cybersecurity product environment. They bring technical depth in NIST 800-53 controls, understand cloud compliance boundaries, and can demonstrate technical automation. This role will also support the program management of government compliance workstreams alongside product, security, and engineering teams.
What Youâll Do
What Youâll Bring
Nice To Have
Better Together
Diversity. Inclusion. Theyâre more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
About Us
BeyondTrust is the global identity security leader protecting Paths to Privilegeâ˘. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
Learn more at www.beyondtrust.com.
#LI-BS1
Designs and operates a vulnerability management program end-to-end, automating processes and driving remediation across products in a regulated environment.
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.
Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.
The Role
The Vulnerability Manager operates BeyondTrustâs product vulnerability management program end to end. This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome. The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based.
What Youâll Do
What Youâll Bring
Nice To Have
Better Together
Diversity. Inclusion. Theyâre more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.
We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.
About Us
BeyondTrust is the global identity security leader protecting Paths to Privilegeâ˘. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.
BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.
Learn more at www.beyondtrust.com.
#LI-BS1
Designs and implements security detection systems and incident response procedures to protect company infrastructure and data.
Designs, implements, and maintains cybersecurity systems and infrastructure to protect organizational assets and data from security threats.
Manages SOC 2 Type II compliance, leads ISO 27001 certification, and oversees security controls, risk assessments, and regulatory framework implementation across the organization.
Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.
What You Will Do
Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.
Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.
How You Will Do It
Security & Compliance
Risk & Governance
Cross-Functional Partnership
Data Protection & Awareness
Continuous Improvement
What Will Enable Your Success
Nice to Have
Salary Range: $140,000 - $170,000 + bonus
Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.
#LI-Remote
#LI-AC2
Maintains SOC 2 Type II compliance, leads ISO 27001 certification, and manages security controls and risk governance across the organization.
Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.
What You Will Do
Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.
Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.
How You Will Do It
Security & Compliance
Risk & Governance
Cross-Functional Partnership
Data Protection & Awareness
Continuous Improvement
What Will Enable Your Success
Nice to Have
Salary Range: $140,000 - $170,000 + bonus
Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.
#LI-Remote
#LI-AC2
Designs, implements, and maintains cloud security infrastructure and protocols to protect systems and data.
Monitors security events, responds to incidents, and maintains security infrastructure for enterprise systems.
DevSecOps engineer integrates security practices into development and deployment pipelines for Army contracting systems.
Partners with enterprise stakeholders to translate privacy, security, and AI compliance requirements into operational controls and governance processes.
Triages and validates security vulnerability submissions from researchers, communicates with clients and researchers, and escalates critical security incidents for bug bounty programs.
We are Bugcrowd. Since 2012, weâve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platformâ˘. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch⢠technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the worldâs biggest companiesâ bug bounty programs. Here are just a few of the reasons why we are the best:
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowdâs clients or researchers when additional information is required. ASEs also handle Incident Response â escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Culture
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowdâs Privacy Policy, which you may review here:Â https://www.bugcrowd.com/privacy.
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:Â https://www.bugcrowd.com/about/careers/
Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates with clients and security teams on bug bounty programs.
We are Bugcrowd. Since 2012, weâve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platformâ˘. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch⢠technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the worldâs biggest companiesâ bug bounty programs. Here are just a few of the reasons why we are the best:
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowdâs clients or researchers when additional information is required. ASEs also handle Incident Response â escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Culture
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowdâs Privacy Policy, which you may review here:Â https://www.bugcrowd.com/privacy.
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:Â https://www.bugcrowd.com/about/careers/
Monitors security alerts, investigates incidents, and responds to threats within the SOC environment.
Monitor and respond to security alerts, provide technical guidance to clients, manage vulnerabilities, and maintain security infrastructure across applications and infrastructure.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers.âŻOur unique âAssess, Design, Protectâ methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. Thatâs why customers trust Avertium to deliver better security, improved compliance, and greater ROI.
The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network. The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives. The CS Analyst will provide security analytics and assistance with security support requests.
In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.
Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (US Full-time employees)
Generous PTO, plus company holidays
Medical, dental, and vision coverage for you and your family
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Flexible spending account and dependent FSA options
Health savings account for eligible plans with company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation, company stock options and 401k
WRITER is an equal-opportunity employer and is committed to diversity. We donât make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
By submitting your application on the application page, you acknowledge and agree to WRITERâs Global Candidate Privacy Notice.