Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Privacy & Security Program Manager at Nanit

Leads privacy and security compliance program, develops policies and controls, manages vendor risk assessments, and embeds privacy/security best practices across products and operations.

Mid Posted about 16 hours ago RemoteFirstJobs Product
What this role involves

About Nanit:

Welcome to Nanit, the high-growth baby tech company that is changing the way parents experience parenthood through the world’s most advanced baby monitor and parenting products. In 2016, the Nanit baby monitor revolutionized the industry with computer-vision and machine-learning capabilities that helped parents understand their baby’s sleep patterns and allowed them to achieve better sleep quality. Now, the company has become the leader in the connected parenting space, with an incredible customer base of highly-engaged parents who look to Nanit as a source of information and expertise on their parenting journey.

About the Role:

We’re seeking a highly motivated and detail-oriented privacy and security professional to lead and evolve Nanit’s privacy and security compliance program. Reporting directly to the Chief Legal & Administrative Officer, you will build and operationalize the policies, controls, and processes that protect our customers’ data and keep Nanit ahead of an evolving regulatory landscape. You’ll partner closely with Legal, Product, Engineering, and business teams to embed privacy and security best practices into how Nanit builds and operates.

What You’ll Be Doing:

  • Develop, maintain and implement Nanit’s privacy and security policies, standards and processes to ensure compliance with applicable laws, regulations and industry frameworks (e.g., CCPA/CPRA and other U.S. state privacy laws, GDPR, COPPA, and relevant security frameworks such as SOC 2, ISO 27001).
  • Conduct and support regular privacy and security risk assessments, audits and gap analyses across systems, vendors, products and business processes, and drive remediation of identified gaps.
  • Collaborate with stakeholders across the organization to assess AI-related privacy, security and compliance risks.
  • Manage the third-party/vendor risk management program, including privacy and security due diligence, contract review support, ongoing monitoring, and enforcement of Nanit’s data protection requirements.
  • Partner with Product and Engineering teams to embed privacy-by-design and security-by-design principles into new features and products, including data mapping, privacy impact assessments (PIAs/DPIAs), and secure development practices.
  • Monitor emerging privacy and security regulatory developments and industry standards, and advise the Chief Legal & Administrative Officer and Chief Technology Officer and other business stakeholders on impact and required action.
  • Lead the company’s response to security and privacy inquiries from customers, partners and regulators, including questionnaires, audits and due diligence requests.
  • Support incident response efforts for privacy and security incidents, including investigation, documentation, remediation tracking and stakeholder communication.
  • Develop and deliver privacy and security metrics, dashboards and reporting for senior management and, as needed, the board of directors.
  • Design and deliver company-wide training and awareness programs on privacy, data security and compliance best practices.
  • Act as a thoughtful business partner who supports a fast-moving culture, flexible teamwork, and pragmatic, scalable solutions that support growth while protecting the company.

Who You Are:

  • Bachelor’s degree in a related field; relevant certifications (e.g., CIPP, CIPM, CISSP, CIPT, CISM) preferred.
  • 3-5+ years of experience in privacy program management, information security, or a related compliance function, ideally spanning both in-house and cross-functional environments.
  • Hands-on experience supporting or operating privacy and/or security programs aligned to frameworks such as SOC 2, ISO 27001⁄27701, NIST CSF, or similar.
  • Working knowledge of consumer privacy laws (e.g., CCPA/CPRA, GDPR, COPPA) and a willingness to build deeper subject-matter expertise over time.
  • Practical experience with, or exposure to, security incident response, vendor risk management, and identity/access management concepts across on-premise and cloud environments.
  • Able to rapidly interpret relevant laws, regulations and technical requirements, and translate them into practical, actionable and business-friendly guidance.
  • Excellent stakeholder management, communication and collaboration skills; able to explain complex privacy/security concepts to both technical and non-technical audiences.
  • Strong organizational skills, a problem-solving mindset, attention to detail, and the ability to exercise sound judgment in ambiguous environments.
  • Strong technical orientation with an understanding of modern cloud architectures and data flows, and the ability to leverage emerging technologies and AI-powered tools to strengthen privacy, security and compliance programs.

Why You’ll Love Working Here:

  • Hybrid in office schedule
  • Remote work from home month in August
  • Flexible PTO (we trust you to take the time you need)
  • Equity options so you can share in our growth
  • Paid parental leave for all new parents
  • Employee discounts on Nanit products
  • Work from home stipend
  • Monthly team events

EEO, Salary and Location:

This role can be offered as either hybrid or fully remote, with a preference for East Coast candidates.

Salary Range: $130,000 to $150,000 targeted salary plus equity, benefits and unlimited PTO. Nanit’s total compensation package includes access to healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, and basic life insurance. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We are proud to be an equal opportunity employer. We provide employment opportunities without regard to age, race, color, ancestry, national origin, religion, disability, sex, gender identity or expression, sexual orientation, veteran status, or any other protected class.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, analyzes threat patterns, and develops automation to protect fintech infrastructure and respond to security incidents.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, reviews security telemetry for malicious activity, and develops automation tools to protect fintech infrastructure and customer data.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, analyzes threat patterns, and develops automation tooling to identify and respond to security threats across fintech infrastructure.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description
Security Fastly: Threat Detection Analyst (Japanese & English speaking)

Monitor and analyze customer security threats, detect attacks like account takeovers and bot attacks, and provide SOC support for cloud security incidents.

Mid Remote Posted 2 days ago We Work Remotely — Programming
What this role involves

Headquarters: Australia (Remote)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including GitHub, Yelp, Paramount, and JetBlue.

We're building a more trustworthy Internet. Come join us.

 

Threat Detection Analyst - APAC (Japanese Speaking)

Leveraging our growing security product suite, the Threat Detection Analyst role contributes real world security insights to Fastly and our customers as we address Internet-scale threats.  Cloud security solutions enable our customers to benefit from extra visibility across the world and expertise from a central team. 

The Fastly Customer Security Operations Center team at Fastly focuses on operational support of Fastly’s security products and services. The Threat Detection Analyst role within this team focuses on delivering outstanding security services to our customers, specifically as it pertains to integrating and supporting agent software installed on customer systems.  The team works with the security, operations and customer organizations internally  to deliver support solutions for security threats faced on the Internet today.

As a 24 x 7 team, SOC analysts are expected to work Friday - Tuesday, with the daily shift being 0000 - 0800 UTC - (9am - 6pm AEST)

What You'll Do

This role within the Fastly Customer Security Operations Center (CSOC) will be responsible for monitoring and analyzing customer activity, with added emphasis on security functions, like identifying account-takeover or Bot Attacks and WAF administration. Much of the focus will be on security and attacks  around the application layer working with different web technologies. You will have the opportunity to work on some of the world’s most scalable distributed systems that handle around 10 million requests per second, as well as the world-class engineers who developed these systems.

In this position, security engineers will be responsible for the following duties:

  • Be an expert in ensuring security for customers, providing an outstanding response to security issues.
  • Provide deep application-security experience on escalated cases from customers & automated systems.
  • Carry out continuous-improvement work & research to drive our customer security products & operations to be the best they can be. 
  • Contribute to the processes and policies that scale our organization as we grow
  • Create & review reporting to customers on security services
  • Create & manage security content for customer environments

What We're Looking For

  • Prior Experience working in a SOC Environment 
  • Experience with some or all the following foundational technologies: SaaS/Cloud or hybrid cloud deployments; Apache/NGINX/IIS or other web server platforms and associated Application server technologies and frameworks
  • Scripting ability with any of the following: Python, Java, Go, Rust, PHP, Unix/Linux Shell, C#, or other common Web languages
  • Strong infosec background with strong knowledge & practical skills in Application Security.
  • Experience in an IT or security technical support, operations, or research role
  • Unix/Linux or Windows System Administration
  • Ability to work with limited supervision but be a good mentor on security knowledge to the greater team
  • Fluent spoken & written English required, tailoring depth to be a good fit for varying audiences
  • Ability and experience in troubleshooting software products
  • Focussed on delivering exceptional customer experiences.

Work Hours:

  • This position will require you to be available during core business hours. 

Work Location(s) & Travel Requirements 

This position is a remote position based out of (locality), with the possibility of becoming a hybrid position as Fastly expands its presence in the region. 

This position will require travel to the US and Internationally, as required by your role or requested by your manager.

Benefits:

We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too. We support our teams with great benefits that start on the first day of your employment with Fastly. Curious about our offerings? 

We offer a comprehensive benefits package designed to meet your needs. Our offerings may vary depending on the country where you work and are subject to change.

Why Fastly?

  • We have a huge impact. Fastly is a fast growing company in a highly dynamic sector. Not only do our customers have a tremendous user base, but we also support a growing number of open source projects and initiatives. Outside of code, employees are encouraged to share causes close to their heart with others, so we can help lend a supportive hand.
  • We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too.
  • We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful -- every day.
  • We are passionate. Fastly is chock full of diverse and passionate people. We’re not ‘one size fits all’. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.

We’re always looking for humble, sharp, and creative folks to join the Fastly team.

If you think you might be a fit please apply, we would love to hear from you.

Why Fastly?

  • We have a huge impact. Fastly is a small company with a big reach. Not only do our customers have a tremendous user base, but we also support a growing number of open source projects and initiatives. Outside of code, employees are encouraged to share causes close to their heart with others so we can help lend a supportive hand.

  • We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful -- every day.

  • We are passionate. Fastly is chock full of passionate people and we’re not ‘one size fits all’. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.

We’re always looking for humble, sharp, and creative folks to join the Fastly team. If you think you might be a fit please apply! A fully completed application and resume or CV are required when applying.

All job applications must be submitted through our official careers site at www.fastly.com/about/careers. We will never request sensitive information, such as your Social Security number, bank account or credit card information during the application process. All official communication will come from an @fastly.com or @recruiting.fastly.com email address.

Fastly is committed to ensuring equal employment opportunity and to providing employees with a safe and welcoming work environment free of discrimination and harassment. Our employment decisions are based on business needs, job requirements and individual qualifications. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, family or parental status, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.

Consistent with the Americans with Disabilities Act (ADA) and federal or state disability laws, Fastly will provide reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact your Recruiter, or the Fastly Employee Relations team at candidateaccommodations@fastly.com or 501-287-4901. 

Fastly collects and processes personal data submitted by job applicants in accordance with our Privacy Policy. Please see our privacy notice for job applicants.

To apply: https://weworkremotely.com/remote-jobs/fastly-threat-detection-analyst-japanese-english-speaking

Read the full description
Security Government Compliance Technical Specialist at BeyondTrust

Manages technical execution of government compliance programs including FedRAMP, maintains security documentation, and automates compliance monitoring for a cybersecurity SaaS company.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

The Government Compliance Technical Specialist is a full-time individual contributor on BeyondTrust’s Trust & Assurance team, reporting to the Director of Trust & Assurance. This role owns day-to-day technical execution of BeyondTrust’s government compliance programs, including FedRAMP Moderate, TX-RAMP, IRAP, and other emerging public-sector frameworks. Responsibilities include continuous monitoring, writing and maintaining compliance documentation, POA&M management, and building automation to support compliance modernization, including FedRAMP 20x. The ability to interpret, define, and design automation for Key Security Indicators (KSIs) is required.

The ideal candidate has run a FedRAMP program end-to-end and can operate with a high degree of autonomy in a fast-paced cybersecurity product environment. They bring technical depth in NIST 800-53 controls, understand cloud compliance boundaries, and can demonstrate technical automation. This role will also support the program management of government compliance workstreams alongside product, security, and engineering teams.

What You’ll Do

  • Lead technical compliance build activities for FedRAMP 20x readiness, including interpreting Key Security Indicators (KSIs), defining evidence strategies, and coordinating machine-readable compliance outputs.
  • Own day-to-day management and execution of FedRAMP Moderate/Class C continuous monitoring, including deliverables, POA&M tracking, and deviation requests.
  • Author and maintain System Security Plans (SSPs), Security Decision Records (SDRs), and other compliance documentation in human and machine readable formats.
  • Manage findings and remediation tracking across all government compliance programs.
  • Coordinate directly with engineering, security, and cloud operations teams to gather evidence, validate control implementation, and close compliance gaps.
  • Support GovRAMP, TX-RAMP, IRAP, and other government or public-sector compliance programs.
  • Manage day-to-day relationships with Third Party Assessment Organizations (3PAOs) and agency stakeholders.
  • Track and report government program health.
  • Monitor FedRAMP policy changes, framework evolution, and translate changes into compliance roadmap.
  • Automate evidence collection pipelines and indicator health tracking.

What You’ll Bring

  • 3 years minimum in FedRAMP program management and technical compliance.
  • 4–7 years of experience in information security, compliance, or GRC.
  • Demonstrated ability to run a FedRAMP Moderate program, including SSP authorship, ConMon execution, POA&M management, and assessor coordination.
  • Deep working knowledge of NIST SP 800-53 controls and their practical implementation in cloud environments.
  • Strong familiarity with FedRAMP 20x concepts, especially Key Security Indicators (KSIs), machine-readable evidence frameworks, and continuous assessment models.
  • The ability to interpret and define KSIs in the context of BeyondTrust’s compliance posture.
  • Demonstrated ability to coordinate across engineering, infrastructure, legal, and operations teams to gather evidence and drive remediation to closure.
  • Experience building or supporting automated compliance evidence pipelines.
  • Experience with GRC tooling for findings management, evidence collection, and program tracking.
  • Ability to track and manage multiple concurrent workstreams, surface blockers, and maintain delivery cadences.
  • Strong written and verbal communication skills to translate technical compliance information to varying audiences.

Nice To Have

  • Strong familiarity with AI security
  • Experience using AI to develop and deploy applications
  • Experience with GovRAMP, TX-RAMP, IRAP, or other public-sector compliance frameworks.
  • Familiarity with FedRAMP High or DoD IL4/IL5 authorization environments.
  • CISSP or CISA certification.
  • Background in cybersecurity product companies or multi-product SaaS environments.
  • Bachelor’s degree in information security, computer science, or a related field.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

#LI-BS1

Read the full description
Security Vulnerability Manager at BeyondTrust

Designs and operates a vulnerability management program end-to-end, automating processes and driving remediation across products in a regulated environment.

Mid Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

The Vulnerability Manager operates BeyondTrust’s product vulnerability management program end to end. This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome. The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based.

What You’ll Do

  • Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure.
  • Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release.
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors.
  • Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue Critical and High findings, and record risk acceptances as time-bound decisions with an expiry.
  • Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
  • Define the requirements for platform integrations built by Security Engineering, covering scanners, ticketing, asset inventory, and dashboards. Partner with that team through delivery and validate the result against the operational need.
  • Own the program metrics: SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume. Report them on a fixed cadence to security and engineering leadership.
  • Monitor the vulnerabilities that matter most. Maintain a current view of critical exposure across the product portfolio and serve as the authoritative answer to what is open, what it means, and when it closes.
  • Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment across the product fleet, mitigation tracking, and stakeholder communication.

What You’ll Bring

  • 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process rather than participation in one.
  • Demonstrated experience designing and operating vulnerability management process in a regulated or audited environment, and sustaining it through assessment cycles.
  • Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
  • Practical automation skill: scripting in Python or equivalent, workflow and reporting tooling, and use of AI assistants to reduce manual triage and reporting effort. This role automates its own process; it does not build platform software.
  • Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance.
  • Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with the judgment to separate a high score from a real exposure.
  • Working knowledge of cloud services (AWS preferred), containers, Kubernetes, CI/CD, web applications, and APIs, sufficient to assess a finding and evaluate a proposed fix.
  • Ability to drive remediation across engineering teams without direct authority.
  • Clear written and verbal communication with engineers, executives, auditors, and customers.

Nice To Have

  • Direct experience supporting FedRAMP Moderate or High authorization and continuous monitoring, or FedRAMP 20x.
  • Experience defining metrics and building reporting or dashboards for executive and audit audiences.
  • Experience with SaaS, identity security, or privileged access management products.
  • Familiarity with agentic or AI-assisted security workflows.
  • Cloud security certifications (AWS, Azure, GCP), GIAC, CISSP, or equivalent.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

#LI-BS1

Read the full description
Security Security Engineer, Detection & Response

Designs and implements security detection systems and incident response procedures to protect company infrastructure and data.

Mid Posted 3 days ago Jobicy AI
What this role involves
Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize...
Read the full description
Security Cyber Security Engineer II

Designs, implements, and maintains cybersecurity systems and infrastructure to protect organizational assets and data from security threats.

Mid Posted 4 days ago Jobicy AI
What this role involves
About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just...
Read the full description
Security Security & Compliance Manager at Relocity, Inc.

Manages SOC 2 Type II compliance, leads ISO 27001 certification, and oversees security controls, risk assessments, and regulatory framework implementation across the organization.

Mid Posted 5 days ago RemoteFirstJobs Product
What this role involves

What Relocity is Doing

Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.

What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company’s primary advisor on security, privacy, and compliance strategy.

Risk & Governance

  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership

  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness

  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement

  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success

  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

How We Support You and Work-Life Balance…

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.

#LI-Remote

#LI-AC2

Read the full description
Security Security & Compliance Manager at Relocity, Inc.

Maintains SOC 2 Type II compliance, leads ISO 27001 certification, and manages security controls and risk governance across the organization.

Mid Posted 5 days ago RemoteFirstJobs Product
What this role involves

What Relocity is Doing

Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.

What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company’s primary advisor on security, privacy, and compliance strategy.

Risk & Governance

  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership

  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness

  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement

  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success

  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

How We Support You and Work-Life Balance…

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.

#LI-Remote

#LI-AC2

Read the full description
Security Security Engineer, Cloud

Designs, implements, and maintains cloud security infrastructure and protocols to protect systems and data.

Mid Remote Posted 6 days ago Jobicy AI
What this role involves
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built....
Read the full description
Security IT Security Operations Analyst

Monitors security events, responds to incidents, and maintains security infrastructure for enterprise systems.

Mid Posted 7 days ago Himalayas
What this role involves
Our client is an European company leading the development and production of responsible packaging solutions for a wide variety of industries.
Read the full description
Security DevSecOps Engineer - Clearance Required

DevSecOps engineer integrates security practices into development and deployment pipelines for Army contracting systems.

Mid Posted 8 days ago Himalayas
What this role involves
OverviewLMI is seeking a highly skilled DevSecOps Engineer to support Army Acquisition, Training, and Readiness (AT&R) in the sustainment and enhancement of the Army Contract Writing System (ACWS).
Read the full description
Security Privacy & Security Enterprise Engagement Officer

Partners with enterprise stakeholders to translate privacy, security, and AI compliance requirements into operational controls and governance processes.

Mid Posted 8 days ago Himalayas
What this role involves
Position Purpose: Serves as a partner and advisor between enterprise stakeholders and Enterprise Privacy & Security Risk Management (EPSRM), ensuring regulatory and contractual privacy, security, AI, and business continuity requirements are translated into practical operational controls, processes, and governance activities.
Read the full description
Security Application Security Engineer II - Contract ( 6 months ) at Bugcrowd

Triages and validates security vulnerability submissions from researchers, communicates with clients and researchers, and escalates critical security incidents for bug bounty programs.

Mid Posted 8 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security Application Security Engineer II - Contract ( 6 months ) at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates with clients and security teams on bug bounty programs.

Mid Posted 8 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security SOC Engineer (Incident Response)

Monitors security alerts, investigates incidents, and responds to threats within the SOC environment.

Mid Posted 9 days ago Himalayas
What this role involves
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users.
Read the full description
Security CyberSecurity Analyst at Avertium

Monitor and respond to security alerts, provide technical guidance to clients, manage vulnerabilities, and maintain security infrastructure across applications and infrastructure.

Mid Posted 9 days ago RemoteFirstJobs Product
What this role involves

Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique “Assess, Design, Protect” methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network.  The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives.  The CS Analyst will provide security analytics and assistance with security support requests.

Responsibilities:

  • Monitor, respond to, and analyze SIEM alerts from monitoring tools.
  • Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products.  Handles daily incidents; monitors, tracks, analyzes and records.
  • Work with vendors, outside consultants, and other third parties to improve information security within the organization.
  • Responds to security related tickets escalated from clients, and works collaboratively with the client to assist in resolving security events.
  • Work with other IT professionals to resolve fast moving vulnerabilities such as spam, virus, spyware and malware.
  • Monitor security vulnerability information from vendors and third parties.
  • Create Weekly and Monthly Status Reports, including daily technical task reports and contract deliverables.

Qualifications for Success:

  • Strong written, verbal and non-verbal communication skills, especially conveying complex information in an understandable manner.
  • CISSP, CISA or GIAC certification is a plus.
  • A minimum of 2-4 years of experience working with Microsoft Active Directory.
  • Experience in managing an organization’s PCI, HIPAA, or SSAE16 certification is preferred.
  • Analyze and resolve complex technical and business problems.
  • Must have proficient knowledge with three or more of the following technologies:  Application / stateful / UTM firewalls; SIEM; DLP; Web content filtering; Web application firewalls (WAF); Vulnerability scanning and penetration testing; IPS/IDS; Security Operations Center operations; Wireless Networking; UNIX, AIX & Solaris, Linux, Windows Server Operating Systems; Endpoint and Malware
  • Knowledge with NIST, FISMA, DIACAP.
  • Knowledge of Windows 2003-12 server platforms.
  • Knowledge of VMware and VM server platforms.
  • Knowledge of UNIX server platforms.
  • Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, Windows.
  • Web and mail logged events.
  • Ability to analyze IANA assigned ports (well known, registered, dynamic and private ports).
  • Ability to troubleshoot common network devices, network, vulnerabilities and network attack patterns.
  • Ability to troubleshoot Windows Event IDs.
  • Interact with all levels of management.
  • Make decisions based on many variables.
  • Manage multiple tasks/projects simultaneously.
  • Minimum of Bachelor’s Degree in computer science, telecommunications management, electrical engineering, or a related field or have 4 years of experience.
  • Advanced network and systems certifications such as CCNP, CCNA and CISSP, are preferred.
  • Other industry certifications such as ITIL, Microsoft, Juniper and Checkpoint are a plus.
  • #LI-CS1

In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.

Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security engineer, application security at WRITER

Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.

Mid Hybrid Posted 9 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description