Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. 🚀
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
Designs and implements AI security controls, guardrails, and sandboxing patterns across company systems while auditing AI tool usage and training users on secure practices.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.
With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai
Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.
You will…
- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.
- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.
- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.
- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.
- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.
- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.
- Document guidance and patterns that a non-security audience can actually follow without needing a security background.
Qualifications:
- Bachelor’s degree in Computer Science or a related field.
- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.
- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.
- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.
- Strong communication skills - you work with engineers as a partner.
Bonus:
- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.
- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.
- Background in autonomous vehicles, robotics, or other safety-critical systems
The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations. Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.
Perks/Benefits:
Waabi provides a competitive benefits package that includes:
- Competitive compensation and equity awards.
- Health and Wellness benefits that include Medical, Vision and Dental coverage.
- Unlimited Vacation.
- Flexible hours and Work from Home support.
- Daily drinks, snacks and catered meals (when in office).
- Regularly scheduled team building activities and social events.
- As we grow, this list continues to evolve!
Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!
Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Establishes AI security controls, designs guardrails for enterprise AI tool adoption, and audits AI integrations to manage risks across the organization.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.
With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai
Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.
You will…
- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.
- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.
- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.
- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.
- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.
- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.
- Document guidance and patterns that a non-security audience can actually follow without needing a security background.
Qualifications:
- Bachelor’s degree in Computer Science or a related field.
- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.
- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.
- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.
- Strong communication skills - you work with engineers as a partner.
Bonus:
- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.
- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.
- Background in autonomous vehicles, robotics, or other safety-critical systems
The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations. Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.
Perks/Benefits:
Waabi provides a competitive benefits package that includes:
- Competitive compensation and equity awards.
- Health and Wellness benefits that include Medical, Vision and Dental coverage.
- Unlimited Vacation.
- Flexible hours and Work from Home support.
- Daily drinks, snacks and catered meals (when in office).
- Regularly scheduled team building activities and social events.
- As we grow, this list continues to evolve!
Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!
Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Monitors and responds to security threats, manages application security vulnerabilities, and ensures compliance with security protocols for Veeam's product infrastructure.
Monitors security systems, analyzes threats, and helps protect organizational infrastructure from cyber attacks.
Leads cybersecurity investigations across cloud, endpoint, and network environments, identifies and remediates security incidents using SIEM and EDR tools.
Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.
Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.
The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.
The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.
#LI-REMOTE
#LI-GK1
We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.
California applicants can find a copy of Oportun’s CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/.
We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).
Deploys, manages, and optimizes CrowdStrike security platform for enterprise customers while providing operational support and cybersecurity advisory services.
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
Job Description
As the Crowdstrike Engineer you will possess solid industry experience, certifications, with proven experience planning, deployment, field and operational support of the CrowdStrike platform and related applications and solutions in a distributed and complex enterprise. The Sr. Crowdstrike Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation, optimization/utility and follow-on customer support for the CrowdStrike platform and applications. You will also be involved in customer advisement regarding best practices and identifying areas to add value to their cybersecurity and cyber-adjacent solution deployments. This role has the potential to develop into a practice lead of a product or capability focused practice.
Additional skills and experience that are highly valued
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Leads a 60-person Security Operations Center team, managing incident response, customer escalations, analyst performance, and SOC service delivery across managed security services.
Position: Manager, Security Operations Centre (SOC)
Location: Hybrid – College Park, MD (On-site 2–3 days per week)
Work Authorization: US Citizenship Required
BlueVoyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of roughly 60 employees, playing a critical role in protecting client relationships and driving retention.
This is a client-facing leadership role responsible for shaping how customers experience the SOC — from escalation handling through the metrics and reporting that inform leadership decisions. The role carries strong potential for growth into a higher-level leadership position as the team and business scale, making it a great fit for an ambitious leader who wants to build and shape a growing organization.
What You’ll Do:
What You’ll Bring:
Technical Expertise:
Nice to Have:
Education:
Bachelor’s degree in Information Security, Computer Science, or another technology / engineering-related field preferred. Candidates with proven experience in security/network operations will also be considered.
Why BlueVoyant?
About BlueVoyant
BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.
Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.
Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats..
All employees must be authorized to work in the United States of America. BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.
Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.
#LI-AH1
#LI-Hybrid
Important Information for Applicants: BlueVoyant uses AI-assisted tools within our applicant tracking system to help identify candidates whose experience and skills best match the requirements of a role. This technology provides hiring teams with added insights to support fair and efficient hiring decisions. All applications are reviewed by a member of our hiring team, and final hiring decisions are made by humans, not AI. By submitting your application, you acknowledge that AI tools may assist in the evaluation of your resume as part of the recruitment process.
Interview Expectations: As part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we embrace the use of AI within our business and recruitment process, we do not permit its use during interviews. Any suspected use of AI during an interview will be challenged, and this may include the use of detection tools.
BlueVoyant Candidate Privacy Notice:To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice
Develops security engineering processes and infrastructure-as-code solutions to ensure FedRAMP and NIST compliance for government cloud environments.
Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we’re now powered by Google, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.
Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!
Minimum qualifications
6+ years of experience in security engineering, DevOps, and systems engineering, with a proven ability developing processes and writing code to solve security/compliance problems.
4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, with a proven ability to assess risk, reduce risk, and build engineering solutions that enable compliance.
Deep understanding of the differences between FR 20x and CR26 ruleset for Rev5 authorizations and the impacts these rule changes have on Cloud Service Providers (CSPs).
Experience working in a cloud-native environment with DevSecOps technologies, specifically including CI/CD, Containers, and Kubernetes.
Strong proficiency in scripting and Infrastructure as Code (IaC), with specific requirements for Shell Scripting, Python, Terraform or OpenTofu, and Preferred AI Harness (Claude Code, OpenAI Codex).
Experience with cloud platforms in government spaces.
Preferred qualifications
Experience with AWS GovCloud.
Experience in Azure Government, Google Cloud for Government (Assured Workloads), or equivalent and associated security services.
Experience with DevSecOps technologies including Microservices, GitOps, and Observability / Logging / SIEM / Platforms.
Experience with Packer, other Configuration as Code tools, and Policy as Code tools.
Experience automating compliance validation using cloud-native tools.
About the job
The Public Sector Compliance Operations Team aims to accelerate Wiz’s growth by developing a comprehensive strategy, in tight partnership with all other organizations, to drive customer value and adoption. As we continue to grow at an incredible speed, we work to ensure each sales team member is set up for success at every phase. We take both a bird’s eye view and dive into the weeds to solve problems as a team to drive employee success and revenue.
We are seeking an experienced Compliance Engineer to serve as the strategic technical lead for Wiz’s FedRAMP CR26 initiative. You will define the long-term technical roadmap by architecting comprehensive compliance-as-code solutions, utilizing both Wiz’s native features and custom-developed automations outside the platform to efficiently address CR26 Class D rule changes. This individual contributor role bridges complex regulatory requirements with scalable engineering practices, ensuring our cloud services meet stringent federal and defense standards while maintaining high availability, security, and audit-readiness.
You will be asked to quickly learn the challenges of the business and find ways to simplify processes within our compliance operations to increase productivity and efficiency. More importantly, the role requires a personality that promotes collaboration and unity.
Responsibilities
Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to an automated, real-time telemetry model.
Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.
Engineer evidence generation frameworks, significantly reducing manual effort required for 3PAO assessments and automating compliance validation for control implementation verification.
Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments.
Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).
Collaborate cross-functionally with legal, product, engineering, devops, architecture, security, and federal customer teams to scope technical compliance verification and validation requirements for new features and services.
Mentor others on FedRAMP/DoW compliance best practices and contribute to internal training programs.
Candidates must meet EAR part 772 and ITAR 120.15 definition of a U.S. person (Any individual who is granted U.S. citizenship; or any individual who is granted U.S. permanent residence (green card holder); or any individual who is granted status as a “protected person”) and that they reside in the contiguous United States.
Compensation + Benefits
Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
The US base salary range for this full-time position is listed below.
US Base Pay Range
$174,000—$238,000 USD
Applicants must have the legal right to work in the country where the position is based, without the need forvisa sponsorship.This role does not offervisasponsorship.
Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.
By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz’s Privacy Policy.
Leads cybersecurity investigations across cloud, endpoint, and network environments, identifying and remediating security incidents while correlating data from SIEM and EDR tools.
Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.
Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.
The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.
The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.
#LI-REMOTE
#LI-GK1
We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.
California applicants can find a copy of Oportun’s CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/.
We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).
Designs, deploys, and manages CrowdStrike security platform implementations for enterprise customers while providing technical guidance on cybersecurity best practices.
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.
Job Description
As the Crowdstrike Engineer you will possess solid industry experience, certifications, with proven experience planning, deployment, field and operational support of the CrowdStrike platform and related applications and solutions in a distributed and complex enterprise. The Sr. Crowdstrike Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation, optimization/utility and follow-on customer support for the CrowdStrike platform and applications. You will also be involved in customer advisement regarding best practices and identifying areas to add value to their cybersecurity and cyber-adjacent solution deployments. This role has the potential to develop into a practice lead of a product or capability focused practice.
Additional skills and experience that are highly valued
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Monitors security systems, analyzes threats, and implements security controls to protect organizational IT infrastructure.
Develops and implements security measures, monitors systems for threats, and maintains information security infrastructure for the organization.
Lead threat assessment and case management for a region, conducting behavioral threat evaluations and coordinating security response across organizational stakeholders.
Headquarters: Remote - Australia
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.
What you'll do:
Required Skills and Experience:
Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).
Annual base salary range (excluding equity and bonus):$200,900—$200,900 AUDTo apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager
Manages threat assessment cases for employees and facilities, conducts behavioral threat analysis, and coordinates security incident response across regional operations.
Headquarters: Remote - EMEA
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.
What you'll do:
Required Skills and Experience:
Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).
Annual base salary range (excluding equity and bonus):£95,490—£106,100 GBPTo apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-1
Manages threat assessment cases end-to-end, conducts behavioral threat assessments, coordinates incident response, and partners cross-functionally to mitigate security risks to employees, executives, and facilities.
Headquarters: Remote - Singapore
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.
What you'll do:
Required Skills and Experience:
Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).
Annual base salary range (excluding equity and bonus):$212,200—$212,200 SGDTo apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-2
Develops and manages global financial crimes screening programs, setting standards for AML/sanctions controls and driving risk management strategy across Stripe's payment infrastructure.
Headquarters: US-Chicago; US-Atlanta; US-Remote; Canada-Toronto; Canada-Remote
Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.
The Financial Crimes Risk Strategy team owns our first-line AML and sanctions programs globally. We own the end-to-end lifecycle of financial crime controls. We set the global standards that govern how risk is managed across our programs, design and drive the development of controls, infrastructure, and tooling with Engineering, Product, and Data Science, and maintain their effectiveness as our products and the regulatory landscape evolve. We build fast, with data, and with AI integrated into how financial crime risk is detected, managed, and monitored across everything Stripe builds.
As a Risk Strategist on the Financial Crimes Risk Strategy team, you'll own our global screening programs — spanning sanctions, PEP, and negative news — setting the standards that govern how screening risk is managed, designing and driving the controls that operationalize those standards, and ensuring they remain effective as our products and the regulatory landscape evolve. Being effective in this role means going deep on both the domain and the data — we don't separate the two.
You'll partner closely with Product, Engineering, Data Science, Compliance, Legal, other Risk Strategy functions, and Operations to ensure screening considerations are embedded in every product and market decision. Beyond protecting against risk, you'll drive innovation in how Stripe approaches screening — staying ahead of regulatory change and pushing the boundaries of what effective, scalable financial crime risk management looks like at a global payments company.
We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.
To apply: https://weworkremotely.com/remote-jobs/stripe-risk-strategist-screening-financial-crimes
Lead Coinbase's global IT and security audit program, managing audits across cloud infrastructure, security operations, and risk management while overseeing a distributed team of auditors.
Headquarters: Remote - USA
Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.
As the Senior Manager, Internal IT & Security Audit, you'll lead Coinbase's global IT and security audit program. Reporting to the Head of Internal Audit, you will operate within an independent third line of defense that maintains functional accountability to the Audit Committee. You'll own the multi-year IT and security audit roadmap, ensuring coordinated coverage across all regions (US, EMEA, UK, APAC) and alignment with Coinbase's enterprise risk profile and regulatory expectations. Your leadership will directly strengthen how Coinbase identifies, evaluates, and mitigates technology and security risks across the organization.
What you'll do:
Required Skills and Experience:
Req ID: #P76564
#LI-Remote
Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)).
Annual base salary range (excluding equity and bonus):$201,365—$236,900 USD
To apply: https://weworkremotely.com/remote-jobs/coinbase-senior-manager-internal-audit-it
Builds and operates enterprise security controls, tooling, and automation across cloud and corporate environments while developing detection content and security automation.
The Security Operations Engineer builds and operates security controls, tooling, and automation across DeepHealth’s cloud and corporate environments. This role is responsible for configuring, integrating, and maintaining the enterprise security tooling stack, developing detection content, and automating security operations tasks so that controls are repeatable, version-controlled, and auditable.
Working within DeepHealth’s established security frameworks and under the direction of the Director, Security Operations, this position operates and tunes security controls, detection content, and guardrails. Independent validation of those controls sits with the security operations watch function — a deliberate separation that keeps the control environment defensible under audit. Remediation follows system ownership across Cloud Operations, Platform, and Application Development; this role supplies technical guidance and implements fixes directly where the control is security-owned.
This position operates within a regulated healthcare environment across a global operating footprint, with obligations under HIPAA, ISO/IEC 27001, and SOC 2. The role reports to the Director, Security Operations, with future reporting to the Manager, Security Operations as that position is established.
· Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments.
· Develop and maintain detection content, correlation rules, and response automation within the SIEM and SOAR platform.
· Onboard new log sources and telemetry feeds, validating ingestion completeness, parsing accuracy, and field normalization.
· Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation.
· Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality.
· Implement and maintain security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.
· Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework, so that controls are version-controlled, repeatable, and auditable.
· Implement policy-as-code and preventive guardrails using native cloud policy engines or an equivalent open policy framework.
· Support cloud security posture management across all cloud environments, including finding deduplication, theme mapping, and routing to owning teams.
· Harden cloud resources including compute, storage, database, container, and serverless services against established benchmarks.
· Configure and maintain Microsoft 365 and Entra ID security controls, including conditional access, identity protection, and Defender workloads in a hybrid directory environment.
· Implement and maintain least-privilege access models, roles, and policies across multiple cloud identity systems.
· Implement container and Kubernetes security controls, including role-based access control, workload security standards, image scanning, and runtime protection.
· Implement and maintain secrets management practices and tooling, and support the elimination of hard-coded credentials across environments.
· Operate vulnerability management tooling, validate scan coverage, and translate raw scanner output into prioritized, owner-routed findings.
· Provide technical remediation guidance to cloud, platform, identity, application, and endpoint owners, who retain accountability for closure of findings in their systems.
· Implement engineering fixes for findings that fall to security-owned tooling and configuration.
· Support remediation tracking for penetration test and vulnerability assessment findings by supplying technical detail and validating that fixes are technically sound.
· Support incident detection and response through hands-on technical investigation, including log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review.
· Support escalations raised by the external managed security partner by supplying technical analysis and environment context.
· Provide feedback into detection quality and alert tuning to reduce noise and improve signal for the monitoring function.
· Contribute technical findings to post-incident review, and implement the resulting control and detection improvements.
· Participate in tabletop exercises and resilience testing, and act on the technical gaps those exercises surface.
· Document all engineering changes to security controls through the change management process, including validation criteria and rollback plans.
· Produce and maintain runbooks, playbooks, and technical operating procedures for repeatable security operations tasks.
· Write clear, documented, and reviewable code and configuration so that work can be inspected, maintained, and handed over without dependence on any one individual.
· Support audit, certification, and customer assurance activities by producing technical evidence on request.
· Maintain accurate inventory of security tooling, control coverage, licensing position, and control operating status.
· Maintain strict confidentiality of security testing results, control configuration detail, and investigative material, and follow established standards for external disclosure.
PLEASE NOTE: This is not an exhaustive list of all duties, responsibilities and requirements of the position described above. Other functions may be assigned and management retains the right to add or change duties at any time.
Minimum Qualifications, Education and Experience
· 4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role. (Required)
· Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience. (Required)
· 2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred. (Required)
· 2+ years operating and tuning a SIEM platform, including working with detection content and log sources. (Required)
· 1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment. (Required)
· Working knowledge of security automation; experience with scripting and infrastructure-as-code is required, with Terraform experience preferred. (Required)
· Working knowledge of cloud security posture management and preventive controls. (Required)
· Working knowledge of container and Kubernetes security, including role-based access control and image scanning. (Required)
· Working knowledge of secrets management tooling and practices. (Required)
· Practical experience with endpoint detection and response tooling. (Required)
· Working knowledge of vulnerability management and the finding remediation lifecycle, including risk-based prioritization. (Required)
· Scripting capability in at least one of: Python, PowerShell, or Bash. (Required)
· Familiarity with recognized security frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2. (Required)
· Able to communicate technical findings clearly in writing and verbally to both technical and non-technical audiences. (Required)
· Able to manage assigned work independently and escalate appropriately. (Required)
· Available to support incident response activity outside standard business hours as required. (Required)
· Microsoft Office experience. (Required)
· Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification. (Preferred)
· Experience in healthcare, medical device, or another regulated industry, and working familiarity with HIPAA obligations. (Preferred)
· Experience working alongside or integrating with a managed security service provider. (Preferred)
Quality Standards
· Communicates, cooperates, and consistently functions professionally and harmoniously with all levels of supervision, co-workers, visitors, and vendors.
· Demonstrates initiative, personal awareness, professionalism and integrity, and exercises confidentiality in all areas of performance.
· Follows all local, regional and country laws concerning employment.
· Follows all DeepHealth policies and procedures.
· Follows data privacy, compliance, safety and confidentiality standards at all times.
· Practices universal safety precautions.
· Promotes good public relations on the phone and in person.
· Adapts and is willing to learn new tasks, methods, and systems.
· Reports to work regularly as scheduled; consistently punctual with respect to working hours, meal and rest breaks, and maintains satisfactory personal attendance in accordance with DeepHealth guidelines.
· Completes job responsibilities in a quality and timely manner.
Travel
This position requires domestic / international travel up to 10%.
Working Environment
Remote
Physical Demands
This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally.
Work Authorization / Visa Sponsorship: DeepHealth does not provide immigration sponsorship for this position, including sponsorship for employment-based visas or other work authorization requiring employer sponsorship. Candidates must be legally authorized to work in the United States without current or future sponsorship from DeepHealth for the duration of employment.
Conducts cybersecurity assessments, develops security strategies and ISMS frameworks, and identifies organizational risks.
Implements and maintains security infrastructure on Oracle Cloud Platform, managing access controls, compliance, and threat detection.