Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Applied AI Security Engineer at Waabi

Designs and implements AI security controls, guardrails, and sandboxing patterns across company systems while auditing AI tool usage and training users on secure practices.

Mid Posted about 3 hours ago RemoteFirstJobs Product
What this role involves

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.

With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai

Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.

You will…

- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.

- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.

- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.

- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.

- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.

- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.

- Document guidance and patterns that a non-security audience can actually follow without needing a security background.

Qualifications:

- Bachelor’s degree in Computer Science or a related field.

- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.

- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.

- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.

- Strong communication skills - you work with engineers as a partner.

Bonus:

- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.

- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.

- Background in autonomous vehicles, robotics, or other safety-critical systems

The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations.  Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.

Perks/Benefits:

Waabi provides a competitive benefits package that includes:

- Competitive compensation and equity awards.

- Health and Wellness benefits that include Medical, Vision and Dental coverage.

- Unlimited Vacation.

- Flexible hours and Work from Home support.

- Daily drinks, snacks and catered meals (when in office).

- Regularly scheduled team building activities and social events.

- As we grow, this list continues to evolve!

Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!

Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Applied AI Security Engineer at Waabi

Establishes AI security controls, designs guardrails for enterprise AI tool adoption, and audits AI integrations to manage risks across the organization.

Mid Posted about 3 hours ago RemoteFirstJobs Product
What this role involves

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.

With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai

Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.

You will…

- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.

- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.

- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.

- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.

- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.

- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.

- Document guidance and patterns that a non-security audience can actually follow without needing a security background.

Qualifications:

- Bachelor’s degree in Computer Science or a related field.

- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.

- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.

- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.

- Strong communication skills - you work with engineers as a partner.

Bonus:

- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.

- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.

- Background in autonomous vehicles, robotics, or other safety-critical systems

The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations.  Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.

Perks/Benefits:

Waabi provides a competitive benefits package that includes:

- Competitive compensation and equity awards.

- Health and Wellness benefits that include Medical, Vision and Dental coverage.

- Unlimited Vacation.

- Flexible hours and Work from Home support.

- Daily drinks, snacks and catered meals (when in office).

- Regularly scheduled team building activities and social events.

- As we grow, this list continues to evolve!

Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!

Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Cyber-Security Operations Analyst III, Product AppSec

Monitors and responds to security threats, manages application security vulnerabilities, and ensures compliance with security protocols for Veeam's product infrastructure.

Mid Posted about 3 hours ago Jobicy AI
What this role involves
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI...
Read the full description
Security Junior Cyber Security Analyst (R-00168)

Monitors security systems, analyzes threats, and helps protect organizational infrastructure from cyber attacks.

Junior Posted about 3 hours ago Himalayas
What this role involves
True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes.
Read the full description
Security Information Security Engineer (R14207) at Oportun

Leads cybersecurity investigations across cloud, endpoint, and network environments, identifies and remediates security incidents using SIEM and EDR tools.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

ABOUT OPORTUN

Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.

WORKING AT OPORTUN

Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.

POSITION OVERVIEW

The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
  • Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation.
  • Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
  • Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
  • Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks.
  • Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.
  • Experience performing root cause analysis and correlating activity across multiple security technologies.
  • Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders.
  • Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations.
  • Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.
  • Continuous learning, security automation, and process improvement.

WHO YOU ARE / WHAT YOU BRING

  • Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation
  • Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality
  • Experience in conducting purple team exercises
  • Coordinate external takedowns and threat remediation with third-party providers.
  • Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
  • Experience using Wiz Cloud Native Application Protection Platform (CNAPP)
  • Experience conducting Threat Hunting using the MITRE ATT&CK framework.
  • Experience developing, tuning, or maintaining security detections and SIEM use cases.
  • Experience with SOAR platforms and security automation.
  • Experience conducting fraud investigations or partnering with Fraud Operations.
  • Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud.
  • Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.

#LI-REMOTE

#LI-GK1

We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.

California applicants can find a copy of Oportun’s CCPA Notice here:  https://oportun.com/privacy/california-privacy-notice/.

We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).

Read the full description
Security Sr. Crowdstrike Engineer (R-00220) at True Zero Technologies

Deploys, manages, and optimizes CrowdStrike security platform for enterprise customers while providing operational support and cybersecurity advisory services.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

Job Description

As the Crowdstrike Engineer you will possess solid industry experience, certifications, with proven experience planning, deployment, field and operational support of the CrowdStrike platform and related applications and solutions in a distributed and complex enterprise.   The Sr. Crowdstrike Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation, optimization/utility and follow-on customer support for the CrowdStrike platform and applications. You will also be involved in customer advisement regarding best practices and identifying areas to add value to their cybersecurity and cyber-adjacent solution deployments.  This role has the potential to develop into a practice lead of a product or capability focused practice.

Qualifications

  • 3+years of implementing, managing, and expanding Crowdstrike and related use cases for customers in a variety of public sector and commercial customers.
  • Bachelor’s degree in Computer Science, Information Technology, Computer Engineering, or related discipline, and 5 years of experience performing IT deployments or in an end user/customer environment
  • Deep understanding of software deployment technologies, and understanding of security operations, practices, and methodologies
  • Highly knowledgeable on Windows, Mac, and Linux platforms
  • Working knowledge of Microsoft Office applications, Word, Excel, Access, PowerPoint, etc.
  • Good communication and collaboration skills
  • Solid analytical/problem solving skills with capability to identify solutions to unusual and complex problems
  • High level of motivation; self-starter; results driven
  • Ability to travel as needed on-site to customers

Additional skills and experience that are highly valued

  • Serve as primary engineering resource responsible for end-to-end integration and operational optimization.
  • Strong background in Crowdstrike Falcon, EDR, ITP, and various other related modules
  • Directly support and mature SOC capibilities
  • Experience deploying and operating prominent enterprise EDR platforms such as Tanium, FireEye HX, Cylance, Carbon Black, Microsoft Defender, and SentinelOne in large and complex environments
  • Knowledge of cloud platforms and technologies, such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)
  • Ability to gain secret clearance if needed

Responsibilities

  •  Provide technical implementation, configuration, and troubleshooting assistance with the deployment of the CrowdStrike platform and associated applications
  • Install CrowdStrike software both remotely and physically
  • Utilize and engineer native and 3rd party software deployment technologies
  • Develop scripts and processes around software deployment
  • Plan and report software deployment status
  • Work closely and collaboratively with customer information technology teams
  • Leveraging CrowdStrike applications (for example, but not limited to, Spotlight and Discover) provide support to customers in vulnerability and asset management
  • Assist customers with the integration of CrowdStrike into existing tools
  • Troubleshoot customer deployment issues across small to large enterprises
  • Establish roadmap and iterative improvement of endpoint detection capabilities and tooling integrations and use of Crowdstrike with maturity model approach
  • Identify opportunities to expand Crowdstrike and other tools to reduce security related enterprise risk
  • Create, enhance, and continuously update documentation and knowledge base (e.g., user guides, quick starts, documentation, demos)
  • Interview additional candidates applying to True Zero Technologies

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Manager, Security Operations Centre (SOC) at BlueVoyant

Leads a 60-person Security Operations Center team, managing incident response, customer escalations, analyst performance, and SOC service delivery across managed security services.

Lead Hybrid Posted 1 day ago RemoteFirstJobs Product
What this role involves

Position: Manager, Security Operations Centre (SOC)

Location: Hybrid – College Park, MD (On-site 2–3 days per week)

Work Authorization: US Citizenship Required

BlueVoyant is seeking a Manager, Security Operations Center (SOC) to lead a growing SOC organization of roughly 60 employees, playing a critical role in protecting client relationships and driving retention.

This is a client-facing leadership role responsible for shaping how customers experience the SOC — from escalation handling through the metrics and reporting that inform leadership decisions. The role carries strong potential for growth into a higher-level leadership position as the team and business scale, making it a great fit for an ambitious leader who wants to build and shape a growing organization.

What You’ll Do:

  • Lead, develop, and manage a team of Team Leads, Trainers, and Security Analysts, providing strategic direction, coaching, and performance management
  • Assume full responsibility and accountability for ensuring all SOC customers receive world-class service
  • Own the management of customer escalations, with the primary goal of client retention, partnering closely with Client Success on remediation plans and client communication
  • Provide oversight and management of Team Leads and the wider Analyst team, ensuring consistent quality and performance across the SOC
  • Lead post-incident review meetings to capture lessons learned following the resolution of critical events
  • Ensure key Security Operations actions incorporate relevant customer impact considerations by engaging key stakeholders and communicating known/suspected implications of technical decisions
  • Validate that Security Operations activities adequately address customer requirements across all MSS services
  • Oversee operations in deterring, identifying, monitoring, investigating, and analyzing network intrusions
  • Supervise complex event investigation and incident declaration, ensuring events are properly identified, analyzed, and escalated to incidents
  • Ensure the team’s incident investigation, handling, response, and documentation meet quality and SLA standards
  • Assist in the advancement of security policies, procedures, and automation
  • Develop incident response reporting and policy updates as needed
  • Partner cross-functionally with Client Success, Content Engineering, Threat Hunt, and Product leadership to drive service improvements and represent the SOC’s priorities
  • Develop and maintain SOC performance metrics, delivering regular reporting on team performance, incident trends, and customer outcomes to leadership
  • Regularly communicate with customer IT teams to inform them of issues, help them remediate, and ensure continued business as usual
  • Maintain a strong awareness of the current threat landscape

What You’ll Bring:

  • Ability and willingness to commute to the College Park, MD office 2–3 days per week
  • ​​​​​​​Experience working within a global organization, partnering with distributed teams across multiple regions and time zones
  • Prior experience managing managers or team leads, with direct accountability for team performance and development
  • Ability to handle high-pressure situations in a productive and professional manner
  • Ability to work directly with customers to understand requirements for and feedback on security services, including managing escalations to protect client relationships
  • Advanced written and verbal communication skills, with the ability to present complex technical topics in clear and easy-to-understand language
  • Strong teamwork and interpersonal skills, including the ability to work effectively with a globally distributed team
  • Able and willing to work in a 24/7/365 environment

Technical Expertise:

  • Knowledge of and experience with the Microsoft Security Stack (Defender, Sentinel etc)
  • ​​​​​​​Knowledge of and experience with intrusion detection/prevention systems and SIEM software
  • Advanced knowledge and understanding of network protocols and devices
  • Advanced experience with Mac OS, Windows, and Unix systems
  • Ability to analyze event logs and recognize signs of cyber intrusions/attacks
  • Strong knowledge of: SIEM, Packet Analysis, SSL Decryption, Malware Detection, HIDS/NIDS, Network Monitoring Tools, Case Management System, Knowledge Base, Web Security Gateway, Email Security, Data Loss Prevention, Anti-Virus, Network Access Control, Encryption, and Vulnerability Identification

Nice to Have:

  • Experience partnering with or managing teams based in the Philippines
  • ​​​​​​​Experience in network/host vulnerability analysis, intrusion analysis, digital forensics, penetration testing, or related areas
  • 8+ years of hands-on SOC/TOC/NOC experience
  • Certifications such as GCIA, GCIH, GCFA, GCFE, CISSP, Security+, Network+, CEH, RHCA, RHCE, MCSA, MCP, or MCSE
  • Familiarity with tools such as IDA Pro, PEiD, PEview, Procmon, Snort, Bro, Kali Linux, Metasploit, NMAP, and Nessus
  • Familiarity with GPO, Landesk, or other IT infrastructure tools
  • Understanding of and/or experience with one or more programming languages: .NET, PHP, Perl, Python, Java, Ruby, C, C++

Education:

Bachelor’s degree in Information Security, Computer Science, or another technology / engineering-related field preferred. Candidates with proven experience in security/network operations will also be considered.

Why BlueVoyant?

  • Work alongside experienced SOC and cybersecurity leaders, including former government cyber professionals and industry veterans
  • ​​​​​​​Gain exposure to complex customer environments and a wide range of MSS services across industries
  • Join a global, mission-driven cybersecurity company defending organizations worldwide with cutting-edge data, technology, and expertise
  • Competitive compensation and a comprehensive benefits package, with support for wellbeing, development, and career growth

About BlueVoyant

BlueVoyant is an AI-driven cybersecurity company dedicated to standing between our customers and cyber threats. By combining human, artificial, and proprietary intelligence, we deliver a unified solution that protects every organization’s network, identities, vendors, and digital footprints as a single attack surface. The company’s award-winning Microsoft Security expertise helps organizations maximize their security investments while reducing risk and ensuring compliance.

Led by CEO, John Hernandez, BlueVoyant’s highly skilled team includes former government cyber officials with extensive frontline experience in responding to advanced cyber threats on behalf of the National Security Agency, Federal Bureau of Investigation, Unit 8200, and GCHQ, together with private sector experts. BlueVoyant services utilize large real-time datasets with industry leading analytics and technologies.

Founded in 2017 by Fortune 500 executives, including Chairman of the Board, Jim Rosenthal, Vice Chairman, Tom Glocer, and former Government cyber officials, BlueVoyant is headquartered in New York City and has offices in Maryland, Tel Aviv, London, Budapest, and Latin America and is committed to building a workplace where talented people are empowered to do their best work in the fight against global cyber threats..

All employees must be authorized to work in the United States of America.  BlueVoyant provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, or genetics. In addition to federal law requirements, BlueVoyant complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.

Disclaimer: Please note that pursuant to contractual requirements and applicable law, for employees to perform work on some of the company’s federal contracts, U.S. citizenship is required. Accordingly, an employee’s ability to perform work on such contracts is contingent upon the company’s verification of the employee’s citizenship status.

#LI-AH1

#LI-Hybrid

Important Information for Applicants: BlueVoyant uses AI-assisted tools within our applicant tracking system to help identify candidates whose experience and skills best match the requirements of a role. This technology provides hiring teams with added insights to support fair and efficient hiring decisions. All applications are reviewed by a member of our hiring team, and final hiring decisions are made by humans, not AI. By submitting your application, you acknowledge that AI tools may assist in the evaluation of your resume as part of the recruitment process.

Interview Expectations: As part of our interview process, we assess your experience through real-time discussion, so we expect responses to be your own. While we embrace the use of AI within our business and recruitment process, we do not permit its use during interviews. Any suspected use of AI during an interview will be challenged, and this may include the use of detection tools.

BlueVoyant Candidate Privacy Notice:To understand how we secure and manage your personal data upon submitting a job application, please see our Candidate Privacy Notice, which can be found here - Candidate Privacy Notice

Read the full description
Security Compliance Engineer - Public Sector at Wiz

Develops security engineering processes and infrastructure-as-code solutions to ensure FedRAMP and NIST compliance for government cloud environments.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we’re now powered by Google, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.

Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!

Minimum qualifications

  • 6+ years of experience in security engineering, DevOps, and systems engineering, with a proven ability developing processes and writing code to solve security/compliance problems.

  • 4+ years of expertise in NIST SP 800-53, FedRAMP High baselines, and DoW SRG overlays, with a proven ability to assess risk, reduce risk, and build engineering solutions that enable compliance.

  • Deep understanding of the differences between FR 20x and CR26 ruleset for Rev5 authorizations and the impacts these rule changes have on Cloud Service Providers (CSPs).

  • Experience working in a cloud-native environment with DevSecOps technologies, specifically including CI/CD, Containers, and Kubernetes.

  • Strong proficiency in scripting and Infrastructure as Code (IaC), with specific requirements for Shell Scripting, Python, Terraform or OpenTofu, and Preferred AI Harness (Claude Code, OpenAI Codex).

  • Experience with cloud platforms in government spaces.

Preferred qualifications

  • Experience with AWS GovCloud.

  • Experience in Azure Government, Google Cloud for Government (Assured Workloads), or equivalent and associated security services.

  • Experience with DevSecOps technologies including Microservices, GitOps, and Observability / Logging / SIEM / Platforms.

  • Experience with Packer, other Configuration as Code tools, and Policy as Code tools.

  • Experience automating compliance validation using cloud-native tools.

About the job

The Public Sector Compliance Operations Team aims to accelerate Wiz’s growth by developing a comprehensive strategy, in tight partnership with all other organizations, to drive customer value and adoption. As we continue to grow at an incredible speed, we work to ensure each sales team member is set up for success at every phase. We take both a bird’s eye view and dive into the weeds to solve problems as a team to drive employee success and revenue.

We are seeking an experienced Compliance Engineer to serve as the strategic technical lead for Wiz’s FedRAMP CR26 initiative. You will define the long-term technical roadmap by architecting comprehensive compliance-as-code solutions, utilizing both Wiz’s native features and custom-developed automations outside the platform to efficiently address CR26 Class D rule changes. This individual contributor role bridges complex regulatory requirements with scalable engineering practices, ensuring our cloud services meet stringent federal and defense standards while maintaining high availability, security, and audit-readiness.

You will be asked to quickly learn the challenges of the business and find ways to simplify processes within our compliance operations to increase productivity and efficiency. More importantly, the role requires a personality that promotes collaboration and unity.

Responsibilities

  • Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to an automated, real-time telemetry model.

  • Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering and product solutions.

  • Engineer evidence generation frameworks, significantly reducing manual effort required for 3PAO assessments and automating compliance validation for control implementation verification.

  • Conduct technical risk assessments, root-cause analysis on compliance findings, and provide guidance for implementation of compensating controls or hardening measures in cloud environments.

  • Own the technical compliance documentation lifecycle, including Security Decision Records (SDRs).

  • Collaborate cross-functionally with legal, product, engineering, devops, architecture, security, and federal customer teams to scope technical compliance verification and validation requirements for new features and services.

  • Mentor others on FedRAMP/DoW compliance best practices and contribute to internal training programs.

Candidates must meet EAR part 772 and ITAR 120.15 definition of a U.S. person (Any individual who is granted U.S. citizenship; or any individual who is granted U.S. permanent residence (green card holder); or any individual who is granted status as a “protected person”) and that they reside in the contiguous United States.

Compensation + Benefits

Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.

The US base salary range for this full-time position is listed below.

US Base Pay Range

$174,000—$238,000 USD

Applicants must have the legal right to work in the country where the position is based, without the need forvisa sponsorship.This role does not offervisasponsorship.

Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz’s Privacy Policy.

Read the full description
Security Information Security Engineer (R14207) at Oportun

Leads cybersecurity investigations across cloud, endpoint, and network environments, identifying and remediating security incidents while correlating data from SIEM and EDR tools.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

ABOUT OPORTUN

Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.

WORKING AT OPORTUN

Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.

POSITION OVERVIEW

The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
  • Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation.
  • Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
  • Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
  • Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks.
  • Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.
  • Experience performing root cause analysis and correlating activity across multiple security technologies.
  • Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders.
  • Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations.
  • Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.
  • Continuous learning, security automation, and process improvement.

WHO YOU ARE / WHAT YOU BRING

  • Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation
  • Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality
  • Experience in conducting purple team exercises
  • Coordinate external takedowns and threat remediation with third-party providers.
  • Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
  • Experience using Wiz Cloud Native Application Protection Platform (CNAPP)
  • Experience conducting Threat Hunting using the MITRE ATT&CK framework.
  • Experience developing, tuning, or maintaining security detections and SIEM use cases.
  • Experience with SOAR platforms and security automation.
  • Experience conducting fraud investigations or partnering with Fraud Operations.
  • Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud.
  • Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.

#LI-REMOTE

#LI-GK1

We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.

California applicants can find a copy of Oportun’s CCPA Notice here:  https://oportun.com/privacy/california-privacy-notice/.

We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).

Read the full description
Security Sr. Crowdstrike Engineer (R-00220) at True Zero Technologies

Designs, deploys, and manages CrowdStrike security platform implementations for enterprise customers while providing technical guidance on cybersecurity best practices.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

True Zero Technologies, a veteran-owned small business, was founded on the principle that the purposeful enablement of people and technology in an organization directly ties to the quality of its outcomes. True Zero recognizes that those outcomes begin and end with our people, and that is what we have built a community of like-minded, driven, and passionate individuals and innovators who are aligned in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross revenue) and “Mid-Atlantic Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In addition, True Zero earned coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained growth driven by our people-first approach and unwavering dedication to excellence.

Job Description

As the Crowdstrike Engineer you will possess solid industry experience, certifications, with proven experience planning, deployment, field and operational support of the CrowdStrike platform and related applications and solutions in a distributed and complex enterprise.   The Sr. Crowdstrike Consultant will have responsibility for all aspects of the deployment from the initial customer engagement, planning, installation, optimization/utility and follow-on customer support for the CrowdStrike platform and applications. You will also be involved in customer advisement regarding best practices and identifying areas to add value to their cybersecurity and cyber-adjacent solution deployments.  This role has the potential to develop into a practice lead of a product or capability focused practice.

Qualifications

  • 3+years of implementing, managing, and expanding Crowdstrike and related use cases for customers in a variety of public sector and commercial customers.
  • Bachelor’s degree in Computer Science, Information Technology, Computer Engineering, or related discipline, and 5 years of experience performing IT deployments or in an end user/customer environment
  • Deep understanding of software deployment technologies, and understanding of security operations, practices, and methodologies
  • Highly knowledgeable on Windows, Mac, and Linux platforms
  • Working knowledge of Microsoft Office applications, Word, Excel, Access, PowerPoint, etc.
  • Good communication and collaboration skills
  • Solid analytical/problem solving skills with capability to identify solutions to unusual and complex problems
  • High level of motivation; self-starter; results driven
  • Ability to travel as needed on-site to customers

Additional skills and experience that are highly valued

  • Serve as primary engineering resource responsible for end-to-end integration and operational optimization.
  • Strong background in Crowdstrike Falcon, EDR, ITP, and various other related modules
  • Directly support and mature SOC capibilities
  • Experience deploying and operating prominent enterprise EDR platforms such as Tanium, FireEye HX, Cylance, Carbon Black, Microsoft Defender, and SentinelOne in large and complex environments
  • Knowledge of cloud platforms and technologies, such as Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP)
  • Ability to gain secret clearance if needed

Responsibilities

  •  Provide technical implementation, configuration, and troubleshooting assistance with the deployment of the CrowdStrike platform and associated applications
  • Install CrowdStrike software both remotely and physically
  • Utilize and engineer native and 3rd party software deployment technologies
  • Develop scripts and processes around software deployment
  • Plan and report software deployment status
  • Work closely and collaboratively with customer information technology teams
  • Leveraging CrowdStrike applications (for example, but not limited to, Spotlight and Discover) provide support to customers in vulnerability and asset management
  • Assist customers with the integration of CrowdStrike into existing tools
  • Troubleshoot customer deployment issues across small to large enterprises
  • Establish roadmap and iterative improvement of endpoint detection capabilities and tooling integrations and use of Crowdstrike with maturity model approach
  • Identify opportunities to expand Crowdstrike and other tools to reduce security related enterprise risk
  • Create, enhance, and continuously update documentation and knowledge base (e.g., user guides, quick starts, documentation, demos)
  • Interview additional candidates applying to True Zero Technologies

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Analyst I, Information Technology

Monitors security systems, analyzes threats, and implements security controls to protect organizational IT infrastructure.

Junior Posted 1 day ago Jobicy AI
What this role involves
At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As...
Read the full description
Security Security Engineer I, Information Technology

Develops and implements security measures, monitors systems for threats, and maintains information security infrastructure for the organization.

Junior Posted 1 day ago Jobicy AI
What this role involves
At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As...
Read the full description
Security Coinbase: Regional Threat Assessment Manager

Lead threat assessment and case management for a region, conducting behavioral threat evaluations and coordinating security response across organizational stakeholders.

Senior Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Australia

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$200,900—$200,900 AUD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases for employees and facilities, conducts behavioral threat analysis, and coordinates security incident response across regional operations.

Senior Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - EMEA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):£95,490—£106,100 GBP
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-1

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases end-to-end, conducts behavioral threat assessments, coordinates incident response, and partners cross-functionally to mitigate security risks to employees, executives, and facilities.

Senior Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Singapore

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$212,200—$212,200 SGD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-2

Read the full description
Security Stripe: Risk Strategist - Screening (Financial Crimes)

Develops and manages global financial crimes screening programs, setting standards for AML/sanctions controls and driving risk management strategy across Stripe's payment infrastructure.

Senior Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: US-Chicago; US-Atlanta; US-Remote; Canada-Toronto; Canada-Remote

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Financial Crimes Risk Strategy team owns our first-line AML and sanctions programs globally. We own the end-to-end lifecycle of financial crime controls. We set the global standards that govern how risk is managed across our programs, design and drive the development of controls, infrastructure, and tooling with Engineering, Product, and Data Science, and maintain their effectiveness as our products and the regulatory landscape evolve. We build fast, with data, and with AI integrated into how financial crime risk is detected, managed, and monitored across everything Stripe builds.

What you'll do

As a Risk Strategist on the Financial Crimes Risk Strategy team, you'll own our global screening programs — spanning sanctions, PEP, and negative news — setting the standards that govern how screening risk is managed, designing and driving the controls that operationalize those standards, and ensuring they remain effective as our products and the regulatory landscape evolve. Being effective in this role means going deep on both the domain and the data — we don't separate the two.

You'll partner closely with Product, Engineering, Data Science, Compliance, Legal, other Risk Strategy functions, and Operations to ensure screening considerations are embedded in every product and market decision. Beyond protecting against risk, you'll drive innovation in how Stripe approaches screening — staying ahead of regulatory change and pushing the boundaries of what effective, scalable financial crime risk management looks like at a global payments company.

Responsibilities

  • Lead our global sanctions and AML screening strategy — setting the standards that drive screening control design and infrastructure development, and translating requirements across OFAC, EU, UN, OFSI, and other applicable regimes, PEP screening, and negative news screening into actionable first-line programs and controls
  • Own the design and ongoing improvement of financial crime controls — including sanctions screening, PEP screening, negative news screening, and digital asset-related safeguards — while continuously improving detection coverage and control performance as our products and the threat landscape evolve
  • Embed screening risk requirements into product and infrastructure roadmaps — ensuring financial crime considerations drive product launches, market expansions, and platform decisions across Product, Engineering, Data Science, Compliance, Legal, and Operations
  • Drive screening infrastructure and tooling forward by owning requirements, leading execution, and maintaining effectiveness metrics for screening systems and controls — building with observability by design and ensuring key performance indicators, key risk indicators, and monitoring thresholds are defined from inception
  • Continuously assess and improve screening controls and systems — identifying gaps, recommending enhancements that strengthen detection effectiveness and anticipate regulatory or ecosystem changes, and leading delivery of those enhancements end-to-end
  • Champion a technology-forward approach to financial crime risk management — leveraging AI tools, self-serve data analytics, and model governance best practices to improve how risk is detected, monitored, and managed at Stripe
  • Stay informed on industry practices and regulatory developments and represent our sanctions and AML programs to regulators, bank and network partners, and external auditors

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 7+ years of professional experience in financial services, payments, or fintech, with at least 5 years in a related role (risk, compliance, or product enablement)
  • Deep subject matter expertise in global sanctions compliance, including hands-on experience with OFAC, EU sanctions regimes, UN Security Council designations, OFSI, and other major global frameworks
  • Demonstrated strong understanding of screening program design and control execution
  • Strong AML screening expertise — proven ability to design, implement, and operationalize PEP screening and negative news screening programs in complex, multi-jurisdiction environments
  • Proven ability to design, implement, and operationalize financial crime standards and controls in complex, global organizations
  • Familiarity with model governance concepts — including model documentation, performance monitoring, and validation — and experience leading or contributing to model governance activities

Preferred qualifications

  • Experience leading transformative AML, Sanctions, or Transaction Monitoring initiatives, including global screening program design or transformations (e.g., vendor selection, watchlist management, false positive tuning)
  • Proficiency with SQL and ability to independently mine and analyze data to develop risk insights and inform strategy
  • Experience with crypto or digital asset products and their associated financial crime risk and regulatory considerations
  • Advanced degree or professional certifications (e.g., CAMS, CGSS, CFCS)

To apply: https://weworkremotely.com/remote-jobs/stripe-risk-strategist-screening-financial-crimes

Read the full description
Security Coinbase: Senior Manager, Internal Audit IT

Lead Coinbase's global IT and security audit program, managing audits across cloud infrastructure, security operations, and risk management while overseeing a distributed team of auditors.

Lead Remote Posted 8 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - USA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

As the Senior Manager, Internal IT & Security Audit, you'll lead Coinbase's global IT and security audit program. Reporting to the Head of Internal Audit, you will operate within an independent third line of defense that maintains functional accountability to the Audit Committee. You'll own the multi-year IT and security audit roadmap, ensuring coordinated coverage across all regions (US, EMEA, UK, APAC) and alignment with Coinbase's enterprise risk profile and regulatory expectations. Your leadership will directly strengthen how Coinbase identifies, evaluates, and mitigates technology and security risks across the organization.

What you'll do:

  • Own the end-to-end delivery of complex, cross-functional IT and security audits covering cloud infrastructure, security operations, identity and access management, data protection, vendor/third-party risk, and key products and services.
  • Lead and develop a high-performing global team of internal auditors and co-sourced resources, setting goals, coaching talent, managing performance, and building succession pipelines across regions.
  • Drive integrated assurance across the three lines of defense by partnering with first and second line risk, compliance, security, and technology teams to rationalize testing and maximize control coverage.
  • Shape executive-level reporting on technology and security control effectiveness, distilling key themes, emerging risks, and root causes into clear materials for senior management, the Head of Internal Audit, and the Audit Committee.
  • Partner with technology and security leadership across Engineering, Security, Infrastructure, and Product to provide independent challenge on major initiatives (e.g., cloud migrations, new product launches, architecture changes) without compromising third-line independence.
  • Build continuous improvement into the audit function by driving adoption of data analytics, automation, and generative AI to modernize IT and security audit execution, including continuous monitoring and automated evidence retrieval.

Required Skills and Experience:

  • 12+ years of experience in internal audit with deep focus on IT and information security, or in first-line / second-line technology/security roles with significant controls and audit exposure.
  • Demonstrated success leading global, cross-functional IT audit portfolios spanning cloud, infrastructure, cybersecurity, and third-party risk across multiple regulatory jurisdictions (US, EMEA, APAC).
  • Deep technical knowledge of cloud-based technology stacks, software development lifecycles, cloud security configurations, and enterprise IT operations risks and controls.
  • Relevant professional certifications (e.g., CISA, CISSP, CIA, CPA) and working fluency with frameworks such as NIST, COBIT, and ITIL.
  • Proven leadership experience building, mentoring, and managing global audit teams, including co-sourced resources and indirect reports across time zones.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Req ID: #P76564

#LI-Remote

 

 

Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)). 

 

Annual base salary range (excluding equity and bonus):$201,365—$236,900 USD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-senior-manager-internal-audit-it

Read the full description
Security Security Operations Engineer at DeepHealth

Builds and operates enterprise security controls, tooling, and automation across cloud and corporate environments while developing detection content and security automation.

Mid Posted 8 days ago RemoteFirstJobs Product
What this role involves

Description

The Security Operations Engineer builds and operates security controls, tooling, and automation across DeepHealth’s cloud and corporate environments. This role is responsible for configuring, integrating, and maintaining the enterprise security tooling stack, developing detection content, and automating security operations tasks so that controls are repeatable, version-controlled, and auditable.

Working within DeepHealth’s established security frameworks and under the direction of the Director, Security Operations, this position operates and tunes security controls, detection content, and guardrails. Independent validation of those controls sits with the security operations watch function — a deliberate separation that keeps the control environment defensible under audit. Remediation follows system ownership across Cloud Operations, Platform, and Application Development; this role supplies technical guidance and implements fixes directly where the control is security-owned.

This position operates within a regulated healthcare environment across a global operating footprint, with obligations under HIPAA, ISO/IEC 27001, and SOC 2. The role reports to the Director, Security Operations, with future reporting to the Manager, Security Operations as that position is established.

Requirements

·       Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments.

·       Develop and maintain detection content, correlation rules, and response automation within the SIEM and SOAR platform.

·       Onboard new log sources and telemetry feeds, validating ingestion completeness, parsing accuracy, and field normalization.

·       Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation.

·       Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality.

·       Implement and maintain security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.

·       Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework, so that controls are version-controlled, repeatable, and auditable.

·       Implement policy-as-code and preventive guardrails using native cloud policy engines or an equivalent open policy framework.

·       Support cloud security posture management across all cloud environments, including finding deduplication, theme mapping, and routing to owning teams.

·       Harden cloud resources including compute, storage, database, container, and serverless services against established benchmarks.

·       Configure and maintain Microsoft 365 and Entra ID security controls, including conditional access, identity protection, and Defender workloads in a hybrid directory environment.

·       Implement and maintain least-privilege access models, roles, and policies across multiple cloud identity systems.

·       Implement container and Kubernetes security controls, including role-based access control, workload security standards, image scanning, and runtime protection.

·       Implement and maintain secrets management practices and tooling, and support the elimination of hard-coded credentials across environments.

·       Operate vulnerability management tooling, validate scan coverage, and translate raw scanner output into prioritized, owner-routed findings.

·       Provide technical remediation guidance to cloud, platform, identity, application, and endpoint owners, who retain accountability for closure of findings in their systems.

·       Implement engineering fixes for findings that fall to security-owned tooling and configuration.

·       Support remediation tracking for penetration test and vulnerability assessment findings by supplying technical detail and validating that fixes are technically sound.

·       Support incident detection and response through hands-on technical investigation, including log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review.

·       Support escalations raised by the external managed security partner by supplying technical analysis and environment context.

·       Provide feedback into detection quality and alert tuning to reduce noise and improve signal for the monitoring function.

·       Contribute technical findings to post-incident review, and implement the resulting control and detection improvements.

·       Participate in tabletop exercises and resilience testing, and act on the technical gaps those exercises surface.

·       Document all engineering changes to security controls through the change management process, including validation criteria and rollback plans.

·       Produce and maintain runbooks, playbooks, and technical operating procedures for repeatable security operations tasks.

·       Write clear, documented, and reviewable code and configuration so that work can be inspected, maintained, and handed over without dependence on any one individual.

·       Support audit, certification, and customer assurance activities by producing technical evidence on request.

·       Maintain accurate inventory of security tooling, control coverage, licensing position, and control operating status.

·       Maintain strict confidentiality of security testing results, control configuration detail, and investigative material, and follow established standards for external disclosure.

PLEASE NOTE: This is not an exhaustive list of all duties, responsibilities and requirements of the position described above.  Other functions may be assigned and management retains the right to add or change duties at any time.

Minimum Qualifications, Education and Experience

·       4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role. (Required)

·       Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience. (Required)

·       2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred. (Required)

·       2+ years operating and tuning a SIEM platform, including working with detection content and log sources. (Required)

·       1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment. (Required)

·       Working knowledge of security automation; experience with scripting and infrastructure-as-code is required, with Terraform experience preferred. (Required)

·       Working knowledge of cloud security posture management and preventive controls. (Required)

·       Working knowledge of container and Kubernetes security, including role-based access control and image scanning. (Required)

·       Working knowledge of secrets management tooling and practices. (Required)

·       Practical experience with endpoint detection and response tooling. (Required)

·       Working knowledge of vulnerability management and the finding remediation lifecycle, including risk-based prioritization. (Required)

·       Scripting capability in at least one of: Python, PowerShell, or Bash. (Required)

·       Familiarity with recognized security frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2. (Required)

·       Able to communicate technical findings clearly in writing and verbally to both technical and non-technical audiences. (Required)

·       Able to manage assigned work independently and escalate appropriately. (Required)

·       Available to support incident response activity outside standard business hours as required. (Required)

·       Microsoft Office experience. (Required)

·       Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification. (Preferred)

·       Experience in healthcare, medical device, or another regulated industry, and working familiarity with HIPAA obligations. (Preferred)

·       Experience working alongside or integrating with a managed security service provider. (Preferred)

Quality Standards

·       Communicates, cooperates, and consistently functions professionally and harmoniously with all levels of supervision, co-workers, visitors, and vendors.

·       Demonstrates initiative, personal awareness, professionalism and integrity, and exercises confidentiality in all areas of performance.

·       Follows all local, regional and country laws concerning employment.

·       Follows all DeepHealth policies and procedures.

·       Follows data privacy, compliance, safety and confidentiality standards at all times.

·       Practices universal safety precautions.

·       Promotes good public relations on the phone and in person.

·       Adapts and is willing to learn new tasks, methods, and systems.

·       Reports to work regularly as scheduled; consistently punctual with respect to working hours, meal and rest breaks, and maintains satisfactory personal attendance in accordance with DeepHealth guidelines.

·       Completes job responsibilities in a quality and timely manner.

Travel

This position requires domestic / international travel up to 10%.

Working Environment

Remote

Physical Demands

This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally.

Work Authorization / Visa Sponsorship: DeepHealth does not provide immigration sponsorship for this position, including sponsorship for employment-based visas or other work authorization requiring employer sponsorship. Candidates must be legally authorized to work in the United States without current or future sponsorship from DeepHealth for the duration of employment.

Read the full description
Security Consultant (Technology) (m/w/d)

Conducts cybersecurity assessments, develops security strategies and ISMS frameworks, and identifies organizational risks.

Mid Posted 8 days ago Himalayas
What this role involves
Die Aufgaben eines Consultant (Technology) (m/w/d) sind vielfältig und können unter anderem folgende Tätigkeiten umfassen: • Durchführung von Cyber-Security-Assessments, Schwachstellenanalysen und Risikoidentifikation • Entwicklung und Implementierung von Sicherheitsstrategien, Referenzarchitekturen, Richtlinien und Standards • Aufbau und Betreuung von ISMS (z.
Read the full description
Security Oracle Cloud Security Engineer

Implements and maintains security infrastructure on Oracle Cloud Platform, managing access controls, compliance, and threat detection.

Mid Remote Posted 8 days ago Himalayas
What this role involves
Oracle Cloud Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description