Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. 🚀
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
Designs and implements AI security controls, guardrails, and sandboxing patterns across company systems while auditing AI tool usage and training users on secure practices.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.
With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai
Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.
You will…
- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.
- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.
- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.
- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.
- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.
- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.
- Document guidance and patterns that a non-security audience can actually follow without needing a security background.
Qualifications:
- Bachelor’s degree in Computer Science or a related field.
- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.
- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.
- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.
- Strong communication skills - you work with engineers as a partner.
Bonus:
- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.
- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.
- Background in autonomous vehicles, robotics, or other safety-critical systems
The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations. Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.
Perks/Benefits:
Waabi provides a competitive benefits package that includes:
- Competitive compensation and equity awards.
- Health and Wellness benefits that include Medical, Vision and Dental coverage.
- Unlimited Vacation.
- Flexible hours and Work from Home support.
- Daily drinks, snacks and catered meals (when in office).
- Regularly scheduled team building activities and social events.
- As we grow, this list continues to evolve!
Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!
Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Establishes AI security controls, designs guardrails for enterprise AI tool adoption, and audits AI integrations to manage risks across the organization.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.
With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai
Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.
You will…
- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.
- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.
- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.
- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.
- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.
- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.
- Document guidance and patterns that a non-security audience can actually follow without needing a security background.
Qualifications:
- Bachelor’s degree in Computer Science or a related field.
- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.
- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.
- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.
- Strong communication skills - you work with engineers as a partner.
Bonus:
- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.
- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.
- Background in autonomous vehicles, robotics, or other safety-critical systems
The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations. Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.
Perks/Benefits:
Waabi provides a competitive benefits package that includes:
- Competitive compensation and equity awards.
- Health and Wellness benefits that include Medical, Vision and Dental coverage.
- Unlimited Vacation.
- Flexible hours and Work from Home support.
- Daily drinks, snacks and catered meals (when in office).
- Regularly scheduled team building activities and social events.
- As we grow, this list continues to evolve!
Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!
Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Monitors and responds to security threats, manages application security vulnerabilities, and ensures compliance with security protocols for Veeam's product infrastructure.
Leads cybersecurity investigations across cloud, endpoint, and network environments, identifies and remediates security incidents using SIEM and EDR tools.
Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.
Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.
The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.
The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.
#LI-REMOTE
#LI-GK1
We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.
California applicants can find a copy of Oportun’s CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/.
We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).
Leads cybersecurity investigations across cloud, endpoint, and network environments, identifying and remediating security incidents while correlating data from SIEM and EDR tools.
Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.
Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.
The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.
The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.
#LI-REMOTE
#LI-GK1
We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.
California applicants can find a copy of Oportun’s CCPA Notice here: https://oportun.com/privacy/california-privacy-notice/.
We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).
Builds and operates enterprise security controls, tooling, and automation across cloud and corporate environments while developing detection content and security automation.
The Security Operations Engineer builds and operates security controls, tooling, and automation across DeepHealth’s cloud and corporate environments. This role is responsible for configuring, integrating, and maintaining the enterprise security tooling stack, developing detection content, and automating security operations tasks so that controls are repeatable, version-controlled, and auditable.
Working within DeepHealth’s established security frameworks and under the direction of the Director, Security Operations, this position operates and tunes security controls, detection content, and guardrails. Independent validation of those controls sits with the security operations watch function — a deliberate separation that keeps the control environment defensible under audit. Remediation follows system ownership across Cloud Operations, Platform, and Application Development; this role supplies technical guidance and implements fixes directly where the control is security-owned.
This position operates within a regulated healthcare environment across a global operating footprint, with obligations under HIPAA, ISO/IEC 27001, and SOC 2. The role reports to the Director, Security Operations, with future reporting to the Manager, Security Operations as that position is established.
·      Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments.
·      Develop and maintain detection content, correlation rules, and response automation within the SIEM and SOAR platform.
·      Onboard new log sources and telemetry feeds, validating ingestion completeness, parsing accuracy, and field normalization.
·      Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation.
·      Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality.
·      Implement and maintain security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.
·      Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework, so that controls are version-controlled, repeatable, and auditable.
·      Implement policy-as-code and preventive guardrails using native cloud policy engines or an equivalent open policy framework.
·      Support cloud security posture management across all cloud environments, including finding deduplication, theme mapping, and routing to owning teams.
·      Harden cloud resources including compute, storage, database, container, and serverless services against established benchmarks.
·      Configure and maintain Microsoft 365 and Entra ID security controls, including conditional access, identity protection, and Defender workloads in a hybrid directory environment.
·      Implement and maintain least-privilege access models, roles, and policies across multiple cloud identity systems.
·      Implement container and Kubernetes security controls, including role-based access control, workload security standards, image scanning, and runtime protection.
·      Implement and maintain secrets management practices and tooling, and support the elimination of hard-coded credentials across environments.
·      Operate vulnerability management tooling, validate scan coverage, and translate raw scanner output into prioritized, owner-routed findings.
·      Provide technical remediation guidance to cloud, platform, identity, application, and endpoint owners, who retain accountability for closure of findings in their systems.
·      Implement engineering fixes for findings that fall to security-owned tooling and configuration.
·      Support remediation tracking for penetration test and vulnerability assessment findings by supplying technical detail and validating that fixes are technically sound.
·      Support incident detection and response through hands-on technical investigation, including log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review.
·      Support escalations raised by the external managed security partner by supplying technical analysis and environment context.
·      Provide feedback into detection quality and alert tuning to reduce noise and improve signal for the monitoring function.
·      Contribute technical findings to post-incident review, and implement the resulting control and detection improvements.
·      Participate in tabletop exercises and resilience testing, and act on the technical gaps those exercises surface.
·      Document all engineering changes to security controls through the change management process, including validation criteria and rollback plans.
·      Produce and maintain runbooks, playbooks, and technical operating procedures for repeatable security operations tasks.
·      Write clear, documented, and reviewable code and configuration so that work can be inspected, maintained, and handed over without dependence on any one individual.
·      Support audit, certification, and customer assurance activities by producing technical evidence on request.
·      Maintain accurate inventory of security tooling, control coverage, licensing position, and control operating status.
·      Maintain strict confidentiality of security testing results, control configuration detail, and investigative material, and follow established standards for external disclosure.
PLEASE NOTE: This is not an exhaustive list of all duties, responsibilities and requirements of the position described above. Other functions may be assigned and management retains the right to add or change duties at any time.
Minimum Qualifications, Education and Experience
·      4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role. (Required)
·      Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience. (Required)
·      2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred. (Required)
·      2+ years operating and tuning a SIEM platform, including working with detection content and log sources. (Required)
·      1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment. (Required)
·      Working knowledge of security automation; experience with scripting and infrastructure-as-code is required, with Terraform experience preferred. (Required)
·      Working knowledge of cloud security posture management and preventive controls. (Required)
·      Working knowledge of container and Kubernetes security, including role-based access control and image scanning. (Required)
·      Working knowledge of secrets management tooling and practices. (Required)
·      Practical experience with endpoint detection and response tooling. (Required)
·      Working knowledge of vulnerability management and the finding remediation lifecycle, including risk-based prioritization. (Required)
·      Scripting capability in at least one of: Python, PowerShell, or Bash. (Required)
·      Familiarity with recognized security frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2. (Required)
·      Able to communicate technical findings clearly in writing and verbally to both technical and non-technical audiences. (Required)
·      Able to manage assigned work independently and escalate appropriately. (Required)
·      Available to support incident response activity outside standard business hours as required. (Required)
·      Microsoft Office experience. (Required)
·      Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification. (Preferred)
·      Experience in healthcare, medical device, or another regulated industry, and working familiarity with HIPAA obligations. (Preferred)
·      Experience working alongside or integrating with a managed security service provider. (Preferred)
Quality Standards
·      Communicates, cooperates, and consistently functions professionally and harmoniously with all levels of supervision, co-workers, visitors, and vendors.
·      Demonstrates initiative, personal awareness, professionalism and integrity, and exercises confidentiality in all areas of performance.
·      Follows all local, regional and country laws concerning employment.
·      Follows all DeepHealth policies and procedures.
·      Follows data privacy, compliance, safety and confidentiality standards at all times.
·      Practices universal safety precautions.
·      Promotes good public relations on the phone and in person.
·      Adapts and is willing to learn new tasks, methods, and systems.
·      Reports to work regularly as scheduled; consistently punctual with respect to working hours, meal and rest breaks, and maintains satisfactory personal attendance in accordance with DeepHealth guidelines.
·      Completes job responsibilities in a quality and timely manner.
Travel
This position requires domestic / international travel up to 10%.
Working Environment
Remote
Physical Demands
This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally.
Work Authorization / Visa Sponsorship: DeepHealth does not provide immigration sponsorship for this position, including sponsorship for employment-based visas or other work authorization requiring employer sponsorship. Candidates must be legally authorized to work in the United States without current or future sponsorship from DeepHealth for the duration of employment.
Conducts cybersecurity assessments, develops security strategies and ISMS frameworks, and identifies organizational risks.
Implements and maintains security infrastructure on Oracle Cloud Platform, managing access controls, compliance, and threat detection.
Integrates security into the software development lifecycle, identifies vulnerabilities, and builds automation tools to improve security practices across engineering teams.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems. We build shared platforms, engineering foundations, and reusable services that enable mission teams to deliver software faster, operate more efficiently, and scale with confidence.
Our roots trace back to the Healthcare.gov recovery effort, where we saw firsthand what talented, mission-driven teams could accomplish together. That experience shaped how we work today: solving complex technical challenges through collaboration, pragmatic engineering, and a relentless focus on delivering value.
Today, we support critical healthcare modernization efforts at the Centers for Medicare & Medicaid Services (CMS), helping build and operate the platforms, tools, and services that enable teams across Medicare and Medicaid to deliver secure, resilient digital experiences.
We’re a remote-first team that values curiosity, kindness, ownership, and continuous learning. We enjoy solving hard technical problems, partnering closely with our clients, and building technology that makes government work better for the people who rely on it.
Contingent Position: This position is contingent upon Corbalt’s successful contract award. Employment offers and start dates are dependent on the award of the associated government contract.
We’re looking for a Security Engineer who enjoys building secure software, improving engineering platforms, and helping teams deliver with confidence. You’ll work closely with software engineers to integrate security into the development lifecycle, automate security practices, and build resilient cloud-native systems that support critical government services.
The base salary range for this position is: $138,677Â - $182,296Â per year.
In addition to the base salary, Corbalt offers:
Corbalt is an Equal Opportunity Employer, including disability and protected veteran status.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Embeds security practices throughout the software development lifecycle, conducts code reviews, maintains secure coding standards, and integrates security tooling into CI/CD pipelines.
We believe in the life changing impact youth sports have on and off the field. Sports encourage leadership, teamwork, responsibility, and confidence – important life lessons that have the power to propel our youth toward meaningful futures. We recognize that without coaches, parents, and volunteers, organized youth sports could not exist. By building the first and best place to experience the youth sports moments important to our community, we are helping families elevate the next generation through youth sports.
So if you love sports and their community building potential, or building cool products is your sport, GameChanger is the team for you. We are a remote first, dynamic tech company based in New York City, and we are solving some of the biggest challenges in youth sports today.
We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation.
Application security
Embed security into every phase of the SDLC
Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack
Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes
Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance
Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)
Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams
Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers
DevSecOps
Integrate and maintain security tooling across CI/CD pipelines
Enforce security quality gates in delivery pipelines
Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments
Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows
Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)
Implement and validate security controls for containerized workloads
Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints
Vulnerability & Risk Management
Operate the application vulnerability management lifecycle
Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability
Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes
Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership
Effectively communicate security risk clearly to both engineering and business leaders
3+ years in application security engineering
Proven experience building and operating internal security developer platforms or tooling that reduces developer friction
Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability
Hands-on experience leading threat modeling engagements and designing paved roads
Proven track record integrating security tooling into CI/CD pipelines
Working knowledge of OWASP Top 10s (web, mobile, API, LLM)
Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches
Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin
Track record of implementing secure primitives in mobile ecosystems (iOS/Android)
Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.
Pragmatic defender. You understand that security must enable the business, not block it. You look for “secure by default” solutions and know how to make the right path the easy path for engineers.
Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default.
Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in.
Automation-first. If you have to do it twice, you’d rather write the script.
Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly.
Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation.
Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction.
Work remotely throughout the US* or from our well-furnished, modern office in Manhattan, NY.
Unlimited vacation policy.
Paid volunteer opportunities.
Technology stipend - $4,000 every 2 years after your start to make sure you have the latest and greatest technology.
WFH stipend - $500 annually to make your WFH situation comfortable.
Monthly physical, mental, wellness & learning stipend offered through Holisticly.
Monthly lifestyle stipend offered through Fringe.
Full health benefits - medical, dental, vision, prescription, FSA, HRA, HSA, and coverage for family/dependents.
Retirement savings - Traditional and Roth 401K plans are offered through Vanguard, with an immediate company match.
Life insurance - basic life, supplemental life, and dependent life.
Disability leave - short-term disability and long-term disability.
Company paid parental leave - up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.
Family building benefits offered through Progyny.
DICK’S Sporting Goods and their family of brands teammate discount.
The target salary range for this position is between $120,000 and $140,000. This is part of a total compensation package that includes incentive, equity, and benefits for eligible roles. Individual pay may vary from the target range and is determined by several factors including experience, internal pay equity, and other relevant business considerations. We constantly review all teammate pay to ensure a great compensation package that is fair and equal across the board.
\* DICK’S Sporting Goods has company-wide practices to monitor and protect the company from significant compliance and monetary implications as it pertains to employer state tax liabilities. Due to said guidelines put in place, we are unable to hire in AK, DE, HI, IA, LA, MS, MT, OK, and SC.
We are an equal opportunity employer and value diversity in our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.
IMPORTANT NOTICE: All official recruitment communications from GameChanger will come from an email address ending in @gc.com or no-reply@ashby.hq.com. If you receive communication from any other domain, please be cautious, as it is likely fraudulent.
Administers and optimizes Web Application Firewall (WAF) infrastructure, manages rulesets, and coordinates with application teams on security configurations.
Monitors security alerts and threats across SIEM/EDR/XDR tools, triages incidents, implements automations, and partners cross-functionally to protect company assets.
Unqork empowers enterprises to accelerate growth by rapidly building, testing, and running AI-powered applications that embody the future of enterprise development. Trusted by the world’s largest organizations in highly regulated industries, these applications become more secure over time while significantly reducing technical debt—allowing businesses to focus on innovation rather than maintenance. Unqork’s customers include Goldman Sachs, Marsh, BlackRock, and the U.S. Department of Health and Human Services.
At Unqork, we value inclusive and innovative thinkers who boldly challenge the status quo. We encourage you to apply!
The Impact U will make:
As a Security Operations Analyst, you will be an analytical and thorough individual contributor reporting to the Director of Security Operations. You will play a role in Threat Detection & Response, Threat Intelligence and Hunting, Technical Security Architecture, IT Operations, and SIEM and SOAR engineering. Your primary focus will be to proactively and reactively protect and defend our critical assets against an evolving threat landscape.
What U bring:
Compensation, Benefits, & Perks
đź’» Work from home with a remote-first community
🏝 Unlimited PTO (and the encouragement to use it)
📝 Student loan payback program
🏥 100% employer-covered medical, dental, and vision options available to you and your dependents
đź’¸ Flexible Spending Account (FSA)
🏠Monthly stipend toward your WFH setup, vacation, development and more
đź’° Employer-sponsored 401(k) with contribution match
🏋🏻‍♀️ Subsidized ClassPass Membership
🍼 Generous Paid Parental Leave
đź’˛ Hiring Ranges:
Unqork employs a market-driven approach to establish compensation ranges. In addition to a base salary, employees may also be eligible to receive a target incentive and company equity in the form of stock options.
An employee’s compensation within the range provided above depends on a variety of factors including, but not limited to, their location, role, skillset, level of experience, and similar peer salaries. As a remote-first company, Unqork incorporates a geographic differential into our compensation structure, depending on the candidate’s location. We utilize a tiered system—Tier 1 and Tier 2—to accurately reflect local market rates and ensure our compensation packages are both fair and competitive.
Our geographic tiers are defined as follows:
Unqork embraces a culture of security and privacy awareness by consistently safeguarding sensitive information, adhering to company policies, and actively participating in training and initiatives to protect our data and the privacy of our stakeholders.
Unqork is an equal opportunity employer. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
Evaluates third-party vendor security risks, builds automation workflows to scale GRC processes, and partners cross-functionally on security governance decisions.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
Affirm values security as being critical to the company’s continued success. The Security Risk Management team is evolving beyond traditional governance, risk, and compliance; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Affirm and our customers.
The ideal candidate will evaluate, build, and refine solutions to third-party risk and security governance challenges across the Security Third Party Program and the broader Security Risk Management program. They are equally comfortable applying security policy to real-world vendor decisions and shipping automation using modern tooling (Python, Cursor, Claude, and other agentic coding platforms) to replace manual GRC work with scalable, code-defined workflows. They will develop deep expertise across the security risk domain, partner closely with business and engineering stakeholders, and play an active role in Affirm’s transformation of Security Risk Management from a compliance-oriented function into a security engineering discipline.
We are looking for a curious, collaborative Security Risk Management Specialist to help scale Affirm’s Third Party Risk Management program through process rigor, hands-on automation, and strong cross-functional partnership.
Base Pay Grade - 3
Equity Grade - 4
Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include equity rewards, monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidized medical coverage, dental and vision for you and your dependents.)
USA Pacific base pay range (CA, WA, NY, NJ, CT) per year: $130,000Â -Â 180,000
USA Sapphire base pay range (all other U.S. states) per year: $115,000Â -Â 165,000
Please note that visa sponsorship is not available for this position.
#LI-Remote
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
[For U.S. positions that could be performed in Los Angeles or San Francisco] Pursuant to the San Francisco Fair Chance Ordinance and Los Angeles Fair Chance Initiative for Hiring Ordinance, Affirm will consider for employment qualified applicants with arrest and conviction records.
By clicking “Submit Application,” you acknowledge that you have read Affirm’s Global Candidate Privacy Notice and hereby freely and unambiguously give informed consent to the collection, processing, use, and storage of your personal information as described therein.
Analyzes and monitors insider threats and suspicious user behavior to mitigate security risks within an organization.
Conducts comprehensive security assessments across mobile apps, IoT devices, firmware, compiled software, and browser extensions.
Manages security operations, incident response, and compliance for a cloud infrastructure company serving enterprise customers across EMEA regions.
Conducts offensive security assessments, penetration tests, and red team operations for enterprise clients while developing tools, training team members, and communicating findings to stakeholders.
SpecterOps is looking for an Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.
A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.
Salary Range: Base salary annually, commensurate with experience.
Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.
Responsibilities
Requirements
Desired Qualifications:
Nice to Haves
What We Offer
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io
Unsolicited resumes are not accepted
#LI-REMOTE
Detection engineer who authors and tunes SIEM detection rules, closes security coverage gaps, and optimizes customer SIEM platforms for cost and performance.
Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel’s professional services practice is just getting started, and we’re looking for the technical expert who’ll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You’ll bring hands-on skill to a team that’s finding its stride, help it grow, and have a real runway to grow into a lead yourself.
Here’s the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You’re the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.
And because this function evolves right alongside our customers and the market, the work won’t stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.
This role is remote within the United States.
The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we’re primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.
We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You’ll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.
We’re only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.
We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
We’ll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.
#LI-Remote
Salary Range
$111,900—$162,300 USD
Analyzes cyber threats targeting cloud environments, synthesizes threat intelligence from multiple sources, and produces detailed threat research reporting.
Come join the organization that is redefining security for the AI era. As one of the fastest-growing startups ever, we enable teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. Trusted by security teams all over the world, we have a proven track record of success and a culture that values world-class talent. Not to mention, we’re now powered by Google, meaning we offer our customers an AI-powered platform that harnesses Google’s Threat Intelligence and Security Operations to better detect, prevent, and respond to threats across all environments, allowing for further innovation.
Our Wizards from all over the globe work together to protect the infrastructure of our customers, including over 65% of the Fortune 100, who trust us to scan and secure over 230 billion files daily. We’re honored to be a leading player in a massive and growing market, and we continue to look for exceptional Wizards who are eager to make a significant impact on our team. At Wiz, you’ll have the freedom to think creatively, dream big, and use your full range of skills to contribute to our momentous growth. Come join our team and help us create secure cloud environments that allow even the best companies to move faster, all while having some fun!
SUMMARY
Wiz is looking for a Cyber Threat Analyst to join the Threat Research team and spread the power of Wiz. In this role, you will track, analyze and report on the most advanced threats targeting cloud environments.
WHAT YOU’LL DO
WHAT YOU’LL BRING
ADVANTAGE
Compensation + Benefits
Compensation for this full-time position includes base salary + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits. Learn more about benefits at Google.
The US base salary range for this full-time position is listed below.
US Base Pay Range
$160,000—$220,000 USD
Applicants must have the legal right to work in the country where the position is based, without the need forvisa sponsorship.This role does not offervisasponsorship.
Wiz is an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.
By submitting your application, you acknowledge that Wiz will process your personal data in accordance with Wiz’s Privacy Policy.
Triages and remediates vulnerabilities in CPython and PyPI, handles malware/supply-chain attacks, and develops security tooling and infrastructure for the Python ecosystem.
Working with the Python Security Response Team, Python core team, and Python Package Index (PyPI) admins to ensure Python is secure for its global and diverse user base. The core mandate for this role is to drive vulnerability reports to remediations and advisories, mitigating malware on the PyPI, and developing solutions to scale our capacity to respond ahead of the growth curve.
You’ll be part of the small-but-mighty team at the Python Software Foundation, the US non-profit organization working every day to help Python and its community thrive. Most of your days will be time-boxing between day-to-day vulnerability coordination and malware handling work alongside long-term projects like documentation, tool development, and gathering and sharing metrics.
Core Responsibilities & Development
Standards, Documentation, Communications
Qualifications
3-5 years experience with Python or C programming languages. Knowledge about vulnerabilities affecting programs written in C, such as memory safety issues. Asynchronous and written communication skills with the ability to manage and prioritize multiple concurrent threads. Experience working with open source projects and communities is a plus.
Security certifications are not required. An ideal candidate will have a collaborative and flexible attitude suited to working with a community of passionate volunteers on small, mutually-supporting teams. Don’t worry if you don’t check all the boxes or aren’t a “security expert”, above all we’re looking for someone who is eager to learn while securing the many domains and users the Python language serves.
Desired Experience
Experience with secure development practices for Python and C programming languages. Experience with vulnerability disclosure, CVE, security teams, and threat models. Experience with code quality and security tools like fuzz-testing, address and memory sanitizers. Experience writing technical documentation. Experience working in public or with open source projects.
Details
The Python Software Foundation is a US 501©(3) non-profit corporation that holds the intellectual property rights behind the Python programming language. We also run the PyCon US conference annually, support other Python conferences/workshops around the world, and fund Python-related development with our grants program. To see more info about the PSF, check out our Annual Impact Report and public records.
We believe that the future of open source must include everyone. We welcome all job-seekers regardless of race, color, ethnicity, religion, age, sexual orientation, gender identity or expression, national origin, physical appearance, body size, socio-economic, veteran or disability status. Python is a global community and the PSF aims to support a safe environment for all. More information can be found on our Code of Conduct page.