Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Application Security Engineer II at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity and accuracy, and communicates findings with clients and security researchers across managed bug bounty programs.

Mid Posted about 1 hour ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security Application Security Engineer II at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates findings to clients and researchers across diverse applications.

Mid Posted about 1 hour ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security AI Security Analyst at LawPay

Monitors and secures AI deployments, assesses AI-specific risks like prompt injection and model misuse, and governs agentic systems across internal and customer-facing platforms.

Mid Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Information Security Engineer at LawPay

Operates cloud security stack, leads incident response and detection engineering, and manages vulnerability remediation across AWS infrastructure.

Mid Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AWS security operations: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams
  • Detection engineering: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity
  • Incident response & forensics: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews
  • Vulnerability management: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage
  • Security awareness & internal ops: Manage KnowBe4 phishing tests/training with Compliance
  • Platform security: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment
  • Data privacy & compliance support: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)
  • Product security & documentation: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate

About you:

  • 4+ years in security engineering or security operations, with real incident response experience.
  • Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).
  • Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python

preferred).

  • Experience with vulnerability management tooling and remediation SLA programs.

  • Comfortable operating independently in a distributed team; strong written English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • PCI DSS or SOC 2 environment experience; ASV scan operations.
  • Terraform/IaC security review experience.
  • Exposure to securing AI-assisted development or agentic tooling.

Additional Information

The monthly gross salary range for this position is CZK 90,000 to CZK 160,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security AI Security Analyst at LawPay

Monitors AI security risks, assesses generative AI deployments for threats, and ensures governance compliance for agentic systems and third-party AI vendors.

Mid Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security AI Security Analyst at LawPay

Monitors AI security risks, assesses AI use cases for threats, and supports governance of generative AI and agentic systems while performing traditional security operations.

Mid Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The AI Security Analyst is a hybrid role combining security operations monitoring with AI-specific risk management and governance support. The role focuses on identifying, assessing, and mitigating risks associated with AI use, particularly generative AI, LLMs, and agentic systems, across internal tools and customer-facing platforms, while contributing to traditional security monitoring. The role does not involve building or training AI models; it secures how AI is deployed, governed, monitored, and used.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AI security and risk management: Identify and mitigate AI-specific threats: prompt injection, jailbreaking and adversarial inputs, sensitive information disclosure, insecure output handling and excessive agency, model misuse and overreliance, and supply chain vulnerabilities in third-party AI services and models.
  • AI use-case review: Triage and risk-assess proposed AI use cases with Engineering, Product, Legal, and Privacy before production deployment; recommend controls and document decisions.
  • Agentic governance support: Support the operation of the company’s agentic-work governance model: autonomy classification reviews, agent activity monitoring, and evidence collection for governance reviews.
  • Vendor and model review: Evaluate third-party AI vendors, model providers, and AI-enabled features for security posture and data handling; maintain the approved-provider view.
  • Security operations and monitoring: Perform SOC-style monitoring, alert triage, and investigation across cloud, application, and AI-enabled systems, including AI API usage and data flows; enhance detection rules and logging for AI-specific activity.
  • Compliance and governance support: Support audit readiness for SOC 2 and PCI DSS and alignment with emerging AI frameworks (NIST AI RMF, OWASP LLM Top 10, ISO/IEC 42001 as the program matures); document AI security controls and risk assessments.
  • Incident support: Support AI-related incident response, investigation, and post-incident analysis.

About you:

  • 3+ years in security operations, security analysis, or GRC with hands-on technical exposure.

  • Working understanding of LLM-specific threat classes (OWASP LLM Top 10) and AI risk frameworks (NIST AI RMF).

  • Ability to read logs, write basic queries and scripts, and investigate independently.

  • Strong written English and documentation discipline; comfortable in a distributed team.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • Experience monitoring or governing agentic AI systems, MCP integrations, or AI developer tooling.
  • Fintech, legal-tech, or other regulated-industry background.

Additional Information

The monthly gross salary range for this position is CZK 75,000 to CZK 140,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Information Security Engineer at LawPay

Operates AWS security stack, performs detection engineering, leads incident response investigations, and manages vulnerability operations for a payments/compliance software platform.

Mid Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

It’s a new day with a new opportunity at 8am!

About the role:

The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.

Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.

This role is hired through an Employer of Record (EOR) partner in the Czech Republic.

About us:

8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.

More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.

What you’ll do:

  • AWS security operations: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams
  • Detection engineering: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity
  • Incident response & forensics: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews
  • Vulnerability management: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage
  • Security awareness & internal ops: Manage KnowBe4 phishing tests/training with Compliance
  • Platform security: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment
  • Data privacy & compliance support: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)
  • Product security & documentation: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate

About you:

  • 4+ years in security engineering or security operations, with real incident response experience.
  • Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).
  • Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python

preferred).

  • Experience with vulnerability management tooling and remediation SLA programs.

  • Comfortable operating independently in a distributed team; strong written English.

  • Demonstrated experience leveraging AI tools and technologies to improve workflows, enhance decision-making, or drive innovation.

  • This position is preferably based in Brno, Czech Republic

Bonus points:

  • PCI DSS or SOC 2 environment experience; ASV scan operations.
  • Terraform/IaC security review experience.
  • Exposure to securing AI-assisted development or agentic tooling.

Additional Information

The monthly gross salary range for this position is CZK 90,000 to CZK 160,000. 8am is committed to fair, objective, and non-discriminatory compensation, and actual pay may vary based on job-related knowledge, skills, experience, and education.

Why join our new 8am Brno hub?

  • Founding Team Impact: Be a founding engineer of our new Brno R&D hub. After a brief 1-6 month integration with U.S. based teams, you will help form fully autonomous, locally-led squads with clear paths to Staff and leadership roles
  • Drive our “AI-First” Transformation: We are building a secure, massive-scale “Unified AI Platform”. Depending on your squad, you will either help architect this core infrastructure (LLM routing, RAG, agent orchestration) or build directly on top of it.
  • Build the Next Generation of Our Platform: Help shape the systems powering products used by more than 250,000 professionals. You’ll work on complex platform capabilities across payments, workflow automation, and AI-powered features as we expand into new professional service markets.

Benefits and Perks

We offer a competitive, locally relevant benefits package designed to support your life in the Czech Republic while giving you access to global opportunities:

  • Performance bonus opportunities and employee referral rewards
  • Flexible Time Off (FTO) and 13 paid public holidays aligned with the Czech calendar
  • Paid sick leave with additional support through the Czech social security system
  • Maternity, paternity, and parental leave in line with Czech regulations, plus additional paid paternity leave from 8am
  • Full statutory benefits, including public health insurance, social security, pension, and work accident coverage

Grow Your Career

  • Access to Coursera (including Gen AI Academy) and ongoing professional development
  • Clear growth paths, regular feedback, and opportunities for advancement

What Makes 8am Different:

  • International company environment with collaboration across Europe and the U.S.
  • Opportunities to travel for company events (including potential U.S. visits)
  • Engaging team culture with local events, outings, and community initiatives
  • High-quality company swag and programs focused on wellness, learning, and connection

Diversity, equity & inclusion at 8am:

At 8am, we recognize that innovation occurs with a strong team of people who are diverse in background, personality, talent and ideas. Experience comes in many forms and ensuring a diverse and inclusive workplace where we continue to learn from each other is an integral part of our culture. We are committed to creating a welcoming and transparent environment for all that embraces those differences through education, equal access to opportunities and information, inclusionary programs, and community outreach.

Security advisory:

Our hiring teams at 8am are dedicated to recruiting top talent that share our passion for serving the professional services industry through innovative financial technology.  As such, our Talent Acquisition Team only follows legitimate hiring practices.  We will always communicate with our candidates using emails with the 8am domain and will never ask for sensitive/personal data during the application process.  All interviews take place over phone call, Zoom/Google Meet or in person.  All offers are communicated verbally by our Talent Acquisition Specialists with a written offer letter as a follow up.

Applicant Data Privacy Notice:

Your personal data will be collected and retained by Controller as long as Controller determines it is necessary to evaluate your application for employment. Under the GDPR, you have the right to request access to your personal data, to request that your personal data be rectified or erased, and to request that processing of your personal data be restricted. You also have the right to data portability. In addition, you may lodge a complaint with an EU supervisory authority.  Full policy linked here.

Read the full description
Security Software Engineer, Infrastructure Security

Builds and maintains infrastructure security systems to protect OpenAI's technology, people, and products from threats.

Mid Posted 1 day ago Jobicy AI
What this role involves
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products....
Read the full description
Security Vulnerability Management Engineer

Identifies, assesses, and remediates security vulnerabilities across systems and infrastructure.

Mid Posted 2 days ago Himalayas
What this role involves
What You'll Do We are looking for apassionate and drivenVulnerability Engineerto join our Vulnerability Management team.
Read the full description
Security Applied AI Security Engineer at Waabi

Designs and implements AI security controls, guardrails, and sandboxing patterns across company systems while auditing AI tool usage and training users on secure practices.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.

With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai

Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.

You will…

- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.

- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.

- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.

- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.

- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.

- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.

- Document guidance and patterns that a non-security audience can actually follow without needing a security background.

Qualifications:

- Bachelor’s degree in Computer Science or a related field.

- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.

- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.

- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.

- Strong communication skills - you work with engineers as a partner.

Bonus:

- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.

- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.

- Background in autonomous vehicles, robotics, or other safety-critical systems

The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations.  Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.

Perks/Benefits:

Waabi provides a competitive benefits package that includes:

- Competitive compensation and equity awards.

- Health and Wellness benefits that include Medical, Vision and Dental coverage.

- Unlimited Vacation.

- Flexible hours and Work from Home support.

- Daily drinks, snacks and catered meals (when in office).

- Regularly scheduled team building activities and social events.

- As we grow, this list continues to evolve!

Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!

Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Applied AI Security Engineer at Waabi

Establishes AI security controls, designs guardrails for enterprise AI tool adoption, and audits AI integrations to manage risks across the organization.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI. With a world-class team, we’re unlocking the next era of autonomous transportation with technology that’s powering commercial autonomous trucks and robotaxis. Waabi is backed by and partners with world leaders in AI, automotive, logistics, and deep tech.

With offices in Toronto, San Francisco, Dallas, and Pittsburgh, Waabi is growing quickly and looking for diverse, innovative and collaborative candidates who want to impact the world in a positive way. To learn more visit: www.waabi.ai

Waabi is leaning into an AI-native strategy — not just in our trucks, but in how we build, ship, and operate every day. Our teams leverage key AI tools to enhance productivity and efficiency, continuously expanding AI integration across our systems and workflows. That’s a huge unlock, and it’s moving fast. We’re looking for someone to make sure it keeps moving fast safely — by establishing the guardrails and collaborating on the implementation of sandboxes and automations that let people adopt AI with confidence instead of second-guessing themselves. You’ll join a small, sharp security team and take primary ownership of AI security controls and considerations across the company. If you’ve got a developer’s instincts, a security mindset, and you’re genuinely curious about what these tools can and can’t be trusted to do, this role is built around you.

You will…

- Audit how AI tools and MCP integrations are currently used across the company, and map where they touch sensitive systems, data, or credentials for the purpose of defining policy.

- Design and implement layered guardrails - enterprise-level system prompts, scoped permissions, sandboxing patterns - that constrain AI behavior before it ever reaches a user’s request.

- Maintain an inventory of both MCP servers and AI-to-service connections and their data access controls, with a clear model of what each one can access and why.

- Partner directly with users across the organization to bake secure-by-default patterns into their AI-assisted workflows so that written policy doesn’t just sit on a shelf.

- Evaluate new AI tools, plugins, and integration requests, and figure out the secure way to say yes.

- Continuously test and red-team your own guardrails - assume they’ll be pushed on, and find the gaps before someone else does.

- Document guidance and patterns that a non-security audience can actually follow without needing a security background.

Qualifications:

- Bachelor’s degree in Computer Science or a related field.

- Professional software development experience, with solid fundamentals in how services, APIs, and permissions fit together.

- Hands-on experience using AI coding/productivity tools (Claude, Copilot, Gemini, or similar) in business-critical workflows.

- Working knowledge of core security concepts — least privilege, sandboxing, trust boundaries, threat modeling basics.

- Strong communication skills - you work with engineers as a partner.

Bonus:

- Experience with MCP (Model Context Protocol) or similar tool-calling/agent-integration frameworks.

- Exposure to prompt injection, jailbreaking, or other AI/LLM-specific attack techniques.

- Background in autonomous vehicles, robotics, or other safety-critical systems

The US yearly salary range for this role is: $139,000- $258,000 USD and the Canada salary range for this role is: $118,000 - $168,000 CAD in addition to competitive perks & benefits. Waabi US Inc. and Waabi Canada Inc.’s yearly salary ranges are determined based on several factors in accordance with the Company’s compensation practices. The salary base range is reflective of the minimum and maximum target for new hire salaries for the position across all US and Canada locations.  Note: The Company provides additional compensation for employees in this role, including discretionary equity incentive awards and discretionary annual performance bonus.

Perks/Benefits:

Waabi provides a competitive benefits package that includes:

- Competitive compensation and equity awards.

- Health and Wellness benefits that include Medical, Vision and Dental coverage.

- Unlimited Vacation.

- Flexible hours and Work from Home support.

- Daily drinks, snacks and catered meals (when in office).

- Regularly scheduled team building activities and social events.

- As we grow, this list continues to evolve!

Waabi is a technology start-up building technologies to transform the way the world moves. Join our talented team to be a part of the future and to make an impact!

Waabi is an equal opportunity employer. We celebrate diversity and are committed to creating a supportive, inclusive, and accessible workplace for all our employees. We seek applicants of all backgrounds and identities, across race, color, ethnicity, national origin or ancestry, age, citizenship, religion, sex, sexual orientation, gender identity or expression, military or veteran status, marital status, pregnancy or parental status, caregiver status, disability, or any other characteristic protected by law. We make workplace accommodations for qualified individuals with disabilities as required by applicable law. If reasonable accommodation is needed to participate in the job application or interview process please let our recruiting team know.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Cyber-Security Operations Analyst III, Product AppSec

Monitors and responds to security threats, manages application security vulnerabilities, and ensures compliance with security protocols for Veeam's product infrastructure.

Mid Posted 3 days ago Jobicy AI
What this role involves
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI...
Read the full description
Security Information Security Engineer (R14207) at Oportun

Leads cybersecurity investigations across cloud, endpoint, and network environments, identifies and remediates security incidents using SIEM and EDR tools.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

ABOUT OPORTUN

Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.

WORKING AT OPORTUN

Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.

POSITION OVERVIEW

The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
  • Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation.
  • Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
  • Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
  • Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks.
  • Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.
  • Experience performing root cause analysis and correlating activity across multiple security technologies.
  • Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders.
  • Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations.
  • Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.
  • Continuous learning, security automation, and process improvement.

WHO YOU ARE / WHAT YOU BRING

  • Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation
  • Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality
  • Experience in conducting purple team exercises
  • Coordinate external takedowns and threat remediation with third-party providers.
  • Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
  • Experience using Wiz Cloud Native Application Protection Platform (CNAPP)
  • Experience conducting Threat Hunting using the MITRE ATT&CK framework.
  • Experience developing, tuning, or maintaining security detections and SIEM use cases.
  • Experience with SOAR platforms and security automation.
  • Experience conducting fraud investigations or partnering with Fraud Operations.
  • Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud.
  • Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.

#LI-REMOTE

#LI-GK1

We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.

California applicants can find a copy of Oportun’s CCPA Notice here:  https://oportun.com/privacy/california-privacy-notice/.

We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).

Read the full description
Security Information Security Engineer (R14207) at Oportun

Leads cybersecurity investigations across cloud, endpoint, and network environments, identifying and remediating security incidents while correlating data from SIEM and EDR tools.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

ABOUT OPORTUN

Oportun (Nasdaq: OPRT) is a mission-driven financial services company that puts its members’ financial goals within reach. With intelligent borrowing, savings, and budgeting capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $21.3 billion in responsible and affordable credit, saved its members more than $2.5 billion in interest and fees, and helped its members set aside an average of more than $1,800 annually.

WORKING AT OPORTUN

Working at Oportun means enjoying a differentiated experience of being part of a team that fosters a diverse, equitable and inclusive culture where we all feel a sense of belonging and are encouraged to share our perspectives. This inclusive culture is directly connected to our organization’s performance and ability to fulfill our mission of delivering affordable credit to those left out of the financial mainstream. We celebrate and nurture our inclusive culture through our employee resource groups.

POSITION OVERVIEW

The Information Security Engineer will lead cybersecurity investigations across cloud, endpoint, identity, SaaS, email, and network environments. This role is responsible for identifying, investigating, containing, and remediating security incidents while correlating data from SIEM, EDR, cloud, identity, and network security tools. The position partners closely with Engineering, Infrastructure, Fraud, Legal, Communications, and Product teams to manage incidents, communicate risk, and improve the organization’s security posture.

The ideal candidate has hands-on experience with incident response, threat hunting, detection engineering, and digital threat protection, along with knowledge of Windows, Linux, AWS, Active Directory, networking, and modern identity-based attacks. This role also supports continuous improvement through automation, AI-assisted security workflows, detection tuning, playbook development. Experience with cloud security, Kubernetes, Wiz, SOAR, purple teaming, fraud investigations, and third-party takedowns is preferred.

WHAT YOU’LL DO

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or 2-5 years of experience in Security Operations, Incident Response, Digital Threat Protection, Threat Intelligence, Cyber Forensics, or Detection Engineering.
  • Experience leading and coordinating cybersecurity investigations from initial detection through containment and remediation.
  • Experience with SIEM platforms such as Splunk for investigation, detection engineering, and threat hunting.
  • Experience investigating incidents across cloud, endpoint, identity, SaaS, and network environments.
  • Experience analyzing telemetry from EDR, firewalls, identity providers, proxies, cloud platforms, email security solutions, and authentication systems.
  • Strong understanding of Windows, Linux, Active Directory, Entra ID (Azure AD), AWS IAM, and modern identity attacks.
  • Working knowledge of networking fundamentals, including TCP/IP, DNS, HTTP/S, SMTP, VPNs, and common enterprise architectures.
  • Experience performing root cause analysis and correlating activity across multiple security technologies.
  • Ability to develop clear executive summaries and communicate technical findings to both technical and non-technical stakeholders.
  • Experience collaborating across Engineering, Infrastructure, Fraud, Legal, , Communications, and Product teams during investigations.
  • Strong documentation skills for investigations, incident timelines, playbooks, and lessons learned.
  • Continuous learning, security automation, and process improvement.

WHO YOU ARE / WHAT YOU BRING

  • Experience leveraging AI-assisted security tools and workflow automation to improve investigation efficiency, threat hunting, detection engineering, and documentation
  • Demonstrate ability to identify repetitive operational tasks suitable for automation and implement AI-enabled workflows that improve analyst productivity without reducing investigation quality
  • Experience in conducting purple team exercises
  • Coordinate external takedowns and threat remediation with third-party providers.
  • Investigate suspicious activity in AWS, Kubernetes, GitHub, SaaS platforms, and identity systems.
  • Experience using Wiz Cloud Native Application Protection Platform (CNAPP)
  • Experience conducting Threat Hunting using the MITRE ATT&CK framework.
  • Experience developing, tuning, or maintaining security detections and SIEM use cases.
  • Experience with SOAR platforms and security automation.
  • Experience conducting fraud investigations or partnering with Fraud Operations.
  • Experience investigating Account Takeover (ATO), payment fraud, synthetic identity fraud, or cyber-enabled fraud.
  • Security certifications such as GCIH, GCTI, AWS Security Specialty, Security+, or equivalent.

#LI-REMOTE

#LI-GK1

We are proud to be an Equal Opportunity Employer and consider all qualified applicants for employment opportunities without regard to race, age, color, religion, gender, national origin, disability, sexual orientation, veteran status or any other category protected by the laws or regulations in the locations where we operate.

California applicants can find a copy of Oportun’s CCPA Notice here:  https://oportun.com/privacy/california-privacy-notice/.

We will never request personal identifiable information (bank, credit card, etc.) before you are hired. We do not charge you for pre-employment fees such as background checks, training, or equipment. If you think you have been a victim of fraud by someone posing as us, please report your experience to the FBI’s Internet Crime Complaint Center (IC3).

Read the full description
Security Security Operations Engineer at DeepHealth

Builds and operates enterprise security controls, tooling, and automation across cloud and corporate environments while developing detection content and security automation.

Mid Posted 11 days ago RemoteFirstJobs Product
What this role involves

Description

The Security Operations Engineer builds and operates security controls, tooling, and automation across DeepHealth’s cloud and corporate environments. This role is responsible for configuring, integrating, and maintaining the enterprise security tooling stack, developing detection content, and automating security operations tasks so that controls are repeatable, version-controlled, and auditable.

Working within DeepHealth’s established security frameworks and under the direction of the Director, Security Operations, this position operates and tunes security controls, detection content, and guardrails. Independent validation of those controls sits with the security operations watch function — a deliberate separation that keeps the control environment defensible under audit. Remediation follows system ownership across Cloud Operations, Platform, and Application Development; this role supplies technical guidance and implements fixes directly where the control is security-owned.

This position operates within a regulated healthcare environment across a global operating footprint, with obligations under HIPAA, ISO/IEC 27001, and SOC 2. The role reports to the Director, Security Operations, with future reporting to the Manager, Security Operations as that position is established.

Requirements

·       Build, configure, integrate, and tune the enterprise security tooling stack across cloud and corporate environments.

·       Develop and maintain detection content, correlation rules, and response automation within the SIEM and SOAR platform.

·       Onboard new log sources and telemetry feeds, validating ingestion completeness, parsing accuracy, and field normalization.

·       Administer and tune endpoint detection and response tooling, including policy configuration, exclusion governance, and coverage validation.

·       Integrate security tooling with adjacent platforms through APIs to reduce manual handling and improve data quality.

·       Implement and maintain security configurations, guardrails, and baselines across Google Cloud Platform, Amazon Web Services, and Microsoft Azure.

·       Build and maintain security automation and infrastructure-as-code using Terraform or an equivalent framework, so that controls are version-controlled, repeatable, and auditable.

·       Implement policy-as-code and preventive guardrails using native cloud policy engines or an equivalent open policy framework.

·       Support cloud security posture management across all cloud environments, including finding deduplication, theme mapping, and routing to owning teams.

·       Harden cloud resources including compute, storage, database, container, and serverless services against established benchmarks.

·       Configure and maintain Microsoft 365 and Entra ID security controls, including conditional access, identity protection, and Defender workloads in a hybrid directory environment.

·       Implement and maintain least-privilege access models, roles, and policies across multiple cloud identity systems.

·       Implement container and Kubernetes security controls, including role-based access control, workload security standards, image scanning, and runtime protection.

·       Implement and maintain secrets management practices and tooling, and support the elimination of hard-coded credentials across environments.

·       Operate vulnerability management tooling, validate scan coverage, and translate raw scanner output into prioritized, owner-routed findings.

·       Provide technical remediation guidance to cloud, platform, identity, application, and endpoint owners, who retain accountability for closure of findings in their systems.

·       Implement engineering fixes for findings that fall to security-owned tooling and configuration.

·       Support remediation tracking for penetration test and vulnerability assessment findings by supplying technical detail and validating that fixes are technically sound.

·       Support incident detection and response through hands-on technical investigation, including log analysis, endpoint examination, identity and authentication tracing, and cloud audit log review.

·       Support escalations raised by the external managed security partner by supplying technical analysis and environment context.

·       Provide feedback into detection quality and alert tuning to reduce noise and improve signal for the monitoring function.

·       Contribute technical findings to post-incident review, and implement the resulting control and detection improvements.

·       Participate in tabletop exercises and resilience testing, and act on the technical gaps those exercises surface.

·       Document all engineering changes to security controls through the change management process, including validation criteria and rollback plans.

·       Produce and maintain runbooks, playbooks, and technical operating procedures for repeatable security operations tasks.

·       Write clear, documented, and reviewable code and configuration so that work can be inspected, maintained, and handed over without dependence on any one individual.

·       Support audit, certification, and customer assurance activities by producing technical evidence on request.

·       Maintain accurate inventory of security tooling, control coverage, licensing position, and control operating status.

·       Maintain strict confidentiality of security testing results, control configuration detail, and investigative material, and follow established standards for external disclosure.

PLEASE NOTE: This is not an exhaustive list of all duties, responsibilities and requirements of the position described above.  Other functions may be assigned and management retains the right to add or change duties at any time.

Minimum Qualifications, Education and Experience

·       4+ years of hands-on experience in security operations, security engineering, or a comparable technical security role. (Required)

·       Bachelor’s degree in information technology, computer science, cybersecurity, or a related field, or equivalent professional experience. (Required)

·       2+ years of hands-on cloud security experience across at least one major cloud provider; Google Cloud Platform and Amazon Web Services preferred. (Required)

·       2+ years operating and tuning a SIEM platform, including working with detection content and log sources. (Required)

·       1+ year administering Microsoft 365 and Entra ID security controls in a hybrid directory environment. (Required)

·       Working knowledge of security automation; experience with scripting and infrastructure-as-code is required, with Terraform experience preferred. (Required)

·       Working knowledge of cloud security posture management and preventive controls. (Required)

·       Working knowledge of container and Kubernetes security, including role-based access control and image scanning. (Required)

·       Working knowledge of secrets management tooling and practices. (Required)

·       Practical experience with endpoint detection and response tooling. (Required)

·       Working knowledge of vulnerability management and the finding remediation lifecycle, including risk-based prioritization. (Required)

·       Scripting capability in at least one of: Python, PowerShell, or Bash. (Required)

·       Familiarity with recognized security frameworks including NIST Cybersecurity Framework, ISO/IEC 27001, and SOC 2. (Required)

·       Able to communicate technical findings clearly in writing and verbally to both technical and non-technical audiences. (Required)

·       Able to manage assigned work independently and escalate appropriately. (Required)

·       Available to support incident response activity outside standard business hours as required. (Required)

·       Microsoft Office experience. (Required)

·       Industry certification such as Security+, CompTIA CySA+, or a cloud provider security certification. (Preferred)

·       Experience in healthcare, medical device, or another regulated industry, and working familiarity with HIPAA obligations. (Preferred)

·       Experience working alongside or integrating with a managed security service provider. (Preferred)

Quality Standards

·       Communicates, cooperates, and consistently functions professionally and harmoniously with all levels of supervision, co-workers, visitors, and vendors.

·       Demonstrates initiative, personal awareness, professionalism and integrity, and exercises confidentiality in all areas of performance.

·       Follows all local, regional and country laws concerning employment.

·       Follows all DeepHealth policies and procedures.

·       Follows data privacy, compliance, safety and confidentiality standards at all times.

·       Practices universal safety precautions.

·       Promotes good public relations on the phone and in person.

·       Adapts and is willing to learn new tasks, methods, and systems.

·       Reports to work regularly as scheduled; consistently punctual with respect to working hours, meal and rest breaks, and maintains satisfactory personal attendance in accordance with DeepHealth guidelines.

·       Completes job responsibilities in a quality and timely manner.

Travel

This position requires domestic / international travel up to 10%.

Working Environment

Remote

Physical Demands

This position often requires sitting, standing, walking, bending, twisting, reaching with hands and arms, using hands and fingers, handling, or feeling, speaking, listening, and high-level cognitive thinking. Also, must be able to lift up to 10 pounds occasionally.

Work Authorization / Visa Sponsorship: DeepHealth does not provide immigration sponsorship for this position, including sponsorship for employment-based visas or other work authorization requiring employer sponsorship. Candidates must be legally authorized to work in the United States without current or future sponsorship from DeepHealth for the duration of employment.

Read the full description
Security Consultant (Technology) (m/w/d)

Conducts cybersecurity assessments, develops security strategies and ISMS frameworks, and identifies organizational risks.

Mid Posted 11 days ago Himalayas
What this role involves
Die Aufgaben eines Consultant (Technology) (m/w/d) sind vielfältig und können unter anderem folgende Tätigkeiten umfassen: • Durchführung von Cyber-Security-Assessments, Schwachstellenanalysen und Risikoidentifikation • Entwicklung und Implementierung von Sicherheitsstrategien, Referenzarchitekturen, Richtlinien und Standards • Aufbau und Betreuung von ISMS (z.
Read the full description
Security Oracle Cloud Security Engineer

Implements and maintains security infrastructure on Oracle Cloud Platform, managing access controls, compliance, and threat detection.

Mid Remote Posted 11 days ago Himalayas
What this role involves
Oracle Cloud Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description
Security Security Engineer at Corbalt

Integrates security into the software development lifecycle, identifies vulnerabilities, and builds automation tools to improve security practices across engineering teams.

Mid Remote Posted 12 days ago RemoteFirstJobs Product
What this role involves

About Corbalt

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems. We build shared platforms, engineering foundations, and reusable services that enable mission teams to deliver software faster, operate more efficiently, and scale with confidence.

Our roots trace back to the Healthcare.gov recovery effort, where we saw firsthand what talented, mission-driven teams could accomplish together. That experience shaped how we work today: solving complex technical challenges through collaboration, pragmatic engineering, and a relentless focus on delivering value.

Today, we support critical healthcare modernization efforts at the Centers for Medicare & Medicaid Services (CMS), helping build and operate the platforms, tools, and services that enable teams across Medicare and Medicaid to deliver secure, resilient digital experiences.

We’re a remote-first team that values curiosity, kindness, ownership, and continuous learning. We enjoy solving hard technical problems, partnering closely with our clients, and building technology that makes government work better for the people who rely on it.

Contingent Position: This position is contingent upon Corbalt’s successful contract award. Employment offers and start dates are dependent on the award of the associated government contract.

Security Engineer

We’re looking for a Security Engineer who enjoys building secure software, improving engineering platforms, and helping teams deliver with confidence. You’ll work closely with software engineers to integrate security into the development lifecycle, automate security practices, and build resilient cloud-native systems that support critical government services.

Responsibilities

  • Integrate security into the software development lifecycle through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform that improve security, developer productivity, and operational visibility (it’s not important that you know these languages).
  • Support security assessments, compliance activities, and continuous monitoring.
  • Contribute to security best practices across engineering teams.

Skills

  • Strong software engineering fundamentals and experience writing production code.
  • Experience with application security, DevSecOps, or cloud security.
  • Understanding of secure software design, authentication/authorization, and common application vulnerabilities.
  • Familiarity with at least one commonly used programming language and one infrastructure-as-code language.
  • Strong communication and collaboration skills with engineering and technical stakeholders.

Experience

  • 3+ years of engineering experience
  • Demonstrated ability to operate independently and ramp quickly in complex environments
  • Experience supporting security assessments, compliance, or continuous monitoring in regulated environments
  • Familiarity with federal cloud and security requirements (e.g., FISMA)
  • Demonstrated experience operating and analyzing systems in AWS, Azure, or Google Cloud.

Values

  • Growth-oriented mindset
  • Intrinsic motivation to learn, grow, and do great work
  • Kindness
  • Grit / perseverance / resilience

Compensation & Benefits

The base salary range for this position is: $138,677 - $182,296 per year.

In addition to the base salary, Corbalt offers:

  • Medical, dental, vision benefits
  • Profit sharing and discretionary bonuses
  • A company 401(k) contribution equal to 3% of your salary
  • Paid vacation, sick time, and company holidays
  • Reimbursement for reasonable expenses that are helpful for work
  • In-person company retreats

Hiring Process

  • The first stage is an informal conversation to learn more about each other, answer questions, and discuss the role.
  • The second stage is a mini-project based on something we’ve actually worked on. The goal of this is to get an idea of what working together is like.
  • The last stage is: a 10-20 minute presentation to the team describing what you did on a previous project and two 30 minute conversations with other people on the team to get an additional perspective on what our work is like.

Other Requirements

  • Due to contractual requirements applicants must:
    • Be authorized to work in the United States
    • Currently reside in the United States or its territories
    • Have resided in the United States or its territories for three of the last five years
    • Have at least three years of professional experience
  • Due to contractual and security requirements, all work must be performed while physically present within the United States or its territories. Work performed while outside the U.S. or its territories is strictly forbidden.
  • Corbalt participates in E-Verify. Upon hire, your Form I-9 information will be provided to the federal government to confirm you are authorized to work in the United States.

Corbalt is an Equal Opportunity Employer, including disability and protected veteran status.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Engineer, Application Security at GameChanger

Embeds security practices throughout the software development lifecycle, conducts code reviews, maintains secure coding standards, and integrates security tooling into CI/CD pipelines.

Mid Remote Posted 12 days ago RemoteFirstJobs Product
What this role involves

About GameChanger:

We believe in the life changing impact youth sports have on and off the field. Sports encourage leadership, teamwork, responsibility, and confidence – important life lessons that have the power to propel our youth toward meaningful futures. We recognize that without coaches, parents, and volunteers, organized youth sports could not exist. By building the first and best place to experience the youth sports moments important to our community, we are helping families elevate the next generation through youth sports.

So if you love sports and their community building potential, or building cool products is your sport, GameChanger is the team for you. We are a remote first, dynamic tech company based in New York City, and we are solving some of the biggest challenges in youth sports today.

The Position:

We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation.

What You’ll Do:

Application security

  • Embed security into every phase of the SDLC

  • Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack

  • Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes

  • Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance

  • Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)

  • Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams

  • Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers

DevSecOps

  • Integrate and maintain security tooling across CI/CD pipelines

  • Enforce security quality gates in delivery pipelines

  • Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments

  • Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows

  • Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)

  • Implement and validate security controls for containerized workloads

  • Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints

Vulnerability & Risk Management

  • Operate the application vulnerability management lifecycle

  • Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability

  • Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes

  • Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership

  • Effectively communicate security risk clearly to both engineering and business leaders

What You’ll Bring:

  • 3+ years in application security engineering

  • Proven experience building and operating internal security developer platforms or tooling that reduces developer friction

  • Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability

  • Hands-on experience leading threat modeling engagements and designing paved roads

  • Proven track record integrating security tooling into CI/CD pipelines

  • Working knowledge of OWASP Top 10s (web, mobile, API, LLM)

  • Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches

  • Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin

  • Track record of implementing secure primitives in mobile ecosystems (iOS/Android)

  • Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.

Who You Are:

  • Pragmatic defender. You understand that security must enable the business, not block it. You look for “secure by default” solutions and know how to make the right path the easy path for engineers.

  • Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default.

  • Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in.

  • Automation-first. If you have to do it twice, you’d rather write the script.

  • Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly.

  • Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation.

  • Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction.

Perks:

  • Work remotely throughout the US* or from our well-furnished, modern office in Manhattan, NY.

  • Unlimited vacation policy.

  • Paid volunteer opportunities.

  • Technology stipend - $4,000 every 2 years after your start to make sure you have the latest and greatest technology.

  • WFH stipend - $500 annually to make your WFH situation comfortable.

  • Monthly physical, mental, wellness & learning stipend offered through Holisticly.

  • Monthly lifestyle stipend offered through Fringe.

  • Full health benefits - medical, dental, vision, prescription, FSA, HRA, HSA, and coverage for family/dependents.

  • Retirement savings - Traditional and Roth 401K plans are offered through Vanguard, with an immediate company match.

  • Life insurance - basic life, supplemental life, and dependent life.

  • Disability leave - short-term disability and long-term disability.

  • Company paid parental leave - up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.

  • Family building benefits offered through Progyny.

  • DICK’S Sporting Goods and their family of brands teammate discount.

The target salary range for this position is between $120,000 and $140,000. This is part of a total compensation package that includes incentive, equity, and benefits for eligible roles. Individual pay may vary from the target range and is determined by several factors including experience, internal pay equity, and other relevant business considerations. We constantly review all teammate pay to ensure a great compensation package that is fair and equal across the board.

\* DICK’S Sporting Goods has company-wide practices to monitor and protect the company from significant compliance and monetary implications as it pertains to employer state tax liabilities. Due to said guidelines put in place, we are unable to hire in AK, DE, HI, IA, LA, MS, MT, OK, and SC.

We are an equal opportunity employer and value diversity in our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

IMPORTANT NOTICE: All official recruitment communications from GameChanger will come from an email address ending in @gc.com or no-reply@ashby.hq.com. If you receive communication from any other domain, please be cautious, as it is likely fraudulent.

Read the full description
Security WAF Services Expert

Administers and optimizes Web Application Firewall (WAF) infrastructure, manages rulesets, and coordinates with application teams on security configurations.

Mid Remote Posted 12 days ago Himalayas
What this role involves
This is a remote position. WAF Services ExpertLocation: RemotePeriod: 01/11/2026 to 31/12/2027Utilisation: Part-time (TBC - approx 36-45% utilisation depending on confirmed period)Contract type: Contract / freelanceKey Responsibilities• Administration of the WAF • WAF ruleset management • WAF platform optimisation according to vendor recommendations and best practice • Liaising with relevant application teams for WAF rule optimisation • Development of customised WAF rules • Documentation of all changes in WAF environments • Monthly activity reports RequirementsEligibility• You must already hold the right to work in the EU, EEA or Switzerland Requirements• Fluent English • Proven experience administering Azure WAF in a production environment • Strong communication skills for liaising with cross-functional application teams BenefitsAs a freelancer / contractor with us, you will enjoy flexible working hours and the freedom to choose your own projects.
Read the full description