Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Senior Security Engineer, Bug Bounty at Mozilla

Manages Mozilla's bug bounty program, triages security reports, validates vulnerabilities, and drives remediation with engineering teams.

Senior Posted about 2 hours ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R3105

Hiring Ranges:

US Tier 1 Locations

$137,000—$183,000 USD

US Tier 2 Locations

$126,000—$168,000 USD

US Tier 3 Locations

$116,000—$155,000 USD

Read the full description
Security Senior Security Engineer, Bug Bounty at Mozilla

Owns and manages Mozilla's bug bounty program, triaging vulnerability reports, validating findings, and coordinating remediation with engineering teams.

Senior Posted about 2 hours ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R3105

Hiring Ranges:

Canada Tier 1 Locations

$104,000—$139,000 CAD

Canada Tier 2 Locations

$95,000—$126,000 CAD

Read the full description
Security Senior Security Engineer, Bug Bounty at Mozilla

Manages Mozilla's bug bounty program, triages security reports, validates vulnerabilities, and coordinates remediation with engineering teams.

Senior Posted about 2 hours ago RemoteFirstJobs Product
What this role involves

To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu.

To learn more about our Hiring Range System, please click this link.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-DNI

Req ID: R3105

Read the full description
Security Engineer, Security Operations & Engineering at Collibra NV

Design and implement secure cloud architectures, manage threat detection and incident response, and ensure compliance with global security standards.

Senior Posted about 6 hours ago RemoteFirstJobs Product
What this role involves

Joining Collibra’s Security Operations & Engineering team

This is an opportunity to work in the Security Operations & Engineering team within the growing Collibra Security Organization.Security Engineers at Collibra design, build, and operate the systems that safeguard our data, infrastructure, and customers. The team combines technical depth with automation and innovation, embedding security across our platforms to ensure resilience and stay ahead of evolving threats. We partner across the business to architect secure systems, embed zero-trust principles, and automate detection and response. Security Engineers are hands-on builders who strengthen Collibra’s defense posture through engineering excellence and continuous improvement.

Security Engineers at Collibra are responsible for

  • Designing and implementing secure architectures across cloud environments, embedding zero-trust principles and identity-based access controls.
  • Managing threat detection, vulnerability assessments, and penetration testing to identify and remediate risks proactively.
  • Leading incident response and leveraging threat intelligence to detect, contain, and prevent evolving cyber threats.
  • Ensuring compliance with global security standards (ISO 27001, NIST 800-53, CIS, OWASP, SOC 2, CSA) and continuously improving Collibra’s security posture.
  • Supporting internal and external security audits by providing necessary documentation and evidence.

You have

  • 5+ years of experience in Information Security, Security Engineering, or a related technical field.
  • Strong understanding of CI/CD workflows and IAC
  • Experience securing cloud environments (AWS, GCP, or Azure).
  • Hands-on experience with SIEM, EDR, vulnerability management, and incident response tools.
  • Strong understanding of network and application security concepts, identity and access management, and encryption practices.
  • Working knowledge of Data Analysis / Data Science concepts and tooling (SQL, Python, etc.)
  • A bachelor’s degree in Computer Science, Information Security, or equivalent related experience.
  • Because this role supports the US government, it is required that this candidate be a US citizen who resides on US soil.
  • Demonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.
  • A bachelor’s degree or equivalent related working experience is required
  • This position is not eligible for visa sponsorship.

You are

  • Analytical, curious, and eager to understand complex systems and emerging threats.
  • Adaptable and ready to learn new tools, techniques, and technologies.
  • Able to communicate security concepts clearly to both technical and non-technical audiences.
  • Collaborative and proactive, with a strong sense of ownership and accountability.
  • Committed to continuous improvement and automating solutions to reduce manual effort.

Measures of Success Are

  • Within your first month: You will understand Collibra’s infrastructure, security architecture, and monitoring environment.
  • By your third month: You will contribute to threat detection, incident response, and vulnerability management workflows.
  • By your sixth month: You will design and implement security automation or architectural improvements that measurably strengthen Collibra’s security posture.

Compensation for this role

The standard base salary range for this position is $116000 - $145000 per year. This position is not eligible for additional commission-based compensation. Salary offers are based on a combination of factors, including, but not limited to, experience, skills, and location.

In addition to base salary, we offer a competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.

Benefits at Collibra

Collibra recognizes and values that everyone has different needs, interests, and life goals. We built our benefits program with flexibility in mind to support you and your loved ones through a diverse range of circumstances and life events. These flexible offerings sit on a foundation of competitive compensation, health coverage, and time off. Learn more about Collibra’s benefits.

We create inclusion and belonging through how we onboard, meet, connect, engage, and communicate. Learn more about diversity, equity, and inclusion at Collibra.

At Collibra, we’re proud to be an equal opportunity employer. We realize the key to creating a company with a world-class culture and employee experience comes from who we hire and creating a workplace that celebrates everyone.

With this, we proudly consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sexual orientation, pregnancy, sex, gender identity, gender expression, genetic information, physical or mental disability, HIV status, registered domestic partner status, caregiver status, marital status, veteran or military status, citizenship status or any other legally protected category. If you have a need that requires accommodation, let us know by completing our Accommodations for Applicants form.

Read the full description
Security Senior AI/LLM Penetration Tester at Bishop Fox

Conducts penetration testing and security assessments of AI/LLM applications, identifying vulnerabilities in language models, agents, and AI-powered systems.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining elite human expertise with the power of its proprietary Cosmos AI engine, the firm delivers industry-leading cloud and application security services, including AI-powered penetration testing and AI/LLM security assessments that reflect real-world attacker behavior. Renowned for its innovation and contributions to the open-source community through flagship tools like Sliver and AIMap, Bishop Fox has released 25+ tools and 75+ advisories in the last 10 years.

As a trusted partner to the world’s most recognizable brands, Bishop Fox protects 26 of the Fortune 100, eight of the top 10 global tech companies, all of the top five global media companies, 10 of the top 20 retailers and 7 of the top 10 manufacturers. A consistent market leader, Bishop Fox has been recognized as a Leader and “Fast Mover” in the GigaOm Radar for Attack Surface Management for five consecutive years. With a 70 NPS rating, the firm remains the trusted partner for organizations seeking to stay ahead of the evolving threat landscape. Learn more at bishopfox.com.

We are now hiring a SeniorAI/LLM Security Consultant to help clients stay ahead of emerging AI threats by conducting cutting-edge security assessments of large language models, AI agents, and AI-powered applications.

Who You Are and What You’ll Do

Our wants are simple: be good at—and most importantly—love what you do. Here’s what we’re looking for:

  • 5+ years of offensive security experience performing penetration tests, red team engagements, or application security assessments

  • Experience assessing AI/LLM-powered applications for vulnerabilities such as:

    • Prompt injection
    • Jailbreak techniques
    • Indirect prompt injection
    • Data leakage and sensitive information disclosure
    • Insecure tool/function calling
    • Agentic AI abuse
    • Model misuse and unsafe output generation
    • Understanding of modern AI architectures, including:
  • Experience performing manual application security testing beyond automated scanning

  • Strong understanding of web application security fundamentals, including the OWASP Top 10 Web, Agentic, and LLM Applications.

  • Experience reviewing AI application architectures and identifying security weaknesses across APIs, cloud infrastructure, and application logic

  • Experience performing source code review and dynamic testing

  • Familiarity with cloud platforms (AWS, Azure, or GCP) and securing AI workloads

  • Scripting or programming experience in Python, JavaScript Go, Java, or similar languages

  • Familiarity withLLM application and agent-orchestration frameworks, inference provider APIs, external capability integration for models, and open sourcetooling across commercial and self-hosted ecosystems.

  • Knowledge of authentication, authorization, networking, APIs, and secure software development practices

  • Excellent written and verbal communication skills, including presenting findings to technical and executive audiences

  • Ability to mentor teammates and contribute to internal research, tooling, and methodology development

  • OSCP, OSEP, GWAPT, GPEN, GXPN, or other relevant certifications are helpful but not required

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field is a plus

What Sets You Apart

  • Experience conducting AI red team exercises against production or pre-production AI systems

  • Research into emerging AI attack techniques or contributions to the offensive security community

  • Experience building or securing AI agents and autonomous workflows

  • Knowledge of adversarial machine learning concepts and model security

  • Experience with cloud-native AI platforms such as Azure OpenAI, Amazon Bedrock, or Google Vertex AI

  • Familiarity with AIsoftware development lifecycle (AI SDLC) and AI governance frameworks

Why Bishop Fox

At Bishop Fox, we’re driven by a simple mission: deliver exceptional quality to our clients, foster a vibrant and fulfilling environment for our team, and champion excellence within our industry. Our core values, which we live by every day, are:

  • Be Excellent to Each Other

  • Do the Right Thing

  • Do What You’ll Say You’ll Do

  • Get Better Together

  • Give a Sh*t

This position is not eligible for visa sponsorship. Applicants must be authorized to work in the United States of America for the duration of employment without sponsorship.

Bishop Fox has always allowed its employees to work remotely, and this role can be based anywhere in the United States.

Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and foster an inclusive culture where employees are empowered to do their best work while advancing the security community through world-class research and consulting.

Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including sexual orientation and gender identity), national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must successfully complete a background check as a condition of employment.

Interested? Apply today!

Read the full description
Security DevSecOps Engineer at Raya

Embed security best practices into AWS/EKS infrastructure and CI/CD pipelines, triaging vulnerabilities and collaborating with DevOps teams to harden cloud environments.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

We prioritize learning and teamwork and love giving people the opportunity to champion solutions to big challenges and grow into better versions of themselves. A great candidate believes in Raya’s vision, which is to enrich lives by fostering relationships through quality, in person interactions. You thrive at the intersection of DevOps and Security, and you’re excited to drive measurable impact by hardening our AWS/EKS environment and systematically closing out security findings.

Responsibilities

  • Security Ownership: Drive software engineering security hygiene end-to-end, from identifying vulnerabilities and misconfigurations to implementing durable fixes across our platform. This includes AWS, Kubernetes, CDN/WAF, and other technologies used in the PDLC

  • Cross-Functional Collaboration: Work hand-in-hand with DevOps and Engineering teams to embed security best practices into everyday workflows, without slowing down velocity

  • Continuous Learning: Stay current on evolving cloud security threats, tooling, and best practices, ensuring Raya’s infrastructure stays ahead of emerging risks

  • Findings Remediation: Triage, prioritize, and systematically close out security findings, translating scanner output into practical, actionable engineering fixes

  • Operational Excellence: Expand and maintain security checks and guardrails in CI/CD pipelines and the broader PDLC, so security becomes a natural part of how we ship, not an afterthought

Qualifications

  • Strong hands-on experience with AWS and Kubernetes/EKS, comfortable navigating cloud infrastructure and container environments from day one

  • Solid foundation in security fundamentals: vulnerability management, IAM, network security, and cloud security posture management

  • Experience triaging and remediating security findings from vulnerability scanners or cloud security tools

  • Familiarity with CI/CD pipelines and integrating security practices into the software development lifecycle

  • Strong communication skills, able to work effectively with both DevOps and Security stakeholders and translate technical risk into clear priorities

  • Experience with Infrastructure-as-Code (e.g., Terraform/OpenTofu), compliance frameworks, or container security tooling

What Sets You Apart

  • Bridge Builder: You naturally sit at the intersection of DevOps and Security, translating between the two and earning trust from both sides

  • Impact-driven: You prioritize the fixes and improvements that meaningfully reduce risk, rather than chasing every alert

  • Growth-oriented: You possess a perpetual learner’s mindset, staying curious about new threats, tools, and cloud-native security practices

  • Ownership mentality: You take findings from discovery to resolution without needing to be chased, and you build systems so problems don’t recur

  • Productivity-obsessed: You value tools, workflows, and automation that make security scalable rather than manual

  • Bias toward shipping and iteration: You’re able to harden systems incrementally, learn, and refine in short cycles rather than waiting for a “perfect” fix

$160,000 - $190,000 a year

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior IAM Engineer at Calendly

Designs, implements, and maintains identity and access management systems, automation workflows, and security controls to protect company infrastructure and enable secure user access at scale.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

What’s in it for you?

Ready to make a serious impact? Millions of people already rely on Calendly, and we’re still in the midst of exciting product growth — it’s a fantastic time to join us. Everything you’ll work on here will accelerate your career to the next level. If you want to learn, grow, and do the best work of your life alongside the best people you’ve ever worked with, then we hope you’ll consider allowing Calendly to be a part of your professional journey.

About the team & opportunity

What’s so great about working on Calendly’s Operations team?

We are the foundation that aims to set up our people for success to do the best work of their life at Calendly.

Why do we need you? Well, we are looking for a Senior IAM Engineer who will bring adaptability, ownership, and a strong desire to drive meaningful results across Calendly. You will report to the Senior Director, IT & Business Systems and will be responsible for owning Calendly’s Identity and Access Management (IAM) strategy, tools, and lifecycle processes. This includes designing, implementing, and maintaining secure access controls, automation workflows, and governance frameworks. In this role, you will work in direct partnership with Calendly’s executives and senior leaders to ensure our IAM posture not only protects the business but also enables productivity at scale.

A day in the life of a Senior IAM Engineer at Calendly

On a typical day, you will:

  • Builds automation workflows to streamline provisioning, deprovisioning (onboarding/offboarding), and access governance.
  • Defines and implements IAM security posture improvements, including business process strategy, entitlement, and access management.
  • Manages the IAM environment including Access Groups, Service Accounts, Sandbox access, and API configuration.
  • Proactively identifies and resolves IAM lifecycle management issues.
  • Conducts regular assessments and audits of relevant systems to ensure compliance with industry standards and regulations.
  • Maintains application dashboards and relevant documentation.
  • Provides high-level estimates for tasks and projects, assisting with project planning and prioritization.
  • Troubleshoots and resolves technical issues related to systems in a timely manner.
  • Collaborates cross-functionally with technical and non-technical stakeholders, clearly communicating complex IAM concepts (e.g., RBAC) to diverse audiences.
  • Facilitates governance discussions with business leaders and partners, ensuring alignment between security needs, compliance requirements, and business objectives.

What do we need from you?

Basic Qualifications

  • 5–7 years of direct IT experience, with 2–3 years as an Okta administrator and/or architect
  • Expert knowledge of Okta products and services, including Okta Identity Cloud, Okta Workflows, and Okta API Access Management.
  • Proficiency in integrating Okta solutions with various applications and systems such as HR systems, finance systems, and cloud platforms.
  • Experience with Google Workspace administration and automation tooling, including GAM for user and group lifecycle management.
  • Hands-on experience with modern identity management tools and public cloud platforms (e.g., Multi-Factor Authentication, Security Tokens, OAuth, Amazon Web Services, Atlassian).
  • Experience working in a primarily macOS, remote-first environment.
  • Strong cross-functional communication skills, with the ability to explain complex IAM concepts to non-technical stakeholders and guide governance discussions.
  • Authorized to work lawfully in the United States of America, as Calendly does not engage in immigration sponsorship at this time.

Preferred Skills and Qualifications

  • Okta Certified Administrator

What’s in it for you?

Ready to make a serious impact? Millions of people already rely on Calendly’s products, and we’re still in the midst of our growth curve — it’s a fantastic time to join us. Everything you’ll work on here will accelerate your career to the next level. If you want to learn, grow, and do the best work of your life alongside the best people you’ve ever worked with, then we hope you’ll consider allowing Calendly to be a part of your professional journey.

If you are an individual with a disability and would like to request a reasonable accommodation as part of the application or recruiting process, please contact us at recruiting@calendly.com . Calendly is registered as an employer in many, but not all, states. If you are located in Alaska, Hawaii, Montana, North Dakota, South Dakota, Nebraska, Iowa, West Virginia, and Rhode Island, you will not be eligible for employment. Note that all individual roles will specify location eligibility.

All candidates can find our Candidate Privacy Statement here

Candidates residing in California may visit our Notice at Collection for California Candidates here: Notice at Collection

The ranges listed below are the expected annual base salary for this role, subject to change.

Calendly takes a number of factors into consideration when determining an employee’s starting salary, including relevant experience, relevant skills sets, interview performance, location/metropolitan area, and internal pay equity.

Base salary is just one component of Calendly’s total rewards package. All full-time (30 hours/week) employees are also eligible for our Top Performer Bonus program (or Sales incentive), equity awards, and competitive benefits.

Calendly uses the zip code of an employee’s remote work location, or the onsite building location if hybrid, to determine which metropolitan pay range we use. Current geographic zones are as follows:

  • Tier 1: San Francisco, CA, San Jose, CA, New York City, NY
  • Tier 2: Chicago, IL, Austin, TX, Denver, CO, Boston, MA, Washington D.C., Philadelphia, PA, Portland, OR, Seattle, WA, Miami, FL, and all other cities in CA.
  • Tier 3: All other locations not in Tier 1 or Tier 2

Tier 1 Salary Hiring Range

$163,548.84—$192,410.40 USD

Tier 2 Salary Hiring Range

$149,919.77—$176,376.20 USD

Tier 3 Salary Hiring Range

$136,290.70—$160,342 USD

The ranges listed above are the expected annual base salary for this role, subject to change.

Calendly takes a number of factors into consideration when determining an employee’s starting salary, including relevant experience, relevant skills sets, interview performance, location/metropolitan area, and internal pay equity.

Base salary is just one component of Calendly’s total rewards package. All full-time (30 hours/week) employees are also eligible for our Top Performer Bonus program (or Sales incentive), equity awards, and competitive benefits.

Calendly uses the zip code of an employee’s remote work location, or the onsite building location if hybrid, to determine which metropolitan pay range we use. Current geographic zones are as follows:

  • Tier 1: San Francisco, CA, San Jose, CA, New York City, NY
  • Tier 2: Chicago, IL, Austin, TX, Denver, CO, Boston, MA, Washington D.C., Philadelphia, PA, Portland, OR, Seattle, WA, Miami, FL, and all other cities in CA.
  • Tier 3: All other locations not in Tier 1 or Tier 2

If you are an individual with a disability and would like to request a reasonable accommodation as part of the application or recruiting process, please let your Recruiter know when first connecting with them. Calendly is registered as an employer in many, but not all, states. If you are located in Alaska, Delaware, Hawaii, Idaho, Iowa, Montana, Nebraska, North Dakota, Rhode Island, South Dakota, and West Virginia, you will not be eligible for employment. Note that all individual roles will specify location eligibility.

All candidates can find our Candidate Privacy Statement here

Candidates residing in California may visit our Notice at Collection for California Candidates here: Notice at Collection

This role may require occasional travel for company events, team collaboration, or offsites.

Read the full description
Security Senior AI/LLM Penetration Tester at Bishop Fox

Conducts security assessments and penetration tests on AI/LLM applications to identify vulnerabilities and protect against emerging AI threats.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining elite human expertise with the power of its proprietary Cosmos AI engine, the firm delivers industry-leading cloud and application security services, including AI-powered penetration testing and AI/LLM security assessments that reflect real-world attacker behavior. Renowned for its innovation and contributions to the open-source community through flagship tools like Sliver and AIMap, Bishop Fox has released 25+ tools and 75+ advisories in the last 10 years.

As a trusted partner to the world’s most recognizable brands, Bishop Fox protects 26 of the Fortune 100, eight of the top 10 global tech companies, all of the top five global media companies, 10 of the top 20 retailers and 7 of the top 10 manufacturers. A consistent market leader, Bishop Fox has been recognized as a Leader and “Fast Mover” in the GigaOm Radar for Attack Surface Management for five consecutive years. With a 70 NPS rating, the firm remains the trusted partner for organizations seeking to stay ahead of the evolving threat landscape. Learn more at bishopfox.com.

We are now hiring a SeniorAI/LLM Security Consultant to help clients stay ahead of emerging AI threats by conducting cutting-edge security assessments of large language models, AI agents, and AI-powered applications.

Who You Are and What You’ll Do

Our wants are simple: be good at—and most importantly—love what you do. Here’s what we’re looking for:

  • 5+ years of offensive security experience performing penetration tests, red team engagements, or application security assessments

  • Experience assessing AI/LLM-powered applications for vulnerabilities such as:

    • Prompt injection
    • Jailbreak techniques
    • Indirect prompt injection
    • Data leakage and sensitive information disclosure
    • Insecure tool/function calling
    • Agentic AI abuse
    • Model misuse and unsafe output generation
    • Understanding of modern AI architectures, including:
  • Experience performing manual application security testing beyond automated scanning

  • Strong understanding of web application security fundamentals, including the OWASP Top 10 Web, Agentic, and LLM Applications.

  • Experience reviewing AI application architectures and identifying security weaknesses across APIs, cloud infrastructure, and application logic

  • Experience performing source code review and dynamic testing

  • Familiarity with cloud platforms (AWS, Azure, or GCP) and securing AI workloads

  • Scripting or programming experience in Python, JavaScript Go, Java, or similar languages

  • Familiarity withLLM application and agent-orchestration frameworks, inference provider APIs, external capability integration for models, and open sourcetooling across commercial and self-hosted ecosystems.

  • Knowledge of authentication, authorization, networking, APIs, and secure software development practices

  • Excellent written and verbal communication skills, including presenting findings to technical and executive audiences

  • Ability to mentor teammates and contribute to internal research, tooling, and methodology development

  • OSCP, OSEP, GWAPT, GPEN, GXPN, or other relevant certifications are helpful but not required

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field is a plus

What Sets You Apart

  • Experience conducting AI red team exercises against production or pre-production AI systems

  • Research into emerging AI attack techniques or contributions to the offensive security community

  • Experience building or securing AI agents and autonomous workflows

  • Knowledge of adversarial machine learning concepts and model security

  • Experience with cloud-native AI platforms such as Azure OpenAI, Amazon Bedrock, or Google Vertex AI

  • Familiarity with AIsoftware development lifecycle (AI SDLC) and AI governance frameworks

Why Bishop Fox

At Bishop Fox, we’re driven by a simple mission: deliver exceptional quality to our clients, foster a vibrant and fulfilling environment for our team, and champion excellence within our industry. Our core values, which we live by every day, are:

  • Be Excellent to Each Other

  • Do the Right Thing

  • Do What You’ll Say You’ll Do

  • Get Better Together

  • Give a Sh*t

This position is not eligible for visa sponsorship. Applicants must be authorized to work in the United States of America for the duration of employment without sponsorship.

Bishop Fox has always allowed its employees to work remotely, and this role can be based anywhere in the United States.

Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and foster an inclusive culture where employees are empowered to do their best work while advancing the security community through world-class research and consulting.

Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including sexual orientation and gender identity), national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must successfully complete a background check as a condition of employment.

Interested? Apply today!

Read the full description
Security DevSecOps Engineer at Raya

DevSecOps engineer who hardens AWS/EKS infrastructure, remediates security findings, and embeds security practices into CI/CD pipelines and development workflows.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

We prioritize learning and teamwork and love giving people the opportunity to champion solutions to big challenges and grow into better versions of themselves. A great candidate believes in Raya’s vision, which is to enrich lives by fostering relationships through quality, in person interactions. You thrive at the intersection of DevOps and Security, and you’re excited to drive measurable impact by hardening our AWS/EKS environment and systematically closing out security findings.

Responsibilities

  • Security Ownership: Drive software engineering security hygiene end-to-end, from identifying vulnerabilities and misconfigurations to implementing durable fixes across our platform. This includes AWS, Kubernetes, CDN/WAF, and other technologies used in the PDLC

  • Cross-Functional Collaboration: Work hand-in-hand with DevOps and Engineering teams to embed security best practices into everyday workflows, without slowing down velocity

  • Continuous Learning: Stay current on evolving cloud security threats, tooling, and best practices, ensuring Raya’s infrastructure stays ahead of emerging risks

  • Findings Remediation: Triage, prioritize, and systematically close out security findings, translating scanner output into practical, actionable engineering fixes

  • Operational Excellence: Expand and maintain security checks and guardrails in CI/CD pipelines and the broader PDLC, so security becomes a natural part of how we ship, not an afterthought

Qualifications

  • Strong hands-on experience with AWS and Kubernetes/EKS, comfortable navigating cloud infrastructure and container environments from day one

  • Solid foundation in security fundamentals: vulnerability management, IAM, network security, and cloud security posture management

  • Experience triaging and remediating security findings from vulnerability scanners or cloud security tools

  • Familiarity with CI/CD pipelines and integrating security practices into the software development lifecycle

  • Strong communication skills, able to work effectively with both DevOps and Security stakeholders and translate technical risk into clear priorities

  • Experience with Infrastructure-as-Code (e.g., Terraform/OpenTofu), compliance frameworks, or container security tooling

What Sets You Apart

  • Bridge Builder: You naturally sit at the intersection of DevOps and Security, translating between the two and earning trust from both sides

  • Impact-driven: You prioritize the fixes and improvements that meaningfully reduce risk, rather than chasing every alert

  • Growth-oriented: You possess a perpetual learner’s mindset, staying curious about new threats, tools, and cloud-native security practices

  • Ownership mentality: You take findings from discovery to resolution without needing to be chased, and you build systems so problems don’t recur

  • Productivity-obsessed: You value tools, workflows, and automation that make security scalable rather than manual

  • Bias toward shipping and iteration: You’re able to harden systems incrementally, learn, and refine in short cycles rather than waiting for a “perfect” fix

$160,000 - $190,000 a year

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer, Incident Response at Twilio

Leads technical response to security incidents across Twilio's infrastructure, conducts triage and remediation, and develops incident response processes and automation.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.

Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.

We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!

.

See yourself at Twilio

Join the team as Twilio’s next Senior Security Engineer, Incident Response

About the job

The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments.  You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities

In this role, you’ll:

  • Be an Owner: Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Write It Down: Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Wear the customer’s shoes: Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Ruthlessly Prioritize: Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Don’t Settle: Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Draw the Owl: Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Empower Others: Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Be Inclusive: Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Qualifications

Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn’t followed a traditional path, don’t let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!

*Required:

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of  controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks

Location

  1. This role will be remote,but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Compensation

*Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only.

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $141,520.00 - $176,900.00.
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $149,840.00 - $187,300.00
  • Based in the San Francisco Bay area, California: $166,400.00 - $208,000.00.
  • This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave.

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Application deadline information

Applications for this role are intended to be accepted until 30th Aug, but may change based on business needs.

Twilio thinks big. Do you?

We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That’s why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.

So, if you’re ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn’t what you’re looking for, please consider other open positions.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Read the full description
Security Senior Cloud Security Engineer (Remote Canada) at Smile Digital Health

Design, deploy, and maintain secure cloud infrastructure across AWS, Azure, OCI, and GCP while providing technical support and guidance to internal teams and customers.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte’s Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.

At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This position works closely with the Cloud Architect and Development teams to ensure infrastructure fulfills the project’s deliverables while keeping a high standard of quality and operational maturity.

Responsibilities:

  • Collaborate with Development and Architecture teams to build  complex and highly available cloud environments for Internal and External infrastructure builds.
  • Provide Level 3 Technical support to Internal teams, Customers and Partners to support our core product.
  • Lead and educate clients on cloud deployment patterns.
  • Act as a SME for implementing and building infrastructure to support our core product.
  • Investigate and resolve any customer integration issues that arise during implementation.
  • Design procedure for system troubleshooting and maintenance.
  • Perform root cause analysis for any implementation errors and provide feedback to the Core dev team.
  • Document best practices and lessons learned.
  • Design, implement and maintain a secure and scalable infrastructure platform.
  • Provide ongoing maintenance and support of internal tools, improve system health and reliability.
  • Accountable for ensuring that all working hours are accurately reported in Netsuite on a daily or weekly basis, that the majority of (if not all) hours are tracked as billable and that the project management tool in Netsuite is properly and fully utilized
  • Tracking and reporting of billable hours is a critical aspect of project management and delivery to our customers and this is a major area of accountability.
  • Participate in on-call rotation to provide application and infrastructure support, incident management and troubleshooting.

Requirements :

  • At least 6+ years of experience in Information technology, with infrastructure and platform services automation expertise.
  • 3+ years of experience with engineering and supporting containerization technology.
  • 3+ years of experience on AWS, Azure, OCI or GCP.
  • Professional Cloud Certifications are preferred.
  • Experience building end-to-end cloud solutions using low level architecture documents.
  • Demonstrated experience in translating customer requirements to net new infrastructure to address business needs.
  • Drive to innovate and use various technologies to solve complex business needs.
  • Expertise in troubleshooting support escalation, on-Call process optimization and documenting knowledge.
  • Solid networking fundamentals and proven experience with Security and Compliance (SOC2, HIPAA, ISO27001) best practices and how to implement controls that support high-velocity software delivery teams.
  • Proven experience with Kubernetes/Openshift and Docker.
  • Experience with Infrastructure as code tools such as Ansible, Terraform or CloudFormation.
  • Deep knowledge of cloud service providers and best practices around implementation and configuration, preferably managing customer environments.

$130,000 - $145,000 a year

Some of the benefits we offer:

\* Remote Work Environment

\* Flexible Time Away From Work Policy including PTO, Personal and Sick Days

\* Competitive Salary and Health/Medical Benefits

\* RRSP/TFSA/401K Employee Contribution

\* Life and Disability

\* Employee Assistance Program

\* FHIR Study Program and Skillsoft Learning

\* Super HAPI Fun Club

Smile’s core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.

We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer, Incident Response at Twilio

Leads technical response to security incidents and events across global infrastructure, conducting triage, containment, remediation, and developing scalable incident response processes.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.

Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.

We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!

.

See yourself at Twilio

Join the team as Twilio’s next Senior Security Engineer, Incident Response

About the job

The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments.  You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities

In this role, you’ll:

  • Be an Owner: Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Write It Down: Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Wear the customer’s shoes: Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Ruthlessly Prioritize: Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Don’t Settle: Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Draw the Owl: Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Empower Others: Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Be Inclusive: Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Qualifications

Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn’t followed a traditional path, don’t let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!

*Required:

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of  controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks

Location

  1. This role will be remote,but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Compensation

*Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only.

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $141,520.00 - $176,900.00.
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $149,840.00 - $187,300.00
  • Based in the San Francisco Bay area, California: $166,400.00 - $208,000.00.
  • This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave.

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Application deadline information

Applications for this role are intended to be accepted until 30th Aug, but may change based on business needs.

Twilio thinks big. Do you?

We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That’s why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.

So, if you’re ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn’t what you’re looking for, please consider other open positions.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Read the full description
Security Senior Security Engineer, Incident Response at Twilio

Lead technical response to security incidents across global infrastructure, conduct triage and remediation, and develop scalable incident response processes and automation.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.

Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.

We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!

.

See yourself at Twilio

Join the team as Twilio’s next Senior Security Engineer, Incident Response

About the job

The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments.  You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities

In this role, you’ll:

  • Be an Owner: Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Write It Down: Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Wear the customer’s shoes: Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Ruthlessly Prioritize: Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Don’t Settle: Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Draw the Owl: Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Empower Others: Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Be Inclusive: Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Qualifications

Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn’t followed a traditional path, don’t let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!

*Required:

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of  controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks

Location

  1. This role will be remote,but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Compensation

*Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only.

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $141,520.00 - $176,900.00.
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $149,840.00 - $187,300.00
  • Based in the San Francisco Bay area, California: $166,400.00 - $208,000.00.
  • This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave.

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Application deadline information

Applications for this role are intended to be accepted until 30th Aug, but may change based on business needs.

Twilio thinks big. Do you?

We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That’s why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.

So, if you’re ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn’t what you’re looking for, please consider other open positions.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Read the full description
Security Senior Cloud Security Engineer (Remote Canada) at Smile Digital Health

Design, deploy, and maintain secure cloud infrastructure across multiple cloud providers while providing technical support and guidance to internal teams and customers.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte’s Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.

At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This position works closely with the Cloud Architect and Development teams to ensure infrastructure fulfills the project’s deliverables while keeping a high standard of quality and operational maturity.

Responsibilities:

  • Collaborate with Development and Architecture teams to build  complex and highly available cloud environments for Internal and External infrastructure builds.
  • Provide Level 3 Technical support to Internal teams, Customers and Partners to support our core product.
  • Lead and educate clients on cloud deployment patterns.
  • Act as a SME for implementing and building infrastructure to support our core product.
  • Investigate and resolve any customer integration issues that arise during implementation.
  • Design procedure for system troubleshooting and maintenance.
  • Perform root cause analysis for any implementation errors and provide feedback to the Core dev team.
  • Document best practices and lessons learned.
  • Design, implement and maintain a secure and scalable infrastructure platform.
  • Provide ongoing maintenance and support of internal tools, improve system health and reliability.
  • Accountable for ensuring that all working hours are accurately reported in Netsuite on a daily or weekly basis, that the majority of (if not all) hours are tracked as billable and that the project management tool in Netsuite is properly and fully utilized
  • Tracking and reporting of billable hours is a critical aspect of project management and delivery to our customers and this is a major area of accountability.
  • Participate in on-call rotation to provide application and infrastructure support, incident management and troubleshooting.

Requirements :

  • At least 6+ years of experience in Information technology, with infrastructure and platform services automation expertise.
  • 3+ years of experience with engineering and supporting containerization technology.
  • 3+ years of experience on AWS, Azure, OCI or GCP.
  • Professional Cloud Certifications are preferred.
  • Experience building end-to-end cloud solutions using low level architecture documents.
  • Demonstrated experience in translating customer requirements to net new infrastructure to address business needs.
  • Drive to innovate and use various technologies to solve complex business needs.
  • Expertise in troubleshooting support escalation, on-Call process optimization and documenting knowledge.
  • Solid networking fundamentals and proven experience with Security and Compliance (SOC2, HIPAA, ISO27001) best practices and how to implement controls that support high-velocity software delivery teams.
  • Proven experience with Kubernetes/Openshift and Docker.
  • Experience with Infrastructure as code tools such as Ansible, Terraform or CloudFormation.
  • Deep knowledge of cloud service providers and best practices around implementation and configuration, preferably managing customer environments.

$130,000 - $145,000 a year

Some of the benefits we offer:

\* Remote Work Environment

\* Flexible Time Away From Work Policy including PTO, Personal and Sick Days

\* Competitive Salary and Health/Medical Benefits

\* RRSP/TFSA/401K Employee Contribution

\* Life and Disability

\* Employee Assistance Program

\* FHIR Study Program and Skillsoft Learning

\* Super HAPI Fun Club

Smile’s core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.

We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Incident Response Analyst at Cloudflare

Responds to customer security incidents, analyzes malicious activity, and provides threat intelligence-driven incident response consulting across diverse environments.

Mid Onsite Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations: Lisbon, Portugal

About the Role

Cloudflare is a system spanning the globe, on a mission to make the internet safer and more powerful everyday. To help fulfill this mission, we are seeking a talented REACT Analyst / Consultant to join us in growing our Cloudforce One REACT organization. In this role, you will be instrumental in building a proactive and threat intelligence-driven approach to protecting Cloudflare and its customers from sophisticated and evolving threat actors.

As a REACT Consultant, you will respond to customer security incidents across on-premises, cloud, and hybrid environments. This position requires an innovative, self-starting, and detail-oriented problem solver with a passion for analyzing, tracking, and triaging malicious activity. You will engage with customers at all levels—including Executive, VP, Director, and engineering levels—serving an integral role alongside forensic analysts, threat researchers, detection engineers, and malware analysts to detect, isolate, and mitigate threats.

Key Responsibilities

1. Incident Response & Active Edge Mitigation

  • Active Edge Mitigation: Execute immediate defensive maneuvers at the Cloudflare edge to protect customer availability. This includes deploying custom WAF rules, implementing L3/L4 DDoS shunning, and performing real-time traffic filtering to neutralize attacks before they reach the customer’s origin.
  • Support Full IR Lifecycle Management: Support and execute the end-to-end incident response process for clients (investigation, containment, remediation, and recovery). Review technical deliverables and coordinate sessions with customer stakeholders to ensure high-quality service and resolution.
  • Incident Remediation: Build a strong understanding of targeted attacks to create and execute customized tactical and strategic remediation plans for compromised organizations.

2. Direct Customer Containment & Threat Isolation

  • Ransomware & BEC: Identify and isolate infected hosts, revoke compromised sessions/identities, and stop data exfiltration within the customer’s infrastructure.
  • Insider Threats & Nation-State Attacks: Track unauthorized lateral movement, identify sophisticated persistent backdoors, correlate threat actor activity across the environment, and execute containment to preserve evidence while neutralizing the adversary.

3. Forensics, Engineering & AI Analysis

  • Forensic Evidence & Chain of Custody: Conduct initial evidence preservation (logs, volatile memory, disk images) within customer environments according to forensic standards to support legal, regulatory, or insurance requirements.
  • Crisis Solution Development: Create and enhance client-facing Crisis & Incident Response solutions based on industry standards (ISO 27001, NIST, CIS). Advance customer cyber readiness by identifying opportunities for process optimization in monitoring, detection, and response.
  • AI-Leveraged Analysis: Utilize AI-powered security platforms to synthesize massive telemetry sets, automate log summarization, and accelerate the identification of emerging threat patterns during active customer engagements.
  • Technical Documentation & Reporting: Prepare high-fidelity incident reports, forensic findings, and client communications. Maintain rigorous standards for clarity and accuracy to ensure customer executives and engineers understand both the threat and the resolution.

Desirable Skills, Knowledge, and Experience

  • Education: Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent training/practical experience.
  • Experience: 3+ years of overall experience in cybersecurity, including 2+ years of dedicated Incident Response / Digital Forensics experience, and 1+ years in a customer-facing role.
  • OS & Cloud Environments: In-depth understanding of Windows operating systems and general knowledge of Unix, Linux, and Mac environments. Familiarity with cloud environments (AWS, Azure, O365, Google Cloud, Cloudflare) and cloud IR methodologies.
  • Network Forensic Analysis: Strong technical knowledge of common network protocols and design patterns (TCP/IP, HTTPS, FTP, SFTP, SSH, RDP, CIFS/SMB, NFS). Experience with network analysis tools like Bro/Zeek or Suricata, and analyzing associated network logs.
  • Industry Standards: Solid understanding of MITRE ATT&CK and NIST Cyber Security Frameworks.
  • Communications: Excellent verbal and written communication skills with a proven ability to establish relationships and clearly explain tasks, guidance, and complex technical findings to executive and technical clients.

Bonus Points

  • Proficient in Python or Golang, capable of writing modular code or simple scripts that can be installed on a remote system.
  • Proficient with Yara and writing rules to detect similar malware samples.
  • Understanding of source code, hex, binary, regular expressions, data correlation, and analysis (such as network flow and system logs).
  • Practical malware analysis experience with static, dynamic, and automated techniques, including the ability to reverse engineer various file formats and analyze complex samples.
  • Reverse engineering experience with APT malware with an understanding of common infection vectors, infrastructure enumeration, malware attribution, and current evasion tactics.
  • Familiarity with bash command-line executables to conduct static analysis and investigate Indicators of Compromise (IOCs).

Compensation

● For Portugal based hires: Estimated annual salary is between €54,000 - €75,000.

  • The final offer will be inclusive of time exemption, in alignment with the applicable law and collective bargaining agreements.

Equity

This role is eligible to participate in Cloudflare’s equity plan.

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security Intelligence Production Lead at Cloudflare

Leads threat intelligence production and analysis operations for Cloudflare's security team, synthesizing vast network data into actionable threat intelligence to disrupt cyber threats.

Lead Onsite Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations: Washington DC

About The Team

Cloudforce One is Cloudflare’s threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cybercriminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation. Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world’s largest global networks can provide. The team is able to analyze these unique data points, at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers.

About The Role

Cloudflare is a global system on a mission to make the internet better, safer, and more powerful every day. To help fulfill this mission, we are seeking a seasoned Intelligence Production Lead to own the end-to-end intelligence production pipeline within our Cloudforce One Organization. As the Intelligence Production Lead, you will do everything a threat intelligence technical writer does — translating complex threat research into clear, concise, and actionable content — and you will also own the process, quality bar, and delivery cadence for the team’s finished intelligence. You will function as the managing editor and production manager for our threat intelligence output, setting the publishing calendar, running review and fact-check cycles, enforcing source-handling and classification standards, and serving as the final quality gate before customer-facing publication. You will collaborate closely with threat researchers, intelligence analysts, security teams, and external partners to prioritize what ships when, and you will mentor writers and analysts to raise the overall standard of the team’s tradecraft and written product. This position requires an independent, results-oriented leader with a passion for cybersecurity and threat intelligence analysis, and the editorial judgment to represent adversary tradecraft with precision.

Key responsibilities include:

  • Owning the end-to-end intelligence production pipeline — from research intake through drafting, editing, review, and publication — for intelligence reports, blog posts, briefing content, and technical documentation related to cyber threats and security research
  • Setting and managing the production schedule and release calendar, coordinating across researchers and analysts to prioritize which intelligence products ship and when
  • Serving as the final quality gate before customer-facing publication, running fact-check, technical-accuracy, and editorial review cycles and adjudicating changes to content
  • Writing, editing, and publishing high-quality intelligence content, and translating raw researcher notes and technical analysis into accessible, well-structured, impactful narratives
  • Developing, maintaining, and enforcing style guides, templates, classification markings, and source-handling and best-practice standards for threat intelligence briefings and publications
  • Reviewing and refining threat research content to ensure clarity, consistency, technical precision, and adherence to Cloudflare’s editorial standards
  • Mentoring and coaching technical writers and analysts on writing craft, intelligence tradecraft, and reporting standards
  • Collaborating with analysts and external partners to contextualize intelligence findings and communicate them effectively to customers and the public
  • Partnering with marketing, design, PR, and communications teams to amplify intelligence content, manage workloads and deadlines, and develop a cohesive security narrative

Examples of Desirable Skills, Knowledge, and Experience

  • Minimum 5 years of experience in a threat intelligence role within the Five Eyes (FVEY) community
  • 7+ years of combined experience across technical writing, cybersecurity research, intelligence analysis, or a related field
  • Minimum 3 years of technical copy editing experience
  • Demonstrated experience leading or managing a threat intelligence reporting, editorial, or production function — owning the production workflow, setting cadence, managing review cycles, and serving as a final quality gate before publication
  • Strong ability to craft — and to lead others in crafting — clear, concise, and engaging technical content for a variety of audiences, from technical defenders to executives
  • Experience collaborating with cybersecurity researchers and analysts, with a strong understanding of intrusion analysis, incident response, malware, adversary TTPs, and network defense strategies
  • Ability to use researcher notes and raw analysis to author articles about individual threats and campaigns, and to guide others in doing the same
  • Understanding of geopolitical issues and their impact on cyber threats
  • Familiarity with cyber threat intelligence frameworks such as the Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model
  • Familiarity with specific threat actor groups, their operations, and TTPs
  • Experience with OSINT research and intelligence collection methodologies
  • Background in intelligence or criminal investigation reporting
  • Experience working in a threat intelligence or security operations center (SOC) environment
  • Demonstrated operational security (OPSEC) awareness and experience with the secure handling of sensitive information
  • Strong research, proofreading, and editing skills with a keen attention to detail
  • Experience communicating with internal teams to negotiate suggested changes to edited content and answer questions on style, grammar, and voice
  • Strong collaboration and leadership skills to work with analysts, marketing, design, and PR teams to coordinate workloads, deadlines, and responsibilities
  • Excellent project management and organizational skills, with the ability to handle multiple priorities and competing deadlines in a fast-paced environment
  • Proficiency in using Google Suite and content management systems (e.g., WordPress, Jira, or similar workflow tools)
  • Bachelor’s degree in English, Journalism, Cybersecurity, Computer Science, or a related field, or equivalent experience

Bonus Points

  • Experience using AI and large language model (LLM) tools to accelerate research, drafting, editing, and intelligence production workflows
  • Experience leading or managing a team of threat intelligence technical writers
  • Certifications such as CISSP, GIAC GCTI, or similar cybersecurity credentials
  • A portfolio of published, public-facing threat intelligence (bylined reports, advisories, or blog posts)
  • Experience presenting threat research at industry conferences (e.g., Black Hat, DEF CON, RSA, FIRST, or SANS CTI Summit)
  • Familiarity with threat intelligence platforms (TIPs) and structured threat-sharing standards

If you are passionate about cybersecurity, excel at communicating complex threats in a clear and actionable way, and are ready to own the standard and cadence of a world-class intelligence production function, we encourage you to apply and help Cloudflare continue its mission to make the internet safer and more resilient.

Please submit a resume and have 3-5 writing samples available upon request.

Compensation

Compensation may be adjusted depending on work location.

  • For Washington DC based hires: Estimated annual salary of $160,000 - $220,000

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family.  Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun!  The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security Senior Security Engineer I – GRC FedRAMP (Remote Eligible) at Smartsheet

Leads FedRAMP and GovRAMP compliance certifications, manages third-party assessments, oversees continuous monitoring, and ensures regulatory authorization maintenance for government customers.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you’ll own Smartsheet’s FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You’ll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You’ll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture.

You Will:

  • Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination.
  • Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation.
  • Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven FedRAMP deliverables including vulnerability scans, penetration testing, system security plan updates, and compliance reporting.
  • Manage Plans of Action and Milestones (POA&M) processes: Own the identification, prioritization, tracking, and remediation of findings. Ensure timely closure of Critical (30 days), High (30 days), and Moderate (90 days) findings while coordinating with engineering and security teams.
  • Coordinate significant change requests and system modifications: Work with product and engineering to document, scope, assess, and obtain agency approval for system changes that impact security controls or compliance posture.
  • Engage with authorizing officials and federal agencies: Build and maintain relationships with government sponsors, CIOs, and agency decision-makers. Provide regular status updates, respond to questions, and demonstrate authorization compliance.
  • Prepare comprehensive assessment packages: Lead the development of System Security Plans (SSP), Security Assessment Plans (SAP), risk exposure tables, and supporting documentation required for audits.
  • Drive compliance automation and efficiency: Identify opportunities to automate evidence collection, simplify reporting, and reduce manual effort while maintaining rigor and auditability.

You Have:

  • 5+ years of hands-on experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including direct involvement in obtaining and maintaining ATOs.
  • Proven experience working with accredited 3PAOs: You’ve coordinated initial assessments, managed annual re-assessments, provided evidence packages, and worked through test results and findings.
  • A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience.
  • Deep understanding of FedRAMP continuous monitoring requirements: Comprehensive knowledge of monthly deliverables, annual assessment cycles, POA&M management, vulnerability scan and penetration test requirements, and compliance reporting cadences.
  • Strong NIST 800-53 control knowledge: Fluency with control baselines, supplemental overlays (ITAR, CJIS, HIPAA, etc.), impact level determination, and control selection for various system types.
  • Project management and stakeholder coordination skills: Experience managing complex, multi-month compliance programs with multiple dependencies, stakeholders, and tight deadlines.
  • Technical foundation in cloud security and compliance: Working knowledge of AWS/GCP/Azure, cloud security controls, identity and access management, encryption, logging, and incident response—sufficient to understand system architecture and control implementations.
  • Excellent documentation and communication skills: Ability to write clear System Security Plans, coordinate across multiple stakeholders, and translate technical and compliance concepts for government audiences.
  • Understanding of federal procurement and contracting: Familiarity with how government agencies acquire and authorize cloud services, and the role of compliance in federal GTM.
  • US Person Status: Must be a U.S. Citizen, U.S. National to meet federal compliance requirements.

Nice to Have:

  • Professional certifications: CISSP, CISM, CISA, CRISC, or FedRAMP-specific credentials.
  • Experience with multiple impact levels: IL2 (Low), IL4 (Moderate), IL6 (High) systems and their specific requirements.
  • Background in government contracting, DoD CMMC, or other federal compliance frameworks.
  • Experience with SaaS FedRAMP authorization, particularly multi-tenant systems and JAB vs. Agency ATO pathways.

Current US Perks & Benefits:

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range

$145,000—$210,000 USD

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

#LI-Remote

Read the full description
Security IAM Architect

Designs and implements identity and access management systems to secure business infrastructure and user authentication across enterprise environments.

Lead Posted 3 days ago Himalayas
What this role involves
About UsTurnkey’s vision is to make the world a safer place to do business.
Read the full description
Security Cyber Defense Senior Analyst

Senior cybersecurity analyst who monitors, detects, and responds to security threats to protect company infrastructure and data.

Senior Posted 4 days ago Jobicy AI
What this role involves
Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,...
Read the full description
Security Cyber Defense Senior Analyst

Monitors and responds to cybersecurity threats, analyzes security incidents, and defends organizational systems against attacks.

Senior Posted 4 days ago Jobicy AI
What this role involves
Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,...
Read the full description