Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security DevSecOps Engineer at Raya

Embed security best practices into AWS/EKS infrastructure and CI/CD pipelines, triaging vulnerabilities and collaborating with DevOps teams to harden cloud environments.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

We prioritize learning and teamwork and love giving people the opportunity to champion solutions to big challenges and grow into better versions of themselves. A great candidate believes in Raya’s vision, which is to enrich lives by fostering relationships through quality, in person interactions. You thrive at the intersection of DevOps and Security, and you’re excited to drive measurable impact by hardening our AWS/EKS environment and systematically closing out security findings.

Responsibilities

  • Security Ownership: Drive software engineering security hygiene end-to-end, from identifying vulnerabilities and misconfigurations to implementing durable fixes across our platform. This includes AWS, Kubernetes, CDN/WAF, and other technologies used in the PDLC

  • Cross-Functional Collaboration: Work hand-in-hand with DevOps and Engineering teams to embed security best practices into everyday workflows, without slowing down velocity

  • Continuous Learning: Stay current on evolving cloud security threats, tooling, and best practices, ensuring Raya’s infrastructure stays ahead of emerging risks

  • Findings Remediation: Triage, prioritize, and systematically close out security findings, translating scanner output into practical, actionable engineering fixes

  • Operational Excellence: Expand and maintain security checks and guardrails in CI/CD pipelines and the broader PDLC, so security becomes a natural part of how we ship, not an afterthought

Qualifications

  • Strong hands-on experience with AWS and Kubernetes/EKS, comfortable navigating cloud infrastructure and container environments from day one

  • Solid foundation in security fundamentals: vulnerability management, IAM, network security, and cloud security posture management

  • Experience triaging and remediating security findings from vulnerability scanners or cloud security tools

  • Familiarity with CI/CD pipelines and integrating security practices into the software development lifecycle

  • Strong communication skills, able to work effectively with both DevOps and Security stakeholders and translate technical risk into clear priorities

  • Experience with Infrastructure-as-Code (e.g., Terraform/OpenTofu), compliance frameworks, or container security tooling

What Sets You Apart

  • Bridge Builder: You naturally sit at the intersection of DevOps and Security, translating between the two and earning trust from both sides

  • Impact-driven: You prioritize the fixes and improvements that meaningfully reduce risk, rather than chasing every alert

  • Growth-oriented: You possess a perpetual learner’s mindset, staying curious about new threats, tools, and cloud-native security practices

  • Ownership mentality: You take findings from discovery to resolution without needing to be chased, and you build systems so problems don’t recur

  • Productivity-obsessed: You value tools, workflows, and automation that make security scalable rather than manual

  • Bias toward shipping and iteration: You’re able to harden systems incrementally, learn, and refine in short cycles rather than waiting for a “perfect” fix

$160,000 - $190,000 a year

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security DevSecOps Engineer at Raya

DevSecOps engineer who hardens AWS/EKS infrastructure, remediates security findings, and embeds security practices into CI/CD pipelines and development workflows.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

We prioritize learning and teamwork and love giving people the opportunity to champion solutions to big challenges and grow into better versions of themselves. A great candidate believes in Raya’s vision, which is to enrich lives by fostering relationships through quality, in person interactions. You thrive at the intersection of DevOps and Security, and you’re excited to drive measurable impact by hardening our AWS/EKS environment and systematically closing out security findings.

Responsibilities

  • Security Ownership: Drive software engineering security hygiene end-to-end, from identifying vulnerabilities and misconfigurations to implementing durable fixes across our platform. This includes AWS, Kubernetes, CDN/WAF, and other technologies used in the PDLC

  • Cross-Functional Collaboration: Work hand-in-hand with DevOps and Engineering teams to embed security best practices into everyday workflows, without slowing down velocity

  • Continuous Learning: Stay current on evolving cloud security threats, tooling, and best practices, ensuring Raya’s infrastructure stays ahead of emerging risks

  • Findings Remediation: Triage, prioritize, and systematically close out security findings, translating scanner output into practical, actionable engineering fixes

  • Operational Excellence: Expand and maintain security checks and guardrails in CI/CD pipelines and the broader PDLC, so security becomes a natural part of how we ship, not an afterthought

Qualifications

  • Strong hands-on experience with AWS and Kubernetes/EKS, comfortable navigating cloud infrastructure and container environments from day one

  • Solid foundation in security fundamentals: vulnerability management, IAM, network security, and cloud security posture management

  • Experience triaging and remediating security findings from vulnerability scanners or cloud security tools

  • Familiarity with CI/CD pipelines and integrating security practices into the software development lifecycle

  • Strong communication skills, able to work effectively with both DevOps and Security stakeholders and translate technical risk into clear priorities

  • Experience with Infrastructure-as-Code (e.g., Terraform/OpenTofu), compliance frameworks, or container security tooling

What Sets You Apart

  • Bridge Builder: You naturally sit at the intersection of DevOps and Security, translating between the two and earning trust from both sides

  • Impact-driven: You prioritize the fixes and improvements that meaningfully reduce risk, rather than chasing every alert

  • Growth-oriented: You possess a perpetual learner’s mindset, staying curious about new threats, tools, and cloud-native security practices

  • Ownership mentality: You take findings from discovery to resolution without needing to be chased, and you build systems so problems don’t recur

  • Productivity-obsessed: You value tools, workflows, and automation that make security scalable rather than manual

  • Bias toward shipping and iteration: You’re able to harden systems incrementally, learn, and refine in short cycles rather than waiting for a “perfect” fix

$160,000 - $190,000 a year

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Incident Response Analyst at Cloudflare

Responds to customer security incidents, analyzes malicious activity, and provides threat intelligence-driven incident response consulting across diverse environments.

Mid Onsite Posted 4 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations: Lisbon, Portugal

About the Role

Cloudflare is a system spanning the globe, on a mission to make the internet safer and more powerful everyday. To help fulfill this mission, we are seeking a talented REACT Analyst / Consultant to join us in growing our Cloudforce One REACT organization. In this role, you will be instrumental in building a proactive and threat intelligence-driven approach to protecting Cloudflare and its customers from sophisticated and evolving threat actors.

As a REACT Consultant, you will respond to customer security incidents across on-premises, cloud, and hybrid environments. This position requires an innovative, self-starting, and detail-oriented problem solver with a passion for analyzing, tracking, and triaging malicious activity. You will engage with customers at all levels—including Executive, VP, Director, and engineering levels—serving an integral role alongside forensic analysts, threat researchers, detection engineers, and malware analysts to detect, isolate, and mitigate threats.

Key Responsibilities

1. Incident Response & Active Edge Mitigation

  • Active Edge Mitigation: Execute immediate defensive maneuvers at the Cloudflare edge to protect customer availability. This includes deploying custom WAF rules, implementing L3/L4 DDoS shunning, and performing real-time traffic filtering to neutralize attacks before they reach the customer’s origin.
  • Support Full IR Lifecycle Management: Support and execute the end-to-end incident response process for clients (investigation, containment, remediation, and recovery). Review technical deliverables and coordinate sessions with customer stakeholders to ensure high-quality service and resolution.
  • Incident Remediation: Build a strong understanding of targeted attacks to create and execute customized tactical and strategic remediation plans for compromised organizations.

2. Direct Customer Containment & Threat Isolation

  • Ransomware & BEC: Identify and isolate infected hosts, revoke compromised sessions/identities, and stop data exfiltration within the customer’s infrastructure.
  • Insider Threats & Nation-State Attacks: Track unauthorized lateral movement, identify sophisticated persistent backdoors, correlate threat actor activity across the environment, and execute containment to preserve evidence while neutralizing the adversary.

3. Forensics, Engineering & AI Analysis

  • Forensic Evidence & Chain of Custody: Conduct initial evidence preservation (logs, volatile memory, disk images) within customer environments according to forensic standards to support legal, regulatory, or insurance requirements.
  • Crisis Solution Development: Create and enhance client-facing Crisis & Incident Response solutions based on industry standards (ISO 27001, NIST, CIS). Advance customer cyber readiness by identifying opportunities for process optimization in monitoring, detection, and response.
  • AI-Leveraged Analysis: Utilize AI-powered security platforms to synthesize massive telemetry sets, automate log summarization, and accelerate the identification of emerging threat patterns during active customer engagements.
  • Technical Documentation & Reporting: Prepare high-fidelity incident reports, forensic findings, and client communications. Maintain rigorous standards for clarity and accuracy to ensure customer executives and engineers understand both the threat and the resolution.

Desirable Skills, Knowledge, and Experience

  • Education: Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent training/practical experience.
  • Experience: 3+ years of overall experience in cybersecurity, including 2+ years of dedicated Incident Response / Digital Forensics experience, and 1+ years in a customer-facing role.
  • OS & Cloud Environments: In-depth understanding of Windows operating systems and general knowledge of Unix, Linux, and Mac environments. Familiarity with cloud environments (AWS, Azure, O365, Google Cloud, Cloudflare) and cloud IR methodologies.
  • Network Forensic Analysis: Strong technical knowledge of common network protocols and design patterns (TCP/IP, HTTPS, FTP, SFTP, SSH, RDP, CIFS/SMB, NFS). Experience with network analysis tools like Bro/Zeek or Suricata, and analyzing associated network logs.
  • Industry Standards: Solid understanding of MITRE ATT&CK and NIST Cyber Security Frameworks.
  • Communications: Excellent verbal and written communication skills with a proven ability to establish relationships and clearly explain tasks, guidance, and complex technical findings to executive and technical clients.

Bonus Points

  • Proficient in Python or Golang, capable of writing modular code or simple scripts that can be installed on a remote system.
  • Proficient with Yara and writing rules to detect similar malware samples.
  • Understanding of source code, hex, binary, regular expressions, data correlation, and analysis (such as network flow and system logs).
  • Practical malware analysis experience with static, dynamic, and automated techniques, including the ability to reverse engineer various file formats and analyze complex samples.
  • Reverse engineering experience with APT malware with an understanding of common infection vectors, infrastructure enumeration, malware attribution, and current evasion tactics.
  • Familiarity with bash command-line executables to conduct static analysis and investigate Indicators of Compromise (IOCs).

Compensation

● For Portugal based hires: Estimated annual salary is between €54,000 - €75,000.

  • The final offer will be inclusive of time exemption, in alignment with the applicable law and collective bargaining agreements.

Equity

This role is eligible to participate in Cloudflare’s equity plan.

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security ICF: Software Security Engineer- Cloud/GovCloud (Top Secret cleared)

Software security engineer who monitors and assesses application/system vulnerabilities, performs secure code reviews, and implements security controls across cloud and on-premise environments.

Mid Remote Posted 5 days ago We Work Remotely — Programming
What this role involves

Headquarters: Nationwide Remote Office (US99)
URL: http://icf.com

Please note: This role is contingent upon a contract award. While it is not an immediate opening, we are actively conducting interviews and extending offers in anticipation of the award.  

The Work:  ICF is seeking an experienced and driven Software Security Engineer to lead and oversee mission-critical initiatives in support of our government customer. In this role, you will help safeguard applications and cloud-based systems by integrating security best practices throughout the software development lifecycle. 

Job Location: This position is remote. If you accept this position, you should note that ICF does monitor employee work locations and blocks access from foreign locations/foreign IP addresses and also prohibits personal VPN connections.  

You may be asked to travel once a quarter to an office or client site.  

Our core work hours are 8am - 5pm Eastern Time with the option to start earlier or work later depending on your time zone. 

What You Will Do:  

  • Proactively monitor and assess application and system security to identify vulnerabilities and potential threats. 

  • Perform secure code reviews and static/dynamic analysis to strengthen application security and ensure adherence to secure coding standards. 

  • Test and evaluate security tools, applications, and system configurations to validate compliance with federal and DoD security requirements. 

  • Investigate and remediate potential security vulnerabilities, recommending and implementing corrective actions to reduce risk. 

  • Design and implement security controls, tools, and automation to enhance protection across cloud and on-premise environments. 

  • Provide guidance and training to development teams on secure coding practices and DevSecOps principles. 

  • Develop and maintain technical documentation related to security architecture, risk findings, and mitigation strategies. 

  • Prepare and deliver executive-level briefings, status reports, and performance updates to government stakeholders and corporate leadership. 

  • Maintain a positive, results-oriented work environment by building partnerships with internal and external partners. 

What You Will Bring With You:  

  • Active Top Secret clearance. 

  • Proven experience (2+ years) in application security, secure software development, or cybersecurity engineering.

What We Would Like You To Bring With You: 

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related technical field. 

  • 2 years’ experience with working on/around cloud platforms in AWS. 

  • Hands-on experience performing secure code reviews and vulnerability assessments using industry-standard tools (e.g., SAST, DAST, SCA). 

  • Experience implementing security controls in cloud environments (e.g., AWS GovCloud or similar secure federal cloud environments). 

  • Strong understanding of secure coding standards (e.g., OWASP, NIST, DoD STIGs). 

  • Experience supporting systems within regulated or high-security environments. 

  • Ability to self-organize, priorities and conduct research on multiple projects under tight deadlines in a fast-paced environment. 

  • An ability to communicate and write clearly in English. 

 

Professional Skills: 

  • Highly effective analytical, problem-solving, and decision-making capabilities. 

  • Excellent communication and interpersonal skills to interface effectively at all levels of the business. 

Working at ICF

ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future.

We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy.

We will consider for employment qualified applicants with arrest and conviction records.

 

Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent  to provide needed reasonable accommodations.  

Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. 

 

Candidate AI Usage Policy

At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.  

However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.  


 

Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position.

The pay range for this position based on full-time employment is:

$81,499.00 - $138,549.00

Nationwide Remote Office (US99)

To apply: https://weworkremotely.com/remote-jobs/icf-software-security-engineer-cloud-govcloud-top-secret-cleared

Read the full description
Security Product Cybersecurity Engineer at May Mobility

Embeds security practices throughout product development lifecycle for autonomous vehicles, manages vulnerabilities, and enforces secure coding standards across hardware and software systems.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

May Mobility is transforming cities through autonomous technology to create a safer, greener, more accessible world. Based in Ann Arbor, Michigan, May develops and deploys autonomous vehicles (AVs) powered by our innovative Multi-Policy Decision Making (MPDM) technology that literally reimagines the way AVs think.

Our vehicles do more than just drive themselves - they provide value to communities, bridge public transit gaps and move people where they need to go safely, easily and with a lot more fun. We’re building the world’s best autonomy system to reimagine transit by minimizing congestion, expanding access and encouraging better land use in order to foster more green, vibrant and livable spaces. Since our founding in 2017, we’ve given more than 500,000 autonomous rides to real people around the globe. And we’re just getting started. We’re hiring people who share our passion for building the future, today, solving real-world problems and seeing the impact of their work. Join us.

Job Summary

The Product Cybersecurity Engineer is responsible for ensuring security is embedded throughout the product development lifecycle—from architecture and code to deployment and operations. This role integrates security practices into development workflows, manages vulnerabilities in vehicle and autonomous systems, supports compliance with automotive cybersecurity standards, and serves as a cross-functional security expert bridging cybersecurity, hardware, and product engineering teams.

Essential Responsibilities

  • Integrate security practices — threat modeling, architecture reviews into product development workflows from requirements through release.
  • Provide early security input on hardware, firmware, and software design decisions, including third-party and supply chain risk considerations.
  • Write, review, and validate security requirements across hardware and software domains; enforce secure coding standards and perform security analysis on main compute systems.
  • Assist with maintaining Software Bill of Materials (SBOM) and Hardware Bill of Materials (HBOM) using dedicated SBOM tooling to ensure component visibility, vulnerability tracking, and supply chain transparency across products.
  • Apply security lenses during safety and functional assessments in collaboration with safety, systems, and software teams.
  • Assist in proactive vulnerability patching and support secure update strategies using product security tooling for threat modeling and risk profiling.
  • Conduct hazard and threat analyses (TARA/HARA) early in the architecture and development lifecycle.
  • Analyze and harden the security architecture of vehicle subsystems and autonomous stacks; define system- and product-level security requirements and ensure validation coverage.
  • Assist senior level engineers with Ethernet, in-vehicle networking, and cloud interface configuration, including port security and network segmentation.
  • Maintain working knowledge of R155/156, ISO 21434 and UL 4600; support internal audits, risk assessments, and compliance documentation.
  • Engage with Auto-ISAC to track emerging threats, attack vectors, and industry best practices.
  • Work across teams such as cybersecurity, hardware, and product engineering — providing architectural security design feedback.
  • Assist with fostering a security-first culture across the organization through integrated best practices and awareness programs.
  • Perform additional responsibilities as directed by your manager.

Skills and Abilities

Success in this role typically requires the following competencies:

  • Clear written communication and the ability to align stakeholders on security priorities before executing.
  • Excellent attention to detail and a rigorous, systematic approach to security analysis.
  • Ability to identify complex security problems across hardware, firmware, and software and devise optimal, innovative solutions that often cross organizational boundaries.

Qualifications and Experience

Candidates most successful in this role typically hold the following qualifications or comparable knowledge or experience:

Required

  • B.S. Degree in Computer Science, Computer Engineering, or an equivalent degree
  • Minimum of [1-3] years of experience in a product cyber security or related role
  • Experience performing threat modeling and attack surface analysis
  • Experience generating and managing Software Bills of Materials (SBOMs) using industry tooling, with working knowledge of SBOM formats such as SPDX and CycloneDX
  • Familiarity with vehicle communication networks and protocols across physical and application layers (CAN, LIN, Ethernet, DBCs), embedded systems interaction, and module security technologies.
  • Familiarity with security-relevant services in ISO 14229-1 (UDS)
  • Experience in TARA and HARA methodologies; experience applying UNECE WP.29, ISO/SAE 21434, and security standards.
  • Ability to clearly communicate findings and collaborate with engineering teams to drive timely mitigation and remediation.

Desirable

  • Experience in automotive product security at an OEM, Tier 1 supplier, or AV company.
  • Experience with autonomous vehicle systems and components.
  • Familiarity with AUTOSAR security modules, secure boot implementations, and penetration testing tools specific to automotive/embedded domains (e.g., CANalyzer, Wireshark, JTAG debugging).
  • Conduct hands-on penetration testing to identify, exploit, and report vulnerabilities across systems, applications, and devices.

Physical Requirements

  • Standard office working conditions which includes but is not limited to:
  • Prolonged sitting
  • Prolonged standing
  • Prolonged computer use
  • Travel required? –  Minimal: 1%-10%

Benefits and Perks

  • Comprehensive healthcare suite including medical, dental, vision, life, and disability plans. Domestic partners who have been residing together at least one year are also eligible to participate.
  • Health Savings and Flexible Spending Healthcare and Dependent Care Accounts available.
  • Rich retirement benefits, including an immediately vested employer safe harbor match.
  • Generous paid parental leave as well as a phased return to work.
  • Flexible vacation policy in addition to paid company holidays.
  • Total Wellness Program providing numerous resources for overall wellbeing

Don’t meet every single requirement? Studies have shown that women and/or people of color are less likely to apply to a job unless they meet every qualification. At May Mobility, we’re committed to building a diverse, inclusive, and authentic workforce, so if you’re excited about this role but your previous experience doesn’t align perfectly with every qualification, we encourage you to apply anyway! You may be the perfect candidate for this or another role at May.

Want to learn more about our culture & benefits? Check out our website!

May Mobility is an equal opportunity employer.  All applicants for employment will be considered without regard to race, color, religion, sex, national origin, age, disability, sexual orientation, gender identity or expression, veteran status, genetics or any other legally protected basis.   Below, you have the opportunity to share your preferred gender pronouns, gender, ethnicity, and veteran status with May Mobility to help us identify areas of improvement in our hiring and recruitment processes. Completion of these questions is entirely voluntary.  Any information you choose to provide will be kept confidential, and will not impact the hiring decision in any way. If you believe that you will need any type of accommodation, please let us know.

Note to Recruitment Agencies: May Mobility does not accept unsolicited agency resumes. Furthermore, May Mobility does not pay placement fees for candidates submitted by any agency other than its approved partners.

Salary Range

$100,000—$155,000 USD

May Mobility uses automated tools to support — but not replace — human judgment in our recruiting process, to find out more please click here

Read the full description
Security Public Facing Security Researcher at CertiK

Public-facing security researcher who conducts Web3 audits and penetration testing while representing CertiK at conferences and on social media.

Mid Remote Posted 8 days ago RemoteFirstJobs Product
What this role involves

About the Company

Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications through cutting-edge security research, formal verification, and AI-powered technology. Founded in 2017 and headquartered in New York City, CertiK provides end-to-end security solutions including smart contract audits, penetration testing, on-chain monitoring, incident response, and compliance services for some of the largest projects in the digital asset ecosystem.

Today, CertiK supports thousands of enterprise clients and Web3 projects globally, with a distributed international team spanning North America, Asia, and Europe. The company is backed by leading investors including Coatue, Goldman Sachs, Insight Partners, and Sequoia Capital, and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation.

About This Role

This role is for a Web3 security researcher who can act as a public face for CertiK. This means having a strong social media presence, speaking at conferences, and being openly helpful to the wider security community. This doesn’t mean you have to have tens of thousands of followers on X, but you do need to be comfortable interacting with the general public. The specific type of security researcher is flexible - contract/chain auditors, pen testers, engineers, and multi-talented individuals can apply. This is a great role for a generalist.

Responsibilities

  • Work closely with the Web3 Task Force Team to create stronger connections to the blockchain ecosystem.

  • Speak at conferences about your area of expertise on behalf of CertiK.

  • Complete interviews about various Web3 security topics.

  • Perform tasks cross-functionally among the various teams at CertiK.

  • Support the marketing and feedback collection of CertiK’s products and services.

Requirements

  • 3+ years of experience in the Web3 space.

  • Strong social media presence and high visibility.

  • Experience speaking at conferences or in front of large audiences.

  • Strong technical skills in the areas of web3 security or related fields.

Bonus Points

  • Large number of social media followers.

  • Previous experience being the public face of an organization.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Public Facing Security Researcher at CertiK

Conducts Web3 security research while serving as a public-facing expert through conference speaking, social media engagement, and community outreach.

Mid Remote Posted 8 days ago RemoteFirstJobs Product
What this role involves

About the Company

Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications through cutting-edge security research, formal verification, and AI-powered technology. Founded in 2017 and headquartered in New York City, CertiK provides end-to-end security solutions including smart contract audits, penetration testing, on-chain monitoring, incident response, and compliance services for some of the largest projects in the digital asset ecosystem.

Today, CertiK supports thousands of enterprise clients and Web3 projects globally, with a distributed international team spanning North America, Asia, and Europe. The company is backed by leading investors including Coatue, Goldman Sachs, Insight Partners, and Sequoia Capital, and has been recognized by organizations such as the World Economic Forum and CB Insights for its contributions to blockchain security innovation.

About This Role

This role is for a Web3 security researcher who can act as a public face for CertiK. This means having a strong social media presence, speaking at conferences, and being openly helpful to the wider security community. This doesn’t mean you have to have tens of thousands of followers on X, but you do need to be comfortable interacting with the general public. The specific type of security researcher is flexible - contract/chain auditors, pen testers, engineers, and multi-talented individuals can apply. This is a great role for a generalist.

Responsibilities

  • Work closely with the Web3 Task Force Team to create stronger connections to the blockchain ecosystem.

  • Speak at conferences about your area of expertise on behalf of CertiK.

  • Complete interviews about various Web3 security topics.

  • Perform tasks cross-functionally among the various teams at CertiK.

  • Support the marketing and feedback collection of CertiK’s products and services.

Requirements

  • 3+ years of experience in the Web3 space.

  • Strong social media presence and high visibility.

  • Experience speaking at conferences or in front of large audiences.

  • Strong technical skills in the areas of web3 security or related fields.

Bonus Points

  • Large number of social media followers.

  • Previous experience being the public face of an organization.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Cybersecurity Engineer II

Implements, operates, and improves cybersecurity capabilities for enterprise clients as a hands-on technical contributor.

Mid Posted 10 days ago Himalayas
What this role involves
The Cybersecurity Engineer II (L2) is a hands-on technical contributor responsible for implementing, operating, and improving client’s cybersecurity capabilities across a rapidly growing enterprise.
Read the full description
Security Cloud Security Analyst

Analyzes cloud infrastructure security, identifies vulnerabilities, and implements security controls to protect hospitality platform systems and customer data.

Mid Posted 11 days ago Jobicy AI
What this role involves
What Makes Us Unique At Cloudbeds, we’re not just building software, we’re transforming hospitality. Our intelligently designed platform powers properties across 150 countries, processing billions in bookings annually. From independent...
Read the full description
Security Offensive Security Engineer

Proactively tests and identifies vulnerabilities across external perimeter, VPS, physical infrastructure, and endpoint defenses to strengthen offensive security posture.

Mid Posted 12 days ago Jobicy AI
What this role involves
About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The...
Read the full description
Security Security Engineer, Detection Response at Vercel

Monitors security alerts, maintains SIEM infrastructure, handles incidents, and builds detections to protect Vercel's internal systems and compliance posture.

Mid Hybrid Posted 13 days ago RemoteFirstJobs Product
What this role involves

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the Role:

We are looking for a Security Engineer to join our Detection Response team. In this role, you will be responsible for managing Vercel’s internal Corporate Security (CorpSec) posture, monitoring for security anomalies, building additional detections and visibility mechanisms, and ensuring the overall security of our internal systems. You will work closely with various teams to support audits, optimize visibility, and handle security incidents as they arise.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you’re located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

What You Will Do:

  • Monitor and respond to security alerts across multiple channels, including managed SOC escalations.
  • Maintain visibility and logging infrastructure, ensuring effective SIEM (Security Information and Event Management) operations.
  • Support security audits for PCI, SOC2, ISO, and other compliance frameworks, gathering evidence and collaborating with Engineering, GRC and the broader Security Division.
  • Proactively enhance security operations by developing and deploying new detections, security tooling and rigorously managing key security partners.
  • Work on security investigations, incidents, and urgent requests as they arise, as well as contributing to the build-out and continuous improvement of the on-call process to enhance efficiency and effectiveness.
  • Continuously act as a guardian to enable the business to navigate risk-based changes.
  • Manage and enhance email security, endpoint security posture (EDR, configuration, and management), GitHub administration best practices, and internal security tooling to strengthen Vercel’s overall security framework

About You:

  • Extensive experience in security operations, including SIEM management, security logging, and detection engineering.
  • Strong knowledge of AWS infrastructure and cloud security best practices.
  • Experience with GitHub administration and security controls.
  • Proficiency in SQL for data analysis and security investigations.
  • Hands-on experience with incident response, including detection, triage, and remediation.
  • Strong endpoint management skills across multiple operating systems (Mac, Windows, Linux).
  • Proficiency in at least one scripting language (Python, Bash) and one compiled language (Rust, Go).
  • Familiarity with serverless functions and API security is a plus.

Bonus If You:

  • Have experience working with managed SOC providers and security automation platforms.
  • Have worked in high-growth, cloud-native environments with a focus on scalability.
  • Are comfortable working in a fast-paced environment with shifting priorities.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000-$312,000. This salary range is an estimate. Actual salary will be based on job-related skills, experience, and location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.

Read the full description
Security GRC Expert at Public Group

GRC Expert manages cybersecurity governance, risk, and compliance programs, conducts assessments, and maintains compliance posture across security, privacy, and third-party risk frameworks.

Mid Hybrid Posted 13 days ago RemoteFirstJobs Product
What this role involves

The organization

Why Join Us? It’s More Than a Job in Retail, It’s Your Story.

At Public Group, we believe in the power of our people in a sustainable way. That’s why we’re not just focused on what you do, but who you become. We’re committed to fueling your growth, because when you win, we all win. Imagine a place where you feel supported, valued, and empowered to make a real difference.  A place where you can build a career you love, to leave your mark in our story!

Public Group strategically invests to create an ecosystem of innovative scaleups around its Omnichannel Retail business, with the objective to provide exciting customer experiences and foster Entrepreneurship in Greece. We bring together technology, talent & entrepreneurship to create value in the Greek market. Our role is to help our subsidiaries or investee companies grow and their founders to succeed through capital and creative synergies. Our investment portfolio includes Public-MediaMarkt, iRepair, Douleutaras.gr, PublicNEXT, Venture Friends.

PublicNEXT leads the digital transformation of retail, with solutions to reimagine processes, integrate technologies and introduce innovative services or platforms that transform employee and customer experience. We develop and unleash the best technology solutions that shape the future of retail. Our team of software developers, engineers, digital and IT experts combine strong technical skills and entrepreneurial thinking to help organizations stay ahead.

As future-ready innovators, we engage in multiple projects and create growth opportunities for everyone to find what they are looking for. Together we can reimagine retail and unleash the best technology platforms to create new capabilities for people and inspire them to enjoy life. We grow by continuously developing on each other’s ideas.

Let’s grow together.

#LI-Hybrid

At Publicnext, we are strengthening our cybersecurity governance, risk, and compliance (GRC) function and looking for a GRC Expert to join the team. Working closely with and reporting directly to the CISO, you will help us mature our risk management and resilience across cybersecurity, privacy, business continuity, AI compliance, and third-party risk.

This is a hands-on delivery role with real ownership. You will run assessments, maintain our risk and compliance posture against recognized frameworks, and support the growing intersection of GRC and IT contract management, reviewing business terms, shaping governance and SLAs, and ensuring our internal and third-party arrangements meet our standards.

Responsibilities:

  • Develop and maintain cybersecurity policies, standards, and procedures aligned to recognized frameworks and regulations (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).

  • Facilitate cybersecurity and technology risk assessments; maintain risk registers and track remediation activities to closure.

  • Participate in risk assessments, vulnerability assessments, and gap analyses, and translate findings into practical improvement plans.

  • Support compliance initiatives including DPIAs, TPRAs (Third-Party Risk Assessments), and EU AI Act readiness.

  • Coordinate and support internal and external audits and Cyber Insurance audits.

  • Oversee third-party cybersecurity risk management processes, ensuring internal teams and vendors adhere to our standards.

  • Review contracts’ business terms and highlight areas for improvement.

  • Contribute to the design of governance and SLAs for contract management.

  • Support the legal and partner interface on contracts, NDAs, and Technical & Organizational Measures (TOMs).

  • Take ownership of delivery within your assigned workstreams and deliverables, ensuring quality and timely execution.

  • Participate in the project management of ongoing GRC engagements.

  • Provide time and effort estimates for prospective engagements and contribute to the technical writing of proposals and offers.

  • Facilitate training sessions and workshops to drive cybersecurity awareness across the organization.

  • Communicate clearly with technical specialists, business leaders, and legal/compliance stakeholders.

Requirements:

  • 3+ years of experience in cybersecurity, information security, compliance, or GRC-related functions.
  • Solid understanding of cybersecurity frameworks and regulatory requirements (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).
  • Experience supporting audits, assessments, and control-maturity activities.
  • Familiarity with IT project management principles and related methodologies.
  • Experience with or exposure to IT contract management (reviewing terms, SLAs, governance).
  • Strong analytical and problem-solving abilities.
  • Ability to communicate technical and cyber-risk concepts to both technical and non-technical audiences, including executives.
  • Strong stakeholder management and cross-functional collaboration skills.
  • A team player who supports and helps drive common goals.
  • Languages: Greek and English (both required, written and spoken).
  • Professional certifications such as ISO 27001 Lead Auditor (ISO27001-LA), CISM, CISA, or similar.
  • Experience working within regulated environments.
  • Prior exposure to Contract Management roles or IT business-facing roles.

What we offer:

  • 💼 Competitive compensation & benefits package
  • 💰 Performance-based bonus scheme
  • 🧑‍⚕️ Comprehensive life & health insurance
  • 🏡 Flexible hybrid working model – to support your work-life balance
  • 🧡 Psychological support via a professional helpline for you and your family
  • 🚀 Career growth opportunities in a role that evolves with you
  • 🎉 Valuable experience in a well-known and fast-growing organization
  • 📚 Continuous learning and upskilling through tailored programs
  • 🏃🏽‍♂️ Employee Wellness Program – office Pilates & sports teams (padel, football, volleyball & more)
  • 🚗 Alternative transportation with company shuttle buses to our offices
  • 📲 Exclusive access to our employee app, OrangeGen, packed with tools, news & perks

What Does OrangeGen Offer? 🔗 Connect: Engage with your colleagues and management seamlessly, ensuring you’re always in the loop and part of our dynamic community.

🎉 Recognize: Celebrate achievements and milestones with a culture of recognition that boosts morale and fosters a positive work environment.

🏆 Custom Rewards: Enjoy personalized rewards and kudos, tailored to recognize your unique contributions and achievements.

Are you ready to be the next #OrangeGen maker?

Orange Gen, is our team of 2.200 people who are committed to cultivating an innovative retailtainment environment, supporting continuous development, and embracing flexibility—all while placing customer centricity at the forefront. We believe in fostering a culture that values your contributions, boosts your ambitions, and supports personal and professional growth. “Joy at Public” is our main motto which lies in creating a workplace where every individual is empowered to excel and evolve, always keeping the customer at the heart of our endeavors. We like to share our moments under the #OrangeTeam celebrating all team’s achievements and Orange Marks Stories!

All applications will be treated with the strictest confidentiality.

Read the full description
Security GRC Expert at Public Group

GRC Expert manages cybersecurity governance, risk, and compliance frameworks while reporting to the CISO and conducting security assessments.

Mid Hybrid Posted 13 days ago RemoteFirstJobs Product
What this role involves

The organization

Why Join Us? It’s More Than a Job in Retail, It’s Your Story.

At Public Group, we believe in the power of our people in a sustainable way. That’s why we’re not just focused on what you do, but who you become. We’re committed to fueling your growth, because when you win, we all win. Imagine a place where you feel supported, valued, and empowered to make a real difference.  A place where you can build a career you love, to leave your mark in our story!

Public Group strategically invests to create an ecosystem of innovative scaleups around its Omnichannel Retail business, with the objective to provide exciting customer experiences and foster Entrepreneurship in Greece. We bring together technology, talent & entrepreneurship to create value in the Greek market. Our role is to help our subsidiaries or investee companies grow and their founders to succeed through capital and creative synergies. Our investment portfolio includes Public-MediaMarkt, iRepair, Douleutaras.gr, PublicNEXT, Venture Friends.

PublicNEXT leads the digital transformation of retail, with solutions to reimagine processes, integrate technologies and introduce innovative services or platforms that transform employee and customer experience. We develop and unleash the best technology solutions that shape the future of retail. Our team of software developers, engineers, digital and IT experts combine strong technical skills and entrepreneurial thinking to help organizations stay ahead.

As future-ready innovators, we engage in multiple projects and create growth opportunities for everyone to find what they are looking for. Together we can reimagine retail and unleash the best technology platforms to create new capabilities for people and inspire them to enjoy life. We grow by continuously developing on each other’s ideas.

Let’s grow together.

#LI-Hybrid

At Publicnext, we are strengthening our cybersecurity governance, risk, and compliance (GRC) function and looking for a GRC Expert to join the team. Working closely with and reporting directly to the CISO, you will help us mature our risk management and resilience across cybersecurity, privacy, business continuity, AI compliance, and third-party risk.

This is a hands-on delivery role with real ownership. You will run assessments, maintain our risk and compliance posture against recognized frameworks, and support the growing intersection of GRC and IT contract management, reviewing business terms, shaping governance and SLAs, and ensuring our internal and third-party arrangements meet our standards.

Responsibilities:

  • Develop and maintain cybersecurity policies, standards, and procedures aligned to recognized frameworks and regulations (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).

  • Facilitate cybersecurity and technology risk assessments; maintain risk registers and track remediation activities to closure.

  • Participate in risk assessments, vulnerability assessments, and gap analyses, and translate findings into practical improvement plans.

  • Support compliance initiatives including DPIAs, TPRAs (Third-Party Risk Assessments), and EU AI Act readiness.

  • Coordinate and support internal and external audits and Cyber Insurance audits.

  • Oversee third-party cybersecurity risk management processes, ensuring internal teams and vendors adhere to our standards.

  • Review contracts’ business terms and highlight areas for improvement.

  • Contribute to the design of governance and SLAs for contract management.

  • Support the legal and partner interface on contracts, NDAs, and Technical & Organizational Measures (TOMs).

  • Take ownership of delivery within your assigned workstreams and deliverables, ensuring quality and timely execution.

  • Participate in the project management of ongoing GRC engagements.

  • Provide time and effort estimates for prospective engagements and contribute to the technical writing of proposals and offers.

  • Facilitate training sessions and workshops to drive cybersecurity awareness across the organization.

  • Communicate clearly with technical specialists, business leaders, and legal/compliance stakeholders.

Requirements:

  • 3+ years of experience in cybersecurity, information security, compliance, or GRC-related functions.
  • Solid understanding of cybersecurity frameworks and regulatory requirements (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).
  • Experience supporting audits, assessments, and control-maturity activities.
  • Familiarity with IT project management principles and related methodologies.
  • Experience with or exposure to IT contract management (reviewing terms, SLAs, governance).
  • Strong analytical and problem-solving abilities.
  • Ability to communicate technical and cyber-risk concepts to both technical and non-technical audiences, including executives.
  • Strong stakeholder management and cross-functional collaboration skills.
  • A team player who supports and helps drive common goals.
  • Languages: Greek and English (both required, written and spoken).
  • Professional certifications such as ISO 27001 Lead Auditor (ISO27001-LA), CISM, CISA, or similar.
  • Experience working within regulated environments.
  • Prior exposure to Contract Management roles or IT business-facing roles.

What we offer:

  • 💼 Competitive compensation & benefits package
  • 💰 Performance-based bonus scheme
  • 🧑‍⚕️ Comprehensive life & health insurance
  • 🏡 Flexible hybrid working model – to support your work-life balance
  • 🧡 Psychological support via a professional helpline for you and your family
  • 🚀 Career growth opportunities in a role that evolves with you
  • 🎉 Valuable experience in a well-known and fast-growing organization
  • 📚 Continuous learning and upskilling through tailored programs
  • 🏃🏽‍♂️ Employee Wellness Program – office Pilates & sports teams (padel, football, volleyball & more)
  • 🚗 Alternative transportation with company shuttle buses to our offices
  • 📲 Exclusive access to our employee app, OrangeGen, packed with tools, news & perks

What Does OrangeGen Offer? 🔗 Connect: Engage with your colleagues and management seamlessly, ensuring you’re always in the loop and part of our dynamic community.

🎉 Recognize: Celebrate achievements and milestones with a culture of recognition that boosts morale and fosters a positive work environment.

🏆 Custom Rewards: Enjoy personalized rewards and kudos, tailored to recognize your unique contributions and achievements.

Are you ready to be the next #OrangeGen maker?

Orange Gen, is our team of 2.200 people who are committed to cultivating an innovative retailtainment environment, supporting continuous development, and embracing flexibility—all while placing customer centricity at the forefront. We believe in fostering a culture that values your contributions, boosts your ambitions, and supports personal and professional growth. “Joy at Public” is our main motto which lies in creating a workplace where every individual is empowered to excel and evolve, always keeping the customer at the heart of our endeavors. We like to share our moments under the #OrangeTeam celebrating all team’s achievements and Orange Marks Stories!

All applications will be treated with the strictest confidentiality.

Read the full description
Security Security Engineer, Detection Response at Vercel

Monitor security alerts, maintain SIEM infrastructure, respond to incidents, and develop detections to protect internal corporate systems and compliance posture.

Mid Hybrid Posted 13 days ago RemoteFirstJobs Product
What this role involves

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the Role:

We are looking for a Security Engineer to join our Detection Response team. In this role, you will be responsible for managing Vercel’s internal Corporate Security (CorpSec) posture, monitoring for security anomalies, building additional detections and visibility mechanisms, and ensuring the overall security of our internal systems. You will work closely with various teams to support audits, optimize visibility, and handle security incidents as they arise.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you’re located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

What You Will Do:

  • Monitor and respond to security alerts across multiple channels, including managed SOC escalations.
  • Maintain visibility and logging infrastructure, ensuring effective SIEM (Security Information and Event Management) operations.
  • Support security audits for PCI, SOC2, ISO, and other compliance frameworks, gathering evidence and collaborating with Engineering, GRC and the broader Security Division.
  • Proactively enhance security operations by developing and deploying new detections, security tooling and rigorously managing key security partners.
  • Work on security investigations, incidents, and urgent requests as they arise, as well as contributing to the build-out and continuous improvement of the on-call process to enhance efficiency and effectiveness.
  • Continuously act as a guardian to enable the business to navigate risk-based changes.
  • Manage and enhance email security, endpoint security posture (EDR, configuration, and management), GitHub administration best practices, and internal security tooling to strengthen Vercel’s overall security framework

About You:

  • Extensive experience in security operations, including SIEM management, security logging, and detection engineering.
  • Strong knowledge of AWS infrastructure and cloud security best practices.
  • Experience with GitHub administration and security controls.
  • Proficiency in SQL for data analysis and security investigations.
  • Hands-on experience with incident response, including detection, triage, and remediation.
  • Strong endpoint management skills across multiple operating systems (Mac, Windows, Linux).
  • Proficiency in at least one scripting language (Python, Bash) and one compiled language (Rust, Go).
  • Familiarity with serverless functions and API security is a plus.

Bonus If You:

  • Have experience working with managed SOC providers and security automation platforms.
  • Have worked in high-growth, cloud-native environments with a focus on scalability.
  • Are comfortable working in a fast-paced environment with shifting priorities.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000-$312,000. This salary range is an estimate. Actual salary will be based on job-related skills, experience, and location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.

Read the full description
Security Information Security Analyst

Monitors and analyzes security threats, manages vulnerability assessments, and implements security controls to protect organizational systems and data.

Mid Posted 13 days ago Himalayas
What this role involves
About the jobMercor connects elite creative and technical talent with leading AI research labs.
Read the full description
Security Offensive Security Engineer

Conducts security testing, perimeter monitoring, and reconnaissance across external domains, websites, and IP infrastructure.

Mid Posted 13 days ago Himalayas
What this role involves
Role OverviewThe Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations.
Read the full description
Security Security Engineer - Full Remote (France) or Hybrid at Voyage PrivĂŠ

Security Engineer embeds security practices across product development, designs secure architectures, and builds automated security guardrails into CI/CD pipelines while advising engineering teams.

Mid Remote Posted 14 days ago RemoteFirstJobs Product
What this role involves

Company Description

✨ About Voyage Privé

Born in France in 2006, Voyage Privé has grown from an ambitious startup into becoming the Europe’s leading travel tech platform. Operating across 9 markets with tens of millions of users, we’re not just another e-commerce success story - we’re a tech powerhouse revolutionizing online travel.

What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.

We’re now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.

Job Description

🎯 Your Mission

As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform.

You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.

You’ll have the opportunity to build many security foundations from scratch — from internal tooling to CI/CD guardrails — and influence key architectural and technical decisions as we redesign our platform for scale.

Your key responsibilities will include:

  • Strengthen the security posture across products, data and infrastructure: secure coding practices, code reviews, threat modeling, vulnerability remediation, cloud, and network hardening.
  • Develop automated security guardrails integrated into CI/CD pipelines (SAST, SCA, secrets scanning).
  • Design secure architectures for applications, APIs, data flows, and integrations in partnership with engineering teams.
  • Secure hybrid environments combining virtual machines, containerized workloads, and cloud-native services, ensuring consistent security standards across the entire platform.
  • Drive proactive risk identification through continuous scanning, threat modeling sessions, risk assessments, and architecture reviews.
  • Enable engineering teams to build secure-by-design practices by acting as a trusted advisor, developing internal tools, and leading security awareness sessions.
  • Operational security & incident readiness: participate in on-call rotations, investigate security events, and improve incident response workflows.
  • Lead security improvement projects: build automation, enhance tools, optimize processes, and foster a culture of security ownership.

Qualifications

💡 What We’re Looking For

We’re looking for builders who move fast, think big, and care deeply about creating impact that lasts

Your profile:

  • 5–7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles.
  • Strong development background (Python, Node.js, Java, Go, PhP or similar).
  • Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins).
  • Solid understanding of cloud security principles (AWS, GCP, Azure).
  • Experience securing both virtualized systems (VMs) and containerized workloads.
  • Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals.
  • Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management.
  • Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints.
  • Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders.
  • Proactive, autonomous, critical thinker with a continuous improvement mindset.
  • Nice to have: previous experience or knowledge of compliance requirements (GDPR, PCI-DSS…)
  • Fluent in French and English.

Additional Information

⚡ Our Recruitment Process

We believe in a fast, transparent, and human recruitment process.

Here’s what you can expect:

  • Intro Call with a Talent Acquisition Partner (30–45 min) – Get to know each other! We’ll share more about the role, the team, and our culture.
  • Manager Interview (60 min) – Deep dive into your experience, missions, and ways of working.
  • Take-Home Task – Practical exercise to showcase your strategic thinking and approach to security.
  • Task Debrief (60 min) – Discuss your task with members of the team
  • On-Site Interview (60 min) – Meet the VP of Engineering to align on expectations, culture, and long-term impact.

📍Location : Aix en Provence or remote, France

📅 Start Date : The sooner, the better

📄 Contract Type : Full-time / Permanent

❤️ You’ll Love Joining Us

Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.

🌴 Prefer flexibility?  We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.

🤝Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.

💪 Forget your gym subscription! Access our large on-site fitness center morning, noon, and night - or challenge your colleagues to a padel match on our private court.

🎉 Live to the rhythm of Voyage Privé’s signature mix of business and fun: Company Breaks, Carnival, Annual Convention, meetups and talks… plus free tickets to every Provence Rugby home match and live music nights at the Dalida Institute.

✈️ And because travel is in our DNA : enjoy up to 20% off our exclusive getaway offers.

Join us and make your next career move a journey worth taking. 🌍

Read the full description
Security Security Engineer - Full Remote (France) or Hybrid at Voyage PrivĂŠ

Embeds security practices across product development, designs secure architectures, and builds automated security guardrails into CI/CD pipelines to strengthen the platform's security posture.

Mid Remote Posted 14 days ago RemoteFirstJobs Product
What this role involves

Company Description

✨ About Voyage Privé

Born in France in 2006, Voyage Privé has grown from an ambitious startup into becoming the Europe’s leading travel tech platform. Operating across 9 markets with tens of millions of users, we’re not just another e-commerce success story - we’re a tech powerhouse revolutionizing online travel.

What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.

We’re now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.

Job Description

🎯 Your Mission

As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform.

You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.

You’ll have the opportunity to build many security foundations from scratch — from internal tooling to CI/CD guardrails — and influence key architectural and technical decisions as we redesign our platform for scale.

Your key responsibilities will include:

  • Strengthen the security posture across products, data and infrastructure: secure coding practices, code reviews, threat modeling, vulnerability remediation, cloud, and network hardening.
  • Develop automated security guardrails integrated into CI/CD pipelines (SAST, SCA, secrets scanning).
  • Design secure architectures for applications, APIs, data flows, and integrations in partnership with engineering teams.
  • Secure hybrid environments combining virtual machines, containerized workloads, and cloud-native services, ensuring consistent security standards across the entire platform.
  • Drive proactive risk identification through continuous scanning, threat modeling sessions, risk assessments, and architecture reviews.
  • Enable engineering teams to build secure-by-design practices by acting as a trusted advisor, developing internal tools, and leading security awareness sessions.
  • Operational security & incident readiness: participate in on-call rotations, investigate security events, and improve incident response workflows.
  • Lead security improvement projects: build automation, enhance tools, optimize processes, and foster a culture of security ownership.

Qualifications

💡 What We’re Looking For

We’re looking for builders who move fast, think big, and care deeply about creating impact that lasts

Your profile:

  • 5–7 years of experience in software engineering, security engineering, DevSecOps, or equivalent technical security roles.
  • Strong development background (Python, Node.js, Java, Go, PhP or similar).
  • Hands-on experience with modern CI/CD systems (GitHub Actions, GitLab, Jenkins).
  • Solid understanding of cloud security principles (AWS, GCP, Azure).
  • Experience securing both virtualized systems (VMs) and containerized workloads.
  • Strong knowledge of secure coding, OWASP Top 10, and application security fundamentals.
  • Experience with SAST, SCA, container/IaC scanning, runtime security tools, IAM, and secrets management.
  • Pragmatic, engineering-first mindset: able to balance security with developer experience, velocity, and real-world constraints.
  • Excellent communication skills: able to translate complex security issues into actionable guidance for both technical and non-technical stakeholders.
  • Proactive, autonomous, critical thinker with a continuous improvement mindset.
  • Nice to have: previous experience or knowledge of compliance requirements (GDPR, PCI-DSS…)
  • Fluent in French and English.

Additional Information

⚡ Our Recruitment Process

We believe in a fast, transparent, and human recruitment process.

Here’s what you can expect:

  • Intro Call with a Talent Acquisition Partner (30–45 min) – Get to know each other! We’ll share more about the role, the team, and our culture.
  • Manager Interview (60 min) – Deep dive into your experience, missions, and ways of working.
  • Take-Home Task – Practical exercise to showcase your strategic thinking and approach to security.
  • Task Debrief (60 min) – Discuss your task with members of the team
  • On-Site Interview (60 min) – Meet the VP of Engineering to align on expectations, culture, and long-term impact.

📍Location : Aix en Provence or remote, France

📅 Start Date : The sooner, the better

📄 Contract Type : Full-time / Permanent

❤️ You’ll Love Joining Us

Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.

🌴 Prefer flexibility?  We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.

🤝Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.

💪 Forget your gym subscription! Access our large on-site fitness center morning, noon, and night - or challenge your colleagues to a padel match on our private court.

🎉 Live to the rhythm of Voyage Privé’s signature mix of business and fun: Company Breaks, Carnival, Annual Convention, meetups and talks… plus free tickets to every Provence Rugby home match and live music nights at the Dalida Institute.

✈️ And because travel is in our DNA : enjoy up to 20% off our exclusive getaway offers.

Join us and make your next career move a journey worth taking. 🌍

Read the full description
Security (fluent Ukrainian) Security Incident Response Specialist

Responds to and resolves security incidents while fluent in Ukrainian, supporting clients' security operations and threat mitigation.

Mid Posted 14 days ago Himalayas
What this role involves
SupportYourApp is an international Intelligent Support-as-a-Service company that has been providing business process outsourcing services to other IT companies around the globe (technical and customer support, services to improve customer experience) for the past 15 years.
Read the full description
Security (fluent Ukrainian) SOC Incident Response Specialist

Monitors security events and responds to incidents as part of a Security Operations Center team, requiring fluent Ukrainian language skills.

Mid Posted 14 days ago Jobicy AI
What this role involves
SupportYourApp is an international Intelligent Support-as-a-Service company that has been providing business process outsourcing services to other IT companies around the globe (technical and customer support, services to improve customer...
Read the full description