Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Senior Security Engineer, Bug Bounty at Mozilla

Manages Mozilla's bug bounty program, triages security reports, validates vulnerabilities, and drives remediation with engineering teams.

Senior Posted about 8 hours ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R3105

Hiring Ranges:

US Tier 1 Locations

$137,000—$183,000 USD

US Tier 2 Locations

$126,000—$168,000 USD

US Tier 3 Locations

$116,000—$155,000 USD

Read the full description
Security Senior Security Engineer, Bug Bounty at Mozilla

Owns and manages Mozilla's bug bounty program, triaging vulnerability reports, validating findings, and coordinating remediation with engineering teams.

Senior Posted about 8 hours ago RemoteFirstJobs Product
What this role involves

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R3105

Hiring Ranges:

Canada Tier 1 Locations

$104,000—$139,000 CAD

Canada Tier 2 Locations

$95,000—$126,000 CAD

Read the full description
Security Senior Security Engineer, Bug Bounty at Mozilla

Manages Mozilla's bug bounty program, triages security reports, validates vulnerabilities, and coordinates remediation with engineering teams.

Senior Posted about 8 hours ago RemoteFirstJobs Product
What this role involves

To learn the Hiring Ranges for this position, please select your location from the Apply Now dropdown menu.

To learn more about our Hiring Range System, please click this link.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company that has shaped the internet for the better over the last 25 years. We make pioneering brands like Firefox, the privacy-minded web browser. Now, with more than 225 million people around the world using our products each month, we’re shaping the next 25 years of technology and helping to reclaim an internet built for people, not companies. Our work focuses on diverse areas including AI, social media, security and more. And we’re doing this while never losing our focus on our core mission – to make the internet better for people.

The Mozilla Corporation is wholly owned by the non-profit 501© Mozilla Foundation. This means we aren’t beholden to any shareholders — only to our mission. Along with thousands of volunteer contributors and collaborators all over the world, Mozillians design, build and distribute open-source software that enables people to enjoy the internet on their terms.

About this team and role:

At Mozilla, we believe the internet is a global public resource—open and accessible to all. As a Security Engineer, you’ll protect that vision by building, breaking, and hardening products that put people’s privacy and safety first. We are looking for a security engineer to own, manage and administer the Mozilla Web Bug Bounty program and work with Mozilla product and SIRT teams to ensure risk mitigation of security incidents and events.

What you’ll do:

  • Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement
  • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community
  • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email)
  • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes
  • Identify root causes and systemic issues, and influence long-term improvements in secure development practices
  • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews
  • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes
  • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

What you’ll bring:

  • 3+ years of demonstrated ability in a security engineering role.
  • Experience operating bug bounty programs, including enhancements, automation and scaling, and/or bug hunting
  • Practical experience working with modern cloud technologies (eg. Amazon Web Services, Google Cloud Platform, Heroku, Microsoft Azure, etc.)
  • Experience analyzing code and systems to move from vulnerability → root cause → prevention
  • Real-world experience in software development and/or engineering operations
  • Ability to develop your own tools as needed in a variety of programming languages (eg. Python, Go, Rust, Javascript, etc.) is a plus, but not required.
  • Strong communication, collaboration, and problem-solving skills, with the ability to influence and guide cross-functional teams.
  • Formal credentials are great, but real-world experience, curiosity, passion and a growth mindset matter more.

What you’ll get:

  • Generous performance-based bonus plans to all eligible employees - we share in our success as one team
  • Rich medical, dental, and vision coverage
  • Generous retirement contributions with 100% immediate vesting (regardless of whether you contribute)
  • Quarterly all-company wellness days where everyone takes a pause together
  • Country specific holidays plus a day off for your birthday
  • One-time home office stipend
  • Annual professional development budget
  • Quarterly well-being stipend
  • Considerable paid parental leave
  • Employee referral bonus program
  • Other benefits (life/AD&D, disability, EAP, etc. - varies by country)

About Mozilla

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations, gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-DNI

Req ID: R3105

Read the full description
Security Engineer, Security Operations & Engineering at Collibra NV

Design and implement secure cloud architectures, manage threat detection and incident response, and ensure compliance with global security standards.

Senior Posted about 12 hours ago RemoteFirstJobs Product
What this role involves

Joining Collibra’s Security Operations & Engineering team

This is an opportunity to work in the Security Operations & Engineering team within the growing Collibra Security Organization.Security Engineers at Collibra design, build, and operate the systems that safeguard our data, infrastructure, and customers. The team combines technical depth with automation and innovation, embedding security across our platforms to ensure resilience and stay ahead of evolving threats. We partner across the business to architect secure systems, embed zero-trust principles, and automate detection and response. Security Engineers are hands-on builders who strengthen Collibra’s defense posture through engineering excellence and continuous improvement.

Security Engineers at Collibra are responsible for

  • Designing and implementing secure architectures across cloud environments, embedding zero-trust principles and identity-based access controls.
  • Managing threat detection, vulnerability assessments, and penetration testing to identify and remediate risks proactively.
  • Leading incident response and leveraging threat intelligence to detect, contain, and prevent evolving cyber threats.
  • Ensuring compliance with global security standards (ISO 27001, NIST 800-53, CIS, OWASP, SOC 2, CSA) and continuously improving Collibra’s security posture.
  • Supporting internal and external security audits by providing necessary documentation and evidence.

You have

  • 5+ years of experience in Information Security, Security Engineering, or a related technical field.
  • Strong understanding of CI/CD workflows and IAC
  • Experience securing cloud environments (AWS, GCP, or Azure).
  • Hands-on experience with SIEM, EDR, vulnerability management, and incident response tools.
  • Strong understanding of network and application security concepts, identity and access management, and encryption practices.
  • Working knowledge of Data Analysis / Data Science concepts and tooling (SQL, Python, etc.)
  • A bachelor’s degree in Computer Science, Information Security, or equivalent related experience.
  • Because this role supports the US government, it is required that this candidate be a US citizen who resides on US soil.
  • Demonstrated proficiency in leveraging AI tools (e.g., Claude, Gemini, ChatGPT, Copilot) to solve real-world business challenges, drive measurable outcomes, or streamline workflows.
  • A bachelor’s degree or equivalent related working experience is required
  • This position is not eligible for visa sponsorship.

You are

  • Analytical, curious, and eager to understand complex systems and emerging threats.
  • Adaptable and ready to learn new tools, techniques, and technologies.
  • Able to communicate security concepts clearly to both technical and non-technical audiences.
  • Collaborative and proactive, with a strong sense of ownership and accountability.
  • Committed to continuous improvement and automating solutions to reduce manual effort.

Measures of Success Are

  • Within your first month: You will understand Collibra’s infrastructure, security architecture, and monitoring environment.
  • By your third month: You will contribute to threat detection, incident response, and vulnerability management workflows.
  • By your sixth month: You will design and implement security automation or architectural improvements that measurably strengthen Collibra’s security posture.

Compensation for this role

The standard base salary range for this position is $116000 - $145000 per year. This position is not eligible for additional commission-based compensation. Salary offers are based on a combination of factors, including, but not limited to, experience, skills, and location.

In addition to base salary, we offer a competitive total rewards package, including bonus potential, equity for eligible roles, a Flex Fund monthly stipend, pension/401k plans, and more.

Benefits at Collibra

Collibra recognizes and values that everyone has different needs, interests, and life goals. We built our benefits program with flexibility in mind to support you and your loved ones through a diverse range of circumstances and life events. These flexible offerings sit on a foundation of competitive compensation, health coverage, and time off. Learn more about Collibra’s benefits.

We create inclusion and belonging through how we onboard, meet, connect, engage, and communicate. Learn more about diversity, equity, and inclusion at Collibra.

At Collibra, we’re proud to be an equal opportunity employer. We realize the key to creating a company with a world-class culture and employee experience comes from who we hire and creating a workplace that celebrates everyone.

With this, we proudly consider qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sexual orientation, pregnancy, sex, gender identity, gender expression, genetic information, physical or mental disability, HIV status, registered domestic partner status, caregiver status, marital status, veteran or military status, citizenship status or any other legally protected category. If you have a need that requires accommodation, let us know by completing our Accommodations for Applicants form.

Read the full description
Security Senior AI/LLM Penetration Tester at Bishop Fox

Conducts penetration testing and security assessments of AI/LLM applications, identifying vulnerabilities in language models, agents, and AI-powered systems.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining elite human expertise with the power of its proprietary Cosmos AI engine, the firm delivers industry-leading cloud and application security services, including AI-powered penetration testing and AI/LLM security assessments that reflect real-world attacker behavior. Renowned for its innovation and contributions to the open-source community through flagship tools like Sliver and AIMap, Bishop Fox has released 25+ tools and 75+ advisories in the last 10 years.

As a trusted partner to the world’s most recognizable brands, Bishop Fox protects 26 of the Fortune 100, eight of the top 10 global tech companies, all of the top five global media companies, 10 of the top 20 retailers and 7 of the top 10 manufacturers. A consistent market leader, Bishop Fox has been recognized as a Leader and “Fast Mover” in the GigaOm Radar for Attack Surface Management for five consecutive years. With a 70 NPS rating, the firm remains the trusted partner for organizations seeking to stay ahead of the evolving threat landscape. Learn more at bishopfox.com.

We are now hiring a SeniorAI/LLM Security Consultant to help clients stay ahead of emerging AI threats by conducting cutting-edge security assessments of large language models, AI agents, and AI-powered applications.

Who You Are and What You’ll Do

Our wants are simple: be good at—and most importantly—love what you do. Here’s what we’re looking for:

  • 5+ years of offensive security experience performing penetration tests, red team engagements, or application security assessments

  • Experience assessing AI/LLM-powered applications for vulnerabilities such as:

    • Prompt injection
    • Jailbreak techniques
    • Indirect prompt injection
    • Data leakage and sensitive information disclosure
    • Insecure tool/function calling
    • Agentic AI abuse
    • Model misuse and unsafe output generation
    • Understanding of modern AI architectures, including:
  • Experience performing manual application security testing beyond automated scanning

  • Strong understanding of web application security fundamentals, including the OWASP Top 10 Web, Agentic, and LLM Applications.

  • Experience reviewing AI application architectures and identifying security weaknesses across APIs, cloud infrastructure, and application logic

  • Experience performing source code review and dynamic testing

  • Familiarity with cloud platforms (AWS, Azure, or GCP) and securing AI workloads

  • Scripting or programming experience in Python, JavaScript Go, Java, or similar languages

  • Familiarity withLLM application and agent-orchestration frameworks, inference provider APIs, external capability integration for models, and open sourcetooling across commercial and self-hosted ecosystems.

  • Knowledge of authentication, authorization, networking, APIs, and secure software development practices

  • Excellent written and verbal communication skills, including presenting findings to technical and executive audiences

  • Ability to mentor teammates and contribute to internal research, tooling, and methodology development

  • OSCP, OSEP, GWAPT, GPEN, GXPN, or other relevant certifications are helpful but not required

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field is a plus

What Sets You Apart

  • Experience conducting AI red team exercises against production or pre-production AI systems

  • Research into emerging AI attack techniques or contributions to the offensive security community

  • Experience building or securing AI agents and autonomous workflows

  • Knowledge of adversarial machine learning concepts and model security

  • Experience with cloud-native AI platforms such as Azure OpenAI, Amazon Bedrock, or Google Vertex AI

  • Familiarity with AIsoftware development lifecycle (AI SDLC) and AI governance frameworks

Why Bishop Fox

At Bishop Fox, we’re driven by a simple mission: deliver exceptional quality to our clients, foster a vibrant and fulfilling environment for our team, and champion excellence within our industry. Our core values, which we live by every day, are:

  • Be Excellent to Each Other

  • Do the Right Thing

  • Do What You’ll Say You’ll Do

  • Get Better Together

  • Give a Sh*t

This position is not eligible for visa sponsorship. Applicants must be authorized to work in the United States of America for the duration of employment without sponsorship.

Bishop Fox has always allowed its employees to work remotely, and this role can be based anywhere in the United States.

Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and foster an inclusive culture where employees are empowered to do their best work while advancing the security community through world-class research and consulting.

Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including sexual orientation and gender identity), national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must successfully complete a background check as a condition of employment.

Interested? Apply today!

Read the full description
Security Senior IAM Engineer at Calendly

Designs, implements, and maintains identity and access management systems, automation workflows, and security controls to protect company infrastructure and enable secure user access at scale.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

What’s in it for you?

Ready to make a serious impact? Millions of people already rely on Calendly, and we’re still in the midst of exciting product growth — it’s a fantastic time to join us. Everything you’ll work on here will accelerate your career to the next level. If you want to learn, grow, and do the best work of your life alongside the best people you’ve ever worked with, then we hope you’ll consider allowing Calendly to be a part of your professional journey.

About the team & opportunity

What’s so great about working on Calendly’s Operations team?

We are the foundation that aims to set up our people for success to do the best work of their life at Calendly.

Why do we need you? Well, we are looking for a Senior IAM Engineer who will bring adaptability, ownership, and a strong desire to drive meaningful results across Calendly. You will report to the Senior Director, IT & Business Systems and will be responsible for owning Calendly’s Identity and Access Management (IAM) strategy, tools, and lifecycle processes. This includes designing, implementing, and maintaining secure access controls, automation workflows, and governance frameworks. In this role, you will work in direct partnership with Calendly’s executives and senior leaders to ensure our IAM posture not only protects the business but also enables productivity at scale.

A day in the life of a Senior IAM Engineer at Calendly

On a typical day, you will:

  • Builds automation workflows to streamline provisioning, deprovisioning (onboarding/offboarding), and access governance.
  • Defines and implements IAM security posture improvements, including business process strategy, entitlement, and access management.
  • Manages the IAM environment including Access Groups, Service Accounts, Sandbox access, and API configuration.
  • Proactively identifies and resolves IAM lifecycle management issues.
  • Conducts regular assessments and audits of relevant systems to ensure compliance with industry standards and regulations.
  • Maintains application dashboards and relevant documentation.
  • Provides high-level estimates for tasks and projects, assisting with project planning and prioritization.
  • Troubleshoots and resolves technical issues related to systems in a timely manner.
  • Collaborates cross-functionally with technical and non-technical stakeholders, clearly communicating complex IAM concepts (e.g., RBAC) to diverse audiences.
  • Facilitates governance discussions with business leaders and partners, ensuring alignment between security needs, compliance requirements, and business objectives.

What do we need from you?

Basic Qualifications

  • 5–7 years of direct IT experience, with 2–3 years as an Okta administrator and/or architect
  • Expert knowledge of Okta products and services, including Okta Identity Cloud, Okta Workflows, and Okta API Access Management.
  • Proficiency in integrating Okta solutions with various applications and systems such as HR systems, finance systems, and cloud platforms.
  • Experience with Google Workspace administration and automation tooling, including GAM for user and group lifecycle management.
  • Hands-on experience with modern identity management tools and public cloud platforms (e.g., Multi-Factor Authentication, Security Tokens, OAuth, Amazon Web Services, Atlassian).
  • Experience working in a primarily macOS, remote-first environment.
  • Strong cross-functional communication skills, with the ability to explain complex IAM concepts to non-technical stakeholders and guide governance discussions.
  • Authorized to work lawfully in the United States of America, as Calendly does not engage in immigration sponsorship at this time.

Preferred Skills and Qualifications

  • Okta Certified Administrator

What’s in it for you?

Ready to make a serious impact? Millions of people already rely on Calendly’s products, and we’re still in the midst of our growth curve — it’s a fantastic time to join us. Everything you’ll work on here will accelerate your career to the next level. If you want to learn, grow, and do the best work of your life alongside the best people you’ve ever worked with, then we hope you’ll consider allowing Calendly to be a part of your professional journey.

If you are an individual with a disability and would like to request a reasonable accommodation as part of the application or recruiting process, please contact us at recruiting@calendly.com . Calendly is registered as an employer in many, but not all, states. If you are located in Alaska, Hawaii, Montana, North Dakota, South Dakota, Nebraska, Iowa, West Virginia, and Rhode Island, you will not be eligible for employment. Note that all individual roles will specify location eligibility.

All candidates can find our Candidate Privacy Statement here

Candidates residing in California may visit our Notice at Collection for California Candidates here: Notice at Collection

The ranges listed below are the expected annual base salary for this role, subject to change.

Calendly takes a number of factors into consideration when determining an employee’s starting salary, including relevant experience, relevant skills sets, interview performance, location/metropolitan area, and internal pay equity.

Base salary is just one component of Calendly’s total rewards package. All full-time (30 hours/week) employees are also eligible for our Top Performer Bonus program (or Sales incentive), equity awards, and competitive benefits.

Calendly uses the zip code of an employee’s remote work location, or the onsite building location if hybrid, to determine which metropolitan pay range we use. Current geographic zones are as follows:

  • Tier 1: San Francisco, CA, San Jose, CA, New York City, NY
  • Tier 2: Chicago, IL, Austin, TX, Denver, CO, Boston, MA, Washington D.C., Philadelphia, PA, Portland, OR, Seattle, WA, Miami, FL, and all other cities in CA.
  • Tier 3: All other locations not in Tier 1 or Tier 2

Tier 1 Salary Hiring Range

$163,548.84—$192,410.40 USD

Tier 2 Salary Hiring Range

$149,919.77—$176,376.20 USD

Tier 3 Salary Hiring Range

$136,290.70—$160,342 USD

The ranges listed above are the expected annual base salary for this role, subject to change.

Calendly takes a number of factors into consideration when determining an employee’s starting salary, including relevant experience, relevant skills sets, interview performance, location/metropolitan area, and internal pay equity.

Base salary is just one component of Calendly’s total rewards package. All full-time (30 hours/week) employees are also eligible for our Top Performer Bonus program (or Sales incentive), equity awards, and competitive benefits.

Calendly uses the zip code of an employee’s remote work location, or the onsite building location if hybrid, to determine which metropolitan pay range we use. Current geographic zones are as follows:

  • Tier 1: San Francisco, CA, San Jose, CA, New York City, NY
  • Tier 2: Chicago, IL, Austin, TX, Denver, CO, Boston, MA, Washington D.C., Philadelphia, PA, Portland, OR, Seattle, WA, Miami, FL, and all other cities in CA.
  • Tier 3: All other locations not in Tier 1 or Tier 2

If you are an individual with a disability and would like to request a reasonable accommodation as part of the application or recruiting process, please let your Recruiter know when first connecting with them. Calendly is registered as an employer in many, but not all, states. If you are located in Alaska, Delaware, Hawaii, Idaho, Iowa, Montana, Nebraska, North Dakota, Rhode Island, South Dakota, and West Virginia, you will not be eligible for employment. Note that all individual roles will specify location eligibility.

All candidates can find our Candidate Privacy Statement here

Candidates residing in California may visit our Notice at Collection for California Candidates here: Notice at Collection

This role may require occasional travel for company events, team collaboration, or offsites.

Read the full description
Security Senior AI/LLM Penetration Tester at Bishop Fox

Conducts security assessments and penetration tests on AI/LLM applications to identify vulnerabilities and protect against emerging AI threats.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

For more than two decades, Bishop Fox has defined the forefront of offensive security. By combining elite human expertise with the power of its proprietary Cosmos AI engine, the firm delivers industry-leading cloud and application security services, including AI-powered penetration testing and AI/LLM security assessments that reflect real-world attacker behavior. Renowned for its innovation and contributions to the open-source community through flagship tools like Sliver and AIMap, Bishop Fox has released 25+ tools and 75+ advisories in the last 10 years.

As a trusted partner to the world’s most recognizable brands, Bishop Fox protects 26 of the Fortune 100, eight of the top 10 global tech companies, all of the top five global media companies, 10 of the top 20 retailers and 7 of the top 10 manufacturers. A consistent market leader, Bishop Fox has been recognized as a Leader and “Fast Mover” in the GigaOm Radar for Attack Surface Management for five consecutive years. With a 70 NPS rating, the firm remains the trusted partner for organizations seeking to stay ahead of the evolving threat landscape. Learn more at bishopfox.com.

We are now hiring a SeniorAI/LLM Security Consultant to help clients stay ahead of emerging AI threats by conducting cutting-edge security assessments of large language models, AI agents, and AI-powered applications.

Who You Are and What You’ll Do

Our wants are simple: be good at—and most importantly—love what you do. Here’s what we’re looking for:

  • 5+ years of offensive security experience performing penetration tests, red team engagements, or application security assessments

  • Experience assessing AI/LLM-powered applications for vulnerabilities such as:

    • Prompt injection
    • Jailbreak techniques
    • Indirect prompt injection
    • Data leakage and sensitive information disclosure
    • Insecure tool/function calling
    • Agentic AI abuse
    • Model misuse and unsafe output generation
    • Understanding of modern AI architectures, including:
  • Experience performing manual application security testing beyond automated scanning

  • Strong understanding of web application security fundamentals, including the OWASP Top 10 Web, Agentic, and LLM Applications.

  • Experience reviewing AI application architectures and identifying security weaknesses across APIs, cloud infrastructure, and application logic

  • Experience performing source code review and dynamic testing

  • Familiarity with cloud platforms (AWS, Azure, or GCP) and securing AI workloads

  • Scripting or programming experience in Python, JavaScript Go, Java, or similar languages

  • Familiarity withLLM application and agent-orchestration frameworks, inference provider APIs, external capability integration for models, and open sourcetooling across commercial and self-hosted ecosystems.

  • Knowledge of authentication, authorization, networking, APIs, and secure software development practices

  • Excellent written and verbal communication skills, including presenting findings to technical and executive audiences

  • Ability to mentor teammates and contribute to internal research, tooling, and methodology development

  • OSCP, OSEP, GWAPT, GPEN, GXPN, or other relevant certifications are helpful but not required

  • Bachelor’s degree in Computer Science, Cybersecurity, or a related technical field is a plus

What Sets You Apart

  • Experience conducting AI red team exercises against production or pre-production AI systems

  • Research into emerging AI attack techniques or contributions to the offensive security community

  • Experience building or securing AI agents and autonomous workflows

  • Knowledge of adversarial machine learning concepts and model security

  • Experience with cloud-native AI platforms such as Azure OpenAI, Amazon Bedrock, or Google Vertex AI

  • Familiarity with AIsoftware development lifecycle (AI SDLC) and AI governance frameworks

Why Bishop Fox

At Bishop Fox, we’re driven by a simple mission: deliver exceptional quality to our clients, foster a vibrant and fulfilling environment for our team, and champion excellence within our industry. Our core values, which we live by every day, are:

  • Be Excellent to Each Other

  • Do the Right Thing

  • Do What You’ll Say You’ll Do

  • Get Better Together

  • Give a Sh*t

This position is not eligible for visa sponsorship. Applicants must be authorized to work in the United States of America for the duration of employment without sponsorship.

Bishop Fox has always allowed its employees to work remotely, and this role can be based anywhere in the United States.

Our comprehensive benefits program is tailored to meet your needs at an affordable price. We embrace diversity and foster an inclusive culture where employees are empowered to do their best work while advancing the security community through world-class research and consulting.

Bishop Fox is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including sexual orientation and gender identity), national origin, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. All new hires must successfully complete a background check as a condition of employment.

Interested? Apply today!

Read the full description
Security Senior Security Engineer, Incident Response at Twilio

Leads technical response to security incidents across Twilio's infrastructure, conducts triage and remediation, and develops incident response processes and automation.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.

Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.

We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!

.

See yourself at Twilio

Join the team as Twilio’s next Senior Security Engineer, Incident Response

About the job

The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments.  You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities

In this role, you’ll:

  • Be an Owner: Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Write It Down: Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Wear the customer’s shoes: Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Ruthlessly Prioritize: Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Don’t Settle: Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Draw the Owl: Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Empower Others: Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Be Inclusive: Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Qualifications

Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn’t followed a traditional path, don’t let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!

*Required:

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of  controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks

Location

  1. This role will be remote,but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Compensation

*Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only.

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $141,520.00 - $176,900.00.
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $149,840.00 - $187,300.00
  • Based in the San Francisco Bay area, California: $166,400.00 - $208,000.00.
  • This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave.

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Application deadline information

Applications for this role are intended to be accepted until 30th Aug, but may change based on business needs.

Twilio thinks big. Do you?

We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That’s why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.

So, if you’re ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn’t what you’re looking for, please consider other open positions.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Read the full description
Security Senior Cloud Security Engineer (Remote Canada) at Smile Digital Health

Design, deploy, and maintain secure cloud infrastructure across AWS, Azure, OCI, and GCP while providing technical support and guidance to internal teams and customers.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte’s Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.

At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This position works closely with the Cloud Architect and Development teams to ensure infrastructure fulfills the project’s deliverables while keeping a high standard of quality and operational maturity.

Responsibilities:

  • Collaborate with Development and Architecture teams to build  complex and highly available cloud environments for Internal and External infrastructure builds.
  • Provide Level 3 Technical support to Internal teams, Customers and Partners to support our core product.
  • Lead and educate clients on cloud deployment patterns.
  • Act as a SME for implementing and building infrastructure to support our core product.
  • Investigate and resolve any customer integration issues that arise during implementation.
  • Design procedure for system troubleshooting and maintenance.
  • Perform root cause analysis for any implementation errors and provide feedback to the Core dev team.
  • Document best practices and lessons learned.
  • Design, implement and maintain a secure and scalable infrastructure platform.
  • Provide ongoing maintenance and support of internal tools, improve system health and reliability.
  • Accountable for ensuring that all working hours are accurately reported in Netsuite on a daily or weekly basis, that the majority of (if not all) hours are tracked as billable and that the project management tool in Netsuite is properly and fully utilized
  • Tracking and reporting of billable hours is a critical aspect of project management and delivery to our customers and this is a major area of accountability.
  • Participate in on-call rotation to provide application and infrastructure support, incident management and troubleshooting.

Requirements :

  • At least 6+ years of experience in Information technology, with infrastructure and platform services automation expertise.
  • 3+ years of experience with engineering and supporting containerization technology.
  • 3+ years of experience on AWS, Azure, OCI or GCP.
  • Professional Cloud Certifications are preferred.
  • Experience building end-to-end cloud solutions using low level architecture documents.
  • Demonstrated experience in translating customer requirements to net new infrastructure to address business needs.
  • Drive to innovate and use various technologies to solve complex business needs.
  • Expertise in troubleshooting support escalation, on-Call process optimization and documenting knowledge.
  • Solid networking fundamentals and proven experience with Security and Compliance (SOC2, HIPAA, ISO27001) best practices and how to implement controls that support high-velocity software delivery teams.
  • Proven experience with Kubernetes/Openshift and Docker.
  • Experience with Infrastructure as code tools such as Ansible, Terraform or CloudFormation.
  • Deep knowledge of cloud service providers and best practices around implementation and configuration, preferably managing customer environments.

$130,000 - $145,000 a year

Some of the benefits we offer:

\* Remote Work Environment

\* Flexible Time Away From Work Policy including PTO, Personal and Sick Days

\* Competitive Salary and Health/Medical Benefits

\* RRSP/TFSA/401K Employee Contribution

\* Life and Disability

\* Employee Assistance Program

\* FHIR Study Program and Skillsoft Learning

\* Super HAPI Fun Club

Smile’s core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.

We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer, Incident Response at Twilio

Leads technical response to security incidents and events across global infrastructure, conducting triage, containment, remediation, and developing scalable incident response processes.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.

Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.

We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!

.

See yourself at Twilio

Join the team as Twilio’s next Senior Security Engineer, Incident Response

About the job

The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments.  You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities

In this role, you’ll:

  • Be an Owner: Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Write It Down: Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Wear the customer’s shoes: Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Ruthlessly Prioritize: Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Don’t Settle: Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Draw the Owl: Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Empower Others: Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Be Inclusive: Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Qualifications

Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn’t followed a traditional path, don’t let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!

*Required:

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of  controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks

Location

  1. This role will be remote,but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Compensation

*Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only.

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $141,520.00 - $176,900.00.
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $149,840.00 - $187,300.00
  • Based in the San Francisco Bay area, California: $166,400.00 - $208,000.00.
  • This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave.

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Application deadline information

Applications for this role are intended to be accepted until 30th Aug, but may change based on business needs.

Twilio thinks big. Do you?

We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That’s why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.

So, if you’re ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn’t what you’re looking for, please consider other open positions.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Read the full description
Security Senior Security Engineer, Incident Response at Twilio

Lead technical response to security incidents across global infrastructure, conduct triage and remediation, and develop scalable incident response processes and automation.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Who we are

At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences.

Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands.

We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions!

.

See yourself at Twilio

Join the team as Twilio’s next Senior Security Engineer, Incident Response

About the job

The Security Incident Response Team (SIRT) is looking for a Senior Security Engineer who is passionate about solving Twilio’s mission of security and reliability by working across the organization to lead the technical response to security events and incidents across Twilio’s global infrastructure, services and applications by effectively conducting triage, containment, remediation and driving post-incident betterments.  You will work within a team that partners with R&D Engineering and R&D Business teams to develop scalable processes and technical solutions.

You will be a valued member of a team of deeply technical Security Engineers to focus on creating bespoke and standard Security response processes, enhancing our capabilities for threat mitigation and incident response, and then automating as much as you possibly can (and more)! You will help us to grow our global, scaled team and program.

Responsibilities

In this role, you’ll:

  • Be an Owner: Lead and support the response to all security events and incidents across Twilio’s complex global infrastructure, services and applications.
  • Write It Down: Be responsible for documentation of incidents and projects you work on and craft best practices as runbooks and standard operating procedures to share knowledge across teams.
  • Wear the customer’s shoes: Work cross-collaboratively to understand and help solve challenges related to a broad spectrum of threat actors and activity.
  • Ruthlessly Prioritize: Work to improve Twilio’s security and reliability posture by driving identified betterments from security events and incidents.
  • Don’t Settle: Rapidly acquire new technical skills and knowledge in a fast-paced, highly disruptive industry environment.
  • Draw the Owl: Own the security incident lifecycle, respond to incidents and participate in on-call rotation and participate in RCAs for security incidents.
  • Empower Others: Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team’s work.
  • Be Inclusive: Provide mentorship, support, and care for the team in a way that enables long-term career development, happiness, and success at scale.

Qualifications

Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn’t followed a traditional path, don’t let that stop you from considering Twilio. We are always looking for people who will bring something new to the table!

*Required:

  • Proven experience: 5+ years of security incident response in a production-cloud environment
  • Subject-matter expert on security issues and technologies
  • Ability to utilize AI for comprehensive, complex security incident response activities delivering high fidelity detections
  • Advanced knowledge of service-oriented architectures, as well as experience with security tools and technologies fit for a cloud environment
  • Experience working across a technology stack on difficult security challenges and initiatives
  • Experience with SIEM platforms and the ability to extend their functionality
  • Experience with SOAR tools and automating manual security processes
  • Experience in either AWS, GCP, or other large cloud platform
  • Excellent written and verbal communication skills
  • Ability to influence and build effective working relationships with every level of the organization.

Desired:

  • AI Model Security & Posture Management: Support Implementation of  controls and safeguards to prevent AI vulnerabilities, such as prompt injections, model evasion, and data poisoning
  • AI-Driven Threat Response: Utilize GenAI and LLM-based security use cases to rapidly interpret alerts, reduce false positives, and contextualize threat data
  • Artifact & Evidence Triage: Collects intrusion artifacts and forensically sound images to analyze malware, trojans, and source code.
  • Threat Intelligence Integration: Monitors external vendor data and threat intelligence to analyze trends and proactively defend against emerging risks

Location

  1. This role will be remote,but is not eligible to be hired in CA, CT, NJ, NY, PA, WA.

Travel

We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings.

What We Offer

Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location.

Compensation

*Please note this role is open to candidates outside of California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State. The information below is provided for candidates hired in those locations only.

The estimated pay ranges for this role are as follows:

  • Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $141,520.00 - $176,900.00.
  • Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $149,840.00 - $187,300.00
  • Based in the San Francisco Bay area, California: $166,400.00 - $208,000.00.
  • This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave.

The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location.

Application deadline information

Applications for this role are intended to be accepted until 30th Aug, but may change based on business needs.

Twilio thinks big. Do you?

We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That’s why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts.

So, if you’re ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn’t what you’re looking for, please consider other open positions.

Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.

Read the full description
Security Senior Cloud Security Engineer (Remote Canada) at Smile Digital Health

Design, deploy, and maintain secure cloud infrastructure across multiple cloud providers while providing technical support and guidance to internal teams and customers.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte’s Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.

At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This position works closely with the Cloud Architect and Development teams to ensure infrastructure fulfills the project’s deliverables while keeping a high standard of quality and operational maturity.

Responsibilities:

  • Collaborate with Development and Architecture teams to build  complex and highly available cloud environments for Internal and External infrastructure builds.
  • Provide Level 3 Technical support to Internal teams, Customers and Partners to support our core product.
  • Lead and educate clients on cloud deployment patterns.
  • Act as a SME for implementing and building infrastructure to support our core product.
  • Investigate and resolve any customer integration issues that arise during implementation.
  • Design procedure for system troubleshooting and maintenance.
  • Perform root cause analysis for any implementation errors and provide feedback to the Core dev team.
  • Document best practices and lessons learned.
  • Design, implement and maintain a secure and scalable infrastructure platform.
  • Provide ongoing maintenance and support of internal tools, improve system health and reliability.
  • Accountable for ensuring that all working hours are accurately reported in Netsuite on a daily or weekly basis, that the majority of (if not all) hours are tracked as billable and that the project management tool in Netsuite is properly and fully utilized
  • Tracking and reporting of billable hours is a critical aspect of project management and delivery to our customers and this is a major area of accountability.
  • Participate in on-call rotation to provide application and infrastructure support, incident management and troubleshooting.

Requirements :

  • At least 6+ years of experience in Information technology, with infrastructure and platform services automation expertise.
  • 3+ years of experience with engineering and supporting containerization technology.
  • 3+ years of experience on AWS, Azure, OCI or GCP.
  • Professional Cloud Certifications are preferred.
  • Experience building end-to-end cloud solutions using low level architecture documents.
  • Demonstrated experience in translating customer requirements to net new infrastructure to address business needs.
  • Drive to innovate and use various technologies to solve complex business needs.
  • Expertise in troubleshooting support escalation, on-Call process optimization and documenting knowledge.
  • Solid networking fundamentals and proven experience with Security and Compliance (SOC2, HIPAA, ISO27001) best practices and how to implement controls that support high-velocity software delivery teams.
  • Proven experience with Kubernetes/Openshift and Docker.
  • Experience with Infrastructure as code tools such as Ansible, Terraform or CloudFormation.
  • Deep knowledge of cloud service providers and best practices around implementation and configuration, preferably managing customer environments.

$130,000 - $145,000 a year

Some of the benefits we offer:

\* Remote Work Environment

\* Flexible Time Away From Work Policy including PTO, Personal and Sick Days

\* Competitive Salary and Health/Medical Benefits

\* RRSP/TFSA/401K Employee Contribution

\* Life and Disability

\* Employee Assistance Program

\* FHIR Study Program and Skillsoft Learning

\* Super HAPI Fun Club

Smile’s core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.

We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer I – GRC FedRAMP (Remote Eligible) at Smartsheet

Leads FedRAMP and GovRAMP compliance certifications, manages third-party assessments, oversees continuous monitoring, and ensures regulatory authorization maintenance for government customers.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

FedRAMP and GovRAMP (formerly StateRAMP) are transforming how Smartsheet serves government and regulated customers. We need a FedRAMP and GovRAMP subject matter expert to lead these programs—someone with real hands-on experience obtaining and maintaining ATO authorizations, navigating 3PAO assessments, and managing continuous monitoring requirements. In this role, you’ll own Smartsheet’s FedRAMP and GovRAMP certifications, manage relationships with our 3PAOs, drive annual assessment preparation, manage POA&M processes, and ensure we maintain authorizations at the highest level. You’ll understand the nuances of federal compliance, speak fluently with government agencies and authorized assessors, and translate complex regulatory requirements into clear roadmaps for engineering and operations teams. You’ll be the voice of federal compliance at Smartsheet and the trusted advisor to government customers on our security posture.

You Will:

  • Own FedRAMP and GovRAMP (formerly StateRAMP) certifications and roadmaps: Lead the overall strategy for obtaining and maintaining federal authorizations, including package management, compliance timelines, and authority coordination.
  • Manage 3PAO relationships and assessments: Work with accredited third-party assessment organizations to conduct initial assessments and annual re-assessments. Coordinate scoping, evidence preparation, testing coordination, and results validation.
  • Lead continuous monitoring (ConMon) execution: Oversee the delivery of monthly, annual, and event-driven FedRAMP deliverables including vulnerability scans, penetration testing, system security plan updates, and compliance reporting.
  • Manage Plans of Action and Milestones (POA&M) processes: Own the identification, prioritization, tracking, and remediation of findings. Ensure timely closure of Critical (30 days), High (30 days), and Moderate (90 days) findings while coordinating with engineering and security teams.
  • Coordinate significant change requests and system modifications: Work with product and engineering to document, scope, assess, and obtain agency approval for system changes that impact security controls or compliance posture.
  • Engage with authorizing officials and federal agencies: Build and maintain relationships with government sponsors, CIOs, and agency decision-makers. Provide regular status updates, respond to questions, and demonstrate authorization compliance.
  • Prepare comprehensive assessment packages: Lead the development of System Security Plans (SSP), Security Assessment Plans (SAP), risk exposure tables, and supporting documentation required for audits.
  • Drive compliance automation and efficiency: Identify opportunities to automate evidence collection, simplify reporting, and reduce manual effort while maintaining rigor and auditability.

You Have:

  • 5+ years of hands-on experience with FedRAMP and/or GovRAMP (StateRAMP) programs, including direct involvement in obtaining and maintaining ATOs.
  • Proven experience working with accredited 3PAOs: You’ve coordinated initial assessments, managed annual re-assessments, provided evidence packages, and worked through test results and findings.
  • A degree in Computer Science, Computer Engineering, Cybersecurity or a related field or equivalent practical experience.
  • Deep understanding of FedRAMP continuous monitoring requirements: Comprehensive knowledge of monthly deliverables, annual assessment cycles, POA&M management, vulnerability scan and penetration test requirements, and compliance reporting cadences.
  • Strong NIST 800-53 control knowledge: Fluency with control baselines, supplemental overlays (ITAR, CJIS, HIPAA, etc.), impact level determination, and control selection for various system types.
  • Project management and stakeholder coordination skills: Experience managing complex, multi-month compliance programs with multiple dependencies, stakeholders, and tight deadlines.
  • Technical foundation in cloud security and compliance: Working knowledge of AWS/GCP/Azure, cloud security controls, identity and access management, encryption, logging, and incident response—sufficient to understand system architecture and control implementations.
  • Excellent documentation and communication skills: Ability to write clear System Security Plans, coordinate across multiple stakeholders, and translate technical and compliance concepts for government audiences.
  • Understanding of federal procurement and contracting: Familiarity with how government agencies acquire and authorize cloud services, and the role of compliance in federal GTM.
  • US Person Status: Must be a U.S. Citizen, U.S. National to meet federal compliance requirements.

Nice to Have:

  • Professional certifications: CISSP, CISM, CISA, CRISC, or FedRAMP-specific credentials.
  • Experience with multiple impact levels: IL2 (Low), IL4 (Moderate), IL6 (High) systems and their specific requirements.
  • Background in government contracting, DoD CMMC, or other federal compliance frameworks.
  • Experience with SaaS FedRAMP authorization, particularly multi-tenant systems and JAB vs. Agency ATO pathways.

Current US Perks & Benefits:

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range

$145,000—$210,000 USD

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

#LI-Remote

Read the full description
Security Cyber Defense Senior Analyst

Senior cybersecurity analyst who monitors, detects, and responds to security threats to protect company infrastructure and data.

Senior Posted 4 days ago Jobicy AI
What this role involves
Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,...
Read the full description
Security Cyber Defense Senior Analyst

Monitors and responds to cybersecurity threats, analyzes security incidents, and defends organizational systems against attacks.

Senior Posted 4 days ago Jobicy AI
What this role involves
Company DescriptionExperian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare,...
Read the full description
Security Senior Cloud Security Engineer - AI Resilience & Security Enhancements (Contract) at Form3

Senior Cloud Security Engineer designs and implements security controls, governance frameworks, and resilience improvements across cloud-native payment infrastructure.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

THE PROJECT 📝

We’re looking for an experienced Senior Cloud Security Engineer to join Form3 on a contract basis to deliver a strategic programme of security enhancements across our cloud-native payments platform.

Focusing on improving cloud security, operational resilience and governance across our engineering ecosystem, you will work closely with our Platform Engineering and Security teams to design and implement practical security improvements that enhance how we build, deploy and operate critical payment infrastructure.

You’ll play a key role in strengthening areas such as cloud platform security, software supply chain security, identity and access management, AI governance, cryptographic controls and automated security assurance, ensuring solutions are scalable, production-ready and aligned with regulatory expectations.

Key responsibilities

  • Assess the current cloud security posture across Form3 environments, identifying risks, control gaps and opportunities for improvement.
  • Design and implement scalable cloud security controls that improve the resilience and security of our cloud-native platform.
  • Enhance perimeter security controls across cloud infrastructure.
  • Strengthen CI/CD pipeline security through secure build processes, automated security testing, deployment governance and artefact integrity.
  • Improve production access security, including RBAC, least-privilege implementation, deployment tooling and operational processes.
  • Enhance software supply chain security through dependency management, container image scanning, provenance, signing and vulnerability remediation.
  • Contribute to the secure adoption and governance of AI-enabled engineering capabilities, including controls for data protection, auditability and operational resilience.
  • Provide technical leadership and guidance on cloud security architecture and secure engineering practices.
  • Produce high-quality technical documentation, including solution designs, implementation plans, operational procedures and security evidence.
  • Collaborate closely with engineering, platform and security teams to deliver maintainable, production-ready security improvements.
  • Ensure all deliverables align with operational resilience requirements, regulatory obligations and internal security standards.
  • Deliver changes using structured, low-risk change management practices while maintaining service availability.

WE’RE LOOKING FOR 🔍

Essential

  • Extensive experience designing and implementing cloud security solutions within large-scale cloud-native environments.
  • Strong hands-on experience securing public cloud platforms (AWS preferred).
  • Expertise in cloud security architecture, identity and access management, workload protection and infrastructure security.
  • Experience securing CI/CD pipelines and modern software delivery practices.
  • Strong understanding of software supply chain security, including dependency management, artefact signing, provenance and vulnerability management.
  • Experience implementing least-privilege access models and RBAC.
  • Knowledge of security monitoring, risk assessment and security governance.
  • Experience working within highly regulated or business-critical production environments.
  • Excellent stakeholder management and communication skills, with the ability to influence engineering teams.
  • Strong technical documentation and design skills.

Desirable

  • Experience implementing security controls for AI or machine learning platforms.
  • Knowledge of cryptographic controls and key management.
  • Experience with Infrastructure as Code and policy-as-code tooling.
  • Familiarity with payment platforms or financial services environments.
  • Understanding of operational resilience frameworks and regulatory requirements affecting critical financial infrastructure.
  • Relevant cloud or security certifications (AWS Security Specialty, CISSP, CCSP or similar).

TECH STACK ⚙️

  • AWS – Cloud infrastructure and security controls.
  • Kubernetes – Container orchestration and workload security.
  • Terraform – Infrastructure as Code and security automation.
  • CI/CD tooling – Secure software delivery, build security and deployment governance.
  • Container security tooling – Image scanning, vulnerability management and runtime protection.
  • Identity & Access Management (IAM) – Least privilege, RBAC and privileged access controls.
  • Software Supply Chain Security – Dependency scanning, artefact signing, provenance and integrity controls.
  • Security monitoring & observability platforms – Detection, auditability and operational visibility.
  • AI governance and security controls – Supporting secure adoption of AI-enabled engineering capabilities.

INTERVIEW PROCESS ✍️

Stage 1: Screening Call with Talent Team

Stage 2: Kubernetes & Linux Interview

Stage 3: Cloud Security & Engineering Best Practices interview

We always aim to stick to the above process, however there may be occasions when an additional interview stage is needed for us to be sure we’re hiring the right fit for the role.

HIRING LOCATIONS📍

Here are the locations that we are looking to engage with contractors from. Please note, we are not looking to engage with contractors outside of these locations.

  • Austria
  • Bulgaria
  • Croatia
  • Cyprus
  • Estonia
  • Greece
  • Hungary
  • Italy
  • Latvia
  • Lithuania
  • Malta
  • Romania
  • Slovakia
  • Slovenia

All contractors start their first day in our office to collect the equipment needed to work remotely.

ABOUT FORM3 💭

Revolutionising the world of payments with our cloud-native, multi-cloud platform. For more information about Form3, check out the following pages:

What we do | Life at Form3 | Payments Cannot Fail Series | .Tech Podcast

OUR DEI&B COMMITMENT

We hire talented people from a variety of backgrounds and experiences and are committed to a work environment based on diversity, open-mindedness and curiosity. We’re united by our company values (we even created them together!) and we celebrate our unique differences.

Our employee lifecycle processes are designed to embrace equal opportunity and prevent discrimination against our people regardless of personal characteristics. It is our strong belief that the more inclusive and belonging we are as a business, the better our work will be.

As an inclusive employer, we guarantee to interview all neurodiverse and physically disabled applicants who meet the minimum criteria for this role. We also encourage candidates to notify us of any reasonable adjustments that may be required during the recruitment process. This includes providing job adverts in alternative, accessible formats or adjustments required at interview stage.

If you consider yourself to be neurodiverse or physically disabled under the UN definition of disability and would like to be considered under this scheme and/or require any reasonable adjustments please let us know by sending an email to careers@form3.tech clearly stating your consent for us to process this data.

For more information please refer to our Recruitment Data Policy.

Read the full description
Security Senior Application Security Engineer at Google Fiber

Senior Application Security Engineer secures applications and development ecosystems by managing defenses, architecting CI/CD security controls, and governing AI integrations within the SDLC.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

At GFiber, we believe that great internet has the power to drive innovation, strengthen communities, enable the impossible, and do all the everyday things that make all of our world go round. And the job of creating better internet is never done - so we’re growing! Our team is committed to building a place where people who want to make a difference can grow their careers and find their spot to belong.

GFiber is an Alphabet company that brings Google Fiber and Google Fiber Webpass internet services to homes and businesses across the United States. Our teams are expanding as we connect more cities and people to exceptional internet.

The application window will be open until at least July 19th, 2026. This opportunity will remain online based on business needs which may be before or after the specified date.

This role is not eligible for immigration sponsorship.

Role Description

As a Senior Application Security Engineer, you will be a core technical advisor for securing GFiber’s applications and development ecosystems. You will partner closely with engineering teams to review code, secure software delivery pipelines, and design frameworks that make writing secure code the path of least resistance. You will lead initiatives ranging from managing threat detection boundaries to establishing cutting-edge AI integrations within our development lifecycle. This is a highly collaborative role where you will influence engineering practices, champion security culture across teams, and occasionally share strategic insights with senior leadership.

In this role, you’ll:

  • Manage and optimize core application defenses, including the Web Application Firewall (WAF) and automated vulnerability scanning tools, while monitoring key security metrics.
  • Architect and maintain security gating processes within the CI/CD pipeline to ensure secure, seamless software delivery.
  • Govern and secure our growing AI pipeline within the SDLC by implementing input/output monitoring, context controls, and safety guardrails around AI-generated code.
  • Partner with development teams to remediate vulnerabilities, scale the security champions program, and co-lead our public bug bounty initiative.
  • Mentor junior engineers and analysts, and occasionally present security postures, trends, and program milestones to upper management.

At a minimum, we would like you to have:

  • Bachelor’s degree in Computer Science, a related technical field, or equivalent practical experience.
  • 5 years of experience with managing Web Application Firewalls (WAF) and integrating automated security gating into CI/CD pipelines.
  • Experience with vulnerability management and cloud-hosted application security scanning tools.
  • Experience collaborating directly with software development teams on threat mitigation.
  • Experience with scripting or programming languages (i.e., Python, Java, Kotlin) to automate security processes.

It’s preferred if you have:

  • Experience implementing security guardrails, context controls, or monitoring for Large Language Models (LLMs) and AI-assisted development tools.
  • Experience leading or growing a security champions program or a bug bounty platform.
  • Experience mentoring junior security professionals or teaching secure coding practices to engineering teams.
  • Experience analyzing technical security risks and presenting metrics or findings to upper management.
  • Knowledge of ISP infrastructure, web-scale networks, or cloud environments (e.g., GCP, AWS).

The US base salary range for this full-time position is between $156,900 - $229,700 + bonus + benefits. As pay varies by location, your recruiter will share more about the specific salary range for your targeted location during the hiring process.

#LI-DNI

GFiber is committed to equal opportunity employment regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, citizenship, marital status, disability or Veteran status. Disclosure is voluntary, and this information will be kept confidential in compliance with Google’s Candidate Privacy Policy. For more information please refer to our Equal Employment Opportunity Policy and the EEOC’s “Know your rights: workplace discrimination is illegal” (PDF).

It’s important to us to create an accessible, inclusive workplace for everyone. If you have a need that requires accommodation, please let us know by completing ouraccommodations for applicants form. Our candidate accommodations team will then connect with you to confidentially discuss your options.

Read the full description
Security Sr. Security Engineer at Brave

Conducts security reviews, penetration testing, triages security reports, and implements security-relevant code across Brave's browser and search products.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Senior Security Engineer

Remote

About Brave

Brave is on a mission to protect the human right to privacy online. We’ve built a free web browser that blocks creepy third-party ads and trackers by default, a private search engine with a truly independent index, a browser-native crypto wallet, and a private ad network (opt-in!) that directly rewards you for your attention. And we’re just getting started. Already 110+ million people have switched to Brave for a faster, more private web. Millions more switch every month.

The internet is a sea of privacy-harmful ads, hackers, and echo chambers. Big Tech makes huge profits off our data, and tells us what’s true and what’s not. Brave is fighting back. Join us!

Summary

We are hiring a staff engineer on the Brave security and privacy team! You will help keep our users safe across Brave’s products, including Brave browser and Brave Search. Responsibilities include:

  1. Security reviews of Brave products
  2. Triaging and fixing security reports
  3. Designing and implementing security-relevant code
  4. Penetration tests of Brave products and infrastructure

Brave is widely-recognized as one of the best browsers for security and privacy, doing industry-leading work with a team that’s a fraction of the size of Big Tech-supported browsers.

Required qualifications

  • At least 5 years experience (or equivalent) in security engineering
  • Experience in penetration testing and/or security auditing
  • Proficiency in C++, both implementing and reviewing
  • Strong familiarity with the Web security model
  • Experience securing AWS infrastructure
  • Very comfortable working and communicating async with a geographically-distributed software development team
  • Be comfortable diving into an extremely large, unfamiliar and complex codebase
  • Be comfortable with Git and collaborating on GitHub

Preferred qualifications

  • Experience contributing to large open source codebases and/or participating in open source communities
  • Proficiency in Web technologies (HTML, CSS, JavaScript)
  • Proficiency in Go and Rust
  • DevOps experience
  • Contributions to other Web browsers
  • Familiarity with Chromium’s architecture, especially security
  • Ability to write clear technical documentation and less technical writing for blog posts or public communication.
  • Be excited about privacy, anonymity, and censorship resistance!
Read the full description
Security Senior Cloud Security Engineer - AI Resilience & Security Enhancements (Contract) at Form3

Design and implement cloud security controls, strengthen CI/CD pipeline security, manage identity/access, and ensure AI governance across a cloud-native payments platform.

Senior Posted 6 days ago RemoteFirstJobs Product
What this role involves

THE PROJECT 📝

We’re looking for an experienced Senior Cloud Security Engineer to join Form3 on a contract basis to deliver a strategic programme of security enhancements across our cloud-native payments platform.

Focusing on improving cloud security, operational resilience and governance across our engineering ecosystem, you will work closely with our Platform Engineering and Security teams to design and implement practical security improvements that enhance how we build, deploy and operate critical payment infrastructure.

You’ll play a key role in strengthening areas such as cloud platform security, software supply chain security, identity and access management, AI governance, cryptographic controls and automated security assurance, ensuring solutions are scalable, production-ready and aligned with regulatory expectations.

Key responsibilities

  • Assess the current cloud security posture across Form3 environments, identifying risks, control gaps and opportunities for improvement.
  • Design and implement scalable cloud security controls that improve the resilience and security of our cloud-native platform.
  • Enhance perimeter security controls across cloud infrastructure.
  • Strengthen CI/CD pipeline security through secure build processes, automated security testing, deployment governance and artefact integrity.
  • Improve production access security, including RBAC, least-privilege implementation, deployment tooling and operational processes.
  • Enhance software supply chain security through dependency management, container image scanning, provenance, signing and vulnerability remediation.
  • Contribute to the secure adoption and governance of AI-enabled engineering capabilities, including controls for data protection, auditability and operational resilience.
  • Provide technical leadership and guidance on cloud security architecture and secure engineering practices.
  • Produce high-quality technical documentation, including solution designs, implementation plans, operational procedures and security evidence.
  • Collaborate closely with engineering, platform and security teams to deliver maintainable, production-ready security improvements.
  • Ensure all deliverables align with operational resilience requirements, regulatory obligations and internal security standards.
  • Deliver changes using structured, low-risk change management practices while maintaining service availability.

WE’RE LOOKING FOR 🔍

Essential

  • Extensive experience designing and implementing cloud security solutions within large-scale cloud-native environments.
  • Strong hands-on experience securing public cloud platforms (AWS preferred).
  • Expertise in cloud security architecture, identity and access management, workload protection and infrastructure security.
  • Experience securing CI/CD pipelines and modern software delivery practices.
  • Strong understanding of software supply chain security, including dependency management, artefact signing, provenance and vulnerability management.
  • Experience implementing least-privilege access models and RBAC.
  • Knowledge of security monitoring, risk assessment and security governance.
  • Experience working within highly regulated or business-critical production environments.
  • Excellent stakeholder management and communication skills, with the ability to influence engineering teams.
  • Strong technical documentation and design skills.

Desirable

  • Experience implementing security controls for AI or machine learning platforms.
  • Knowledge of cryptographic controls and key management.
  • Experience with Infrastructure as Code and policy-as-code tooling.
  • Familiarity with payment platforms or financial services environments.
  • Understanding of operational resilience frameworks and regulatory requirements affecting critical financial infrastructure.
  • Relevant cloud or security certifications (AWS Security Specialty, CISSP, CCSP or similar).

TECH STACK ⚙️

  • AWS – Cloud infrastructure and security controls.
  • Kubernetes – Container orchestration and workload security.
  • Terraform – Infrastructure as Code and security automation.
  • CI/CD tooling – Secure software delivery, build security and deployment governance.
  • Container security tooling – Image scanning, vulnerability management and runtime protection.
  • Identity & Access Management (IAM) – Least privilege, RBAC and privileged access controls.
  • Software Supply Chain Security – Dependency scanning, artefact signing, provenance and integrity controls.
  • Security monitoring & observability platforms – Detection, auditability and operational visibility.
  • AI governance and security controls – Supporting secure adoption of AI-enabled engineering capabilities.

INTERVIEW PROCESS ✍️

Stage 1: Screening Call with Talent Team

Stage 2: Kubernetes & Linux Interview

Stage 3: Cloud Security & Engineering Best Practices interview

We always aim to stick to the above process, however there may be occasions when an additional interview stage is needed for us to be sure we’re hiring the right fit for the role.

HIRING LOCATIONS📍

Here are the locations that we are looking to engage with contractors from. Please note, we are not looking to engage with contractors outside of these locations.

  • Austria
  • Bulgaria
  • Croatia
  • Cyprus
  • Estonia
  • Greece
  • Hungary
  • Italy
  • Latvia
  • Lithuania
  • Malta
  • Romania
  • Slovakia
  • Slovenia

All contractors start their first day in our office to collect the equipment needed to work remotely.

ABOUT FORM3 💭

Revolutionising the world of payments with our cloud-native, multi-cloud platform. For more information about Form3, check out the following pages:

What we do | Life at Form3 | Payments Cannot Fail Series | .Tech Podcast

OUR DEI&B COMMITMENT

We hire talented people from a variety of backgrounds and experiences and are committed to a work environment based on diversity, open-mindedness and curiosity. We’re united by our company values (we even created them together!) and we celebrate our unique differences.

Our employee lifecycle processes are designed to embrace equal opportunity and prevent discrimination against our people regardless of personal characteristics. It is our strong belief that the more inclusive and belonging we are as a business, the better our work will be.

As an inclusive employer, we guarantee to interview all neurodiverse and physically disabled applicants who meet the minimum criteria for this role. We also encourage candidates to notify us of any reasonable adjustments that may be required during the recruitment process. This includes providing job adverts in alternative, accessible formats or adjustments required at interview stage.

If you consider yourself to be neurodiverse or physically disabled under the UN definition of disability and would like to be considered under this scheme and/or require any reasonable adjustments please let us know by sending an email to careers@form3.tech clearly stating your consent for us to process this data.

For more information please refer to our Recruitment Data Policy.

Read the full description
Security EB IT-Dienstleistungen: IT-Security Manager BCM (m/w/d)

Develops and manages business continuity and information security management systems for a municipal government, ensuring operational resilience of critical business processes.

Senior Hybrid Posted 6 days ago We Work Remotely — Programming
What this role involves

Headquarters: Dresden, SACHSEN, 01069, Germany
URL: http://dresden.de

Wir sind ein Eigenbetrieb innerhalb der Stadtverwaltung Dresden mit einer komplexen IT- und Geschäftsprozesslandschaft. Zur Sicherstellung der Betriebsfähigkeit unserer kritischen Geschäftsprozesse suchen wir zum nächstmöglichen Zeitpunkt eine engagierte Persönlichkeit als # ***IT-Security Manager BCM (w/m/d)*** **Chiffre:                         EB17 04/2026** **Arbeitszeit:                 Vollzeit, 39 Wochenarbeitsstunden, unbefristet                  ** **Entgeltgruppe:           EG 10** ## Was wir bieten - ein attraktives, unbefristetes Anstellungsverhältnis mit einem interessanten und anspruchsvollen Aufgabengebiet - flexible Arbeitszeiten mit Home-Office-Option und eine familienfreundliche Ausrichtung - tarifliches Entgelt plus Jahressonderzahlung - 30 Tage Erholungsurlaub bei einer 5-Tage-Woche im Kalenderjahr - geringe bis keine Reisetätigkeit - umfangreiche Qualifizierungsangebote - zahlreiche Arbeitgeberleistungen (z. B. Jobticket, Jobradleasing, Gesundheitsleistungen, Altersvorsorge) - Möglichkeit des Bildungsurlaubs - eine strukturierte Einarbeitung sowie eine positive Arbeitsatmosphäre mit hilfsbereiten Kolleg\*innen ## Das erwartet Sie  **1.       Konzeption, Aufbau und kontinuierliche Weiterentwicklung der Managementsysteme zur Sicherstellung der Informationssicherheit und Compliance der LHD** - Konzeption, Aufbau, Betrieb und kontinuierliche Weiterentwicklung eines Business-Continuity-Management-Systems (BCMS) gemäß BSI-Standard 200-4 BCM - Identifikation und Bewertung von Risiken für Geschäftsprozesse und IT-Systeme - Durchführung von Business Impact Analysen (BIA) für kritische Geschäftsprozesse - Entwicklung und Pflege von Notfall- und Wiederanlaufplänen - Zusammenarbeit mit der ISMS-Sicherheitsorganisation der LHD - Mitwirkung bei der Durchführung von Risikoanalysen (Risikomanagement) - Erstellung und Aktualisierung von organisatorischen Regelungen, insbesondere Informationssicherheitsrichtlinien - Analyse und Dokumentation von Sicherheitsvorfällen (Detailanalyse komplexer, komponenten- und systemübergreifender, technischer Fehler Zustände, sowie die Ableitung von notwendigen Maßnahmen) - Mitwirkung bei der Konzeption, Erarbeitung und Durchführung von Sensibilisierungs- und Schulungsmaßnahmen zum Thema Informationssicherheit - Monitoring: Funktions- und Performanceüberwachung und Optimierung - Entwicklung und Erhebung von Kennzahlen / Key Performance Indicators (KPI) - Dokumentation der eingeführten IT-Sicherheits-Infrastruktur - Gemeinsame Erstellung und Pflege von Betriebs-, Einsatz- und Umstellungs-Handbüchern/Konzepten und Regelungen zum Einsatz der Systeme **2.     Mitarbeit in und Leitung von Projekten bei der Konzeption und Implementierung technischen und organisatorischen Maßnahmen in Bezug auf die Informationssicherheit** - Erstellung, Kontrolle und Weiterentwicklung von (verfahrensspezifischen) Informationssicherheitskonzepten - Mitwirkung an der Erstellung von Projektvereinbarungen, Vorhabenanmeldungen und anderer Dokumente zur Unterstützung interner Betriebsabläufen **3.       Mitwirkung bei Konzeption, Aufbau und Einrichtung von IT-Sicherheitssystemen (technisch/administrativ)** - Bereitstellung, Implementation (Installation und Konfiguration), Weiterentwicklung, Administration und Monitoring **4.        Systembetreuung IT-Sicherheitssysteme** - Softwarepflege/-wartung einschließlich Vertrag-/Lizensierungsregelungen - Sicherstellung laufender Betrieb, operative Aufgaben - Konfigurationsmanagement, Customizing (Anpassung/Parametrierung) - Unterstützung Helpdesk, Second-Level-Support, Ticketbearbeitung ** ** ## Das bringen Sie mit -  Diplom (FH), Bachelor (FH und Uni), Fachwirt (VWA, BA) auf dem Gebiet der Informatik, Wirtschaftsinformatik, IT-Forensik, IT-Sicherheit, Cyber Security oder vergleichbares Gebiet Sie sollten darüber hinaus - Neben den Erfahrungen und Kenntnissen im Fachbereich Informatik auch über ein - großes Interesse für und Sensibilität gegenüber dem Bereich IT-/Cyber-/Informations-Sicherheit verfügen - Berufserfahrung in den Gebieten Informationssicherheit wäre wünschenswert - gute Kenntnisse von ITK-Technologien und -Infrastrukturen besitzen - selbständig und gewissenhaft arbeiten, konzeptionell und analytisch denken können - kommunikationsfähig, sowie teamfähig sein und kundenorientiert arbeiten, sowie die Bereitschaft zur laufenden Fortbildung mitbringen - Einblicke in das Verwaltungsrecht sind von Vorteil - Bereitschaft zur Sicherheitsüberprüfung nach Sicherheitsüberprüfungsgesetz (SÜG) **Haben wir Ihren Nerv getroffen?** Wünschen Sie sich eine umfangreiche Einarbeitung in spannende Themen und ein gutes Team, welches Sie immer unterstützt? Dann erfüllen wir womöglich ihre Anforderungen und Sie unsere? …und freuen uns sehr auf Ihre Bewerbung. Bewerben Sie sich mit Ihren vollständigen Unterlagen über unser Online-Bewerberportal. Aus Sicherheitsgründen können nur Anhänge im PDF-Format angenommen werden. Bis zum Abschluss des Auswahlverfahrens werden Ihre personenbezogenen Daten unter Beachtung der EU-Datenschutzgrundverordnung (EU-DSGVO), des Sächsischen Datenschutzgesetzes (SächsDSG) und des Sächsischen Datenschutzdurchführungsgesetzes (SächsDSDG) in maschinenlesbarer Form im Personalmanagementsystem gespeichert und ausschließlich für den Zweck dieses Verfahrens verarbeitet und genutzt. Ihre persönlichen Daten werden vertraulich behandelt und nicht an Dritte weitergegeben. Die ausführlichen Datenschutzhinweise finden Sie unter: [www.dresden.de/stellenangeboten](http://www.dresden.de/stellenangeboten)

To apply: https://weworkremotely.com/remote-jobs/eb-it-dienstleistungen-it-security-manager-bcm-m-w-d

Read the full description