Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Toptal: Senior Security Compliance Consultant (SOC 2 & GRC Specialist)

Lead SOC 2 Type II audit readiness initiatives by conducting gap analyses, designing security controls, automating compliance workflows, and coordinating cross-functional teams toward audit completion.

Senior Remote Posted about 7 hours ago We Work Remotely — Programming
What this role involves

Headquarters:

Summary

We are seeking an elite, hands-on Senior Security Compliance Consultant (SOC 2 & GRC Specialist) to lead a critical, company-wide SOC 2 Type II audit readiness initiative. In this strategic engagement, you will perform comprehensive gap analyses, assess existing security controls, design robust compliance workflows, and drive cross-functional teams toward audit completion.

The ideal candidate brings a proven track record in GRC frameworks, control mapping, evidence automation, and policy development. Utilizing automated compliance platforms such as Sprinto, you will build repeatable compliance processes, validate technical controls, and ensure a seamless audit experience across the entire organization.

General Information (About the Client)

Our client is a fast-scaling, cloud-native technology platform committed to maintaining enterprise-grade trust, security, and data privacy. To support their rapid commercial growth and enterprise sales pipeline, they are establishing a formal, highly disciplined security governance model.

They operate a modern, cloud-first environment where compliance is treated not as a passive checklist, but as an active, automated operational advantage. By leveraging modern GRC platforms and fostering a security-conscious culture, they provide an empowering environment for compliance experts to drive real architectural and procedural improvements.

Tasks and Deliverables

SOC 2 Readiness & Gap Analysis: Conduct a thorough assessment of existing technical and operational security controls, pinpointing compliance gaps and building an actionable remediation roadmap.

Control Design & Implementation: Author, refine, and operationalize security controls, policies, and procedures aligned with SOC 2 Trust Services Criteria (TSC) and PCI DSS standards.

Automated Evidence Collection: Lead evidence-gathering workflows using automated GRC tooling (Sprinto), ensuring all technical artifacts, access logs, and policy attestations are validated and audit-ready.

PCI DSS Guidance: Provide expert advisory on maintaining PCI DSS alignment alongside SOC 2, ensuring overlapping control requirements are mapped efficiently to reduce operational drag.

Cross-Functional Coordination: Collaborate with engineering, DevOps, HR, and IT teams to embed compliance workflows into daily operations without slowing down feature execution.

Auditor Interface & Readiness: Serve as the primary liaison during the audit preparation phase, coordinating directly with external auditors to present evidence, resolve findings, and ensure a successful audit cycle.

Required Experience

SOC 2 Mastery: Proven track record of leading end-to-end SOC 2 readiness, gap remediation, and audit preparation initiatives for cloud-native or B2B SaaS companies.

GRC & PCI DSS Acumen: Deep familiarity with Governance, Risk, and Compliance (GRC) frameworks, risk assessment methodologies, and PCI DSS compliance requirements.

Tooling Proficiency (Sprinto): Direct, practical experience leveraging automated compliance and evidence-collection platforms, specifically Sprinto (or equivalent modern platforms like Vanta/Drata).

Policy & Control Mapping: Exceptional capability to author clear, enforceable security policies and translate abstract regulatory requirements into concrete engineering controls.

Cross-Functional Facilitation: Strong stakeholder management skills with a history of driving accountability across distributed engineering, product, and operations teams.

To apply: https://weworkremotely.com/remote-jobs/toptal-senior-security-compliance-consultant-soc-2-grc-specialist

Read the full description
Security Cyber Security Analyst(Remote) at TechBiz Global

Monitors security alerts, analyzes threats, responds to incidents, and manages endpoint protection for managed security service clients.

Junior Remote Posted about 7 hours ago RemoteFirstJobs Product
What this role involves

Description

At TechBiz Global, we are providing recruitment service to our TOP clients from our portfolio. We are currently seeking a Cyber Security Analyst to join one of our clients’ teams. If you’re looking for an exciting opportunity to grow in a innovative environment, this could be the perfect fit for you. We are seeking an enthusiastic and motivated individual to provide Managed Cyber Security Services to our valued customers. As a key member of the Optimization Engineering & Analytics team, you will be part of an integral and group that is dedicated to protecting system resources from cyber-attacks and other online threats that could have devastating consequences for millions of end users.

Successful candidates will demonstrate foundational Network Security and System Administration with advanced understanding across Endpoint Protection, Threat and Vulnerability Management, Security Automation, and Security Analysis.

Requirements

KEY RESPONSIBILITIES:

• Provide client-facing support of our managed security services, including adherence and development of processes and operational frameworks.

• Ability to work assigned shift, covering alternate shifts as needed.

• Analyze, escalate, and assist in the remediation of critical information security incidents.

• Assist with the integration, deployment, on-boarding and management of endpoint defense and attack surface managed customers.

• Perform real-time alert monitoring and analyze security event data from network and endpoint environments, peer analysts, customer platforms, and other data sources.

• Provide Incident Response (IR) support and assist customers remediation guidance.

• Review procedures relating to Cyber threat intelligence, monitoring, incident response, attack surface reduction, and design automated actions to accelerate the triage, validation, eradication, and remediation of security incidents.

• Leverage expertise in leading security operations tools and industry standard scripting languages to effectively write playbooks in security orchestration, automation, and response.

• Collaborate with team members to create, maintain, and manage a library of automated playbooks for common information security threats and customize these plans for client specific environments.

• Actively identify areas of improvement within the processes of the Security Operations Center and Cyber Incident Response with the goal of decreasing response times, increasing effectiveness, eliminating waste, and streamlining security operations.

• Integrate new security platform functionality with existing systems and automated processes as threats and controls evolve.

• Create well documented and clearly articulated code/ scripts, process, and service documentation.

• Perform health checks and optimization activities on client security technologies or systems.

• Determine information security risk and facilitate remediation actions of identified vulnerabilities and security risk across the enterprise.

• Other, as needed.

MINIMUM QUALIFICATIONS

• 4+ years of IT experience.

• 3+ years of Cyber Security experience.

• Advanced operating systems experience, in 2 or more of the following, Microsoft, MacOS, Linux.

• General network security and troubleshooting knowledge.

• Foundational scripting knowledge preferred in any of the following: PowerShell, Python, Bash.

• In-depth knowledge of TCP/IP, UDP, DNS, FTP, SSH, SSL/TLS, and HTTP Protocols, network analysis, and network/security applications.

• Good knowledge of common malware threats and attack methodologies.

• Passionate about emerging threats and security tools/technologies.

• Malware and Threat analysis.

• Incident Management.

• Able to work under general to minimal supervision.

PREFERRED QUALIFICATIONS

• 3+ years of experience with endpoint security tools (Trellix ePO, Trellix ENS, Trellix EDR, Trellix HX, CrowdStrike, Microsoft Defender, Microsoft ATP, SentinelOne).

• 3+ years managing security endpoints.

• 3+ years of experience with SIEM management and tuning in one or more of the following: LogScale formerly Humio, Splunk, Trellix Helix, Trellix ESM, Azure Sentinel, Elastic SIEM, Chronical, or Devo.

• Experience with Windows patch management tools (Automox, SCCM, SolarWinds, GFI Languard, etc.) a plus.

• Experience creating detection rules in a one ore more SIEM technologies

• Certifications a plus: CEH, CRISC, CISA, CGEIT, CISSP, CIPP, GMON, GHIA, GCIH.

• Bachelor’s Degree (Math, CS, and Engineering), preferred.

• Excellent knowledge of security methodologies, processes (i.e., Cyber Kill Chain/Diamond Models, and the MITRE ATT&CK framework).

Read the full description
Security Sr SOC Analyst at BeyondTrust

Monitors and investigates security alerts across SIEM/EDR/CSPM platforms, responds to incidents, and uses AI-driven tools to enhance detection and triage workflows.

Senior Posted about 9 hours ago RemoteFirstJobs Product
What this role involves

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

BeyondTrust is a global leader in privileged access management. Our products provide remote access and privileged control capabilities that are deployed across thousands of enterprise environments worldwide. That makes us a high-value target. Nation-state actors, ransomware operators, and sophisticated threat groups actively target companies like ours—not just to compromise our corporate environment, but to reach the customers who trust our software to protect their most sensitive systems. A compromise of BeyondTrust is a compromise of the privileged access layer inside our customers’ networks. We take that responsibility seriously.

As a SOC Analyst on our Cyber Defense Operations team, you will serve as a front-line defender responsible for protecting both BeyondTrust’s enterprise infrastructure and the integrity of the products our customers depend on. You will monitor, investigate, and respond to security events in an environment where the stakes are real and the adversaries are capable. You will work alongside experienced threat hunters, incident responders, and detection engineers in a collaborative team that values sharp analytical thinking over checkbox compliance.

This team is building toward an AI-augmented operating model. You will be expected to use AI-driven tools in your daily work and to contribute to how we integrate these capabilities into our detection, triage, and response workflows. We are not looking for people who are waiting to be told what to do—we are looking for people who want to build something.

What You’ll Do

Alert Triage & Monitoring

  • Monitor and triage security alerts across SIEM, EDR, and CSPM platforms covering both corporate and product environments.
  • Investigate alerts to determine scope, severity, and whether escalation is warranted.
  • Leverage AI-assisted triage and enrichment tools to accelerate analysis and reduce mean time to detect.
  • Classify, document, and track alerts through the full lifecycle using ticketing and case management systems.

Incident Response & Investigation

  • Participate in or lead incident response engagements from detection through remediation, including evidence collection, forensic analysis, root cause determination, and stakeholder communication.
  • Conduct investigations across SIEM, EDR, CSPM, and cloud-native log sources including identity provider logs, cloud audit trails, and network flow data—spanning both corporate and product infrastructure.
  • Execute established IR runbooks across identity, endpoint, cloud, and email investigation workflows.
  • Manage or assist with evidence handling, forensic artifact collection, and chain-of-custody procedures.
  • Produce clear, decision-ready incident summaries and post-incident reports for both technical and leadership audiences.

Detection Engineering & Threat Intelligence

  • Contribute to the design, implementation, and tuning of detection rules across SIEM and EDR platforms, with a focus on reducing false positives and closing coverage gaps.
  • Translate threat intelligence (CVE advisories, CISA alerts, vendor bulletins, open-source feeds) into actionable detection content, with particular attention to threats targeting privileged access tooling and supply chain attack vectors.
  • Help maintain and evolve detection coverage mapped to MITRE ATT&CK.
  • Partner with threat hunting peers to validate detection logic through hypothesis-driven hunts.

AI Integration & Automation

  • Use AI-driven tools for alert triage, enrichment, and investigation as a standard part of daily operations.
  • Contribute to the evaluation, integration, and optimization of AI and automation capabilities across the team’s workflows.
  • Assist in designing prompts, agent workflows, or LLM-based pipelines that augment analyst capabilities and reduce manual effort.
  • Partner with engineering teams to improve log ingestion, data quality, and tool integrations.

Operational Excellence

  • Maintain daily operational notes and shift handoff documentation.
  • Contribute to and refine IR runbooks, playbooks, and standard operating procedures.
  • Participate in on-call rotation for after-hours incident escalation.
  • Track and report on operational metrics (MTTD, MTTR, MTTC, false positive rate) and identify improvement opportunities.
  • Participate in tabletop exercises, purple team activities, and post-incident reviews.

What You’ll Bring

  • 2+ years of experience in a SOC, security operations, or incident response role.
  • Understanding of common attack frameworks (MITRE ATT&CK), network protocols, and endpoint behavior.
  • Experience with at least one SIEM platform and familiarity with writing search or detection queries.
  • Familiarity with EDR platforms and cloud environments (IaaS preferred).
  • Comfort using AI systems (e.g., LLM-based assistants, copilots, or AI-driven analysis tools) as part of security workflows.
  • Strong written communication skills; able to document findings clearly and concisely for both technical and non-technical audiences.

Nice To Have

  • Experience leading or co-leading complex incident response engagements from triage through remediation.
  • Experience with identity and access management platforms and cloud security posture management tools.
  • Scripting and automation skills (Python, PowerShell, or equivalent) applied to security workflows.
  • Familiarity with SOAR platforms or orchestration tools for automated response and enrichment.
  • Experience designing or implementing AI agent architectures, LLM-based automation pipelines, or prompt engineering for security use cases.
  • Experience building or contributing to threat intelligence programs or detection-as-code pipelines.
  • Understanding of the privileged access management landscape and the threat actors that target it.
  • Track record of evaluating and adopting emerging technologies in a production security environment.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

#LI-DF1

Read the full description
Security IT Security Operations Analyst

Monitors security events, responds to incidents, and maintains security infrastructure for enterprise systems.

Mid Posted about 21 hours ago Himalayas
What this role involves
Our client is an European company leading the development and production of responsible packaging solutions for a wide variety of industries.
Read the full description
Security Cyber Security Architect

Designs and implements comprehensive cybersecurity infrastructure and strategies for enterprise environments.

Senior Remote Posted about 23 hours ago Himalayas
What this role involves
Location: Remote UK, United KingdomThales is a global technology leader with more than 83,000 employees on five continents.
Read the full description
Security DevSecOps Engineer - Clearance Required

DevSecOps engineer integrates security practices into development and deployment pipelines for Army contracting systems.

Mid Posted 2 days ago Himalayas
What this role involves
OverviewLMI is seeking a highly skilled DevSecOps Engineer to support Army Acquisition, Training, and Readiness (AT&R) in the sustainment and enhancement of the Army Contract Writing System (ACWS).
Read the full description
Security Privacy & Security Enterprise Engagement Officer

Partners with enterprise stakeholders to translate privacy, security, and AI compliance requirements into operational controls and governance processes.

Mid Posted 2 days ago Himalayas
What this role involves
Position Purpose: Serves as a partner and advisor between enterprise stakeholders and Enterprise Privacy & Security Risk Management (EPSRM), ensuring regulatory and contractual privacy, security, AI, and business continuity requirements are translated into practical operational controls, processes, and governance activities.
Read the full description
Security Application Security Engineer II - Contract ( 6 months ) at Bugcrowd

Triages and validates security vulnerability submissions from researchers, communicates with clients and researchers, and escalates critical security incidents for bug bounty programs.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security Application Security Engineer II - Contract ( 6 months ) at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates with clients and security teams on bug bounty programs.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security Principal Security Engineer, Orchestration and Automation

Builds automation, orchestration, and AI-driven detection and response capabilities for the organization's security operations.

Lead Posted 2 days ago Himalayas
What this role involves
Cyber Detection & Response Automation EngineerThe Cyber Detection & Response Automation Engineer is responsible for building the automation, orchestration, and AI-driven capabilities that power the organization's detection and response function.
Read the full description
Security SOC Engineer (Incident Response)

Monitors security alerts, investigates incidents, and responds to threats within the SOC environment.

Mid Posted 3 days ago Himalayas
What this role involves
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users.
Read the full description
Security CyberSecurity Analyst at Avertium

Monitor and respond to security alerts, provide technical guidance to clients, manage vulnerabilities, and maintain security infrastructure across applications and infrastructure.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique “Assess, Design, Protect” methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network.  The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives.  The CS Analyst will provide security analytics and assistance with security support requests.

Responsibilities:

  • Monitor, respond to, and analyze SIEM alerts from monitoring tools.
  • Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products.  Handles daily incidents; monitors, tracks, analyzes and records.
  • Work with vendors, outside consultants, and other third parties to improve information security within the organization.
  • Responds to security related tickets escalated from clients, and works collaboratively with the client to assist in resolving security events.
  • Work with other IT professionals to resolve fast moving vulnerabilities such as spam, virus, spyware and malware.
  • Monitor security vulnerability information from vendors and third parties.
  • Create Weekly and Monthly Status Reports, including daily technical task reports and contract deliverables.

Qualifications for Success:

  • Strong written, verbal and non-verbal communication skills, especially conveying complex information in an understandable manner.
  • CISSP, CISA or GIAC certification is a plus.
  • A minimum of 2-4 years of experience working with Microsoft Active Directory.
  • Experience in managing an organization’s PCI, HIPAA, or SSAE16 certification is preferred.
  • Analyze and resolve complex technical and business problems.
  • Must have proficient knowledge with three or more of the following technologies:  Application / stateful / UTM firewalls; SIEM; DLP; Web content filtering; Web application firewalls (WAF); Vulnerability scanning and penetration testing; IPS/IDS; Security Operations Center operations; Wireless Networking; UNIX, AIX & Solaris, Linux, Windows Server Operating Systems; Endpoint and Malware
  • Knowledge with NIST, FISMA, DIACAP.
  • Knowledge of Windows 2003-12 server platforms.
  • Knowledge of VMware and VM server platforms.
  • Knowledge of UNIX server platforms.
  • Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, Windows.
  • Web and mail logged events.
  • Ability to analyze IANA assigned ports (well known, registered, dynamic and private ports).
  • Ability to troubleshoot common network devices, network, vulnerabilities and network attack patterns.
  • Ability to troubleshoot Windows Event IDs.
  • Interact with all levels of management.
  • Make decisions based on many variables.
  • Manage multiple tasks/projects simultaneously.
  • Minimum of Bachelor’s Degree in computer science, telecommunications management, electrical engineering, or a related field or have 4 years of experience.
  • Advanced network and systems certifications such as CCNP, CCNA and CISSP, are preferred.
  • Other industry certifications such as ITIL, Microsoft, Juniper and Checkpoint are a plus.
  • #LI-CS1

In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.

Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security engineer, application security at WRITER

Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.

Mid Hybrid Posted 3 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description
Security Security engineer, application security (UK) at WRITER

Builds security foundations for enterprise AI systems by conducting threat modeling, designing secure architectures, and embedding security controls across the platform.

Mid Hybrid Posted 3 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our London office, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • 4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

🍩 Benefits & perks (UK full-time employees):

  • Generous PTO, plus company holidays

  • Comprehensive medical and dental insurance

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Competitive pension scheme and company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation and company stock options

Read the full description
Security Cybersecurity Director at Business Wire

Directs cybersecurity strategy, GRC program, and security infrastructure while overseeing risk management, compliance, and cross-functional security initiatives across the organization.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

Business Wire, a Berkshire Hathaway company, is the global market leader in press release distribution and regulatory disclosure. We are on a mission to redefine how organizations connect with their audiences - and that’s just the beginning!

Organizations, large and small, depend on us to accurately publicize market-moving news and multimedia, and generate social engagements that develop interactions with their target audiences.

About the Role

The Cybersecurity Director is responsible for providing strategic leadership across Business Wire’s cybersecurity function, providing strategy, overseeing security architecture and infrastructure, guiding cybersecurity-related risk decisions across the organization, and advancing and managing a comprehensive Governance, Risk, and Compliance (GRC) program.

This role works collaboratively with all areas of the business to ensure that we maintain a robust and highly effective Information Security program for our existing solutions while also supporting the buildout of new client solutions hosted in our data centers and the cloud. This role provides oversight of our external cyber defense partner and drives efforts in cloud security, application security, identity and access strategies, Zero Trust, vulnerability management, email security, data protection, privacy requirements, and emerging technology risks—including AI.

This role is additionally responsible for establishing a robust security governance framework, ensuring compliance with internal and external audit requirements, fostering a security-first culture across the organization, and collaborating with cross-functional teams to integrate risk management practices into all business operations.

What You’ll Do

  • Develop and maintain cybersecurity and GRC strategy and long-term roadmap, with the goal of enhancing overall strategy in alignment with business objectives.
  • Make continuous improvements to our security strategies to protect critical assets and data.
  • Provide strategic decision-making and problem-solving to navigate complex security and regulatory landscapes.
  • Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits, client assessments, and regulatory standards such as PCI DSS, SOC 2, and ISO 27001; ensure that our company meets all internal and external audit requirements.
  • Conduct regular risk assessments and periodic penetration testing and vulnerability assessments to identify and mitigate potential threats to the organization’s infrastructure, applications, and data.
  • Manage the timely creation and dissemination of security-related communications including security awareness and training announcements, security compliance policies and processes, security alerts, and event messaging.
  • Provide oversight in maintaining a successful collaborative relationship with our external cyber defense partner, including evaluation of service delivery performance and in alignment with BW’s cybersecurity priorities.
  • Provide strategic leadership during cybersecurity incidents, coordinating with IT, Legal, HR, Privacy, Communications, and other stakeholders, and act as executive-level point-of-contact.
  • Offer senior-level guidance in developing and improving cybersecurity governance programs, policies, standards, and secure architecture guidelines.
  • Oversee enterprise cybersecurity risk assessments and ensure corrective actions are prioritized and implemented effectively; provide direction for privacy and data protection initiatives.
  • Provide leadership, guidance, and mentorship to cybersecurity and GRC team members, drive strong performance across all initiatives and support individual and team development.
  • Act as a trusted advisor to senior leadership on cybersecurity risk, architecture decisions, and strategic measures.
  • Use metrics to evaluate and track effectiveness of security, governance, and compliance initiatives.
  • Leverage exceptional communication skills to translate technical requirements into actionable business solutions.

What You’ll Need

  • Ability to work in the San Francisco office an average of twice a week.
  • Bachelor’s or Master’s degree in Computer Science, Information Security, or a related field.
  • 10+ years of relevant industry experience in Information Security, with 5+ years of managerial and strategic leadership experience.
  • Knowledge of data protection, privacy regulations, and cybersecurity governance frameworks.
  • Expertise in cloud security, including AWS and Azure, as well as cybersecurity architecture, application security, identity management, and Zero Trust.
  • Experience in data encryption, access controls, code reviews, and secure coding practices.
  • Expertise in building and implementing GRC frameworks and risk management processes.
  • Familiarity with regulatory compliance requirements, including PCI DSS, SOC 2, and ISO 27001.
  • Certified Information Systems Security Professional (CISSP) or equivalent certification is a plus.
  • Strong leadership and team-building skills.
  • Excellent written and verbal communication skills with external and internal stakeholders and executives, and the ability to simplify complex cybersecurity topics.  Ability to deliver constructive & encouraging feedback.
  • Proactive, organized, analytical, detail-oriented, and persistent.
  • Experience managing and overseeing external security service providers or technology partners.

Business Wire will not sponsor a new applicant for employment authorization for this position.

What We Offer

The base salary range for this position is $230K to $245K/year.  Offered salary will be determined by several factors, including but not limited to: applicant’s education, experience, knowledge, skills and abilities, as well as internal equity and alignment with geographic market data.  Business Wire reserves the right to modify this salary range at any time.

Business Wire’s total rewards include:

  • Ability to work remotely
  • Excellent health benefits that begin on your first day of employment
  • $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
  • 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
  • PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!

A pre-employment background check will be required after the acceptance of an offer. Business Wire is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Business Wire will also consider for employment qualified applicants with arrest and conviction records.

Read the full description
Security CyberSecurity Analyst at Avertium

CyberSecurity Analyst monitors SIEM alerts, responds to security incidents, provides technical guidance to clients, and maintains security measures across applications, web, and infrastructure.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique “Assess, Design, Protect” methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network.  The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives.  The CS Analyst will provide security analytics and assistance with security support requests.

Responsibilities:

  • Monitor, respond to, and analyze SIEM alerts from monitoring tools.
  • Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products.  Handles daily incidents; monitors, tracks, analyzes and records.
  • Work with vendors, outside consultants, and other third parties to improve information security within the organization.
  • Responds to security related tickets escalated from clients, and works collaboratively with the client to assist in resolving security events.
  • Work with other IT professionals to resolve fast moving vulnerabilities such as spam, virus, spyware and malware.
  • Monitor security vulnerability information from vendors and third parties.
  • Create Weekly and Monthly Status Reports, including daily technical task reports and contract deliverables.

Qualifications for Success:

  • Strong written, verbal and non-verbal communication skills, especially conveying complex information in an understandable manner.
  • CISSP, CISA or GIAC certification is a plus.
  • A minimum of 2-4 years of experience working with Microsoft Active Directory.
  • Experience in managing an organization’s PCI, HIPAA, or SSAE16 certification is preferred.
  • Analyze and resolve complex technical and business problems.
  • Must have proficient knowledge with three or more of the following technologies:  Application / stateful / UTM firewalls; SIEM; DLP; Web content filtering; Web application firewalls (WAF); Vulnerability scanning and penetration testing; IPS/IDS; Security Operations Center operations; Wireless Networking; UNIX, AIX & Solaris, Linux, Windows Server Operating Systems; Endpoint and Malware
  • Knowledge with NIST, FISMA, DIACAP.
  • Knowledge of Windows 2003-12 server platforms.
  • Knowledge of VMware and VM server platforms.
  • Knowledge of UNIX server platforms.
  • Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, Windows.
  • Web and mail logged events.
  • Ability to analyze IANA assigned ports (well known, registered, dynamic and private ports).
  • Ability to troubleshoot common network devices, network, vulnerabilities and network attack patterns.
  • Ability to troubleshoot Windows Event IDs.
  • Interact with all levels of management.
  • Make decisions based on many variables.
  • Manage multiple tasks/projects simultaneously.
  • Minimum of Bachelor’s Degree in computer science, telecommunications management, electrical engineering, or a related field or have 4 years of experience.
  • Advanced network and systems certifications such as CCNP, CCNA and CISSP, are preferred.
  • Other industry certifications such as ITIL, Microsoft, Juniper and Checkpoint are a plus.
  • #LI-CS1

In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.

Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security engineer, application security at WRITER

Builds application security foundations for enterprise AI systems, conducting threat modeling, designing secure architectures, and embedding security controls across the platform.

Mid Hybrid Posted 3 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description
Security Security engineer, application security (UK) at WRITER

Security engineer builds and maintains application security controls, threat models AI systems, and embeds security practices across the enterprise AI platform.

Mid Hybrid Posted 3 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our London office, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • 4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

🍩 Benefits & perks (UK full-time employees):

  • Generous PTO, plus company holidays

  • Comprehensive medical and dental insurance

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Competitive pension scheme and company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation and company stock options

Read the full description
Security Staff Application Security Engineer

Designs and implements application security strategies, conducts threat assessments, and leads security architecture initiatives to protect company systems and data.

Lead Posted 3 days ago Jobicy AI
What this role involves
Meet Upside: We created Upside to transform brick-and-mortar commerce. Our technology uses the sophistication of online retail—profit measurement, attribution, and incrementality—to provide users with more value on their everyday purchases...
Read the full description
Security Head of Financial Crimes

Leads financial crimes prevention and compliance strategy for an AI-native banking platform serving business owners.

Exec Posted 3 days ago Jobicy AI
What this role involves
Flex is building the AI-native private bank for business owners. We’re re-architecting the entire financial system for entrepreneurs—from the first dollar a business earns to how that value compounds, moves,...
Read the full description