Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. đ
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
Designs, implements, and maintains cloud security infrastructure and protocols to protect systems and data.
Monitors security events, responds to incidents, and maintains security infrastructure for enterprise systems.
DevSecOps engineer integrates security practices into development and deployment pipelines for Army contracting systems.
Partners with enterprise stakeholders to translate privacy, security, and AI compliance requirements into operational controls and governance processes.
Triages and validates security vulnerability submissions from researchers, communicates with clients and researchers, and escalates critical security incidents for bug bounty programs.
We are Bugcrowd. Since 2012, weâve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platformâ˘. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch⢠technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the worldâs biggest companiesâ bug bounty programs. Here are just a few of the reasons why we are the best:
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowdâs clients or researchers when additional information is required. ASEs also handle Incident Response â escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Culture
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowdâs Privacy Policy, which you may review here:Â https://www.bugcrowd.com/privacy.
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:Â https://www.bugcrowd.com/about/careers/
Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates with clients and security teams on bug bounty programs.
We are Bugcrowd. Since 2012, weâve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platformâ˘. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch⢠technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the worldâs biggest companiesâ bug bounty programs. Here are just a few of the reasons why we are the best:
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowdâs clients or researchers when additional information is required. ASEs also handle Incident Response â escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Culture
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowdâs Privacy Policy, which you may review here:Â https://www.bugcrowd.com/privacy.
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:Â https://www.bugcrowd.com/about/careers/
Monitors security alerts, investigates incidents, and responds to threats within the SOC environment.
Monitor and respond to security alerts, provide technical guidance to clients, manage vulnerabilities, and maintain security infrastructure across applications and infrastructure.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers.âŻOur unique âAssess, Design, Protectâ methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. Thatâs why customers trust Avertium to deliver better security, improved compliance, and greater ROI.
The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network. The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives. The CS Analyst will provide security analytics and assistance with security support requests.
In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.
Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (US Full-time employees)
Generous PTO, plus company holidays
Medical, dental, and vision coverage for you and your family
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Flexible spending account and dependent FSA options
Health savings account for eligible plans with company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation, company stock options and 401k
WRITER is an equal-opportunity employer and is committed to diversity. We donât make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
By submitting your application on the application page, you acknowledge and agree to WRITERâs Global Candidate Privacy Notice.
Builds security foundations for enterprise AI systems by conducting threat modeling, designing secure architectures, and embedding security controls across the platform.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our London office, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (UK full-time employees):
Generous PTO, plus company holidays
Comprehensive medical and dental insurance
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Competitive pension scheme and company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation and company stock options
CyberSecurity Analyst monitors SIEM alerts, responds to security incidents, provides technical guidance to clients, and maintains security measures across applications, web, and infrastructure.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers.âŻOur unique âAssess, Design, Protectâ methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. Thatâs why customers trust Avertium to deliver better security, improved compliance, and greater ROI.
The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network. The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives. The CS Analyst will provide security analytics and assistance with security support requests.
In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.
Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Builds application security foundations for enterprise AI systems, conducting threat modeling, designing secure architectures, and embedding security controls across the platform.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (US Full-time employees)
Generous PTO, plus company holidays
Medical, dental, and vision coverage for you and your family
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Flexible spending account and dependent FSA options
Health savings account for eligible plans with company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation, company stock options and 401k
WRITER is an equal-opportunity employer and is committed to diversity. We donât make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
By submitting your application on the application page, you acknowledge and agree to WRITERâs Global Candidate Privacy Notice.
Security engineer builds and maintains application security controls, threat models AI systems, and embeds security practices across the enterprise AI platform.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our London office, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (UK full-time employees):
Generous PTO, plus company holidays
Comprehensive medical and dental insurance
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Competitive pension scheme and company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation and company stock options
Analyzes and manages security threats and vulnerabilities using the HackerOne platform and community of security researchers.
Develops and implements security measures to protect applications from vulnerabilities and threats.
Manages compliance with security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS), maintains internal controls, and collaborates across teams to ensure regulatory adherence.
Headquarters: Remote - United States
Vercel is the agentic infrastructure company. We free people and agents to ship whatâs next.
For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.
Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.
We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether youâre building our products, supporting our customers, growing our community, or shaping our story, youâll help define what comes next.
We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.
You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).
Think you may not have all the skills and are hesitant to apply? There is no âperfectâ candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.
If youâre based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.
The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Â
To apply: https://weworkremotely.com/remote-jobs/vercel-grc-analyst
Analyzes Microsoft Sentinel security data to provide advisory guidance, interprets incidents and trends, and coaches customers on improving their security posture.
As one of Microsoftâs most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovationâsupported by a culture that values craftsmanship, open collaboration, and technical expertise. If youâre looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.
Spyglass is Quisitiveâs Security-as-a-Service offering â a modern, insight-driven approach to managed security that goes beyond alerts and tickets. In this role, youâll help customers turn Microsoft Sentinel insights into better decisions and measurable risk reduction.
This is a remote position and can be based anywhere in the continental US.
The Microsoft Sentinel Security Consultant is a customer-facing, advisory role focused on translating Microsoft Sentinel telemetry into clear, actionable security guidance. This is not a traditional SOC role. Instead, itâs designed for professionals who enjoy analyzing patterns, explaining security findings, and coaching customers on how to improve their security posture over time.
Youâll work closely with Spyglass Security Coaches, SecOps teams, and Customer Success Managers to help customers understand what Sentinel is telling them, why it matters, and what to do next.
â
US Citizens, Green Card holders and those authorized to work in the US are encouraged to apply. We are unable to offer sponsorship at this time.
About Quisitive â
With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clientsâ businesses and achieve remarkable business outcomes. â
Azure Security Consultant designs, implements, and optimizes Microsoft security solutions including identity, endpoint protection, and compliance across cloud environments for enterprise clients.
As one of Microsoftâs most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovationâsupported by a culture that values craftsmanship, open collaboration, and technical expertise. If youâre looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.
Weâre looking for an Azure Security Consultant who enjoys solving complex challenges, working directly with clients, and staying current with Microsoftâs rapidly evolving security ecosystem. This role is ideal for someone who combines technical expertise with a consultative mindset and wants to make a meaningful impact on customer environments.
This is a remote position and can be based anywhere in the United States. Prefer Central or Eastern time zones.
As an Azure Security Consultant, youâll work with clients and fellow Quisitive consultants to design, implement, and optimize Microsoft security solutions across cloud, identity, endpoint, and data protection platforms.
Weâre seeking someone who is passionate about technology, enjoys working with customers, and thrives in a collaborative consulting environment.
âUS Citizens and those authorized to work in the US are encouraged to apply. We are unable to offer sponsorship at this time.
About Quisitive â
âWith significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clientsâ businesses and achieve remarkable business outcomes. â
Security advisor who coaches clients on improving security posture through reviews, roadmap planning, and actionable recommendations aligned with business goals.
As one of Microsoftâs most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovationâsupported by a culture that values craftsmanship, open collaboration, and technical expertise. If youâre looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.
The Security Coach is a client-facing security advisor responsible for helping customers improve their security posture through recurring coaching, tactical deep-dives, roadmap planning, and practical guidance. In this role, you will partner closely with customers, Quisitive MDR/SecOps teams, Customer Success, and technical consultants to translate security insights, Microsoft telemetry, compliance requirements, and threat trends into clear, actionable recommendations.
This role supports Quisitiveâs Spyglass managed security service offering by helping customers understand their current security state, prioritize improvements, and drive adoption of Microsoft security capabilities in a way that aligns with their business goals, risk profile, licensing, and operational needs.
As Microsoft continues to expand AI-powered capabilities across the security and productivity landscape, this role will also help customers understand emerging AI security and governance considerations related to Microsoft Copilot, AI-enabled workloads, and agent-based technologies. While AI security is not the primary focus of the role, the Security Coach will help customers balance innovation, security, compliance, and risk as they adopt these solutions.
Security Coaches are a critical connection point between our customers, Quisitive security teams, and the Microsoft security ecosystem. You will help customers move from insight to action by turning telemetry, threat trends, compliance needs, and technical findings into practical steps that improve security outcomes over time.
This is a role for someone who enjoys being both strategic and hands-on, someone who can lead customer conversations, interpret complex security data, build trust with stakeholders, and help customers make meaningful progress in protecting their business.
As our customers increasingly adopt Microsoft Copilot, AI-powered workloads, and agent-based technologies, you will also help them navigate emerging security and governance considerations while building your expertise in Microsoft Agent 365 and the evolving AI security landscape.
â
About Quisitive â
âWith significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clientsâ businesses and achieve remarkable business outcomes. â
Manages FedRAMP compliance requirements, evidence collection, and security control implementation across technical teams while building compliance-as-code capabilities.
Abnormal AI is looking for a Federal Security and Compliance Analyst who wants to help build how modern federal compliance operates inside a fast-moving cybersecurity company.
You will work at the intersection of security engineering, cloud operations, security, and federal compliance, helping Abnormal Gov scale its FedRAMP High/Class D security and compliance program. You will own security requirement implementation and evidence, work directly with technical teams to drive risk and remediation to closure, and help build our compliance as code capabilities in alignment with FedRAMP 20x.
Youâll have meaningful ownership early, with the opportunity to improve processes rather than simply inherit them. The strongest candidate will be technically curious, highly organized, comfortable navigating ambiguity, and motivated by making compliance more accurate, automated, measurable, and operationally useful.
.
#LI-PP1
Actual compensation will be determined based on several non-discriminatory factors including skills, experience, qualifications, and geographic location.
In addition to base salary, this role may be eligible for bonus or incentive compensation, equity, and a comprehensive benefits package.
Base salary range:
$114,800â$173,250 USD
A note on AI in our process: Abnormal AI uses AI-assisted tools to help our recruiting team prepare for candidate interviews. These tools analyze resume content and role requirements to suggest interview questions and areas for the interviewer to explore.They do not make hiring decisions or screen candidates automatically. Every decision about a candidacy is made by a person. Further, if your application is successful and Abnormal AI makes a conditional offer of employment, we will carry out pre-employment checks which must be successfully completed to progress to a final offer. All processes and pre-employment checks are in line with prevailing legislation and Abnormal AIâs policies relevant to our security and privacy standards.
Abnormal AI is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status or other characteristics protected by law. For our EEO policy statement please click here. If you would like more information on your EEO rights under the law, please click here.