Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Cyber Security Engineer II

Designs, implements, and maintains cybersecurity systems and infrastructure to protect organizational assets and data from security threats.

Mid Posted about 18 hours ago Jobicy AI
What this role involves
About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just...
Read the full description
Security Security & Compliance Manager at Relocity, Inc.

Manages SOC 2 Type II compliance, leads ISO 27001 certification, and oversees security controls, risk assessments, and regulatory framework implementation across the organization.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

What Relocity is Doing

Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.

What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company’s primary advisor on security, privacy, and compliance strategy.

Risk & Governance

  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership

  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness

  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement

  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success

  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

How We Support You and Work-Life Balance…

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.

#LI-Remote

#LI-AC2

Read the full description
Security Security & Compliance Manager at Relocity, Inc.

Maintains SOC 2 Type II compliance, leads ISO 27001 certification, and manages security controls and risk governance across the organization.

Mid Posted 1 day ago RemoteFirstJobs Product
What this role involves

What Relocity is Doing

Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.

What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company’s primary advisor on security, privacy, and compliance strategy.

Risk & Governance

  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership

  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness

  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement

  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success

  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

How We Support You and Work-Life Balance…

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.

#LI-Remote

#LI-AC2

Read the full description
Security Security Engineer, Cloud

Designs, implements, and maintains cloud security infrastructure and protocols to protect systems and data.

Mid Remote Posted 3 days ago Jobicy AI
What this role involves
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built....
Read the full description
Security IT Security Operations Analyst

Monitors security events, responds to incidents, and maintains security infrastructure for enterprise systems.

Mid Posted 4 days ago Himalayas
What this role involves
Our client is an European company leading the development and production of responsible packaging solutions for a wide variety of industries.
Read the full description
Security DevSecOps Engineer - Clearance Required

DevSecOps engineer integrates security practices into development and deployment pipelines for Army contracting systems.

Mid Posted 5 days ago Himalayas
What this role involves
OverviewLMI is seeking a highly skilled DevSecOps Engineer to support Army Acquisition, Training, and Readiness (AT&R) in the sustainment and enhancement of the Army Contract Writing System (ACWS).
Read the full description
Security Privacy & Security Enterprise Engagement Officer

Partners with enterprise stakeholders to translate privacy, security, and AI compliance requirements into operational controls and governance processes.

Mid Posted 5 days ago Himalayas
What this role involves
Position Purpose: Serves as a partner and advisor between enterprise stakeholders and Enterprise Privacy & Security Risk Management (EPSRM), ensuring regulatory and contractual privacy, security, AI, and business continuity requirements are translated into practical operational controls, processes, and governance activities.
Read the full description
Security Application Security Engineer II - Contract ( 6 months ) at Bugcrowd

Triages and validates security vulnerability submissions from researchers, communicates with clients and researchers, and escalates critical security incidents for bug bounty programs.

Mid Posted 5 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security Application Security Engineer II - Contract ( 6 months ) at Bugcrowd

Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates with clients and security teams on bug bounty programs.

Mid Posted 5 days ago RemoteFirstJobs Product
What this role involves

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary

At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the world’s biggest companies’ bug bounty programs. Here are just a few of the reasons why we are the best:

  • A tenure at Bugcrowd often means you have worked on not only one company’s security program but potentially on hundreds.
  • As an ASE at Bugcrowd you will be exposed to the Internet’s best security researchers and their cutting-edge security testing methodologies. Our ASEs quickly become technically fluent in obscure/complex XSS, SQLi, XXE, IDOR, SSTI, SSRF, and many other vulnerability types. There is no other organization that offers the learning opportunity that Bugcrowd does.
  • You will be exposed to things outside of your comfort zone. We routinely run security programs for cars, IoT devices, embedded systems, mobile applications, and more!
  • We have an awesome team and tons of perks. We’ve even been selected as one of “The 10 Coolest Security Startups Of 2016” by crn.com.

Essential Duties & Responsibilities

An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowd’s clients or researchers when additional information is required. ASEs also handle Incident Response – escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process.  The ASE position is perfect for security professionals looking to take their skills to the next level.

Education, Experience, Skills, & Abilities

  • Bachelor’s degree or previous security consulting experience
  • Published and demonstrated passion for security assessment research
  • High proficiency with Burp Suite (or any other interception proxy) and a working level of experience with other industry standard tools (nmap, sqlmap, anything included in Kali Linux)
  • Ability to execute on individual projects but still contribute to the team
  • Ability to complete tasks on time
  • Strong organization, influencing, and communication skills

Working Conditions

The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.

Sitting and/or standing - Must be able to remain in a stationary position 50% of the time

Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.

Any personal data you submit in connection with your application will be processed in compliance with Bugcrowd’s Privacy Policy, which you may review here: https://www.bugcrowd.com/privacy.

Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.

Apply at: https://www.bugcrowd.com/about/careers/

Read the full description
Security SOC Engineer (Incident Response)

Monitors security alerts, investigates incidents, and responds to threats within the SOC environment.

Mid Posted 6 days ago Himalayas
What this role involves
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users.
Read the full description
Security CyberSecurity Analyst at Avertium

Monitor and respond to security alerts, provide technical guidance to clients, manage vulnerabilities, and maintain security infrastructure across applications and infrastructure.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique “Assess, Design, Protect” methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network.  The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives.  The CS Analyst will provide security analytics and assistance with security support requests.

Responsibilities:

  • Monitor, respond to, and analyze SIEM alerts from monitoring tools.
  • Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products.  Handles daily incidents; monitors, tracks, analyzes and records.
  • Work with vendors, outside consultants, and other third parties to improve information security within the organization.
  • Responds to security related tickets escalated from clients, and works collaboratively with the client to assist in resolving security events.
  • Work with other IT professionals to resolve fast moving vulnerabilities such as spam, virus, spyware and malware.
  • Monitor security vulnerability information from vendors and third parties.
  • Create Weekly and Monthly Status Reports, including daily technical task reports and contract deliverables.

Qualifications for Success:

  • Strong written, verbal and non-verbal communication skills, especially conveying complex information in an understandable manner.
  • CISSP, CISA or GIAC certification is a plus.
  • A minimum of 2-4 years of experience working with Microsoft Active Directory.
  • Experience in managing an organization’s PCI, HIPAA, or SSAE16 certification is preferred.
  • Analyze and resolve complex technical and business problems.
  • Must have proficient knowledge with three or more of the following technologies:  Application / stateful / UTM firewalls; SIEM; DLP; Web content filtering; Web application firewalls (WAF); Vulnerability scanning and penetration testing; IPS/IDS; Security Operations Center operations; Wireless Networking; UNIX, AIX & Solaris, Linux, Windows Server Operating Systems; Endpoint and Malware
  • Knowledge with NIST, FISMA, DIACAP.
  • Knowledge of Windows 2003-12 server platforms.
  • Knowledge of VMware and VM server platforms.
  • Knowledge of UNIX server platforms.
  • Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, Windows.
  • Web and mail logged events.
  • Ability to analyze IANA assigned ports (well known, registered, dynamic and private ports).
  • Ability to troubleshoot common network devices, network, vulnerabilities and network attack patterns.
  • Ability to troubleshoot Windows Event IDs.
  • Interact with all levels of management.
  • Make decisions based on many variables.
  • Manage multiple tasks/projects simultaneously.
  • Minimum of Bachelor’s Degree in computer science, telecommunications management, electrical engineering, or a related field or have 4 years of experience.
  • Advanced network and systems certifications such as CCNP, CCNA and CISSP, are preferred.
  • Other industry certifications such as ITIL, Microsoft, Juniper and Checkpoint are a plus.
  • #LI-CS1

In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.

Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security engineer, application security at WRITER

Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.

Mid Hybrid Posted 6 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description
Security Security engineer, application security (UK) at WRITER

Builds security foundations for enterprise AI systems by conducting threat modeling, designing secure architectures, and embedding security controls across the platform.

Mid Hybrid Posted 6 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our London office, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • 4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

🍩 Benefits & perks (UK full-time employees):

  • Generous PTO, plus company holidays

  • Comprehensive medical and dental insurance

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Competitive pension scheme and company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation and company stock options

Read the full description
Security CyberSecurity Analyst at Avertium

CyberSecurity Analyst monitors SIEM alerts, responds to security incidents, provides technical guidance to clients, and maintains security measures across applications, web, and infrastructure.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique “Assess, Design, Protect” methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network.  The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives.  The CS Analyst will provide security analytics and assistance with security support requests.

Responsibilities:

  • Monitor, respond to, and analyze SIEM alerts from monitoring tools.
  • Provide technical guidance / recommendations to clients to enhance their overall security posture within the managed products.  Handles daily incidents; monitors, tracks, analyzes and records.
  • Work with vendors, outside consultants, and other third parties to improve information security within the organization.
  • Responds to security related tickets escalated from clients, and works collaboratively with the client to assist in resolving security events.
  • Work with other IT professionals to resolve fast moving vulnerabilities such as spam, virus, spyware and malware.
  • Monitor security vulnerability information from vendors and third parties.
  • Create Weekly and Monthly Status Reports, including daily technical task reports and contract deliverables.

Qualifications for Success:

  • Strong written, verbal and non-verbal communication skills, especially conveying complex information in an understandable manner.
  • CISSP, CISA or GIAC certification is a plus.
  • A minimum of 2-4 years of experience working with Microsoft Active Directory.
  • Experience in managing an organization’s PCI, HIPAA, or SSAE16 certification is preferred.
  • Analyze and resolve complex technical and business problems.
  • Must have proficient knowledge with three or more of the following technologies:  Application / stateful / UTM firewalls; SIEM; DLP; Web content filtering; Web application firewalls (WAF); Vulnerability scanning and penetration testing; IPS/IDS; Security Operations Center operations; Wireless Networking; UNIX, AIX & Solaris, Linux, Windows Server Operating Systems; Endpoint and Malware
  • Knowledge with NIST, FISMA, DIACAP.
  • Knowledge of Windows 2003-12 server platforms.
  • Knowledge of VMware and VM server platforms.
  • Knowledge of UNIX server platforms.
  • Working knowledge of analyzing IIS, SQL, firewall, IPS/IDS, Windows.
  • Web and mail logged events.
  • Ability to analyze IANA assigned ports (well known, registered, dynamic and private ports).
  • Ability to troubleshoot common network devices, network, vulnerabilities and network attack patterns.
  • Ability to troubleshoot Windows Event IDs.
  • Interact with all levels of management.
  • Make decisions based on many variables.
  • Manage multiple tasks/projects simultaneously.
  • Minimum of Bachelor’s Degree in computer science, telecommunications management, electrical engineering, or a related field or have 4 years of experience.
  • Advanced network and systems certifications such as CCNP, CCNA and CISSP, are preferred.
  • Other industry certifications such as ITIL, Microsoft, Juniper and Checkpoint are a plus.
  • #LI-CS1

In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.

Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security engineer, application security at WRITER

Builds application security foundations for enterprise AI systems, conducting threat modeling, designing secure architectures, and embedding security controls across the platform.

Mid Hybrid Posted 6 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description
Security Security engineer, application security (UK) at WRITER

Security engineer builds and maintains application security controls, threat models AI systems, and embeds security practices across the enterprise AI platform.

Mid Hybrid Posted 6 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our London office, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • 4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

🍩 Benefits & perks (UK full-time employees):

  • Generous PTO, plus company holidays

  • Comprehensive medical and dental insurance

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Competitive pension scheme and company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation and company stock options

Read the full description
Security Product Security Analyst

Analyzes and manages security threats and vulnerabilities using the HackerOne platform and community of security researchers.

Mid Posted 8 days ago Jobicy AI
What this role involves
HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to...
Read the full description
Security Application Security Engineer

Develops and implements security measures to protect applications from vulnerabilities and threats.

Mid Posted 8 days ago Himalayas
What this role involves
Application Security EngineerParallels is seeking a highly motivated and talented Application Security Engineer to join our team.
Read the full description
Security Vercel: GRC Analyst

Manages compliance with security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS), maintains internal controls, and collaborates across teams to ensure regulatory adherence.

Mid Hybrid Posted 9 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - United States

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role:

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.

You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

What you will do:

  • Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.

About you:

  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.

Bonus if you have :

  • Strong experience with cloud infrastructure (e.g., Azure, AWS)
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
  • Experience with frontend development and open source components
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

 

To apply: https://weworkremotely.com/remote-jobs/vercel-grc-analyst

Read the full description
Security Microsoft Sentinel Security Consultant at Quisitive

Analyzes Microsoft Sentinel security data to provide advisory guidance, interprets incidents and trends, and coaches customers on improving their security posture.

Mid Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

As one of Microsoft’s most recognized global partners, Quisitive sits at the forefront of cloud transformation, enterprise data strategy, cybersecurity, and the emerging frontier of agentic AI. Here, consultants and technologists operate on the edge of innovation—supported by a culture that values craftsmanship, open collaboration, and technical expertise. If you’re looking for a place where you can innovate, solve complex problems, and build solutions that make a measurable impact, join us.

Spyglass is Quisitive’s Security-as-a-Service offering — a modern, insight-driven approach to managed security that goes beyond alerts and tickets. In this role, you’ll help customers turn Microsoft Sentinel insights into better decisions and measurable risk reduction.

This is a remote position and can be based anywhere in the continental US.

About the Role

The Microsoft Sentinel Security Consultant is a customer-facing, advisory role focused on translating Microsoft Sentinel telemetry into clear, actionable security guidance. This is not a traditional SOC role. Instead, it’s designed for professionals who enjoy analyzing patterns, explaining security findings, and coaching customers on how to improve their security posture over time.

You’ll work closely with Spyglass Security Coaches, SecOps teams, and Customer Success Managers to help customers understand what Sentinel is telling them, why it matters, and what to do next.

What You’ll Do

Microsoft Sentinel Advisory (Primary Focus)

  • Review and interpret Microsoft Sentinel incidents, analytics rules, detections, and trends for assigned customers
  • Analyze recurring security signals to identify attack patterns, control gaps, and risk trends over time
  • Develop, read, and explain KQL queries, workbooks, and Sentinel dashboards
  • Partner with MDR and SecOps teams to validate detections, distinguish real risk from noise, and convert findings into advisory recommendations
  • Guide customers on how to act on Sentinel insights, not just respond to alerts

Security Coaching & Advisory

  • Support and contribute to monthly Spyglass security coaching sessions
  • Translate technical Sentinel outputs into clear, business-relevant narratives
  • Participate in executive and technical security advisory discussions
  • Contribute to customer security roadmaps informed by Sentinel-driven insights

Platform & Control Alignment

  • Assess customer security posture across Microsoft Sentinel, Microsoft Defender XDR, and Entra ID
  • Map Sentinel findings to security frameworks such as NIST CSF and CIS Controls
  • Identify gaps in telemetry, detection coverage, and control effectiveness

Delivery & Collaboration

  • Support Spyglass flex work by helping scope, estimate, and validate customer security engagements
  • Develop customer-facing materials such as security narratives, coaching decks, and Sentinel-backed summaries
  • Collaborate closely with Security Coaches, Customer Success Managers, and SecOps teams

What We’re Looking For

Required Qualifications

  • Hands-on experience with Microsoft Sentinel, including incident review, analytics rules, workbooks, and KQL
  • Working knowledge of Microsoft Defender for Endpoint, Identity, Office 365, Cloud Apps, and Entra ID
  • Ability to communicate security insights clearly to non-SOC and business audiences
  • Experience in a consultative or advisory security role
  • Strong ownership mindset and customer-focused communication skills
  • Ability to work with and balance workload with multiple customers

Preferred Qualifications

  • Experience delivering recurring security coaching or advisory services
  • Familiarity with NIST CSF and CIS Controls
  • Experience supporting regulated industries such as healthcare or financial services
  • Microsoft security certifications (SC-200, SC-300, SC-400, AZ-500)

​

US Citizens, Green Card holders and those authorized to work in the US are encouraged to apply.  We are unable to offer sponsorship at this time.

About Quisitive ​

With significant growth since 2016, Quisitive is rapidly progressing our vision of becoming the leading global Microsoft partner as we continue to expand across the United States, Canada and India. With a diversified delivery model that includes both nearshore and offshore capabilities, our team of Microsoft experts delivers cloud solutions, artificial intelligence and business applications that transform our clients’ businesses and achieve remarkable business outcomes. ​

Read the full description