Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Senior IAM Engineer II (AI Native) at Life360

Designs and owns enterprise IAM infrastructure, setting security architecture and engineering standards while leveraging AI tools to automate access workflows and system management.

Senior Remote Posted about 21 hours ago RemoteFirstJobs Product
What this role involves

About Life360

Life360’s mission is to keep people close to the ones they love. Our category-leading mobile app,Tile tracking devices, and Pet GPS tracker empower members to protect the people, pets, and things they care about most with a range of services, including location sharing, safe driver reports, and crash detection with emergency dispatch. Life360 serves approximately 97.8 million monthly active users (MAU), as of March 31, 2026, across more than 180 countries.

Life360 delivers peace of mind and enhances everyday family life with seamless coordination for all the moments that matter, big and small. By continuing to innovate and deliver for our customers, we have become a household name and the must-have mobile-based membership for families (and those friends who are basically family).

Life360 has more than 500 (and growing!) remote-first employees. For more information, please visit life360.com.

Life360 is a Remote First company, which means a remote work environment will be the primary experience for all employees. All positions, unless otherwise specified, can be performed remotely (within the US and Canada) regardless of any specified location above.

We are AI Native

We are building an AI native company where AI is an integral part of how we build and operate. AI tool usage during interviews varies by role. You may be asked to demonstrate proficiency with AI tools, discuss how you leverage AI, or complete interview exercises without AI assistance. Your Recruiter will provide clear guidance as you move through the interview process.

Undisclosed use of AI not previously discussed with or approved by your Recruiter may impact your candidacy.

About The Team

Security and IT at Life360 operate as a single integrated function — and we’re building it like one. That means treating identity infrastructure the way engineering teams treat product infrastructure: owned in code, measured with data, and continuously improved. You’ll own Enterprise IAM at Life360 — setting the architecture, engineering standards, and program direction for how every employee accesses every system, at a company that handles sensitive location data for nearly 100 million users. AI is core to how this team operates day to day — from drafting and validating IaC changes to automating access-review workflows — so identity engineering here means designing systems that pair automation with human judgment, not replacing one with the other.

About the Job

We’re looking for a Sr. IAM Engineer who thinks in systems, writes code to solve operational problems, and treats identity as a platform discipline. You’ll own the full enterprise identity stack: how it’s architected, how it’s measured, and how it scales as we grow. The foundation is in place now and we need someone to drive the design, automation, and governance layers forward. We’re building toward a metrics-first operating model, and you’ll build the instrumentation that makes that real. You’ll partner with HR, Security, and Engineering, and you’ll be expected to replace manual processes with durable, testable code wherever it exists. In your first year, success looks like a consolidated Okta footprint with orphaned accounts and stale SSO integrations cleaned up, access reviews running on a measurable cadence, and identity provisioning largely codified in Terraform rather than handled manually.

For candidates based in the US, the salary range for this position is $91,000 to $169,000 USD. For candidates based out of Canada, the salary range for this position is 132,000 to 157,000 CAD. Note: Please be aware that the job title for positions in Canada will be “Developer” in lieu of “Engineer.” We take into consideration an individual’s background and experience in determining final salary; therefore, base pay offered may vary considerably depending on geographic location, job-related knowledge, skills, and experience. The compensation package includes a wide range of medical, dental, vision, financial, and other benefits, as well as equity.

What You’ll Do

  • Own the enterprise identity platform as an engineering system — architect SSO integrations, lifecycle workflows, MFA policy, and group provisioning in Okta using IaC as the source of truth; configuration drift is a bug, not a ticket
  • Engineer the identity lifecycle management layer — design access control models and codify provisioning/deprovisioning workflows in IaC, partnering with HR systems to eliminate manual access operations and return clean provisioning capability to the helpdesk tier
  • Engineer access governance across the cloud and SaaS portfolio — own role assignments, group structures, and access controls across cloud infrastructure and collaboration platforms; design and automate periodic access reviews so auditability is structural, not procedural
  • Harden the device-to-identity trust boundary — own device trust integrations between our identity provider and MDM platforms, ensuring device compliance signals are correctly evaluated in access policy and that the control surface is fully codified
  • Rationalize and consolidate legacy identity surface — lead the technical cleanup of orphaned accounts, stale SSO integrations, and guest access sprawl across the SaaS portfolio; treat this as technical debt reduction with measurable outcomes
  • Build the IAM measurement layer — define, instrument, and track KPIs (access review completion rates, provisioning latency, orphaned account age, ticket volume trends) that justify investment decisions and demonstrate program maturity to Security leadership
  • Define the identity layer of our access request platform — architect the entitlement structures and access controls exposed through our self-service access tooling; codify the configuration in IaC and own the integration contract between identity infrastructure and the employee-facing access experience
  • Contribute to a unified service catalog — ensure identity workflows are clearly surfaced through a single employee-facing entry point and that the handoff between self-service and engineer-owned provisioning is unambiguous
  • Use AI coding agents as a first-class part of the identity engineering workflow — draft and validate Terraform modules, provisioning logic, and access-policy changes with AI assistance, and own review of anything AI-generated before it reaches production identity infrastructure

What We’re Looking For

  • Production experience in engineering and operating an enterprise identity platform at scale; SSO, lifecycle management, MFA, application integrations, and group-based access, with a strong bias toward configuration-as-code over manual administration
  • Strong IaC skills are required (Terraform or equivalent) applied to identity infrastructure — you write modules, manage state, and treat IaC plans as the change control mechanism
  • Deep working knowledge of SAML 2.0, OAuth 2.0, OIDC, and SCIM — you can debug a broken SAML assertion, reason through an OAuth flow, and design a SCIM provisioning schema without looking things up— including hands-on experience with custom authorization servers
  • Experience designing access control models in SaaS-heavy, remote-first environments. You understand the difference between a pragmatic access model and one that will collapse under growth
  • Experience governing access across cloud and SaaS platforms via SSO and SCIM — including group structures, permission boundaries, and collaboration platform controls
  • Comfort writing code to automate identity operations — Python, Go, or similar; you reach for a script before you reach for a ticket
  • Track record of defining measurable outcomes for security/identity programs and communicating them to non-technical stakeholders
  • Demonstrated fluency with AI coding/agent tools in a production engineering context — you can describe an end-to-end AI-assisted workflow you built (not just tool usage), and you know how to review AI-generated IaC or configuration before it ships

Nice to Have

  • Experience integrating device trust between an identity provider and MDM platforms to enforce compliance as a condition of access
  • Familiarity with self-service access request platforms
  • Experience operating in SOX, SOC 2, GDPR, CCPA, or COPPA compliance environments
  • Exposure to zero-trust architecture patterns and their application to workforce identity

AI-Native Expectations

  • Daily use: you use AI coding agents (e.g. Claude Code, Cursor, GitHub Copilot) daily to draft Terraform modules, provisioning scripts, and access-policy configuration — not just for autocomplete
  • Judgment and ownership: you review and are accountable for anything AI-generated before it touches production identity infrastructure; you can describe a time AI output was wrong and what you changed as a result
  • Velocity: AI fluency is expected to translate into measurable output leverage — faster IaC iteration, faster incident triage, fewer manual provisioning tickets
  • Team leadership: you share what you learn — reusable prompts, context docs, agent setups — and help raise the AI fluency of the broader Security/IT team
  • Continuous learning: you stay current on agentic tooling and bring recommendations back to the team rather than waiting for tooling decisions to be made for you

Our Benefits

  • Competitive pay and benefits.
  • Medical, dental, vision, life, and disability insurance plans (100% paid for US employees). We offer supplemental plans for medical and dental for Canadian employees.
  • 401(k) plan with company matching program in the US and RRSP with DPSP plan for Canadian employees.
  • Employee Assistance Program (EAP) for mental wellness.
  • Flexible PTO and 12 company-wide days off throughout the year.
  • Winter and Summer Weeklong Synchronized Company Shutdowns
  • Learning & Development programs.
  • Equipment, tools, and reimbursement support for a productive remote environment.
  • Free Life360 Platinum Membership for your preferred circle.
  • Free Tile Products

Life360 Values

Our company’s mission-driven culture is guided by our shared values to create a trusted work environment where you can bring your authentic self to work and make a positive difference

  • Be a Good Person - We have a team of high integrity people you can trust.
  • Be Direct With Respect - We communicate directly, even when it’s hard.
  • Members Before Metrics - We focus on building an exceptional experience for families.
  • High Intensity, High Impact - We do whatever it takes to get the job done.

Our Commitment to Diversity

We believe that different ideas, perspectives and backgrounds create a stronger and more creative work environment that delivers better results. Together, we continue to build an inclusive culture that encourages, supports, and celebrates the diverse voices of our employees. It fuels our innovation and connects us closer to our customers and the communities we serve. We strive to create a workplace that reflects the communities we serve and where everyone feels empowered to bring their authentic best selves to work.

We are an equal opportunity employer and value diversity at Life360. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability status or any legally protected status.

We encourage people of all backgrounds to apply. We believe that a diversity of perspectives and experiences create a foundation for the best ideas. Come join us in building something meaningful. Even if you don’t meet 100% of the below qualifications, you should still seriously consider applying!

#LI-Remote

\_\_\__________________________________________________________________________

Read the full description
Security Cybersecurity Engineer II

Implements, operates, and improves cybersecurity capabilities for enterprise clients as a hands-on technical contributor.

Mid Posted about 21 hours ago Himalayas
What this role involves
The Cybersecurity Engineer II (L2) is a hands-on technical contributor responsible for implementing, operating, and improving client’s cybersecurity capabilities across a rapidly growing enterprise.
Read the full description
Security Akamai: Security Architect II

Detects and mitigates cyber attacks in real-time for enterprise clients, analyzing threats and deploying security solutions on Akamai platforms.

Senior Posted about 23 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Costa Rica
URL: http://akamai.com

Description

Are you excited by the prospect of detecting and mitigating the latest cyber attacks?

Would you enjoy protecting the world's leading brands in a fast-paced environment?

Work with industry leading technology

Our Team strives to be the most trusted support services partner and to keep our customers online businesses up and running. We utilize tools, process and knowledge to diagnose and resolve product, platform, and customer issues. Our team delivers managed services for both media and security to proactively maintain quality and protect our customers' online presence.

Respond to cyber attacks in real time

As a Security Architect II in SOCC, advising on mitigating attacks for managed security clients. Protect critical web applications and APIs for enterprises, including banks and e-commerce. Identify cyber threats using data, strategize mitigations, and deploy solutions. Ensure minimal impact on end users while addressing real-time security concerns.

As a Security Architect II, you will be responsible for:

  • Devising and engaging mitigation strategies to prevent real-time attacks, using Akamai products & platform
  • Conducting advanced analysis to identify attacks and threats targeting digital properties, web applications, and APIs.
  • Providing consultation & attack mitigation strategies to customers or peer teams based on the analysis

Do what you love

To be successful in this role you will:

  • Have +5 years of experience and a High School / Bachelor's degree in Computer Science or its equivalent
  • Have familiarity with Jupyter Notebooks, Streamlit, or Dash for rapid prototyping
  • Understand REST APIs, parse JSON, fetch scan data, utilize Python, and apply SQL effectively.
  • Have experience with Git and collaboration tools (Jira, Confluence, GitHub) and clustering (esp. for anomaly detection
  • Demonstrate expertise in Python, SQL, and foundational statistics, including mean, median, mode, and correlation.
  • Understand protocols such as HTTP, TCP/IP, OWASP top 10, and their relation to internet security risks.
  • Understand common attack preventive security techniques on L7

About us

At Akamai, we make life better for billions of people, trillions of times a day.
Whether you're streaming live events, scrolling social media, watching your favorite series, or managing your savings, we're the engine behind the scenes. We provide the world's most distributed platform from Cloud to Edge to help the giants of the digital world work faster and stay more secure, making the internet a better experience for everyone.

Our focus is simple:
Cloud and Edge: Running apps closer to users for instant performance.
Security: Neutralizing threats before they ever reach your data.
Content Delivery: Scaling the world's biggest moments without a glitch.
AI: Enabling our customers to build, secure, and scale AI apps on the world's most distributed cloud platform.

At Akamai, we don't just support the internet; we power and protect it, because behind every great digital experience is a massive hidden challenge. And we're the ones who solve it. When millions of people hit play or pay, Akamai ensures it just works.

Benefits at Akamai: We support your health, well-being, finances, and life beyond work. See our benefits.

FlexBase adapts to your job's needs

Akamai's FlexBase program is yet another way we show our commitment to providing employees with an exceptional workplace experience. It's not about telling employees where to work; it's about supporting employees to do their best work.

We trust our incredible employees to work in ways that suit them best: at home, in an office, or a combination of both.

Connect with us on social and see what life at Akamai is like!



To apply: https://weworkremotely.com/remote-jobs/akamai-security-architect-ii

Read the full description
Security Unqork: Intern-Web Application Penetration Tester

Intern conducts manual and automated penetration testing on web applications and AI/LLM systems, identifies vulnerabilities, develops proofs-of-concept, and documents security findings.

Junior Remote Posted about 23 hours ago We Work Remotely — Programming
What this role involves

Headquarters: United States (Remote)
URL: http://unqork.com

Unqork empowers enterprises to accelerate growth by rapidly building, testing, and running AI-powered applications that embody the future of enterprise development. Trusted by the world’s largest organizations in highly regulated industries, these applications become more secure over time while significantly reducing technical debt—allowing businesses to focus on innovation rather than maintenance. Unqork’s customers include Goldman Sachs, Marsh, BlackRock, and the U.S. Department of Health and Human Services. 

At Unqork, we value inclusive and innovative thinkers who boldly challenge the status quo. We encourage you to apply!

We are looking to hire an Intern to join our Product Security team .

Title: Intern-Web Application Penetration Tester

Department: Product Security

Reports to: Director, Product Security

Type: Paid Internship $30/hr

We are looking to hire an Intern- Web Application Penetration Tester to join our product security team. This role is designed for rising seniors or a recent college graduate with a strong foundational background in Computer Science or Cybersecurity who wants to transition theoretical knowledge into real-world ethical hacking. In this role, you won't just run automated scanners. You will actively dissect complex web applications, hunt for business logic flaws, and evaluate the security posture of our emerging AI and Large Language Model (LLM) integrations.

What Impact U would make 

  • Vulnerability Assessment & Pentesting: Assist in conducting manual and automated penetration tests on web application and APIs to identify security vulnerabilities (OWASP Top 10).
  • AI/LLM Security Evaluation: Help assess the security of AI-driven features and LLM implementations, checking for vulnerabilities like prompt injection, data poisoning, insecure output handling, and model denial of service (OWASP Top 10 for LLMs).
  • Exploitation & PoC Development: Safely demonstrate the impact of discovered vulnerabilities by creating clear Proof-of-Concept (PoC) exploits.
  • Documentation & Reporting: Write comprehensive, technical security reports detailing findings, exploitation paths, risk ratings, and actionable remediation steps for development teams.
  • Collaboration: Work closely with software engineers to explain security flaws and guide them on secure coding best practices and remediation verification.

What U bring:

  • Currently pursuing an undergraduate or graduate degree in Computer Science, Cybersecurity, or a related field.
  • Demonstrates a strong interest in cybersecurity and a commitment to staying current on emerging threats, security risks, attack vectors, and industry best practices.
  • Possesses exceptional attention to detail and strong organizational skills.
  • Excellent written and verbal communication abilities, with the capacity to convey technical information clearly and effectively.
  • Confident and comfortable collaborating with peers, cross-functional teams, and management-level stakeholders.
  • Proven ability to prioritize and manage multiple responsibilities while working independently in a fast-paced, dynamic environment.

Preferred Traits:

  • Curious and proactive problem solver
  • Process-oriented with a continuous improvement mindset
  • Comfortable working with ambiguity and learning new systems quickly
  • Collaborative team player with a strong sense of ownership

Unqork embraces a culture of security and privacy awareness by consistently safeguarding sensitive information, adhering to company policies, and actively participating in training and initiatives to protect our data and the privacy of our stakeholders. 

Unqork is an equal opportunity employer. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.

To apply: https://weworkremotely.com/remote-jobs/unqork-intern-web-application-penetration-tester

Read the full description
Security Senior Security Engineer at Prolific

Senior Security Engineer performs hands-on application security work including vulnerability discovery, security testing, threat modeling, and building security tooling across the platform.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Senior Security Engineer

Engineering

Prolific

Prolific is not just another player in the AI space – we are the architects of the human data infrastructure that’s reshaping the landscape of AI development. In a world where foundational AI technologies are increasingly commoditized, it’s the quality and diversity of human-generated data that truly differentiates products and models.

The role

Security at Prolific isn’t an afterthought, it’s foundational to how we build. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, the security of our application layer is critical. We handle participant data, researcher credentials, payment flows, and API integrations that demand rigorous protection at the code level.

As a Senior Security Engineer, you’ll be the technical authority on application security at Prolific. You’ll work hands-on with our engineering teams to find and fix vulnerabilities in our codebase, perform security testing, build security tooling, and embed secure development practices into how we ship software. This isn’t a governance or policy role, you’ll be in the code, reviewing pull requests, threat modelling new features, and building the automation that keeps our platform secure as we scale.

You’ll report to the Head of Engineering/Platform and work cross-functionally with product engineering, platform, data, and TechOps teams.

What you’ll bring to the role

  • Several years in application/product security and a background in software engineering
  • Strong knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic abuse, supply chain)
  • Experience working with complex, large-scale systems and modern architectures
  • Hands-on security testing experience (especially Burp Suite) across web apps and APIs
  • Python for security tooling, automation, or custom detection (Django a plus)
  • Experience implementing and tuning SAST, SCA, DAST, and secret scanning in CI/CD
  • Practical threat modelling experience, including leading lightweight sessions
  • Strong collaboration skills, able to clearly explain issues and drive remediation
  • Builder mindset, you automate wherever possible

Nice to haves..

  • Experience with Django, Vue.js, MongoDB, GCP
  • Security champions or bug bounty programmes
  • Supply chain security (SCA, SBOMs, dependency review)
  • IaC security (e.g. Terraform, policy-as-code)
  • Hands-on certifications (OSCP, GWAPT, BSCP)
  • Experience in scaling environments building out security practices

What you’ll be doing in the role

You’ll help secure Prolific’s applications end-to-end, from hands-on testing and code review to threat modelling and CI/CD security. You’ll partner closely with engineers to identify and fix vulnerabilities, build and tune security tooling, and embed secure development practices across the SDLC. This includes running penetration tests, improving detection coverage, and staying ahead of emerging threats to continuously strengthen our security posture.

Why Prolific is a great place to work

We’ve built a unique platform that connects researchers and companies with a global pool of participants, enabling the collection of high-quality, ethically sourced human behavioral data and feedback. This data is the cornerstone of developing more accurate, nuanced, and aligned AI systems.

We believe that the next leap in AI capabilities won’t come solely from scaling existing models, but from integrating diverse human perspectives and behaviors into AI development. By providing this crucial human data infrastructure, Prolific is positioning itself at the forefront of the next wave of AI innovation – one that reflects the breath and the best of humanity.

Working for us will place you at the forefront of AI innovation, providing access to our unique human data platform and opportunities for groundbreaking research. Join us to enjoy a competitive salary, benefits, and remote working within our impactful, mission-driven culture.

Links to more information on Prolific

Benefits

External Handbook

Website

Youtube

Privacy Statement

By submitting your application, you agree that Prolific may collect your personal data for recruiting and global organisation planning. Prolific’s Candidate Privacy Notice explains what personal information Prolific may process, where Prolific may process your personal information, its purposes for processing your personal information, and the rights you can exercise over Prolific use of your personal information.

Read the full description
Security Senior Security Engineer at Prolific

Hands-on application security engineer who finds and fixes vulnerabilities in code, performs security testing, builds security tooling, and embeds secure development practices across engineering teams.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Senior Security Engineer

Engineering

Prolific

Prolific is not just another player in the AI space – we are the architects of the human data infrastructure that’s reshaping the landscape of AI development. In a world where foundational AI technologies are increasingly commoditized, it’s the quality and diversity of human-generated data that truly differentiates products and models.

The role

Security at Prolific isn’t an afterthought, it’s foundational to how we build. As a company trusted by world-leading research institutions and AI labs to handle sensitive data at scale, the security of our application layer is critical. We handle participant data, researcher credentials, payment flows, and API integrations that demand rigorous protection at the code level.

As a Senior Security Engineer, you’ll be the technical authority on application security at Prolific. You’ll work hands-on with our engineering teams to find and fix vulnerabilities in our codebase, perform security testing, build security tooling, and embed secure development practices into how we ship software. This isn’t a governance or policy role, you’ll be in the code, reviewing pull requests, threat modelling new features, and building the automation that keeps our platform secure as we scale.

You’ll report to the Head of Engineering/Platform and work cross-functionally with product engineering, platform, data, and TechOps teams.

What you’ll bring to the role

  • Several years in application/product security and a background in software engineering
  • Strong knowledge of OWASP Top 10 (Web & API) and modern attack paths (e.g. auth flaws, SSRF, injection, business logic abuse, supply chain)
  • Experience working with complex, large-scale systems and modern architectures
  • Hands-on security testing experience (especially Burp Suite) across web apps and APIs
  • Python for security tooling, automation, or custom detection (Django a plus)
  • Experience implementing and tuning SAST, SCA, DAST, and secret scanning in CI/CD
  • Practical threat modelling experience, including leading lightweight sessions
  • Strong collaboration skills, able to clearly explain issues and drive remediation
  • Builder mindset, you automate wherever possible

Nice to haves..

  • Experience with Django, Vue.js, MongoDB, GCP
  • Security champions or bug bounty programmes
  • Supply chain security (SCA, SBOMs, dependency review)
  • IaC security (e.g. Terraform, policy-as-code)
  • Hands-on certifications (OSCP, GWAPT, BSCP)
  • Experience in scaling environments building out security practices

What you’ll be doing in the role

You’ll help secure Prolific’s applications end-to-end, from hands-on testing and code review to threat modelling and CI/CD security. You’ll partner closely with engineers to identify and fix vulnerabilities, build and tune security tooling, and embed secure development practices across the SDLC. This includes running penetration tests, improving detection coverage, and staying ahead of emerging threats to continuously strengthen our security posture.

Why Prolific is a great place to work

We’ve built a unique platform that connects researchers and companies with a global pool of participants, enabling the collection of high-quality, ethically sourced human behavioral data and feedback. This data is the cornerstone of developing more accurate, nuanced, and aligned AI systems.

We believe that the next leap in AI capabilities won’t come solely from scaling existing models, but from integrating diverse human perspectives and behaviors into AI development. By providing this crucial human data infrastructure, Prolific is positioning itself at the forefront of the next wave of AI innovation – one that reflects the breath and the best of humanity.

Working for us will place you at the forefront of AI innovation, providing access to our unique human data platform and opportunities for groundbreaking research. Join us to enjoy a competitive salary, benefits, and remote working within our impactful, mission-driven culture.

Links to more information on Prolific

Benefits

External Handbook

Website

Youtube

Privacy Statement

By submitting your application, you agree that Prolific may collect your personal data for recruiting and global organisation planning. Prolific’s Candidate Privacy Notice explains what personal information Prolific may process, where Prolific may process your personal information, its purposes for processing your personal information, and the rights you can exercise over Prolific use of your personal information.

Read the full description
Security Cloud Security Analyst

Analyzes cloud infrastructure security, identifies vulnerabilities, and implements security controls to protect hospitality platform systems and customer data.

Mid Posted 2 days ago Jobicy AI
What this role involves
What Makes Us Unique At Cloudbeds, we’re not just building software, we’re transforming hospitality. Our intelligently designed platform powers properties across 150 countries, processing billions in bookings annually. From independent...
Read the full description
Security Security Operations Engineer I (Weekend Shift)

Builds security designs, manages compliance and vulnerabilities, and conducts penetration testing for cloud infrastructure.

Junior Posted 3 days ago Himalayas
What this role involves
Role OverviewThe Security Operations Engineer will work with the Cloud and Delivery team to build Security Design and Architecture, Compliance, Threat and Vulnerability Management, and Penetration Testing.
Read the full description
Security Offensive Security Engineer

Proactively tests and identifies vulnerabilities across external perimeter, VPS, physical infrastructure, and endpoint defenses to strengthen offensive security posture.

Mid Posted 3 days ago Jobicy AI
What this role involves
About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The...
Read the full description
Security Chief Information Security Officer

Develops and executes enterprise security strategy, manages risk and compliance across multiple business units.

Exec Posted 4 days ago Jobicy AI
What this role involves
Position Summary The Chief Information Security Officer (CISO) owns enterprise security strategy, risk management, and compliance for the FAL Group of companies under Fortive (Accruent, Gordian, and ServiceChannel) all of...
Read the full description
Security Security Engineer, Detection Response at Vercel

Monitors security alerts, maintains SIEM infrastructure, handles incidents, and builds detections to protect Vercel's internal systems and compliance posture.

Mid Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the Role:

We are looking for a Security Engineer to join our Detection Response team. In this role, you will be responsible for managing Vercel’s internal Corporate Security (CorpSec) posture, monitoring for security anomalies, building additional detections and visibility mechanisms, and ensuring the overall security of our internal systems. You will work closely with various teams to support audits, optimize visibility, and handle security incidents as they arise.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you’re located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

What You Will Do:

  • Monitor and respond to security alerts across multiple channels, including managed SOC escalations.
  • Maintain visibility and logging infrastructure, ensuring effective SIEM (Security Information and Event Management) operations.
  • Support security audits for PCI, SOC2, ISO, and other compliance frameworks, gathering evidence and collaborating with Engineering, GRC and the broader Security Division.
  • Proactively enhance security operations by developing and deploying new detections, security tooling and rigorously managing key security partners.
  • Work on security investigations, incidents, and urgent requests as they arise, as well as contributing to the build-out and continuous improvement of the on-call process to enhance efficiency and effectiveness.
  • Continuously act as a guardian to enable the business to navigate risk-based changes.
  • Manage and enhance email security, endpoint security posture (EDR, configuration, and management), GitHub administration best practices, and internal security tooling to strengthen Vercel’s overall security framework

About You:

  • Extensive experience in security operations, including SIEM management, security logging, and detection engineering.
  • Strong knowledge of AWS infrastructure and cloud security best practices.
  • Experience with GitHub administration and security controls.
  • Proficiency in SQL for data analysis and security investigations.
  • Hands-on experience with incident response, including detection, triage, and remediation.
  • Strong endpoint management skills across multiple operating systems (Mac, Windows, Linux).
  • Proficiency in at least one scripting language (Python, Bash) and one compiled language (Rust, Go).
  • Familiarity with serverless functions and API security is a plus.

Bonus If You:

  • Have experience working with managed SOC providers and security automation platforms.
  • Have worked in high-growth, cloud-native environments with a focus on scalability.
  • Are comfortable working in a fast-paced environment with shifting priorities.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000-$312,000. This salary range is an estimate. Actual salary will be based on job-related skills, experience, and location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.

Read the full description
Security GRC Expert at Public Group

GRC Expert manages cybersecurity governance, risk, and compliance programs, conducts assessments, and maintains compliance posture across security, privacy, and third-party risk frameworks.

Mid Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

The organization

Why Join Us? It’s More Than a Job in Retail, It’s Your Story.

At Public Group, we believe in the power of our people in a sustainable way. That’s why we’re not just focused on what you do, but who you become. We’re committed to fueling your growth, because when you win, we all win. Imagine a place where you feel supported, valued, and empowered to make a real difference.  A place where you can build a career you love, to leave your mark in our story!

Public Group strategically invests to create an ecosystem of innovative scaleups around its Omnichannel Retail business, with the objective to provide exciting customer experiences and foster Entrepreneurship in Greece. We bring together technology, talent & entrepreneurship to create value in the Greek market. Our role is to help our subsidiaries or investee companies grow and their founders to succeed through capital and creative synergies. Our investment portfolio includes Public-MediaMarkt, iRepair, Douleutaras.gr, PublicNEXT, Venture Friends.

PublicNEXT leads the digital transformation of retail, with solutions to reimagine processes, integrate technologies and introduce innovative services or platforms that transform employee and customer experience. We develop and unleash the best technology solutions that shape the future of retail. Our team of software developers, engineers, digital and IT experts combine strong technical skills and entrepreneurial thinking to help organizations stay ahead.

As future-ready innovators, we engage in multiple projects and create growth opportunities for everyone to find what they are looking for. Together we can reimagine retail and unleash the best technology platforms to create new capabilities for people and inspire them to enjoy life. We grow by continuously developing on each other’s ideas.

Let’s grow together.

#LI-Hybrid

At Publicnext, we are strengthening our cybersecurity governance, risk, and compliance (GRC) function and looking for a GRC Expert to join the team. Working closely with and reporting directly to the CISO, you will help us mature our risk management and resilience across cybersecurity, privacy, business continuity, AI compliance, and third-party risk.

This is a hands-on delivery role with real ownership. You will run assessments, maintain our risk and compliance posture against recognized frameworks, and support the growing intersection of GRC and IT contract management, reviewing business terms, shaping governance and SLAs, and ensuring our internal and third-party arrangements meet our standards.

Responsibilities:

  • Develop and maintain cybersecurity policies, standards, and procedures aligned to recognized frameworks and regulations (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).

  • Facilitate cybersecurity and technology risk assessments; maintain risk registers and track remediation activities to closure.

  • Participate in risk assessments, vulnerability assessments, and gap analyses, and translate findings into practical improvement plans.

  • Support compliance initiatives including DPIAs, TPRAs (Third-Party Risk Assessments), and EU AI Act readiness.

  • Coordinate and support internal and external audits and Cyber Insurance audits.

  • Oversee third-party cybersecurity risk management processes, ensuring internal teams and vendors adhere to our standards.

  • Review contracts’ business terms and highlight areas for improvement.

  • Contribute to the design of governance and SLAs for contract management.

  • Support the legal and partner interface on contracts, NDAs, and Technical & Organizational Measures (TOMs).

  • Take ownership of delivery within your assigned workstreams and deliverables, ensuring quality and timely execution.

  • Participate in the project management of ongoing GRC engagements.

  • Provide time and effort estimates for prospective engagements and contribute to the technical writing of proposals and offers.

  • Facilitate training sessions and workshops to drive cybersecurity awareness across the organization.

  • Communicate clearly with technical specialists, business leaders, and legal/compliance stakeholders.

Requirements:

  • 3+ years of experience in cybersecurity, information security, compliance, or GRC-related functions.
  • Solid understanding of cybersecurity frameworks and regulatory requirements (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).
  • Experience supporting audits, assessments, and control-maturity activities.
  • Familiarity with IT project management principles and related methodologies.
  • Experience with or exposure to IT contract management (reviewing terms, SLAs, governance).
  • Strong analytical and problem-solving abilities.
  • Ability to communicate technical and cyber-risk concepts to both technical and non-technical audiences, including executives.
  • Strong stakeholder management and cross-functional collaboration skills.
  • A team player who supports and helps drive common goals.
  • Languages: Greek and English (both required, written and spoken).
  • Professional certifications such as ISO 27001 Lead Auditor (ISO27001-LA), CISM, CISA, or similar.
  • Experience working within regulated environments.
  • Prior exposure to Contract Management roles or IT business-facing roles.

What we offer:

  • 💼 Competitive compensation & benefits package
  • 💰 Performance-based bonus scheme
  • 🧑‍⚕️ Comprehensive life & health insurance
  • 🏡 Flexible hybrid working model – to support your work-life balance
  • 🧡 Psychological support via a professional helpline for you and your family
  • 🚀 Career growth opportunities in a role that evolves with you
  • 🎉 Valuable experience in a well-known and fast-growing organization
  • 📚 Continuous learning and upskilling through tailored programs
  • 🏃🏽‍♂️ Employee Wellness Program – office Pilates & sports teams (padel, football, volleyball & more)
  • 🚗 Alternative transportation with company shuttle buses to our offices
  • 📲 Exclusive access to our employee app, OrangeGen, packed with tools, news & perks

What Does OrangeGen Offer? 🔗 Connect: Engage with your colleagues and management seamlessly, ensuring you’re always in the loop and part of our dynamic community.

🎉 Recognize: Celebrate achievements and milestones with a culture of recognition that boosts morale and fosters a positive work environment.

🏆 Custom Rewards: Enjoy personalized rewards and kudos, tailored to recognize your unique contributions and achievements.

Are you ready to be the next #OrangeGen maker?

Orange Gen, is our team of 2.200 people who are committed to cultivating an innovative retailtainment environment, supporting continuous development, and embracing flexibility—all while placing customer centricity at the forefront. We believe in fostering a culture that values your contributions, boosts your ambitions, and supports personal and professional growth. “Joy at Public” is our main motto which lies in creating a workplace where every individual is empowered to excel and evolve, always keeping the customer at the heart of our endeavors. We like to share our moments under the #OrangeTeam celebrating all team’s achievements and Orange Marks Stories!

All applications will be treated with the strictest confidentiality.

Read the full description
Security GRC Expert at Public Group

GRC Expert manages cybersecurity governance, risk, and compliance frameworks while reporting to the CISO and conducting security assessments.

Mid Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

The organization

Why Join Us? It’s More Than a Job in Retail, It’s Your Story.

At Public Group, we believe in the power of our people in a sustainable way. That’s why we’re not just focused on what you do, but who you become. We’re committed to fueling your growth, because when you win, we all win. Imagine a place where you feel supported, valued, and empowered to make a real difference.  A place where you can build a career you love, to leave your mark in our story!

Public Group strategically invests to create an ecosystem of innovative scaleups around its Omnichannel Retail business, with the objective to provide exciting customer experiences and foster Entrepreneurship in Greece. We bring together technology, talent & entrepreneurship to create value in the Greek market. Our role is to help our subsidiaries or investee companies grow and their founders to succeed through capital and creative synergies. Our investment portfolio includes Public-MediaMarkt, iRepair, Douleutaras.gr, PublicNEXT, Venture Friends.

PublicNEXT leads the digital transformation of retail, with solutions to reimagine processes, integrate technologies and introduce innovative services or platforms that transform employee and customer experience. We develop and unleash the best technology solutions that shape the future of retail. Our team of software developers, engineers, digital and IT experts combine strong technical skills and entrepreneurial thinking to help organizations stay ahead.

As future-ready innovators, we engage in multiple projects and create growth opportunities for everyone to find what they are looking for. Together we can reimagine retail and unleash the best technology platforms to create new capabilities for people and inspire them to enjoy life. We grow by continuously developing on each other’s ideas.

Let’s grow together.

#LI-Hybrid

At Publicnext, we are strengthening our cybersecurity governance, risk, and compliance (GRC) function and looking for a GRC Expert to join the team. Working closely with and reporting directly to the CISO, you will help us mature our risk management and resilience across cybersecurity, privacy, business continuity, AI compliance, and third-party risk.

This is a hands-on delivery role with real ownership. You will run assessments, maintain our risk and compliance posture against recognized frameworks, and support the growing intersection of GRC and IT contract management, reviewing business terms, shaping governance and SLAs, and ensuring our internal and third-party arrangements meet our standards.

Responsibilities:

  • Develop and maintain cybersecurity policies, standards, and procedures aligned to recognized frameworks and regulations (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).

  • Facilitate cybersecurity and technology risk assessments; maintain risk registers and track remediation activities to closure.

  • Participate in risk assessments, vulnerability assessments, and gap analyses, and translate findings into practical improvement plans.

  • Support compliance initiatives including DPIAs, TPRAs (Third-Party Risk Assessments), and EU AI Act readiness.

  • Coordinate and support internal and external audits and Cyber Insurance audits.

  • Oversee third-party cybersecurity risk management processes, ensuring internal teams and vendors adhere to our standards.

  • Review contracts’ business terms and highlight areas for improvement.

  • Contribute to the design of governance and SLAs for contract management.

  • Support the legal and partner interface on contracts, NDAs, and Technical & Organizational Measures (TOMs).

  • Take ownership of delivery within your assigned workstreams and deliverables, ensuring quality and timely execution.

  • Participate in the project management of ongoing GRC engagements.

  • Provide time and effort estimates for prospective engagements and contribute to the technical writing of proposals and offers.

  • Facilitate training sessions and workshops to drive cybersecurity awareness across the organization.

  • Communicate clearly with technical specialists, business leaders, and legal/compliance stakeholders.

Requirements:

  • 3+ years of experience in cybersecurity, information security, compliance, or GRC-related functions.
  • Solid understanding of cybersecurity frameworks and regulatory requirements (NIST CSF, GDPR, NIS2, PCI DSS, EU AI Act).
  • Experience supporting audits, assessments, and control-maturity activities.
  • Familiarity with IT project management principles and related methodologies.
  • Experience with or exposure to IT contract management (reviewing terms, SLAs, governance).
  • Strong analytical and problem-solving abilities.
  • Ability to communicate technical and cyber-risk concepts to both technical and non-technical audiences, including executives.
  • Strong stakeholder management and cross-functional collaboration skills.
  • A team player who supports and helps drive common goals.
  • Languages: Greek and English (both required, written and spoken).
  • Professional certifications such as ISO 27001 Lead Auditor (ISO27001-LA), CISM, CISA, or similar.
  • Experience working within regulated environments.
  • Prior exposure to Contract Management roles or IT business-facing roles.

What we offer:

  • 💼 Competitive compensation & benefits package
  • 💰 Performance-based bonus scheme
  • 🧑‍⚕️ Comprehensive life & health insurance
  • 🏡 Flexible hybrid working model – to support your work-life balance
  • 🧡 Psychological support via a professional helpline for you and your family
  • 🚀 Career growth opportunities in a role that evolves with you
  • 🎉 Valuable experience in a well-known and fast-growing organization
  • 📚 Continuous learning and upskilling through tailored programs
  • 🏃🏽‍♂️ Employee Wellness Program – office Pilates & sports teams (padel, football, volleyball & more)
  • 🚗 Alternative transportation with company shuttle buses to our offices
  • 📲 Exclusive access to our employee app, OrangeGen, packed with tools, news & perks

What Does OrangeGen Offer? 🔗 Connect: Engage with your colleagues and management seamlessly, ensuring you’re always in the loop and part of our dynamic community.

🎉 Recognize: Celebrate achievements and milestones with a culture of recognition that boosts morale and fosters a positive work environment.

🏆 Custom Rewards: Enjoy personalized rewards and kudos, tailored to recognize your unique contributions and achievements.

Are you ready to be the next #OrangeGen maker?

Orange Gen, is our team of 2.200 people who are committed to cultivating an innovative retailtainment environment, supporting continuous development, and embracing flexibility—all while placing customer centricity at the forefront. We believe in fostering a culture that values your contributions, boosts your ambitions, and supports personal and professional growth. “Joy at Public” is our main motto which lies in creating a workplace where every individual is empowered to excel and evolve, always keeping the customer at the heart of our endeavors. We like to share our moments under the #OrangeTeam celebrating all team’s achievements and Orange Marks Stories!

All applications will be treated with the strictest confidentiality.

Read the full description
Security Security Engineer, Detection Response at Vercel

Monitor security alerts, maintain SIEM infrastructure, respond to incidents, and develop detections to protect internal corporate systems and compliance posture.

Mid Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the Role:

We are looking for a Security Engineer to join our Detection Response team. In this role, you will be responsible for managing Vercel’s internal Corporate Security (CorpSec) posture, monitoring for security anomalies, building additional detections and visibility mechanisms, and ensuring the overall security of our internal systems. You will work closely with various teams to support audits, optimize visibility, and handle security incidents as they arise.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday. If you’re located beyond that distance, the role is fully remote. For location-specific details, please connect with our recruiting team.

What You Will Do:

  • Monitor and respond to security alerts across multiple channels, including managed SOC escalations.
  • Maintain visibility and logging infrastructure, ensuring effective SIEM (Security Information and Event Management) operations.
  • Support security audits for PCI, SOC2, ISO, and other compliance frameworks, gathering evidence and collaborating with Engineering, GRC and the broader Security Division.
  • Proactively enhance security operations by developing and deploying new detections, security tooling and rigorously managing key security partners.
  • Work on security investigations, incidents, and urgent requests as they arise, as well as contributing to the build-out and continuous improvement of the on-call process to enhance efficiency and effectiveness.
  • Continuously act as a guardian to enable the business to navigate risk-based changes.
  • Manage and enhance email security, endpoint security posture (EDR, configuration, and management), GitHub administration best practices, and internal security tooling to strengthen Vercel’s overall security framework

About You:

  • Extensive experience in security operations, including SIEM management, security logging, and detection engineering.
  • Strong knowledge of AWS infrastructure and cloud security best practices.
  • Experience with GitHub administration and security controls.
  • Proficiency in SQL for data analysis and security investigations.
  • Hands-on experience with incident response, including detection, triage, and remediation.
  • Strong endpoint management skills across multiple operating systems (Mac, Windows, Linux).
  • Proficiency in at least one scripting language (Python, Bash) and one compiled language (Rust, Go).
  • Familiarity with serverless functions and API security is a plus.

Bonus If You:

  • Have experience working with managed SOC providers and security automation platforms.
  • Have worked in high-growth, cloud-native environments with a focus on scalability.
  • Are comfortable working in a fast-paced environment with shifting priorities.

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $208,000-$312,000. This salary range is an estimate. Actual salary will be based on job-related skills, experience, and location. The total compensation package also includes benefits and equity-based compensation. Your recruiter can share more about the specific pay range for your location during the hiring process.

Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don’t necessarily check every box on the job description.

Read the full description
Security Senior Cyber Threat Analyst

Analyzes cyber threats, identifies vulnerabilities, and develops security strategies to protect organizational systems and data.

Senior Posted 4 days ago Himalayas
What this role involves
Position DescriptionValiant Solutions is seeking a Senior Cyber Threat Analyst to join our rapidly growing and innovative cybersecurity team!
Read the full description
Security Information Security Analyst

Monitors and analyzes security threats, manages vulnerability assessments, and implements security controls to protect organizational systems and data.

Mid Posted 4 days ago Himalayas
What this role involves
About the jobMercor connects elite creative and technical talent with leading AI research labs.
Read the full description
Security Principal Information Security Engineer

Principal-level security engineer who designs and implements information security strategies and solutions for a banking organization.

Lead Posted 4 days ago Himalayas
What this role involves
Make banking a Fifth Third betterÂŽ We connect great people to great opportunities.
Read the full description
Security Offensive Security Engineer

Conducts security testing, perimeter monitoring, and reconnaissance across external domains, websites, and IP infrastructure.

Mid Posted 4 days ago Himalayas
What this role involves
Role OverviewThe Offensive Security Engineer owns the security testing, continuous perimeter monitoring, and reconnaissance across all Sporty Group external domains, websites, public IP blocks, and DNS configurations.
Read the full description
Security Staff Security Engineer, Application Security at NinjaTrader

Staff Security Engineer leads application security initiatives, works with engineering teams to build secure systems, and drives security automation and developer enablement.

Lead Posted 5 days ago RemoteFirstJobs Product
What this role involves

Disclaimer:Please be advised that the most accurate and up-to-date information about our open roles—including job descriptions, compensation, and benefits—can only be guaranteed on our official job board. For the latest listings and details, please visit: https://job-boards.greenhouse.io/ninjatrader.

JOIN US ON OUR MISSION TO BECOME THE #1 RETAIL TRADING PLATFORM IN THE WORLD

Welcome to the dynamic world of NinjaTrader! As an industry-leading trading platform and futures broker, we’re empowering traders to take control of their financial destiny. How do we do it? We provide cutting-edge products and services that enhance the trading journey. Whether a seasoned pro or just starting out, NinjaTrader equips traders with award-winning software and brokerage services to navigate the world’s leading financial markets with confidence.

Our growth story is nothing short of exhilarating. Since 2003, NinjaTrader has been dedicated to understanding and supporting traders on their journey toward trading triumph. Through those efforts, our user base has grown to over 2 million users and we have become the number one rated futures brokerage worldwide.

But we’re not stopping there. We’re constantly evolving, pushing boundaries, and modernizing the futures industry. Our commitment to innovation means users will always have access to dynamic tools, real-time support, and a community of like-minded traders.

So, why work at NinjaTrader? Here, you’re not just part of a team; you’re part of a movement. We empower employees to reach new heights in their careers by providing a dynamic culture focused on social connection, professional development, and employee recognition initiatives. Sounds too good to be true? Take it from our employees.

Join us as we redefine what’s possible in trading, advocate for our customers, and continue our journey toward becoming the world’s top retail-focused trading platform in the world.

What you’ll do:

We’re looking for aStaff Security Engineer, Application Securityto help scale and mature our security program. You’ll own key security domains and initiatives end-to-end, working closely with engineering to ensure systems are secure by design. This role is highly hands-on, with opportunities to drive meaningful impact through automation, secure design, and developer enablement. You’ll operate with significant autonomy while partnering with senior engineers and security leadership to scale security across the organization.

In this role you will:

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security
  • Drive improvements in security coverage, prioritization, and remediation workflows
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows
  • Provide actionable, pragmatic guidance that helps teams ship securely
  • Develop and improve security tooling and automation to reduce manual effort
  • Implement and tune tools for SAST, SCA, DAST, dependency security, and container security
  • Leverage AI/LLMs where appropriate to improve triage, detection, and review processes
  • Triage and prioritize vulnerabilities using risk-based approaches
  • Partner with teams to ensure timely remediation of critical issues
  • Help define and improve SLAs, metrics, and reporting
  • Conduct threat modeling, design reviews, and security assessments
  • Contribute to incident response and postmortems for security events
  • Identify and help remediate systemic risks

What you’ll need:

  • 7+ years of experience in Application Security, Product Security, or Security Engineering
  • Strong hands-on experience with threat modeling and secure design
  • Experience with vulnerability management and application security tooling
  • Experience working in cloud-native environments such as AWS and GCP
  • Experience integrating security into CI/CD pipelines and developer workflows
  • Ability to write code in Python, Go, or similar languages for automation and tooling
  • Strong ability to work cross-functionally with engineering teams

Bonus points for:

  • Experience scaling security in a high-growth or late-stage startup
  • Familiarity with AI-driven security workflows or automation
  • Background in API security, data protection, or multi-tenant systems
  • Experience with bug bounty programs and penetration testing
  • Security certifications such as CISSP

Compensation:

The salary range for this role will be $210,000.00 - $260,000.00 USD. In addition, this position will also receive an annual target bonus of 12%. Bonus pay at NinjaTrader is based on individual performance (50%) as well as company/team performance (50%).

Salary and bonus earnings are only two components of the total compensation package offered by NinjaTrader. NinjaTrader offers a 401K plan through ADP under which the company will match up to 3.5% of employee contributions. Annual paid time off allowance accrues at a rate of23 days per year(some positions may qualify for more) plus seven paid holidays.

Location:

This role is based in Chicago, IL. *There may be remote flexibility for exceptional candidates in the following states: California, Colorado, Florida, Georgia, Illinois, Indiana, Minnesota, Missouri, Montana, New Jersey, New York, North Carolina, Ohio, Oregon, Pennsylvania, South Carolina, Texas, Utah, Vermont, Virginia, Washington, Washington DC, Wisconsin.

Hybrid:

For Chicago-based employees, we follow a hybrid work schedule: In-office Tuesday through Thursday, with remote work on Mondays and Fridays. In addition to these weekly remote days, we offer:

  • 20 additional flex remote days annually
  • 5 Company Wide Office-Optional weeks tied to major holidays

Our Core Benefits Include:

  • Generous PTO
  • 7 Paid Holidays Annually + 5 Conditional Holidays Annually
  • 1 Service Day Annually
  • 401k with 3.5% Company Match
  • Paid Parental Bonding Leave
  • Health, Vision, Dental Coverage
  • Life and Disability Insurance Covered 100% by NinjaTrader

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender, gender identity or expression, or veteran status. We are proud to be an equal opportunity workplace.

Read the full description
Security Principal Security Field Engineer at Databricks

Principal Security Field Engineer who meets with customers to solve security and compliance questions, creates technical content, and builds scalable enablement resources for Databricks' data platform.

Senior Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

RDQ327R177

While candidates in the listed location(s) are encouraged for this role, candidates in other US locations will be considered.

The Security Field Engineering team helps data teams solve the world’s toughest problems by empowering customers to understand the security of the Databricks platform and by helping account teams address questions that come up during security reviews. Reporting to the Head of Security Field Engineering, you will meet with customers to answer questions, train other Databricks team members, build customer-facing content such as slide decks, white papers, and maybe write code that customers can use. Our team prioritizes scale – we’d rather spend an hour building a doc than be in ten hours of meetings, rather deliver agent skills and knowledge base articles than be the rock star answering all the questions. If you want high growth, autonomy, and to touch all elements of security, look no further.

The impact you will have:

  • You will be viewed as a security expert as you work with field teams and customers to understand architectures, address concerns and handle compliance questions
  • Your contributions may come in multiple ways, including customer interactions, scalable slides or white paper creation, internal enablement, process improvement, automation, or technical leadership—no one excels in every area, but all are valuable
  • When you’re on the call, you will be directly appreciated. When you’re not, your impact will be felt across the company through the enablement, collateral, knowledge management, and systems you build
  • You might not come from an assurance team, but you’ll come up to speed with common security and compliance regimes to save customers hours of effort and months of uncertainty
  • You will identify customer pain points and work with product management and product marketing will improve our product and our messaging
  • You will contribute to internal-facing services and automation that make life easier for our field staff and our customers.
  • You are probably already great at AI productivity, but you’ll sit in a group focused on becoming legendary.

What we look for:

  • 5+ years of technical pre-sales or post-sales experience where you’re the person in the room explaining the hard concepts
  • Equal love of understanding complex security principles and architectures, and of communicating them simply
  • Real-world experience in multiple security domains such as IaaS+PaaS+SaaS, network and endpoint security, web applications, vulnerability management, identity management, and SIEM, though not all are needed
  • You’ve done some scripting or programming, and are excited to use AI relentlessly to scale our impact across many thousands of customers and employees.
  • Understanding of the Databricks platform is a strong plus.

Pay Range Transparency

Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles.  Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above. For more information regarding which range your location is in visit our page here.

Zone 1 Pay Range

$270,300—$371,700 USD

Zone 2 Pay Range

$243,300—$334,500 USD

Zone 3 Pay Range

$229,800—$315,900 USD

Zone 4 Pay Range

$216,200—$297,350 USD

About Databricks

Databricks is the data and AI company. More than 10,000 organizations worldwide — including Comcast, Condé Nast, Grammarly, and over 50% of the Fortune 500 — rely on the Databricks Data Intelligence Platform to unify and democratize data, analytics and AI. Databricks is headquartered in San Francisco, with offices around the globe and was founded by the original creators of Lakehouse, Apache Spark™, Delta Lake and MLflow. To learn more, follow Databricks on Twitter, LinkedIn and Facebook.

BenefitsAt Databricks, we strive to provide comprehensive benefits and perks that meet the needs of all of our employees. For specific details on the benefits offered in your region click here.

Our Commitment to Diversity and Inclusion

At Databricks, we are committed to fostering a diverse and inclusive culture where everyone can excel. We take great care to ensure that our hiring practices are inclusive and meet equal employment opportunity standards. Individuals looking for employment at Databricks are considered without regard to age, color, disability, ethnicity, family or marital status, gender identity or expression, language, national origin, physical and mental ability, political affiliation, race, religion, sexual orientation, socio-economic status, veteran status, and other protected characteristics.

Compliance

If access to export-controlled technology or source code is required for performance of job duties, it is within Employer’s discretion whether to apply for a U.S. government license for such positions, and Employer may decline to proceed with an applicant on this basis alone.

Read the full description