Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Coinbase: Regional Threat Assessment Manager

Lead threat assessment and case management for a region, conducting behavioral threat evaluations and coordinating security response across organizational stakeholders.

Senior Remote Posted about 13 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Australia

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$200,900—$200,900 AUD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases for employees and facilities, conducts behavioral threat analysis, and coordinates security incident response across regional operations.

Senior Remote Posted about 13 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - EMEA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):£95,490—£106,100 GBP
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-1

Read the full description
Security Coinbase: Regional Threat Assessment Manager

Manages threat assessment cases end-to-end, conducts behavioral threat assessments, coordinates incident response, and partners cross-functionally to mitigate security risks to employees, executives, and facilities.

Senior Remote Posted about 13 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - Singapore

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

We're hiring a Regional Threat Assessment Manager to join the Protective Intelligence program within Coinbase's Security organization. This team protects Coinbase employees, executives, facilities, and operations by identifying, assessing, and mitigating threats through intelligence-led case management and structured behavioral assessment. You'll serve as the regional lead and subject matter expert for Threat Assessment and Management, owning complex and sensitive threat cases end-to-end while partnering with GSOC, Executive Protection, Legal, HR/ER, Insider Threat, and other stakeholders to drive coordinated response and help mature the program's regional capabilities.

What you'll do:

  • Own end-to-end threat case management for your region, from intake, triage, and behavioral assessment through mitigation planning, documentation, and closure for threats impacting employees, executives, facilities, and other Coinbase assets.
  • Lead structured behavioral threat assessments using Coinbase methodologies and accepted frameworks (e.g., JACA, WAVR-21, CTAP-25) to evaluate motivation, capability, escalation indicators, and stabilizers, then translate findings into clear operational recommendations.
  • Drive intelligence-led incident response by serving as the intelligence lead during active incidents, coordinating with GSOC, ensuring timely escalation, and delivering decision support through resolution.
  • Partner cross-functionally with Executive Protection, GSOC, Legal, HR/ER, Insider Threat, and Communications to coordinate response actions, align mitigations, and manage reporting obligations.
  • Produce decision-ready briefings, written assessments, and executive updates that communicate threat posture, risk rationale, and recommended next steps to security leadership and cross-functional partners.
  • Strengthen regional program maturity by improving intake standards, QA/QC, playbooks, metrics, training, and handoff processes, and by mentoring peers through expertise and influence.

Required Skills and Experience:

  • 7+ years of progressively responsible experience in threat assessment and management, protective intelligence, workplace violence prevention, behavioral threat assessment, or closely related security functions.
  • Demonstrated track record operating as a senior individual contributor and regional SME, independently owning ambiguous, high-consequence casework with limited oversight while influencing outcomes across teams without direct authority.
  • Proven ability to conduct threat investigations and translate fragmented information into clear assessments, prioritized risks, and practical mitigation plans using structured professional judgment frameworks.
  • Proficiency with case management and intelligence tools (e.g., Ontic, OSINT platforms, public records research, social media monitoring) with a track record of improving processes and tooling to increase signal quality.
  • Experience coordinating with law enforcement, managing investigative referrals, and navigating workplace violence reporting obligations across jurisdictions.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Pay Transparency Notice: The target annual base salary for this position can range as detailed below. Total compensation may also include equity and bonus eligibility and benefits (including medical, dental, and vision).

Annual base salary range (excluding equity and bonus):$212,200—$212,200 SGD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-regional-threat-assessment-manager-2

Read the full description
Security Stripe: Risk Strategist - Screening (Financial Crimes)

Develops and manages global financial crimes screening programs, setting standards for AML/sanctions controls and driving risk management strategy across Stripe's payment infrastructure.

Senior Remote Posted about 13 hours ago We Work Remotely — Programming
What this role involves

Headquarters: US-Chicago; US-Atlanta; US-Remote; Canada-Toronto; Canada-Remote

Who we are

About Stripe

Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world's largest enterprises to the most ambitious startups—use Stripe to accept payments, grow their revenue, and accelerate new business opportunities. Our mission is to increase the GDP of the internet, and we have a staggering amount of work ahead. That means you have an unprecedented opportunity to put the global economy within everyone's reach while doing the most important work of your career.

About the team

The Financial Crimes Risk Strategy team owns our first-line AML and sanctions programs globally. We own the end-to-end lifecycle of financial crime controls. We set the global standards that govern how risk is managed across our programs, design and drive the development of controls, infrastructure, and tooling with Engineering, Product, and Data Science, and maintain their effectiveness as our products and the regulatory landscape evolve. We build fast, with data, and with AI integrated into how financial crime risk is detected, managed, and monitored across everything Stripe builds.

What you'll do

As a Risk Strategist on the Financial Crimes Risk Strategy team, you'll own our global screening programs — spanning sanctions, PEP, and negative news — setting the standards that govern how screening risk is managed, designing and driving the controls that operationalize those standards, and ensuring they remain effective as our products and the regulatory landscape evolve. Being effective in this role means going deep on both the domain and the data — we don't separate the two.

You'll partner closely with Product, Engineering, Data Science, Compliance, Legal, other Risk Strategy functions, and Operations to ensure screening considerations are embedded in every product and market decision. Beyond protecting against risk, you'll drive innovation in how Stripe approaches screening — staying ahead of regulatory change and pushing the boundaries of what effective, scalable financial crime risk management looks like at a global payments company.

Responsibilities

  • Lead our global sanctions and AML screening strategy — setting the standards that drive screening control design and infrastructure development, and translating requirements across OFAC, EU, UN, OFSI, and other applicable regimes, PEP screening, and negative news screening into actionable first-line programs and controls
  • Own the design and ongoing improvement of financial crime controls — including sanctions screening, PEP screening, negative news screening, and digital asset-related safeguards — while continuously improving detection coverage and control performance as our products and the threat landscape evolve
  • Embed screening risk requirements into product and infrastructure roadmaps — ensuring financial crime considerations drive product launches, market expansions, and platform decisions across Product, Engineering, Data Science, Compliance, Legal, and Operations
  • Drive screening infrastructure and tooling forward by owning requirements, leading execution, and maintaining effectiveness metrics for screening systems and controls — building with observability by design and ensuring key performance indicators, key risk indicators, and monitoring thresholds are defined from inception
  • Continuously assess and improve screening controls and systems — identifying gaps, recommending enhancements that strengthen detection effectiveness and anticipate regulatory or ecosystem changes, and leading delivery of those enhancements end-to-end
  • Champion a technology-forward approach to financial crime risk management — leveraging AI tools, self-serve data analytics, and model governance best practices to improve how risk is detected, monitored, and managed at Stripe
  • Stay informed on industry practices and regulatory developments and represent our sanctions and AML programs to regulators, bank and network partners, and external auditors

Who you are

We're looking for someone who meets the minimum requirements to be considered for the role. If you meet these requirements, you are encouraged to apply. The preferred qualifications are a bonus, not a requirement.

Minimum requirements

  • 7+ years of professional experience in financial services, payments, or fintech, with at least 5 years in a related role (risk, compliance, or product enablement)
  • Deep subject matter expertise in global sanctions compliance, including hands-on experience with OFAC, EU sanctions regimes, UN Security Council designations, OFSI, and other major global frameworks
  • Demonstrated strong understanding of screening program design and control execution
  • Strong AML screening expertise — proven ability to design, implement, and operationalize PEP screening and negative news screening programs in complex, multi-jurisdiction environments
  • Proven ability to design, implement, and operationalize financial crime standards and controls in complex, global organizations
  • Familiarity with model governance concepts — including model documentation, performance monitoring, and validation — and experience leading or contributing to model governance activities

Preferred qualifications

  • Experience leading transformative AML, Sanctions, or Transaction Monitoring initiatives, including global screening program design or transformations (e.g., vendor selection, watchlist management, false positive tuning)
  • Proficiency with SQL and ability to independently mine and analyze data to develop risk insights and inform strategy
  • Experience with crypto or digital asset products and their associated financial crime risk and regulatory considerations
  • Advanced degree or professional certifications (e.g., CAMS, CGSS, CFCS)

To apply: https://weworkremotely.com/remote-jobs/stripe-risk-strategist-screening-financial-crimes

Read the full description
Security Coinbase: Senior Manager, Internal Audit IT

Lead Coinbase's global IT and security audit program, managing audits across cloud infrastructure, security operations, and risk management while overseeing a distributed team of auditors.

Lead Remote Posted about 13 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - USA

Ready to do the most impactful work of your career? At Coinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase.

As the Senior Manager, Internal IT & Security Audit, you'll lead Coinbase's global IT and security audit program. Reporting to the Head of Internal Audit, you will operate within an independent third line of defense that maintains functional accountability to the Audit Committee. You'll own the multi-year IT and security audit roadmap, ensuring coordinated coverage across all regions (US, EMEA, UK, APAC) and alignment with Coinbase's enterprise risk profile and regulatory expectations. Your leadership will directly strengthen how Coinbase identifies, evaluates, and mitigates technology and security risks across the organization.

What you'll do:

  • Own the end-to-end delivery of complex, cross-functional IT and security audits covering cloud infrastructure, security operations, identity and access management, data protection, vendor/third-party risk, and key products and services.
  • Lead and develop a high-performing global team of internal auditors and co-sourced resources, setting goals, coaching talent, managing performance, and building succession pipelines across regions.
  • Drive integrated assurance across the three lines of defense by partnering with first and second line risk, compliance, security, and technology teams to rationalize testing and maximize control coverage.
  • Shape executive-level reporting on technology and security control effectiveness, distilling key themes, emerging risks, and root causes into clear materials for senior management, the Head of Internal Audit, and the Audit Committee.
  • Partner with technology and security leadership across Engineering, Security, Infrastructure, and Product to provide independent challenge on major initiatives (e.g., cloud migrations, new product launches, architecture changes) without compromising third-line independence.
  • Build continuous improvement into the audit function by driving adoption of data analytics, automation, and generative AI to modernize IT and security audit execution, including continuous monitoring and automated evidence retrieval.

Required Skills and Experience:

  • 12+ years of experience in internal audit with deep focus on IT and information security, or in first-line / second-line technology/security roles with significant controls and audit exposure.
  • Demonstrated success leading global, cross-functional IT audit portfolios spanning cloud, infrastructure, cybersecurity, and third-party risk across multiple regulatory jurisdictions (US, EMEA, APAC).
  • Deep technical knowledge of cloud-based technology stacks, software development lifecycles, cloud security configurations, and enterprise IT operations risks and controls.
  • Relevant professional certifications (e.g., CISA, CISSP, CIA, CPA) and working fluency with frameworks such as NIST, COBIT, and ITIL.
  • Proven leadership experience building, mentoring, and managing global audit teams, including co-sourced resources and indirect reports across time zones.
  • Utilizes generative AI responsibly, maintaining human oversight to deliver business-ready outputs and drive measurable improvements in workflow efficiency, cost, and quality.

Req ID: #P76564

#LI-Remote

 

 

Pay Transparency Notice: Base salary varies by location (see range below). Total compensation may also include equity and bonus eligibility, and benefits (medical, dental, vision, 401(k)). 

 

Annual base salary range (excluding equity and bonus):$201,365—$236,900 USD
  • Application Limit: Candidates may submit a maximum of 3 applications within a 6-month period.
  • Equal Opportunity Employer: Coinbase is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or genetic information. Applicants with criminal histories will be considered consistent with applicable federal, state, and local laws.
  • US Applicants: View Employee Rights, Know Your Rights, and E-Verify Notice of Participation.
  • Accommodations: If you are an individual with a disability who needs a reasonable accommodation, email us your request and contact info at accommodations[at]coinbase.com. Need screen reading technology? Click here to download a free compatible screen reader and view the tutorial.
  • Data Privacy & Arbitration: By submitting your application, you agree to our Candidate Privacy Notice. US applicants: By submitting your application, you agree to Arbitration of Disputes.

To apply: https://weworkremotely.com/remote-jobs/coinbase-senior-manager-internal-audit-it

Read the full description
Security Oracle Cloud Security Engineer

Implements and maintains security infrastructure on Oracle Cloud Platform, managing access controls, compliance, and threat detection.

Mid Remote Posted about 21 hours ago Himalayas
What this role involves
Oracle Cloud Security Engineer – Remote Bright Vision Technologies is a technology consulting and software development company delivering cloud, AI, data, and enterprise solutions across the United States.
Read the full description
Security Security Engineer at Corbalt

Integrates security into the software development lifecycle, identifies vulnerabilities, and builds automation tools to improve security practices across engineering teams.

Mid Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Corbalt

Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems. We build shared platforms, engineering foundations, and reusable services that enable mission teams to deliver software faster, operate more efficiently, and scale with confidence.

Our roots trace back to the Healthcare.gov recovery effort, where we saw firsthand what talented, mission-driven teams could accomplish together. That experience shaped how we work today: solving complex technical challenges through collaboration, pragmatic engineering, and a relentless focus on delivering value.

Today, we support critical healthcare modernization efforts at the Centers for Medicare & Medicaid Services (CMS), helping build and operate the platforms, tools, and services that enable teams across Medicare and Medicaid to deliver secure, resilient digital experiences.

We’re a remote-first team that values curiosity, kindness, ownership, and continuous learning. We enjoy solving hard technical problems, partnering closely with our clients, and building technology that makes government work better for the people who rely on it.

Contingent Position: This position is contingent upon Corbalt’s successful contract award. Employment offers and start dates are dependent on the award of the associated government contract.

Security Engineer

We’re looking for a Security Engineer who enjoys building secure software, improving engineering platforms, and helping teams deliver with confidence. You’ll work closely with software engineers to integrate security into the development lifecycle, automate security practices, and build resilient cloud-native systems that support critical government services.

Responsibilities

  • Integrate security into the software development lifecycle through automation, testing, and continuous improvement.
  • Identify, investigate, and remediate application and infrastructure vulnerabilities.
  • Develop tools and automation in Python, Go, or Terraform that improve security, developer productivity, and operational visibility (it’s not important that you know these languages).
  • Support security assessments, compliance activities, and continuous monitoring.
  • Contribute to security best practices across engineering teams.

Skills

  • Strong software engineering fundamentals and experience writing production code.
  • Experience with application security, DevSecOps, or cloud security.
  • Understanding of secure software design, authentication/authorization, and common application vulnerabilities.
  • Familiarity with at least one commonly used programming language and one infrastructure-as-code language.
  • Strong communication and collaboration skills with engineering and technical stakeholders.

Experience

  • 3+ years of engineering experience
  • Demonstrated ability to operate independently and ramp quickly in complex environments
  • Experience supporting security assessments, compliance, or continuous monitoring in regulated environments
  • Familiarity with federal cloud and security requirements (e.g., FISMA)
  • Demonstrated experience operating and analyzing systems in AWS, Azure, or Google Cloud.

Values

  • Growth-oriented mindset
  • Intrinsic motivation to learn, grow, and do great work
  • Kindness
  • Grit / perseverance / resilience

Compensation & Benefits

The base salary range for this position is: $138,677 - $182,296 per year.

In addition to the base salary, Corbalt offers:

  • Medical, dental, vision benefits
  • Profit sharing and discretionary bonuses
  • A company 401(k) contribution equal to 3% of your salary
  • Paid vacation, sick time, and company holidays
  • Reimbursement for reasonable expenses that are helpful for work
  • In-person company retreats

Hiring Process

  • The first stage is an informal conversation to learn more about each other, answer questions, and discuss the role.
  • The second stage is a mini-project based on something we’ve actually worked on. The goal of this is to get an idea of what working together is like.
  • The last stage is: a 10-20 minute presentation to the team describing what you did on a previous project and two 30 minute conversations with other people on the team to get an additional perspective on what our work is like.

Other Requirements

  • Due to contractual requirements applicants must:
    • Be authorized to work in the United States
    • Currently reside in the United States or its territories
    • Have resided in the United States or its territories for three of the last five years
    • Have at least three years of professional experience
  • Due to contractual and security requirements, all work must be performed while physically present within the United States or its territories. Work performed while outside the U.S. or its territories is strictly forbidden.
  • Corbalt participates in E-Verify. Upon hire, your Form I-9 information will be provided to the federal government to confirm you are authorized to work in the United States.

Corbalt is an Equal Opportunity Employer, including disability and protected veteran status.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Engineer, Application Security at GameChanger

Embeds security practices throughout the software development lifecycle, conducts code reviews, maintains secure coding standards, and integrates security tooling into CI/CD pipelines.

Mid Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

About GameChanger:

We believe in the life changing impact youth sports have on and off the field. Sports encourage leadership, teamwork, responsibility, and confidence – important life lessons that have the power to propel our youth toward meaningful futures. We recognize that without coaches, parents, and volunteers, organized youth sports could not exist. By building the first and best place to experience the youth sports moments important to our community, we are helping families elevate the next generation through youth sports.

So if you love sports and their community building potential, or building cool products is your sport, GameChanger is the team for you. We are a remote first, dynamic tech company based in New York City, and we are solving some of the biggest challenges in youth sports today.

The Position:

We’re looking for a Security Engineer to join our InfoSec team and become the primary security partner for our software engineering organization. Reporting to the Security Engineering Manager, you’ll operate application security across the SDLC, champion secure design and development practices, and bring DevSecOps discipline to how we build and ship software. This is a high-impact, highly collaborative role. You’ll work closely with platform and product engineers to make security a part of how we build and deliver. You will also be a member of our weekly on-call rotation.

What You’ll Do:

Application security

  • Embed security into every phase of the SDLC

  • Champion security requirements for the responsible and secure integration of Gen AI and agentic AI tools within our product stack

  • Conduct security-by-design engagements for new features, APIs, platform initiatives, and infrastructure changes

  • Perform secure code reviews providing engineers with clear, actionable findings and remediation guidance

  • Partner with architecture and platform teams to establish secure API patterns (REST and GraphQL)

  • Contribute to and maintain secure coding guidelines, API security standards, and security architectural patterns that serve as the “paved roads” for all engineering teams

  • Give useful code review feedback, write documentation that outlasts the ticket, and run the occasional workshop or lunch-and-learn for engineers

DevSecOps

  • Integrate and maintain security tooling across CI/CD pipelines

  • Enforce security quality gates in delivery pipelines

  • Harden the CI/CD platform components, including configuration and hardening of GitHub Actions and runner environments

  • Identify opportunities to leverage AI for increasing engineering productivity and agentic security workflows

  • Work alongside DevOps engineers to ensure cloud infrastructure is defined and deployed securely via IaC (terraform, k8s)

  • Implement and validate security controls for containerized workloads

  • Support the implementation of application-layer network security controls, such as Web Application Firewalls (WAFs) and CDN security, to protect application endpoints

Vulnerability & Risk Management

  • Operate the application vulnerability management lifecycle

  • Triage and prioritize findings from our sources (including; GHAS, NowSecure, Wiz, BugCrowd, penetration tests) by business impact and exploitability

  • Proactively identify systemic risks and facilitate cross-functional initiatives to address root causes

  • Track security-specific KPIs (e.g., MTTR, vulnerability density, and security coverage of CI/CD pipelines) and translate them into actionable insights for engineering and business leadership

  • Effectively communicate security risk clearly to both engineering and business leaders

What You’ll Bring:

  • 3+ years in application security engineering

  • Proven experience building and operating internal security developer platforms or tooling that reduces developer friction

  • Demonstrated ability to use AI/ML-driven tools to enhance security effectiveness and scalability

  • Hands-on experience leading threat modeling engagements and designing paved roads

  • Proven track record integrating security tooling into CI/CD pipelines

  • Working knowledge of OWASP Top 10s (web, mobile, API, LLM)

  • Hands-on experience securing deployments in AWS with container and Kubernetes security, IaC scanning, and policy-as-code approaches

  • Demonstrated expertise in security-by-design in TypeScript, Swift, and/or Kotlin

  • Track record of implementing secure primitives in mobile ecosystems (iOS/Android)

  • Beneficial certifications: AWS Certified Security Specialty, CKS, GWEB, GMOB, or equivalent.

Who You Are:

  • Pragmatic defender. You understand that security must enable the business, not block it. You look for “secure by default” solutions and know how to make the right path the easy path for engineers.

  • Force multiplier. You don’t solve every security problem yourself. You coach, document, and build systems that make the engineers around you more secure by default.

  • Clear communicator. You can trace a BOLA vulnerability chain to a frontend engineer and translate the same risk into business terms for a VP; and you know which conversation you’re in.

  • Automation-first. If you have to do it twice, you’d rather write the script.

  • Long-view oriented. You think about medium-to-long-term system health, not just the current sprint, and you proactively address root causes rather than patching symptoms repeatedly.

  • Collaborative and cross-functional. You bring product, business, and operational context into your security decisions, not just security best practices in isolation.

  • Approachable. You foster open dialogue, encourage diverse perspectives, and make it easy for engineers to surface security concerns without fear of judgment or friction.

Perks:

  • Work remotely throughout the US* or from our well-furnished, modern office in Manhattan, NY.

  • Unlimited vacation policy.

  • Paid volunteer opportunities.

  • Technology stipend - $4,000 every 2 years after your start to make sure you have the latest and greatest technology.

  • WFH stipend - $500 annually to make your WFH situation comfortable.

  • Monthly physical, mental, wellness & learning stipend offered through Holisticly.

  • Monthly lifestyle stipend offered through Fringe.

  • Full health benefits - medical, dental, vision, prescription, FSA, HRA, HSA, and coverage for family/dependents.

  • Retirement savings - Traditional and Roth 401K plans are offered through Vanguard, with an immediate company match.

  • Life insurance - basic life, supplemental life, and dependent life.

  • Disability leave - short-term disability and long-term disability.

  • Company paid parental leave - up to 20 weeks for birthing parents and up to 12 weeks for non-birthing parents.

  • Family building benefits offered through Progyny.

  • DICK’S Sporting Goods and their family of brands teammate discount.

The target salary range for this position is between $120,000 and $140,000. This is part of a total compensation package that includes incentive, equity, and benefits for eligible roles. Individual pay may vary from the target range and is determined by several factors including experience, internal pay equity, and other relevant business considerations. We constantly review all teammate pay to ensure a great compensation package that is fair and equal across the board.

\* DICK’S Sporting Goods has company-wide practices to monitor and protect the company from significant compliance and monetary implications as it pertains to employer state tax liabilities. Due to said guidelines put in place, we are unable to hire in AK, DE, HI, IA, LA, MS, MT, OK, and SC.

We are an equal opportunity employer and value diversity in our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

IMPORTANT NOTICE: All official recruitment communications from GameChanger will come from an email address ending in @gc.com or no-reply@ashby.hq.com. If you receive communication from any other domain, please be cautious, as it is likely fraudulent.

Read the full description
Security WAF Services Expert

Administers and optimizes Web Application Firewall (WAF) infrastructure, manages rulesets, and coordinates with application teams on security configurations.

Mid Remote Posted 2 days ago Himalayas
What this role involves
This is a remote position. WAF Services ExpertLocation: RemotePeriod: 01/11/2026 to 31/12/2027Utilisation: Part-time (TBC - approx 36-45% utilisation depending on confirmed period)Contract type: Contract / freelanceKey Responsibilities• Administration of the WAF • WAF ruleset management • WAF platform optimisation according to vendor recommendations and best practice • Liaising with relevant application teams for WAF rule optimisation • Development of customised WAF rules • Documentation of all changes in WAF environments • Monthly activity reports RequirementsEligibility• You must already hold the right to work in the EU, EEA or Switzerland Requirements• Fluent English • Proven experience administering Azure WAF in a production environment • Strong communication skills for liaising with cross-functional application teams BenefitsAs a freelancer / contractor with us, you will enjoy flexible working hours and the freedom to choose your own projects.
Read the full description
Security Insider Risk Analyst (Remote, GBR)

Analyzes and monitors insider threats and suspicious user behavior to mitigate security risks within an organization.

Mid Remote Posted 3 days ago Himalayas
What this role involves
As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations.
Read the full description
Security Security Specialist – EMEA (location flexible)

Manages security operations, incident response, and compliance for a cloud infrastructure company serving enterprise customers across EMEA regions.

Mid Remote Posted 3 days ago Jobicy AI
What this role involves
About ClickHouse Recognized on the 2025 Forbes Cloud 100 list, ClickHouse is one of the most innovative and fast-growing private cloud companies. With more than 4,000 customers and ARR that...
Read the full description
Security Associate Offensive Security Consultant at SpecterOps

Conducts offensive security assessments, penetration tests, and red team operations for enterprise clients while developing tools and training materials.

Junior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for an Associate Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Associate Consultant - $100,000 - $125,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Associate Consultant:

As an Associate Consultant, your primary responsibility will be to learn. You will engage in, participate in, and contribute to the execution of various services and projects. In doing so, you will develop a foundational understanding of the SpecterOps Adversary Simulation service line and enhance your skills in one or more technical areas.

Desired Qualifications:

  • Foundational knowledge of offensive security concepts and assessments
  • Foundational knowledge of security principles, policies, and industry best practices
  • Working knowledge of Windows and *NIX-based operating systems
  • Working knowledge of networking concepts
  • Working knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Proficient written/verbal communication and interpersonal skills
  • A strong determination to improve both personal skills and the overall information security community through research efforts, including blog posts, conference presentations, open-source tool releases, and white paper publications
  • Willingness to support the delivery of public and private training offerings (e.g. providing lab support, addressing student questions, etc.)

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and quarterly bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $150 monthly cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Offensive Security Consultant at SpecterOps

Conducts offensive security assessments, penetration tests, and red team operations for enterprise clients while developing tools, training team members, and communicating findings to stakeholders.

Mid Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for an Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Consultant - $120,000 - $150,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Desired Qualifications:

  • Working knowledge of offensive security concepts and assessments
  • Working knowledge of security principles, policies, and industry best practices
  • Working knowledge of Windows and *NIX-based operating systems
  • Working knowledge of networking concepts
  • Working knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Proficient written/verbal communication and interpersonal skills
  • Independently contribute to significant services and projects
  • Ability to lead small teams and engagements
  • Ability to manage multiple projects at once
  • Ability to effectively communicate with clients, team members, and management for project delivery
  • Ability to manage client projects with limited supervision
  • Willingness to lead and execute offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, offensive maturity assessment, etc.)
  • Willingness to develop and deliver training content as a lead course instructor
  • Willingness to mentor and train fellow consultants

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and quarterly bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $150 monthly cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Senior Offensive Security Consultant at SpecterOps

Senior consultant conducting offensive security assessments, red team operations, penetration tests, and training team members on adversary tactics and tools.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

SpecterOps is looking for a Senior Offensive Security Consultant to work on the Consulting Services team as operators, trainers, and program developers. The Adversary Simulation service line primarily works in large commercial enterprises conducting offensive security assessment services (red team assessments, penetration tests, offensive maturity assessments, web application tests, and specialty security assessments), supporting internal offensive programs, delivering training courses, and supporting research and development efforts. Our consultants work both onsite and offsite in diverse environments supporting our customers, anywhere from developing toolsets in support of operations to briefing executives.

A successful candidate will have excellent technical skills, impeccable soft skills, and be a well-organized, self-directed individual.

Salary Range: Base salary annually, commensurate with experience.

  • Senior Consultant - $145,000 - $170,000

Location: This position is remote, based in the U.S. with travel quarterly for in person company events and other ad hoc meetings.

  • Candidate must be authorized to work and reside in the United States; we do not currently sponsor immigration visas

Responsibilities

  • Plan and conduct offensive security engagements ranging in size, scope, focus, and approach
  • Effectively communicate findings, attack paths, recommendations, and strategy to technical and executive client stakeholders through written reports and verbal presentations
  • Build scripts, tools, or methodologies to enhance offensive services
  • Serve as a subject matter expert (SME) in one of the following areas: initial access, open-source intelligence analysis, adversary tradecraft, offensive Windows/Linux/macOS operations, evasion operations, or technical capability development
  • Utilize common offensive security testing tools and tradecraft
  • Stay up to date with cutting-edge adversary tradecraft and vulnerabilities
  • Effectively communicate successes and obstacles with fellow team members and team lead(s)
  • Interface with client contact(s) and staff in a constructive and professional manner
  • Coordinate and prepare for internal and customer facing meetings
  • Assist with scoping prospective engagements, participating in technical testing from kickoff through remediation, and mentoring less experienced staff
  • Train team members in adversary Tactics, Techniques, and Procedures (TTPs) and tools
  • Contribute new or improve existing content for SpecterOps training courses and assist in the delivery of course offerings (instruction, lab support, etc.)

Requirements

  • Ability to travel domestically and internationally; up to an average of 25% annually
  • Must be able to pass a criminal background check
  • Desire to embody our core values of passionate curiosity, consistent improvement, empathy, sustainability, humility, and empowerment through transparency

Desired Qualifications:

  • Proficient knowledge of offensive security concepts and assessments
  • Proficient knowledge of security principles, policies, and industry best practices
  • Proficient knowledge of Windows and *NIX-based operating systems
  • Proficient knowledge of networking concepts
  • Proficient knowledge of Active Directory
  • Working knowledge of programming or scripting languages, such as C#/.NET, C++, Python, PowerShell, Bash, etc.
  • Aptitude for technical writing, including assessment reports, presentations and operating procedures
  • Strong written/verbal communication and interpersonal skills
  • A clear expert in one or more service lines and/or technical areas
  • Experience leading small teams and engagements
  • Experience managing multiple projects at once
  • Experience communicating with clients and delivering presentations
  • Experience independently managing client projects
  • Ability to lead and execute majority of offensive security service offerings (e.g., red team, penetration test, web application security assessment, cloud security assessment, offensive maturity assessment, etc.)
  • Willingness to develop and deliver training content as a lead course instructor
  • Willingness to mentor and train fellow consultants

Nice to Haves

  • Bachelor’s degree in a technical field
  • Experience participating in and/or leading Fortune 1000 and/or large Federal Government security assessments
  • Public community contributions (e.g., conference presentations, blog posts, white papers, public tool development)
  • Experience in administering, attacking, or defending Windows/Active Directory, Linux, and/or macOS environments
  • Experience in technical writing
  • Experience working for a service-based information security consultancy
  • Experience developing and/or providing technical training
  • Desire to teach and train students in offensive techniques
  • Desire to travel internationally and domestically on a more frequent basis

What We Offer

  • Health/Dental/Vision/life insurance: 100% covered for both the employee and their family
  • Flexible time off policy
  • 13 paid holidays annually
  • 401(k) with up to 4% company match
  • Equity and bonuses based on company performance
  • Remote work: $1,500 first year allowance to set up home office
  • $500 annual home office allowance after first year
  • $1800 annual cell phone and internet reimbursement
  • $5,000 annual professional development allowance
  • $5,250 towards continuing education or student loan repayment
  • $1,200 annual budget for lifestyle, wellness, pet insurance and more
  • A one-time $10,000 benefit towards family planning
  • Open intellectual property policies; allow researchers to retain rights over open-sourced research & tools
  • In person and virtual employee events throughout the year
  • And of course, company swag!

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. To request reasonable accommodations, please contact us at careers@specterops.io

Unsolicited resumes are not accepted

#LI-REMOTE

Read the full description
Security Freelancer - OSINT/WEBINT Experts

Conducts open-source and web-based intelligence research to identify security threats and risks for trust and safety operations.

Remote Posted 4 days ago Himalayas
What this role involves
DescriptionAlice. io (formerly known as ActiveFence) is a leading trust, safety, and security company.
Read the full description
Security Product Security Engineer III at Carolinas Investment Consulting

Builds secure infrastructure and tools for engineers, combining software development with application security expertise to enable safe healthcare platform scaling.

Senior Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

Our healthcare system is the leading cause of personal bankruptcy in the U.S. Every year, over 50 million Americans suffer adverse financial consequences as a result of seeking care, from lower credit scores to garnished wages. The challenge is only getting worse, as high deductible health plans are the fastest growing plan design in the U.S.

Cedar’s mission is to leverage data science, smart product design and personalization to make healthcare more affordable and accessible. Today, healthcare providers still engage with its consumers in a “one-size-fits-all” approach; and Cedar is excited to leverage consumer best practices to deliver a superior experience.

Location: Remote

Our healthcare system is the leading cause of personal bankruptcy in the U.S. Every year, over 50 million Americans suffer adverse financial consequences as a result of seeking care, from lower credit scores to garnished wages. The challenge is only getting worse, as high deductible health plans are the fastest growing plan design in the U.S.

Cedar’s mission is to leverage data science, smart product design and personalization to securely make healthcare more affordable and accessible. Today, healthcare providers still engage with its consumers in a “one-size-fits-all” approach; and Cedar is excited to leverage consumer best practices to deliver a superior experience.

The Role

The Product Security team at Cedar combines software development with deep application security expertise in order to help build our patient-focused solutions efficiently and safely. As a Product Security Engineer at Cedar, you will work with an inquisitive, diverse, and experienced team on a platform that is rapidly scaling. You’ll help solve problems that matter, affecting tens of millions of patients annually.

Our core tenets include using good judgment and having the autonomy to be successful. Your role will be to build secure, supportable secure paths for other engineers to follow and help accelerate Cedar Engineering’s mission. Whether it’s an improvement on single sign on experience, a smoother UI for credential management, or multi-tenant encrypted vault solutions, Cedar Product Security Engineers build the security tools others need to do their work more safely and more efficiently.

At Cedar, we don’t require experience with particular languages, but deep familiarity with modern and industry-standard technologies, like Python, Go, and Kotlin are a plus.

About You

  • You’re an application security engineer who prioritizes addressing security challenges with technology, not process
  • You love building services and tools that help product and platform engineers build, deploy, and maintain products that help hundreds of millions of people
  • You have experience with security code review, threat modeling or security architecture reviews.
  • You’re proficient in Python, Go, or Kotlin

Bonus Points if you have

  • Familiarity with HIPAA, PCI, and the unique considerations around securing health and payments data
  • Experience creating developer focused security tooling or libraries
  • Participation in security capture-the-flag events

Responsibilities

  • Create and extend services and tools that help product and platform engineers build, deploy, and maintain Cedar products safely and efficiently.
  • Serve as a Security Partner for multiple engineering teams across the SSDLC, evangelizing security and helping threat model features, bake security into designs, and review code and implementations
  • Contribute to security automation projects, such as static analysis, vulnerability management, and asset inventory

What do we offer to the ideal candidate?

  • A chance to improve the U.S. healthcare system at a fast-moving company! Our leading healthcare financial platform is scaling rapidly, helping millions of patients per year
  • Flexibility to work from home or in the office, depending on what works best for you
  • Unlimited PTO for vacation, sick and mental health days–we encourage everyone to take at least 20 days of vacation per year to ensure dedicated time to spend with loved ones, explore, rest and recharge
  • 16 weeks paid parental leave with health benefits for all parents, plus flexible re-entry schedules for returning to work
  • Diversity initiatives that encourage Cedarians to bring their whole selves to work, including three employee resource groups: be@cedar (for BIPOC-identifying Cedarians and their allies), Pridecones (for LGBTQIA+ Cedarians and their allies) and Cedar Women+ (for female-identifying Cedarians)
  • Competitive pay, equity (for qualifying roles) and health benefits that start on your first day
  • 401k plan with 3% employer non-election contribution
  • Access to hands-on mentorship, employee and management coaching, and a stipend for learning and development resources to help you grow both professionally and personally

About us

Cedar was co-founded by Florian Otto and Arel Lidow in 2016 after a negative medical billing experience inspired them to help improve our healthcare system. With a commitment to solving billing and patient experience issues, Cedar has become a leading healthcare technology company fueled by remarkable growth. “Over the past several years, we’ve raised more than $350 million in funding & have the active support of Thrive and Andreessen Horowitz (a16z).

Compensation Range and Benefits

  • Salary/Hourly Rate Range: $157,250-$185,000
  • This role is also bonus and equity eligible
  • This role offers a competitive benefits and wellness package

*Subject to location, experience, and education

What do we offer to the ideal candidate?

  • A chance to improve the U.S. healthcare system at a high-growth company! Our leading healthcare financial platform is scaling rapidly, helping millions of patients per year
  • Unless stated otherwise, most roles have flexibility to work from home or in the office, depending on what works best for you
  • For exempt employees: Unlimited PTO for vacation, sick and mental health days–we encourage everyone to take at least 20 days of vacation per year to ensure dedicated time to spend with loved ones, explore, rest and recharge
  • 16 weeks paid parental leave with health benefits for all parents, plus flexible re-entry schedules for returning to work
  • Diversity initiatives that encourage Cedarians to bring their whole selves to work, including three employee resource groups: be@cedar (for BIPOC-identifying Cedarians and their allies), Pridecones (for LGBTQIA+ Cedarians and their allies) and Cedar Women+ (for female-identifying Cedarians)
  • Competitive pay, equity (for qualifying roles), and health benefits, including fertility & adoption assistance, that start on the first of the month following your start date (or on your start date if your start date coincides with the first of the month)
  • Cedar matches 100% of your 401(k) contributions, up to 3% of your annual compensation
  • Access to hands-on mentorship, employee and management coaching, and a team discretionary budget for learning and development resources to help you grow both professionally and personally

About us

Cedar was co-founded by Florian Otto and Arel Lidow in 2016 after a negative medical billing experience inspired them to help improve our healthcare system. With a commitment to solving billing and patient experience issues, Cedar has become a leading healthcare technology company fueled by remarkable growth. “Over the past several years, we’ve raised more than $350 million in funding & have the active support of Thrive and Andreessen Horowitz (a16z).

As of November 2024, Cedar is engaging with 26 million patients annually and is on target to process $3.5 billion in patient payments annually. Cedar partners with more than 55 leading healthcare providers and payers including Highmark Inc., Allegheny Health Network, Novant Health, Allina Health and Providence.

Read the full description
Security Regional Director - Cybersecurity | Remote, South Central Enterprise

Leads regional cybersecurity strategy and operations for enterprise clients across the South Central US.

Lead Remote Posted 5 days ago Himalayas
What this role involves
This position is Remote and must be based in Texas with a strong preference for candidates located in the Houston or Dallas-Fort Worth Area.
Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer leads application security, vulnerability management, and detection engineering across a global wellness platform, embedding security practices into product development.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Senior Security Engineer | AppSec at Gympass

Senior Security Engineer drives application security, vulnerability management, and detection engineering across a global wellness platform, embedding security into product development and owning security controls end-to-end.

Senior Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Senior Security Engineer| AppSec to our Information Security team in Brazil!  This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our global subscription platform serving millions of users. As a Senior Security Engineer, you will drive software security across our product verticals — starting with application security (secure SDLC, SAST/DAST, secure design reviews) and expanding into adjacent domains like detection engineering, IAM, and vulnerability management. This is a unique opportunity to help build a security engineering program from the ground up in a high-growth environment. You will own a control domain end-to-end in a role that is deliberately generalist — we are looking for someone who reasons deeply about root causes and partners closely with engineering teams to embed security seamlessly into product delivery.

YOUR IMPACT

  • Own core application security services, security tooling (e.g., SAST/DAST, IAM, vulnerability management), and detection pipelines end-to-end.
  • Lead post-incident responses and post-mortems, transforming root-cause findings into concrete guardrails, automation, and policy improvements.
  • Drive security-by-design standards across product development by writing clear RFCs, threat models, and architectural design docs for high-risk projects.
  • Establish and enforce vulnerability remediation SLAs and security metrics, utilizing monitoring tools to hold engineering teams accountable.
  • Execute seamless security-critical migrations and platform updates while preserving data integrity and auditability throughout.
  • Partner with cross-functional teams (Engineering, Legal, Product) to deliver medium-to-large security initiatives while maintaining transparency as scope evolves.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life balance.

WHO YOU ARE

  • An experienced security engineer with prior work experience delivering high-impact security tooling, detection logic, or secure SDLC mechanisms in modern cloud environments.
  • An adaptable and collaborative professional with a willingness to step outside your primary AppSec focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A proactive technical partner with extensive experience in modern cloud architectures and container ecosystems (e.g., AWS/EKS, GCP/GKE, Istio, ArgoCD).
  • A clear, empathetic communicator with fluency in English and Portuguese, able to translate complex technical security risks into actionable guidance for engineers and non-technical stakeholders alike.
  • A pragmatic problem-solver with the ability to balance rigorous security standards against product velocity, making data-informed trade-off decisions.
  • A developer at heart with in-depth knowledge of secure coding practices, proficient in writing clean, well-tested code for security automation.
  • A security champion with familiarity with key governance and compliance frameworks (e.g., SOC 2, ISO 27001, LGPD/GDPR) to inform daily engineering decisions.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement .

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

And to get a glimpse of life at Wellhub… Follow us on Instagram @lifeatwellhub and LinkedIn !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description
Security Staff Security Engineer | AppSec at Gympass

Staff Security Engineer leads application security initiatives across multiple domains including vulnerability management, threat modeling, pentesting, and incident response.

Lead Remote Posted 6 days ago RemoteFirstJobs Product
What this role involves

Your wellbeing, our mission. Join a company shaping a healthier world.

GET TO KNOW US

At Wellhub we’re revolutionizing workplace wellness. Our platform connects employees worldwide to the best partners for fitness, mindfulness, therapy, nutrition, and sleep—all in one simple subscription. Headquartered in NYC with team members in Europe, North America and South America, we’re on a mission to make every company a wellness company.

We believe work should be fulfilling, inspiring, and balanced. Here, you’ll find a team that values wellbeing, collaboration, and different perspectives, where passion and creativity push boundaries to create real impact. Your contributions will help shape a healthier, more balanced world for you and millions of people globally.

Join us in redefining the future of wellbeing!

THE OPPORTUNITY

We are hiring a Staff Security Engineer | AppSec to our Information Security team in Brazil! This is a Remote – Brazil position, meaning you can work from anywhere within the country. Please note that this role is only open to candidates in Brazil.

The Information Security team is responsible for protecting our subscription-based product serving millions of users globally. As a Staff Security Engineer, you will own multiple security domains end-to-end — with your center of gravity in software security (secure SDLC, vulnerability management, threat modeling, pentesting, and red teaming) while reaching across incident response, threat intelligence, cloud security, and compliance as the team’s mandate requires.

You will become the organization’s go-to authority for the hardest, cross-domain security trade-offs — the ones without an obvious owner. By connecting pentest findings, incident root causes, compliance requirements, and cloud misconfigurations into a unified risk strategy, you will shape baseline security standards, mentor engineering teams, and drive medium-to-large strategic initiatives that scale with our growth.

YOUR IMPACT

  • Own multiple security domains end-to-end, serving as the technical authority for complex, cross-service security challenges across the entire organization.
  • Establish secure-by-design architectural standards, lead threat modeling sessions, and set the secure-coding benchmarks that other engineers follow.
  • Drive complex, cross-service incident responses and post-mortems, converting critical findings into systemic guardrails and platform-level preventions.
  • Lead offensive and defensive strategy initiatives—including Red Team exercises and pentest engagements—driving root-cause remediation directly with engineering teams.
  • Ensure organization-wide security posture by setting SLAs, SLOs, and KPIs (remediation windows, response times, posture drift), building the monitoring needed to hold teams accountable.
  • Partner with cross-functional leadership (Engineering, Product, Legal) to align threat intelligence, compliance needs, and long-term security investments with business priorities.

Live the mission: inspire and empower others by genuinely caring for your own wellbeing and your colleagues. Bring wellbeing to the forefront of work, and create a supportive environment where everyone feels comfortable taking care of themselves, taking time off, and finding work-life wellness.

WHO YOU ARE

  • A seasoned security specialist with extensive experience in Security Engineering (or software engineering with high security impact) and a proven track record of scaling security in complex cloud environments.
  • An adaptable professional with a willingness to step outside your primary focus to support other InfoSec contexts—such as Cloud Security, GRC, or Detection—as team priorities evolve.
  • A strategic technical partner with expert knowledge in secure architecture design, threat modeling, and setting engineering-wide secure coding standards.
  • An influential communicator with fluency in English and Portuguese, able to translate intricate security tradeoffs into clear risk statements for executive leadership and product partners.
  • A pragmatic risk navigator with the ability to balance long-term risk reduction against business velocity, making high-stakes decisions independently.
  • A forward-thinking specialist with a deep understanding of attacker TTPs, modern cloud ecosystems (AWS/EKS, GCP/GKE, Istio, ArgoCD), and regulatory frameworks (SOC 2, ISO 27001, LGPD, GDPR).
  • A dedicated mentor with prior work experience guiding and uplifting engineering teams to foster a security-minded engineering culture.

We recognize that individuals approach job applications differently. We strongly encourage all aspiring applicants to go for it, even if they don’t match the job description 100%. We welcome your application and will be delighted to explore if you could be a great fit for our team. For this specific role, please note that prior experience in security engineering is a mandatory requirement.

WHAT WE OFFER YOU

With thoughtful benefits, emotional wellbeing resources, and a culture that empowers you to take ownership of your role and your wellbeing, we create an environment where you can thrive in all dimensions of your life.

Our flexible benefits program allows you to customize some of the benefits, according to your needs!

Our benefits include:

WELLHUB: Free Gold+ membership with access to onsite gyms and studios, digital fitness programs, and online wellness resources for meditation, nutrition, mental wellbeing support, and more! Add up to three family members to your plan, ensuring access to wellness for those who matter most to you.

WELLZ: A complete emotional wellbeing program with a unique approach. It offers personalized journeys that combine individual therapy sessions (52 per year) and on-demand content.

HEALTHCARE: Health, dental, and life insurance.

FLEXIBLE WORK: As a Flexible First company, we offer hybrid and remote options to give you the freedom to work in a way that suits you. The model for this specific role can be discussed with your recruiter and hiring manager. When you join, use our home office reimbursement to set up your home office.

PAID TIME OFF: It’s important to take time away from work to recharge.Employees receive vacations after 6 months and additional 3 days off per year + 1 day off for each year of tenure (up to 5 additional days) + an extra holiday for your birthday!

PAID PARENTAL LEAVE: Welcoming a new child is one of the most special moments in your life. Take the time to be present and enjoy your growing family. We offer 100% paid parental leave to all new parents. Parents giving birth are eligible for an extended leave and a ramp-back period to return part-time while they get settled.

CAREER GROWTH: Access world-class platforms, participate in interactive sessions,  build your personalized development roadmap, and explore internal opportunities. We focus on continuous learning and feedback to support your journey toward personal and professional success.

CULTURE: You’ll join a team of passionate people who come together to break boundaries, support each other, and create a meaningful impact in workplace wellness. We win together, building trust through open communication and a culture where every perspective matters. Learn more about our shared culture and values here.

Want to see what it’s really like to work here? Follow us on Instagram @lifeatwellhub and watch our team video on YouTube !

Diversity, Equity, and Belonging at Wellhub

We aim to create a collaborative, supportive, and inclusive space where everyone knows they belong.

Wellhub is committed to creating a diverse work environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, sex, gender identity or expression, sexual orientation, age, non-disqualifying physical or mental disability, national origin, veteran status, or any other basis covered by appropriate law.

Our commitment to inclusion also extends to how we recognize and reward our people. We’re proud to be Syndio Fair Pay Certified, reflecting our ongoing dedication to equitable and fair pay practices across our global team. Read more about it here.

Questions on how we treat your personal data? See our Aviso de Privacidade para Candidatos.

#LI-REMOTE

#LI-CM1

Read the full description