Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Senior Cloud Security Engineer at Alloy

Secures Alloy’s AWS cloud environment by managing CSPM and SIEM tooling, improving permissions and networks, investigating incidents, and remediating infrastructure risks.

Senior Hybrid Posted 8 days ago RemoteFirstJobs Product
What this role involves

Alloy is where you belong!

Alloy is the AI-powered identity and fraud prevention platform that accelerates onboarding, stops fraud, and scales compliance across the customer lifecycle so financial organizations can grow without limits. More than 900 of the world’s leading financial institutions and fintechs trust Alloy for smarter risk management that drives growth.

Through our values: Be Bold, Go Fast, Collaborate, and Celebrate Our Differences, we are creating a workplace where you can grow, thrive, and belong. See how we’ve been continuously recognized and named one of Inc. Magazine’s Best Workplaces, Forbes America’s Best Startup Employers, Best Fintech to Work for by American Banker, year after year.

Check out our investors and read more about us here.

About the team

Product Security covers application security and cloud security at Alloy. Our customers are banks and fintechs, so the state of our security program is not an internal matter. It shows up in client due diligence, in what we can sell, and in whether deals close. The team is small and the program is still being matured, which means the person in this seat shapes how engineering across the company designs and ships infrastructure rather than inheriting someone else’s finished playbook.

Alloy operates in a hybrid-work environment. We look to foster collaboration and community by having our local employees onsite three days a week.

What you’ll be doing

You’ll own the security of Alloy’s AWS environment and the tooling that keeps it visible. You will work closest with the Infrastructure team, but your reach will extend to every engineering team.

  • Partner with the Infrastructure team to build security into new cloud infrastructure as it is designed, and act as the security point of contact for new builds
  • Lead initiatives you scope yourself to reduce cloud infrastructure risk in ways that are repeatable and maintainable
  • Build alerts, detections, and dashboards in our CSPM and SIEM, and write the runbooks that make them actionable for the people who get paged
  • Own CSPM findings end to end, from triage through remediation, including the Terraform changes that fix the problem at its source
  • Drive AWS permissions and network design toward least privilege, and debug both without widening the attack surface in the process
  • Join the on-call rotation, investigate security incidents to root cause, and put controls in place so the same incident does not recur

Who we’re looking for

Must-haves:

  • 3+ years in cloud security, or in cloud infrastructure with a security focus, primarily in AWS
  • Hands-on with AWS networking and security services: VPC design, security groups, NACLs, WAF, GuardDuty, Config, Inspector, KMS, and IAM
  • Provisioning infrastructure as code with Terraform and working knowledge of Kubernetes or EKS
  • Working experience with a SIEM and a CSPM, including tuning alerts and building detections that engineers act on
  • Scripting or programming in Python or TypeScript, with an eye for where the code itself creates risk
  • On-call incident response experience, and the ability to explain risk and remediation to engineers who do not work in security

Nice-to-haves:

  • AWS Organizations and multi-account environments
  • AWS Solutions Architect Associate or AWS Security Specialty
  • Public key infrastructure and applied cryptography

Alloy is committed to fair and equitable compensation practices. Below is the anticipated starting base compensation range for this role; however, pay may vary depending on job-related knowledge, in-demand skills, relevant experience, and/or geography. In addition to a competitive base salary, this position is also eligible for equity awards in the form of stock options (ISOs) as well as a competitive total benefits package. Your recruiter will be happy to walk you through the details and what compensation could look like for you specifically!

This position has a salary range of $163,000 - $206,000.

Benefits and Perks

  • Unlimited PTO and flexible work policy
  • Employee stock options
  • Medical, dental, vision plans with HSA (monthly employer contribution) and FSA options
  • 401k with 100% match up to 4% of annual employee compensation
  • Eligible new parents receive 16 weeks of paid parental leave
  • Home office stipend for new employees
  • Annual Learning & Development annual stipend
  • Well-being benefits include access to ClassPass, OneMedical, UrbanSitter, and Spring Health
  • Hybrid work environment: employees are expected to work Tuesdays through Thursdays from our HQ in Union Square, Manhattan. Tasty lunches catered from a variety of local restaurants and frequent employee-organized cultural events contribute to our positive office energy. On Monday/Friday most employees Zoom into work from home while some take advantage of the quieter office.

How to apply

Apply right here! You’ve found the application!

Alloy is proud to be an equal-opportunity workplace and employer. We’re committed to equal opportunity regardless of race, color, ancestry, religion, gender, gender identity, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, disability, or veteran status. We are committed to an inclusive interview experience and provide reasonable accommodations to applicants with visible and invisible disabilities. We encourage applicants to share needed accommodations with their recruiter.

All Alloy jobs are listed on our careers page. Any communication during the recruitment process, including interview requests or job offers, will come directly from a recruiting team member with an alloy.com email address. We do not use outside applications or automated text messaging in our recruiting process. We will not ask for any sensitive financial or identification information during the recruiting process. If you’re ever unsure, please contact us directly via our website before sharing personal information.

Read the full description
Security Senior Cloud Security Engineer at Alloy

Secures Alloy’s AWS environment by managing cloud security tooling, detections, permissions, infrastructure risks, and incident response.

Senior Hybrid Posted 8 days ago RemoteFirstJobs Product
What this role involves

Alloy is where you belong!

Alloy is the AI-powered identity and fraud prevention platform that accelerates onboarding, stops fraud, and scales compliance across the customer lifecycle so financial organizations can grow without limits. More than 900 of the world’s leading financial institutions and fintechs trust Alloy for smarter risk management that drives growth.

Through our values: Be Bold, Go Fast, Collaborate, and Celebrate Our Differences, we are creating a workplace where you can grow, thrive, and belong. See how we’ve been continuously recognized and named one of Inc. Magazine’s Best Workplaces, Forbes America’s Best Startup Employers, Best Fintech to Work for by American Banker, year after year.

Check out our investors and read more about us here.

About the team

Product Security covers application security and cloud security at Alloy. Our customers are banks and fintechs, so the state of our security program is not an internal matter. It shows up in client due diligence, in what we can sell, and in whether deals close. The team is small and the program is still being matured, which means the person in this seat shapes how engineering across the company designs and ships infrastructure rather than inheriting someone else’s finished playbook.

Alloy operates in a hybrid-work environment. We look to foster collaboration and community by having our local employees onsite three days a week.

What you’ll be doing

You’ll own the security of Alloy’s AWS environment and the tooling that keeps it visible. You will work closest with the Infrastructure team, but your reach will extend to every engineering team.

  • Partner with the Infrastructure team to build security into new cloud infrastructure as it is designed, and act as the security point of contact for new builds
  • Lead initiatives you scope yourself to reduce cloud infrastructure risk in ways that are repeatable and maintainable
  • Build alerts, detections, and dashboards in our CSPM and SIEM, and write the runbooks that make them actionable for the people who get paged
  • Own CSPM findings end to end, from triage through remediation, including the Terraform changes that fix the problem at its source
  • Drive AWS permissions and network design toward least privilege, and debug both without widening the attack surface in the process
  • Join the on-call rotation, investigate security incidents to root cause, and put controls in place so the same incident does not recur

Who we’re looking for

Must-haves:

  • 3+ years in cloud security, or in cloud infrastructure with a security focus, primarily in AWS
  • Hands-on with AWS networking and security services: VPC design, security groups, NACLs, WAF, GuardDuty, Config, Inspector, KMS, and IAM
  • Provisioning infrastructure as code with Terraform and working knowledge of Kubernetes or EKS
  • Working experience with a SIEM and a CSPM, including tuning alerts and building detections that engineers act on
  • Scripting or programming in Python or TypeScript, with an eye for where the code itself creates risk
  • On-call incident response experience, and the ability to explain risk and remediation to engineers who do not work in security

Nice-to-haves:

  • AWS Organizations and multi-account environments
  • AWS Solutions Architect Associate or AWS Security Specialty
  • Public key infrastructure and applied cryptography

Alloy is committed to fair and equitable compensation practices. Below is the anticipated starting base compensation range for this role; however, pay may vary depending on job-related knowledge, in-demand skills, relevant experience, and/or geography. In addition to a competitive base salary, this position is also eligible for equity awards in the form of stock options (ISOs) as well as a competitive total benefits package. Your recruiter will be happy to walk you through the details and what compensation could look like for you specifically!

This position has a salary range of $163,000 - $206,000.

Benefits and Perks

  • Unlimited PTO and flexible work policy
  • Employee stock options
  • Medical, dental, vision plans with HSA (monthly employer contribution) and FSA options
  • 401k with 100% match up to 4% of annual employee compensation
  • Eligible new parents receive 16 weeks of paid parental leave
  • Home office stipend for new employees
  • Annual Learning & Development annual stipend
  • Well-being benefits include access to ClassPass, OneMedical, UrbanSitter, and Spring Health
  • Hybrid work environment: employees are expected to work Tuesdays through Thursdays from our HQ in Union Square, Manhattan. Tasty lunches catered from a variety of local restaurants and frequent employee-organized cultural events contribute to our positive office energy. On Monday/Friday most employees Zoom into work from home while some take advantage of the quieter office.

How to apply

Apply right here! You’ve found the application!

Alloy is proud to be an equal-opportunity workplace and employer. We’re committed to equal opportunity regardless of race, color, ancestry, religion, gender, gender identity, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, disability, or veteran status. We are committed to an inclusive interview experience and provide reasonable accommodations to applicants with visible and invisible disabilities. We encourage applicants to share needed accommodations with their recruiter.

All Alloy jobs are listed on our careers page. Any communication during the recruitment process, including interview requests or job offers, will come directly from a recruiting team member with an alloy.com email address. We do not use outside applications or automated text messaging in our recruiting process. We will not ask for any sensitive financial or identification information during the recruiting process. If you’re ever unsure, please contact us directly via our website before sharing personal information.

Read the full description
Security Senior Systems Engineer - Application Security at Cloudflare

Builds and maintains application security systems and products such as WAF, Page Shield, and API Shield at internet scale.

Senior Hybrid Posted 9 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available locations: Amsterdam, Netherlands, Brussels, Belgium, Lisbon, Portugal, London, UK, Munich, Germany, Paris, France, Sweden, Switzerland. This role requires two days in office, it is not a fully remote role.

About The Team

Application Security is responsible for Cloudflare’s fast-growing security product portfolio including WAF, Page Shield, Web Asset Management and API Shield. Being part of Cloudflare means working at internet scale and we are uniquely positioned to tackle challenging problems related to being connected to more networks, websites and customers than any other provider worldwide. Working at great scale by default (to an extent not offered by most other employers in big tech) means pushing boundaries well beyond what commodity solutions like Nginx and Kafka provide out of the box. You’ll be working with custom components that have been created in an engineering-driven and pragmatic way - our code is well-tested and documented and uses modern ecosystems like Go and Rust. This gives you confidence that you will spend your time having an impact and not firefighting!

You’d be joining a high-profile part of the business that can really accelerate and support your career. Cloudflare has a strong track record of growing in a thoughtful way and hires carefully so we’re confident that you will enjoy working with your colleagues here!

About You

You must have at least 5 years of professional experience working hands-on as a software developer. We require proficiency with at least one of Go or Rust, plus exposure to devops tooling like but not limited to Kubernetes, Salt, Kafka or Systemd. Strong Linux / Unix fundamentals will be very helpful. You must have experience working with distributed systems at scale. Experience with cyber security is preferred but not essential.

Cloudflare’s culture is busy and multifaceted, and people who succeed here are persistent, have a can-do attitude and a genuine willingness to assume good faith in others. This last quality in particular requires them to be empathetic and emotionally intelligent, so you’re someone willing to take responsibility for the culture and environment that you create around you.

What You’ll Do

  • Design systems and write code following bleeding edge industry best practices and help others on the team do the same. Review RFCs, technical specifications and code.
  • Deploy and maintain live software-based services at scale (up to 100m requests / second, 1m customers). Take regular shifts as part of the team’s On Call rota.
  • Support and grow other Engineers through knowledge sharing.
  • Keep up to date with trends in detecting current and emerging security risks to web applications and provide input on how these impact Cloudflare’s products.
  • Work with Engineers and Product Managers outside your immediate team in communicating our roadmap and getting things done.

Benefits

Cloudflare offers a positive and stimulating place to work, where you can enjoy friendly relationships with your colleagues and the freedom to have real impact on our products and customers. While the work is demanding, the company is unusual in offering an unlimited leave policy. This is not a “race to the bottom” or proxy for reducing the amount of leave taken; leaders around the company model the behaviour of always taking the time off that they need.

In addition to a competitive base salary, Cloudflare offers an equity program with stock grants on joining and regular refreshers linked to performance. And in common with other big tech companies, we offer medical and dental insurance, mental health support, a tax efficient defined contributions pension plan and life insurance.

Compensation

Compensation may be adjusted depending on work location.

Lisbon Estimated Base salary $66,000 - $91,000.

Equity

This role is eligible to participate in Cloudflare’s equity plan.

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security Security Analyst III (Afternoons) at Deepwatch

Monitors and investigates cybersecurity threats in a managed security operations center during an afternoon shift.

Senior Hybrid Posted 9 days ago RemoteFirstJobs Product
What this role involves

Come join Deepwatch’s team of world-class cybersecurity professionals and the brightest minds in the industry. If you’re ready to challenge yourself with work that matters, then this is the place for you. We’re redefining cybersecurity as one of the fastest growing companies in the U.S. – and we have a blast doing it!

Who We Are

Deepwatch is the leader in managed security services, protecting organizations from ever-increasing cyber threats 24/7/365. Powered by Deepwatch’s cloud-based security operations platform, Deepwatch provides the industry’s fastest, most comprehensive detection and automated response to cyber threats together with tailored guidance from dedicated experts to mitigate risk and measurably improve security posture. Hundreds of organizations, from Fortune 100 to mid-sized enterprises, trust Deepwatch to protect their business.

Our core values drive everything we do at Deepwatch, including our approach to tackling tough cyber challenges. We seek out tenacious individuals who are passionate about solving complex problems and protecting our customers. At Deepwatch, every decision, process, and hire is made with a focus on improving our cybersecurity solutions and delivering an exceptional experience for our customers. By embracing our values, we create a culture of excellence that is dedicated to empowering our team members to explore their potential, expand their skill sets, and achieve their career aspirations, which is supported by our unique annual professional development benefit.

Deepwatch recognition includes:

  • 2025, 2024, 2023, 2022 and 2021 Great Place to WorkÂŽ Certified
  • 2026, 2025, 2024, 2023, 2022 Forbes America’s Best Startup Employers
  • 2025 Cybersecurity Breakthrough Award: Managed Security Solution of the Year
  • 2025 CRN Security 100 - Top 20 Endpoint and Managed Security Companies
  • 2024 Military Times Best for Vets Employers
  • 2024 US Department of Labor Hire Vets Gold Award
  • 2024 Cyber Defense Magazine, Global Infosec Awards
  • 2023 LinkedIn Top 50 Startups
  • 2023 InHerSight #1 Cyber Workplace for Women
  • 2023 and 2022 Fortress Cybersecurity Award
  • Backed by premier investors with >$275 Million in growth capital from Goldman Sachs, Vista Equity Partners, Springcoast, Splunk Ventures, and ABS Capital

Security Analyst III

Reports to: SOC Manager

Shift and Location Details:

  • The Shift: Monday to Friday, 2:00 PM to 10:00 PM EST
  • Tampa Hybrid: Expectation is 3 days a week in our Tampa Center of Excellence (your choice of days), and 2 days remote.

Deepwatch is looking for a highly motivated, self-driven, technical analyst dedicated to making a difference in global security by protecting organizations against the most advanced attackers in the world. The Deepwatch Security Operations Center offers opportunities to expand your skill set through a wide variety of experiences, detecting and responding to incidents as they occur in real-time for our customers.

The Deepwatch Security Operations Center is a unique approach to how we support our customers and ultimately provide an experience not found anywhere else. You’ll be an integral part of supporting our customers by understanding their bespoke environment, needs and challenges. You will be playing a key role in supporting some of the top organizations in the world, and have the opportunity to develop your skills by working with the best responders in the industry, your team and your shift!

In this role, you’ll get to:

  • Act as an escalation point  for alert triage processes across security technologies and multiple platforms including Windows, Linux and macOS
  • Provide in depth analysis from escalated requests originating from any team member who needs support
  • Validate suspicious events by performing investigations using SIEM and SOAR technologies
  • Leverage Deepwatch proprietary tooling, OSINT, TTPs and IOCs
  • Act as a key resource for Management, providing opportunities for improvement and actionable recommendations on creating efficiencies
  • Identify gaps in customer environments, data ingested or configuration errors which reduce telemetry quality
  • Collaborate directly with leadership and customers to highlight and resolve security  concerns
  • Provide investigative support to analysts and train others on a regular basis
  • Produce high-quality written and verbal communications, recommendations, and findings to customer management in a timely manner
  • Further hone your skills and capabilities through hands-on experience and the Deepwatch learning & development program
  • Engage in peer review sessions to evolve and enhance analysis quality

To be successful in this role, you’ll need to:

  • Possess strong understanding of cyber security principles, concepts and practices which includes the ability to perform a complete and thorough incident investigation and triage as the final point of escalation
  • Possess comprehensive knowledge of Splunk SIEM, alongside the capability to utilize alternative platforms like Google SecOps or Microsoft Sentinel, ensuring smooth console navigation, optimized query execution for streamlined investigations, and precise alert evaluations
  • Have working knowledge of modern EDR tools like CrowdStrike & SentinelOne, email security, and cloud identity platforms
  • Have confidence to autonomously resolve complex investigations
  • Effectively meet client expectations ensuring action items are tracked to completion while maintaining transparent communication with peers and leadership.
  • Have advanced knowledge of Adversary Tactics, Techniques, & Procedures (TTP), Event Logging, and Event Triage
  • Demonstrate the ability to pivot to other log sources, cloud systems or consoles to perform a comprehensive analysis from multiple data sources.
  • A desire to support others and uplift the program and team through updating training materials and SOPs
  • Hands-on experience utilizing enterprise ticketing systems such as ServiceNow, Jira, or similar case management tools
  • Demonstrate the ability to write well-written reports and analysis that’s thorough, accurate and complete
  • Monitor and manage incoming security alerts against strict operational SLAs
  • Preferred Certifications: Security X,  CySA+,  GCSA, GCIH
  • Experience in an MDR or MSSP environment is highly desirable

Statutory Pay Disclosure

The anticipated base salary range for this role is $95,000 - $105,000 + stock options + benefits. Actual compensation may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level.

ITAR Compliance

This position will have access to customer data and as such is subject to International Traffic in Arms Regulations (ITAR). Upon application, candidates will be asked to confirm that they are a U.S. Person as defined by the following:

  • A citizen of the U.S.;
  • A lawful permanent resident of the United States;
  • A person admitted to the United States as a refugee; or
  • A person that has been granted asylum by the United States government.

The intent of this requirement is not to verify employment eligibility overall, but to ensure compliance with import/export regulations. If you do not meet these requirements, we encourage you to apply for other open roles at Deepwatch. This information will be verified upon offer of employment.

What We Offer:

Deepwatch is excited to provide benefits designed to support team members and their families. Including:

  • Medical, dental, vision, and disability insurance
  • Flexible Time Off (FTO), 12 company holidays, sick leave and 8-Weeks Paid Parental Leave
  • Unique professional development benefits with Annual “development dollars” to support our people growth and development
  • Wellness contests and monthly educational programs
  • 401(K) retirement program
  • Learn more here: Deepwatch Benefits

We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.  Please review our DEI Statement here.

Deepwatch welcomes and encourages applications from people with disabilities and accommodations are available on request for candidates taking part in all aspects of the selection process. Please inform your recruiter or contact recruiting@deepwatch.com for further information.

All Deepwatch employees are expected to:

  • Be interested in and able to work remotely from a home office when not at a corporate office
  • Pass a pre-employment background check in accordance with applicable laws

Deepwatch is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, marital status, sexual orientation, gender identity, genetic information, protected veteran status, or any other characteristic protected by law.  In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.

By submitting your application, you agree that Deepwatch may collect your personal data for recruiting, global organization planning, and related purposes. The Deepwatch Privacy Policy explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Deepwatch’s use of your personal information.

Read the full description
Security Industrial Security Analyst / Facility Security Officer (FSO) at Red Cell Partners

Administers industrial security programs for a cleared defense contractor, ensuring NISPOM compliance and overseeing personnel security, operations security, and visitor control.

Mid Hybrid Posted 15 days ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

About Defcon AI

RESILIENCE IN THE FACE OF DISRUPTION. Defcon AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, Defcon AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

We are seeking an Industrial Security Analyst / Facility Security Officer (FSO) to support and help scale our security program as DEFCON AI’s classified work continues to grow. This individual will play a key role in maintaining compliance with government security requirements while helping build the processes, controls, and culture needed to support a rapidly growing defense technology company.

This is a hybrid position based in McLean, VA, with an expectation of three days per week in the office.

Position Overview

The Industrial Security Analyst / FSO is responsible for the day-to-day administration and oversight of DEFCON AI’s Industrial Security Program. This role ensures compliance with the National Industrial Security Program Operating Manual (NISPOM), customer requirements, and internal security policies while supporting employees, leadership, and external security partners.

The ideal candidate has experience supporting industrial security programs within a cleared contractor environment and is comfortable operating in a fast-paced organization where security processes continue to evolve and mature.

What You’ll Do

Industrial Security & Compliance

  • Support day-to-day industrial security operations across multiple disciplines, including Personnel Security (PERSEC), Operations Security (OPSEC), Contract Security, Security Education, Training and Awareness (SETA), Visitor Control, Investigations, and Document Control
  • Ensure compliance with NISPOM, ICD requirements, customer security requirements, and internal security policies
  • Maintain readiness for DCSA, customer, and internal security inspections and compliance reviews
  • Conduct self-inspections, identify areas for improvement, and implement corrective actions
  • Support the ongoing development and maturation of DEFCON AI’s industrial security program

Personnel & Program Security

  • Process and manage personnel security requirements, including clearance actions, visit requests, visit authorizations, and onboarding activities
  • Maintain personnel security records and related databases
  • Investigate security incidents and violations and ensure proper reporting and resolution in accordance with government and company requirements
  • Provide security guidance and support to employees, consultants, and approved visitors
  • Support contract security requirements, including DD Form 254 administration and subcontractor security management

Classified Information Protection

  • Maintain classified material accountability programs and secure storage requirements
  • Conduct inventories and maintain accountability of classified information and assets
  • Ensure proper marking, handling, transmission, storage, transportation, sanitization, reuse, and destruction of classified information and media
  • Support the protection of classified facilities, systems, and information in accordance with applicable regulations

Security Training & Program Development

  • Develop and administer Security Awareness, Annual Refresher, and OPSEC training programs
  • Create and maintain required security documentation, including SOPs, OPSEC plans, CONOPS, security procedures, and work instructions
  • Promote a culture of security awareness and compliance throughout the organization

Security Systems & Inspection Readiness

  • Maintain records and security actions within NISS, DISS, and other government security systems as required
  • Support DCSA, customer, and internal inspections and audits
  • Assist with corrective action implementation and continuous process improvement initiatives

Required Qualifications

  • Bachelor’s degree and 6+ years of industrial security or related experience; OR Master’s degree and 4+ years; OR Associate’s degree and 8+ years; OR High School diploma and 12+ years of relevant experience

  • Active U.S. Government Top Secret security clearance and ability to obtain and maintain SCI and SAP access

  • Strong knowledge of NISPOM (32 CFR Part 117), ICD security requirements, and industrial security compliance standards

  • Understanding and familiarity of DD-254 implementation requirements including issuing Subcontract DD-254 using NI2

  • Experience supporting personnel security, classified material control, and compliance programs within a cleared contractor environment

  • Experience utilizing government security systems such as NISS, DISS, or similar platforms

  • Strong organizational, communication, and problem-solving skills

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Outlook

Preferred Qualifications

  • Experience serving as an FSO, AFSO, or Industrial Security Specialist within a cleared facility
  • CDSE FSO Program Management Certification for Processing and/or Non-Possessing Facilities
  • Experience supporting multiple classified programs and government customers
  • Experience preparing for and supporting DCSA or other government inspections
  • Knowledge of DD Form 254 requirements and subcontractor security administration
  • Experience supporting SCI and/or SAP programs
  • Experience building, improving, or scaling security processes within a growing organization
  • Strong customer service skills and the ability to build trusted relationships with internal and external stakeholders
  • Ability to work independently, manage competing priorities, and thrive in a fast-paced environment

Why DEFCON AI

At DEFCON AI, you’ll help build and scale security capabilities that directly support critical national security missions. You’ll work alongside a mission-driven team developing AI-powered solutions for some of the Department of War’s most complex operational challenges.

What We Offer:

  • A fully remote environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $120,000-$150,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits (may differ for each incubation):

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security Cybersecurity Compliance Analyst (Hybrid - Bay Area) at Xantrion

Analyzes client cybersecurity controls, develops compliance documentation, and assesses vendor security risks using frameworks like NIST CSF and CIS Controls.

Mid Hybrid Posted 15 days ago RemoteFirstJobs Product
What this role involves

If you’re looking to join a winning information technology team and receive outstanding benefits that support your family—while working for a company that takes a people-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.

Location: San Francisco Bay Area

Hybrid: 2 days in office / 3 days remote per week

Primary Purpose and Function

Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.

This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.

Travel: None required.

Roles and Responsibilities

Client Compliance and Documentation

  • Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
  • Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
  • Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
  • Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
  • Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
  • Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
  • Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
  • Maintain annual testing schedules and track documentation, review dates, and follow-up items.
  • Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
  • Improve reusable templates and assessment procedures that support consistent delivery across clients.

Internal Compliance Support

  • Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
  • Organize audit documentation, maintain request trackers, and follow up with internal control owners.
  • Review evidence for completeness and consistency and identify missing or outdated documentation.
  • Provide seasonal support during internal audit preparation and review periods.

Position Requirements

Required Qualifications

  • Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
  • Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
  • Experience reviewing technical configurations or administrative reports against documented standards.
  • Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
  • Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
  • Ability to distinguish documented policies from evidence that controls are implemented and operating.
  • Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
  • Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
  • Professional communication skills and sound judgment when handling confidential client information.

Preferred Qualifications

  • Experience supporting registered investment advisers (RIAs) or other financial services organizations.
  • Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
  • Experience working for a managed service provider or supporting multiple client environments.
  • Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
  • Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
  • Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
  • Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
  • Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
  • A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.

Performance Metrics

The Cybersecurity Compliance Analyst performance success will be based on the following criteria:

  • Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
  • Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
  • Risk registers, crosswalks, and supporting documentation remain organized and current.
  • Internal audit requests are tracked and supported with complete, accessible evidence.
  • Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.

Physical Demands

  • Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
  • Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
  • Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
  • Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
  • Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
  • Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
  • Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
  • Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
  • Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion’s office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.

Company Policy and Procedure Compliance

  • Follow and support company policies and procedures as well as all local, state, and federal laws.
  • Always maintain confidentiality of company and customer records and information.
  • Maintain a professional image, adhering to Xantrion’s dress code.
  • Must have an existing cell phone (running current Android or iOS).
  • If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance.  See the Xantrion Handbook for details.

When Working Remote

  • Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
  • Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
  • Must use Xantrion-provided PC and headset to execute job functions.

Benefits

  • Salary range $100-120K; depending on experience.
  • 100% of medical, dental, and vision for you and your family.
  • 401K with company match up to 4% of salary.
  • Certification reimbursement and annual training budget.
  • 17 Days PTO per year in addition to paid training days.
  • Bonuses for referring new clients or employees.

Equal Opportunity Employer

Xantrion is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, age, color, sex, religion, sexual orientation, national origin, disability, medical condition, genetic information, pregnancy, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws. All employment is decided on the basis of qualifications, merit, and business needs at the time.

AI Disclosure for Recruitment

We use AI to support our recruiting team, improve the candidate experiences, and allow our teams to spend more time on meaningful candidate interactions. Our use of AI is limited to administrative tasks such as organizing application information and taking or summarizing interview notes. AI does not screen, advance, or reject candidates, and it does not make hiring or any significant decisions. Applications and candidate qualifications are reviewed by our recruiting team, and all decisions about interviews, advancement, offers, and hiring are made by our recruiters and hiring managers.

Read the full description
Security Security Assistant at Assystem

Supports personnel security operations by processing vetting applications, monitoring clearances, liaising with external agencies, and maintaining security compliance controls.

Junior Hybrid Posted 18 days ago RemoteFirstJobs Product
What this role involves

Company Description

Today, Assystem is among the top three independent nuclear engineering firms worldwide. With over 60 years of experience in highly regulated sectors, the group supports public and industrial stakeholders in the execution of complex and strategic infrastructure projects, subject to high safety and security requirements.

Assystem mobilizes 8,000 experts in 13 countries and intervenes across the entire project lifecycle, in engineering, project management and digital solutions.

Job Description

🔐 Security Assistant

Reporting to the Personnel Security Manager, the Security Assistant will support the company’s Personnel Security activities, with a focus on security vetting, aftercare and security compliance.

📍 Location: Bolton

🏢 Working pattern: Hybrid – 2–3 days per week in the office

🔹 Key Responsibilities

🛡️ Process vetting applications for staff and contractors, providing guidance on all types of vetting.

🔄 Monitor security clearances and ensure renewals are completed promptly.

📋 Communicate changes to vetting policies and procedures.

🤝 Liaise with external agencies and verify internal and external clearances.

🔎 Conduct thorough checks and maintain effective Personnel Security controls.

💬 Act as the main contact for vetting and security enquiries, handling information sensitively and in line with data protection requirements.

🚨 Support security incident reporting, follow-up actions and lessons learned.

📁 Provide security support for key projects.

🎫 Manage site-specific security responsibilities, including issuing site passes.

📢 Support the wider Security Department with general security activities, communications and awareness campaigns.

Qualifications

🎓 Essential Experience & Qualifications

💻 Experienced user of Microsoft Office, particularly Word and Excel

⭐ Desirable Experience

🛡️ Previous experience in a similar security role

🎓 DISA Training

👤 Person Specification

⏰ Reliable and dependable

🚀 Self-motivated and proactive

🤝 Honest and trustworthy

📋 Well organised

🎯 Able to meet deadlines and prioritise workload

🔎 Methodical and accurate

🔐 Able to gain and maintain the appropriate security clearance

Additional Information

Due to the nature of work to be undertaken applicants will be required to meet certain residency criteria in order to attain a minimum level of UK security clearance if not already security cleared to a minimum SC level.

NOTICE TO CANDIDATES ON RECRUITMENT FRAUD - We are committed to safeguarding candidates from fraudulent activity associated with our recruitment process. Please note that we will never offer specialist CV writing services, request payment or ask for sensitive personal information during the recruitment process.

We are committed to equal treatment of candidates and promote, as well as foster all forms of diversity within our company. We believe that bringing together people with different backgrounds and perspectives is essential for creating innovative and impactful solutions. Skills, talent, and our people’s ability to dare are the only things that matter !. Bring your unique contributions and help us shape the future.

Read the full description
Security Security engineer, application security at WRITER

Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.

Mid Hybrid Posted 26 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description
Security Security engineer, application security (UK) at WRITER

Builds security foundations for enterprise AI systems by conducting threat modeling, designing secure architectures, and embedding security controls across the platform.

Mid Hybrid Posted 26 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our London office, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • 4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

🍩 Benefits & perks (UK full-time employees):

  • Generous PTO, plus company holidays

  • Comprehensive medical and dental insurance

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Competitive pension scheme and company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation and company stock options

Read the full description
Security Security engineer, application security at WRITER

Builds application security foundations for enterprise AI systems, conducting threat modeling, designing secure architectures, and embedding security controls across the platform.

Mid Hybrid Posted 26 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

    • *This role is open to Mid, Sr. and Staff level candidates

🍩 Benefits & perks (US Full-time employees)

  • Generous PTO, plus company holidays

  • Medical, dental, and vision coverage for you and your family

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Flexible spending account and dependent FSA options

  • Health savings account for eligible plans with company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation, company stock options and 401k

WRITER is an equal-opportunity employer and is committed to diversity. We don’t make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.

By submitting your application on the application page, you acknowledge and agree to WRITER’s Global Candidate Privacy Notice.

Read the full description
Security Security engineer, application security (UK) at WRITER

Security engineer builds and maintains application security controls, threat models AI systems, and embeds security practices across the enterprise AI platform.

Mid Hybrid Posted 26 days ago RemoteFirstJobs Product
What this role involves

🚀 About WRITER

WRITER is where the world’s leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And we’re proving it’s possible – through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITER’s end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their company’s data and fueled by WRITER’s enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.

Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and we’re looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.

📐 About the role

This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you’ll be building the security foundations that protect the AI systems powering some of the world’s most recognizable brands. You’ll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.

The opportunity is massive: you’ll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isn’t about saying “no”—it’s about finding creative ways to say “yes, and here’s how we do it securely.” You’ll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didn’t exist a few years ago.

This role is hybrid from our London office, reporting to the head of security engineering.

🦸🏻‍♀️ What you’ll do

  • Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day one—not after the fact

  • Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production

  • Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default

  • Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..

  • Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products

  • Lead security assessments and penetration testing of WRITER’s applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale

  • Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents

  • Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks

⭐️ What you need

  • 4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systems—bonus points if you’ve worked in fast-growing startups or high-growth environments

  • Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.

  • Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications

  • Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practices—you know which tools to use and when automation beats manual review

  • Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiences—you can explain why something matters and motivate teams to action

  • A builder’s mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecks—you understand that security enables the business, not blocks it

  • Alignment with WRITER’s values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of what’s possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)

🍩 Benefits & perks (UK full-time employees):

  • Generous PTO, plus company holidays

  • Comprehensive medical and dental insurance

  • Paid parental leave for all parents (16 weeks)

  • Fertility and family planning support

  • Early-detection cancer testing through Galleri

  • Competitive pension scheme and company contribution

  • Annual work-life stipends for:

    • Wellness stipend for gym, massage/chiropractor, personal training, etc.

    • Learning and development stipend

  • Company-wide off-sites and team off-sites

  • Competitive compensation and company stock options

Read the full description
Security DevSecOps Engineer (DoD Secret | Hybrid) at Rackner

Configures and maintains CI/CD pipelines and DevSecOps tools to ensure compliance with DoD security controls while supporting software development teams.

Senior Hybrid Posted 29 days ago RemoteFirstJobs Product
What this role involves

Senior DevSecOps Engineer

Location: Hybrid. ( 2 days/week in College Park, MD)

Clearance: Active DoD Secret Clearance

Employment Type: Full-time

What You’ll Do:

  • You will work on the Forge DevSecOps (DSO) Tools Team as a DevSecOps Engineer.
  • You will configure Pipelines and DevSecOps tools to be compliant with technical controls as defined by the Forge Cyber Guild to receive authorizations.
  • You will work with Software Product teams to help resolve CI/CD Pipeline issues that are reported by Developers.

Required Qualifications and Skillsets

  • Experience designing, administering, and troubleshooting CI/CD pipelines using GitLab CI/CD.
  • Hands-on experience installing, configuring, securing, scaling, and maintaining GitLab Runners across Linux-based and/or containerized environments.
  • Experience building and maintaining applications using common build/package tools, such as Maven, Gradle, npm, pip, NuGet, Make, or similar tools appropriate to supported development languages.
  • Experience integrating containerized applications and services is Kubernetes.

Desired Qualifications and Skillsets

  • Experience with the NAVSEA Afloat Software Authorization Pathway (ASAP) process
  • Experience working on Gov Cloud infrastructure with Accredited DOD (Unclassified and Classified) Networks
  • Experience administering instances of: Gitlab, SonarQube, Anchore, and Artifactory

Who We Are:

  • Rackner is a cloud-native software consultancy delivering solutions for startups, enterprises, and the public sector.
  • We enable digital transformation through DevSecOps, AI/ML, and cloud-first innovation.
  • Join a team that thrives on solving high-impact problems and delivering secure, scalable solutions for the Department of Defense and federal health programs.

Why You’ll Love Working Here:

  • Weekly Pay & Hybrid (2 days/week)
  • Professional Growth – Paid certifications and training for relevant technologies
  • Comprehensive Benefits – 401k (100% match up to 6%), PTO, medical/dental/vision, life & disability insurance
  • Work-Life Perks – Gym/fitness membership, home office setup, swag, snacks, and social events

Hashtags for Visibility

#DevSecOps #Kubernetes #Terraform #AWSGovCloud  #ClearanceJobs #RacknerCareers #FederalTech #CloudEngineering #hybrid

Read the full description
Security Vercel: GRC Analyst

Manages compliance with security and privacy frameworks (ISO 27001, SOC 2, HIPAA, PCI DSS), maintains internal controls, and collaborates across teams to ensure regulatory adherence.

Mid Hybrid Posted 29 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote - United States

About Vercel:

Vercel is the agentic infrastructure company. We free people and agents to ship what’s next.

For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create products that help builders move from idea to production with speed, security, and exceptional developer experience.

Now, software is entering a new era, and the next generation of products will not just be used by people. They will be built, extended, and operated by agents.

We are building the platform for that future, trusted by companies like OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide. Whether you’re building our products, supporting our customers, growing our community, or shaping our story, you’ll help define what comes next.

About the role:

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks, policies, procedures, and commercial assessments, including ISO 27001, SOC 2, HIPAA, PCI DSS, and more. Your role will be instrumental in ensuring that our company operates ethically, responsibly, and in accordance with regulatory requirements.

You will collaborate with cross-functional teams to promote a culture of accountability and integrity throughout the organization and foster an environment where everyone understands the importance of adhering to established guidelines and ethical practices. You will report to the Head of GRC and will be located ((remote, onsite, hybrid)).

Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics.

If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.

What you will do:

  • Collaborate with internal teams to maintain an effective suite of internal controls and driving remediation efforts to completion with clear documentation of progress.
  • Build strong working relationships across the business so compliance accountability is shared and stakeholders are informed.
  • Streamline annual audits by managing audit deliverables, developing treatment plans, and coordinating across teams to document and track completion to ensure audit success.
  • Monitor and improve controls, processes, and evidence management practices, identify opportunities to automate and streamline GRC operations, and contribute to controls maturity scoring and reporting
  • Enable go-to-market teams and accelerate deal cycles by supporting security questionnaires, addressing compliance inquiries, and maintaining clear, customer-facing documentation on Vercel’s security and compliance posture.
  • Design and manage company training and enhance visibility on compliance-specific topics for internal stakeholders to ensure an understanding of compliance, ethics, and regulatory requirements within the organization.

About you:

  • At least 3 years of relevant experience in supporting the audit lifecycle in a cloud-centric environment (SOC 2, ISO 27001, PCI, HIPAA, etc.), with strong organizational skills to be flexible and proactive in a high-growth, start-up environment.
  • Experience collaborating closely with internal partners to seamlessly incorporate policies and technical controls into the SDLC.
  • Strong project management skills and sense of ownership with the ability to communicate and collaborate effectively, and execute projects across various business units and levels.

Bonus if you have :

  • Strong experience with cloud infrastructure (e.g., Azure, AWS)
  • Familiarity with compliance or software development tools and systems (e.g., Drata, Linear, Datadog, etc.)
  • Experience with frontend development and open source components
  • Relevant industry certifications (i.e., CISM, CISSP, CCEP) is a plus, but not required

Benefits:

  • Competitive compensation package, including equity.
  • Inclusive Healthcare Package.
  • Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
  • Flexible Time Off.
  • We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.

The San Francisco, CA base pay range for this role is $134,000-$202,000. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.

 

To apply: https://weworkremotely.com/remote-jobs/vercel-grc-analyst

Read the full description