Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Cyber Leadership and Human Risk - Manager

Manages cybersecurity leadership and human risk initiatives across the security lifecycle.

Mid Posted about 3 hours ago Himalayas
What this role involves
We AreAccenture Security helps organizations prepare, protect, detect, respond, and recover along with all points of the security lifecycle.
Read the full description
Security GRC Analyst

Manages governance, risk, and compliance controls, assessments, policies, and security audits for the organization.

Mid Posted 2 days ago Jobicy AI
What this role involves
About Vercel: Vercel is the agentic infrastructure company, freeing people and agents to ship what’s next. For more than a decade we’ve helped builders move from idea to production with...
Read the full description
Security Security Engineer at Oddball

Secures AWS cloud environments, manages federal ATO and POAM remediation, and implements DevSecOps, CI/CD, IaC, and Zero Trust practices.

Mid Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We’re looking for a Security Engineer to join our SEC team, working alongside our DevSecOps engineers to harden our cloud environment, maintain our ATO, and actively drive down the program’s POAM backlog.

What you’ll be doing:

  • Deploy and automate CI/CD pipelines and establish IaC using modern DevSecOps techniques including serverless and Zero Trust patterns
  • Own the POAM process end to end — develop a plan of attack with target dates, track progress in real time, and close findings proactively
  • Assess incoming security findings, identify duplicates and dependencies, and develop LOEs for remediation
  • Conduct Security Impact Analyses (SIAs) to achieve and maintain ATO
  • Implement data tagging and sensitivity management practices to reduce the SEC’s ATO management burden
  • Engage directly with engineers and external stakeholders to drive remediation forward
  • Maintain a live dashboard and tracker for all security findings and POAM status

What you’ll bring:

  • Hands-on experience remediating POAMs and navigating the federal ATO process

  • Proficiency with AWS environments and cloud security practices

  • Experience with CI/CD pipelines, CloudFormation, and infrastructure as code

  • Familiarity with Zero Trust principles and federal cybersecurity frameworks including FISMA and NIST 800-53

  • Strong organizational skills with the ability to manage multiple findings, timelines, and stakeholders simultaneously

  • Comfortable engaging directly with engineers and external stakeholders to move remediation forward

  • Experience with Docker and containerized environments is a plus

  • Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team

  • Communicates clearly and openly, whether updating a tracker or presenting findings to leadership

  • Performs other related duties as assigned

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s degree

Benefits:

  • Fully remote
  • Annual stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hello@Oddball.io

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $120,000 – $155,000

Read the full description
Security Business Systems Security Analyst at Wrike

Secures Salesforce and other business SaaS systems by managing permissions, integrations, data flows, privacy, and business-continuity risks.

Mid Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.

Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You’ll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we’d love to hear from you.

Our vision: A world where everyone is free to focus on their most purposeful work, together.

About the Role:

You’ll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Salesforce, Marketo, Salesloft, and a growing web of integrated SaaS tools run large parts of Wrike’s business. As that footprint grows, we’re hiring a dedicated analyst to bring stronger visibility, governance, and risk understanding to this business systems estate — partnering closely with the teams who own and use these tools.

Your Impact:

  • Own security for Wrike’s business systems SaaS tools such as Salesforce, Marketo, Salesloft, and the integrations that connect them, covering permissions, sharing rules, connected apps, OAuth scopes, and integrations.
  • Build and maintain clear visibility into what data lives in these systems, why it’s there, and how it flows between integrated tools.
  • Partner with RevOps, Marketing, Legal and others to embed security into how these platforms are configured, extended, and connected to third-party services.
  • Translate security and business-continuity issues into clear, actionable terms for non-technical stakeholders.
  • Ensure business systems handling personal data hold up against privacy frameworks including GDPR and CCPA, in close collaboration with Legal and Compliance.
  • Chase data-flow and permission questions to ground truth which means following through until the answer and its implications are genuinely clear.

Your Qualifications:

Your primary expertise is in Salesforce administration and business systems security. Everything else listed here is context you’ll operate in. Depth in the primary domain matters more than breadth across all of them.

  • Salesforce administration experience with a strong security lens. This means permissions, sharing rules, connected apps, and integration patterns.
  • Solid understanding of how business systems interconnect and why that matters for data exposure and business continuity.
  • Able to communicate issues precisely to both technical and non-technical audiences.
  • Working knowledge of privacy frameworks such as GDPR and CCPA at minimum.

You don’t need to tick every box! We’re looking for depth in business systems security and the drive to grow across the rest.

Standout Qualities:

  • Certified Salesforce Administrator credential.
  • Security+, ISC2 CC, or an equivalent security certification.
  • Experience auditing or governing SaaS-to-SaaS integrations
  • Exposure to data security posture management (DSPM) or data classification in SaaS environments.
  • You use AI as a force multiplier — to move faster, think wider, and go deeper — but your security instincts and judgement are your own. You don’t outsource thinking to a tool.
  • Demonstrated tenacity in chasing complex data flows and access permissions across multi-tool integrations to a definitive answer.

Team Dynamics:

You will be joining Wrike’s 15-member global Security team led by Maksim Pekuryn, Director of Security. You will report directly to Swen Groeneveld, Head of Security Operations, whose 8-person sub-team includes Security Engineers, Application Security, and SOC specialists. You’ll also work closely with cross-functional partners in RevOps, Marketing, and Legal.

Our Work Style:

  • Tech stack: Salesforce, Marketo, Salesloft, OAuth integrations, connected apps, and related business SaaS tooling.
  • Collaborative environment working closely with RevOps, Legal, and Marketing teams.
  • Hybrid mode.

Benefits & Perks:

  • 28 calendar days of paid vacation
  • Sick Leave Compensation (5 Paid Uncertified Sick Days)
  • Parental Leave: 18 Weeks Maternity / 4 Week Paternity
  • 2 Volunteer Days
  • Health Insurance (Employees + Dependents)
  • Life Insurance Plan
  • Utility Allowance (30 EUR/month, subject to taxation)
  • Fitness Plan (800 EUR/year)
  • Full-remote & On-demand access to Co-working space

What’s Next?

  • Recruiter Screen (30 mins)
  • Department Interview / Technical Discussion (60 mins)
  • Cultural Interview with Hiring Manager, CISO, and HRBP

Your recruitment buddy will be Aleksandar Chernev, Senior Technical Recruiter.

#LI-AC1

Who Is Wrike and Our Culture

We’re a team of innovators and creators who solve the complex work problems of today and tomorrow.

Hybrid work mode

Wrike is our people, not a place. With 1,000+ employees collaborating across nearly every time zone, we support talent through 10 global hubs — Australia, Costa Rica, Cyprus, Czechia, Estonia, France, India, Ireland, Japan, and the United States — offering flexible ways of working that include remote work, hybrid environments, and co-working spaces across many locations.

While flexibility looks different across teams and regions, employees located near certain hubs — particularly in Prague (CZ), Nicosia (CY), Bangalore (IN), and Rennes (FR) — are generally expected to collaborate in person around 2–3 days per week, balancing the flexibility of distributed work with opportunities for in-person collaboration and connection.

Our persona

💡  Smart: We love what we do, and we’re great at it because this is our domain. Our combined knowledge in this space is unmatched.

💚  Dedicated: We get up every day focused on helping our customers win. We’re committed to helping our teammates win, too!

🤗  Approachable: We’re friendly, easy to get along with, considerate, and helpful.

Our culture and Values

🤩 Customer-Focused

We care about our customers. We understand the customer journey, experience, and value derived from Wrike. Decision-making and action-taking are done with the customer in mind.

🤝 Collaborative

We work as one and win together, each bringing unique strengths that contribute to diversity of thought for better outcomes. Leveraging our own work management platform, we foster an environment of creative collaboration and shared achievement.

🎨 Creative

We strive to succeed through continuous innovation. It’s our pursuit of novel concepts that helped us create a market category. We continue to cultivate a workplace that fosters creative thinking as a means of transcending conventional boundaries and empowers us to break new ground to deliver extraordinary work management solutions.

đź’Ş Committed

We believe in ownership at all levels of the organization, by owning workflows from start to finish. Each member of our team is an integral part of this commitment, establishing work as a platform for personal growth and transformation, as well as collective success and growth.

Check out our LinkedIn Life Page, Company culture page, Instagram, Wrike Engineering Team, Medium, Meetup.com, Youtube for a feel for what life is like at Wrike.

Read the full description
Security Business Systems Security Analyst at Wrike

Secures Salesforce and other business SaaS systems by managing permissions, integrations, data flows, privacy compliance, and stakeholder risk communication.

Mid Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.

Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You’ll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we’d love to hear from you.

Our vision: A world where everyone is free to focus on their most purposeful work, together.

About the Role:

You’ll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Salesforce, Marketo, Salesloft, and a growing web of integrated SaaS tools run large parts of Wrike’s business. As that footprint grows, we’re hiring a dedicated analyst to bring stronger visibility, governance, and risk understanding to this business systems estate — partnering closely with the teams who own and use these tools.

Your Impact:

  • Own security for Wrike’s business systems SaaS tools such as Salesforce, Marketo, Salesloft, and the integrations that connect them, covering permissions, sharing rules, connected apps, OAuth scopes, and integrations.
  • Build and maintain clear visibility into what data lives in these systems, why it’s there, and how it flows between integrated tools.
  • Partner with RevOps, Marketing, Legal and others to embed security into how these platforms are configured, extended, and connected to third-party services.
  • Translate security and business-continuity issues into clear, actionable terms for non-technical stakeholders.
  • Ensure business systems handling personal data hold up against privacy frameworks including GDPR and CCPA, in close collaboration with Legal and Compliance.
  • Chase data-flow and permission questions to ground truth which means following through until the answer and its implications are genuinely clear.

Your Qualifications:

Your primary expertise is in Salesforce administration and business systems security. Everything else listed here is context you’ll operate in. Depth in the primary domain matters more than breadth across all of them.

  • Salesforce administration experience with a strong security lens. This means permissions, sharing rules, connected apps, and integration patterns.
  • Solid understanding of how business systems interconnect and why that matters for data exposure and business continuity.
  • Able to communicate issues precisely to both technical and non-technical audiences.
  • Working knowledge of privacy frameworks such as GDPR and CCPA at minimum.

You don’t need to tick every box! We’re looking for depth in business systems security and the drive to grow across the rest.

Standout Qualities:

  • Certified Salesforce Administrator credential.
  • Security+, ISC2 CC, or an equivalent security certification.
  • Experience auditing or governing SaaS-to-SaaS integrations
  • Exposure to data security posture management (DSPM) or data classification in SaaS environments.
  • You use AI as a force multiplier — to move faster, think wider, and go deeper — but your security instincts and judgement are your own. You don’t outsource thinking to a tool.
  • Demonstrated tenacity in chasing complex data flows and access permissions across multi-tool integrations to a definitive answer.

Team Dynamics:

You will be joining Wrike’s 15-member global Security team led by Maksim Pekuryn, Director of Security. You will report directly to Swen Groeneveld, Head of Security Operations, whose 8-person sub-team includes Security Engineers, Application Security, and SOC specialists. You’ll also work closely with cross-functional partners in RevOps, Marketing, and Legal.

Our Work Style:

  • Tech stack: Salesforce, Marketo, Salesloft, OAuth integrations, connected apps, and related business SaaS tooling.
  • Collaborative environment working closely with RevOps, Legal, and Marketing teams.
  • Hybrid mode.

Benefits & Perks:

  • 25 calendar days of paid vacation
  • Sick Leave Compensation (5 Paid Uncertified Sick Days)
  • Parental Leave: 18 Weeks Maternity / 4 Week Paternity
  • 2 Volunteer Days
  • Medical Insurance (Employees + Dependents)
  • Hybrid Working Model
  • School Allowance (Up to €600/month for school aged kids)
  • Simcard w/ Unlimited Internet Access for active employees
  • Office Lunch Allowance (via Wolt) on Wednesdays / Thursday

What’s Next?

  • Recruiter Screen (30 mins)
  • Department Interview / Technical Discussion (60 mins)
  • Cultural Interview with Hiring Manager, CISO, and HRBP

Your recruitment buddy will be Aleksandar Chernev, Senior Technical Recruiter.

#LI-AC1

Who Is Wrike and Our Culture

We’re a team of innovators and creators who solve the complex work problems of today and tomorrow.

Hybrid work mode

Wrike is our people, not a place. With 1,000+ employees collaborating across nearly every time zone, we support talent through 10 global hubs — Australia, Costa Rica, Cyprus, Czechia, Estonia, France, India, Ireland, Japan, and the United States — offering flexible ways of working that include remote work, hybrid environments, and co-working spaces across many locations.

While flexibility looks different across teams and regions, employees located near certain hubs — particularly in Prague (CZ), Nicosia (CY), Bangalore (IN), and Rennes (FR) — are generally expected to collaborate in person around 2–3 days per week, balancing the flexibility of distributed work with opportunities for in-person collaboration and connection.

Our persona

💡  Smart: We love what we do, and we’re great at it because this is our domain. Our combined knowledge in this space is unmatched.

💚  Dedicated: We get up every day focused on helping our customers win. We’re committed to helping our teammates win, too!

🤗  Approachable: We’re friendly, easy to get along with, considerate, and helpful.

Our culture and Values

🤩 Customer-Focused

We care about our customers. We understand the customer journey, experience, and value derived from Wrike. Decision-making and action-taking are done with the customer in mind.

🤝 Collaborative

We work as one and win together, each bringing unique strengths that contribute to diversity of thought for better outcomes. Leveraging our own work management platform, we foster an environment of creative collaboration and shared achievement.

🎨 Creative

We strive to succeed through continuous innovation. It’s our pursuit of novel concepts that helped us create a market category. We continue to cultivate a workplace that fosters creative thinking as a means of transcending conventional boundaries and empowers us to break new ground to deliver extraordinary work management solutions.

đź’Ş Committed

We believe in ownership at all levels of the organization, by owning workflows from start to finish. Each member of our team is an integral part of this commitment, establishing work as a platform for personal growth and transformation, as well as collective success and growth.

Check out our LinkedIn Life Page, Company culture page, Instagram, Wrike Engineering Team, Medium, Meetup.com, Youtube for a feel for what life is like at Wrike.

Read the full description
Security Business Systems Security Analyst at Wrike

Secures Salesforce and other business SaaS systems by managing permissions, integrations, data flows, privacy, and business continuity risks.

Mid Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.

Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You’ll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we’d love to hear from you.

Our vision: A world where everyone is free to focus on their most purposeful work, together.

About the Role:

You’ll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Salesforce, Marketo, Salesloft, and a growing web of integrated SaaS tools run large parts of Wrike’s business. As that footprint grows, we’re hiring a dedicated analyst to bring stronger visibility, governance, and risk understanding to this business systems estate — partnering closely with the teams who own and use these tools.

Your Impact:

  • Own security for Wrike’s business systems SaaS tools such as Salesforce, Marketo, Salesloft, and the integrations that connect them, covering permissions, sharing rules, connected apps, OAuth scopes, and integrations.
  • Build and maintain clear visibility into what data lives in these systems, why it’s there, and how it flows between integrated tools.
  • Partner with RevOps, Marketing, Legal and others to embed security into how these platforms are configured, extended, and connected to third-party services.
  • Translate security and business-continuity issues into clear, actionable terms for non-technical stakeholders.
  • Ensure business systems handling personal data hold up against privacy frameworks including GDPR and CCPA, in close collaboration with Legal and Compliance.
  • Chase data-flow and permission questions to ground truth which means following through until the answer and its implications are genuinely clear.

Your Qualifications:

Your primary expertise is in Salesforce administration and business systems security. Everything else listed here is context you’ll operate in. Depth in the primary domain matters more than breadth across all of them.

  • Salesforce administration experience with a strong security lens. This means permissions, sharing rules, connected apps, and integration patterns.
  • Solid understanding of how business systems interconnect and why that matters for data exposure and business continuity.
  • Able to communicate issues precisely to both technical and non-technical audiences.
  • Working knowledge of privacy frameworks such as GDPR and CCPA at minimum.

You don’t need to tick every box! We’re looking for depth in business systems security and the drive to grow across the rest.

Standout Qualities:

  • Certified Salesforce Administrator credential.
  • Security+, ISC2 CC, or an equivalent security certification.
  • Experience auditing or governing SaaS-to-SaaS integrations
  • Exposure to data security posture management (DSPM) or data classification in SaaS environments.
  • You use AI as a force multiplier — to move faster, think wider, and go deeper — but your security instincts and judgement are your own. You don’t outsource thinking to a tool.
  • Demonstrated tenacity in chasing complex data flows and access permissions across multi-tool integrations to a definitive answer.

Team Dynamics:

You will be joining Wrike’s 15-member global Security team led by Maksim Pekuryn, Director of Security. You will report directly to Swen Groeneveld, Head of Security Operations, whose 8-person sub-team includes Security Engineers, Application Security, and SOC specialists. You’ll also work closely with cross-functional partners in RevOps, Marketing, and Legal.

Our Work Style:

  • Tech stack: Salesforce, Marketo, Salesloft, OAuth integrations, connected apps, and related business SaaS tooling.
  • Collaborative environment working closely with RevOps, Legal, and Marketing teams.
  • Hybrid mode.

Benefits & Perks:

  • 28 calendar days of paid vacation
  • Sick Leave Compensation (5 Paid Uncertified Sick Days)
  • Parental Leave: 18 Weeks Maternity / 4 Week Paternity
  • 2 Volunteer Days
  • Health Insurance (Employees + Dependents)
  • Life Insurance Plan
  • Utility Allowance (30 EUR/month, subject to taxation)
  • Fitness Plan (800 EUR/year)
  • Full-remote & On-demand access to Co-working space

What’s Next?

  • Recruiter Screen (30 mins)
  • Department Interview / Technical Discussion (60 mins)
  • Cultural Interview with Hiring Manager, CISO, and HRBP

Your recruitment buddy will be Aleksandar Chernev, Senior Technical Recruiter.

#LI-AC1

Who Is Wrike and Our Culture

We’re a team of innovators and creators who solve the complex work problems of today and tomorrow.

Hybrid work mode

Wrike is our people, not a place. With 1,000+ employees collaborating across nearly every time zone, we support talent through 10 global hubs — Australia, Costa Rica, Cyprus, Czechia, Estonia, France, India, Ireland, Japan, and the United States — offering flexible ways of working that include remote work, hybrid environments, and co-working spaces across many locations.

While flexibility looks different across teams and regions, employees located near certain hubs — particularly in Prague (CZ), Nicosia (CY), Bangalore (IN), and Rennes (FR) — are generally expected to collaborate in person around 2–3 days per week, balancing the flexibility of distributed work with opportunities for in-person collaboration and connection.

Our persona

💡  Smart: We love what we do, and we’re great at it because this is our domain. Our combined knowledge in this space is unmatched.

💚  Dedicated: We get up every day focused on helping our customers win. We’re committed to helping our teammates win, too!

🤗  Approachable: We’re friendly, easy to get along with, considerate, and helpful.

Our culture and Values

🤩 Customer-Focused

We care about our customers. We understand the customer journey, experience, and value derived from Wrike. Decision-making and action-taking are done with the customer in mind.

🤝 Collaborative

We work as one and win together, each bringing unique strengths that contribute to diversity of thought for better outcomes. Leveraging our own work management platform, we foster an environment of creative collaboration and shared achievement.

🎨 Creative

We strive to succeed through continuous innovation. It’s our pursuit of novel concepts that helped us create a market category. We continue to cultivate a workplace that fosters creative thinking as a means of transcending conventional boundaries and empowers us to break new ground to deliver extraordinary work management solutions.

đź’Ş Committed

We believe in ownership at all levels of the organization, by owning workflows from start to finish. Each member of our team is an integral part of this commitment, establishing work as a platform for personal growth and transformation, as well as collective success and growth.

Check out our LinkedIn Life Page, Company culture page, Instagram, Wrike Engineering Team, Medium, Meetup.com, Youtube for a feel for what life is like at Wrike.

Read the full description
Security Threat Detection Analyst (Japanese Speaking)

Monitors and investigates cyber threats using detection tools while supporting Fastly’s security operations for Japanese-speaking contexts.

Mid Posted 4 days ago Jobicy AI
What this role involves
Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and...
Read the full description
Security Cyber Security Engineer

Provides cybersecurity engineering expertise to support a customer project on a flexible part-time contract.

Mid Remote Posted 4 days ago Himalayas
What this role involves
Job Type: Contractor (~15 hrs a week) Location: Remote Schedule: Flexible, you pick the hours and days (including weekends if desired) micro1 is selecting Cyber Security Engineers to contribute technical expertise to a dynamic customer project.
Read the full description
Security Detection & Response Engineer at Beyond Finance

Builds and manages cloud security detections, telemetry pipelines, alert automation, and incident-response workflows using Datadog Cloud SIEM.

Mid Posted 8 days ago RemoteFirstJobs Product
What this role involves

At Beyond Finance, we’ve made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we’ve helped over 1 million clients on their path to a brighter future.

While we’re proud of what we’ve already accomplished, we’re searching for new collaborators to help us get to the next level! If you’re looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

The Role

You’ll build the detections and automation that protect our cloud, SaaS applications, and user workstations. You’ll be the team’s Datadog expert, owning how security telemetry gets into Datadog Cloud SIEM, how it’s filtered, and the detections that run on it. You’ll also automate the repetitive work around alerts and support triage and investigations. As we bring automation and AI into security operations, you’ll help build and ship the new capabilities.

What You’ll Own

  • Detection engineering: write, tune, and retire Cloud SIEM detections, and map coverage to MITRE ATT&CK to close gaps.
  • Logging pipeline: onboard sources and build Datadog log pipelines that parse, normalize, and enrich security telemetry.
  • Detection-as-code: manage detections in version control with testing and peer review.
  • Automation: build workflows for alert enrichment, triage, containment, and notification.
  • AI in the SOC: build AI-assisted triage and alert summarization, with a human in the loop.
  • Measurement: track coverage, false-positive rate, and automation rate to decide what to fix next.
  • Filtering and cost: manage indexes, exclusion filters, and retention tiers to cut noise and cost without losing coverage.
  • Security operations: support triage, investigations, and incident response, including on-call.

What You Bring

  • 3+ years in security operations, detection engineering, or security engineering.
  • You write your own scripts and build detection logic as code. Infrastructure as code and CI/CD experience is a plus.
  • Deep hands-on Datadog experience, especially Cloud SIEM detection rules and log pipelines.
  • Experience with automation orchestration tooling.
  • Working knowledge of MITRE ATT&CK. Threat hunting or purple teaming experience is a plus.
  • Experience with security telemetry from cloud platforms, SaaS applications, and EDR.
  • You can take a project from prototype to production with little direction.

The Ideal Candidate

The ideal candidate measures success by real threats caught and noise removed, not by the number of detections written. Automating a problem is their first move, and they would rather ship a working detection this week and tune it than wait for a perfect rule. They know Datadog well enough to test every parsing and detection change against real logs before calling it done. They use AI to move faster but verify its output, and when they find a coverage gap or a noisy log source, they fix it instead of filing a ticket.

#LI-LB2

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$100,000—$120,000 USD

Why Join Us?

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program
  • Merit advancement opportunities
  • Career development & training

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions.  No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team.  No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team.

Read the full description
Security Detection & Response Engineer at Beyond Finance

Builds and manages cloud SIEM detections, security telemetry pipelines, alert automation, and incident response workflows.

Mid Posted 8 days ago RemoteFirstJobs Product
What this role involves

At Beyond Finance, we’ve made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,a culture focused on compliance and ethics, supportive user-centric technology, and customized financial solutions, we’ve helped over 1 million clients on their path to a brighter future.

While we’re proud of what we’ve already accomplished, we’re searching for new collaborators to help us get to the next level! If you’re looking to join a forward-thinking, rapidly growing organization with helping people as its number one goal, we want to hear from you.

The Role

You’ll build the detections and automation that protect our cloud, SaaS applications, and user workstations. You’ll be the team’s Datadog expert, owning how security telemetry gets into Datadog Cloud SIEM, how it’s filtered, and the detections that run on it. You’ll also automate the repetitive work around alerts and support triage and investigations. As we bring automation and AI into security operations, you’ll help build and ship the new capabilities.

What You’ll Own

  • Detection engineering: write, tune, and retire Cloud SIEM detections, and map coverage to MITRE ATT&CK to close gaps.
  • Logging pipeline: onboard sources and build Datadog log pipelines that parse, normalize, and enrich security telemetry.
  • Detection-as-code: manage detections in version control with testing and peer review.
  • Automation: build workflows for alert enrichment, triage, containment, and notification.
  • AI in the SOC: build AI-assisted triage and alert summarization, with a human in the loop.
  • Measurement: track coverage, false-positive rate, and automation rate to decide what to fix next.
  • Filtering and cost: manage indexes, exclusion filters, and retention tiers to cut noise and cost without losing coverage.
  • Security operations: support triage, investigations, and incident response, including on-call.

What You Bring

  • 3+ years in security operations, detection engineering, or security engineering.
  • You write your own scripts and build detection logic as code. Infrastructure as code and CI/CD experience is a plus.
  • Deep hands-on Datadog experience, especially Cloud SIEM detection rules and log pipelines.
  • Experience with automation orchestration tooling.
  • Working knowledge of MITRE ATT&CK. Threat hunting or purple teaming experience is a plus.
  • Experience with security telemetry from cloud platforms, SaaS applications, and EDR.
  • You can take a project from prototype to production with little direction.

The Ideal Candidate

The ideal candidate measures success by real threats caught and noise removed, not by the number of detections written. Automating a problem is their first move, and they would rather ship a working detection this week and tune it than wait for a perfect rule. They know Datadog well enough to test every parsing and detection change against real logs before calling it done. They use AI to move faster but verify its output, and when they find a coverage gap or a noisy log source, they fix it instead of filing a ticket.

#LI-LB2

The base annual salary range is listed below. This role is eligible for additional incentives, including an annual bonus.

Base Salary Range

$100,000—$120,000 USD

Why Join Us?

While you make a difference for others, we’ll work to make a difference for you, providing an uplifting, collaborative work environment and benefits that reflect your value to us. For eligible full-time employees, we offer:

  • Considerable employer contributions for health, dental, and vision programs
  • Generous PTO, paid holidays, and paid parental leave
  • 401(k) matching program
  • Merit advancement opportunities
  • Career development & training

And finally, our team spirit and culture! We cultivate an environment of community, connection, and belonging across our entire organization.

Beyond Finance does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job positions.  No fee will be paid to their parties who submit unsolicited candidates directly to Beyond Finance employees or the Beyond Finance HR team.  No placement fee will be paid to any third party unless such a request has been made by the Beyond HR team.

Read the full description
Security Information Security Compliance Coordinator

Supports the Director of Compliance with day-to-day information security compliance activities for ISO 27001, SOC 2, and CMMC.

Mid Remote Posted 8 days ago Himalayas
What this role involves
Information Security Compliance Coordinator Contact Discovery Services - Washington, DC Location: Remote Start Date: Negotiable A leading eDiscovery technology and consulting firm headquartered in Washington, DC is looking for a part-time Information Security Compliance Coordinator in the eDiscovery space to support the Director of Compliance with day-to-day compliance-related activities associated with ISO 27001, SOC 2, and CMMC.
Read the full description
Security Threat Detection Analyst (Japanese & English speaking)

Monitors systems for cybersecurity threats and investigates suspicious activity using Japanese and English language skills.

Mid Posted 10 days ago Jobicy AI
What this role involves
Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and...
Read the full description
Security Security Engineer, Insider Threat Detection & Response

Detects and responds to insider threats by monitoring security systems, investigating suspicious activities, and implementing threat mitigation strategies.

Mid Posted 12 days ago Jobicy AI
What this role involves
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products....
Read the full description
Security Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, D

Develops and implements application security measures to identify vulnerabilities, protect systems from threats, and minimize organizational risk.

Mid Remote Posted 13 days ago Himalayas
What this role involves
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk.
Read the full description
Security Expel: Managed SIEM Detection Engineer

Detection engineer who authors and tunes SIEM detection content, optimizes security tooling, and delivers professional services engagements to help customers close coverage gaps and reduce alert noise.

Mid Remote Posted 14 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor's degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range$111,900—$162,300 USD

To apply: https://weworkremotely.com/remote-jobs/expel-managed-siem-detection-engineer

Read the full description
Security Industrial Security Analyst / Facility Security Officer (FSO) at Red Cell Partners

Administers industrial security programs for a cleared defense contractor, ensuring NISPOM compliance and overseeing personnel security, operations security, and visitor control.

Mid Hybrid Posted 15 days ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

About Defcon AI

RESILIENCE IN THE FACE OF DISRUPTION. Defcon AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, Defcon AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

We are seeking an Industrial Security Analyst / Facility Security Officer (FSO) to support and help scale our security program as DEFCON AI’s classified work continues to grow. This individual will play a key role in maintaining compliance with government security requirements while helping build the processes, controls, and culture needed to support a rapidly growing defense technology company.

This is a hybrid position based in McLean, VA, with an expectation of three days per week in the office.

Position Overview

The Industrial Security Analyst / FSO is responsible for the day-to-day administration and oversight of DEFCON AI’s Industrial Security Program. This role ensures compliance with the National Industrial Security Program Operating Manual (NISPOM), customer requirements, and internal security policies while supporting employees, leadership, and external security partners.

The ideal candidate has experience supporting industrial security programs within a cleared contractor environment and is comfortable operating in a fast-paced organization where security processes continue to evolve and mature.

What You’ll Do

Industrial Security & Compliance

  • Support day-to-day industrial security operations across multiple disciplines, including Personnel Security (PERSEC), Operations Security (OPSEC), Contract Security, Security Education, Training and Awareness (SETA), Visitor Control, Investigations, and Document Control
  • Ensure compliance with NISPOM, ICD requirements, customer security requirements, and internal security policies
  • Maintain readiness for DCSA, customer, and internal security inspections and compliance reviews
  • Conduct self-inspections, identify areas for improvement, and implement corrective actions
  • Support the ongoing development and maturation of DEFCON AI’s industrial security program

Personnel & Program Security

  • Process and manage personnel security requirements, including clearance actions, visit requests, visit authorizations, and onboarding activities
  • Maintain personnel security records and related databases
  • Investigate security incidents and violations and ensure proper reporting and resolution in accordance with government and company requirements
  • Provide security guidance and support to employees, consultants, and approved visitors
  • Support contract security requirements, including DD Form 254 administration and subcontractor security management

Classified Information Protection

  • Maintain classified material accountability programs and secure storage requirements
  • Conduct inventories and maintain accountability of classified information and assets
  • Ensure proper marking, handling, transmission, storage, transportation, sanitization, reuse, and destruction of classified information and media
  • Support the protection of classified facilities, systems, and information in accordance with applicable regulations

Security Training & Program Development

  • Develop and administer Security Awareness, Annual Refresher, and OPSEC training programs
  • Create and maintain required security documentation, including SOPs, OPSEC plans, CONOPS, security procedures, and work instructions
  • Promote a culture of security awareness and compliance throughout the organization

Security Systems & Inspection Readiness

  • Maintain records and security actions within NISS, DISS, and other government security systems as required
  • Support DCSA, customer, and internal inspections and audits
  • Assist with corrective action implementation and continuous process improvement initiatives

Required Qualifications

  • Bachelor’s degree and 6+ years of industrial security or related experience; OR Master’s degree and 4+ years; OR Associate’s degree and 8+ years; OR High School diploma and 12+ years of relevant experience

  • Active U.S. Government Top Secret security clearance and ability to obtain and maintain SCI and SAP access

  • Strong knowledge of NISPOM (32 CFR Part 117), ICD security requirements, and industrial security compliance standards

  • Understanding and familiarity of DD-254 implementation requirements including issuing Subcontract DD-254 using NI2

  • Experience supporting personnel security, classified material control, and compliance programs within a cleared contractor environment

  • Experience utilizing government security systems such as NISS, DISS, or similar platforms

  • Strong organizational, communication, and problem-solving skills

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Outlook

Preferred Qualifications

  • Experience serving as an FSO, AFSO, or Industrial Security Specialist within a cleared facility
  • CDSE FSO Program Management Certification for Processing and/or Non-Possessing Facilities
  • Experience supporting multiple classified programs and government customers
  • Experience preparing for and supporting DCSA or other government inspections
  • Knowledge of DD Form 254 requirements and subcontractor security administration
  • Experience supporting SCI and/or SAP programs
  • Experience building, improving, or scaling security processes within a growing organization
  • Strong customer service skills and the ability to build trusted relationships with internal and external stakeholders
  • Ability to work independently, manage competing priorities, and thrive in a fast-paced environment

Why DEFCON AI

At DEFCON AI, you’ll help build and scale security capabilities that directly support critical national security missions. You’ll work alongside a mission-driven team developing AI-powered solutions for some of the Department of War’s most complex operational challenges.

What We Offer:

  • A fully remote environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $120,000-$150,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits (may differ for each incubation):

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security Cybersecurity Compliance Analyst (Hybrid - Bay Area) at Xantrion

Analyzes client cybersecurity controls, develops compliance documentation, and assesses vendor security risks using frameworks like NIST CSF and CIS Controls.

Mid Hybrid Posted 15 days ago RemoteFirstJobs Product
What this role involves

If you’re looking to join a winning information technology team and receive outstanding benefits that support your family—while working for a company that takes a people-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.

Location: San Francisco Bay Area

Hybrid: 2 days in office / 3 days remote per week

Primary Purpose and Function

Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.

This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.

Travel: None required.

Roles and Responsibilities

Client Compliance and Documentation

  • Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
  • Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
  • Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
  • Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
  • Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
  • Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
  • Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
  • Maintain annual testing schedules and track documentation, review dates, and follow-up items.
  • Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
  • Improve reusable templates and assessment procedures that support consistent delivery across clients.

Internal Compliance Support

  • Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
  • Organize audit documentation, maintain request trackers, and follow up with internal control owners.
  • Review evidence for completeness and consistency and identify missing or outdated documentation.
  • Provide seasonal support during internal audit preparation and review periods.

Position Requirements

Required Qualifications

  • Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
  • Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
  • Experience reviewing technical configurations or administrative reports against documented standards.
  • Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
  • Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
  • Ability to distinguish documented policies from evidence that controls are implemented and operating.
  • Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
  • Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
  • Professional communication skills and sound judgment when handling confidential client information.

Preferred Qualifications

  • Experience supporting registered investment advisers (RIAs) or other financial services organizations.
  • Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
  • Experience working for a managed service provider or supporting multiple client environments.
  • Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
  • Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
  • Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
  • Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
  • Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
  • A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.

Performance Metrics

The Cybersecurity Compliance Analyst performance success will be based on the following criteria:

  • Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
  • Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
  • Risk registers, crosswalks, and supporting documentation remain organized and current.
  • Internal audit requests are tracked and supported with complete, accessible evidence.
  • Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.

Physical Demands

  • Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
  • Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
  • Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
  • Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
  • Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
  • Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
  • Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
  • Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
  • Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion’s office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.

Company Policy and Procedure Compliance

  • Follow and support company policies and procedures as well as all local, state, and federal laws.
  • Always maintain confidentiality of company and customer records and information.
  • Maintain a professional image, adhering to Xantrion’s dress code.
  • Must have an existing cell phone (running current Android or iOS).
  • If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance.  See the Xantrion Handbook for details.

When Working Remote

  • Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
  • Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
  • Must use Xantrion-provided PC and headset to execute job functions.

Benefits

  • Salary range $100-120K; depending on experience.
  • 100% of medical, dental, and vision for you and your family.
  • 401K with company match up to 4% of salary.
  • Certification reimbursement and annual training budget.
  • 17 Days PTO per year in addition to paid training days.
  • Bonuses for referring new clients or employees.

Equal Opportunity Employer

Xantrion is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, age, color, sex, religion, sexual orientation, national origin, disability, medical condition, genetic information, pregnancy, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws. All employment is decided on the basis of qualifications, merit, and business needs at the time.

AI Disclosure for Recruitment

We use AI to support our recruiting team, improve the candidate experiences, and allow our teams to spend more time on meaningful candidate interactions. Our use of AI is limited to administrative tasks such as organizing application information and taking or summarizing interview notes. AI does not screen, advance, or reject candidates, and it does not make hiring or any significant decisions. Applications and candidate qualifications are reviewed by our recruiting team, and all decisions about interviews, advancement, offers, and hiring are made by our recruiters and hiring managers.

Read the full description
Security IT Systems Auditor

Audits IT systems and controls for compliance, identifies security vulnerabilities, and ensures adherence to organizational and regulatory standards.

Mid Remote Posted 16 days ago Himalayas
What this role involves
OverviewAmyx is seeking to hire a IT Systems Auditor-II for our Defense Logistics Agency program remotely.
Read the full description
Security Vigilant IT Security Manager – Portugal/Poland

Manages IT security operations and strategies for a globally distributed team across Portugal/Poland regions.

Mid Remote Posted 16 days ago Jobicy AI
What this role involves
This is not an offshoring back-office job for an international company. You will be a key player in our globally distributed team. We’re searching for a Vigilant IT Security Manager...
Read the full description
Security GRC Manager

Manages governance, risk, and compliance programs to ensure organizational adherence to regulatory standards and security policies.

Mid Posted 16 days ago Jobicy AI
What this role involves
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in...
Read the full description