Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Staff IAM Analyst at Addepar

Manages identity and access administration, governance, access reviews, least-privilege controls, and improvements to the internal IAM security program.

Senior Posted about 4 hours ago RemoteFirstJobs Product
What this role involves

Who We Are

Addepar is a global data and AI platform empowering investment professionals to turn complex financial information into actionable intelligence. Addepar unifies portfolio, market and client data in a total portfolio view and delivers AI-powered insights within investment and client workflows. More than 1,500 firms in 60 countries use Addepar to manage and advise on nearly $10 trillion in assets. Its open platform integrates with 650 software, data and consulting partners to power end-to-end investment operations across firms of all sizes and levels of complexity. Addepar supports clients worldwide with offices in New York City, Salt Lake City, SĂŁo Paulo, London, Edinburgh, Geneva, Warsaw, Dubai, Pune and Singapore.

The Role

We are currently seeking an IAM Analyst to join our growing Information Security & Risk team . The successful candidate will have the opportunity to help take Addepar’s Internal Identity & Access Management program to the next level. In this role, this person will work as part of the internal Identity & Access Management (IAM) function to improve the overall security posture of the organization.

Applicants must have, and maintain, the right to work in the United Kingdom from the first day of employment. Please note that visa sponsorship is not available for this role.

What You’ll Do

  • Provide operational support for IAM related administration tools:

    • Application onboarding and role definitions
    • Recertification campaigns based on security and audit requirements
    • Handling end user escalations and support requests
  • Assist with improving the overall maturity of the internal IAM program:

    • Analyze, design, and implement improvements to data quality and role decisions across integrated systems.
    • Governance Initiatives, such as Entitlement Reviews and proper inventory management of identities
    • Enhancing IAM posture including human and non-human identities.
    • Continually improve the IAM practice through platform enhancements, user process improvements and identity risk assessments.
  • Analyze access requirements, system flows, and security policies to enforce a strict Least Privilege access model while balancing user experience.

  • Design and implement scalable processes and/or technologies to improve the overall security posture of Addepar.

  • Assisting with the development and refinement of Information Security Policies & Standards.

  • Partner with the broader Security team to define the governance strategy and technical controls for Agentic AI Workflows, ensuring that autonomous agents and Non-Human Identities (NHIDs) operate within a secure, auditable, and least-privileged framework.

Who You Are

  • Extensive hands-on Identity & Access Management experience with a track record of solving diverse access challenges.
  • Bachelor’s degree/equivalent or higher. Computer Science or Engineering related education preferred.
  • Experience with Identity & Access Management tools.
  • Familiar with IT Governance and Compliance functions, including SOC2 and Data Governance.
  • An understanding of Non Human Identities (NHIs) and the unique challenges within an information security setting.
  • Attention to details and analytical skills.
  • Curious, always learning and deeply interested in Information Security.
  • Ability to build strong relationships and work collaboratively with internal and external partners.
  • Excellent verbal and written communication skills with the ability to build strong relationships with internal stakeholders and external partners.

Desired Technical Skills:

  • Hands-on experience with IGA tools such as C1, Saviynt, or similar enterprise-grade solutions.
  • Experience working with IAM related systems such as Identity Providers (IdP), Multi-Factor Authentication (MFA), Zero Trust Access (ZTA) and Privileged Access Management (PAM) platforms.
  • Familiarity with ‘Source of Truth’ integrations (e.g. Workday/BambooHR) for automated onboarding/offboarding.
  • Hands-on experience with Amazon Web Services (AWS) or similar cloud platform and strong understanding of IAM related policies and configurations.
  • Experience with Okta and Google Workspace environments.
  • Experience with Infrastructure as Code tools such as Terraform.

Our Values

  • Act Like an Owner - Think and operate with intention, purpose and care. Own outcomes.
  • Build Together - Collaborate to unlock the best solutions. Deliver lasting value.
  • Champion Our Clients - Exceed client expectations. Our clients’ success is our success.
  • Drive Innovation - Be bold and unconstrained in problem solving. Transform the industry.
  • Embrace Learning - Engage our community to broaden our perspective. Bring a growth mindset.

In addition to our core values, Addepar is proud to be an equal opportunity employer. We seek to bring together diverse ideas, experiences, skill sets, perspectives, backgrounds and identities to drive innovative solutions. We commit to promoting a welcoming environment where inclusion and belonging are held as a shared responsibility.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

PHISHING SCAM WARNING: Addepar is among several companies recently made aware of a phishing scam involving con artists posing as hiring managers recruiting via email, text and social media. The imposters are creating misleading email accounts, conducting remote “interviews,” and making fake job offers in order to collect personal and financial information from unsuspecting individuals. Please be aware that no job offers will be made from Addepar without a formal interview process. Additionally, Addepar will not ask you to purchase equipment or supplies as part of your onboarding process. If you have any questions, please reach out to ta-operations@addepar.com.

Read the full description
Security Senior Developer (Windows), Product Security

Develops Windows software and strengthens product security for 1Password.

Senior Posted about 4 hours ago Jobicy AI
What this role involves
1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up...
Read the full description
Security Security Consultant

Manages security reviews, technical audits, and coordination of offensive security initiatives for a fully remote team.

Senior Remote Posted 1 day ago Himalayas
What this role involves
En Logicalis Spain actualmente estamos buscando a una persona con experiencia en gestión de revisiones de seguridad, auditorías técnicas y coordinación de iniciativas ofensivas para incorporar en uno de nuestros equipos como Security Review Manager en modalidad 100% remoto.
Read the full description
Security Senior DevOps & Security Engineer at Synapticure

Builds and secures AWS and Kubernetes infrastructure, automates delivery, manages vulnerabilities, and supports HIPAA and SOC 2 compliance.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Synapticure

Synapticure is the largest, most comprehensive specialty care and life sciences company in the country for those living with neurodegenerative diseases. Founded by patients and caregivers living with these diseases, we are redefining the care and the research paradigm for conditions like Alzheimer’s, Parkinson’s, and ALS in all 50 states.

Our business is powered by two connected engines.

The CARES Engine (Clinical Operations)

A scalable, 50-state virtualized clinical network providing timely access to expert neurologists and cutting edge treatments with wraparound care coordination and behavioral health support. Our team creates personalized care plans focused on education and empowerment, connecting patients with a multidisciplinary team of subspecialty neurologists, geriatricians, psychologists, and care coordinators who collaborate to deliver comprehensive care.

The CURES Engine (Research & Innovation)

Leveraging our deeply engaged, well characterized national patient cohort, CURES partners with life science, pharma, biotech, and medical device companies to accelerate the development of neurodegenerative treatments, spanning discovery stage lab services, clinical trial services, and real world evidence data and analytics.

Partnering with providers, health plans, and life sciences companies, including CMS’ GUIDE dementia care model, Synapticure is dedicated to transforming the lives of millions of individuals and their families living with neurodegenerative diseases.

About the Role

The Senior DevOps & Security Engineer is a hands-on technical role responsible for building, operating, securing, automating, and improving our cloud infrastructure and software delivery environments. Reporting to the Director of IT, DevOps & Security, this role works across Engineering, Data, and other teams to maintain secure, reliable, and well-monitored systems.

The role focuses heavily on cloud security, compliance, vulnerability management, AWS, Terraform, Kubernetes, CI/CD, observability, and production reliability.

This is a strong fit for someone who enjoys working across cloud infrastructure, security engineering, compliance, and broader technical problem-solving.

The Day to Day

  • Translate security and compliance requirements into practical technical controls and directly support HIPAA, SOC 2, and related activities.
  • Build, maintain, secure, and improve AWS infrastructure, Kubernetes/EKS environments, identity and access controls (IAM), networking, databases, storage, logging, monitoring, and SIEM integrations.
  • Develop and maintain Terraform, secure CI/CD pipelines, deployment tooling, and related automation.
  • Manage vulnerability scanning, security telemetry, incident response support, and application/infrastructure hardening.
  • Partner with Engineering, Data, and other internal teams to automate workflows, connect systems, and reduce manual work.
  • Build scripts, integrations, internal tools, and API-based automations across technical and business systems.
  • Maintain clear technical documentation, architecture diagrams, and infrastructure security standards.
  • Research and evaluate new tools, security practices, and infrastructure approaches to determine how they can be applied effectively in our environment.
  • Participate in on-call or escalation coverage as operational needs evolve. Our production environment is generally stable and relatively low-traffic, so after-hours work tends to focus more on planned maintenance, upgrades, and proactive security improvements than on responding to outages.

Minimum Qualifications

  • 4+ years of experience in cloud security engineering, DevOps, cloud infrastructure, SRE, or a related field.
  • Strong understanding of cloud security, IAM, networking, vulnerability management, observability, and incident response.
  • Hands-on experience supporting or implementing security controls in regulated environments (e.g., HIPAA, SOC 2).
  • Hands-on experience with SentinelOne (or similar EDR/endpoint security platforms), AWS, Terraform, Kubernetes, and securing CI/CD pipelines.
  • Ability to write scripts (Python, Bash, etc.) and work with APIs, integrations, and security automation.
  • Excellent written and verbal communication skills, with a proven ability to produce clear technical writing, architecture documentation, and cross-functional collaboration.
  • Ability to work independently, research unfamiliar problems, and take projects from problem definition through implementation.

Preferred Qualifications

  • Experience in healthcare, healthtech, financial services, or another highly regulated sector.
  • Familiarity with tools such as Datadog, SentinelOne, Argo CD, GitHub Actions, or Google Workspace administration.
  • Direct experience with SIEM setup, detection engineering, or penetration testing remediation.
  • Background in disaster recovery planning and backup restoration testing.

$150,000 - $170,000 a year

Compensation

Final compensation will be determined based on location, experience, and qualifications.

Our Values

We are a remote-first company. While our team is located all across the United States, these core principles tie us together around a common identity:

  • Relentless focus on patients and caregivers: We are determined to provide an exceptional experience for every patient we have the privilege to serve, and we put our patients first in everything we do.
  • Embody the spirit and humanity of those living with neurodegenerative disease: Inspired by our founders, families, and personal experiences, we recognize the seriousness of our patients’ circumstances and meet that challenge every day with empathy, compassion, kindness, joy, and hope.
  • Seek to understand, and stay curious: We start by listening to one another, our partners, our patients, and their caregivers. We communicate with authenticity and humility, prioritizing honesty and directness while recognizing we always have something to learn.
  • Embrace the opportunity: We are energized by the importance of our mission and maintain a strong bias toward action.

Benefits & Perks

Full time employees are eligible for:

  • Remote First: Work from anywhere in the 50 United States, with home office technology provided.
  • Comprehensive Healthcare: Medical, dental, and vision insurance options for you and your family.
  • Financial & Retirement Support: 401(k) plan with employer matching, plus short and long-term disability, and basic and supplemental life insurance.
  • Time Off & Leave: 15 vacation days, 5 sick days, 12 paid holidays, and 2 floating holidays, plus a fully paid end-of-year company holiday break (typically Christmas through New Year’s).
  • Wellness & Family Growth: Comprehensive family-building and fertility services through Kindbody (where available) at a 20% discount, 24⁄7 mental health support via Health Advocate and Talkspace (including 12 free on-demand sessions per year), and access to One Medical.

Travel Requirements & Remote Workplace Setup

We’re a remote-first company and provide the necessary technology to work from home. Most roles involve only occasional travel, such as for team meetings or professional collaboration events, unless otherwise specified in the job-specific details above.

Equal Opportunity Employer

Synapticure is an equal opportunity employer and a remote-first workplace. We believe that embedding equity, inclusion, compliance, and operational excellence across all aspects of our employee lifecycle directly reflects our core values. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Please apply even if you feel you do not meet all qualifications.

At this time, Synapticure is unable to provide work visa sponsorship.

If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to [email protected].

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer at Anduril Industries

Designs and implements defensive security controls, automation, architecture reviews, and incident response across cloud, application, and corporate infrastructure.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

Anduril’s Security Engineering team is looking for a security engineer to focus on building world class defensive controls to protect the infrastructure around our defense technology products.

WHAT YOU’LL DO

  • Design and implement security controls across cloud, production, and corporate infrastructure
  • Develop tools and systems to improve security posture and operational efficiency
  • Conduct security architecture and design reviews for systems and applications
  • Build automation to detect, monitor, and remediate security issues
  • Work across infrastructure, application, and operational security domains

REQUIRED QUALIFICATIONS

  • Strong programming ability in one or more general purpose languages (Python, Go, Rust, etc)
  • Experience with one or more infrastructure as code languages (e.g., Terraform, AWS CDK) in a production capacity
  • Experience conducting security architecture or design reviews around custom business applications
  • Solid understanding of modern attack vectors and defensive mitigation strategies
  • Experience working with cloud platforms and deploying applications through CI/CD pipelines
  • Experience developing and implementing defensive controls around endpoint and SaaS applications
  • Ability to work autonomously, take ownership of projects, and collaborate across teams
  • Have participated in or supported incident response events
  • Eligible to obtain and maintain a U.S. TS clearance

PREFERRED QUALIFICATIONS

  • Experience building bespoke solutions in high-growth and high-complexity environments
  • Experience with log aggregation, secrets management, or endpoint security tools
  • Experience with AWS, Azure, or GCP security ecosystem and tooling
  • Strong experience with Linux operating systems

US Salary Range

$166,000—$220,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril’s total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We’ve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:

    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency’s authenticity by reaching out to contact@anduril.com.
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender’s email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Anduril’s candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.

By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.

Read the full description
Security Senior Security Engineer OT at Anduril Industries

Designs and implements defensive security controls, risk assessments, and threat detection for operational technology and industrial control systems.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

Anduril’s Security Engineering team is looking for a security engineer to focus on building world class defensive controls to protect the infrastructure around our advanced defense technology products. This is a role with a direct focus on securing Anduril’s OT (Operational Technology) and ICS (Industrial Control Systems) environments. In this role, you will design and implement foundational security solutions playing a critical role in Anduril’s rollout of cutting edge factory systems.

ABOUT THE JOB

WHAT YOU’LL DO

  • Lead OT risk assessments, gap analyses, and develop a multi-year OT security roadmap
  • Architect and implement defensive security controls for cloud, production, and corporate environments
  • Support the deployment, configuration, and maintenance of security tools
  • Build systems to support automation, visibility, and threat detection for efforts across various information security and infrastructure teams
  • Independently drive security initiatives and foster a security-first mindset across the organization
  • Work closely with factory production teams to review designs and use-cases, ensuring our environments are secure by design

REQUIRED QUALIFICATIONS

  • Experience with routing, switching, and network design principles
  • Familiarity with zero trust architecture and segmentation strategies when it comes to OT networks
  • Experience conducting security architecture or design reviews for OT/ICS environments
  • Experience with threat modeling frameworks and applying these concepts to the OT/ICS domain (e.g. MITRE ATT&CK for ICS)
  • Experience with programming in one or more general purpose languages (Python, Go, Rust, etc)
  • Experience developing and implementing defensive controls in corporate and industrial production environments
  • Ability to work autonomously and take ownership of complex projects
  • Have participated in or supported incident response events
  • Eligible to obtain and maintain an active U.S. Top Secret security clearance
  • Ability to travel up to 50%

PREFERRED QUALIFICATIONS

  • Familiarity with OT protocols (e.g., Modbus, DNP3, Ethernet/IP) and ICS environments
  • Experience with specific ICS/SCADA vendor platforms (Siemens, Rockwell, Honeywell, etc.)
  • Experience building bespoke solutions in high-growth high-complexity network environments
  • Strong experience with Linux operating systems

US Salary Range

$166,000—$220,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril’s total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We’ve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:

    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency’s authenticity by reaching out to contact@anduril.com.
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender’s email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Anduril’s candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.

By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.

Read the full description
Security SailPoint Engineer (IIQ/ISC) - (Remote in the US) at GuidePoint Security

Implements and integrates SailPoint identity governance solutions, develops workflows and connectors, supports deployments, and advises clients on cybersecurity requirements.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.

General Description

We’re looking for an Implementation Engineer to design, build, and deploy identity governance solutions on the SailPoint platform, including IdentityIQ (IIQ) and/or Identity Security Cloud (ISC). This is a hands-on technical role with plenty of client interaction. You’ll be part of a small, collaborative team where your work is visible and your input shapes how we deliver.

About the IGA Practice

Our team of Practice Leads, Managing Security Consultants, Architects, and Engineers focus on SailPoint IIQ/ISC, Saviynt, C1, and Lumos engagements for external clients.

Roles and Responsibilities:

  • Implement and configure SailPoint IIQ and ISC solutions, including identity lifecycle management, access certifications, access requests, provisioning, and password management
  • Build and maintain application onboarding: connectors, aggregation, correlation, and account/entitlement mapping
  • Develop rules, workflows, forms, and transforms (BeanShell/Java for IIQ; transforms, rules, and workflows for ISC)
  • Design and support IIQ-to-ISC migrations, including assessment, gap analysis, and cutover planning
  • Integrate SailPoint with source systems such as Active Directory, Entra ID, Okta, HR platforms (Workday, SuccessFactors), ServiceNow, SAP, databases, and SaaS applications
  • Work with client stakeholders to gather requirements, run design sessions, and translate business needs into technical designs
  • Write clear technical documentation, including design documents, configuration guides, test plans, and runbooks
  • Support UAT, deployment, and hypercare, and troubleshoot issues across environments
  • Follow SailPoint best practices for configuration management, version control, and promotion across dev/test/prod
  • Mentor junior engineers and contribute to reusable accelerators, templates, and internal knowledge

Required Experience and Education:

  • 5+ years of hands-on experience implementing SailPoint IdentityIQ and/or Identity Security Cloud
  • Working knowledge of both platforms, with depth in at least one
  • Strong understanding of IAM/IGA concepts: joiner/mover/leaver, RBAC, role mining, SoD, certifications, and least privilege
  • Experience with IIQ development (Java, BeanShell, XML artifacts) or ISC configuration (transforms, rules, REST APIs, VA management)
  • Experience with connectors and integration patterns (LDAP/AD, JDBC, delimited file, web services/REST, SCIM)
  • Solid SQL and scripting skills, plus familiarity with JSON, XML, and REST APIs
  • Strong written and verbal communication, with the ability to explain technical concepts to non-technical audiences
  • Comfortable working independently in a remote, distributed team
  • Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes.

Preferred Experience and Education

  • Consulting or professional services experience, including client-facing delivery, scoping, and managing multiple engagements
  • SailPoint certifications (e.g., IdentityIQ Engineer, Identity Security Cloud Engineer)
  • Experience leading or contributing to IIQ-to-ISC migrations
  • Familiarity with Git, CI/CD, and SSB or similar configuration management tools
  • Knowledge of adjacent identity technologies (PAM, Access Management, SSO, MFA)
  • Experience in regulated industries (financial services, healthcare, government)
  • Background in Java development, Linux/Windows administration, or application servers (Tomcat, WebLogic)

Travel Requirements:

  • Up to 10% travel

Physical Requirements:

  • Sedentary work
  • Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
  • Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day

We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don’t miss updates on your application.

Why GuidePoint? GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,300 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.

Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.

This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.

Some added perks
.

  • Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
  • Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
  • Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
  • 12 corporate holidays and a Flexible Time Off (FTO) program
  • Healthy mobile phone and home internet allowance
  • Eligibility for retirement plan after 2 months at open enrollment
  • Pet Benefit Option
Read the full description
Security Senior DevOps & Security Engineer at Synapticure

Builds and secures AWS and Kubernetes infrastructure, automates delivery, manages vulnerabilities, and supports HIPAA and SOC 2 compliance.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Synapticure

Synapticure is the largest, most comprehensive specialty care and life sciences company in the country for those living with neurodegenerative diseases. Founded by patients and caregivers living with these diseases, we are redefining the care and the research paradigm for conditions like Alzheimer’s, Parkinson’s, and ALS in all 50 states.

Our business is powered by two connected engines.

The CARES Engine (Clinical Operations)

A scalable, 50-state virtualized clinical network providing timely access to expert neurologists and cutting edge treatments with wraparound care coordination and behavioral health support. Our team creates personalized care plans focused on education and empowerment, connecting patients with a multidisciplinary team of subspecialty neurologists, geriatricians, psychologists, and care coordinators who collaborate to deliver comprehensive care.

The CURES Engine (Research & Innovation)

Leveraging our deeply engaged, well characterized national patient cohort, CURES partners with life science, pharma, biotech, and medical device companies to accelerate the development of neurodegenerative treatments, spanning discovery stage lab services, clinical trial services, and real world evidence data and analytics.

Partnering with providers, health plans, and life sciences companies, including CMS’ GUIDE dementia care model, Synapticure is dedicated to transforming the lives of millions of individuals and their families living with neurodegenerative diseases.

About the Role

The Senior DevOps & Security Engineer is a hands-on technical role responsible for building, operating, securing, automating, and improving our cloud infrastructure and software delivery environments. Reporting to the Director of IT, DevOps & Security, this role works across Engineering, Data, and other teams to maintain secure, reliable, and well-monitored systems.

The role focuses heavily on cloud security, compliance, vulnerability management, AWS, Terraform, Kubernetes, CI/CD, observability, and production reliability.

This is a strong fit for someone who enjoys working across cloud infrastructure, security engineering, compliance, and broader technical problem-solving.

The Day to Day

  • Translate security and compliance requirements into practical technical controls and directly support HIPAA, SOC 2, and related activities.
  • Build, maintain, secure, and improve AWS infrastructure, Kubernetes/EKS environments, identity and access controls (IAM), networking, databases, storage, logging, monitoring, and SIEM integrations.
  • Develop and maintain Terraform, secure CI/CD pipelines, deployment tooling, and related automation.
  • Manage vulnerability scanning, security telemetry, incident response support, and application/infrastructure hardening.
  • Partner with Engineering, Data, and other internal teams to automate workflows, connect systems, and reduce manual work.
  • Build scripts, integrations, internal tools, and API-based automations across technical and business systems.
  • Maintain clear technical documentation, architecture diagrams, and infrastructure security standards.
  • Research and evaluate new tools, security practices, and infrastructure approaches to determine how they can be applied effectively in our environment.
  • Participate in on-call or escalation coverage as operational needs evolve. Our production environment is generally stable and relatively low-traffic, so after-hours work tends to focus more on planned maintenance, upgrades, and proactive security improvements than on responding to outages.

Minimum Qualifications

  • 4+ years of experience in cloud security engineering, DevOps, cloud infrastructure, SRE, or a related field.
  • Strong understanding of cloud security, IAM, networking, vulnerability management, observability, and incident response.
  • Hands-on experience supporting or implementing security controls in regulated environments (e.g., HIPAA, SOC 2).
  • Hands-on experience with SentinelOne (or similar EDR/endpoint security platforms), AWS, Terraform, Kubernetes, and securing CI/CD pipelines.
  • Ability to write scripts (Python, Bash, etc.) and work with APIs, integrations, and security automation.
  • Excellent written and verbal communication skills, with a proven ability to produce clear technical writing, architecture documentation, and cross-functional collaboration.
  • Ability to work independently, research unfamiliar problems, and take projects from problem definition through implementation.

Preferred Qualifications

  • Experience in healthcare, healthtech, financial services, or another highly regulated sector.
  • Familiarity with tools such as Datadog, SentinelOne, Argo CD, GitHub Actions, or Google Workspace administration.
  • Direct experience with SIEM setup, detection engineering, or penetration testing remediation.
  • Background in disaster recovery planning and backup restoration testing.

$150,000 - $170,000 a year

Compensation

Final compensation will be determined based on location, experience, and qualifications.

Our Values

We are a remote-first company. While our team is located all across the United States, these core principles tie us together around a common identity:

  • Relentless focus on patients and caregivers: We are determined to provide an exceptional experience for every patient we have the privilege to serve, and we put our patients first in everything we do.
  • Embody the spirit and humanity of those living with neurodegenerative disease: Inspired by our founders, families, and personal experiences, we recognize the seriousness of our patients’ circumstances and meet that challenge every day with empathy, compassion, kindness, joy, and hope.
  • Seek to understand, and stay curious: We start by listening to one another, our partners, our patients, and their caregivers. We communicate with authenticity and humility, prioritizing honesty and directness while recognizing we always have something to learn.
  • Embrace the opportunity: We are energized by the importance of our mission and maintain a strong bias toward action.

Benefits & Perks

Full time employees are eligible for:

  • Remote First: Work from anywhere in the 50 United States, with home office technology provided.
  • Comprehensive Healthcare: Medical, dental, and vision insurance options for you and your family.
  • Financial & Retirement Support: 401(k) plan with employer matching, plus short and long-term disability, and basic and supplemental life insurance.
  • Time Off & Leave: 15 vacation days, 5 sick days, 12 paid holidays, and 2 floating holidays, plus a fully paid end-of-year company holiday break (typically Christmas through New Year’s).
  • Wellness & Family Growth: Comprehensive family-building and fertility services through Kindbody (where available) at a 20% discount, 24⁄7 mental health support via Health Advocate and Talkspace (including 12 free on-demand sessions per year), and access to One Medical.

Travel Requirements & Remote Workplace Setup

We’re a remote-first company and provide the necessary technology to work from home. Most roles involve only occasional travel, such as for team meetings or professional collaboration events, unless otherwise specified in the job-specific details above.

Equal Opportunity Employer

Synapticure is an equal opportunity employer and a remote-first workplace. We believe that embedding equity, inclusion, compliance, and operational excellence across all aspects of our employee lifecycle directly reflects our core values. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Please apply even if you feel you do not meet all qualifications.

At this time, Synapticure is unable to provide work visa sponsorship.

If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to [email protected].

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Sr Identity Engineer at Simeio

Designs, implements, integrates, and troubleshoots IBM identity and access management systems, including SSO, MFA, federation, and directory services.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Senior Identity Engineer – IBM IAM

We are seeking a Senior Identity Engineer with strong hands-on experience designing, implementing, and supporting IBM Identity and Access Management (IAM) solutions. This individual will work across enterprise environments to enhance authentication, access management, identity lifecycle, and security capabilities.

Key Responsibilities:

  • Design, implement, configure, and troubleshoot IBM IAM solutions.
  • Support IBM Security Verify Access (ISVA), IBM Security Verify Governance (ISVG), IBM Security Verify, and/or IBM Security Verify Directory.
  • Integrate IAM platforms with enterprise applications, directories, APIs, and authentication services.
  • Implement SSO, MFA, federation, OAuth/OIDC, SAML, LDAP, and Active Directory integrations.
  • Troubleshoot complex identity, authentication, and access-management issues.
  • Provide technical leadership and guidance on IAM architecture and security best practices.

Qualifications:

  • 5+ years of IAM/Identity Engineering experience.
  • Strong hands-on experience with IBM IAM / IBM Security Verify technologies.
  • Experience with enterprise SSO, MFA, federation, LDAP/AD, SAML, OAuth, and OIDC.
  • Strong troubleshooting, scripting, integration, and technical communication skills.
  • Experience working in complex enterprise or hybrid environments preferred.

Simeio is an equal opportunity employer. If you require assistance with completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to any of the recruitment team at recruitment@simeio.com or +1 404-882-3700.

Read the full description
Security Senior DevOps & Security Engineer at Synapticure

Builds and secures AWS and Kubernetes infrastructure, automates delivery, manages vulnerabilities, and supports HIPAA and SOC 2 compliance.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Synapticure

Synapticure is the largest, most comprehensive specialty care and life sciences company in the country for those living with neurodegenerative diseases. Founded by patients and caregivers living with these diseases, we are redefining the care and the research paradigm for conditions like Alzheimer’s, Parkinson’s, and ALS in all 50 states.

Our business is powered by two connected engines.

The CARES Engine (Clinical Operations)

A scalable, 50-state virtualized clinical network providing timely access to expert neurologists and cutting edge treatments with wraparound care coordination and behavioral health support. Our team creates personalized care plans focused on education and empowerment, connecting patients with a multidisciplinary team of subspecialty neurologists, geriatricians, psychologists, and care coordinators who collaborate to deliver comprehensive care.

The CURES Engine (Research & Innovation)

Leveraging our deeply engaged, well characterized national patient cohort, CURES partners with life science, pharma, biotech, and medical device companies to accelerate the development of neurodegenerative treatments, spanning discovery stage lab services, clinical trial services, and real world evidence data and analytics.

Partnering with providers, health plans, and life sciences companies, including CMS’ GUIDE dementia care model, Synapticure is dedicated to transforming the lives of millions of individuals and their families living with neurodegenerative diseases.

About the Role

The Senior DevOps & Security Engineer is a hands-on technical role responsible for building, operating, securing, automating, and improving our cloud infrastructure and software delivery environments. Reporting to the Director of IT, DevOps & Security, this role works across Engineering, Data, and other teams to maintain secure, reliable, and well-monitored systems.

The role focuses heavily on cloud security, compliance, vulnerability management, AWS, Terraform, Kubernetes, CI/CD, observability, and production reliability.

This is a strong fit for someone who enjoys working across cloud infrastructure, security engineering, compliance, and broader technical problem-solving.

The Day to Day

  • Translate security and compliance requirements into practical technical controls and directly support HIPAA, SOC 2, and related activities.
  • Build, maintain, secure, and improve AWS infrastructure, Kubernetes/EKS environments, identity and access controls (IAM), networking, databases, storage, logging, monitoring, and SIEM integrations.
  • Develop and maintain Terraform, secure CI/CD pipelines, deployment tooling, and related automation.
  • Manage vulnerability scanning, security telemetry, incident response support, and application/infrastructure hardening.
  • Partner with Engineering, Data, and other internal teams to automate workflows, connect systems, and reduce manual work.
  • Build scripts, integrations, internal tools, and API-based automations across technical and business systems.
  • Maintain clear technical documentation, architecture diagrams, and infrastructure security standards.
  • Research and evaluate new tools, security practices, and infrastructure approaches to determine how they can be applied effectively in our environment.
  • Participate in on-call or escalation coverage as operational needs evolve. Our production environment is generally stable and relatively low-traffic, so after-hours work tends to focus more on planned maintenance, upgrades, and proactive security improvements than on responding to outages.

Minimum Qualifications

  • 4+ years of experience in cloud security engineering, DevOps, cloud infrastructure, SRE, or a related field.
  • Strong understanding of cloud security, IAM, networking, vulnerability management, observability, and incident response.
  • Hands-on experience supporting or implementing security controls in regulated environments (e.g., HIPAA, SOC 2).
  • Hands-on experience with SentinelOne (or similar EDR/endpoint security platforms), AWS, Terraform, Kubernetes, and securing CI/CD pipelines.
  • Ability to write scripts (Python, Bash, etc.) and work with APIs, integrations, and security automation.
  • Excellent written and verbal communication skills, with a proven ability to produce clear technical writing, architecture documentation, and cross-functional collaboration.
  • Ability to work independently, research unfamiliar problems, and take projects from problem definition through implementation.

Preferred Qualifications

  • Experience in healthcare, healthtech, financial services, or another highly regulated sector.
  • Familiarity with tools such as Datadog, SentinelOne, Argo CD, GitHub Actions, or Google Workspace administration.
  • Direct experience with SIEM setup, detection engineering, or penetration testing remediation.
  • Background in disaster recovery planning and backup restoration testing.

$150,000 - $170,000 a year

Compensation

Final compensation will be determined based on location, experience, and qualifications.

Our Values

We are a remote-first company. While our team is located all across the United States, these core principles tie us together around a common identity:

  • Relentless focus on patients and caregivers: We are determined to provide an exceptional experience for every patient we have the privilege to serve, and we put our patients first in everything we do.
  • Embody the spirit and humanity of those living with neurodegenerative disease: Inspired by our founders, families, and personal experiences, we recognize the seriousness of our patients’ circumstances and meet that challenge every day with empathy, compassion, kindness, joy, and hope.
  • Seek to understand, and stay curious: We start by listening to one another, our partners, our patients, and their caregivers. We communicate with authenticity and humility, prioritizing honesty and directness while recognizing we always have something to learn.
  • Embrace the opportunity: We are energized by the importance of our mission and maintain a strong bias toward action.

Benefits & Perks

Full time employees are eligible for:

  • Remote First: Work from anywhere in the 50 United States, with home office technology provided.
  • Comprehensive Healthcare: Medical, dental, and vision insurance options for you and your family.
  • Financial & Retirement Support: 401(k) plan with employer matching, plus short and long-term disability, and basic and supplemental life insurance.
  • Time Off & Leave: 15 vacation days, 5 sick days, 12 paid holidays, and 2 floating holidays, plus a fully paid end-of-year company holiday break (typically Christmas through New Year’s).
  • Wellness & Family Growth: Comprehensive family-building and fertility services through Kindbody (where available) at a 20% discount, 24⁄7 mental health support via Health Advocate and Talkspace (including 12 free on-demand sessions per year), and access to One Medical.

Travel Requirements & Remote Workplace Setup

We’re a remote-first company and provide the necessary technology to work from home. Most roles involve only occasional travel, such as for team meetings or professional collaboration events, unless otherwise specified in the job-specific details above.

Equal Opportunity Employer

Synapticure is an equal opportunity employer and a remote-first workplace. We believe that embedding equity, inclusion, compliance, and operational excellence across all aspects of our employee lifecycle directly reflects our core values. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law. Please apply even if you feel you do not meet all qualifications.

At this time, Synapticure is unable to provide work visa sponsorship.

If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to [email protected].

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Security Engineer at Anduril Industries

Designs and implements defensive security controls, automation, architecture reviews, and incident-response capabilities across cloud, production, and corporate infrastructure.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

Anduril’s Security Engineering team is looking for a security engineer to focus on building world class defensive controls to protect the infrastructure around our defense technology products.

WHAT YOU’LL DO

  • Design and implement security controls across cloud, production, and corporate infrastructure
  • Develop tools and systems to improve security posture and operational efficiency
  • Conduct security architecture and design reviews for systems and applications
  • Build automation to detect, monitor, and remediate security issues
  • Work across infrastructure, application, and operational security domains

REQUIRED QUALIFICATIONS

  • Strong programming ability in one or more general purpose languages (Python, Go, Rust, etc)
  • Experience with one or more infrastructure as code languages (e.g., Terraform, AWS CDK) in a production capacity
  • Experience conducting security architecture or design reviews around custom business applications
  • Solid understanding of modern attack vectors and defensive mitigation strategies
  • Experience working with cloud platforms and deploying applications through CI/CD pipelines
  • Experience developing and implementing defensive controls around endpoint and SaaS applications
  • Ability to work autonomously, take ownership of projects, and collaborate across teams
  • Have participated in or supported incident response events
  • Eligible to obtain and maintain a U.S. TS clearance

PREFERRED QUALIFICATIONS

  • Experience building bespoke solutions in high-growth and high-complexity environments
  • Experience with log aggregation, secrets management, or endpoint security tools
  • Experience with AWS, Azure, or GCP security ecosystem and tooling
  • Strong experience with Linux operating systems

US Salary Range

$166,000—$220,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril’s total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We’ve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:

    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency’s authenticity by reaching out to contact@anduril.com.
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender’s email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Anduril’s candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.

By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.

Read the full description
Security Senior Security Engineer OT at Anduril Industries

Leads OT/ICS security assessments, architects defensive controls, deploys security tools, and secures factory production environments.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

Anduril’s Security Engineering team is looking for a security engineer to focus on building world class defensive controls to protect the infrastructure around our advanced defense technology products. This is a role with a direct focus on securing Anduril’s OT (Operational Technology) and ICS (Industrial Control Systems) environments. In this role, you will design and implement foundational security solutions playing a critical role in Anduril’s rollout of cutting edge factory systems.

ABOUT THE JOB

WHAT YOU’LL DO

  • Lead OT risk assessments, gap analyses, and develop a multi-year OT security roadmap
  • Architect and implement defensive security controls for cloud, production, and corporate environments
  • Support the deployment, configuration, and maintenance of security tools
  • Build systems to support automation, visibility, and threat detection for efforts across various information security and infrastructure teams
  • Independently drive security initiatives and foster a security-first mindset across the organization
  • Work closely with factory production teams to review designs and use-cases, ensuring our environments are secure by design

REQUIRED QUALIFICATIONS

  • Experience with routing, switching, and network design principles
  • Familiarity with zero trust architecture and segmentation strategies when it comes to OT networks
  • Experience conducting security architecture or design reviews for OT/ICS environments
  • Experience with threat modeling frameworks and applying these concepts to the OT/ICS domain (e.g. MITRE ATT&CK for ICS)
  • Experience with programming in one or more general purpose languages (Python, Go, Rust, etc)
  • Experience developing and implementing defensive controls in corporate and industrial production environments
  • Ability to work autonomously and take ownership of complex projects
  • Have participated in or supported incident response events
  • Eligible to obtain and maintain an active U.S. Top Secret security clearance
  • Ability to travel up to 50%

PREFERRED QUALIFICATIONS

  • Familiarity with OT protocols (e.g., Modbus, DNP3, Ethernet/IP) and ICS environments
  • Experience with specific ICS/SCADA vendor platforms (Siemens, Rockwell, Honeywell, etc.)
  • Experience building bespoke solutions in high-growth high-complexity network environments
  • Strong experience with Linux operating systems

US Salary Range

$166,000—$220,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril’s total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We’ve observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:

    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency’s authenticity by reaching out to contact@anduril.com.
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender’s email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Anduril’s candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.

By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.

Read the full description
Security Senior Manager, Enterprise Security at Rubrik

Leads enterprise security services, hardens corporate systems and applications, establishes security standards, and partners with IT and SOC teams on risk management.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About the team:

The Information Security organization advances the overall state of security at Rubrik through critical initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our assets, provides awareness education to teams on security best practices for data protection, and ensures data governance and data sharing relationships with third parties in order to securely protect Rubrik information.

About the role:

Rubrik is seeking a Senior Manager to oversee the Enterprise Security services function. In this role, you will

be responsible for ensuring that Rubrik’s Corporate Enterprise IT technologies are designed and

implemented to the highest possible security standards. You will partner with a variety of stakeholders

across the business to improve the security posture of SaaS applications, integrations, identity and

access operations, ensure corporate endpoints are secured, wireless networks are designed and

implemented securely, IOT devices are securely managed, and regularly audit for compliance to

Enterprise Security standards.

What you’ll do:

● Design and implement security standards across Identity (Okta), Endpoint (Windows, MacOS,

Linux), Secrets Management (Vault, Lastpass) and Business Applications (Salesforce, Glean,

etc).

● Partner with IT and other organizations to improve the security posture of enterprise applications,

integrations, and access to sensitive and business data.

● Actively participate in evaluation, development, and management of security and compliance

policies within IT management systems such as JAMF, inTune, etc.

● Analyze and harden existing applications, infrastructure, automation, and deployment processes:

CircleCI, Github workflows, Tines, Zapier, etc.

● Work with Corp IT teams, operations, governance, and other stakeholders to draft security

standards and implement monitoring, alerting, and governance.

● Review and approve application security review requests to ensure new applications used by

Rubrik and employees are secure, monitored, and security standards are enforced.

● Support the SOC in analyzing applicable threats, vulnerabilities, controls, and residual risks.

● Partner with Vulnerability Management and Threat Operations to drive remediation of critical

vulnerabilities and detection of IOC’s in the environment.

● Actively monitor and manage EDR policies.

● Partner with the organization to deploy technologies for AI usage and security.

● Leverage AI tools and agents to improve team performance, enterprise security capabilities, and

team efficiency - do more with less and faster.

Experience you’ll need:

● 5+ years of management experience

● Experience in enterprise security, with hands on experience in administration and design across

Windows, Mac, Okta, and public cloud infrastructure

● Broad knowledge of enterprise attack vectors and exploits in both end-user and IT Apps

● Subject matter expertise in business applications, endpoint and Identity management

● Deep understanding of endpoint systems, corporate networking including wi-fi and IT application

systems (Salesforce, Mulesoft, Lastpass, etc)

● Programming experience in PowerShell, Python, Go or Java

● Experience with deploying and securing Enterprise applications and environments at scale

● Security and administrative expertise in at least one major public cloud provider (AWS, GCP,

Azure)

● Understanding of corporate security maturity model frameworks and how to apply them

● Strong written and verbal communication skills

● Knowledge of regulatory guidelines and standards such as SOC2, ISO 27001, FedRAMP, etc.

The minimum and maximum base salaries for this role are posted below; additionally, the role is eligible for bonus potential, equity and benefits. The range displayed reflects the minimum and maximum target for new hire salaries for the role based on U.S. location. Within the range, the salary offered will be determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

US (SF Bay Area, DC Metro, NYC, Seattle) Pay Range

$212,800—$319,200 USD

The minimum and maximum base salaries for this role are posted below; additionally, the role is eligible for bonus potential, equity and benefits. The range displayed reflects the minimum and maximum target for new hire salaries for the role based on U.S. location. Within the range, the salary offered will be determined by work location and additional factors, including job-related skills, experience, and relevant education or training.

US2 (all other US offices/remote) Pay Range

$191,500—$287,300 USD

Join Us in Securing and Accelerating the World’s AI Transformation

Rubrik (RBRK), the Security and AI Operations Company, leads at the intersection of data protection, cyber resilience, and enterprise AI acceleration. Rubrik Security Cloud delivers complete cyber resilience by securing, monitoring, and recovering data, identities, and workloads across clouds. Rubrik Agent Cloud accelerates trusted AI agent deployments at scale by monitoring and auditing agentic actions, enforcing real-time guardrails, fine-tuning for accuracy and undoing agentic mistakes.

Linkedin | X (formerly Twitter) | Instagram | Rubrik.com

Inclusion @ Rubrik

At Rubrik, we are dedicated to fostering a culture where people from all backgrounds are valued, feel they belong, and believe they can succeed. Our commitment to inclusion is at the heart of our mission to secure the world’s data.

Our goal is to hire and promote the best talent, regardless of background. We continually review our hiring practices to ensure fairness and strive to create an environment where every employee has equal access to opportunities for growth and excellence. We believe in empowering everyone to bring their authentic selves to work and achieve their fullest potential.

Our inclusion strategy focuses on three core areas of our business and culture:

  • Our Company: We are committed to building a merit-based organization that offers equal access to growth and success for all employees globally. Your potential is limitless here.

  • Our Culture: We strive to create an inclusive atmosphere where individuals from all backgrounds feel a strong sense of belonging, can thrive, and do their best work. Your contributions help us innovate and break boundaries.

  • Our Communities: We are dedicated to expanding our engagement with the communities we operate in, creating opportunities for underrepresented talent and driving greater innovation for our clients. Your impact extends beyond Rubrik, contributing to safer and stronger communities.

Equal Opportunity Employer/Veterans/Disabled

Rubrik is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

Rubrik provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Rubrik complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please contact us at hr@rubrik.com if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.

EEO IS THE LAW

NOTIFICATION OF EMPLOYEE RIGHTS UNDER FEDERAL LABOR LAWS

Read the full description
Security Senior Application Security Engineer at Capital.com

Leads application security architecture, threat modeling, vulnerability testing, and automated security tooling across engineering teams.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

Capital.com’s Product Security team protects our web and mobile applications, infrastructure, and external perimeter in a highly regulated environment. As Senior/Staff Application Security Engineer, you will raise the bar for application security across the organisation. This role is measured by leverage: how well you design, automate, and scale security processes so that many engineering teams can build securely by default.

You will lead security architecture reviews and threat modelling, increasingly with the help of AI tooling, and turn one-off security work into repeatable, self-service capabilities. The role combines deep hands-on offensive and defensive security expertise with the engineering mindset needed to automate at scale. You will work closely with development, QA, DevOps, and platform teams.

Responsibilities:

Security Architecture & Threat Modelling:

  • Lead security architecture reviews and threat modelling for new and existing systems, using AI tools to make reviews faster, more consistent, and scalable across teams
  • Act as a security force multiplier by influencing the standards, patterns, and guardrails that let teams move fast and stay secure

Security Automation & Tooling:

  • Design, build, and automate scalable security processes that engineering teams can self-serve, covering secure design review, threat modelling, testing, and remediation workflows
  • Integrate and automate security checks across the SDLC and CI/CD pipelines (SAST, DAST, SCA, secrets, and IaC scanning), tuned for strong signal and low friction
  • Own and evolve security tooling such as DefectDojo and SAST, DAST, and SCA platforms, maximising automation, coverage, and integration
  • Apply AI and LLM-based tooling to architecture review, threat modelling, code review, and vulnerability triage, and help define how the team adopts these tools safely

Security Testing & Vulnerability Management:

  • Conduct and oversee security assessments of web and mobile applications, APIs, and cloud infrastructure, including manual testing and PoC development
  • Run vulnerability scans across internal infrastructure and the external perimeter, then analyse findings, define remediation, and track issues to closure
  • Support and triage the Bug Bounty Program and external vulnerability reports, automating triage where possible
  • Participate in and help lead red teaming and offensive security exercises

Enablement:

  • Drive knowledge sharing on secure development, mentor engineers, and deliver training for development and QA teams

Requirements:

Experience:

  • 5+ years in application or product security, or equivalent depth, with a track record of senior or staff-level impact
  • Demonstrable experience leading security architecture reviews and threat modelling (e.g. STRIDE, attack trees, data-flow analysis) across multiple teams or products
  • Proven ability to automate and scale security processes by building tooling, integrations, and self-service workflows that reduce manual effort

Technical:

  • Strong hands-on security testing skills, including code review and web, mobile, and API application security assessments, as well as the ability to triage and validate external vulnerability reports and bug bounty submissions
  • Strong software engineering ability in at least one language (e.g. Python, Go, JavaScript), with the ability to build automation, not just scripts
  • Deep understanding of the OWASP Top Ten, secure design, and secure coding best practices
  • Experience with SAST, DAST, SCA, and vulnerability management platforms, and integrating them into CI/CD
  • Strong understanding of modern application architectures: REST APIs, microservices, cloud-based systems, and containers
  • Practical experience applying AI and LLM tooling to security work, or clear enthusiasm and aptitude to do so

Collaboration:

  • Excellent communication and influencing skills: you can explain security concepts to technical and non-technical stakeholders and drive change without direct authority
  • A self-starter who enjoys solving complex problems, building leverage through automation, mentoring others, and strengthening security culture

Nice to have:

  • Experience securing the AI harness: hardening LLM and agent pipelines, prompts, tool and MCP integrations, and model endpoints against prompt injection, data leakage, and insecure agent actions
  • Experience securing Kubernetes, including cluster hardening, RBAC, network policies, admission control, workload isolation, and image and supply-chain security
  • Experience securing AWS infrastructure, including IAM, network and account architecture, key and secret management, and CSPM
  • Experience building AI-assisted security tooling or internal self-service security platforms
  • Experience mentoring or technically leading a security team
  • Offensive or advanced security certifications such as OSAI, OSEP, OSCP, or OSWE

What you’ll get in return:

  • You will join the company, that cares about work and life balance
  • Annual Bonus based on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with 30 more remote days available.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Application Security Architect at Capital.com

Defines application security architecture, threat-modeling practices, secure development standards, and product security requirements for regulated trading platforms.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.

Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.

Responsibilities:

Security Architecture & Standards:

  • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
  • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
  • Lead the redesign of user authentication and the delivery of security features into the product
  • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room
  • Define internal policies for the safe use of AI-assisted and vibe-coding tools
  • Define security requirements for acquired technology and guide its secure integration

Threat Modelling & Design Review:

  • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product’s risk tier
  • Own the security review stage of the new product approval process, covering architecture design and configuration
  • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
  • Identify design-level risks and agree practical, prioritised mitigations with engineering teams

Secure SDLC, DevSecOps & Supply Chain:

  • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership
  • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering
  • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths
  • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
  • Improve the security of our internal tools

Requirements:

Experience:

  • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership
  • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
  • Deep, demonstrable threat-modelling experience across product portfolios

Technical:

  • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
  • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
  • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients

Collaboration:

  • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
  • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
  • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Nice to have:

  • Experience in fintech, trading, brokerage, or another regulated environment
  • Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
  • Software supply-chain security, including SBOMs and artifact and build integrity
  • Experience securing AI-integrated product features, or using AI to scale an AppSec programme
  • Experience building or running a Security Champions programme
  • CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience

What you’ll get in return:

  • You will join the company, that cares about work and life balance
  • Annual Bonus based on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with 30 more remote days available.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Application Security Engineer at Capital.com

Leads application security architecture, threat modeling, offensive testing, vulnerability management, and automated security tooling across engineering teams.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

Capital.com’s Product Security team protects our web and mobile applications, infrastructure, and external perimeter in a highly regulated environment. As Senior/Staff Application Security Engineer, you will raise the bar for application security across the organisation. This role is measured by leverage: how well you design, automate, and scale security processes so that many engineering teams can build securely by default.

You will lead security architecture reviews and threat modelling, increasingly with the help of AI tooling, and turn one-off security work into repeatable, self-service capabilities. The role combines deep hands-on offensive and defensive security expertise with the engineering mindset needed to automate at scale. You will work closely with development, QA, DevOps, and platform teams.

Responsibilities:

Security Architecture & Threat Modelling:

  • Lead security architecture reviews and threat modelling for new and existing systems, using AI tools to make reviews faster, more consistent, and scalable across teams
  • Act as a security force multiplier by influencing the standards, patterns, and guardrails that let teams move fast and stay secure

Security Automation & Tooling:

  • Design, build, and automate scalable security processes that engineering teams can self-serve, covering secure design review, threat modelling, testing, and remediation workflows
  • Integrate and automate security checks across the SDLC and CI/CD pipelines (SAST, DAST, SCA, secrets, and IaC scanning), tuned for strong signal and low friction
  • Own and evolve security tooling such as DefectDojo and SAST, DAST, and SCA platforms, maximising automation, coverage, and integration
  • Apply AI and LLM-based tooling to architecture review, threat modelling, code review, and vulnerability triage, and help define how the team adopts these tools safely

Security Testing & Vulnerability Management:

  • Conduct and oversee security assessments of web and mobile applications, APIs, and cloud infrastructure, including manual testing and PoC development
  • Run vulnerability scans across internal infrastructure and the external perimeter, then analyse findings, define remediation, and track issues to closure
  • Support and triage the Bug Bounty Program and external vulnerability reports, automating triage where possible
  • Participate in and help lead red teaming and offensive security exercises

Enablement:

  • Drive knowledge sharing on secure development, mentor engineers, and deliver training for development and QA teams

Requirements:

Experience:

  • 5+ years in application or product security, or equivalent depth, with a track record of senior or staff-level impact
  • Demonstrable experience leading security architecture reviews and threat modelling (e.g. STRIDE, attack trees, data-flow analysis) across multiple teams or products
  • Proven ability to automate and scale security processes by building tooling, integrations, and self-service workflows that reduce manual effort

Technical:

  • Strong hands-on security testing skills, including code review and web, mobile, and API application security assessments, as well as the ability to triage and validate external vulnerability reports and bug bounty submissions
  • Strong software engineering ability in at least one language (e.g. Python, Go, JavaScript), with the ability to build automation, not just scripts
  • Deep understanding of the OWASP Top Ten, secure design, and secure coding best practices
  • Experience with SAST, DAST, SCA, and vulnerability management platforms, and integrating them into CI/CD
  • Strong understanding of modern application architectures: REST APIs, microservices, cloud-based systems, and containers
  • Practical experience applying AI and LLM tooling to security work, or clear enthusiasm and aptitude to do so

Collaboration:

  • Excellent communication and influencing skills: you can explain security concepts to technical and non-technical stakeholders and drive change without direct authority
  • A self-starter who enjoys solving complex problems, building leverage through automation, mentoring others, and strengthening security culture

Nice to have:

  • Experience securing the AI harness: hardening LLM and agent pipelines, prompts, tool and MCP integrations, and model endpoints against prompt injection, data leakage, and insecure agent actions
  • Experience securing Kubernetes, including cluster hardening, RBAC, network policies, admission control, workload isolation, and image and supply-chain security
  • Experience securing AWS infrastructure, including IAM, network and account architecture, key and secret management, and CSPM
  • Experience building AI-assisted security tooling or internal self-service security platforms
  • Experience mentoring or technically leading a security team
  • Offensive or advanced security certifications such as OSAI, OSEP, OSCP, or OSWE

What you’ll get in return:

  • You will join the company, that cares about work and life balance
  • Annual Bonus based on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with 30 more remote days available.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Application Security Architect at Capital.com

Leads application security architecture, threat modeling, secure coding standards, and security reviews for trading platforms and backend services.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

Capital.com builds and operates web and mobile trading platforms, public and partner APIs, and the backend services behind them, all in a highly regulated environment. As Application Security Architect, you will be the senior design authority for the security of these products. You will set the direction for how we secure software at scale: you will own secure-by-design patterns and standards, lead threat modelling and architecture reviews, and define the application security baseline that engineering teams build against.

Working closely with the Product Security team and the Director of Product Security, you will guide AppSec processes and set the vision for your area without direct line management. You will treat security as a shared outcome rather than a gate, balancing strong protection with developer experience and delivery speed, and you will earn adoption through enablement rather than mandates.

Responsibilities:

Security Architecture & Standards:

  • Define and maintain secure-by-default reference architectures for common patterns: web apps, mobile backends, microservices, public and partner APIs, and event-driven services
  • Own core application security architecture decisions: authentication and authorisation, session management, API security, secrets management, multi-tenant isolation, and security logging and auditing
  • Lead the redesign of user authentication and the delivery of security features into the product
  • Develop and roll out application security standards, secure-coding guidelines, configuration standards, reusable design patterns, and architecture decision records (ADRs) that engineers can apply without a security expert in the room
  • Define internal policies for the safe use of AI-assisted and vibe-coding tools
  • Define security requirements for acquired technology and guide its secure integration

Threat Modelling & Design Review:

  • Establish and run a threat-modelling operating model, covering scope, cadence, templates, and facilitation, proportionate to each product’s risk tier
  • Own the security review stage of the new product approval process, covering architecture design and configuration
  • Lead design reviews for high-impact initiatives: new products, new auth flows, payment and sensitive-data flows, platform migrations, and major refactors
  • Identify design-level risks and agree practical, prioritised mitigations with engineering teams

Secure SDLC, DevSecOps & Supply Chain:

  • Assess the current state of application security, propose improvements, and drive the secure SDLC strategy with Engineering and Security leadership
  • Oversee AppSec processes and own the tooling strategy (SAST, DAST, IAST, SCA, and secrets scanning), including how findings flow back to engineering
  • Embed security controls as guardrails in CI/CD through policy-as-code, with agreed enforcement and escalation paths
  • Partner with DevOps to organise repository management and prevent supply-chain attacks, covering safe component usage, dependency management, SBOMs, and build integrity
  • Improve the security of our internal tools

Requirements:

Experience:

  • 8+ years in technology, including 5+ years in a dedicated application or product security role, with a strong engineering background and hands-on architecture or design ownership
  • Proven track record creating, documenting, and rolling out security standards, patterns, and best practices across a complex engineering organisation
  • Deep, demonstrable threat-modelling experience across product portfolios

Technical:

  • Experience designing and implementing a secure SDLC in a cloud-native environment. Strong AWS knowledge is required, and exposure to GCP or other clouds is welcome
  • Strong command of OWASP standards (Top 10, ASVS) and DevSecOps practice, including AppSec tooling (SAST, DAST, IAST, SCA, secrets scanning) and vulnerability management
  • Deep understanding of modern distributed architectures: microservices, REST and GraphQL APIs, event-driven systems, OAuth2/OIDC, and containerised workloads (Docker, Kubernetes). You should be able to reason about their trust boundaries, attack surface, and data flows across web and mobile clients

Collaboration:

  • Exceptional ability to influence and align engineering teams without direct authority, and to brief both engineers and executives
  • Pragmatism and strategic thinking: you balance the ideal with the achievable, protect delivery throughput, and turn long-term direction into an actionable plan
  • Clear written communication through diagrams, ADRs, and patterns, plus a track record of mentoring and cross-functional collaboration

Nice to have:

  • Experience in fintech, trading, brokerage, or another regulated environment
  • Awareness of relevant regulatory and compliance drivers: FCA and CySEC operational resilience, GDPR, and PCI DSS
  • Software supply-chain security, including SBOMs and artifact and build integrity
  • Experience securing AI-integrated product features, or using AI to scale an AppSec programme
  • Experience building or running a Security Champions programme
  • CSSLP, GIAC GDSA, or a hands-on offensive security certification. Certifications are valued but secondary to demonstrated experience

What you’ll get in return:

  • You will join the company, that cares about work and life balance
  • Annual Bonus based on the performance review cycle
  • Generous Annual Leave Policy
  • Medical Insurance and Pension fund, with additional benefit packages based on the location
  • Hybrid working model (3 days from our modern office and 2 days fully remotely)
  • Comprehensive Workation Policy with 30 more remote days available.
  • Possibility of taking two additional days of paid leave per year to dedicate to volunteering efforts.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Software Engineer – Infrastructure Security

Builds and maintains infrastructure security systems as a senior software engineer for Quora.

Senior Remote Posted 3 days ago Jobicy AI
What this role involves
[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by...
Read the full description
Security Business Systems Security Analyst at Wrike

Secures Salesforce and other SaaS business systems by managing permissions, integrations, data flows, privacy, and governance.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Wrike is the most powerful work management platform. Built for teams and organizations looking to collaborate, create, and exceed every day, Wrike brings everyone and all work into a single place to remove complexity, increase productivity, and free people up to focus on their most purposeful work.

Wrike is our people, not a place. As a distributed team, we own our growth, stay globally connected, and rely on the product we build to deliver impactful work alongside brilliant minds. You’ll have real ownership over meaningful work, a global team that has your back, and the flexibility to do your best work your way. If that sounds like you, we’d love to hear from you.

Our vision: A world where everyone is free to focus on their most purposeful work, together.

About the Role:

You’ll work alongside diverse, cross-border teams and supportive colleagues who share knowledge and want to see you succeed. Salesforce, Marketo, Salesloft, and a growing web of integrated SaaS tools run large parts of Wrike’s business. As that footprint grows, we’re hiring a dedicated analyst to bring stronger visibility, governance, and risk understanding to this business systems estate — partnering closely with the teams who own and use these tools.

Your Impact:

  • Own security for Wrike’s business systems SaaS tools such as Salesforce, Marketo, Salesloft, and the integrations that connect them, covering permissions, sharing rules, connected apps, OAuth scopes, and integrations.
  • Build and maintain clear visibility into what data lives in these systems, why it’s there, and how it flows between integrated tools.
  • Partner with RevOps, Marketing, Legal and others to embed security into how these platforms are configured, extended, and connected to third-party services.
  • Translate security and business-continuity issues into clear, actionable terms for non-technical stakeholders.
  • Ensure business systems handling personal data hold up against privacy frameworks including GDPR and CCPA, in close collaboration with Legal and Compliance.
  • Chase data-flow and permission questions to ground truth which means following through until the answer and its implications are genuinely clear.

Your Qualifications:

Your primary expertise is in Salesforce administration and business systems security. Everything else listed here is context you’ll operate in. Depth in the primary domain matters more than breadth across all of them.

  • Salesforce administration experience with a strong security lens. This means permissions, sharing rules, connected apps, and integration patterns.
  • Solid understanding of how business systems interconnect and why that matters for data exposure and business continuity.
  • Able to communicate issues precisely to both technical and non-technical audiences.
  • Working knowledge of privacy frameworks such as GDPR and CCPA at minimum.

You don’t need to tick every box! We’re looking for depth in business systems security and the drive to grow across the rest.

Standout Qualities:

  • Certified Salesforce Administrator credential.
  • Security+, ISC2 CC, or an equivalent security certification.
  • Experience auditing or governing SaaS-to-SaaS integrations
  • Exposure to data security posture management (DSPM) or data classification in SaaS environments.
  • You use AI as a force multiplier — to move faster, think wider, and go deeper — but your security instincts and judgement are your own. You don’t outsource thinking to a tool.
  • Demonstrated tenacity in chasing complex data flows and access permissions across multi-tool integrations to a definitive answer.

Team Dynamics:

You will be joining Wrike’s 15-member global Security team led by Maksim Pekuryn, Director of Security. You will report directly to Swen Groeneveld, Head of Security Operations, whose 8-person sub-team includes Security Engineers, Application Security, and SOC specialists. You’ll also work closely with cross-functional partners in RevOps, Marketing, and Legal.

Our Work Style:

  • Tech stack: Salesforce, Marketo, Salesloft, OAuth integrations, connected apps, and related business SaaS tooling.
  • Collaborative environment working closely with RevOps, Legal, and Marketing teams.
  • Hybrid mode.

Benefits & Perks:

  • 25 calendar days of paid vacation
  • Sick Leave Compensation (5 Paid Uncertified Sick Days)
  • Parental Leave: 18 Weeks Maternity / 4 Week Paternity
  • 2 Volunteer Days
  • Medical Insurance (Employees + Dependents)
  • Hybrid Working Model
  • School Allowance (Up to €600/month for school aged kids)
  • Simcard w/ Unlimited Internet Access for active employees
  • Office Lunch Allowance (via Wolt) on Wednesdays / Thursday

What’s Next?

  • Recruiter Screen (30 mins)
  • Department Interview / Technical Discussion (60 mins)
  • Cultural Interview with Hiring Manager, CISO, and HRBP

Your recruitment buddy will be Aleksandar Chernev, Senior Technical Recruiter.

#LI-AC1

Who Is Wrike and Our Culture

We’re a team of innovators and creators who solve the complex work problems of today and tomorrow.

Hybrid work mode

Wrike is our people, not a place. With 1,000+ employees collaborating across nearly every time zone, we support talent through 10 global hubs — Australia, Costa Rica, Cyprus, Czechia, Estonia, France, India, Ireland, Japan, and the United States — offering flexible ways of working that include remote work, hybrid environments, and co-working spaces across many locations.

While flexibility looks different across teams and regions, employees located near certain hubs — particularly in Prague (CZ), Nicosia (CY), Bangalore (IN), and Rennes (FR) — are generally expected to collaborate in person around 2–3 days per week, balancing the flexibility of distributed work with opportunities for in-person collaboration and connection.

Our persona

💡  Smart: We love what we do, and we’re great at it because this is our domain. Our combined knowledge in this space is unmatched.

💚  Dedicated: We get up every day focused on helping our customers win. We’re committed to helping our teammates win, too!

đŸ€—Â  Approachable: We’re friendly, easy to get along with, considerate, and helpful.

Our culture and Values

đŸ€© Customer-Focused

We care about our customers. We understand the customer journey, experience, and value derived from Wrike. Decision-making and action-taking are done with the customer in mind.

đŸ€ Collaborative

We work as one and win together, each bringing unique strengths that contribute to diversity of thought for better outcomes. Leveraging our own work management platform, we foster an environment of creative collaboration and shared achievement.

🎹 Creative

We strive to succeed through continuous innovation. It’s our pursuit of novel concepts that helped us create a market category. We continue to cultivate a workplace that fosters creative thinking as a means of transcending conventional boundaries and empowers us to break new ground to deliver extraordinary work management solutions.

đŸ’Ș Committed

We believe in ownership at all levels of the organization, by owning workflows from start to finish. Each member of our team is an integral part of this commitment, establishing work as a platform for personal growth and transformation, as well as collective success and growth.

Check out our LinkedIn Life Page, Company culture page, Instagram, Wrike Engineering Team, Medium, Meetup.com, Youtube for a feel for what life is like at Wrike.

Read the full description
Security Senior Security Engineer - Enterprise Security at Samsara

Operates and improves enterprise security systems, zero-trust controls, access policies, device trust, monitoring, and incident triage.

Senior Remote Posted 4 days ago RemoteFirstJobs Product
What this role involves

Who we are

Samsara (NYSE: IOT) is the pioneer of the Connected Operationsℱ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale.

Working at Samsara means you’ll help define the future of physical operations and be on a team that’s shaping an exciting array of product solutions, including Video-Based Safety, Vehicle Telematics, Apps and Driver Workflows, and Equipment Monitoring. As part of a recently public company, you’ll have the autonomy and support to make an impact as we build for the long term.

About the role:

The Senior Security Engineer – Enterprise Security shares ownership of the day-to-day operation of the Samsara security environment. You will keep our network access, device trust, and visibility systems running, tuned, and resilient at enterprise scale in partnership with a global team. Utilizing modern principles, you’ll maintain and evolve a modern zero trust program, spend time both on policy design and real-time triage for escalations.

You take security seriously and believe the best solutions are low-friction and built in partnership with others. You are comfortable owning and maintaining production systems for long term success - troubleshooting systemic issues, tuning policies based on real incidents, and continuously improving what is already built. You bring an automation mindset to repetitive work, whether using Python, SOAR platforms, or AI-assisted tools. You enjoy supporting teammates and helping other engineers build their security knowledge.

This is a remote position open to candidates residing in the United Kingdom. Relocation assistance will not be provided for this role.

About this team:

Enterprise Security is a global team spanning the US, EMEA, and India. We work in close partnership with our coworkers as collaborators rather than gatekeepers. Leadership is hands-on and technical, and our culture encourages everyone to contribute across the full stack.

Executive leadership actively champions security as a competitive advantage that builds customer trust and helps win enterprise partnerships. You will see a direct line between the zero trust systems you operate and the security that protects our physical operations partners worldwide. Our on-call rotation for the highest severity incidents is spread evenly across the team for one week out of every ten.

In this role, you will:

  • Co-own the day-to-day operation, triage, and tuning of the Samsara endpoint security environment by responding to escalations, investigating anomalies, and resolving issues
  • Continuously improve existing endpoint visibility tools and workflows in partnership with our Security Operations team, and based on real usage patterns and incident learnings
  • Write clear, concise documentation and runbooks for enterprise security workflows
  • Collaborate with partners across Engineering, IT, and Security to ensure proper implementation of security tools and policies
  • Assist the Security Operations team during security investigations, acting as a technical subject matter expert within your domain
  • Partner with engineering teams to triage and support remediation of vulnerabilities and misconfigurations
  • Mentor engineers on the Security team to grow their domain knowledge, tool-specific skills, and communication abilities
  • Champion, role model, and embed Samsara cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team)

Minimum requirements for the role:

  • 5+ years of relevant experience in an Enterprise Security role with demonstrated impact
  • Hands-on experience operating and maintaining endpoint security and visibility tools at enterprise scale (e.g. Crowdstrike, osquery, or similar)
  • Exposure to at least one additional enterprise security tool stack beyond endpoint security, such as Secure Access Service Edge (SASE), zero trust systems,  email security, Data Loss Prevention (DLP), or Identity and Access Management (IAM)
  • An automation mindset with experience scripting and debugging code with Python (with or without AIassistance) and using SOAR platforms
  • Strong familiarity with common security challenges and the ability to independently evaluate their severity and business impact
  • Track record of delivering impactful work across multiple quarters and collaborating effectively across teams

An ideal candidate also has:

  • Significant breadth across the endpoint security ecosystem, including designing layered controls with EDR tools, passive telemetry, integration with threat intelligence feeds, and operation in cloud and containerized environments.
  • History of building out security programs using modern SaaS security platforms such as Crowdstrike, Mimecast Incydr, and Splunk
  • Experience with infrastructure as code deployments using Terraform
  • Experience with AI-driven automations

Total Rewards

At Samsara, we build for the people who keep the global economy moving. We want owners, not passengers, which is why our rewards are designed to fuel high-impact builders. Our compensation program delivers above-market total compensation through a combination of base salary, performance-based bonus/variable pay, and equity (for eligible roles) in a high-growth public company. We meaningfully differentiate pay for our top performers, who have the opportunity to earn above-market compensation that can outpace the broader market over time.

Beyond compensation, we provide the foundations that enable long-term success: a flexible, employee-led remote model, a professional development stipend, comprehensive health and parental leave plans, and more. If you’re ready to build for the long term and own the outcome, your journey starts here.

Flexible Working

At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams. Our offices are open for those who prefer to work in-person and we also support remote work where it aligns with our operational requirements. For certain positions, being close to one of our offices or within a specific geographic area is important to facilitate collaboration, access to resources, or alignment with our service regions. In these cases, the job description will clearly indicate any working location requirements. Our goal is to ensure that all members of our team can contribute effectively, whether they are working on-site, in a hybrid model, or fully remotely. All offers of employment are contingent upon an individual’s ability to secure and maintain the legal right to work at the company and in the specified work location, if applicable.

Belonging at Samsara

At Samsara, we welcome everyone regardless of their background. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, protected veteran status, disability, age, and other characteristics protected by law. We depend on the unique approaches of our team members to help us solve complex problems and want to ensure that Samsara is a place where people from all backgrounds can make an impact.

Accommodations

Samsara is an inclusive work environment, and we are committed to ensuring equal opportunity in employment for qualified persons with disabilities. Please email accessibleinterviewing@samsara.com or click here if you require any reasonable accommodations throughout the recruiting process.

Our Commitment to Authenticity

We use Tofu, a fraud detection tool, to validate the authenticity of applications and protect against identity fraud. This ensures we are connecting with real people and allows us to prioritize genuine candidates. Please see Samsara’s Candidate Privacy Notice for more information.

Fraudulent Employment Offers

Samsara is aware of scams involving fake job interviews and offers. Please know we do not charge fees to applicants at any stage of the hiring process. Official communication about your application will only come from emails ending in @samsara.com, @us-greenhouse-mail.io or @mail3.guide.co. For more information regarding fraudulent employment offers, please visit our blog post here.

Read the full description