Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Product Security Engineer at LaunchDarkly

Leads threat modeling and cloud security posture assessments while triaging security findings, partnering with engineering teams to embed security into the development lifecycle.

Senior Posted about 12 hours ago RemoteFirstJobs Product
What this role involves

About the Job:

LaunchDarkly’s Product Security team is hiring a Product Security Engineer II to strengthen how we secure the platform engineers build with every day. You’ll bring depth in security fundamentals and program design as a member of a small, high-leverage team with strong engineering instincts.

LaunchDarkly is critical infrastructure. Our security team keeps it safe for the global systems that depend on us. You’ll spend most of your time on threat modeling and cloud security posture, with rotating exposure to the rest of the ProdSec surface area. Your work will help developers move fast without sacrificing security, through automation, guidance, and the kind of partnership that makes the secure path the easy one.

You’ll report to the Director of Security and work closely with software engineers, product managers, and other security engineers. We expect you to bring a sharp point of view on where AI can take work off the team’s plate and make our coverage deeper.

Responsibilities:

  • Lead threat modeling engagements on the features and services where the risk warrants it.

  • Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running.

  • Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup.

  • Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team’s work demands.

  • Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives.

  • Bring AI to the work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts.

  • Push the security floor up over time through documentation, office hours, small tooling improvements, and the kind of compounding work that prevents incidents rather than responds to them.

About You:

  • You’re proactive by default. You’d rather spot drift early and fix the cause than chase symptoms after an incident.

  • You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs.

  • You invest in relationships with the engineering, product, and leadership teams you work with.

  • You know security work moves at the speed of trust.

  • You’re a good partner. You’re helpful and direct, you say no with reasons and alternatives, and you don’t mistake gatekeeping for rigor.

  • You’re security-first by background but engineering-curious by nature. You want to understand how the systems work, not just what’s wrong with them.

  • You treat AI as part of the toolkit. You’re skeptical where you should be, aggressive where it pays off, and you want to work somewhere that’s serious about both.

Qualifications:

  • 2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred.

  • Comfortable reading and critiquing pull requests in a modern stack. You don’t need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps.

  • Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent).

  • Working knowledge of cloud security posture. Exposure to a CNAPP is a strong plus.

  • Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, common cloud misconfigurations.

  • Hands-on experience applying AI tooling to security or engineering work. You can point to specific examples where it changed how you operated.

Nice to Haves:

  • Experience with developer tools, SaaS platforms, or feature management

  • Bug bounty triage experience (HackerOne, Bugcrowd)

  • Familiarity with Go, Python, or TypeScript

  • Contributions to internal security tooling or open-source security projects

Pay:

Target pay ranges based on Geographic Zones* for Level 2:

  • Zone 1: San Francisco/Bay Area or NYC Metropolitan Area, Boston, Seattle - $136,500 - $187,660*
  • Zone 2: Irvine, LA, Monterey, Santa Barbara, Santa Rosa, Austin, Portland, Philadelphia, Chicago - $122,800 - $168,850**
  • Zone 3: All other US locations - $116,000 - $159,500**

LaunchDarkly operates from a place of high trust and transparency; we are happy to state the pay range for our open roles to best align with your needs. Exact compensation may vary based on skills, experience, and location.

*Within the United States, our geographic pay zones are defined by counties surrounding major metropolitan areas.

**Restricted Stock Units (RSUs), health, vision, and dental insurance, and mental health benefits in addition to salary.

About LaunchDarkly:

Modern software delivery was supposed to be the foundation for a thriving digital business but reality has proven otherwise. Slow, inefficient development cycles, costly outages, and fragmented customer experiences are preventing developers from building their best software. The LaunchDarkly platform helps developers innovate on new features faster while protecting them with a safety valve to instantly rewind when things go wrong. Developers can target product experiences to any customer segment and maximize the business impact of every feature. And by gradually rolling out new application components, they escape nightmare “big-bang” technology migrations.

The LaunchDarkly platform was built to guide engineers to the next frontier of DevOps by:

  • Improving the velocity and stability of software releases, without the fear of end customer outages
  • Delivering targeted experiences by easily personalizing features to customer cohorts
  • Maximizing the business impact of every feature through the ability to experiment and optimize
  • Coordinating the release and optimization of software to provide consistent experiences across mobile platforms and device types
  • Improving the effectiveness and productivity of engineering teams, by providing insights into engineering cadence and stability

At LaunchDarkly, we believe in the power of teams. We’re building a team that is humble, open, collaborative, respectful and kind. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, or disability status. LD invites any applicant to review our written Affirmative Action Plan. To do so, contact People Ops at hr@launchdarkly.com.

Do you need a disability accommodation?

Fill out this accommodations request form and someone from our People Operations team will contact you for assistance.

Your safety matters to us. To protect yourself from potential scams, LaunchDarkly recruiters will only contact you from @LaunchDarkly.com email addresses or via LinkedIn from “Verified Recruiter” accounts.Be cautious of emails from other domains.  Legitimate LaunchDarkly recruiters will never ask for money, fees, or banking information before making a job offer. LaunchDarkly will never make a job offer without conducting a formal interview process. Our interview process does not involve asking detailed questions by email. If you are ever unsure about a communication that you receive, don’t click any links—visit Careers | LaunchDarkly  directly for confirmed job openings and links to apply.

Please notify us of any fraudulent representation by sending an email to careers@launchdarkly.com.

Read the full description
Security Expel: Managed SIEM Detection Engineer

Detection engineer who authors and tunes SIEM detection content, optimizes security tooling, and delivers professional services engagements to help customers close coverage gaps and reduce alert noise.

Mid Remote Posted about 15 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor's degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range$111,900—$162,300 USD

To apply: https://weworkremotely.com/remote-jobs/expel-managed-siem-detection-engineer

Read the full description
Security Industrial Security Analyst / Facility Security Officer (FSO) at Red Cell Partners

Administers industrial security programs for a cleared defense contractor, ensuring NISPOM compliance and overseeing personnel security, operations security, and visitor control.

Mid Hybrid Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

About Defcon AI

RESILIENCE IN THE FACE OF DISRUPTION. Defcon AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, Defcon AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

We are seeking an Industrial Security Analyst / Facility Security Officer (FSO) to support and help scale our security program as DEFCON AI’s classified work continues to grow. This individual will play a key role in maintaining compliance with government security requirements while helping build the processes, controls, and culture needed to support a rapidly growing defense technology company.

This is a hybrid position based in McLean, VA, with an expectation of three days per week in the office.

Position Overview

The Industrial Security Analyst / FSO is responsible for the day-to-day administration and oversight of DEFCON AI’s Industrial Security Program. This role ensures compliance with the National Industrial Security Program Operating Manual (NISPOM), customer requirements, and internal security policies while supporting employees, leadership, and external security partners.

The ideal candidate has experience supporting industrial security programs within a cleared contractor environment and is comfortable operating in a fast-paced organization where security processes continue to evolve and mature.

What You’ll Do

Industrial Security & Compliance

  • Support day-to-day industrial security operations across multiple disciplines, including Personnel Security (PERSEC), Operations Security (OPSEC), Contract Security, Security Education, Training and Awareness (SETA), Visitor Control, Investigations, and Document Control
  • Ensure compliance with NISPOM, ICD requirements, customer security requirements, and internal security policies
  • Maintain readiness for DCSA, customer, and internal security inspections and compliance reviews
  • Conduct self-inspections, identify areas for improvement, and implement corrective actions
  • Support the ongoing development and maturation of DEFCON AI’s industrial security program

Personnel & Program Security

  • Process and manage personnel security requirements, including clearance actions, visit requests, visit authorizations, and onboarding activities
  • Maintain personnel security records and related databases
  • Investigate security incidents and violations and ensure proper reporting and resolution in accordance with government and company requirements
  • Provide security guidance and support to employees, consultants, and approved visitors
  • Support contract security requirements, including DD Form 254 administration and subcontractor security management

Classified Information Protection

  • Maintain classified material accountability programs and secure storage requirements
  • Conduct inventories and maintain accountability of classified information and assets
  • Ensure proper marking, handling, transmission, storage, transportation, sanitization, reuse, and destruction of classified information and media
  • Support the protection of classified facilities, systems, and information in accordance with applicable regulations

Security Training & Program Development

  • Develop and administer Security Awareness, Annual Refresher, and OPSEC training programs
  • Create and maintain required security documentation, including SOPs, OPSEC plans, CONOPS, security procedures, and work instructions
  • Promote a culture of security awareness and compliance throughout the organization

Security Systems & Inspection Readiness

  • Maintain records and security actions within NISS, DISS, and other government security systems as required
  • Support DCSA, customer, and internal inspections and audits
  • Assist with corrective action implementation and continuous process improvement initiatives

Required Qualifications

  • Bachelor’s degree and 6+ years of industrial security or related experience; OR Master’s degree and 4+ years; OR Associate’s degree and 8+ years; OR High School diploma and 12+ years of relevant experience

  • Active U.S. Government Top Secret security clearance and ability to obtain and maintain SCI and SAP access

  • Strong knowledge of NISPOM (32 CFR Part 117), ICD security requirements, and industrial security compliance standards

  • Understanding and familiarity of DD-254 implementation requirements including issuing Subcontract DD-254 using NI2

  • Experience supporting personnel security, classified material control, and compliance programs within a cleared contractor environment

  • Experience utilizing government security systems such as NISS, DISS, or similar platforms

  • Strong organizational, communication, and problem-solving skills

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Outlook

Preferred Qualifications

  • Experience serving as an FSO, AFSO, or Industrial Security Specialist within a cleared facility
  • CDSE FSO Program Management Certification for Processing and/or Non-Possessing Facilities
  • Experience supporting multiple classified programs and government customers
  • Experience preparing for and supporting DCSA or other government inspections
  • Knowledge of DD Form 254 requirements and subcontractor security administration
  • Experience supporting SCI and/or SAP programs
  • Experience building, improving, or scaling security processes within a growing organization
  • Strong customer service skills and the ability to build trusted relationships with internal and external stakeholders
  • Ability to work independently, manage competing priorities, and thrive in a fast-paced environment

Why DEFCON AI

At DEFCON AI, you’ll help build and scale security capabilities that directly support critical national security missions. You’ll work alongside a mission-driven team developing AI-powered solutions for some of the Department of War’s most complex operational challenges.

What We Offer:

  • A fully remote environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $120,000-$150,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits (may differ for each incubation):

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security Cybersecurity Compliance Analyst (Hybrid - Bay Area) at Xantrion

Analyzes client cybersecurity controls, develops compliance documentation, and assesses vendor security risks using frameworks like NIST CSF and CIS Controls.

Mid Hybrid Posted 1 day ago RemoteFirstJobs Product
What this role involves

If you’re looking to join a winning information technology team and receive outstanding benefits that support your family—while working for a company that takes a people-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.

Location: San Francisco Bay Area

Hybrid: 2 days in office / 3 days remote per week

Primary Purpose and Function

Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.

This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.

Travel: None required.

Roles and Responsibilities

Client Compliance and Documentation

  • Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
  • Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
  • Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
  • Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
  • Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
  • Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
  • Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
  • Maintain annual testing schedules and track documentation, review dates, and follow-up items.
  • Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
  • Improve reusable templates and assessment procedures that support consistent delivery across clients.

Internal Compliance Support

  • Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
  • Organize audit documentation, maintain request trackers, and follow up with internal control owners.
  • Review evidence for completeness and consistency and identify missing or outdated documentation.
  • Provide seasonal support during internal audit preparation and review periods.

Position Requirements

Required Qualifications

  • Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
  • Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
  • Experience reviewing technical configurations or administrative reports against documented standards.
  • Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
  • Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
  • Ability to distinguish documented policies from evidence that controls are implemented and operating.
  • Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
  • Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
  • Professional communication skills and sound judgment when handling confidential client information.

Preferred Qualifications

  • Experience supporting registered investment advisers (RIAs) or other financial services organizations.
  • Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
  • Experience working for a managed service provider or supporting multiple client environments.
  • Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
  • Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
  • Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
  • Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
  • Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
  • A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.

Performance Metrics

The Cybersecurity Compliance Analyst performance success will be based on the following criteria:

  • Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
  • Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
  • Risk registers, crosswalks, and supporting documentation remain organized and current.
  • Internal audit requests are tracked and supported with complete, accessible evidence.
  • Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.

Physical Demands

  • Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
  • Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
  • Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
  • Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
  • Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
  • Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
  • Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
  • Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
  • Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion’s office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.

Company Policy and Procedure Compliance

  • Follow and support company policies and procedures as well as all local, state, and federal laws.
  • Always maintain confidentiality of company and customer records and information.
  • Maintain a professional image, adhering to Xantrion’s dress code.
  • Must have an existing cell phone (running current Android or iOS).
  • If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance.  See the Xantrion Handbook for details.

When Working Remote

  • Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
  • Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
  • Must use Xantrion-provided PC and headset to execute job functions.

Benefits

  • Salary range $100-120K; depending on experience.
  • 100% of medical, dental, and vision for you and your family.
  • 401K with company match up to 4% of salary.
  • Certification reimbursement and annual training budget.
  • 17 Days PTO per year in addition to paid training days.
  • Bonuses for referring new clients or employees.

Equal Opportunity Employer

Xantrion is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, age, color, sex, religion, sexual orientation, national origin, disability, medical condition, genetic information, pregnancy, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws. All employment is decided on the basis of qualifications, merit, and business needs at the time.

AI Disclosure for Recruitment

We use AI to support our recruiting team, improve the candidate experiences, and allow our teams to spend more time on meaningful candidate interactions. Our use of AI is limited to administrative tasks such as organizing application information and taking or summarizing interview notes. AI does not screen, advance, or reject candidates, and it does not make hiring or any significant decisions. Applications and candidate qualifications are reviewed by our recruiting team, and all decisions about interviews, advancement, offers, and hiring are made by our recruiters and hiring managers.

Read the full description
Security Security Engineering Manager at Stedi

Lead a security engineering team managing AWS infrastructure, compliance, and security strategy while actively coding and shipping security projects.

Lead Posted 1 day ago RemoteFirstJobs Product
What this role involves

We’re building a new healthcare clearinghouse

Stedi is the only headless clearinghouse and RCM engine. Headless means every part of our product is accessible via API. Developers and AI agents build their own interface on top of it. By offering modern, AI-ready APIs alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions. Our clearinghouse product and customer-first approach have set us apart. Stedi was ranked by Ramp as one of the fastest-growing SaaS vendors.

Stedi has lightning in a bottle: engineers and designers shipping products week in and week out; a lean business team supporting the company’s infrastructure; a passion for automation and eliminating toil; and $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more.

To see what we ship, watch the 2026 Stedi Keynote. To learn more about how we work, watch our founder Zack’s interview with First Round Capital.

What we’re looking for

Stedi is looking for a Security Engineering Manager to lead our scaling security function. This team is at the core of our infrastructure, managing multiple AWS Organizations and providing the foundational tools and services that enable our engineering teams to build reliable, secure, and compliant applications for healthcare technology companies that process transactions for millions of patients each month.

This is a true player-coach role where you’ll be managing a team of talented security engineers while still being in the weeds. You’ll own our security strategy and do the work: writing CDK, building playbooks, and pushing security projects through yourself. An ideal candidate is excited to have the leverage of setting the team’s direction while still staying deep in the technical details.

You’ll be accountable for security across AWS infrastructure, our software development lifecycle, endpoint security, and our compliance posture – and for making it seamless for every engineer at Stedi to build in a way that meets regulatory requirements without slowing down innovation.

How we build

  • We use AWS exclusively for our customer-facing backend infrastructure. We use tools like GitHub, Stripe, Vanta, and PagerDuty, but all of our application work happens on AWS.

  • We use serverless technologies almost exclusively to build our products: Lambda, API Gateway, SQS, SNS, DynamoDB, Aurora Serverless, and more. We don’t run a single server.

  • We use CDK (TypeScript) to define infrastructure as code.

What you’ll do

  • Lead and grow a high-performing security team by setting an ambitious pace with rigorous quality expectations, and by hiring as the function scales.

  • Oversee our compliance engineering posture, ensuring our processes and evidence meet SOC, HIPAA, and HITRUST requirements.

  • Manage daily engineering efforts, monitoring timelines and resources to ensure projects are executed efficiently and to a high standard.

  • Increase accountability across the team by setting clear performance expectations and regularly reviewing progress to ensure high standards are consistently met.

  • Continuously assess vulnerabilities, perform regular risk assessments, and prioritize remediation based on actual risk to the business and our customers.

  • Mentor engineers and make security a shared responsibility and focus across Stedi.

Who you are

  • 6+ years of experience in security or security adjacent roles, with at least 3+ years in a management role.

  • Experience with compliance frameworks such as SOC, HIPAA, and/or HITRUST and control design.

  • Hands-on experience in application security and endpoint security.

  • Exceptional written communication skills, with the ability to synthesize and clearly convey complex technical and risk information to both engineers and executives.

  • Proven experience managing and fostering collaboration in a remote-first environment, ensuring team alignment and cohesion.

  • A commitment to cultivating a high-performing team.

  • High bandwidth with the ability to pay thoughtful attention to many areas simultaneously.

  • Ability to context switch throughout the course of the day or week as priorities shift.

  • Philosophical alignment with the Stedi Standards.

We’ve been made aware of individuals impersonating the Stedi recruiting team. Please note:

  • All official communication about roles at Stedi will only come from an @ stedi.com email address, or from our official identification verification partner, Persona, @frompersona.com.

  • If you’re unsure whether a message is legitimate or have any concerns, feel free to contact us directly at careers@stedi.com .

We appreciate your attention to this and your interest in joining Stedi.

At Stedi, we’re looking for people who are deeply curious and aligned to our ways of working. You’re encouraged to apply even if your experience doesn’t perfectly match the job description.

Read the full description
Security Cybersecurity Engineer- Junior level

Junior cybersecurity engineer supporting DoD enterprise network modernization and infrastructure security.

Junior Posted 1 day ago Himalayas
What this role involves
Job Title: Cybersecurity Engineer- Junior levelJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee Type: RegularPercentage of Travel Required: Up to 50%Type of Travel: Continental US* * *The OpportunityCACI's Enterprise Network Services (ENS) Division supports the Department of Defense (DoD) in modernizing mission-critical communications and enterprise network infrastructures.
Read the full description
Security Penetration Tester Team Lead

Leads a penetration testing team conducting continuous security assessments using AI-powered tools and human oversight.

Lead Posted 2 days ago Himalayas
What this role involves
DescriptionTerra Security provides agentic AI-powered continuous penetration testing aligned to code changes and evolving attack surfaces, combining a swarm of trained AI agents with human supervision for safety and control.
Read the full description
Security Staff Security Engineer, Threat Intelligence

Designs and implements threat intelligence strategies to identify, analyze, and mitigate security threats across the platform infrastructure.

Senior Posted 2 days ago Himalayas
What this role involves
About Multi Media, LLCMulti Media, LLC is a global technology company operating a high-traffic live-streaming platform used by millions of people around the world.
Read the full description
Security IT Systems Auditor

Audits IT systems and controls for compliance, identifies security vulnerabilities, and ensures adherence to organizational and regulatory standards.

Mid Remote Posted 2 days ago Himalayas
What this role involves
OverviewAmyx is seeking to hire a IT Systems Auditor-II for our Defense Logistics Agency program remotely.
Read the full description
Security Head of Security at Snorkel AI

Lead and build Snorkel's security function end-to-end, including infrastructure, application, and compliance, while hiring and scaling the security team.

Lead Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Snorkel

At Snorkel, we believe meaningful AI doesn’t start with the model, it starts with the data.

We’re on a mission to help enterprises transform expert knowledge into specialized AI at scale. The AI landscape has gone through incredible changes since 2015, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today. But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems. We work with some of the world’s largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler!

About Snorkel

Snorkel AI is the frontier AI data lab, helping teams build the data and environments behind high-performing frontier and agentic AI. We combine technology with research-driven AI data development to create datasets, benchmarks, evals, and custom solutions for real-world AI systems. Founded out of the Stanford AI Lab in 2019, Snorkel works with leading AI labs and enterprises to move from better data to better outcomes.

Excited to help us redefine how AI is built? Apply to be the newest Snorkeler!

About The Role

Snorkel is hiring a Head of Security to build and lead our security function end-to-end — infrastructure security, application security, and governance, risk & compliance (GRC). You’ll own the security function end-to-end — strategy, team, and execution — and operate as the primary security voice with customers, auditors, and the exec team. You’ll report to the CTO.

This is a builder’s role: you’ll take security from its current state to a mature, right-sized function as Snorkel scales, hiring and developing the team as needs grow.

Key Responsibilities

Security Leadership & Team Building

  • Define Snorkel’s overall security strategy, goals, and roadmap across infrastructure, application, and compliance domains
  • Build, hire, and lead a high-performing security organization — starting lean and scaling deliberately as the company and its risk surface grow
  • Establish the operating cadence for security (metrics, reporting, incident response, risk register) and represent security posture to the executive team and board

Infrastructure & Cloud Security

  • Own cloud security architecture and posture across AWS (and other cloud providers as adopted) — IAM, network segmentation, encryption, landing zone design
  • Direct detection & response capabilities, threat modeling, and vulnerability management programs
  • Set standards for secure infrastructure-as-code, CI/CD, and secrets management

Application Security

  • Embed security into the product development lifecycle — secure design reviews, threat modeling for new features, and AI/ML-specific risks (data protection, model/prompt security, training pipeline integrity)
  • Partner with Engineering and Product leadership to build security into the SDLC without blocking velocity
  • Own application security tooling and practices (SAST/DAST/SCA, pen testing, bug bounty)
  • Design identity, access, and activity-monitoring controls that correctly handle Snorkel’s non-employee marketplace workforce — external contractor (1099 or similar) experts accessing the platform. This population isn’t in scope for standard employee compliance obligations, but provisioning, deprovisioning, access boundaries, and monitoring still need to work correctly for them

Governance, Risk & Compliance (GRC)

  • Build and run Snorkel’s compliance program (e.g., SOC 2, ISO 27001, and customer-driven frameworks) — own audits end-to-end
  • Establish enterprise risk management practices: risk register, third-party/vendor risk, policy framework
  • Serve as the primary security point of contact for customer security reviews and questionnaires

Executive & Cross-Functional Partnership

  • Act as a trusted advisor to the CTO and executive team on security risk and investment tradeoffs
  • Partner cross-functionally with Legal, Sales, Operations, and Engineering to unblock enterprise deals and support customer trust requirements
  • Communicate security posture, incidents, and roadmap clearly to both technical and non-technical audiences

Who You Are

Experience & Leadership

  • 10+ years in technology security, including significant leadership experience; you’ve held director-level or above scope
  • Track record building and scaling a security function from a founding stage (team of ~1) through a mature org (10–30+), ideally at a high-growth technology company
  • Experience owning security budget, vendor selection, and board/exec-level reporting

Technical Depth

  • Deep expertise across infrastructure/cloud security (AWS, IAM, network security, encryption) and application security (SDLC integration, threat modeling, AppSec tooling)
  • Hands-on familiarity with modern security tooling: SIEM, EDR, CSPM, vulnerability management
  • Experience working with AI/ML-specific security risks (model security, data pipeline protection, prompt injection)

Governance & Compliance

  • Proven experience building and running compliance programs (SOC 2, ISO 27001, or equivalent) from the ground up
  • Comfortable as the face of security to customers during security reviews/audits, and to auditors during certification cycles

General

  • Bachelor’s degree in Computer Science, Information Technology, or related field; advanced degree a plus
  • Excellent written and verbal communication; able to flex between board-level summary and engineering-level depth

Why This Role

You’ll have meaningful ownership over the infrastructure that determines how quickly Snorkel can experiment with, evaluate, and productionize new AI systems. This isn’t a role focused on training a single model or maintaining traditional ML pipelines - you’ll build the platform that makes large-scale AI experimentation possible.

You’ll work on some of the hardest emerging infrastructure problems in AI: operating non-deterministic systems reliably, reproducing agent behavior across environments, evaluating long-running trajectories, scaling simulations and experiments, and turning rapidly evolving research workflows into robust production systems.

The architecture decisions made by this team will define how Snorkel builds and operates AI systems for years to come.

Snorkel is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel embraces diversity and provides equal employment opportunities to all employees and applicants for employment.

Actual compensation will be determined based on factors including skills, qualifications, experience, and geographic location.

Be Your Best at Snorkel

Joining Snorkel AI means becoming part of a company that has market proven solutions, robust funding, and is scaling rapidly—offering a unique combination of stability and the excitement of high growth. As a member of our team, you’ll have meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success. Whether you’re looking to deepen your technical expertise, explore leadership opportunities, or learn new skills across multiple functions, you’re fully supported in building your career in an environment designed for growth, learning, and shared success.

Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment. Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law. All employment is decided on the basis of qualifications, performance, merit, and business need.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Actual compensation will be determined based on factors including skills, qualifications, experience, and geographic location.

Salary range(s) for this role

$252,000—$370,000 USD

Be Your Best at Snorkel

Joining Snorkel AI means becoming part of a company that has market proven solutions, robust funding, and is scaling rapidly—offering a unique combination of stability and the excitement of high growth. As a member of our team, you’ll have meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success. Whether you’re looking to deepen your technical expertise, explore leadership opportunities, or learn new skills across multiple functions, you’re fully supported in building your career in an environment designed for growth, learning, and shared success.

Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment. Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law. All employment is decided on the basis of qualifications, performance, merit, and business need.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Read the full description
Security Vigilant IT Security Manager – Portugal/Poland

Manages IT security operations and strategies for a globally distributed team across Portugal/Poland regions.

Mid Remote Posted 3 days ago Jobicy AI
What this role involves
This is not an offshoring back-office job for an international company. You will be a key player in our globally distributed team. We’re searching for a Vigilant IT Security Manager...
Read the full description
Security Cobalt Core Pentester

Conducts penetration testing and security assessments as part of a skilled pentester community.

Posted 3 days ago Jobicy AI
What this role involves
Who We Are The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the...
Read the full description
Security Cobalt Core Pentester – UK, Germany, Nordics

Conducts penetration testing and security assessments as part of a specialized pentester community across UK, Germany, and Nordic regions.

Senior Remote Posted 3 days ago Jobicy AI
What this role involves
Who We Are The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the...
Read the full description
Security GRC Manager

Manages governance, risk, and compliance programs to ensure organizational adherence to regulatory standards and security policies.

Mid Posted 3 days ago Jobicy AI
What this role involves
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in...
Read the full description
Security Senior Cloud Security Engineer

Designs, implements, and maintains cloud security infrastructure and protocols to protect institutional real estate platforms and data systems.

Senior Posted 3 days ago Himalayas
What this role involves
ABOUT GREYSTAR Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing.
Read the full description
Security Public Facing Security Researcher

Conducts security research on blockchain protocols and smart contracts, communicating findings to external stakeholders and the Web3 community.

Posted 3 days ago Jobicy AI
What this role involves
About the Company Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications...
Read the full description
Security Security Analyst (Cyber Defense Analyst)

Monitors and defends against cyber threats, analyzes security incidents, and implements defensive measures to protect enterprise systems and infrastructure.

Posted 3 days ago Himalayas
What this role involves
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
Read the full description
Security Vulnerability Research Engineer

Researches and identifies software vulnerabilities in open source code and dependencies to help organizations manage security risks.

Mid Posted 4 days ago Jobicy AI
What this role involves
About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our...
Read the full description
Security SecOps Engineer I

Manages security operations, monitors infrastructure for threats, responds to incidents, and maintains security compliance systems.

Junior Posted 4 days ago Jobicy AI
What this role involves
LivePerson (NASDAQ:LPSN) is a Conversational AI company creating digital experiences that are Curiously Human. Everyperson is unique, and our technology makes it possible for companies, including leading brands like HSBC,...
Read the full description
Security Security Assistant at Assystem

Supports personnel security operations by processing vetting applications, monitoring clearances, liaising with external agencies, and maintaining security compliance controls.

Junior Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

Company Description

Today, Assystem is among the top three independent nuclear engineering firms worldwide. With over 60 years of experience in highly regulated sectors, the group supports public and industrial stakeholders in the execution of complex and strategic infrastructure projects, subject to high safety and security requirements.

Assystem mobilizes 8,000 experts in 13 countries and intervenes across the entire project lifecycle, in engineering, project management and digital solutions.

Job Description

🔐 Security Assistant

Reporting to the Personnel Security Manager, the Security Assistant will support the company’s Personnel Security activities, with a focus on security vetting, aftercare and security compliance.

📍 Location: Bolton

🏢 Working pattern: Hybrid – 2–3 days per week in the office

🔹 Key Responsibilities

🛡️ Process vetting applications for staff and contractors, providing guidance on all types of vetting.

🔄 Monitor security clearances and ensure renewals are completed promptly.

📋 Communicate changes to vetting policies and procedures.

🤝 Liaise with external agencies and verify internal and external clearances.

🔎 Conduct thorough checks and maintain effective Personnel Security controls.

💬 Act as the main contact for vetting and security enquiries, handling information sensitively and in line with data protection requirements.

🚨 Support security incident reporting, follow-up actions and lessons learned.

📁 Provide security support for key projects.

🎫 Manage site-specific security responsibilities, including issuing site passes.

📢 Support the wider Security Department with general security activities, communications and awareness campaigns.

Qualifications

🎓 Essential Experience & Qualifications

💻 Experienced user of Microsoft Office, particularly Word and Excel

⭐ Desirable Experience

🛡️ Previous experience in a similar security role

🎓 DISA Training

👤 Person Specification

⏰ Reliable and dependable

🚀 Self-motivated and proactive

🤝 Honest and trustworthy

📋 Well organised

🎯 Able to meet deadlines and prioritise workload

🔎 Methodical and accurate

🔐 Able to gain and maintain the appropriate security clearance

Additional Information

Due to the nature of work to be undertaken applicants will be required to meet certain residency criteria in order to attain a minimum level of UK security clearance if not already security cleared to a minimum SC level.

NOTICE TO CANDIDATES ON RECRUITMENT FRAUD - We are committed to safeguarding candidates from fraudulent activity associated with our recruitment process. Please note that we will never offer specialist CV writing services, request payment or ask for sensitive personal information during the recruitment process.

We are committed to equal treatment of candidates and promote, as well as foster all forms of diversity within our company. We believe that bringing together people with different backgrounds and perspectives is essential for creating innovative and impactful solutions. Skills, talent, and our people’s ability to dare are the only things that matter !. Bring your unique contributions and help us shape the future.

Read the full description