Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Expel: Managed SIEM Detection Engineer

Detection engineer who authors and tunes SIEM detection content, optimizes security tooling, and delivers professional services engagements to help customers close coverage gaps and reduce alert noise.

Mid Remote Posted about 16 hours ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor's degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range$111,900—$162,300 USD

To apply: https://weworkremotely.com/remote-jobs/expel-managed-siem-detection-engineer

Read the full description
Security Industrial Security Analyst / Facility Security Officer (FSO) at Red Cell Partners

Administers industrial security programs for a cleared defense contractor, ensuring NISPOM compliance and overseeing personnel security, operations security, and visitor control.

Mid Hybrid Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

About Defcon AI

RESILIENCE IN THE FACE OF DISRUPTION. Defcon AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, Defcon AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

We are seeking an Industrial Security Analyst / Facility Security Officer (FSO) to support and help scale our security program as DEFCON AI’s classified work continues to grow. This individual will play a key role in maintaining compliance with government security requirements while helping build the processes, controls, and culture needed to support a rapidly growing defense technology company.

This is a hybrid position based in McLean, VA, with an expectation of three days per week in the office.

Position Overview

The Industrial Security Analyst / FSO is responsible for the day-to-day administration and oversight of DEFCON AI’s Industrial Security Program. This role ensures compliance with the National Industrial Security Program Operating Manual (NISPOM), customer requirements, and internal security policies while supporting employees, leadership, and external security partners.

The ideal candidate has experience supporting industrial security programs within a cleared contractor environment and is comfortable operating in a fast-paced organization where security processes continue to evolve and mature.

What You’ll Do

Industrial Security & Compliance

  • Support day-to-day industrial security operations across multiple disciplines, including Personnel Security (PERSEC), Operations Security (OPSEC), Contract Security, Security Education, Training and Awareness (SETA), Visitor Control, Investigations, and Document Control
  • Ensure compliance with NISPOM, ICD requirements, customer security requirements, and internal security policies
  • Maintain readiness for DCSA, customer, and internal security inspections and compliance reviews
  • Conduct self-inspections, identify areas for improvement, and implement corrective actions
  • Support the ongoing development and maturation of DEFCON AI’s industrial security program

Personnel & Program Security

  • Process and manage personnel security requirements, including clearance actions, visit requests, visit authorizations, and onboarding activities
  • Maintain personnel security records and related databases
  • Investigate security incidents and violations and ensure proper reporting and resolution in accordance with government and company requirements
  • Provide security guidance and support to employees, consultants, and approved visitors
  • Support contract security requirements, including DD Form 254 administration and subcontractor security management

Classified Information Protection

  • Maintain classified material accountability programs and secure storage requirements
  • Conduct inventories and maintain accountability of classified information and assets
  • Ensure proper marking, handling, transmission, storage, transportation, sanitization, reuse, and destruction of classified information and media
  • Support the protection of classified facilities, systems, and information in accordance with applicable regulations

Security Training & Program Development

  • Develop and administer Security Awareness, Annual Refresher, and OPSEC training programs
  • Create and maintain required security documentation, including SOPs, OPSEC plans, CONOPS, security procedures, and work instructions
  • Promote a culture of security awareness and compliance throughout the organization

Security Systems & Inspection Readiness

  • Maintain records and security actions within NISS, DISS, and other government security systems as required
  • Support DCSA, customer, and internal inspections and audits
  • Assist with corrective action implementation and continuous process improvement initiatives

Required Qualifications

  • Bachelor’s degree and 6+ years of industrial security or related experience; OR Master’s degree and 4+ years; OR Associate’s degree and 8+ years; OR High School diploma and 12+ years of relevant experience

  • Active U.S. Government Top Secret security clearance and ability to obtain and maintain SCI and SAP access

  • Strong knowledge of NISPOM (32 CFR Part 117), ICD security requirements, and industrial security compliance standards

  • Understanding and familiarity of DD-254 implementation requirements including issuing Subcontract DD-254 using NI2

  • Experience supporting personnel security, classified material control, and compliance programs within a cleared contractor environment

  • Experience utilizing government security systems such as NISS, DISS, or similar platforms

  • Strong organizational, communication, and problem-solving skills

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Outlook

Preferred Qualifications

  • Experience serving as an FSO, AFSO, or Industrial Security Specialist within a cleared facility
  • CDSE FSO Program Management Certification for Processing and/or Non-Possessing Facilities
  • Experience supporting multiple classified programs and government customers
  • Experience preparing for and supporting DCSA or other government inspections
  • Knowledge of DD Form 254 requirements and subcontractor security administration
  • Experience supporting SCI and/or SAP programs
  • Experience building, improving, or scaling security processes within a growing organization
  • Strong customer service skills and the ability to build trusted relationships with internal and external stakeholders
  • Ability to work independently, manage competing priorities, and thrive in a fast-paced environment

Why DEFCON AI

At DEFCON AI, you’ll help build and scale security capabilities that directly support critical national security missions. You’ll work alongside a mission-driven team developing AI-powered solutions for some of the Department of War’s most complex operational challenges.

What We Offer:

  • A fully remote environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $120,000-$150,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits (may differ for each incubation):

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security Cybersecurity Compliance Analyst (Hybrid - Bay Area) at Xantrion

Analyzes client cybersecurity controls, develops compliance documentation, and assesses vendor security risks using frameworks like NIST CSF and CIS Controls.

Mid Hybrid Posted 1 day ago RemoteFirstJobs Product
What this role involves

If you’re looking to join a winning information technology team and receive outstanding benefits that support your family—while working for a company that takes a people-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.

Location: San Francisco Bay Area

Hybrid: 2 days in office / 3 days remote per week

Primary Purpose and Function

Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.

This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.

Travel: None required.

Roles and Responsibilities

Client Compliance and Documentation

  • Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
  • Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
  • Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
  • Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
  • Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
  • Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
  • Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
  • Maintain annual testing schedules and track documentation, review dates, and follow-up items.
  • Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
  • Improve reusable templates and assessment procedures that support consistent delivery across clients.

Internal Compliance Support

  • Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
  • Organize audit documentation, maintain request trackers, and follow up with internal control owners.
  • Review evidence for completeness and consistency and identify missing or outdated documentation.
  • Provide seasonal support during internal audit preparation and review periods.

Position Requirements

Required Qualifications

  • Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
  • Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
  • Experience reviewing technical configurations or administrative reports against documented standards.
  • Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
  • Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
  • Ability to distinguish documented policies from evidence that controls are implemented and operating.
  • Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
  • Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
  • Professional communication skills and sound judgment when handling confidential client information.

Preferred Qualifications

  • Experience supporting registered investment advisers (RIAs) or other financial services organizations.
  • Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
  • Experience working for a managed service provider or supporting multiple client environments.
  • Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
  • Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
  • Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
  • Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
  • Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
  • A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.

Performance Metrics

The Cybersecurity Compliance Analyst performance success will be based on the following criteria:

  • Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
  • Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
  • Risk registers, crosswalks, and supporting documentation remain organized and current.
  • Internal audit requests are tracked and supported with complete, accessible evidence.
  • Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.

Physical Demands

  • Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
  • Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
  • Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
  • Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
  • Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
  • Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
  • Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
  • Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
  • Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion’s office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.

Company Policy and Procedure Compliance

  • Follow and support company policies and procedures as well as all local, state, and federal laws.
  • Always maintain confidentiality of company and customer records and information.
  • Maintain a professional image, adhering to Xantrion’s dress code.
  • Must have an existing cell phone (running current Android or iOS).
  • If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance.  See the Xantrion Handbook for details.

When Working Remote

  • Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
  • Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
  • Must use Xantrion-provided PC and headset to execute job functions.

Benefits

  • Salary range $100-120K; depending on experience.
  • 100% of medical, dental, and vision for you and your family.
  • 401K with company match up to 4% of salary.
  • Certification reimbursement and annual training budget.
  • 17 Days PTO per year in addition to paid training days.
  • Bonuses for referring new clients or employees.

Equal Opportunity Employer

Xantrion is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, age, color, sex, religion, sexual orientation, national origin, disability, medical condition, genetic information, pregnancy, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws. All employment is decided on the basis of qualifications, merit, and business needs at the time.

AI Disclosure for Recruitment

We use AI to support our recruiting team, improve the candidate experiences, and allow our teams to spend more time on meaningful candidate interactions. Our use of AI is limited to administrative tasks such as organizing application information and taking or summarizing interview notes. AI does not screen, advance, or reject candidates, and it does not make hiring or any significant decisions. Applications and candidate qualifications are reviewed by our recruiting team, and all decisions about interviews, advancement, offers, and hiring are made by our recruiters and hiring managers.

Read the full description
Security IT Systems Auditor

Audits IT systems and controls for compliance, identifies security vulnerabilities, and ensures adherence to organizational and regulatory standards.

Mid Remote Posted 3 days ago Himalayas
What this role involves
OverviewAmyx is seeking to hire a IT Systems Auditor-II for our Defense Logistics Agency program remotely.
Read the full description
Security Vigilant IT Security Manager – Portugal/Poland

Manages IT security operations and strategies for a globally distributed team across Portugal/Poland regions.

Mid Remote Posted 3 days ago Jobicy AI
What this role involves
This is not an offshoring back-office job for an international company. You will be a key player in our globally distributed team. We’re searching for a Vigilant IT Security Manager...
Read the full description
Security GRC Manager

Manages governance, risk, and compliance programs to ensure organizational adherence to regulatory standards and security policies.

Mid Posted 3 days ago Jobicy AI
What this role involves
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in...
Read the full description
Security Vulnerability Research Engineer

Researches and identifies software vulnerabilities in open source code and dependencies to help organizations manage security risks.

Mid Posted 4 days ago Jobicy AI
What this role involves
About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our...
Read the full description
Security Privacy & Security Program Manager at Nanit

Leads privacy and security compliance program, develops policies and controls, manages vendor risk assessments, and embeds privacy/security best practices across products and operations.

Mid Posted 5 days ago RemoteFirstJobs Product
What this role involves

About Nanit:

Welcome to Nanit, the high-growth baby tech company that is changing the way parents experience parenthood through the world’s most advanced baby monitor and parenting products. In 2016, the Nanit baby monitor revolutionized the industry with computer-vision and machine-learning capabilities that helped parents understand their baby’s sleep patterns and allowed them to achieve better sleep quality. Now, the company has become the leader in the connected parenting space, with an incredible customer base of highly-engaged parents who look to Nanit as a source of information and expertise on their parenting journey.

About the Role:

We’re seeking a highly motivated and detail-oriented privacy and security professional to lead and evolve Nanit’s privacy and security compliance program. Reporting directly to the Chief Legal & Administrative Officer, you will build and operationalize the policies, controls, and processes that protect our customers’ data and keep Nanit ahead of an evolving regulatory landscape. You’ll partner closely with Legal, Product, Engineering, and business teams to embed privacy and security best practices into how Nanit builds and operates.

What You’ll Be Doing:

  • Develop, maintain and implement Nanit’s privacy and security policies, standards and processes to ensure compliance with applicable laws, regulations and industry frameworks (e.g., CCPA/CPRA and other U.S. state privacy laws, GDPR, COPPA, and relevant security frameworks such as SOC 2, ISO 27001).
  • Conduct and support regular privacy and security risk assessments, audits and gap analyses across systems, vendors, products and business processes, and drive remediation of identified gaps.
  • Collaborate with stakeholders across the organization to assess AI-related privacy, security and compliance risks.
  • Manage the third-party/vendor risk management program, including privacy and security due diligence, contract review support, ongoing monitoring, and enforcement of Nanit’s data protection requirements.
  • Partner with Product and Engineering teams to embed privacy-by-design and security-by-design principles into new features and products, including data mapping, privacy impact assessments (PIAs/DPIAs), and secure development practices.
  • Monitor emerging privacy and security regulatory developments and industry standards, and advise the Chief Legal & Administrative Officer and Chief Technology Officer and other business stakeholders on impact and required action.
  • Lead the company’s response to security and privacy inquiries from customers, partners and regulators, including questionnaires, audits and due diligence requests.
  • Support incident response efforts for privacy and security incidents, including investigation, documentation, remediation tracking and stakeholder communication.
  • Develop and deliver privacy and security metrics, dashboards and reporting for senior management and, as needed, the board of directors.
  • Design and deliver company-wide training and awareness programs on privacy, data security and compliance best practices.
  • Act as a thoughtful business partner who supports a fast-moving culture, flexible teamwork, and pragmatic, scalable solutions that support growth while protecting the company.

Who You Are:

  • Bachelor’s degree in a related field; relevant certifications (e.g., CIPP, CIPM, CISSP, CIPT, CISM) preferred.
  • 3-5+ years of experience in privacy program management, information security, or a related compliance function, ideally spanning both in-house and cross-functional environments.
  • Hands-on experience supporting or operating privacy and/or security programs aligned to frameworks such as SOC 2, ISO 27001⁄27701, NIST CSF, or similar.
  • Working knowledge of consumer privacy laws (e.g., CCPA/CPRA, GDPR, COPPA) and a willingness to build deeper subject-matter expertise over time.
  • Practical experience with, or exposure to, security incident response, vendor risk management, and identity/access management concepts across on-premise and cloud environments.
  • Able to rapidly interpret relevant laws, regulations and technical requirements, and translate them into practical, actionable and business-friendly guidance.
  • Excellent stakeholder management, communication and collaboration skills; able to explain complex privacy/security concepts to both technical and non-technical audiences.
  • Strong organizational skills, a problem-solving mindset, attention to detail, and the ability to exercise sound judgment in ambiguous environments.
  • Strong technical orientation with an understanding of modern cloud architectures and data flows, and the ability to leverage emerging technologies and AI-powered tools to strengthen privacy, security and compliance programs.

Why You’ll Love Working Here:

  • Hybrid in office schedule
  • Remote work from home month in August
  • Flexible PTO (we trust you to take the time you need)
  • Equity options so you can share in our growth
  • Paid parental leave for all new parents
  • Employee discounts on Nanit products
  • Work from home stipend
  • Monthly team events

EEO, Salary and Location:

This role can be offered as either hybrid or fully remote, with a preference for East Coast candidates.

Salary Range: $130,000 to $150,000 targeted salary plus equity, benefits and unlimited PTO. Nanit’s total compensation package includes access to healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, and basic life insurance. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We are proud to be an equal opportunity employer. We provide employment opportunities without regard to age, race, color, ancestry, national origin, religion, disability, sex, gender identity or expression, sexual orientation, veteran status, or any other protected class.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, analyzes threat patterns, and develops automation to protect fintech infrastructure and respond to security incidents.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, reviews security telemetry for malicious activity, and develops automation tools to protect fintech infrastructure and customer data.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, analyzes threat patterns, and develops automation tooling to identify and respond to security threats across fintech infrastructure.

Mid Posted 6 days ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description
Security Fastly: Threat Detection Analyst (Japanese & English speaking)

Monitor and analyze customer security threats, detect attacks like account takeovers and bot attacks, and provide SOC support for cloud security incidents.

Mid Remote Posted 6 days ago We Work Remotely — Programming
What this role involves

Headquarters: Australia (Remote)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including GitHub, Yelp, Paramount, and JetBlue.

We're building a more trustworthy Internet. Come join us.

 

Threat Detection Analyst - APAC (Japanese Speaking)

Leveraging our growing security product suite, the Threat Detection Analyst role contributes real world security insights to Fastly and our customers as we address Internet-scale threats.  Cloud security solutions enable our customers to benefit from extra visibility across the world and expertise from a central team. 

The Fastly Customer Security Operations Center team at Fastly focuses on operational support of Fastly’s security products and services. The Threat Detection Analyst role within this team focuses on delivering outstanding security services to our customers, specifically as it pertains to integrating and supporting agent software installed on customer systems.  The team works with the security, operations and customer organizations internally  to deliver support solutions for security threats faced on the Internet today.

As a 24 x 7 team, SOC analysts are expected to work Friday - Tuesday, with the daily shift being 0000 - 0800 UTC - (9am - 6pm AEST)

What You'll Do

This role within the Fastly Customer Security Operations Center (CSOC) will be responsible for monitoring and analyzing customer activity, with added emphasis on security functions, like identifying account-takeover or Bot Attacks and WAF administration. Much of the focus will be on security and attacks  around the application layer working with different web technologies. You will have the opportunity to work on some of the world’s most scalable distributed systems that handle around 10 million requests per second, as well as the world-class engineers who developed these systems.

In this position, security engineers will be responsible for the following duties:

  • Be an expert in ensuring security for customers, providing an outstanding response to security issues.
  • Provide deep application-security experience on escalated cases from customers & automated systems.
  • Carry out continuous-improvement work & research to drive our customer security products & operations to be the best they can be. 
  • Contribute to the processes and policies that scale our organization as we grow
  • Create & review reporting to customers on security services
  • Create & manage security content for customer environments

What We're Looking For

  • Prior Experience working in a SOC Environment 
  • Experience with some or all the following foundational technologies: SaaS/Cloud or hybrid cloud deployments; Apache/NGINX/IIS or other web server platforms and associated Application server technologies and frameworks
  • Scripting ability with any of the following: Python, Java, Go, Rust, PHP, Unix/Linux Shell, C#, or other common Web languages
  • Strong infosec background with strong knowledge & practical skills in Application Security.
  • Experience in an IT or security technical support, operations, or research role
  • Unix/Linux or Windows System Administration
  • Ability to work with limited supervision but be a good mentor on security knowledge to the greater team
  • Fluent spoken & written English required, tailoring depth to be a good fit for varying audiences
  • Ability and experience in troubleshooting software products
  • Focussed on delivering exceptional customer experiences.

Work Hours:

  • This position will require you to be available during core business hours. 

Work Location(s) & Travel Requirements 

This position is a remote position based out of (locality), with the possibility of becoming a hybrid position as Fastly expands its presence in the region. 

This position will require travel to the US and Internationally, as required by your role or requested by your manager.

Benefits:

We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too. We support our teams with great benefits that start on the first day of your employment with Fastly. Curious about our offerings? 

We offer a comprehensive benefits package designed to meet your needs. Our offerings may vary depending on the country where you work and are subject to change.

Why Fastly?

  • We have a huge impact. Fastly is a fast growing company in a highly dynamic sector. Not only do our customers have a tremendous user base, but we also support a growing number of open source projects and initiatives. Outside of code, employees are encouraged to share causes close to their heart with others, so we can help lend a supportive hand.
  • We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too.
  • We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful -- every day.
  • We are passionate. Fastly is chock full of diverse and passionate people. We’re not ‘one size fits all’. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.

We’re always looking for humble, sharp, and creative folks to join the Fastly team.

If you think you might be a fit please apply, we would love to hear from you.

Why Fastly?

  • We have a huge impact. Fastly is a small company with a big reach. Not only do our customers have a tremendous user base, but we also support a growing number of open source projects and initiatives. Outside of code, employees are encouraged to share causes close to their heart with others so we can help lend a supportive hand.

  • We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful -- every day.

  • We are passionate. Fastly is chock full of passionate people and we’re not ‘one size fits all’. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.

We’re always looking for humble, sharp, and creative folks to join the Fastly team. If you think you might be a fit please apply! A fully completed application and resume or CV are required when applying.

All job applications must be submitted through our official careers site at www.fastly.com/about/careers. We will never request sensitive information, such as your Social Security number, bank account or credit card information during the application process. All official communication will come from an @fastly.com or @recruiting.fastly.com email address.

Fastly is committed to ensuring equal employment opportunity and to providing employees with a safe and welcoming work environment free of discrimination and harassment. Our employment decisions are based on business needs, job requirements and individual qualifications. All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, family or parental status, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.

Consistent with the Americans with Disabilities Act (ADA) and federal or state disability laws, Fastly will provide reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact your Recruiter, or the Fastly Employee Relations team at candidateaccommodations@fastly.com or 501-287-4901. 

Fastly collects and processes personal data submitted by job applicants in accordance with our Privacy Policy. Please see our privacy notice for job applicants.

To apply: https://weworkremotely.com/remote-jobs/fastly-threat-detection-analyst-japanese-english-speaking

Read the full description
Security Government Compliance Technical Specialist at BeyondTrust

Manages technical execution of government compliance programs including FedRAMP, maintains security documentation, and automates compliance monitoring for a cybersecurity SaaS company.

Mid Posted 7 days ago RemoteFirstJobs Product
What this role involves

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

The Government Compliance Technical Specialist is a full-time individual contributor on BeyondTrust’s Trust & Assurance team, reporting to the Director of Trust & Assurance. This role owns day-to-day technical execution of BeyondTrust’s government compliance programs, including FedRAMP Moderate, TX-RAMP, IRAP, and other emerging public-sector frameworks. Responsibilities include continuous monitoring, writing and maintaining compliance documentation, POA&M management, and building automation to support compliance modernization, including FedRAMP 20x. The ability to interpret, define, and design automation for Key Security Indicators (KSIs) is required.

The ideal candidate has run a FedRAMP program end-to-end and can operate with a high degree of autonomy in a fast-paced cybersecurity product environment. They bring technical depth in NIST 800-53 controls, understand cloud compliance boundaries, and can demonstrate technical automation. This role will also support the program management of government compliance workstreams alongside product, security, and engineering teams.

What You’ll Do

  • Lead technical compliance build activities for FedRAMP 20x readiness, including interpreting Key Security Indicators (KSIs), defining evidence strategies, and coordinating machine-readable compliance outputs.
  • Own day-to-day management and execution of FedRAMP Moderate/Class C continuous monitoring, including deliverables, POA&M tracking, and deviation requests.
  • Author and maintain System Security Plans (SSPs), Security Decision Records (SDRs), and other compliance documentation in human and machine readable formats.
  • Manage findings and remediation tracking across all government compliance programs.
  • Coordinate directly with engineering, security, and cloud operations teams to gather evidence, validate control implementation, and close compliance gaps.
  • Support GovRAMP, TX-RAMP, IRAP, and other government or public-sector compliance programs.
  • Manage day-to-day relationships with Third Party Assessment Organizations (3PAOs) and agency stakeholders.
  • Track and report government program health.
  • Monitor FedRAMP policy changes, framework evolution, and translate changes into compliance roadmap.
  • Automate evidence collection pipelines and indicator health tracking.

What You’ll Bring

  • 3 years minimum in FedRAMP program management and technical compliance.
  • 4–7 years of experience in information security, compliance, or GRC.
  • Demonstrated ability to run a FedRAMP Moderate program, including SSP authorship, ConMon execution, POA&M management, and assessor coordination.
  • Deep working knowledge of NIST SP 800-53 controls and their practical implementation in cloud environments.
  • Strong familiarity with FedRAMP 20x concepts, especially Key Security Indicators (KSIs), machine-readable evidence frameworks, and continuous assessment models.
  • The ability to interpret and define KSIs in the context of BeyondTrust’s compliance posture.
  • Demonstrated ability to coordinate across engineering, infrastructure, legal, and operations teams to gather evidence and drive remediation to closure.
  • Experience building or supporting automated compliance evidence pipelines.
  • Experience with GRC tooling for findings management, evidence collection, and program tracking.
  • Ability to track and manage multiple concurrent workstreams, surface blockers, and maintain delivery cadences.
  • Strong written and verbal communication skills to translate technical compliance information to varying audiences.

Nice To Have

  • Strong familiarity with AI security
  • Experience using AI to develop and deploy applications
  • Experience with GovRAMP, TX-RAMP, IRAP, or other public-sector compliance frameworks.
  • Familiarity with FedRAMP High or DoD IL4/IL5 authorization environments.
  • CISSP or CISA certification.
  • Background in cybersecurity product companies or multi-product SaaS environments.
  • Bachelor’s degree in information security, computer science, or a related field.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

#LI-BS1

Read the full description
Security Vulnerability Manager at BeyondTrust

Designs and operates a vulnerability management program end-to-end, automating processes and driving remediation across products in a regulated environment.

Mid Remote Posted 7 days ago RemoteFirstJobs Product
What this role involves

BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cybersecurity SaaS portfolio.

Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself.

The Role

The Vulnerability Manager operates BeyondTrust’s product vulnerability management program end to end. This is an operator role: you design the process, drive the automation that runs it, own the metrics, and are accountable for the answer when leadership asks what our open vulnerability risk is today. The primary focus is vulnerability management for FedRAMP 20x and standing up vulnerability management for new products as they ship. You partner closely with Security Engineering to define the integration requirements, partner with them closely through delivery, and own the operational outcome. The ideal candidate has designed a vulnerability management process inside a regulated environment, uses automation and AI to remove manual work rather than absorbing it, and can hold a remediation conversation with an engineering lead and an evidence conversation with an assessor on the same day. Fully remote, must be North America based.

What You’ll Do

  • Design and operate the product vulnerability management process end to end: intake, triage, risk assessment, assignment, SLA tracking, exception handling, and closure verification.
  • Own vulnerability management for FedRAMP 20x, including continuous monitoring cadence, machine-readable evidence, Key Security Indicator reporting, and POA&M lifecycle from creation through closure.
  • Stand up vulnerability management for new products and services as they ship: define scan coverage, onboard them into the process, set SLAs, and establish reporting from first release.
  • Assess and rank vulnerability risk using exploitability, exposure, asset criticality, and compensating controls rather than CVSS alone, and defend that ranking to engineers, executives, and assessors.
  • Drive remediation with product engineering teams: assign ownership, agree timelines, escalate overdue Critical and High findings, and record risk acceptances as time-bound decisions with an expiry.
  • Automate the process wherever manual effort scales with finding volume, using scripting, workflow tooling, and AI-assisted analysis for triage, deduplication, enrichment, summarization, and evidence collection.
  • Define the requirements for platform integrations built by Security Engineering, covering scanners, ticketing, asset inventory, and dashboards. Partner with that team through delivery and validate the result against the operational need.
  • Own the program metrics: SLA attainment, mean time to remediate, vulnerability aging, backlog trend, scan and asset coverage, and exception volume. Report them on a fixed cadence to security and engineering leadership.
  • Monitor the vulnerabilities that matter most. Maintain a current view of critical exposure across the product portfolio and serve as the authoritative answer to what is open, what it means, and when it closes.
  • Lead rapid response for actively exploited and zero-day vulnerabilities, including exposure assessment across the product fleet, mitigation tracking, and stakeholder communication.

What You’ll Bring

  • 5+ years in vulnerability management, product security, or security operations, with direct ownership of a vulnerability management process rather than participation in one.
  • Demonstrated experience designing and operating vulnerability management process in a regulated or audited environment, and sustaining it through assessment cycles.
  • Working knowledge of FedRAMP and NIST SP 800-53, specifically vulnerability scanning, flaw remediation, continuous monitoring, configuration management, and POA&M management.
  • Hands-on operation of enterprise vulnerability and exposure management platforms, cloud security posture tooling, container scanning, and software composition analysis.
  • Practical automation skill: scripting in Python or equivalent, workflow and reporting tooling, and use of AI assistants to reduce manual triage and reporting effort. This role automates its own process; it does not build platform software.
  • Ability to write clear technical requirements and partner with security engineering through design, delivery, and acceptance.
  • Strong understanding of CVSS, CISA Known Exploited Vulnerabilities (KEV), EPSS, and risk-based prioritization, with the judgment to separate a high score from a real exposure.
  • Working knowledge of cloud services (AWS preferred), containers, Kubernetes, CI/CD, web applications, and APIs, sufficient to assess a finding and evaluate a proposed fix.
  • Ability to drive remediation across engineering teams without direct authority.
  • Clear written and verbal communication with engineers, executives, auditors, and customers.

Nice To Have

  • Direct experience supporting FedRAMP Moderate or High authorization and continuous monitoring, or FedRAMP 20x.
  • Experience defining metrics and building reporting or dashboards for executive and audit audiences.
  • Experience with SaaS, identity security, or privileged access management products.
  • Familiarity with agentic or AI-assisted security workflows.
  • Cloud security certifications (AWS, Azure, GCP), GIAC, CISSP, or equivalent.

Better Together

Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected.

We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together.

About Us

BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders.

BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners.

Learn more at www.beyondtrust.com.

#LI-BS1

Read the full description
Security Security Engineer, Detection & Response

Designs and implements security detection systems and incident response procedures to protect company infrastructure and data.

Mid Posted 7 days ago Jobicy AI
What this role involves
Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize...
Read the full description
Security Cyber Security Engineer II

Designs, implements, and maintains cybersecurity systems and infrastructure to protect organizational assets and data from security threats.

Mid Posted 8 days ago Jobicy AI
What this role involves
About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just...
Read the full description
Security Security & Compliance Manager at Relocity, Inc.

Manages SOC 2 Type II compliance, leads ISO 27001 certification, and oversees security controls, risk assessments, and regulatory framework implementation across the organization.

Mid Posted 9 days ago RemoteFirstJobs Product
What this role involves

What Relocity is Doing

Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.

What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company’s primary advisor on security, privacy, and compliance strategy.

Risk & Governance

  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership

  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness

  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement

  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success

  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

How We Support You and Work-Life Balance…

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.

#LI-Remote

#LI-AC2

Read the full description
Security Security & Compliance Manager at Relocity, Inc.

Maintains SOC 2 Type II compliance, leads ISO 27001 certification, and manages security controls and risk governance across the organization.

Mid Posted 9 days ago RemoteFirstJobs Product
What this role involves

What Relocity is Doing

Relocity is reimagining the global mobility experience. We enable enterprises to attract, retain, and engage talent globally. Powered by our AI-driven workforce mobility platform, we bring together local experts and insightful content in our native mobile app to deliver an excellent user experience for people on the move. Our core values drive us to focus on our customers, innovation, integrity, and excellence. Relocity serves hundreds of cities in more than 40 markets across the United States, Europe, and Asia. Learn more at www.relocity.com.

What You Will Do

Relocity is seeking an experienced Security & Compliance Manager to maintain and strengthen our information security, privacy, and data governance programs. Reporting into leadership, you will partner closely with Engineering, Product, Operations, and G&A to keep our systems, processes, and policies aligned with evolving regulatory and security requirements as the company grows.

Our compliance foundation is already established. You will own the ongoing maintenance of our SOC 2 Type II program, lead our ISO 27001 certification effort to completion, and continuously improve our governance and risk management practices. You will use Vanta as our compliance platform to streamline monitoring, evidence collection, and audit readiness.

How You Will Do It

Security & Compliance

  • Maintain SOC 2 Type II compliance, including control operation, evidence collection, and annual audit readiness.
  • Lead the ISO 27001 certification effort, from gap assessment through certification and ongoing surveillance.
  • Own additional security and privacy frameworks, including GDPR, CCPA, and other applicable regulations.
  • Serve as the company’s primary advisor on security, privacy, and compliance strategy.

Risk & Governance

  • Establish and continuously improve security controls, governance standards, policies, and risk management practices.
  • Conduct security risk assessments, manage incident response, and drive remediation efforts.
  • Administer Vanta and related tooling to automate compliance monitoring, continuous control testing, and audit workflows.

Cross-Functional Partnership

  • Partner with Engineering, Product, Operations, Legal, and leadership to embed security and privacy into products, systems, and business processes.
  • Translate technical risk into practical business recommendations that inform strategic decisions.

Data Protection & Awareness

  • Define enterprise data governance standards, including data classification, retention, and lifecycle management.
  • Lead company-wide security awareness initiatives that promote responsible data stewardship.

Continuous Improvement

  • Monitor evolving regulations, emerging threats, and industry best practices to strengthen our security program.
  • Evaluate and implement technologies and processes that improve automation, visibility, and operational efficiency.

What Will Enable Your Success

  • Experience: Three to Five years in information security, data privacy, governance, compliance, or risk management.
  • Compliance Leadership: Direct experience maintaining SOC 2 Type II and leading or supporting ISO 27001 certification within a SaaS or cloud-first environment.
  • Compliance Automation: Hands-on experience with Vanta or comparable GRC platforms such as Drata, Secureframe, or Sprinto.
  • Privacy Expertise: Strong working knowledge of GDPR, CCPA, and other applicable privacy regulations.
  • Governance: Demonstrated success designing and implementing data classification, retention, privacy, and security programs.
  • Technical Aptitude: Familiarity with cloud infrastructure, SaaS environments, identity and access management, and security controls.
  • Communication: Ability to explain complex technical concepts to technical and non-technical audiences.
  • Cross-Functional Leadership: Proven ability to influence stakeholders and lead initiatives across multiple functions.
  • Education: Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, Legal Studies, or a related field, or equivalent practical experience.

Nice to Have

  • Professional certifications such as CIPP/US, CIPM, CISSP, CISM, or CRISC.
  • Experience in a high-growth SaaS or technology startup environment.
  • Knowledge of privacy-by-design principles.

How We Support You and Work-Life Balance…

  • Competitive Compensation
  • Paid Time Off
  • Paid Parental Leave
  • Remote Workplace
  • Flexible Work Schedules
  • Health, Dental, Vision, and LTD Insurance
  • 401(k)
  • Professional Development Opportunities

Salary Range: $140,000 - $170,000 + bonus

Relocity is an Equal Opportunity Employer and does not discriminate against any applicant on the basis of race, color, religion/creed, national origin, gender, sex, marital status, age, disability, use of a guide dog or service animal, sexual orientation, military/veteran status, or any other status protected by federal, state, or local law. Relocity will only employ individuals who are legally authorized to work. Any offer of employment is conditioned upon the successful completion of a background investigation.

#LI-Remote

#LI-AC2

Read the full description
Security Security Engineer, Cloud

Designs, implements, and maintains cloud security infrastructure and protocols to protect systems and data.

Mid Remote Posted 10 days ago Jobicy AI
What this role involves
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped how the web is built....
Read the full description
Security IT Security Operations Analyst

Monitors security events, responds to incidents, and maintains security infrastructure for enterprise systems.

Mid Posted 10 days ago Himalayas
What this role involves
Our client is an European company leading the development and production of responsible packaging solutions for a wide variety of industries.
Read the full description