Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Director of Security Risk Engineering at Flywire

Director leads enterprise security infrastructure across six domains including application, cloud, AI security, and red teaming, partnering with CISO to mature global security systems.

Exec Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you!

Who we are:

Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world.

Today we support more than 5,100 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,200 global FlyMates, representing more than 40 nationalities, and in 12 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.

Job Description

The Opportunity:

As the Director of Security Risk Engineering, you will serve as a key senior leader working in direct partnership with the CISO to drive, shape, and mature Flywire’s global enterprise security infrastructure and systems. In this role, you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing).

In partnership with the internal stakeholder organizations, you will lead the organizational shift from technical recovery to global enterprise operational resilience, managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration, innovation, and continuous improvement. A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required.

Responsibilities:

  • Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps/Incident Detection & Response), and Red Teaming (Penetration Testing), aligning initiatives with global business objectives and emerging financial threats.
  • Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
  • Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring strict alignment with security best practices.
  • Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle. Engage actively with external stakeholders, auditors and global regulators on related fronts.
  • Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses against vulnerabilities across all engineering domains.
  • Adversarial / Penetration Testing: Personally adopt an attacker’s mindset to identify complex attack chains, logic flaws, and zero-day vulnerabilities within financial platforms and product architectures.
  • Incident Response & Operational Resilience: Direct and coordinate responses to critical enterprise security incidents, managing containment, forensic investigation, and rapid remediation efforts alongside SecOps.
  • Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
  • Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior executive leadership, and the Board.
  • Innovation & Emerging Tech: Stay ahead of global fintech trends, adopting cutting-edge technologies and methodologies—specifically regarding secure AI deployment—to continuously strengthen the organization’s security posture.

Qualifications

Here’s What We’re Looking For:

  • Education: Bachelor’s degree required in Computer Science, Information Security, or a related technical field. A Master’s degree is highly preferred.
  • Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles. Must be an active technical practitioner with a proven track record of independently performing manual penetration testing, vulnerability exploitation, detection/response activities, and code reviews across cloud and application infrastructures, without relying solely on automated commercial tools.
  • Leadership Experience: 3+ years of proven experience in senior leadership or management roles specifically within a security engineering organization, managing people, cross-functional teams and complex security programs.
  • Domain Mastery: In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming).

Highly Preferred Certifications

  • Core Security: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager)
  • Governance & Risk: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), or ISACA AAISM™ (Advanced in AI Security Management)
  • Hands-On Offensive & AI: OffSec OSAI (Offensive Security AI Red Teamer), OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert), or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)

Skills and Abilities

  • Strategic & Tactical Balancer with a Commercial Mindset: Highly hands-on and technically skilled. Strong strategic thinker with the ability to contribute to and translate the CISO’s high-level vision into actionable plans and drive successful execution. Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
  • Executive Presence: Exceptional communication and stakeholder management skills, with a demonstrated ability to articulate complex security risks and technical concepts to both engineering teams and executive management/the Board.
  • 2nd-Line Cyber Risk Oversight & Governance: Robust capability to operate as a strategic second-line risk leader. Proven experience defining enterprise security risk appetites, establishing governance frameworks, and executing independent control testing to validate that the first line (engineering/product teams) effectively manages cyber risk.
  • Defense-in-Depth Expertise: Comprehensive understanding of modern system security design principles, intrusion prevention, API security, and automated vulnerability management.
  • High-Pressure Decision Making: Demonstrated capability to prioritize tasks, maintain cross-functional transparency, and make critical risk decisions under pressure during live security incidents.
  • Lateral Influencing / Influential Leadership: Ability to collaborate effectively as a trusted partner across the global organization, promoting a collaborative culture of continuous resilience and security awareness.

Additional Information

What We Offer:

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Work with brilliant people globally  Learn more about their journeys by checking out #InsideFlywire on social media
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
  • Be a meaningful part in our success - every FlyMate makes an impact
  • Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions.

The US base salary range for this full-time position is $200,000 - 210,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

#LI-Hybrid

Read the full description
Security Detection Development Intern, Fall 2026 at Coveo

Build and tune threat detection rules in XSIAM, analyze security logs and telemetry, and research attack vectors to strengthen detection coverage across SaaS platforms and cloud infrastructure.

Junior Hybrid Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

What does it take to detect real threats across a large SaaS environment?

Are you curious about how enterprise security teams identify suspicious activity, build detections, and improve visibility across modern cloud and Software as a Service (SaaS) platforms? Coveo is looking for a Detection Engineering Intern to join our Security Operations Center (SOC) team. Your mission? Help us strengthen our detection coverage by building and tuning threat detection rules for the technologies that support Coveo’s production environment.

The SOC team plays a key role in protecting Coveo by monitoring security activity, investigating alerts, and continuously improving our ability to detect threats across our SaaS and infrastructure footprint. As an intern, you’ll contribute to initiatives that expand our detection capabilities while gaining hands-on experience with real enterprise threat detection tools in a production environment.

Your impact, day to day:

  • Participate in daily stand-up meetings to discuss progress, roadblocks, and priorities. Collaborate with team members to ensure alignment and effective communication.
  • Build and tune detection rules in XSIAM for different technologies, SaaS platforms, and log sources.
  • Research how services and tools could be abused by threat actors in order to identify realistic detection opportunities.
  • Contribute to detection coverage for platforms such as 1Password, AWS, Cortex XDR logs, and other more.
  • Analyze logs and security telemetry to better understand user activity, system behavior, and potential indicators of suspicious activity.
  • Take an active role in discussions around detection quality. Share your thinking, ask questions, and receive feedback to strengthen your analytical approach and technical skills.
  • Develop your skills by drawing on your coach’s expertise. Watch, learn, and apply best practices used in security monitoring, threat detection, and detection engineering.

The Essentials:

  • You are currently studying Software Engineering or Computer Science in a Bachelors degree or higher in the province of QuĂŠbec.
  • You can be present at the office at least two days a week. Our hybrid work model offers flexibility, you can benefit from face-to-face learning from your team on office days while home days allow you to focus and complete complex work.
  • You are available to work full-time for 15 weeks and are legally entitled to do so in Canada.

Think you’ve got what it takes? Let’s see!

  • You are curious, eager to learn, and motivated to understand how security tools and systems work.
  • You are able to think analytically and consider the broader context behind security events, instead of focusing only on isolated details.
  • You have an interest in threat detection, security monitoring, incident response, or detection engineering.
  • You have some familiarity with security information and event management (SIEM), core concepts of security tooling.
  • You have participated in some Capture The Flag competitions and/or have a few personal projects.
  • You have a strong sense of ownership and are proud of what you create.

Join the Coveolife!

Do you think you can bring this role to life? Send us your application, we want to hear from you!

We encourage all qualified candidates to apply regardless of, for example, age, gender, disability, gaps in CV, national or ethnic background.

This job description was written by humans, assisted by AI. We may leverage technology in our hiring process to help us see the person behind the resume.

Coveo is committed to providing accessible employment practices. If you require accommodation due to a disability at any point during the recruitment process, please contact HR@Coveo.com to discuss your needs.

Read the full description
Security Director of Security Risk Engineering at Flywire

Director leads enterprise security infrastructure across application, cloud, AI, and operations domains while partnering with CISO on strategic risk mitigation.

Exec Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you!

Who we are:

Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world.

Today we support more than 5,100 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,200 global FlyMates, representing more than 40 nationalities, and in 12 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.

Job Description

The Opportunity:

As the Director of Security Risk Engineering, you will serve as a key senior leader working in direct partnership with the CISO to drive, shape, and mature Flywire’s global enterprise security infrastructure and systems. In this role, you will bridge the gap between high-level security strategy and tactical engineering execution across six core domains: Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps), and Red Teaming (Penetration Testing).

In partnership with the internal stakeholder organizations, you will lead the organizational shift from technical recovery to global enterprise operational resilience, managing a highly impactful program that safeguards our global payment rails while fostering a culture of collaboration, innovation, and continuous improvement. A solid working knowledge of all aspects of cloud-native infrastructure, software applications, AI/LLM model development, governance & validation, and automated risk mitigation is required.

Responsibilities:

  • Strategic Domain Leadership: Define, implement, and monitor a comprehensive security engineering strategy across Application Security, AI Security, Cloud Security, Corporate Security, Security Operations (SecOps/Incident Detection & Response), and Red Teaming (Penetration Testing), aligning initiatives with global business objectives and emerging financial threats.
  • Team Management & Mentorship: Support the CISO to lead and manage the global security engineering organization, including hiring, training, mentoring, performance management, and budget oversight.
  • Secure Architecture & Governance: Oversee the design and continuous improvement of secure architecture for systems, cloud infrastructure, networks, and applications, ensuring strict alignment with security best practices.
  • Global Cross-Functional Collaboration: Partner with Business, Development, DevOps, Product, Program, Risk/Compliance, and IT leaders to seamlessly integrate security controls into all phases of the engineering and CI/CD lifecycle. Engage actively with external stakeholders, auditors and global regulators on related fronts.
  • Advanced Cyber Risk Efficacy: Leverage AI and automated tooling to develop proactive measures, threat intelligence capabilities, and scalable defenses against vulnerabilities across all engineering domains.
  • Adversarial / Penetration Testing: Personally adopt an attacker’s mindset to identify complex attack chains, logic flaws, and zero-day vulnerabilities within financial platforms and product architectures.
  • Incident Response & Operational Resilience: Direct and coordinate responses to critical enterprise security incidents, managing containment, forensic investigation, and rapid remediation efforts alongside SecOps.
  • Regulatory Compliance Frameworks: Maintain an information security framework that ensures continuous readiness for strict industry audits and regulatory compliance requirements globally (e.g., NIST CSF 2.0, ISO 27001, PCI-DSS 4.0, DORA).
  • Executive & Stakeholder Reporting: Define and maintain metrics that communicate security posture, program progress, and incident risk analysis to the CISO, senior executive leadership, and the Board.
  • Innovation & Emerging Tech: Stay ahead of global fintech trends, adopting cutting-edge technologies and methodologies—specifically regarding secure AI deployment—to continuously strengthen the organization’s security posture.

Qualifications

Here’s What We’re Looking For:

  • Education: Bachelor’s degree required in Computer Science, Information Security, or a related technical field. A Master’s degree is highly preferred.
  • Core Experience: 12+ years of progressive experience in information security, IT risk management, or cyber defense roles. Must be an active technical practitioner with a proven track record of independently performing manual penetration testing, vulnerability exploitation, detection/response activities, and code reviews across cloud and application infrastructures, without relying solely on automated commercial tools.
  • Leadership Experience: 3+ years of proven experience in senior leadership or management roles specifically within a security engineering organization, managing people, cross-functional teams and complex security programs.
  • Domain Mastery: In-depth technical knowledge of security architecture, secure cloud infrastructure (e.g., AWS/Azure/GCP), application security principles, and adversarial emulation (Red Teaming).

Highly Preferred Certifications

  • Core Security: CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager)
  • Governance & Risk: CRISC (Certified in Risk and Information Systems Control), CISA (Certified Information Systems Auditor), or ISACA AAISM™ (Advanced in AI Security Management)
  • Hands-On Offensive & AI: OffSec OSAI (Offensive Security AI Red Teamer), OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert), or SANS GXPN (GIAC Exploit Researcher and Advanced Penetration Tester)

Skills and Abilities

  • Strategic & Tactical Balancer with a Commercial Mindset: Highly hands-on and technically skilled. Strong strategic thinker with the ability to contribute to and translate the CISO’s high-level vision into actionable plans and drive successful execution. Balances technical risk reduction with business enablement, ensuring security infrastructure serves as a competitive advantage that unblocks global revenue and enterprise-client acquisition.
  • Executive Presence: Exceptional communication and stakeholder management skills, with a demonstrated ability to articulate complex security risks and technical concepts to both engineering teams and executive management/the Board.
  • 2nd-Line Cyber Risk Oversight & Governance: Robust capability to operate as a strategic second-line risk leader. Proven experience defining enterprise security risk appetites, establishing governance frameworks, and executing independent control testing to validate that the first line (engineering/product teams) effectively manages cyber risk.
  • Defense-in-Depth Expertise: Comprehensive understanding of modern system security design principles, intrusion prevention, API security, and automated vulnerability management.
  • High-Pressure Decision Making: Demonstrated capability to prioritize tasks, maintain cross-functional transparency, and make critical risk decisions under pressure during live security incidents.
  • Lateral Influencing / Influential Leadership: Ability to collaborate effectively as a trusted partner across the global organization, promoting a collaborative culture of continuous resilience and security awareness.

Additional Information

What We Offer:

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Competitive time off, including Digital Disconnect and FlyBetter Days to volunteer in a cause you believe in.
  • Work with brilliant people globally  Learn more about their journeys by checking out #InsideFlywire on social media
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
  • Be a meaningful part in our success - every FlyMate makes an impact
  • Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers, OneFlywire Career Mobility)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet with different FlyMates including the Hiring Manager, Peers on the team, the VP of the department, and a skills assessment. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for any questions.

The US base salary range for this full-time position is $200,000 - 210,000 and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

#LI-Hybrid

Read the full description
Security Director, Fraud Risk at Flywire

Leads fraud risk strategy and detection across a global payments platform, designing prevention frameworks and overseeing merchant and account security.

Lead Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

Company Description

Are you ready to trade your job for a journey? Become a FlyMate!

Passion, excitement & global collaboration are all core to what it means to be a FlyMate. At Flywire, we’re on a mission to deliver the world’s most important and complex payments. We use our Flywire Advantage - the combination of our next-gen payments platform, proprietary payment network and vertical specific software, to help our clients get paid, and help their customers pay with ease - no matter where they are in the world.

What more do we need to truly be unstoppable? Perhaps, that is you!

Who we are:

Flywire is a global payments enablement and software company, founded more than a decade ago to solve high-stakes, high-value payments in higher education. We’ve since scaled into new regions and industry verticals and expanded our product offerings to deliver meaningful value to our clients around the world.

Today we support more than 4,800 clients across the global education, healthcare, travel & B2B industries, with diverse payment methods across 240 countries & territories and more than 140 currencies.

With over 1,200 global FlyMates, representing more than 40 nationalities, and in 12 offices world-wide, we’re looking for FlyMates to join the next stage of our journey as we continue to grow.

Job Description

The Opportunity

As our Fraud Risk Director, you will help architect our fraud risk strategy for our Flywire ecosystem. You won’t just be reacting to threats; you will be the chief architect of a proactive, global fraud prevention strategy. You’ll lead the charge in balancing a frictionless customer experience with rigorous security, ensuring that as we scale into new markets and complex payment methods, our financial and reputational integrity remains ironclad. We need a leader who is as comfortable with machine learning logic as they are with operations and high-level executive strategy.

What You’ll Do:

  • Own the Strategy: Design, implement, and iterate on a global fraud risk framework that addresses diverse attack vectors across our core verticals (Education, Healthcare, Travel, and B2B).
  • Detection & Analysis: Oversee the fraud assessment process for new and existing accounts, focusing on merchant fraud, Account Takeover (ATO), and sophisticated social engineering schemes.
  • Data-Driven Decisioning: Partner with Analytics and Engineering to build and refine real-time fraud decisioning and automated rulesets that leverage Flywire’s unique global payment data.
  • Incident Management & Response: Architect a robust, real-time fraud monitoring and response program. You will lead the “War Room” during high-stakes fraud events, orchestrating rapid remediation, loss recovery, and cross-functional post-mortems to ensure continuous system defense.
  • Global Expansion: Guide Flywire’s entry into new geographies by assessing localized fraud patterns, regional payment method risks, and emerging regulatory requirements.
  • Cross-Functional Leadership: Act as a key advisor to Product and Engineering teams to embed fraud prevention into the user journey—implementing tools like 3DS, biometrics, and behavioral analytics without stifling the payment experience.

Qualifications

Here’s what we’re looking for:

  • The Seasoned Pro: You have 10+ years of experience in fraud risk, specifically within Payments or Fintech. You know the difference between a chargeback and a true fraud loss and understand the “plumbing” of global money movement.
  • The Strategic Thinker: You don’t just “plug holes;” you anticipate where the next one will appear. You understand that end-to-end fraud prevention is a competitive advantage, not a cost center.
  • A Data Native: You are highly analytical and comfortable with data. You can speak the language of feature engineering and model performance (Precision/Recall) to drive technical insights.
  • An Exceptional Communicator: You can translate technical fraud trends into clear, actionable risk narratives and solutions for the Executive Team and Board.
  • A Thoughtful People Leader: You encourage the growth and development of your team, knowing that their success is the company’s success.
  • Calm Under Pressure: You are able to make high-stakes decisions with limited information when an attack is underway.

Additional Information

What We Offer:

  • Competitive compensation
  • Employee Stock Purchase Plan (ESPP)
  • Flying Start - Our immersive Global Induction Program (Meet our Execs & Global Teams)
  • Work with brilliant people that will keep you on your toes, learn more about their journeys by checking out #InsideFlywire on social media
  • Dynamic & Global Team (we have been collaborating virtually for years!)
  • Wellbeing Programs (Mental Health, Wellness, Yoga/Pilates/HIIT Classes) with Global FlyMates
  • Competitive time off including FlyBetter Days to volunteer in your community and Digital Disconnect Days!
  • Great Talent & Development Programs (Managers Taking Flight – for new or aspiring managers!)

Submit today and get started!

We are excited to get to know you! Throughout our process you can expect to meet different FlyMates including the Hiring Manager and other Flymates. Your Talent Acquisition Partner will walk you through the steps and be your “go-to” person for questions.

Flywire is an equal opportunity employer and follows a policy of administering all employment decisions and personnel actions without regard to race, color, religion, sex, pregnancy, gender identity, national origin, age, ancestry, physical or mental disability, sexual orientation, genetic disposition or carrier status, veteran status, or any other category protected under applicable national, federal, state or local law.

The US base salary range for this full-time position is $160,000 - $200,000 plus bonus, and benefits. Our salary ranges are determined by role, position level, and location. The range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and several other factors, including job-related skills, experience, relevant education and training.

#LI-Hybrid

Read the full description
Security Detection Development Intern, Fall 2026 at Coveo

Detection engineering intern builds and tunes threat detection rules in XSIAM, analyzes security logs, and researches threat actor tactics to strengthen SOC detection capabilities.

Junior Hybrid Posted about 17 hours ago RemoteFirstJobs Product
What this role involves

What does it take to detect real threats across a large SaaS environment?

Are you curious about how enterprise security teams identify suspicious activity, build detections, and improve visibility across modern cloud and Software as a Service (SaaS) platforms? Coveo is looking for a Detection Engineering Intern to join our Security Operations Center (SOC) team. Your mission? Help us strengthen our detection coverage by building and tuning threat detection rules for the technologies that support Coveo’s production environment.

The SOC team plays a key role in protecting Coveo by monitoring security activity, investigating alerts, and continuously improving our ability to detect threats across our SaaS and infrastructure footprint. As an intern, you’ll contribute to initiatives that expand our detection capabilities while gaining hands-on experience with real enterprise threat detection tools in a production environment.

Your impact, day to day:

  • Participate in daily stand-up meetings to discuss progress, roadblocks, and priorities. Collaborate with team members to ensure alignment and effective communication.
  • Build and tune detection rules in XSIAM for different technologies, SaaS platforms, and log sources.
  • Research how services and tools could be abused by threat actors in order to identify realistic detection opportunities.
  • Contribute to detection coverage for platforms such as 1Password, AWS, Cortex XDR logs, and other more.
  • Analyze logs and security telemetry to better understand user activity, system behavior, and potential indicators of suspicious activity.
  • Take an active role in discussions around detection quality. Share your thinking, ask questions, and receive feedback to strengthen your analytical approach and technical skills.
  • Develop your skills by drawing on your coach’s expertise. Watch, learn, and apply best practices used in security monitoring, threat detection, and detection engineering.

The Essentials:

  • You are currently studying Software Engineering or Computer Science in a Bachelors degree or higher in the province of QuĂŠbec.
  • You can be present at the office at least two days a week. Our hybrid work model offers flexibility, you can benefit from face-to-face learning from your team on office days while home days allow you to focus and complete complex work.
  • You are available to work full-time for 15 weeks and are legally entitled to do so in Canada.

Think you’ve got what it takes? Let’s see!

  • You are curious, eager to learn, and motivated to understand how security tools and systems work.
  • You are able to think analytically and consider the broader context behind security events, instead of focusing only on isolated details.
  • You have an interest in threat detection, security monitoring, incident response, or detection engineering.
  • You have some familiarity with security information and event management (SIEM), core concepts of security tooling.
  • You have participated in some Capture The Flag competitions and/or have a few personal projects.
  • You have a strong sense of ownership and are proud of what you create.

Join the Coveolife!

Do you think you can bring this role to life? Send us your application, we want to hear from you!

We encourage all qualified candidates to apply regardless of, for example, age, gender, disability, gaps in CV, national or ethnic background.

This job description was written by humans, assisted by AI. We may leverage technology in our hiring process to help us see the person behind the resume.

Coveo is committed to providing accessible employment practices. If you require accommodation due to a disability at any point during the recruitment process, please contact HR@Coveo.com to discuss your needs.

Read the full description
Security IT GRC Specialist - Fully Remote | Upto $120/hr

Manages IT governance, risk, and compliance frameworks to ensure organizational security and regulatory adherence.

Mid Remote Posted about 17 hours ago Himalayas
What this role involves
About the jobMercor connects elite creative and technical talent with leading AI research labs.
Read the full description
Security Senior Security Engineer

Designs and implements security infrastructure and protocols to protect healthcare systems and sensitive patient data across government assistance programs.

Senior Posted 1 day ago Jobicy AI
What this role involves
About Pair TeamPair Team is building a new kind of healthcare system across Medicaid, Medicare, and public assistance programs: one that recognizes that access to housing, nutritious food, and reliable...
Read the full description
Security Security Engineer at Primer

Builds product security infrastructure through threat modeling, security reviews, compliance, and AppSec tooling for a payments platform.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

An Introduction to Primer

Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.

Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we’re building the payments layer the world’s best companies rely on.

Watch our showcase >

Read up on our $100m Series C

Learn more about our culture >

Which team will you be joining?

You’ll help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You’d be the second hire, and the person that function finally gets to share the work with.

This is a hands-on delivery role, and a genuinely formative one. You’ll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams. You’ll have a clear direction to work within and someone senior to learn from, while still owning your projects end to end.

Security at Primer sits close to the engineering teams it protects rather than off to one side, so you’ll spend real time embedded with the people building Cloud, Infra, and product. For someone who wants to go deep in product security with room to grow, there are few better seats than being the second engineer in a function that’s only now scaling.

What will you be doing?

  • Running security reviews and threat modelling on features and systems across Primer’s product, and turning findings into clear, actionable guidance for the teams shipping them

  • Independently planning and delivering your own security projects, from initial design through to rollout

  • Building tooling and automation that makes future reviews faster and cheaper to run

  • Coordinating penetration testing and tracking remediation through to closure

  • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows

  • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM

  • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for

  • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

What we’re looking for

  • Working experience in product or application security: you’ve done security reviews or threat modelling and can spot the risks that matter

  • The ability to read and write code, not just review it. You’re comfortable building small tools and automation rather than only filing findings

  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly

  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer

  • Clear communication with engineers who aren’t security specialists, since most of your impact lands through their work

Nice to have:

  • Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them

  • Background in payments, fintech, or another regulated, high-stakes domain

  • Interest in areas like supply chain security, detection engineering, or AI security

You may not like it here

  • It’s remote-first and high autonomy. You’ll get direction, but nobody checks your progress daily. If you need close structure, this will be uncomfortable

  • You’ll move between proactive project work and reactive BAU, and priorities will shift as audits and incidents land. Tolerating that change is part of the role.

✅ A typical interview process

  • An initial intro call with a Talent Partner

  • An interview with the Hiring Manager

  • Challenge Stage - Contextualised to the role

  • A final, values-alignment interview

What’s the culture like at Primer?

We’re building a culture where people can do their best work and be proud of the impact they have. You’ll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.

We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and co-working space access worldwide.

The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there’s a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It’s never something you face alone.

Our benefits

🌍 We are fully remote and globally distributed; and have been since day one

💰 Competitive share options

🌴 Uncapped holiday, with 25 days minimum to be taken

🗣️ Co-working space access

📅 Workations & Company Retreat

💻 The best equipment for your role

🏠 £500 towards your home office setup

🔎 Generous learning budget

🏥 Private Medical Insurance

📈 A broad set of additional perks and benefits ( depending on location)

Don’t meet every single requirement?

At Primer, we’re dedicated to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience doesn’t align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.

Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.

Read the full description
Security Staff, Security Engineer at Fullscript

Staff-level security engineer who designs and implements security solutions across applications and platforms while mentoring teams and shaping security strategy.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.

Join us and shape the future of care.

The Opportunity

We’re looking for a Staff Security Engineer to join Fullscript’s Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You’ll work closely with engineering teams to design and implement security solutions that scale across Fullscript’s products and platforms. As a Staff-level engineer, you’ll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You’ll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We’re looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you’ll do

  • Lead the design and implementation of security solutions across Fullscript’s applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript’s long-term security posture.

What you bring to the table

  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.

Bonus if you have

  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.

What we can offer you

  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career

Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More

www.fullscript.com

@fullscriptHQon instagram

@fullscript on YouTube

FullScripton LinkedIn

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Engineer at Primer

Conducts security reviews, threat modeling, and compliance work for a payments platform while building AppSec tooling and automation.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

An Introduction to Primer

Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.

Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we’re building the payments layer the world’s best companies rely on.

Watch our showcase >

Read up on our $100m Series C

Learn more about our culture >

Which team will you be joining?

You’ll help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You’d be the second hire, and the person that function finally gets to share the work with.

This is a hands-on delivery role, and a genuinely formative one. You’ll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams. You’ll have a clear direction to work within and someone senior to learn from, while still owning your projects end to end.

Security at Primer sits close to the engineering teams it protects rather than off to one side, so you’ll spend real time embedded with the people building Cloud, Infra, and product. For someone who wants to go deep in product security with room to grow, there are few better seats than being the second engineer in a function that’s only now scaling.

What will you be doing?

  • Running security reviews and threat modelling on features and systems across Primer’s product, and turning findings into clear, actionable guidance for the teams shipping them

  • Independently planning and delivering your own security projects, from initial design through to rollout

  • Building tooling and automation that makes future reviews faster and cheaper to run

  • Coordinating penetration testing and tracking remediation through to closure

  • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows

  • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM

  • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for

  • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

What we’re looking for

  • Working experience in product or application security: you’ve done security reviews or threat modelling and can spot the risks that matter

  • The ability to read and write code, not just review it. You’re comfortable building small tools and automation rather than only filing findings

  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly

  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer

  • Clear communication with engineers who aren’t security specialists, since most of your impact lands through their work

Nice to have:

  • Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them

  • Background in payments, fintech, or another regulated, high-stakes domain

  • Interest in areas like supply chain security, detection engineering, or AI security

You may not like it here

  • It’s remote-first and high autonomy. You’ll get direction, but nobody checks your progress daily. If you need close structure, this will be uncomfortable

  • You’ll move between proactive project work and reactive BAU, and priorities will shift as audits and incidents land. Tolerating that change is part of the role.

✅ A typical interview process

  • An initial intro call with a Talent Partner

  • An interview with the Hiring Manager

  • Challenge Stage - Contextualised to the role

  • A final, values-alignment interview

What’s the culture like at Primer?

We’re building a culture where people can do their best work and be proud of the impact they have. You’ll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.

We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and co-working space access worldwide.

The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there’s a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It’s never something you face alone.

Our benefits

🌍 We are fully remote and globally distributed; and have been since day one

💰 Competitive share options

🌴 Uncapped holiday, with 25 days minimum to be taken

🗣️ Co-working space access

📅 Workations & Company Retreat

💻 The best equipment for your role

🏠 £500 towards your home office setup

🔎 Generous learning budget

🏥 Private Medical Insurance

📈 A broad set of additional perks and benefits ( depending on location)

Don’t meet every single requirement?

At Primer, we’re dedicated to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience doesn’t align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.

Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.

Read the full description
Security Security Engineer at Primer

Security engineer performs threat modeling, security reviews, compliance work, and builds AppSec tooling for a payments infrastructure platform.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

An Introduction to Primer

Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.

Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we’re building the payments layer the world’s best companies rely on.

Watch our showcase >

Read up on our $100m Series C

Learn more about our culture >

Which team will you be joining?

You’ll help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You’d be the second hire, and the person that function finally gets to share the work with.

This is a hands-on delivery role, and a genuinely formative one. You’ll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams. You’ll have a clear direction to work within and someone senior to learn from, while still owning your projects end to end.

Security at Primer sits close to the engineering teams it protects rather than off to one side, so you’ll spend real time embedded with the people building Cloud, Infra, and product. For someone who wants to go deep in product security with room to grow, there are few better seats than being the second engineer in a function that’s only now scaling.

What will you be doing?

  • Running security reviews and threat modelling on features and systems across Primer’s product, and turning findings into clear, actionable guidance for the teams shipping them

  • Independently planning and delivering your own security projects, from initial design through to rollout

  • Building tooling and automation that makes future reviews faster and cheaper to run

  • Coordinating penetration testing and tracking remediation through to closure

  • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows

  • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM

  • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for

  • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

What we’re looking for

  • Working experience in product or application security: you’ve done security reviews or threat modelling and can spot the risks that matter

  • The ability to read and write code, not just review it. You’re comfortable building small tools and automation rather than only filing findings

  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly

  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer

  • Clear communication with engineers who aren’t security specialists, since most of your impact lands through their work

Nice to have:

  • Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them

  • Background in payments, fintech, or another regulated, high-stakes domain

  • Interest in areas like supply chain security, detection engineering, or AI security

You may not like it here

  • It’s remote-first and high autonomy. You’ll get direction, but nobody checks your progress daily. If you need close structure, this will be uncomfortable

  • You’ll move between proactive project work and reactive BAU, and priorities will shift as audits and incidents land. Tolerating that change is part of the role.

✅ A typical interview process

  • An initial intro call with a Talent Partner

  • An interview with the Hiring Manager

  • Challenge Stage - Contextualised to the role

  • A final, values-alignment interview

What’s the culture like at Primer?

We’re building a culture where people can do their best work and be proud of the impact they have. You’ll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.

We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and co-working space access worldwide.

The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there’s a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It’s never something you face alone.

Our benefits

🌍 We are fully remote and globally distributed; and have been since day one

💰 Competitive share options

🌴 Uncapped holiday, with 25 days minimum to be taken

🗣️ Co-working space access

📅 Workations & Company Retreat

💻 The best equipment for your role

🏠 £500 towards your home office setup

🔎 Generous learning budget

🏥 Private Medical Insurance

📈 A broad set of additional perks and benefits ( depending on location)

Don’t meet every single requirement?

At Primer, we’re dedicated to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience doesn’t align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.

Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.

Read the full description
Security Staff, Security Engineer at Fullscript

Staff-level security engineer designs and implements security solutions across products, leads technical initiatives, and mentors engineering teams on embedding security in the SDLC.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.

Join us and shape the future of care.

The Opportunity

We’re looking for a Staff Security Engineer to join Fullscript’s Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You’ll work closely with engineering teams to design and implement security solutions that scale across Fullscript’s products and platforms. As a Staff-level engineer, you’ll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You’ll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We’re looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you’ll do

  • Lead the design and implementation of security solutions across Fullscript’s applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript’s long-term security posture.

What you bring to the table

  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.

Bonus if you have

  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.

What we can offer you

  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career

Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More

www.fullscript.com

@fullscriptHQon instagram

@fullscript on YouTube

FullScripton LinkedIn

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Network and Cybersecurity SME

Provides infrastructure support and cybersecurity expertise for NIH-contracted work, managing network security and IT infrastructure.

Senior Remote Posted 3 days ago Jobicy AI
What this role involves
ECS is seeking an experienced Network and Cybersecurity SME to work remotely providing infrastructure support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other tasks...
Read the full description
Security Network and Cybersecurity Delivery Lead

Leads network and cybersecurity infrastructure delivery for government contracts, managing technical implementation and team oversight.

Lead Remote Posted 3 days ago Jobicy AI
What this role involves
ECS is seeking an experienced Network and Cybersecurity Delivery Lead to work remotely providing infrastructure support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other...
Read the full description
Security System Administrator (Cyber Infrastructure)

Manages cyber infrastructure systems and provides infrastructure support for government research contracts, ensuring secure and reliable IT operations.

Mid Remote Posted 3 days ago Jobicy AI
What this role involves
ECS is seeking an experienced Cyber Infrastructure System Administrator to work remotely providing infrastructure support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other tasks...
Read the full description
Security Computer Security System Specialist

Provides cybersecurity support and manages security systems for a government contract supporting NIH research operations.

Mid Remote Posted 3 days ago Jobicy AI
What this role involves
ECS is seeking an experienced Computer Security System Specialist to work remotely providing cybersecurity support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other tasks...
Read the full description
Security Cybersecurity Pentester

Conducts penetration testing and security assessments to identify and remediate vulnerabilities in systems and applications.

Posted 3 days ago Himalayas
What this role involves
Powering the world’s payments ecosystemACI powers the payments ecosystem – globally, and you power ACI.
Read the full description
Security Red Team Operator I

Conducts offensive security testing and adversarial simulations to identify vulnerabilities in government and critical infrastructure systems.

Junior Posted 3 days ago Himalayas
What this role involves
SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats.
Read the full description
Security Sr Security Operations Engineer, Detection and Response

Detects, investigates, and responds to security threats and incidents across the organization's systems and networks.

Senior Posted 3 days ago Jobicy AI
What this role involves
Who we are At Fortis Games we aspire to make great games that bring people together while redefining how game companies work. We believe in building a sense of belonging...
Read the full description
Security Security Analyst 3rd Level

Investigates complex security incidents, performs deep analysis, escalates critical issues, and coordinates communication between customers and internal teams.

Senior Posted 3 days ago Himalayas
What this role involves
deine mission • Komplexe Security Incidents landen bei dir - du gehst in die Tiefe, analysierst sauber und triffst fundierte Entscheidungen • Als Eskalationsinstanz bringst du Ruhe in kritische Situationen und hältst die Kommunikation zwischen Kund:innen und internen Teams klar und strukturiert • In Kundenterminen (z.
Read the full description