Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Security Compliance Analyst

Assesses cyber risks, manages vulnerabilities, and supports security compliance for a case management modernization program.

Senior Posted about 6 hours ago Himalayas
What this role involves
Type of Requisition:RegularClearance Level Must Currently Possess: NoneClearance Level Must Be Able to Obtain: NonePublic Trust/Other Required:NoneJob Family: Cyber and IT Risk ManagementJob Qualifications:Skills:Cyber Risks, Security Compliance, Vulnerability Assessments, Vulnerability ManagementCertifications:NoneExperience:5 + years of related experienceUS Citizenship Required:NoJob Description: Seize your opportunity to make a personal impact supporting the Case Management Modernization (CMM) Program.
Read the full description
Security Senior Electronic Security Engineer | Remote at Cambridge International Systems, Inc.

Engineers, integrates, modernizes, tests, and sustains electronic security systems including access control, intrusion detection, and surveillance for government missions.

Senior Remote Posted about 7 hours ago RemoteFirstJobs Product
What this role involves

Senior Electronic Security Engineer | Remote

Cambridge International Systems, Inc.

Join a dynamic global team united by shared values: commitment, integrity, and perseverance. At Cambridge, you’ll work alongside top talent worldwide, tackling some of today’s most complex and critical challenges in defense and security.

We are currently seeking a Senior Electronic Security Engineer to support our team in a fully remote capacity.  This position is contingent on contract award, with an expected start date of March 13, 2028.

What You’ll Do

As a Senior Electronic Security Engineer, you will play a critical role in the engineering, design, integration, modernization, and sustainment of Electronic Security Systems supporting U.S. government missions. You will represent Cambridge in the delivery of electronic security system engineering products and solutions. You will:

  • Electronic Security Systems (ESS) engineering and design
  • Physical Access Control Systems / Access Control Systems (PACS/ACS)
  • Intrusion Detection Systems (IDS)
  • Video Surveillance Systems / CCTV (VSS/CCTV)
  • ESS command-and-control systems
  • Data transmission/network infrastructure supporting ESS
  • ESS system integration
  • Site surveys and system design
  • Development and review of engineering drawings and technical packages
  • Equipment selection and Bill of Materials development
  • Installation oversight
  • System testing, commissioning, and Government acceptance
  • ESS modernization and sustainment
  • DoD/Army physical security requirements
  • Cybersecurity/RMF as applied to ESS, OT, or facility-related systems
  • Support for multiple simultaneous ESS projects
  • CONUS and OCONUS installation experience

What You’ll Bring

Required Qualifications:

  • Must be proficient in using computers, engineering/design tools, and other technologies, tools, and systems pertinent to electronic security system engineering.

Education & Experience:

  • Bachelor’s degree or higher in Engineering from an accredited university or college.
  • Minimum 10 years of experience in Electronic Security Systems.

Technical Expertise:

  • Knowledge of DoD/Army physical security requirements and cybersecurity/RMF as applied to ESS, OT, or facility-related systems.
  • Experience supporting system installation, testing, commissioning, Government acceptance, modernization, and sustainment.
  • Experience with ESS integration, site surveys, engineering drawings, technical packages, equipment selection, and Bill of Materials development.
  • Knowledge of PACS/ACS, IDS, VSS/CCTV, ESS command-and-control systems, and supporting network infrastructure.
  • Strong experience in Electronic Security Systems engineering and design.

Clearance:

  • Must have a current and active DoD Secret security clearance.

Preferred (Nice to Have):

  • U.S. Professional Engineer (PE) certification or Certified Protection Professional (CPP) certification.
  • Direct ESS VII or Huntsville ESS-MCX experience.
  • Experience with large federal ESS integrators or multi-site/global ESS programs.
  • Experience supporting DoD electronic security integration programs.
  • Experience supporting Army ESS programs or Army installation physical security programs.
  • Experience supporting the USACE Electronic Security Systems Mandatory Center of Expertise (ESS-MCX).
  • Experience supporting USACE Huntsville / CEHNC, ESS VII, ESS VI, or earlier USACE ESS vehicles.

Travel Requirements

Travel may be required to support customer sites and program requirements, including CONUS and OCONUS locations. Some overnight travel may be required.

Physical & Work Environment Requirements

  • Interaction with others in dynamic environments, including situations requiring problem-solving and conflict resolution.
  • Ability to manage competing priorities, work under deadlines, and maintain attention to detail.
  • Communication with team members, customers, and stakeholders through verbal and written methods.
  • Occasional extended work hours, including evenings or weekends, as needed.
  • Occasional travel between work locations, including customer sites and government installations, may be required.
  • Work is primarily performed remotely in a home-office or other approved remote work environment.
  • Periods of prolonged sitting, including desk-based computer work and extended use of computers and engineering/design software.

Background & Security

Employment is contingent upon successful background investigation

Alcohol and Drug screening may be required for federal contract compliance

Benefits & Perks

We believe in investing in our team—both professionally and personally:

Medical, dental, vision, life, accident, and critical illness insurance

401(k) immediate vesting and match

Paid time off and company holidays

Generous tuition & training support

Relocation assistance

Sign-on and performance-based bonuses

Employee referral program

Access to Tickets at Work, EAP, wellness initiatives, and more

Wellness program

Employee referral program

Access to Tickets at Work, EAP, wellness initiatives, and more

Join Us

If you’re driven by mission, technology, and teamwork—we want to hear from you. Cambridge is growing, and this position is just one of many opportunities on our global team. Know someone perfect for the role? Referrals are welcome—both employees and non-employees may qualify for a bonus.

Apply today and help shape the future of secure technology for national security.

About Cambridge International Systems

At Cambridge, we believe innovation and agility thrive when people work together. Our culture is built on teamwork, collaboration, and a commitment to listening, learning, and bringing out the best ideas in every employee. We empower our people to take on challenges, persevere to get the job done, and lead with integrity in everything we do.

Our commitment to our employees and workplace culture has been recognized through the DAV Patriot Small Employer of the Year Award in 2026 and the Cigna Healthy Workforce Gold Designation in 2025. These recognitions reflect our ongoing commitment to creating a workplace where employees are valued, supported, and empowered to do their best work. At Cambridge, we are proud to foster an environment where people can grow, contribute, and make a meaningful impact. Learn more at www.cbridgeinc.com.

We are an equal opportunity employer. Applicants and employees are considered for positions and are evaluated without regard to any protected status under applicable law or other similar factors that are not job-related. We encourage all qualified individuals to apply for employment. Selected applicants may be subject to a background investigation and/or education verification.

We provide reasonable accommodation for qualified individuals with disabilities in accordance with federal, state, and local law. If you require a reasonable accommodation to participate in the application process or to perform the essential functions of the position, please contact our Recruiting Team at [email protected].

Read the full description
Security Principal Security Engineer, Infrastructure Security

Leads infrastructure security engineering to protect the company’s technology, people, and products.

Lead Posted about 7 hours ago Jobicy AI
What this role involves
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products....
Read the full description
Security Principal Software Engineer, Infrastructure Security

Leads software engineering for infrastructure security, protecting the company’s technology, people, and products.

Lead Posted about 7 hours ago Jobicy AI
What this role involves
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products....
Read the full description
Security Remote Encryption Engineer (HSM)

Designs, implements, and maintains encryption systems and hardware security modules for a six-month remote contract.

Remote Posted about 7 hours ago Himalayas
What this role involves
Exciting Remote Encryption Engineer (HSM), 6 months, contract opportunity.
Read the full description
Security Cloud Security Engineer at Smile Digital Health

Designs, automates, and deploys secure production-grade cloud infrastructure across AWS, Azure, OCI, and GCP while supporting internal teams and customers.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte’s Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.

At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Cloud Security Engineer is responsible for designing, automating and deploying production-grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This position works closely with the Cloud Architect and Development teams to ensure infrastructure fulfills the project’s deliverables while keeping a high standard of quality and operational maturity.

Responsibilities:

  • Collaborate with Development and Architecture teams to build  complex and highly available cloud environments for Internal and External infrastructure builds.
  • Provide Level 3 Technical support to Internal teams, customers, and Partners to support our core product.
  • Lead and educate clients on cloud deployment patterns.
  • Act as a SME for implementing and building infrastructure to support our core product.
  • Investigate and resolve any customer integration issues that arise during implementation.
  • Design procedures for system troubleshooting and maintenance.
  • Perform root cause analysis for any implementation errors and provide feedback to the Core dev team.
  • Document best practices and lessons learned.
  • Design, implement and maintain a secure and scalable infrastructure platform.
  • Provide ongoing maintenance and support of internal tools, improve system health and reliability.

Requirements:

  • At least 6+ years of experience in Information technology, with infrastructure and platform services automation expertise.
  • 4+ years of experience with engineering and supporting containerization technology.
  • 4+ years of experience on AWS, Azure, OCI or GCP.
  • Professional Cloud Certifications are preferred.
  • Experience building end-to-end cloud solutions using low-level architecture documents.
  • Demonstrated experience in translating customer requirements to net new infrastructure to address business needs.
  • Drive to innovate and use various technologies to solve complex business needs.
  • Expertise in troubleshooting support escalation, on-Call process optimization and documenting knowledge.
  • Solid networking fundamentals and proven experience with Security and Compliance (SOC2, HIPAA, ISO27001) best practices and how to implement controls that support high-velocity software delivery teams.
  • Proven experiencewith Kubernetes/Openshift and Docker.
  • Experience with Infrastructure as Code tools such as Ansible, Terraform or CloudFormation.
  • Deep knowledge of cloud service providers and best practices around implementation and configuration, preferably managing customer environments.

$120,000 - $140,000 a year

Smile discloses that artificial intelligence (AI) may be used in portions of the recruitment and selection process, such as resume screening or application assessment. All hiring decisions are ultimately made by qualified human decision-makers, and AI tools are used to support — not replace — fair and equitable hiring practices.

This position is a new role, created to support Smile’s continued growth and commitment to operational excellence.

Some of the benefits we offer:

\* Remote Work Environment

\* Flexible Time Away From Work Policy including PTO, Personal and Sick Days

\* Competitive Salary and Health/Medical Benefits

\* RRSP/TFSA/401K Employee Contribution

\* Life and Disability

\* Employee Assistance Program

\* FHIR Study Program and Skillsoft Learning

\* Super HAPI Fun Club

Smile’s core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.

We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Staff/Principal Security Engineer (U. S. Air Force) at Skylight

Staff/Principal security engineer who guides teams through security best practices, conducts audits, and manages compliance frameworks across modernization projects.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

About Skylight

Skylight is a digital consultancy using design and technology to help government agencies deliver better public services.

We’re at the forefront of a civic movement to reinvent how all levels of government serve families, patients, and many others in today’s digital world.

If you want to play a part in driving this critical movement forward, we’d love for you to join our growing team of public interest technologists.

The work we do matters.

About the job

At Skylight, security engineers stay up to date with the cutting edge of security and help teams implement new processes, tools, and remediations. They’re familiar with modern software development and work in cross-functional teams to inform and guide security best practices at all stages of the software development life cycle.

Skylight has partnered with the U.S. Air Force across multiple legacy modernization efforts. The work spans modernization of legacy systems, new capability development in multi-vendor environments, iteration on established platforms, all inside an agile transformation and broader organizational change.

You’ll be the security voice across several modernization efforts: assessing legacy applications, guiding teams toward compliant architectures on Air Force platforms, and making security an enabler of faster delivery rather than a gate at the end.

What to know going in

Your first 30 days are about working with the Skylight team and government personnel, learning the client’s domain and organization, and enabling your government partners. Access to users varies from team to team, so you’ll need to get creative about how you reach them. The client is early- to mid-transformation, so expect organizational and operational change along the way.

This role is contingent on Skylight being awarded the underlying contract. If we’re not awarded the contract, we’ll let you know promptly and discuss whether there are other opportunities that fit.

What you’ll do

  • Protect sensitive data by applying security and privacy best practices
  • Conduct security audits and risk analyses of legacy applications and their modernized replacements
  • Execute Risk Management Framework (RMF), Authorization to Operate (ATO), and continuous ATO (cATO) processes, and carry the security documentation and narrative that supports authorization
  • Write security controls and documentation as the build proceeds, so security is a build-time deliverable in the pipeline rather than an audit at the end
  • Conduct ongoing research to keep up with industry practices and new attack vectors
  • Select and use the right tools, frameworks, languages, and technologies for the job, with a preference for open-source solutions
  • Pair with and coach government engineers so secure practices become part of how the teams work

What we’re looking for

Basic qualifications

  • Experience taking systems through RMF and ATO, ideally in a DoD context, including authoring the control implementation and body of evidence
  • Able to detect risks by continually reviewing all aspects of the application for vulnerabilities and enumerating them
  • Able to mitigate and prevent risks by proactively working with teams to build secure and compliant systems
  • Familiarity with common sources of vulnerability information
  • Familiarity with regulatory requirements regarding security and compliance
  • Experience working in agile software development
  • Interest in mentoring, coaching, and pairing with government partners so they can carry the work forward
  • Experience working on cross-functional teams (product, design, engineering, ops) in iterative delivery
  • A mindset and work approach that aligns with our core values

Nice-to-haves

  • Can write clean, working, and reusable code in at least one programming language
  • Experience with application development, particularly web development and testing frameworks
  • Experience with cloud infrastructure and infrastructure as code
  • Military or government experience
  • Experience delivering technology in government, regulated industries, or other public-benefit settings
  • A track record of staying aligned and accountable on remote teams

Don’t meet every qualification but think you can do the job? We’d still love to hear from you. If you’re excited about the role, apply. We consider candidates with a range of backgrounds and experiences.

Other requirements

  • Some of our available roles are on federal contracts that require a degree or additional years of experience as a substitute.
  • All work must be conducted within the U.S., excluding U.S. territories.
  • This contract requires U.S. citizenship to be eligible for employment.
  • You must be able to obtain and maintain a Common Access Card (CAC), which requires a favorable background check.
  • You must complete a company background check successfully.

Logistics

Position type

This is a full-time, exempt position.

Location

This is a fully remote position.

Travel

Expect occasional travel to Air Force bases across the U.S., quarterly at most.

Expected start date

November 2026

Care package

Salary

We want to give you the most competitive salary possible. After all, you deserve it! To that end, we use the results of our interview process to determine what salary is most appropriate given your current level of seniority. For a Security Engineer at Skylight, the current salary ranges are as follows:

  • Associate Security Engineer: $90,000–$125,000
  • Security Engineer I: $120,000–$140,000
  • Security Engineer II: $135,000–$160,000
  • Senior Security Engineer: $150,000–$185,000
  • Staff Security Engineer: $170,000–$203,000
  • Principal Security Engineer: $180,000–$230,000

Benefits

Your well-being is important to us, so we focus on supporting you in a variety of ways:

  • Medical insurance, dental insurance, vision insurance
  • Short-term and long-term disability insurance
  • Life and AD&D insurance
  • Dependent care FSA, healthcare FSA, health savings account
  • Dollar-for-dollar 401(k) match up to 10% of your salary with no vesting period
  • Flexible paid-time-off policy (generally around 25 days per year), plus 11 paid federal holidays
  • Up to 12 weeks paid-time-off for all eligible new birth, adoption, or foster parents
  • Performance rewards, including annual salary increase, annual performance bonus, spot bonuses, and stock options
  • Business development / sales bonuses
  • Referral bonuses
  • Annual $2000 allowance for professional development
  • Annual $750 allowance for tech-related purchases
  • Annual swag budget of $100 to display your Skylight pride with some merchandise (hoodies, hats, and more)
  • Flexible, remote-friendly work environment
  • An environment that empowers you to unleash your superpowers for public good

Interview tips

Our process includes a preliminary screen, a skills interview, a behavioral interview, and a reverse interview where you meet your potential team — usually four conversations across two to three weeks. Here are some tips to help you prepare for a successful interview:

  • Visit our join page to learn more about how our interview process works.
  • Check out our Career Pathways framework to learn more about the different roles within Skylight and the skills needed to do them.
  • Browse our case studies to learn more about our work.

If you’d like to request reasonable accommodations during the application or interviewing process, please contact our recruiting team at recruiting@skylight.digital.

We participate in E-Verify and upon hire, will provide the federal government with your Form I-9 information to confirm that you’re authorized to work in the U.S.

We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, sex, religion, age, disability, veteran status, or any other category protected by applicable law.

Read the full description
Security Cloud Security Engineer at Smile Digital Health

Designs, automates, and deploys secure production cloud infrastructure across AWS, Azure, OCI, and GCP while supporting internal teams and customers.

Senior Posted 1 day ago RemoteFirstJobs Product
What this role involves

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte’s Technology Fast 50 Ranking for 2024!

Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.

At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Cloud Security Engineer is responsible for designing, automating and deploying production-grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP. This position works closely with the Cloud Architect and Development teams to ensure infrastructure fulfills the project’s deliverables while keeping a high standard of quality and operational maturity.

Responsibilities:

  • Collaborate with Development and Architecture teams to build  complex and highly available cloud environments for Internal and External infrastructure builds.
  • Provide Level 3 Technical support to Internal teams, customers, and Partners to support our core product.
  • Lead and educate clients on cloud deployment patterns.
  • Act as a SME for implementing and building infrastructure to support our core product.
  • Investigate and resolve any customer integration issues that arise during implementation.
  • Design procedures for system troubleshooting and maintenance.
  • Perform root cause analysis for any implementation errors and provide feedback to the Core dev team.
  • Document best practices and lessons learned.
  • Design, implement and maintain a secure and scalable infrastructure platform.
  • Provide ongoing maintenance and support of internal tools, improve system health and reliability.

Requirements:

  • At least 6+ years of experience in Information technology, with infrastructure and platform services automation expertise.
  • 4+ years of experience with engineering and supporting containerization technology.
  • 4+ years of experience on AWS, Azure, OCI or GCP.
  • Professional Cloud Certifications are preferred.
  • Experience building end-to-end cloud solutions using low-level architecture documents.
  • Demonstrated experience in translating customer requirements to net new infrastructure to address business needs.
  • Drive to innovate and use various technologies to solve complex business needs.
  • Expertise in troubleshooting support escalation, on-Call process optimization and documenting knowledge.
  • Solid networking fundamentals and proven experience with Security and Compliance (SOC2, HIPAA, ISO27001) best practices and how to implement controls that support high-velocity software delivery teams.
  • Proven experiencewith Kubernetes/Openshift and Docker.
  • Experience with Infrastructure as Code tools such as Ansible, Terraform or CloudFormation.
  • Deep knowledge of cloud service providers and best practices around implementation and configuration, preferably managing customer environments.

$120,000 - $140,000 a year

Smile discloses that artificial intelligence (AI) may be used in portions of the recruitment and selection process, such as resume screening or application assessment. All hiring decisions are ultimately made by qualified human decision-makers, and AI tools are used to support — not replace — fair and equitable hiring practices.

This position is a new role, created to support Smile’s continued growth and commitment to operational excellence.

Some of the benefits we offer:

\* Remote Work Environment

\* Flexible Time Away From Work Policy including PTO, Personal and Sick Days

\* Competitive Salary and Health/Medical Benefits

\* RRSP/TFSA/401K Employee Contribution

\* Life and Disability

\* Employee Assistance Program

\* FHIR Study Program and Skillsoft Learning

\* Super HAPI Fun Club

Smile’s core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.

We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security ATO Specialist at Oddball

Leads Authority to Operate (ATO) lifecycle, security authorization, and compliance efforts for federal information systems while coordinating with engineering and government stakeholders.

Senior Remote Posted 1 day ago RemoteFirstJobs Product
What this role involves

Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.

We are seeking an experienced ATO Specialist to lead security authorization and compliance efforts for the VA Chatbot program. In this role, you’ll own and drive the Authority to Operate (ATO) lifecycle for a veteran-facing system, partnering closely with engineering, program leadership, and government stakeholders to maintain a strong, audit-ready security posture while supporting ongoing delivery.

What you’ll be doing:

  • Lead and manage the ATO, reauthorization, and Continuous Monitoring lifecycle for the VA Voicebot system
  • Serve as the primary security point of contact for the program, coordinating with VA stakeholders and internal leadership
  • Prepare, maintain, and update required security and privacy artifacts, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Assessment Reports (SARs), Privacy Impact Assessments (PIAs), and supporting evidence
  • Partner with engineering and program management teams to ensure security controls are properly implemented, documented, and maintained in alignment with RMF and VA security policy
  • Coordinate control assessments, evidence collection, and responses to audit or assessment findings
  • Advocate for and support adoption of security best practices, including Zero Trust Architecture (ZTA) concepts, to strengthen the platform’s overall security posture

What you’ll bring:

  • Proven experience leading ATO processes for federal information systems

  • Strong working knowledge of the Risk Management Framework (RMF) and federal security requirements

  • Demonstrated experience producing and maintaining federal security documentation, including SSPs, POA&Ms, PIAs, and SARs

  • Familiarity with Zero Trust Architecture principles and how they apply within federal systems

  • Performs other related duties as assigned.

Requirements:

  • Applicants must be authorized to work in the United States. In alignment with federal contract requirements, certain roles may also require U.S. citizenship and the ability to obtain and maintain a federal background investigation and/or a security clearance.

Education:

  • Bachelor’s degree

Benefits:

  • Fully remote
  • Yearly stipend
  • Comprehensive Benefits Package
  • Company Match 401(k) plan
  • Flexible PTO, Paid Holidays

Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hello@Oddball.io

Compensation:

At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.

United States Wage Range: $100,000 – $140,000

Read the full description
Security Security Engineer, Insider Threat Detection & Response

Detects and responds to insider threats by monitoring security systems, investigating suspicious activities, and implementing threat mitigation strategies.

Mid Posted 1 day ago Jobicy AI
What this role involves
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products....
Read the full description
Security Security Engineering Manager

Manages security engineering team and oversees implementation of security systems and protocols across the organization.

Lead Posted 1 day ago Jobicy AI
What this role involves
OUR ORIGIN STORY 🎂 In 2011 SkySlope started as an idea born at the kitchen table of our CEO, with just him and two others. Headquartered in Sacramento, California, we...
Read the full description
Security Application Security Engineer - Mid-Atlantic region (Remote in VA, MD, PA, NC, D

Develops and implements application security measures to identify vulnerabilities, protect systems from threats, and minimize organizational risk.

Mid Remote Posted 2 days ago Himalayas
What this role involves
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk.
Read the full description
Security Principal Information Security Manager - remote working within Germany at Staffbase

Principal Information Security Manager oversees compliance, audit cycles, customer trust initiatives, and modernizes InfoSec operations with AI-driven workflows for an enterprise SaaS company.

Senior Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

About Staffbase

We inspire people to achieve great things together. Our mission is to help organizations unlock the power of inspirational communication with the first AI-native Employee Experience Platform. Our industry-leading and award-winning agentic AI communications channels - intranet, employee app and email solutions - create engaging experiences that connect and empower employees.

Headquartered in Chemnitz, Germany and New York City, with offices in Berlin, London, Sydney, Tokyo, Prague, and Minneapolis–St. Paul, our diverse team of 550+ employees supports 1,500+ customers—reaching over 14 million employees—in transforming their employee experience.

We are proud to be a Unicorn company—privately valued at over $1 billion—demonstrating strong growth, innovation, and lasting impact in our industry. Together, we’re shaping the future of workplace communication.

Our information security program is fit for purpose and operationally sound. The next chapter is about making it investor-ready, AI-efficient, and capable of sustaining enterprise customer trust at scale.

This is not a build-from-scratch role. It is a step up in maturity: fewer manual processes and sharper governance.

The position sits at the center of the InfoSec team; you coordinate across teams, own outcomes and represent the function. You are comfortable being the person customers and auditors talk to.

You think in programs and systems, not tasks. You identify where manual effort can be replaced by tooling or AI-assisted workflows, and are empowered to drive that change as we build out our AI-driven operating model across the company.

What you’ll be doing

You will act as the senior deputy for InfoSec within our Finance & Operations department, owning the function day-to-day, representing it internally and externally, and making it run with less friction and more intelligence.

You report directly to the SVP Business Operations & Transformation and work closely with Legal, Procurement, Engineering, external auditors and enterprise customers.

You will own;

Compliance & Audit

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end in preparation, evidence collection, auditor management, and findings remediation
  • Own the control framework and ensure it stays current as the business evolves
  • Prepare the InfoSec program for investor and M&A due diligence scrutiny

Customer Trust

  • Own the response to enterprise customer security questionnaires and RFPs
  • Represent Staffbase credibly in customer security reviews, calls, and audits
  • Build scalable approaches (automation, templates, knowledge base) to reduce response time without sacrificing quality

Risk & Vendor Security

  • Maintain the risk register and drive risk treatment decisions with relevant stakeholders
  • Own vendor security assessments for critical and high-risk suppliers
  • Partner with Procurement and Legal on AI-assisted review workflows

Policy & Awareness

  • Own the internal security policy framework, keep it current, understandable, and enforced
  • Design and run security awareness programs that change behaviour, not just tick boxes

Incident Response

  • Own the incident response plan and lead execution when incidents occur
  • Coordinate with Engineering, Legal, and leadership during incidents
  • Drive post-incident reviews and close findings with owners

What you need to be successful

Essential Experience

  • 5+ years of hands-on InfoSec experience in a SaaS or B2B tech company
  • Proven ownership of ISO 27001 and/or SOC 2 programs
  • Track record of representing InfoSec to enterprise customers, including security reviews and escalations
  • Must be fluent in English
  • Comfortable with AI-driven tooling; actively looks for automation opportunities in compliance and operations

Highly Desirable

  • Experience supporting or preparing for M&A or investor due diligence processes
  • Background working alongside Legal, Procurement, and Engineering
  • Practical understanding of cloud security architecture (enough to challenge and validate, not operate)
  • Relevant certification: CISM, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent. Certification matters less than what you have built

What you’ll get

  • Competitive Compensation - we offer attractive salary packages including LTIP (unit-based Long Term Incentive Plan)
  • Flexibility- we offer flexible working time models and the option of hybrid work, and support this with a yearly flex work allowance of €1560
  • Recharge - with 31 vacation days annually (incl. one floating holiday), plus pro rata fully paid Fridays off during August
  • Support-we’re offering a company pension scheme
  • Volunteers Day- you’ll get one day off per year for supporting a social project
Read the full description
Security Staff Security Engineer at Garner Health

Lead technical security design and architecture for healthcare systems, owning design reviews and building automated defenses to protect sensitive patient data at scale.

Lead Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

What you’ll be part of

Garner is on a mission to transform the U.S. healthcare system — and we’re the only proven player doing exactly that. We partner with employers to redesign how healthcare works: applying 550+ proprietary clinical metrics across 80+ specialties to a dataset of 320M+ patients to identify the best-performing doctors, then using compelling incentives to steer members to the care that helps them get healthier, faster.

The result is a rare “win win” — better care and lower costs for both members and employers. In just five years, our work has helped over 2.5 million people access higher-quality care and saved $1B in healthcare costs. We recently raised our Series E and have doubled five years running. If you’ve ever wanted your work to solve a problem that touches every person in this country, this is the opportunity to do exactly that. You’d be joining a team fundamentally reimagining healthcare in the U.S. — and using AI to scale that impact further and faster than anyone else can.

About the role:

We are seeking a Staff Security Engineer to serve as a technical anchor for our security function. This role is critical for leading technical design reviews and ensuring our security posture scales alongside our rapid customer growth. You will be responsible for defining the security standards that protect sensitive healthcare data, ensuring our systems are resilient against evolving threats while maintaining high engineering velocity.

Where you will work:

Garner is headquartered in NYC, but this position is available for individuals who are comfortable with remote work and occasional travel to HQ.

What you will do:

  • Lead technical security design: Own the technical design and review process for security-critical systems, ensuring all new features meet Garner’s high standards for data protection and resilience
  • Master complex domains: Maintain and apply a mastery of one or more technical security domains (e.g., Cloud Security, AppSec, or Data) to solve the most complex business and technical challenges
  • Course-correct technical direction: Identify when technical paths are inefficient or insufficient and proactively redirect efforts to capture higher ROI for the firm
  • Architect automated defenses: Create and implement advanced tools and automation that increase the efficacy of security monitoring and incident response
  • Translate ambiguity into execution: Take broad, complex security objectives and break them down into well-defined deliverables and architectural requirements for the broader engineering team
  • Mentor through technical rigor: Raise the bar for the engineering function by providing high-level feedback during code and design reviews, fostering a culture of security-first development

The ideal candidate has:

  • Exceptional Technical Judgment: Proven ability to make high-stakes technical decisions that result in positive long-term outcomes for the company’s security posture
  • Strategic Problem-Solving: Effectively leverages context and data to analyze root causes and prioritize security initiatives that offer the greatest impact on risk reduction
  • Influential Stakeholder Management: Builds strong relationships across the organization, conveying complex security risks in a clear and compelling manner to both technical and non-technical partners
  • Drive for Innovation: Continuously identifies and implements creative solutions to pay down technical debt and improve the efficiency of our security infrastructure
  • Reliability Under Pressure: Handles complex escalations and security incidents with discipline, ensuring rigorous analysis and comprehensive resolution without jumping to conclusions
  • A desire to be a part of a high-performing, mission-driven team that operates with intense urgency, a strong sense of individual accountability, and a commitment to authentic feedback

Technologies we use:

  • Python, Kubernetes, Snowflake, AWS, Terraform, Wiz, Cyberhaven, and more

This is a unique opportunity to join a fast-growing company in a transformative role, helping shape the future of healthcare.

Compensation Transparency:

The target salary range for this position is $258,000 - $310,000. Individual compensation for this role will depend on various factors, including qualifications, skills, and applicable laws. In addition to base compensation, this role is eligible to participate in our equity incentive and competitive benefits plans, including but not limited to: flexible PTO, Medical/Dental/Vision plan options, 401(k), Teladoc Health and more.

Fraud and Security Notice:

Please be aware of recent job scam attempts. Our recruiters use getgarner.com and garnerhealth.com email domains exclusively. If you have been contacted by someone claiming to be a Garner recruiter or a hiring manager from a different domain about a potential job, please report it to law enforcement here and to candidateprotection@garnerhealth.com.

Equal Employment Opportunity:

Garner Health is proud to be an Equal Employment Opportunity employer and values diversity in the workplace. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.

Garner Health is committed to providing accommodations for qualified individuals with disabilities in our recruiting process. If you need assistance or an accommodation due to a disability, you may contact us at talent@garnerhealth.com.

Read the full description
Security Product Security Engineer at LaunchDarkly

Leads threat modeling and cloud security posture assessments while triaging security findings, partnering with engineering teams to embed security into the development lifecycle.

Senior Posted 3 days ago RemoteFirstJobs Product
What this role involves

About the Job:

LaunchDarkly’s Product Security team is hiring a Product Security Engineer II to strengthen how we secure the platform engineers build with every day. You’ll bring depth in security fundamentals and program design as a member of a small, high-leverage team with strong engineering instincts.

LaunchDarkly is critical infrastructure. Our security team keeps it safe for the global systems that depend on us. You’ll spend most of your time on threat modeling and cloud security posture, with rotating exposure to the rest of the ProdSec surface area. Your work will help developers move fast without sacrificing security, through automation, guidance, and the kind of partnership that makes the secure path the easy one.

You’ll report to the Director of Security and work closely with software engineers, product managers, and other security engineers. We expect you to bring a sharp point of view on where AI can take work off the team’s plate and make our coverage deeper.

Responsibilities:

  • Lead threat modeling engagements on the features and services where the risk warrants it.

  • Partner with the ProdSec lead to evolve the practice from on-request to repeatable, with clear criteria for when an engagement is worth running.

  • Own day-to-day triage of CNAPP findings end to end. Investigate, prioritize, route to service owners, and close the loop. Look for patterns that point to systemic fixes instead of one-off cleanup.

  • Contribute to SDLC tooling, SAST/SCA workflows, and bug bounty triage as the team’s work demands.

  • Partner with product engineering teams as a trusted reviewer. Catch issues early, explain the why, propose paths forward. Say no when needed, with reasons and alternatives.

  • Bring AI to the work. Use it to accelerate triage, summarize findings, draft threat models, scan code, and reduce toil. Help the team build durable patterns for safe and effective use, not one-off prompts.

  • Push the security floor up over time through documentation, office hours, small tooling improvements, and the kind of compounding work that prevents incidents rather than responds to them.

About You:

  • You’re proactive by default. You’d rather spot drift early and fix the cause than chase symptoms after an incident.

  • You believe security is a craft of habits and systems. Small consistent improvements beat heroic one-offs.

  • You invest in relationships with the engineering, product, and leadership teams you work with.

  • You know security work moves at the speed of trust.

  • You’re a good partner. You’re helpful and direct, you say no with reasons and alternatives, and you don’t mistake gatekeeping for rigor.

  • You’re security-first by background but engineering-curious by nature. You want to understand how the systems work, not just what’s wrong with them.

  • You treat AI as part of the toolkit. You’re skeptical where you should be, aggressive where it pays off, and you want to work somewhere that’s serious about both.

Qualifications:

  • 2 to 4 years of full-time experience in a security-focused role. AppSec, ProdSec, or cloud security preferred.

  • Comfortable reading and critiquing pull requests in a modern stack. You don’t need to ship production services, but you should follow the code, ask sharp questions, and write small tools when it helps.

  • Experience participating in or leading threat modeling exercises. Familiar with at least one structured approach (STRIDE, attack trees, or equivalent).

  • Working knowledge of cloud security posture. Exposure to a CNAPP is a strong plus.

  • Strong fundamentals: OWASP Top 10, authentication and authorization patterns, secrets management, common cloud misconfigurations.

  • Hands-on experience applying AI tooling to security or engineering work. You can point to specific examples where it changed how you operated.

Nice to Haves:

  • Experience with developer tools, SaaS platforms, or feature management

  • Bug bounty triage experience (HackerOne, Bugcrowd)

  • Familiarity with Go, Python, or TypeScript

  • Contributions to internal security tooling or open-source security projects

Pay:

Target pay ranges based on Geographic Zones* for Level 2:

  • Zone 1: San Francisco/Bay Area or NYC Metropolitan Area, Boston, Seattle - $136,500 - $187,660*
  • Zone 2: Irvine, LA, Monterey, Santa Barbara, Santa Rosa, Austin, Portland, Philadelphia, Chicago - $122,800 - $168,850**
  • Zone 3: All other US locations - $116,000 - $159,500**

LaunchDarkly operates from a place of high trust and transparency; we are happy to state the pay range for our open roles to best align with your needs. Exact compensation may vary based on skills, experience, and location.

*Within the United States, our geographic pay zones are defined by counties surrounding major metropolitan areas.

**Restricted Stock Units (RSUs), health, vision, and dental insurance, and mental health benefits in addition to salary.

About LaunchDarkly:

Modern software delivery was supposed to be the foundation for a thriving digital business but reality has proven otherwise. Slow, inefficient development cycles, costly outages, and fragmented customer experiences are preventing developers from building their best software. The LaunchDarkly platform helps developers innovate on new features faster while protecting them with a safety valve to instantly rewind when things go wrong. Developers can target product experiences to any customer segment and maximize the business impact of every feature. And by gradually rolling out new application components, they escape nightmare “big-bang” technology migrations.

The LaunchDarkly platform was built to guide engineers to the next frontier of DevOps by:

  • Improving the velocity and stability of software releases, without the fear of end customer outages
  • Delivering targeted experiences by easily personalizing features to customer cohorts
  • Maximizing the business impact of every feature through the ability to experiment and optimize
  • Coordinating the release and optimization of software to provide consistent experiences across mobile platforms and device types
  • Improving the effectiveness and productivity of engineering teams, by providing insights into engineering cadence and stability

At LaunchDarkly, we believe in the power of teams. We’re building a team that is humble, open, collaborative, respectful and kind. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, gender identity, sexual orientation, age, marital status, veteran status, or disability status. LD invites any applicant to review our written Affirmative Action Plan. To do so, contact People Ops at hr@launchdarkly.com.

Do you need a disability accommodation?

Fill out this accommodations request form and someone from our People Operations team will contact you for assistance.

Your safety matters to us. To protect yourself from potential scams, LaunchDarkly recruiters will only contact you from @LaunchDarkly.com email addresses or via LinkedIn from “Verified Recruiter” accounts.Be cautious of emails from other domains.  Legitimate LaunchDarkly recruiters will never ask for money, fees, or banking information before making a job offer. LaunchDarkly will never make a job offer without conducting a formal interview process. Our interview process does not involve asking detailed questions by email. If you are ever unsure about a communication that you receive, don’t click any links—visit Careers | LaunchDarkly  directly for confirmed job openings and links to apply.

Please notify us of any fraudulent representation by sending an email to careers@launchdarkly.com.

Read the full description
Security Expel: Managed SIEM Detection Engineer

Detection engineer who authors and tunes SIEM detection content, optimizes security tooling, and delivers professional services engagements to help customers close coverage gaps and reduce alert noise.

Mid Remote Posted 3 days ago We Work Remotely — Programming
What this role involves

Headquarters: Remote

Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself.

Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden.

And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next.

What Expel can do for you

  • Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers
  • Provide real runway for professional development as the function grows
  • Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments
  • Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling
  • Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success
  • Accelerate your career by letting you own meaningful outcomes end to end

What you can do for Expel

  • Deliver end-to-end professional services engagements, including detection strategy, MITRE ATT&CK assessment, SIEM optimization and integrations, SOAR playbook development, and custom log parsing
  • Develop and validate detection content that satisfies defined security use cases, at onboarding and as environments evolve, with strong coverage and clean fidelity
  • Optimize SIEM performance and cost by tuning detections for fidelity, reducing alert noise, and improving ingestion efficiency
  • Contribute to Expel's professional services proprietary detection library, continuously improving our detection strategy and capability
  • Translate detection logic between SIEM platforms and write custom parsers for standard and non-standard log sources, using AI-assisted tools where they help and validating the outputs
  • Partner with Detection Engineering and the SOC to hand off environments ready for ongoing co-managed operations, and work with SOC analysts to sharpen the fidelity and actionability of rules and alerts
  • Track the evolving threat landscape and turn it into new detection development
  • Help the function grow by contributing repeatable processes, templates, and tooling that raise the quality and consistency of what we deliver

What you should bring to Expel

  • Hands-on SIEM expertise across Splunk, Microsoft Sentinel, and/or CrowdStrike NG SIEM, including architecture, data ingestion, and detection rule development
  • 3+ years with detection and response tooling, particularly SIEM, SOAR, and EDR
  • 3+ years writing, deploying, and tuning custom detections from research or investigative work against common datasets (Windows Event Logs, auditd, CloudTrail, and similar)
  • SIEM migration experience translating detection logic between platforms and re-pointing log sources
  • Working knowledge of attacker tactics and techniques and the MITRE ATT&CK framework
  • Solid fundamentals across Windows, macOS, and Linux, networking basics (TCP/IP, OSI), and working knowledge of cloud IAM models and platforms
  • Basic proficiency with Python, Go, or similar, and comfort using Git/GitHub for version control of detection content, scripts, and templates
  • Curiosity, strong ownership, and the appetite for growth
  • A willingness to travel up to 20%

Bonus points for

  • One or more SIEM or vendor certifications (e.g., Splunk Core Certified Power User or Enterprise Security Certified Admin, Microsoft SC-200, CrowdStrike CCFA/CCFR)
  • Experience authoring platform-agnostic detections with Sigma and converting rules across SIEM backends
  • Familiarity with detection-as-code practices, including version-controlled rules, testing, and CI/CD for detection content
  • Industry security certifications such as GIAC (e.g., GCDA, GCIA), Security+, or similar
  • A bachelor's degree in Computer Science or Information Security

Additional notes

This role is remote within the United States.

The base salary range for this role is between $111,900 USD and $162,300 USD + bonus eligibility and equity. While the full salary band reflects our long-term compensation framework, we're primarily targeting candidates between $120,000 and $140,000 based on experience, skills, and market data.

We believe in paying transparently and equitably. Your salary will ultimately be based on factors such as your experience, skills, team equity, and market data. You'll also be eligible for unlimited PTO (which we model and encourage), work location flexibility, up to 24 weeks of parental leave, and really excellent health benefits.

We're only hiring those authorized to work in the United States. We do not currently sponsor immigration visas.

We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

We'll ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please let us know if you need accommodation of any kind.

#LI-Remote

Salary Range$111,900—$162,300 USD

To apply: https://weworkremotely.com/remote-jobs/expel-managed-siem-detection-engineer

Read the full description
Security Industrial Security Analyst / Facility Security Officer (FSO) at Red Cell Partners

Administers industrial security programs for a cleared defense contractor, ensuring NISPOM compliance and overseeing personnel security, operations security, and visitor control.

Mid Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

About Defcon AI

RESILIENCE IN THE FACE OF DISRUPTION. Defcon AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, Defcon AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

We are seeking an Industrial Security Analyst / Facility Security Officer (FSO) to support and help scale our security program as DEFCON AI’s classified work continues to grow. This individual will play a key role in maintaining compliance with government security requirements while helping build the processes, controls, and culture needed to support a rapidly growing defense technology company.

This is a hybrid position based in McLean, VA, with an expectation of three days per week in the office.

Position Overview

The Industrial Security Analyst / FSO is responsible for the day-to-day administration and oversight of DEFCON AI’s Industrial Security Program. This role ensures compliance with the National Industrial Security Program Operating Manual (NISPOM), customer requirements, and internal security policies while supporting employees, leadership, and external security partners.

The ideal candidate has experience supporting industrial security programs within a cleared contractor environment and is comfortable operating in a fast-paced organization where security processes continue to evolve and mature.

What You’ll Do

Industrial Security & Compliance

  • Support day-to-day industrial security operations across multiple disciplines, including Personnel Security (PERSEC), Operations Security (OPSEC), Contract Security, Security Education, Training and Awareness (SETA), Visitor Control, Investigations, and Document Control
  • Ensure compliance with NISPOM, ICD requirements, customer security requirements, and internal security policies
  • Maintain readiness for DCSA, customer, and internal security inspections and compliance reviews
  • Conduct self-inspections, identify areas for improvement, and implement corrective actions
  • Support the ongoing development and maturation of DEFCON AI’s industrial security program

Personnel & Program Security

  • Process and manage personnel security requirements, including clearance actions, visit requests, visit authorizations, and onboarding activities
  • Maintain personnel security records and related databases
  • Investigate security incidents and violations and ensure proper reporting and resolution in accordance with government and company requirements
  • Provide security guidance and support to employees, consultants, and approved visitors
  • Support contract security requirements, including DD Form 254 administration and subcontractor security management

Classified Information Protection

  • Maintain classified material accountability programs and secure storage requirements
  • Conduct inventories and maintain accountability of classified information and assets
  • Ensure proper marking, handling, transmission, storage, transportation, sanitization, reuse, and destruction of classified information and media
  • Support the protection of classified facilities, systems, and information in accordance with applicable regulations

Security Training & Program Development

  • Develop and administer Security Awareness, Annual Refresher, and OPSEC training programs
  • Create and maintain required security documentation, including SOPs, OPSEC plans, CONOPS, security procedures, and work instructions
  • Promote a culture of security awareness and compliance throughout the organization

Security Systems & Inspection Readiness

  • Maintain records and security actions within NISS, DISS, and other government security systems as required
  • Support DCSA, customer, and internal inspections and audits
  • Assist with corrective action implementation and continuous process improvement initiatives

Required Qualifications

  • Bachelor’s degree and 6+ years of industrial security or related experience; OR Master’s degree and 4+ years; OR Associate’s degree and 8+ years; OR High School diploma and 12+ years of relevant experience

  • Active U.S. Government Top Secret security clearance and ability to obtain and maintain SCI and SAP access

  • Strong knowledge of NISPOM (32 CFR Part 117), ICD security requirements, and industrial security compliance standards

  • Understanding and familiarity of DD-254 implementation requirements including issuing Subcontract DD-254 using NI2

  • Experience supporting personnel security, classified material control, and compliance programs within a cleared contractor environment

  • Experience utilizing government security systems such as NISS, DISS, or similar platforms

  • Strong organizational, communication, and problem-solving skills

  • Proficiency with Microsoft Office applications, including Word, Excel, PowerPoint, and Outlook

Preferred Qualifications

  • Experience serving as an FSO, AFSO, or Industrial Security Specialist within a cleared facility
  • CDSE FSO Program Management Certification for Processing and/or Non-Possessing Facilities
  • Experience supporting multiple classified programs and government customers
  • Experience preparing for and supporting DCSA or other government inspections
  • Knowledge of DD Form 254 requirements and subcontractor security administration
  • Experience supporting SCI and/or SAP programs
  • Experience building, improving, or scaling security processes within a growing organization
  • Strong customer service skills and the ability to build trusted relationships with internal and external stakeholders
  • Ability to work independently, manage competing priorities, and thrive in a fast-paced environment

Why DEFCON AI

At DEFCON AI, you’ll help build and scale security capabilities that directly support critical national security missions. You’ll work alongside a mission-driven team developing AI-powered solutions for some of the Department of War’s most complex operational challenges.

What We Offer:

  • A fully remote environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $120,000-$150,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits (may differ for each incubation):

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security Cybersecurity Compliance Analyst (Hybrid - Bay Area) at Xantrion

Analyzes client cybersecurity controls, develops compliance documentation, and assesses vendor security risks using frameworks like NIST CSF and CIS Controls.

Mid Hybrid Posted 4 days ago RemoteFirstJobs Product
What this role involves

If you’re looking to join a winning information technology team and receive outstanding benefits that support your family—while working for a company that takes a people-first approach to business—we invite you to explore our Cybersecurity Compliance Analyst position.

Location: San Francisco Bay Area

Hybrid: 2 days in office / 3 days remote per week

Primary Purpose and Function

Xantrion is seeking a Cybersecurity Compliance Analyst to support our Compliance Service offering and internal compliance programs. You will help assess client security controls, develop practical compliance documentation, evaluate vendor cybersecurity risk, and organize evidence that supports client requirements.

This role combines technical IT knowledge with strong analytical and writing skills to support our Client Strategy team across a diverse client base. The team leads client assessments, executive discussions, and remediation planning, while you provide supporting analysis and produce accurate, well-organized deliverables using established templates, standards, and guidance.

Travel: None required.

Roles and Responsibilities

Client Compliance and Documentation

  • Support current-state and target-state cybersecurity assessments using NIST Cybersecurity Framework (CSF), CIS Controls, and Xantrion standards.
  • Review IT configurations and supporting evidence against established templates and control requirements; document gaps and findings for virtual Chief Information Officer (vCIO) review.
  • Draft and maintain incident response plans (IRPs), business continuity plans (BCPs), written information security programs (WISPs), and supporting security policies and procedures.
  • Support business impact analyses, risk and gap assessments, cybersecurity risk registers, and risk-acceptance records.
  • Prepare control crosswalks, prioritized remediation roadmaps, executive risk summaries, and reporting scorecards under vCIO direction.
  • Conduct vendor cybersecurity risk reviews by evaluating questionnaires, audit reports, security documentation, and supporting evidence.
  • Maintain software and vendor inventories, data inventories, data flow documentation, and evidence indexes.
  • Maintain annual testing schedules and track documentation, review dates, and follow-up items.
  • Translate technical findings into clear descriptions of risk, supporting evidence, and recommended actions.
  • Improve reusable templates and assessment procedures that support consistent delivery across clients.

Internal Compliance Support

  • Coordinate evidence collection and auditor requests for Xantrion’s annual SOC 2 Type II examination and ISO/IEC 27001 audit activities.
  • Organize audit documentation, maintain request trackers, and follow up with internal control owners.
  • Review evidence for completeness and consistency and identify missing or outdated documentation.
  • Provide seasonal support during internal audit preparation and review periods.

Position Requirements

Required Qualifications

  • Three or more years of combined experience in IT operations, cybersecurity, IT audit, or compliance, including at least one year supporting control assessments, audit evidence collection, or security documentation.
  • Practical understanding of business IT environments, including identity and access management, endpoint security, email security, backups, networking, and cloud services.
  • Experience reviewing technical configurations or administrative reports against documented standards.
  • Working knowledge of NIST CSF and CIS Controls, with familiarity with NIST SP 800-53 and ISO/IEC 27001 control concepts.
  • Strong writing skills and the ability to produce clear, accurate policies, procedures, assessment findings, and client documentation.
  • Ability to distinguish documented policies from evidence that controls are implemented and operating.
  • Strong organization, attention to detail, and the ability to manage deliverables across multiple clients.
  • Ability to work independently on assigned tasks, identify questions or evidence gaps, and incorporate vCIO feedback.
  • Professional communication skills and sound judgment when handling confidential client information.

Preferred Qualifications

  • Experience supporting registered investment advisers (RIAs) or other financial services organizations.
  • Familiarity with cybersecurity and information protection requirements relevant to financial services, including SEC Regulation S-P, the FTC Safeguards Rule under GLBA, and applicable FINRA requirements.
  • Experience working for a managed service provider or supporting multiple client environments.
  • Hands-on familiarity with Microsoft 365, Entra ID, Intune, and common endpoint and security management tools.
  • Experience conducting vendor cybersecurity reviews and evaluating SOC 2 reports.
  • Experience supporting SOC 2 Type II examinations or ISO/IEC 27001 audits.
  • Familiarity with additional requirements and programs such as HIPAA, CJIS, NIST SP 800-171, CMMC, or FedRAMP.
  • Relevant certifications, such as Security+, CGRC, CISA, or an ISO/IEC 27001 credential.
  • A relevant degree or certification is welcome but is not required. Equivalent practical experience will be considered.

Performance Metrics

The Cybersecurity Compliance Analyst performance success will be based on the following criteria:

  • Client deliverables are accurate, clearly written, tailored to the client, and completed on schedule.
  • Assessment findings are supported by evidence and clearly describe gaps for vCIO review.
  • Risk registers, crosswalks, and supporting documentation remain organized and current.
  • Internal audit requests are tracked and supported with complete, accessible evidence.
  • Templates and processes improve the consistency and efficiency of Xantrion’s compliance services.

Physical Demands

  • Sitting or Standing for Long Periods: Ability to remain seated or standing at a workstation for extended durations, with regular breaks to prevent fatigue.
  • Viewing a Computer Monitor: Sustained ability to focus on a computer screen for tasks such as reading, typing, and data entry, with appropriate lighting and screen settings to reduce eye strain.
  • Digital Dexterity and Hand/Eye Coordination: Proficient use of hands and fingers to operate office equipment, including frequent alpha/numeric keyboarding, mouse usage, and handling other peripherals.
  • Oral Communications: Engaging in clear and effective verbal communication over the phone, video calls, and occasionally in person, requiring strong speech and active listening skills.
  • Use of Peripheral Devices: Handling and operating devices such as a mouse, headset, and other computer accessories with precision.
  • Basic Ergonomic Adjustments: Ability to adjust seating, monitor height, and other workstation elements to maintain comfort and reduce physical strain.
  • Environmental Awareness: Maintaining a workspace free from excessive noise and distractions to ensure focus and productivity.
  • Occasional Lifting and Moving: Ability to lift and move light objects, such as laptops, documents, and office supplies, as needed.
  • Periodic Travel to Xantrion’s Office: Willingness and ability to travel to Xantrion’s office or shared workspace as needed, which may involve air travel, driving, ride-sharing, or using public transportation.

Company Policy and Procedure Compliance

  • Follow and support company policies and procedures as well as all local, state, and federal laws.
  • Always maintain confidentiality of company and customer records and information.
  • Maintain a professional image, adhering to Xantrion’s dress code.
  • Must have an existing cell phone (running current Android or iOS).
  • If applicable Xantrion will provide a cell phone, internet connection, and home office equipment allowance.  See the Xantrion Handbook for details.

When Working Remote

  • Must have a reliable, high-speed internet connection that effectively supports work responsibilities, including video conferencing.
  • Must have a dedicated, secure, and private workspace. Unless arranged by Xantrion, shared work environments, such as coworking spaces, are unacceptable. Client information must always be kept private.
  • Must use Xantrion-provided PC and headset to execute job functions.

Benefits

  • Salary range $100-120K; depending on experience.
  • 100% of medical, dental, and vision for you and your family.
  • 401K with company match up to 4% of salary.
  • Certification reimbursement and annual training budget.
  • 17 Days PTO per year in addition to paid training days.
  • Bonuses for referring new clients or employees.

Equal Opportunity Employer

Xantrion is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, age, color, sex, religion, sexual orientation, national origin, disability, medical condition, genetic information, pregnancy, military or veteran status, or any other protected characteristic as outlined by federal, state, or local laws. All employment is decided on the basis of qualifications, merit, and business needs at the time.

AI Disclosure for Recruitment

We use AI to support our recruiting team, improve the candidate experiences, and allow our teams to spend more time on meaningful candidate interactions. Our use of AI is limited to administrative tasks such as organizing application information and taking or summarizing interview notes. AI does not screen, advance, or reject candidates, and it does not make hiring or any significant decisions. Applications and candidate qualifications are reviewed by our recruiting team, and all decisions about interviews, advancement, offers, and hiring are made by our recruiters and hiring managers.

Read the full description
Security Security Engineering Manager at Stedi

Lead a security engineering team managing AWS infrastructure, compliance, and security strategy while actively coding and shipping security projects.

Lead Posted 4 days ago RemoteFirstJobs Product
What this role involves

We’re building a new healthcare clearinghouse

Stedi is the only headless clearinghouse and RCM engine. Headless means every part of our product is accessible via API. Developers and AI agents build their own interface on top of it. By offering modern, AI-ready APIs alongside traditional real-time and batch EDI processes, we enable both healthcare technology businesses and established players to exchange mission-critical transactions. Our clearinghouse product and customer-first approach have set us apart. Stedi was ranked by Ramp as one of the fastest-growing SaaS vendors.

Stedi has lightning in a bottle: engineers and designers shipping products week in and week out; a lean business team supporting the company’s infrastructure; a passion for automation and eliminating toil; and $142 million in funding from top investors like Stripe, Addition, USV, Bloomberg Beta, First Round Capital, and more.

To see what we ship, watch the 2026 Stedi Keynote. To learn more about how we work, watch our founder Zack’s interview with First Round Capital.

What we’re looking for

Stedi is looking for a Security Engineering Manager to lead our scaling security function. This team is at the core of our infrastructure, managing multiple AWS Organizations and providing the foundational tools and services that enable our engineering teams to build reliable, secure, and compliant applications for healthcare technology companies that process transactions for millions of patients each month.

This is a true player-coach role where you’ll be managing a team of talented security engineers while still being in the weeds. You’ll own our security strategy and do the work: writing CDK, building playbooks, and pushing security projects through yourself. An ideal candidate is excited to have the leverage of setting the team’s direction while still staying deep in the technical details.

You’ll be accountable for security across AWS infrastructure, our software development lifecycle, endpoint security, and our compliance posture – and for making it seamless for every engineer at Stedi to build in a way that meets regulatory requirements without slowing down innovation.

How we build

  • We use AWS exclusively for our customer-facing backend infrastructure. We use tools like GitHub, Stripe, Vanta, and PagerDuty, but all of our application work happens on AWS.

  • We use serverless technologies almost exclusively to build our products: Lambda, API Gateway, SQS, SNS, DynamoDB, Aurora Serverless, and more. We don’t run a single server.

  • We use CDK (TypeScript) to define infrastructure as code.

What you’ll do

  • Lead and grow a high-performing security team by setting an ambitious pace with rigorous quality expectations, and by hiring as the function scales.

  • Oversee our compliance engineering posture, ensuring our processes and evidence meet SOC, HIPAA, and HITRUST requirements.

  • Manage daily engineering efforts, monitoring timelines and resources to ensure projects are executed efficiently and to a high standard.

  • Increase accountability across the team by setting clear performance expectations and regularly reviewing progress to ensure high standards are consistently met.

  • Continuously assess vulnerabilities, perform regular risk assessments, and prioritize remediation based on actual risk to the business and our customers.

  • Mentor engineers and make security a shared responsibility and focus across Stedi.

Who you are

  • 6+ years of experience in security or security adjacent roles, with at least 3+ years in a management role.

  • Experience with compliance frameworks such as SOC, HIPAA, and/or HITRUST and control design.

  • Hands-on experience in application security and endpoint security.

  • Exceptional written communication skills, with the ability to synthesize and clearly convey complex technical and risk information to both engineers and executives.

  • Proven experience managing and fostering collaboration in a remote-first environment, ensuring team alignment and cohesion.

  • A commitment to cultivating a high-performing team.

  • High bandwidth with the ability to pay thoughtful attention to many areas simultaneously.

  • Ability to context switch throughout the course of the day or week as priorities shift.

  • Philosophical alignment with the Stedi Standards.

We’ve been made aware of individuals impersonating the Stedi recruiting team. Please note:

  • All official communication about roles at Stedi will only come from an @ stedi.com email address, or from our official identification verification partner, Persona, @frompersona.com.

  • If you’re unsure whether a message is legitimate or have any concerns, feel free to contact us directly at careers@stedi.com .

We appreciate your attention to this and your interest in joining Stedi.

At Stedi, we’re looking for people who are deeply curious and aligned to our ways of working. You’re encouraged to apply even if your experience doesn’t perfectly match the job description.

Read the full description
Security Cybersecurity Engineer- Junior level

Junior cybersecurity engineer supporting DoD enterprise network modernization and infrastructure security.

Junior Posted 4 days ago Himalayas
What this role involves
Job Title: Cybersecurity Engineer- Junior levelJob Category: Information TechnologyTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee Type: RegularPercentage of Travel Required: Up to 50%Type of Travel: Continental US* * *The OpportunityCACI's Enterprise Network Services (ENS) Division supports the Department of Defense (DoD) in modernizing mission-critical communications and enterprise network infrastructures.
Read the full description