Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Staff Security Engineer, Customer Support and Integrity

Designs and implements security solutions to protect customer support systems and prevent fraud across DoorDash's marketplace platform.

Lead Posted about 5 hours ago Jobicy AI
What this role involves
About the TeamAt DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of consumers, merchants, and Dashers. Security is paramount to the success...
Read the full description
Security Compliance and Security Lead at ada CX

Leads Ada's security compliance program end-to-end, managing audits, vendor risk, vulnerability management, and serving as the internal/external authority on compliance and security posture.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure,  Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Compliance and Security Lead at ada CX

Own Ada's security compliance program end-to-end, managing audits, vendor risk, vulnerability management, and serving as internal/external compliance authority for enterprise customers.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure,  Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security Compliance and Security Lead at ada CX

Lead Ada's security compliance program end-to-end, managing audits, vendor risk, vulnerability management, and serving as internal/external compliance authority.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Us

Ada is an AI customer service company whose mission is to make customer service extraordinary for everyone. We’re driven to raise a new standard of quality customer service at scale, enabling enterprise companies to deliver experiences that people love–instant, proactive, personalized, and effortless.

Ada is an AI transformation platform and partner—combining strategic expertise with powerful AI agent management technology to accelerate businesses’ AI maturity to keep them ahead of the curve. With Ada, 83% of customer conversations—and counting—are effortlessly resolved through automation, giving teams more time back, companies more resources to focus on growth, and customers more life to focus on what matters most to them.

Established in 2016, Ada is a Canadian company that has powered over 5.5 billion interactions for leading brands like Square, YETI, IPSY, and Monday.com, saving millions of hours of human effort. Backed with over $250M in funding from tier-one investors including Accel, Bessemer, FirstMark, Spark, and Version One Ventures, Ada is a pioneer in the management and application of AI in customer service.

At Ada, we see growth as a reflection of each individual owner’s personal growth. That’s why our values are rooted in driving progress and continuous improvement. If you’re ambitious and eager to grow, Ada could be the place for you.

Learn more at www.ada.cx.

Security at Ada

Ada’s AI Agent resolves customer service conversations for enterprises — which means our customers trust us with their customers’ data and their brand. Security and compliance are how we earn and keep that trust. The Security team partners across engineering, legal, and go-to-market to make sure Ada’s controls are real, evidenced, and easy for customers to verify.

Our Role

As Compliance & Security Lead, you own Ada’s security compliance program end to end: audits, customer trust, vendor risk, vulnerability management, and the control framework that ties it all together. Our audit season runs August through November — your mandate is to automate evidence collection and process to the point where the team is audit-ready year-round, not scrambling seasonally. You are the internal source of truth on compliance status and the external face of Ada’s security posture: you will own security conversations with enterprise prospects and customers. As agentic AI regulation takes shape (starting with AIUC), you translate framework movement into concrete requirements for the platform team.

About You

  • Deep audit experience across SOC 1, SOC 2, PCI DSS, NIST frameworks, AICPA standards, and PII/privacy requirements. You have run audits end to end: evidence collection, control mapping, and auditor coordination.
  • Experience working directly with major audit firms such as Deloitte or EY; you know what a gold-standard audit engagement looks like from the inside.
  • You have inherited manual compliance programs and driven them toward automation tooling, process, and repeatability (Drata or similar compliance automation platforms).
  • Vulnerability management at scale: you have taken a large vulnerability backlog (thousands of findings) and driven it down through prioritization, ownership, and process.
  • Customer-facing confidence: you own the room in security posture conversations with enterprise prospects, and you are equally comfortable saying “let me get back to you” and then actually getting back to them.
  • An engineering background is preferred but not required; you must understand modern infrastructure,  Kubernetes, Terraform, CI/CD! well enough to hold your own with engineers and auditors alike.
  • Experienced owner of RFP security sections, customer security questionnaires, and trust centers (SafeBase or similar).
  • Strong writer: policies, control documentation, and data handling standards that people actually follow.
  • Proactive owner who builds programs that outlast you: process, documentation, and tooling over heroics.
  • You track regulatory and framework movement interest in agentic AI governance (AIUC and emerging frameworks) is a strong plus.

Outcomes

  • Own Ada’s security audits end to end: the upcoming AIUC audit, PCI, and SOC 2. Evidence collection, control mapping, and auditor coordination, run through Drata.
  • Automate evidence collection and control monitoring so that audit season (August–November) no longer requires heroics the team is audit-ready year-round.
  • Own the security and compliance sections of customer RFPs and security questionnaires. Maintain the SafeBase trust center so deals stop stalling on security review.
  • Own vulnerability management as a program: drive the backlog down with clear prioritization, ownership, and SLAs for critical findings.
  • Run vendor security and privacy reviews as a standing process with clear SLAs, not one-off scrambles.
  • Maintain the control framework and its documentation: policies, data handling, retention, and the evidence that controls actually operate.
  • Be the point of contact for customer security, privacy, and legal teams, and the internal source of truth on compliance status.
  • Track regulatory and framework movement relevant to agentic AI, starting with AIUC, and translate it into concrete internal requirements for the platform team.
  • Take ownership of the compliance work currently spread across the team, and make it sustainable.
  • First 90 days: take full ownership of the AIUC audit, produce a current-state gap assessment against our target frameworks, and turn the RFP security response into a repeatable process.

#LI-NS1

Benefits & Perks

At Ada, you’ll not only build extraordinary products but also thrive in an environment designed for your success. We prioritize your well-being, growth, and work-life balance. Here’s what we offer:

Benefits

  • Unlimited Vacation: Recharge when you need to.
  • Comprehensive Benefits: Extended health coverage, dental, vision, travel, and life insurance.
  • Wellness Account: Empowering you to invest in your overall well-being and lifestyle.
  • Employee & Family Assistance Plan: Resources to support you and your loved ones.

Perks

  • Flexible Work Schedule: Balance your work and personal life.
  • Remote-First, In-Person Friendly: Options to work from home or at our local hub.
  • Learning & Development Budget: Invest in your long-term growth goals and skills.
  • Work from Home Budget: Equipping you with the tools and support for a seamless remote work experience.
  • Access to Cutting-Edge AI Tools: Work with the best AI tech stack in the industry.
  • Hands-On with LLMs: Enhance your expertise in leveraging large language models.
  • A Thriving Industry: Join the forefront of innovation in AI, shaping the future of technology.

The above Benefits and Perks only apply to full-time, permanent employees.

As part of our recruitment process, we may use AI enabled tools to support certain aspects of hiring, such as interview note-taking. All hiring decisions are made by our team.

Thank you for your interest in joining us at Ada. Due to the high volume of applications, we will only contact candidates whose qualifications match closely to the requirements of the position. We appreciate the time you have invested in learning more about us.

Read the full description
Security DevSecOps Lead

Leads DevSecOps initiatives, integrating security practices into development and operations workflows for federal technology solutions.

Lead Posted 3 days ago Himalayas
What this role involves
About Concept Plus Concept Plus is a mission-focused technology solutions provider that transforms IT concepts into impactful solutions for federal agencies.
Read the full description
Security Field CISO at Sprinto

Field CISO builds market-facing security and compliance thought leadership, speaking engagements, and practitioner credibility for a compliance automation platform.

Lead Remote Posted 5 days ago RemoteFirstJobs Product
What this role involves

Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers.

Sprinto autonomously executes tasks needed to maintain trust across compliance, audits, risk management, vendor risk, privacy, and AI governance, enabling organizations to maintain a strong, reliable trust posture without draining operational bandwidth and resources on repetitive tasks.

Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we’ve raised $31.8M in funding to fuel our mission. Trusted by over 4,000 organizations across 75 countries, Sprinto helps organizations stay audit-ready, manage real-time risks, and scale fearlessly. With 300+ native integrations and AI-driven automation, Sprinto supports 200+ global security standards natively, including SOC 2, ISO 27001, GDPR, HIPAA, PCI-DSS, and more. Sprinto’s extensible architecture enables organizations to build and support an infinite number of custom integrations and frameworks.

Founded in 2020 by second-time founders Girish Redekar and Raghuveer Kancherla, Sprinto powers compliance for organizations like Whatfix, Encora, Anaconda, Whatnot, Ultrahuman, WeWork, Everstage, AI Foundation, HackerRank, and many more.

Life as a Sprinter -

Nobody succeeds at Sprinto by staying in their lane.

We are organized around problems, not job titles. Sprinters take ownership beyond their role, solve hard problems, and care deeply about the impact they create. If something can be improved, fixed, or built, we don’t wait for permission; we step in.

Being remote means we rely less on proximity and more on trust. We write things down, communicate openly, and move quickly because great teams aren’t built by sitting together, they’re built by pulling in the same direction.

We believe progress beats perfection, feedback is a gift, and doing the right thing matters, even when nobody is watching.

And while we move with urgency, we never move alone.

The mission -

This is Sprinto’s first dedicated Field CISO hire in the US. You are not walking into a built function. You are building the market-facing security and compliance voice from scratch - with full access to the founders, the GTM team, and the product roadmap.

This is a marketing and thought leadership role. You make every Sprinto channel more credible, more attended, and more influential - because the voice behind it is a practitioner, not a vendor. Every roundtable you run, every stage you speak from, every webinar you anchor - you own the prospect experience.

The scope runs from the first piece of content to the narratives & depth in all Sprinto content.

Where you’ll leave your mark?

  • Take the Autonomous Trust thesis to market - together - Sprinto has built the product and defined the category. You bring the platform to carry the thesis publicly - at events, in content, on stage, in every conversation that shapes how enterprise CISOs think about compliance. We build the narrative. You carry it into rooms we cannot reach alone.
  • Show up at the industry’s biggest stages as Sprinto’s practitioner voice - When we walk into RSA, ISACA, or a regional CISO summit, we walk in as participants in the conversation - not vendors looking for a slot. Your point of view on stage is how we earn that position. Together we make sure Sprinto is never just a name on a booth.
  • Build the rooms where CISOs talk openly - Webinars and roundtables only work when the right person anchors them. You bring the practitioner credibility that makes a CISO clear their calendar. We bring the platform and the agenda. Together we create conversations where CISOs share what they actually need - and the pipeline follows naturally.
  • Put a practitioner’s fingerprint on everything we publish - Our content team has the reach and the production. You have the voice that turns good content into content CISOs forward. We write together, you shape the thinking, and you push it through channels we do not own - your newsletter, your LinkedIn, your podcast. The audience you bring is the distribution we cannot manufacture from scratch.
  • Deepen the advisory board into a real community - We have built relationships with some of the most respected security leaders in the market. You deepen them - not as a coordinator, but as a peer. The more substantively you engage, the more the advisory board compounds into events, content, and deals none of us could run alone.
  • Walk into deals at different stages where needed - Early in a prospect conversation, you help them see what their compliance program could look like when the detection-remediation gap closes. You are not pitching - you are workshopping. You sit with their reality, map it against the Autonomous Trust model, and help them arrive at the vision themselves.

By the time a deal reaches the final room, you have already shaped how they think about the problem. When a CISO-level objection surfaces late, you walk back in as a peer and move it. Sales closes. The work you did upstream is why it lands.

The kind of builder we’re looking for -

  • 10+ years in security leadership; you have held a CISO, Deputy CISO, or senior advisory role and know what that job actually demands

  • Savvy with Compliance implementations for frameworks like SOC 2, ISO 27001, NIST CSF, HIPAA, and FedRAMP - you use these in conversation, not on slides

  • A track record of engaging enterprise CISOs as a peer, not as a vendor representative

  • Comfort with commercial accountability - you have owned numbers before or you are ready to

  • Simplify complex thesis and ideas into simpler and readable chunks.

  • You are not a vendor with a blog. You are a practitioner with a thesis. Bring original thinking on where the CISO’s office is headed - Autonomous Trust is part of that story, not the whole of it

  • Operate independently across multiple channels with rest of the team at your disposal to enable and unlock where needed.

We are open to structuring this as a full-time role or an advisory and consulting engagement - depending on what works best for everyone involved. If the fit is right, the arrangement is a conversation.

How we care for our Sprinters?

  • 100% remote

  • Health, dental, and vision insurance

  • Annual learning and development reimbursement

  • Home office setup stipend

  • Device reimbursement

Inclusion & Diversity -

At Sprinto, talent, curiosity, and ownership matter more than where you come from. We hire people for the problems they can solve, the impact they create, and the way they help others succeed—not their background, identity, or personal circumstances. We believe the best teams are built when people with different perspectives come together around a shared ambition to build something meaningful.

We’re proud to be an equal opportunity employer and are committed to creating a fair, inclusive, and accessible hiring process for everyone.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Director, Enterprise Risk Management & IT SOX Risk Advisory at HubSpot

Leads enterprise risk management and IT SOX compliance initiatives, manages risk professionals, and advises stakeholders on regulatory and technology risk across the organization.

Lead Posted 5 days ago RemoteFirstJobs Product
What this role involves

POS-7385

Director, Enterprise Risk Management & IT SOX Risk Advisory

Role Summary

Our mission at HubSpot is to help millions of organizations grow better.

HubSpot’s Risk and Internal Audit function is growing in scope and complexity. This Director role owns two of the function’s most strategic portfolios: Enterprise Risk Management and IT SOX Risk Advisory, including the expansion of SOX coverage and transformation initiatives.

In this role, you’ll lead Enterprise Risk Management (ERM) facilitation across the business, own the risk advisory relationship with Engineering and Finance stakeholders, and provide director-level oversight of IT SOX readiness as HubSpot scales. You’ll manage a team of risk professionals and serve as a key voice in executive reporting on technology risk.

What You’ll Do

  • Lead execution of the enterprise risk assessment, including surveys, interviews, and cross-functional facilitation.
  • Maintain the enterprise risk register and Key Risk Indicator (KRI) reporting cadence.
  • Synthesize risk inputs from risk owners into executive-ready reporting and recommendations.
  • Track mitigation plan progress and escalate stalled items to leadership.
  • Monitor emerging risks—including AI, regulatory, cybersecurity, and macroeconomic trends—and integrate them into the Enterprise Risk Assessment cycle.
  • Partner with the Head of Risk and Internal Audit to connect Enterprise Risk Assessment outputs to the annual audit plan.
  • Lead the SOX Risk Advisory portfolio, including pre-implementation reviews, control design guidance, and readiness assessments across key business initiatives.
  • Own director-level relationships with Finance and Engineering stakeholders across SOX-relevant system changes.
  • Lead implementations requiring IT audit scoping, control design, and readiness validation.
  • Apply IT SOX expertise to assess ITGC impacts of system migrations, API changes, and platform builds.
  • Partner with the IT Internal Audit team and external auditors on scoping and reliance where advisory work intersects.
  • Manage and develop a team of business and IT risk professionals.
  • Set quality standards for advisory deliverables and risk documentation.
  • Allocate team capacity across concurrent advisory workstreams.
  • Coach advisors on stakeholder management, technical writing, and control design thinking.

What You’ll Bring

Required Qualifications

  • 10+ years of experience across IT audit, risk, or advisory.
  • Bachelor’s degree or equivalent experience in Information Systems, Accounting Information Systems, Management Information Systems, Computer Science, or a related field.
  • Experience facilitating Enterprise Risk Management processes, including leading risk assessments, synthesizing outputs, and presenting findings to leadership.
  • Deep IT SOX experience, including ITGC design, operating effectiveness testing, deficiency assessment, and external auditor coordination.
  • Hands-on experience supporting SOX readiness for new systems, ERP implementations, or product features in a technology or SaaS environment.
  • Track record of managing or mentoring teams in a high-volume, multi-stakeholder environment.
  • Ability to translate technical IT and SOX observations into business risk language for non-technical executive audiences.
  • Strong control design expertise with the ability to advise Engineering and Finance stakeholders before implementation, not just after.
  • Comfortable managing ambiguity across concurrent, fast-moving workstreams.
  • Collaborative approach that builds credibility with Engineering, Finance, Legal, and Product stakeholders while maintaining appropriate independence.
  • Executive presence with the ability to deliver leadership updates on risk and advisory themes.

Nice-to-Have Qualifications

  • Certified Information Systems Auditor (CISA).
  • Certified Internal Auditor (CIA).
  • Additional professional certifications related to risk management, governance, or internal audit.

Where You’ll Work

  • Location: Anywhere within the United States
  • Work location preference: Remote (United States)
  • Posting: Internal and External
  • Travel: Minimal travel as needed.

Pay & Benefits

The cash compensation below includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are tailored to your skills, experience, qualifications, and other job-related reasons.

This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.

Benefits are also an important piece of your total compensation package. Explore the benefits and perks HubSpot offers to help employees grow better.

At HubSpot, fair compensation practices aren’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.

Annual Cash Compensation Range:

$209,400—$335,000 USD

We know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.

If you need accommodations or assistance due to a disability, please reach out to us using this form.

At HubSpot, we value both flexibility and connection. Whether you’re a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you’ll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.

If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Germany Applicants: (m/f/d) - link to HubSpot’s Career Diversity page here.

India Applicants: link to HubSpot India’s equal opportunity policy here.

About HubSpot

HubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot’s connected platform enables businesses to grow faster by focusing on what matters most: customers.

At HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.

We’re building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.

Recognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.

Explore more:

  • HubSpot Careers
  • Life at HubSpot on Instagram

HubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. We may use CLEAR ID Verification during the hiring process to confirm your identity and help maintain a safe, secure, and trusted experience for all candidates. Refer to HubSpot’s Recruiting Privacy Notice for details on data processing and your rights.

Read the full description
Security Director of Information Security Engineering

Leads information security engineering strategy, manages security infrastructure, and oversees a team protecting the organization's systems and data.

Lead Posted 5 days ago Himalayas
What this role involves
Southern New Hampshire University is a team of innovators.
Read the full description
Security Manager, Detection Engineering (Rapid Response Team) at SentinelOne

Lead a rapid response detection engineering team building security rules and detection coverage for emerging threats while managing team health and technical direction.

Lead Posted 6 days ago RemoteFirstJobs Product
What this role involves

Our Purpose

At SentinelOne, we are driven by a clear purpose: to give the advantage to those who secure our future. As AI reshapes how organizations build, operate, and innovate, the responsibility to protect them becomes more critical than ever. When you join SentinelOne, your work helps protect global enterprises, critical infrastructure, and the technologies shaping tomorrow. If you are motivated by meaningful challenges and want your impact to be real, measurable, and global, you will find purpose here.

About Us

SentinelOne is a company at the intersection of AI and security, pioneering a new operating model for cybersecurity. Our AI-native platform unifies protection across endpoint, cloud, identity, data, and AI systems to deliver autonomous detection and response with clarity and speed. By combining real-time analytics, intelligent automation, and a unified data foundation, we reduce noise, simplify complexity, and empower security teams to focus on what truly matters.

Our teams are builders, problem-solvers, and innovators committed to shaping the future of security. If you are excited to solve hard problems alongside talented, mission-driven people, we invite you to help us build a safer future for humanity.

What Are We Looking For?

We’re looking for people who are relentlessly curious and committed to continuous learning. AI is reshaping every function across our business, and we enable every team member, regardless of role or level, to build fluency in AI tools and concepts. Those who thrive here actively seek out new solutions, experiment thoughtfully, and apply what they learn to drive better, faster, smarter outcomes.

As a Manager, Detection Engineering, you will be tasked with leading our Rapid Response Team (RRT), responsible for fast, reliable detection coverage across emerging and actively exploited threats, critical vulnerabilities, supply chain attacks, and detection gaps surfaced through every avenue, from customer escalations to internal research and threat intelligence. This is a hands-on, technical leadership role where you will lead from the front, personally contributing to detection engineering work and setting the technical bar through your own rule development and code review, while owning the health, throughput, and direction of a specialized detection engineering team and protecting its focus in a fast-moving, reactive environment. You will partner closely with cross-functional teams and detection leadership to ensure RRT delivers consistent, timely detection coverage.

What Will You Do?

Primary responsibilities include:

  • Stay hands-on: personally develop, review, and drive detections to merge and release, especially during surges and for the hardest threats, setting the technical standard the team is measured against.
  • Lead, coach, and grow a team of five or more Senior to Staff detection engineers, owning hiring, development, performance, and day-to-day operations.
  • Own RRT’s operational cadence: threat triage and prioritization, SLO adherence, incident coordination, and workload balancing across concurrent threats.
  • Protect the team’s focus and capacity, shielding engineers from unscoped demand while ensuring high-priority work is met within target turnaround times.
  • Grow the cross-functional partnerships that extend RRT’s reach, representing the team in shared forums that drive accountability, surface emerging threats, and communicate impact to leadership.
  • Own and evolve the team’s roadmap, process documentation, service charter, and metrics, keeping the operation mature, measurable, and defensible.
  • Champion the detection automation and tooling that multiplies engineer output, aligning the automation roadmap with the team’s needs.
  • Drive proactive, transparent communication of RRT’s work, coverage, and outcomes to stakeholders, partner teams, and detection leadership.

What Skills and Knowledge Will You Bring?

Ideal candidates will have:

  • Proven experience leading or mentoring a detection engineering, threat detection, or SOC-adjacent team. Direct people management is ideal, but a strong technical lead ready to step fully into management will also be considered; this is a people leadership role for someone who wants to grow as a leader and is also deeply technical.
  • Current, hands-on detection engineering expertise: you can personally write, review, and tune detection rules today, not just oversee others, with a firm grasp of the end-to-end detection lifecycle and false negative and false positive feedback loops.
  • Strong, hands-on experience with GitHub and detection-as-code pipelines, including fluency in pull requests, code review, and merge-to-release workflows.
  • Hands-on experience developing detections across more than one engine (endpoint behavioral, signature-based such as YARA, and cloud or SIEM-based across multiple data sources), or the ability to ramp quickly across engines.
  • Experience developing detections at a product or vendor company, where coverage must span many customers and industries rather than a single organization.
  • Strong understanding of adversary behavior, MITRE ATT&CK, and real-world threats such as ransomware and in-the-wild campaigns.
  • A track record in fast-moving, SLO-driven environments with competing priorities, and the flexibility to lead emerging threat responses whenever they break, including outside a traditional schedule rather than waiting for the next business day.
  • Excellent communication and stakeholder management skills, able to represent a technical team to senior leadership and partner teams.
  • Experience establishing or maturing team processes, metrics, and documentation that leadership can rely on.
  • Familiarity with intake and triage workflows and detection automation tooling is a strong plus.

Why SentinelOne?

AI is redefining how the world operates and rewriting the rules of security in real time, and SentinelOne was built for this moment. From day one, we architected an AI-native platform designed to operate at machine speed, not as an add-on to legacy systems but as the foundation itself. If you want to build where innovation and impact move together, this is that place.

We invest in our Sentinels with comprehensive, competitive benefits designed to support you and your family:

Equity & Rewards

  • Restricted Stock Units (RSUs)
  • Employee Stock Purchase Plan (ESPP)

Time Off & Wellbeing

  • Flexible time off
  • Paid company holidays and paid sick time
  • Gender-neutral parental leave
  • Grandparent leave

Insurance & Financial Security

  • Medical, dental, and vision coverage
  • 401(k) retirement plan with company match
  • Life and disability insurance
  • Health and dependent care FSA
  • Voluntary benefits (hospital, accident, critical illness)
  • Employee Assistance Program (EAP)
  • ARAG pre-paid legal
  • Nationwide pet insurance
  • Cancer Care program
  • Global business travel medical insurance

Work Perks & Flexibility

  • Home office allowance
  • Mobile phone reimbursement

Wellness & Lifestyle

  • Wellness coach
  • Wellness/gym reimbursement
  • Fertility coverage
  • Adoption & surrogacy reimbursement

This U.S. role has a base pay range that will vary based on the location of the candidate. For some locations, a different pay range may apply.  If so, this range will be provided to you during the recruiting process. You can also reach out to the recruiter with any questions.

Base Salary Range

$164,000—$226,000 USD

SentinelOne is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.

SentinelOne participates in the E-Verify Program for all U.S. based roles.

Read the full description
Security Associate Director - Security Strategy & Analytics (Hybrid) at AbbVie

Lead security analytics and reporting teams while developing strategic security insights and data platforms to drive executive decision-making.

Lead Hybrid Posted 7 days ago RemoteFirstJobs Product
What this role involves

Company Description

About AbbVie

AbbVie’s mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people’s lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.

Job Description

The Associate Director, Information Security Strategy & Analytics is a senior people leader who partners with the ISRM leadership team and CISO to define and document the function’s strategic direction while leading the team responsible for security reporting and analytics. This role translates business priorities, risk insights, and hard security data into insights that drive strategic decisions, while owning the platforms and reporting capabilities that make those strategies measurable.

This role has three defining requirements: seasoned security practitioner depth, the ability to communicate strategy and data clearly and credibly to executive audiences, and a proven track record leading technical or analytical teams.

Responsibilities:

  • Lead the metrics and reporting team, including hiring, performance management, talent development, and defining the team’s portfolio, processes, and ways of working.
  • Partner with security domain leaders to develop impactful cross-functional reporting that gives leadership clear insight into security posture, operational health, and program value.
  • Collaborate with ISRM leadership and portfolio management to define ISRM’s strategic direction, including strategic priorities, target state, and multi-year roadmap, grounded in threat and risk insights, key metrics, business priorities, and delivery realities.
  • Own ISRM’s strategic narrative by developing and maintaining strategy documentation, executive communications, and leadership presentations that clearly articulate direction and value to stakeholders and partners.
  • Lead the process of translating ISRM’s strategic priorities into annual planning inputs, including LRP and capital planning submissions, ensuring investment rationale is clearly tied to execution roadmaps.
  • Own and mature ISRM’s data lake and reporting platforms, ensuring they deliver consistent, accurate, and timely data to support leadership decision-making.
  • Own and mature the semi-annual cyber business review process, delivering periodic cybersecurity performance reporting to business executives.
  • Track ISRM’s security maturity progress against frameworks such as NIST CSF, ensuring assessment results are reflected in strategic priorities, roadmap inputs, and remediation planning.

Qualifications

Required:

  • Bachelor’s Degree and 9 years of experience; OR Master’s Degree and 8 years of experience; OR PhD and 4 years of experience.
  • Respective years of relevant technical security roles (e.g., security architecture, security engineering, cyber defense).
  • 4+ years of leadership experience, including direct management of senior individual contributors in technical or analytical functions.
  • Demonstrated experience in information security strategy, security program leadership, or security transformation within a large, complex organization.
  • Strong experience developing and/or maintaining complex, cross-functional reporting targeted at executive leadership.
  • Exceptional executive communication and stakeholder engagement skills, with demonstrated ability to present and influence at the CISO and senior leadership level.
  • Exceptional written communication skills, with demonstrated experience producing both executive-level security reporting and strategic documents (roadmaps, decision papers, governance narratives) that inform and influence senior leadership.
  • Strong working knowledge of corporate security domains (e.g., security architecture, AppSec, security operations, GRC, TPRM) and the ability to build trust with the leaders of those programs.
  • Experience with security maturity frameworks such as NIST CSF, including translating findings into strategic priorities and remediation plans.

Preferred:

  • 6+ years in relevant technical security roles (e.g., security architecture, security engineering, cyber defense).
  • Experience in a security strategy, chief-of-staff, transformation, or metrics leadership role.
  • Hands-on experience with software development, data engineering, or security engineering.
  • Experience supporting globally distributed teams and stakeholders.
  • Experience developing multi-year security roadmaps, service strategies, operating model materials, or investment cases.

Additional Information

Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: ​

  • The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. ​
  • We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees.​
  • This job is eligible to participate in our long-term incentive programs.

Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company’s sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law.​

AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.  Equal Opportunity Employer/Veterans/Disabled.

US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html

US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:

https://www.abbvie.com/join-us/reasonable-accommodations.html

Read the full description
Security Red Team Lead (Offensive Cybersecurity)

Leads offensive cybersecurity red team operations, conducting penetration testing and vulnerability assessments for critical infrastructure projects.

Lead Remote Posted 8 days ago Himalayas
What this role involves
Role Title: Red Team Lead (Offensive Cybersecurity) Role Type: Contractor Location: Remote micro1 is engaging Red Team Leads (Offensive Cybersecurity) to contribute expertise to a customer's critical cybersecurity project.
Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at DEF CON

Lead DevSecOps engineer designs, builds, and operates secure CI/CD pipelines and infrastructure for government cloud environments while directing a team of platform and security engineers.

Lead Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;
  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contactrecruiting@defconai.com.

Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice .

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at Red Cell Partners

Leads DevSecOps platform design and deployment for government cloud environments, building CI/CD pipelines with embedded security controls and directing a small engineering team.

Lead Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

About Us

Red Cell Partners is an incubation firm building and investing in rapidly scalable technology-led companies that are bringing revolutionary advancements to market in three distinct practice areas: healthcare, cyber, and national security. United by a shared sense of duty and deep belief in the power of innovation, Red Cell is developing powerful tools and solutions to address our Nation’s most pressing problems.

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

Our Red Cell Partners Benefits:

For full-time roles

  • Career track opportunity with potential for rapid advancement with strong performance as the firm grows

  • 100% employer paid, comprehensive health care including medical, dental, and vision for you and your family.

  • Paid maternity and paternity for 14 weeks at employees’ normal pay.

  • Unlimited PTO, with management approval.

  • Opportunities for professional development and continued learning.

  • Optional 401K, FSA, and equity incentives available.

  • Mental health benefits are available through Tara Mind.

  • Cost effective GLP-1 solutions available through Crux.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Red Cell Partners, LLC (“Red Cell”) uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;

  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;

  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact talent @redcellpartners.com .

Red Cell requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Red Cell’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

Read the full description
Security DevSecOps Project Lead (Sr DevSecOps Engineer) at DEF CON

Leads DevSecOps platform architecture and delivery for government AI systems, building CI/CD pipelines with embedded security controls while directing a small engineering team.

Lead Remote Posted 10 days ago RemoteFirstJobs Product
What this role involves

ABOUT DEFCON AI

RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today’s dynamically changing world, DEFCON AI’s technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role

As DevSecOps Lead you will build and operate the delivery platform for a new AI-enabled program in a government cloud environment: the CI/CD pipeline, the infrastructure it runs on, the security controls built into it, and the artifacts that pipeline produces to support authorization. The work spans modern commercial DevOps practice and the realities of DoW deployment at IL-5, and requires sound decisions across government networks, cloud environments, and container strategy.

This is a lead role that stays hands on keyboard. You will make the architecture calls and you will also build them. Security is engineered in from the first week rather than added at the end: the pipeline enforces hardened baselines, runs the scans, and generates control evidence on every commit. As the program ramps you will direct a small group of platform, cloud, and cyber engineers, and you will be the engineering counterpart to the customer’s security and accreditation staff.

We need someone who can move immediately. An early deliverable puts a working platform into the government environment on a fixed date, and cloud accounts, network access, credentials, and approved service and image lists all arrive on the government’s timeline rather than ours. This is a fully remote role with occasional travel (up to 25%) to DEFCON AI HQ, customer sites, and vendor facilities as required.

Key Responsibilities

First Deliverable: Platform Into the Government Environment

  • Own the initial platform deployment into the government IL-5 environment, which is the program’s first contract deliverable and lands early.
  • Build and prove the pipeline and infrastructure as code on our own cloud first, using portable templates, so deployment into the government environment is a port rather than a build.
  • Deploy early and deliberately to surface the real network, security, and interface constraints while there is still time to design around them.
  • Track and drive the government-side prerequisites this deliverable depends on: account and boundary provisioning, network path, certificates, approved service list, approved base-image source, container registry access, scanning-tool approvals, and package-repository egress policy.

Platform and Pipeline Ownership

  • Own the CI/CD pipeline end to end: build, test, static and dynamic security analysis, software composition analysis, container and infrastructure-as-code scanning, SBOM generation, and gated promotion to production.
  • Establish and operate development, test, and production environments in AWS GovCloud at IL-5.
  • Build the platform so it is reusable across programs rather than rebuilt for each one.

Cloud and Infrastructure Architecture

  • Make the architecture calls for the delivery platform: account and boundary structure, network path, identity integration, container strategy, and hardened base images.
  • Work within an approved-service list and an approved base-image source, and drive those decisions to closure with the customer’s cloud and security staff.
  • Design for zero-downtime deployment and rehearsed rollback.
  • Build observability into the platform: metrics, logging, tracing, and alerting sufficient to find and fix problems in production before users report them.
  • Integrate CAC / PIV authentication and role-based access control.

Security Engineering and Authorization Support

  • Implement security controls from week one and produce the control evidence continuously from the pipeline.
  • Own the security artifact package: System Security Plan inputs, SBOMs, STIG and SCAP results, scan results, test coverage, audit trails, and pipeline gate definitions.
  • Serve as the engineering counterpart to the customer’s security and accreditation staff, and support the authorization decision on their timeline.
  • Drive an evidence-based authorization approach in which the assessment consumes pipeline output directly rather than requiring the same information reassembled by hand.
  • Absorb cyber and RMF responsibility for the program, with support from dedicated cyber staff as the team grows.

Release Management and Delivery Performance

  • Own the release cadence, from capability intake through production deployment, on both commercial and government timelines.
  • Establish and report delivery and reliability metrics: deployment frequency, lead time for change, change failure rate, and time to restore service.
  • Secure standing release approval or an automated-change exemption so continuous delivery is operationally real and not just technically true.
  • Integrate monitoring and alerting with the customer’s network and security operations centers.

Technical Leadership

  • Direct a small group of platform, cloud, and DevOps engineers as the program ramps, including partner and subcontractor staff.
  • Set the standards the rest of engineering builds against: environment parity, branching, release hygiene, secrets handling, and infrastructure as code.
  • Communicate clearly about status, risk, and tradeoffs, and escalate blockers early.

Required Qualifications

  • 8+ years of DevOps and DevSecOps engineering experience, including at least one production pipeline owned end to end at scale.
  • 3+ years working in DoW or federal cloud environments at IL-4 or IL-5, or an equivalent authorized environment. AWS GovCloud strongly preferred.
  • Hands-on keyboard w hile leading. You make the architecture calls and you build. This role is not a coordination or oversight function.
  • Cloud and infrastructure depth: containers and orchestration (Docker, Kubernetes or equivalent), infrastructure as code (Terraform, CloudFormation, or similar), and CI/CD tooling on at least one major cloud, including hardened base images and image promotion
  • Observability practice: you instrument what you build and use metrics and logs to drive improvements, rather than waiting on incident reports.
  • Security built into delivery: you treat security scanning, compliance validation, and evidence generation as normal pipeline stages.
  • Direct experience supporting an ATO, cATO, or equivalent authorization, including producing the artifacts an assessor actually accepts.
  • A track record of standing something up under a hard deadline, in an environment where access, approvals, and accounts were outside your control. You have shipped a first deployment into a government environment on a fixed date, and you know what has to be in motion beforehand to make that possible.
  • Ready on day one. The first deliverable comes early, so we need someone who arrives with a pipeline pattern they already know works and adapts it, rather than researching an approach from scratch.
  • An owner: you drive work to done, communicate status and risk plainly, and do not need to be managed through the details.
  • US Citizenship Required
  • Active US Secret clearance. The work is performed in a controlled government cloud environment and requires a favorable investigation and CAC eligibility from the start.
  • Willingness to travel up to 25% to customer sites, DEFCON AI HQ, and vendor facilities as required.

Preferred Qualifications

  • Active TS/SCI Clearance
  • Experience taking a program from an empty government cloud account to a deployed, authorized production system.
  • Hands-on experience managing a complete ATO or cATO pathway in production, and familiarity with continuous authorization models.
  • Working knowledge of DoW impact-level boundaries and the Cloud Computing SRG.
  • Iron Bank container certification experience, and familiarity with STIG and SCAP tooling, ACAS, OpenSCAP, and FIPS requirements.
  • Experience with AWS Bedrock or comparable managed inference services inside a government boundary, including model enablement and boundary constraints.
  • Familiarity with government secure-software platforms such as Second Front (Game Warden), Stormbreaker, or Black Pearl.
  • Experience integrating with enterprise ICAM or IdP services and DoD PKI.
  • Experience working alongside partner or subcontractor engineering pods.
  • Experience delivering into a high-volume federal case-processing or workflow environment handling sensitive personal data.

What Success Looks Like

  • A hardened pipeline deploying end to end within the first month, with security gates active and authorization evidence generating automatically, on our own infrastructure and ready to port.
  • The platform deployed into the government IL-5 environment on schedule, with network, security, and integration constraints surfaced and worked rather than discovered later.
  • Authorization evidence accepted by the customer’s assessor as it is produced, rather than assembled into a package at the end.
  • Zero critical or high vulnerabilities at delivery, with the pipeline enforcing that standard on every build.
  • Application teams never blocked on environment or deployment, because the platform was ready before they needed it.
  • A platform and a set of practices that get reused on the next program instead of rebuilt.

What We Offer:

  • A fully remote, results-based environment
  • Competitive salary, bonus, and equity package
  • 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
  • Unlimited PTO, with your manager’s approval
  • Flexible work environment where you manage your work day
  • 14 weeks of fully-paid parental leave

Salary Range: $175,000-$215,000. This represents the typical salary range for this position based on experience, skills, and other factors.

We’re an Equal Opportunity Employer: You’ll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure

By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

  • Managing and administering your application throughout the hiring process;
  • Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
  • Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contactrecruiting@defconai.com.

Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice .

Read the full description
Security Manager of IT Security

Manages IT security operations, policies, and infrastructure to protect company systems and data across e-commerce and learning platforms.

Lead Posted 22 days ago Jobicy AI
What this role involves
Company DescriptionAt Lakeshore, we create innovative learning materials and world-class guest experiences for teachers, parents and children. Since 1954, we’ve grown into a global community—with a thriving e-commerce business, multiple...
Read the full description
Security Engineering Manager – Ubuntu Security

Manages security engineering team responsible for Ubuntu's security infrastructure and protecting millions of systems worldwide.

Lead Posted 22 days ago Jobicy AI
What this role involves
As the most widely used Linux distribution, Ubuntu underpins the security of the entire internet. The role of Security Engineering Manager directly impacts the safety and security of millions of...
Read the full description
Security Engineering Manager – Security Standards and Hardening

Manages security engineering team focused on Linux hardening and security standards implementation across a widely-used platform.

Lead Posted 22 days ago Jobicy AI
What this role involves
As the most widely used Linux distribution, Ubuntu underpins the security of the entire internet. The role of Security Engineering Manager directly impacts the safety and security of millions of...
Read the full description
Security Engineering Manager – Ubuntu Security

Leads a security engineering team responsible for Ubuntu's Linux distribution security and internet infrastructure protection.

Lead Posted 22 days ago Jobicy AI
What this role involves
As the most widely used Linux distribution, Ubuntu underpins the security of the entire internet. The role of Security Engineering Manager directly impacts the safety and security of millions of...
Read the full description
Security Intelligence Production Lead at Cloudflare

Leads threat intelligence production and analysis operations for Cloudflare's security team, synthesizing vast network data into actionable threat intelligence to disrupt cyber threats.

Lead Onsite Posted 26 days ago RemoteFirstJobs Product
What this role involves

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.

At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.

Available Locations: Washington DC

About The Team

Cloudforce One is Cloudflare’s threat operations and research team, responsible for identifying and disrupting cyber threats ranging from sophisticated cybercriminal activity to nation-state sponsored advanced persistent threats (APTs). Cloudforce One works in close partnership with external organizations and internal Cloudflare teams, continuously developing operational tradecraft and expanding ever-growing sources of threat intelligence to enable expedited threat hunting and remediation. Members of Cloudforce One are at the helm of leveraging an incredibly vast and varied set of data points that only one of the world’s largest global networks can provide. The team is able to analyze these unique data points, at massive scale and efficiency, synthesizing findings into actionable threat intelligence to better protect our customers.

About The Role

Cloudflare is a global system on a mission to make the internet better, safer, and more powerful every day. To help fulfill this mission, we are seeking a seasoned Intelligence Production Lead to own the end-to-end intelligence production pipeline within our Cloudforce One Organization. As the Intelligence Production Lead, you will do everything a threat intelligence technical writer does — translating complex threat research into clear, concise, and actionable content — and you will also own the process, quality bar, and delivery cadence for the team’s finished intelligence. You will function as the managing editor and production manager for our threat intelligence output, setting the publishing calendar, running review and fact-check cycles, enforcing source-handling and classification standards, and serving as the final quality gate before customer-facing publication. You will collaborate closely with threat researchers, intelligence analysts, security teams, and external partners to prioritize what ships when, and you will mentor writers and analysts to raise the overall standard of the team’s tradecraft and written product. This position requires an independent, results-oriented leader with a passion for cybersecurity and threat intelligence analysis, and the editorial judgment to represent adversary tradecraft with precision.

Key responsibilities include:

  • Owning the end-to-end intelligence production pipeline — from research intake through drafting, editing, review, and publication — for intelligence reports, blog posts, briefing content, and technical documentation related to cyber threats and security research
  • Setting and managing the production schedule and release calendar, coordinating across researchers and analysts to prioritize which intelligence products ship and when
  • Serving as the final quality gate before customer-facing publication, running fact-check, technical-accuracy, and editorial review cycles and adjudicating changes to content
  • Writing, editing, and publishing high-quality intelligence content, and translating raw researcher notes and technical analysis into accessible, well-structured, impactful narratives
  • Developing, maintaining, and enforcing style guides, templates, classification markings, and source-handling and best-practice standards for threat intelligence briefings and publications
  • Reviewing and refining threat research content to ensure clarity, consistency, technical precision, and adherence to Cloudflare’s editorial standards
  • Mentoring and coaching technical writers and analysts on writing craft, intelligence tradecraft, and reporting standards
  • Collaborating with analysts and external partners to contextualize intelligence findings and communicate them effectively to customers and the public
  • Partnering with marketing, design, PR, and communications teams to amplify intelligence content, manage workloads and deadlines, and develop a cohesive security narrative

Examples of Desirable Skills, Knowledge, and Experience

  • Minimum 5 years of experience in a threat intelligence role within the Five Eyes (FVEY) community
  • 7+ years of combined experience across technical writing, cybersecurity research, intelligence analysis, or a related field
  • Minimum 3 years of technical copy editing experience
  • Demonstrated experience leading or managing a threat intelligence reporting, editorial, or production function — owning the production workflow, setting cadence, managing review cycles, and serving as a final quality gate before publication
  • Strong ability to craft — and to lead others in crafting — clear, concise, and engaging technical content for a variety of audiences, from technical defenders to executives
  • Experience collaborating with cybersecurity researchers and analysts, with a strong understanding of intrusion analysis, incident response, malware, adversary TTPs, and network defense strategies
  • Ability to use researcher notes and raw analysis to author articles about individual threats and campaigns, and to guide others in doing the same
  • Understanding of geopolitical issues and their impact on cyber threats
  • Familiarity with cyber threat intelligence frameworks such as the Cyber Kill Chain, MITRE ATT&CK, and the Diamond Model
  • Familiarity with specific threat actor groups, their operations, and TTPs
  • Experience with OSINT research and intelligence collection methodologies
  • Background in intelligence or criminal investigation reporting
  • Experience working in a threat intelligence or security operations center (SOC) environment
  • Demonstrated operational security (OPSEC) awareness and experience with the secure handling of sensitive information
  • Strong research, proofreading, and editing skills with a keen attention to detail
  • Experience communicating with internal teams to negotiate suggested changes to edited content and answer questions on style, grammar, and voice
  • Strong collaboration and leadership skills to work with analysts, marketing, design, and PR teams to coordinate workloads, deadlines, and responsibilities
  • Excellent project management and organizational skills, with the ability to handle multiple priorities and competing deadlines in a fast-paced environment
  • Proficiency in using Google Suite and content management systems (e.g., WordPress, Jira, or similar workflow tools)
  • Bachelor’s degree in English, Journalism, Cybersecurity, Computer Science, or a related field, or equivalent experience

Bonus Points

  • Experience using AI and large language model (LLM) tools to accelerate research, drafting, editing, and intelligence production workflows
  • Experience leading or managing a team of threat intelligence technical writers
  • Certifications such as CISSP, GIAC GCTI, or similar cybersecurity credentials
  • A portfolio of published, public-facing threat intelligence (bylined reports, advisories, or blog posts)
  • Experience presenting threat research at industry conferences (e.g., Black Hat, DEF CON, RSA, FIRST, or SANS CTI Summit)
  • Familiarity with threat intelligence platforms (TIPs) and structured threat-sharing standards

If you are passionate about cybersecurity, excel at communicating complex threats in a clear and actionable way, and are ready to own the standard and cadence of a world-class intelligence production function, we encourage you to apply and help Cloudflare continue its mission to make the internet safer and more resilient.

Please submit a resume and have 3-5 writing samples available upon request.

Compensation

Compensation may be adjusted depending on work location.

  • For Washington DC based hires: Estimated annual salary of $160,000 - $220,000

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family.  Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun!  The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.

Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.

1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs.  More details about this will be available at that stage of the interview process.

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.

Read the full description
Security IAM Architect

Designs and implements identity and access management systems to secure business infrastructure and user authentication across enterprise environments.

Lead Posted 26 days ago Himalayas
What this role involves
About UsTurnkey’s vision is to make the world a safer place to do business.
Read the full description