Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. đ
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
Manages cyber compliance programs and governance frameworks to ensure organizational adherence to security standards and regulatory requirements.
Conducts security assessments and compliance evaluations using NIST frameworks, develops security documentation (SSPs, SARs, POA&Ms), and verifies implementation of security controls for federal and commercial clients.
TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world.  We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.
TestPros is looking for Security Controls Assessors with experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks.
Start: Future projects late 2026 or 2027 (not an immediate job opening)
Type: Part-time consulting
Overview
Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.
Responsibilities and Duties:
You should be able to deliver on the following expertly and consistently:
Qualifications and Skills:
Rate: $50-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.
Equal Opportunity Employer
TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.
Offer Considerations
TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.
Federal Compliance
As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.
Design and implement CyberArk integrations with enterprise applications, identity platforms, and cloud services to strengthen security infrastructure.
Manages compliance frameworks (SOC 2, ISO 27001, etc.) and responds to security questionnaires from enterprise customers and regulated organizations.
Who we are
At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility â all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers â like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy â are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented â and we want to be the ones building it. For more information, visit www.domino.ai
What we are building
The Quality & Compliance team at Domino isâŚ
What your impact will be
In your first year, you will:
What we look for in this role
What we value
#LI-Remote
Conducts security assessments, triages vulnerabilities, and builds AI-powered automation tools to streamline security operations for Cloudflare's products.
About Us
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the worldâs largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazineâs Top Company Cultures list and ranked among the Worldâs Most Innovative Companies by Fast Company.
At Cloudflare, weâre not looking for people who wait for a polished roadmap; weâre looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a ânormalizedâ problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If youâre the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, youâll fit right in.
Available Locations: Austin, TX
As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflareâs core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.
On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.
Responsibilities
Bonus points
Equity
This role is eligible to participate in Cloudflareâs equity plan.
Benefits
Cloudflare offers a complete package of benefits and programs to support you and your family. Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun! The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.
Health & Welfare Benefits
Financial Benefits
Time Off
What Makes Cloudflare Special?
Weâre not just a highly ambitious, large-scale technology company. Weâre a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
Project Galileo: Since 2014, weâve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflareâs enterprise customersâat no cost.
Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, weâve provided services to more than 425 local government election websites in 33 states.
1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Hereâs the deal - we donât store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.
Sound like something youâd like to be a part of? Weâd love to hear from you!
Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Cloudflare is proud to be an equal opportunity employer. Â We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. Â All qualified applicants will be considered for employment without regard to their, or any other personâs, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Â Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. Â If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.
Embeds security into federal software delivery by conducting risk assessments, supporting ATO compliance efforts, and maintaining FISMA/FedRAMP security postures for VA systems.
Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.
Weâre looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.
What youâll be doing:
What youâll bring:
Experience supporting ATO and RMF processes including documentation and continuous monitoring
Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks
Experience securing cloud environments such as AWS GovCloud or Azure Government
Familiarity with vulnerability scanning tools such as Nessus or ACAS
Familiarity with SIEM platforms such as Splunk or ELK Stack
Some scripting or automation experience in Python, Bash, or PowerShell is a plus
CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus
Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team
Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams
Performs other related duties as assigned.
Requirements:
Education:
Benefits:
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:
Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or Š consistent with the contractorâs legal duty to furnish information. 41 CFR 60-1.35Š
Compensation:
At Oddball, itâs important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.
United States Wage Range: $110,000 â $145,000
Embed security into federal software delivery by integrating security requirements into development workflows, supporting ATO processes, and conducting risk assessments aligned with NIST and VA standards.
Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.
Weâre looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.
What youâll be doing:
What youâll bring:
Experience supporting ATO and RMF processes including documentation and continuous monitoring
Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks
Experience securing cloud environments such as AWS GovCloud or Azure Government
Familiarity with vulnerability scanning tools such as Nessus or ACAS
Familiarity with SIEM platforms such as Splunk or ELK Stack
Some scripting or automation experience in Python, Bash, or PowerShell is a plus
CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus
Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team
Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams
Performs other related duties as assigned.
Requirements:
Education:
Benefits:
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:
Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or Š consistent with the contractorâs legal duty to furnish information. 41 CFR 60-1.35Š
Compensation:
At Oddball, itâs important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.
United States Wage Range: $110,000 â $145,000
Security engineer designs and manages IAM infrastructure, Okta environments, and SaaS data governance while enforcing least privilege access controls.
Headquarters: Argentina
URL: http://solvd.com
Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes.
Following the acquisition of Tooploox, a premier AI and product development company, Solvd now offers true end-to-end deliveryâfrom strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively.
We are looking for a Mid-Tier Security Engineer specializing in Identity and Access Management (IAM) and Data Governance to join our Cyber Security team. In this role, you won't just be managing user tickets; you will be the engineer designing, implementing, and securing our identity perimeter and SaaS ecosystem.
You will own our Okta environment and drive data governance strategies across our core SaaS applications (e.g., Google Workspace, Microsoft 365, Slack, Salesforce, GitHub). Your goal is to ensure seamless user lifecycle management while aggressively enforcing the principle of least privilege and monitoring data exposure.
Identity & Access Management (IAM) Engineering
Okta Architecture & Admin: Act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies.
Lifecycle Automation: Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts to eliminate manual provisioning errors.
Federation & Protocols: Standardize and implement SSO integrations utilizing SAML 2.0, OIDC, and OAuth 2.0, ensuring secure token exchange and scoping.
Data Governance & SaaS Security
Least Privilege Enforcement: Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across all enterprise SaaS platforms.
Data Exposure Mitigation: Monitor and remediate unauthorized data sharing, public file exposure, and "shadow IT" API integrations within our SaaS ecosystem.
Access Reviews & Compliance: Lead quarterly user access reviews (UARs) and provide evidentiary support for security frameworks such as SOC 2 Type II, ISO 27001, and GDPR.
SaaS Security Posture Management (SSPM): Leverage SSPM tools or native security centers to continuously audit and harden SaaS application configurations.
Monitoring & Incident Response
Threat Detection: Analyze Okta System Logs and SaaS audit logs to detect anomalous behavior (e.g., impossible travel, credential stuffing, unauthorized data exfiltration).
SIEM Integration: Collaborate with the SOC team to ensure critical IAM and SaaS logs are correctly ingested into our SIEM for real-time alerting.
Experience: 3â5 years of dedicated experience in a Security Engineering, IAM, or Systems Engineering role with a heavy security focus.
Okta Mastery: Strong engineering-level knowledge of Okta (Okta Certified Administrator or Certified Consultant preferred).
Security Mindset: Proven track record of implementing data governance principles, data loss prevention (DLP), and zero-trust access models.
Core Protocols: Deep understanding of networking and identity protocols: TCP/IP, HTTP, SAML, OAuth, OIDC, and SCIM.
Scripting: Proficiency in Python, PowerShell, or Bash to interact with REST APIs for custom security tooling and automation.
Log Analysis: Experience querying logs (Splunk, ELK, SQL, or cloud-native SIEMs) to investigate identity-related security incidents.
When you join Solvd, you'llâŚ
Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.
Be part of a global team with equal opportunities for collaboration across continents and cultures.
Thrive in an inclusive environment that prioritizes continuous learning, innovation, and ethical AI standards.
Ready to make an impact?
If you're excited to build things that matter, champion responsible AI, and grow with some of the industryâs sharpest minds. Apply today and letâs innovate together.
Solvd is an equal opportunity employer.
To apply: https://weworkremotely.com/remote-jobs/solvd-security-engineer-ii-iam-saas-governance
Embeds security practices across product development, builds CI/CD security guardrails, designs secure architectures, and enables engineering teams to adopt secure-by-design practices.
⨠About Voyage PrivÊ
Born in France in 2006, Voyage PrivĂŠ has grown from an ambitious startup into becoming the Europeâs leading travel tech platform. Operating across 9 markets with tens of millions of users, weâre not just another e-commerce success story - weâre a tech powerhouse revolutionizing online travel.
What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.
Weâre now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.
đŻÂ Your Mission
As a Security Engineer, youâll play a key role in shaping the security and resilience of Voyage PrivĂŠâs technology platform.
Youâll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.
Youâll have the opportunity to build many security foundations from scratch â from internal tooling to CI/CD guardrails â and influence key architectural and technical decisions as we redesign our platform for scale.
Your key responsibilities will include:
đĄÂ What Weâre Looking For
Weâre looking for builders who move fast, think big, and care deeply about creating impact that lasts
Your profile:
⥠Our Recruitment Process
We believe in a fast, transparent, and human recruitment process.
Hereâs what you can expect:
đLocation : Aix en Provence or remote, France
đ Â Start Date : The sooner, the better
đ Contract Type : Full-time / Permanent
â¤ď¸ Youâll Love Joining Us
Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.
đ´ Prefer flexibility? Â We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.
đ¤Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.
đŞ Forget your gym subscription! Access our large on-site fitness center morning, noon, and night - or challenge your colleagues to a padel match on our private court.
đ Live to the rhythm of Voyage PrivĂŠâs signature mix of business and fun: Company Breaks, Carnival, Annual Convention, meetups and talks⌠plus free tickets to every Provence Rugby home match and live music nights at the Dalida Institute.
âď¸ And because travel is in our DNA : enjoy up to 20% off our exclusive getaway offers.
Join us and make your next career move a journey worth taking. đ
Develops and implements application security practices, conducts security assessments, and manages vulnerability remediation within the software development lifecycle.
Conducts application security reviews, implements secure SDLC initiatives, and supports security monitoring across the company's software development lifecycle.
About FareHarbor
At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.
With over 20,000 clients across 90+ countriesâweâre the largest in our industry and shaping the future of travel, together.
Our team is an âOhana of 700+ people around the world. Weâre passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.
FareHarbor Core Values:
Why FareHarbor?
Founding FareHarbor required unwavering passion. Turning a start-up into the worldâs leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, weâve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.
And since day one, weâve known that our real success lies in our peopleâthe Ohana.
With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to workâto believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.
From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we canât wait to see all thatâs to come.
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.
To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.
Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.
Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.
CENSUSâ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.
We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.
Key Responsibilities
Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.
Design and support the implementation of secure Azure cloud architectures.
Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.
Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.
Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.
Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).
Ensure that the implemented solutions align with the productâs security architecture, requirements and threat model.
Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.
Document and present product security risks in both technical and business contexts.
Minimum Qualifications
MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.
3 + years of experience in IT or Cybersecurity
2 + years of experience in cloud applications or cloud security related roles â preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.
Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).
Problem solving skills, analytical thinking and willingness to learn/grow.
Proficient in English.
Required Skills
Experience with:
Designing, implementing and auditing cloud platform security architecture and engaged technologies.
The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).
Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.
Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.
DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.
Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.
Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.
Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).
Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.
Nice-to-Have Skills
Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.
Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.
Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).
Familiarity with debugging, instrumenting and profiling software running on cloud platforms.
Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.
Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.
Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.
Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.
Experienced in working with international teams in other regions and time zones worldwide.
#LI-Remote
Application Security Engineer who conducts security reviews, implements secure SDLC practices, and supports security monitoring across the platform.
About FareHarbor
At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.
With over 20,000 clients across 90+ countriesâweâre the largest in our industry and shaping the future of travel, together.
Our team is an âOhana of 700+ people around the world. Weâre passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.
FareHarbor Core Values:
Why FareHarbor?
Founding FareHarbor required unwavering passion. Turning a start-up into the worldâs leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, weâve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.
And since day one, weâve known that our real success lies in our peopleâthe Ohana.
With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to workâto believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.
From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we canât wait to see all thatâs to come.
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.
To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.
Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.
Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.
CENSUSâ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.
We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.
Key Responsibilities
Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.
Design and support the implementation of secure Azure cloud architectures.
Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.
Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.
Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.
Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).
Ensure that the implemented solutions align with the productâs security architecture, requirements and threat model.
Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.
Document and present product security risks in both technical and business contexts.
Minimum Qualifications
MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.
3 + years of experience in IT or Cybersecurity
2 + years of experience in cloud applications or cloud security related roles â preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.
Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).
Problem solving skills, analytical thinking and willingness to learn/grow.
Proficient in English.
Required Skills
Experience with:
Designing, implementing and auditing cloud platform security architecture and engaged technologies.
The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).
Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.
Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.
DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.
Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.
Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.
Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).
Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.
Nice-to-Have Skills
Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.
Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.
Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).
Familiarity with debugging, instrumenting and profiling software running on cloud platforms.
Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.
Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.
Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.
Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.
Experienced in working with international teams in other regions and time zones worldwide.
#LI-Remote
Designs and implements security controls across compliance, cloud infrastructure, and IT systems to strengthen organizational security posture.
Designs, deploys, and maintains Microsoft Entra ID and Active Directory solutions for enterprise identity and access management across a global workforce.
About AbbVie
AbbVieâs mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on peopleâs lives across several key therapeutic areas including immunology, oncology, and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.
Join AbbVieâs Information Security & Risk Management (ISRM) team as an IAM Directory Services Engineer, where we empower our partners to succeed by delivering the knowledge, tools, and support needed to leverage data and technology securely and effectively. As part of our Identity & Access Management (IAM) team, you will play a pivotal role in shaping and executing our enterprise-wide IAM strategy.
The ideal candidate will have deep expertise in Microsoft Entra ID (formerly Azure AD), Active Directory, Certificate Services, supporting related authentication tools, and PowerShell scripting experience to design, implement, and manage Directory and Authentication solutions for our global workforce of 80,000 users.
Responsibilities:
Preferred:
âApplicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: â
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of  any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Companyâs sole and absolute discretion unless and until paid and may be modified at the Companyâs sole and absolute discretion, consistent with applicable law. â
AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community.⯠Equal Opportunity Employer/Veterans/Disabled.
US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html
US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:
https://www.abbvie.com/join-us/reasonable-accommodations.html
Designs, implements, and secures enterprise network infrastructure using Aruba and HPE technologies while managing firewalls, VPNs, and security controls.
Headquarters: Remote
URL: https://www.toptal.com/
We're looking for a Network Security Engineer to design, implement, and secure enterprise network infrastructure built on Aruba and HPE technologies. This is a hands-on role spanning both network engineering and security â you'll be responsible for building reliable network architecture while ensuring it's hardened against modern threats. If you can move fluidly between network design and security enforcement, this role is built for that.
Design, configure, and maintain enterprise network infrastructure using Aruba and HPE hardware and platforms
Implement and manage network security controls, including firewalls, VPNs, and access control policies
Monitor network traffic and security events to identify and respond to potential threats
Conduct network security assessments and vulnerability analysis
Design and enforce network segmentation, VLANs, and wireless security architecture
Troubleshoot network performance, connectivity, and security incidents
Maintain documentation for network architecture, configurations, and security policies
Collaborate with IT and security teams to align network infrastructure with broader security standards
Support compliance efforts related to network and IT security requirements
Stay current on emerging network security threats and Aruba/HPE platform capabilities
Strong hands-on experience with Aruba networking and security products
Experience with HP Enterprise (HPE) infrastructure and platforms
Solid background in IT security, including threat identification and mitigation
Strong network engineering skills, including routing, switching, and wireless architecture
Practical experience implementing network security best practices and controls
Ability to troubleshoot complex network and security issues independently
Strong documentation and communication skills for cross-functional collaboration
Relevant certifications (e.g., Aruba Certified, HPE certifications, Security+, CCNA/CCNP Security)
Experience with network access control (NAC) solutions
Familiarity with SIEM tools and security monitoring platforms
Experience supporting compliance frameworks (e.g., PCI-DSS, HIPAA, ISO 27001)
To apply: https://weworkremotely.com/remote-jobs/toptal-network-security-engineer-aruba-hpe-remote
Security Engineer who manages vulnerability lifecycle, conducts code reviews, monitors cloud infrastructure, and supports compliance audits across development teams.
Please note, this is a remote role based in one of the 23 States Ladder is currently hiring in - AZ, CA, CO, CT, FL, GA, IA, KS, MA, MD, MN, NC, NH, NJ, NV, NY, OH, OR, PA, TX, VA, WA, WI with the exception of the following cities: SF Bay Area, New York City, and Seattle.
We saw a problem within the life insurance industry: getting covered took too long, involved too much paperwork, and required too many in-person meetings with sales agents. Having lost his father at a young age, our CEO, Jamie, was determined to make it easier for people to get the coverage they needed to provide for their families. So, we got to work. We developed a method of real-time underwriting leveraging AI and, in doing so, reduced the months-long process of applying for life insurance to minutes. Our digital experience is quick (instant decisions!), loved by users (check out our Trustpilot or Google reviews) and prolific ($74 billion+ in coverage provided).
We are looking for a cybersecurity unicorn. A Security Engineer / Analyst who brings a rare blend of application security engineering and risk management maturity. In this role, you will be the driving force behind our vulnerability management lifecycle, balancing day-to-day security operations with development-facing vulnerability management and compliance.
Your primary mission will be embedded within our development lifecycles, taking ownership of application security vulnerability management for our engineering teams. Because our backend infrastructure runs heavily on Clojure, you wonât just be running automated scanners, you will actively look at code and leverage your functional programming experience to strengthen our shift-left security philosophy. Beyond AppSec, you will wear multiple hats: monitoring our cloud infrastructure and responding to alerts, conducting security risk reviews, supporting compliance audits, and ensuring our day-to-day workspace remains locked down.
The ideal candidate is well-rounded and has the ability to interact with all levels of management and external auditors, and operate effectively in a rapidly scaling, dynamic environment.We are looking for someone who is organized, self-motivated, has excellent problem-solving and writing skills, and enjoys working with people in a challenging and fast-paced environment. In this role, you will have the opportunity to drive innovation within the reporting function and help build out the accounting function.
Please note, Ladder is not currently sponsoring or transferring OPT or H1-B visaâs.
What Youâll Do
Experience Required
Technologies Used
Ladder is highly collaborative and fun. To support you in your role, we offer fantastic perks and benefits that reflect our mission of care and support, including:
Base pay for this role is determined by the location where the work will be performed and is aligned with the two compensation tiers, as indicated below. Base pay may vary depending on job-related knowledge, skills, experience, and business needs. In addition to the base pay range listed below, this role is also eligible for equity and benefits as shared above.
Tier 1 (San Francisco, New York)
$122,000 - $144,000
Tier 2 & Tier 3 (All other locations that Ladder hires)
$109,000 - $130,000
Ladder is building a diverse team of talented and enthusiastic people. We are an equal opportunity workplace. At Ladder, differences are celebrated and supported to benefit our people, product, and community. Let us know why youâre interested in this position and what unique contributions you can make to the Ladder team. We look forward to hearing from you.
Research shows that candidates from underrepresented backgrounds often donât apply for roles if they donât meet all the criteria â unlike majority candidates meeting significantly fewer requirements. We strongly encourage you to apply if youâre interested: weâd love to know how you can elevate our team with your unique experience!
By clicking âSubmit Application,â you acknowledge that you have read and agree to the Ladder Job Applicant Privacy Policy and Notice at Collection.
Identifies, assesses, and documents cybersecurity and AI-related risks while supporting risk management frameworks and AI governance controls across infrastructure and products.
Who We Are:
Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24â5 trading, and more.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. Weâre deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.
Our Team Members:
Weâre a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!
Weâre searching for passionate individuals eager to contribute to Alpacaâs rapid growth. If you align with our core valuesâStay Curious, Have Empathy, and Be Accountableâand are ready to make a significant impact, we encourage you to apply.
Your Role:
As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpacaâs security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.
You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.
This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. Youâll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.
Weâre looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the group up - then this role is for you. Prior GRC experience is a plus, but not required, weâre happy to invest in the right candidate.
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Recruitment Privacy Policy
Identifies, assesses, and documents cybersecurity and AI-related risks across infrastructure, products, and trading systems while establishing AI governance controls.
Who We Are:
Alpaca is a US-headquartered, global leader in agent-first brokerage infrastructure for stocks, ETFs, options, crypto, fixed income, 24â5 trading, and more.
Amongst our subsidiaries, Alpaca is a licensed financial services company, serving hundreds of financial institutions across 40 countries with our institutional-grade APIs. This includes broker-dealers, investment advisors, wealth managers, hedge funds, and crypto exchanges, totalling over 10 million brokerage accounts.
Our global team is a diverse group of experienced engineers, traders, and brokerage professionals who are working to achieve our mission of opening financial services to everyone on the planet. Weâre deeply committed to open-source contributions and fostering a vibrant community, continuously enhancing our award-winning, developer-friendly API and the robust infrastructure behind it.
Alpaca is proudly backed by $400 million in funding from top-tier global investors including Portage Ventures, Spark Capital, Tribe Capital, Social Leverage, Horizons Ventures, Opera Tech Ventures, SBI Group, Derayah Financial, Unbound, Peak XV, Elefund, and Y Combinator.
Our Team Members:
Weâre a dynamic team of 400+ globally distributed members who thrive working from our favorite places around the world, with teammates spanning the USA, Canada, Japan, Hungary, Nigeria, Brazil, the UK, and beyond!
Weâre searching for passionate individuals eager to contribute to Alpacaâs rapid growth. If you align with our core valuesâStay Curious, Have Empathy, and Be Accountableâand are ready to make a significant impact, we encourage you to apply.
Your Role:
As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpacaâs security, compliance, and AI risk posture across the organization. Working closely with the Cyber GRC Lead, you will support the identification, assessment, and documentation of cybersecurity and AI-related risks that impact our infrastructure, products, trading systems, and internal operations.
You will contribute to the design and execution of our risk management framework across traditional cyber domains (cloud security, infrastructure, application security, third-party risk, regulatory compliance) while also helping establish foundational governance controls for AI systems, models, and AI-enabled product features.
This role sits at the intersection of cybersecurity, emerging AI governance, regulatory expectations, and financial services risk management. Youâll collaborate closely with Engineering, Product, Legal, Compliance, and IT teams to ensure Alpaca remains resilient, compliant, and forward-looking in how we manage both Cyber and AI risk.
Weâre looking for someone curious, organized, and eager to grow. If you enjoy learning how technical systems work, translating risk into clear language, and building structured programs from the group up - then this role is for you. Prior GRC experience is a plus, but not required, weâre happy to invest in the right candidate.
Alpaca is proud to be an equal opportunity workplace dedicated to pursuing and hiring a diverse workforce.
Recruitment Privacy Policy