Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Penetration Tester Team Lead

Leads a penetration testing team conducting continuous security assessments using AI-powered tools and human oversight.

Lead Posted about 11 hours ago Himalayas
What this role involves
DescriptionTerra Security provides agentic AI-powered continuous penetration testing aligned to code changes and evolving attack surfaces, combining a swarm of trained AI agents with human supervision for safety and control.
Read the full description
Security Staff Security Engineer, Threat Intelligence

Designs and implements threat intelligence strategies to identify, analyze, and mitigate security threats across the platform infrastructure.

Senior Posted about 11 hours ago Himalayas
What this role involves
About Multi Media, LLCMulti Media, LLC is a global technology company operating a high-traffic live-streaming platform used by millions of people around the world.
Read the full description
Security IT Systems Auditor

Audits IT systems and controls for compliance, identifies security vulnerabilities, and ensures adherence to organizational and regulatory standards.

Mid Remote Posted about 12 hours ago Himalayas
What this role involves
OverviewAmyx is seeking to hire a IT Systems Auditor-II for our Defense Logistics Agency program remotely.
Read the full description
Security Head of Security at Snorkel AI

Lead and build Snorkel's security function end-to-end, including infrastructure, application, and compliance, while hiring and scaling the security team.

Lead Posted about 13 hours ago RemoteFirstJobs Product
What this role involves

About Snorkel

At Snorkel, we believe meaningful AI doesn’t start with the model, it starts with the data.

We’re on a mission to help enterprises transform expert knowledge into specialized AI at scale. The AI landscape has gone through incredible changes since 2015, when Snorkel started as a research project in the Stanford AI Lab, to the generative AI breakthroughs of today. But one thing has remained constant: the data you use to build AI is the key to achieving differentiation, high performance, and production-ready systems. We work with some of the world’s largest organizations to empower scientists, engineers, financial experts, product creators, journalists, and more to build custom AI with their data faster than ever before. Excited to help us redefine how AI is built? Apply to be the newest Snorkeler!

About Snorkel

Snorkel AI is the frontier AI data lab, helping teams build the data and environments behind high-performing frontier and agentic AI. We combine technology with research-driven AI data development to create datasets, benchmarks, evals, and custom solutions for real-world AI systems. Founded out of the Stanford AI Lab in 2019, Snorkel works with leading AI labs and enterprises to move from better data to better outcomes.

Excited to help us redefine how AI is built? Apply to be the newest Snorkeler!

About The Role

Snorkel is hiring a Head of Security to build and lead our security function end-to-end — infrastructure security, application security, and governance, risk & compliance (GRC). You’ll own the security function end-to-end — strategy, team, and execution — and operate as the primary security voice with customers, auditors, and the exec team. You’ll report to the CTO.

This is a builder’s role: you’ll take security from its current state to a mature, right-sized function as Snorkel scales, hiring and developing the team as needs grow.

Key Responsibilities

Security Leadership & Team Building

  • Define Snorkel’s overall security strategy, goals, and roadmap across infrastructure, application, and compliance domains
  • Build, hire, and lead a high-performing security organization — starting lean and scaling deliberately as the company and its risk surface grow
  • Establish the operating cadence for security (metrics, reporting, incident response, risk register) and represent security posture to the executive team and board

Infrastructure & Cloud Security

  • Own cloud security architecture and posture across AWS (and other cloud providers as adopted) — IAM, network segmentation, encryption, landing zone design
  • Direct detection & response capabilities, threat modeling, and vulnerability management programs
  • Set standards for secure infrastructure-as-code, CI/CD, and secrets management

Application Security

  • Embed security into the product development lifecycle — secure design reviews, threat modeling for new features, and AI/ML-specific risks (data protection, model/prompt security, training pipeline integrity)
  • Partner with Engineering and Product leadership to build security into the SDLC without blocking velocity
  • Own application security tooling and practices (SAST/DAST/SCA, pen testing, bug bounty)
  • Design identity, access, and activity-monitoring controls that correctly handle Snorkel’s non-employee marketplace workforce — external contractor (1099 or similar) experts accessing the platform. This population isn’t in scope for standard employee compliance obligations, but provisioning, deprovisioning, access boundaries, and monitoring still need to work correctly for them

Governance, Risk & Compliance (GRC)

  • Build and run Snorkel’s compliance program (e.g., SOC 2, ISO 27001, and customer-driven frameworks) — own audits end-to-end
  • Establish enterprise risk management practices: risk register, third-party/vendor risk, policy framework
  • Serve as the primary security point of contact for customer security reviews and questionnaires

Executive & Cross-Functional Partnership

  • Act as a trusted advisor to the CTO and executive team on security risk and investment tradeoffs
  • Partner cross-functionally with Legal, Sales, Operations, and Engineering to unblock enterprise deals and support customer trust requirements
  • Communicate security posture, incidents, and roadmap clearly to both technical and non-technical audiences

Who You Are

Experience & Leadership

  • 10+ years in technology security, including significant leadership experience; you’ve held director-level or above scope
  • Track record building and scaling a security function from a founding stage (team of ~1) through a mature org (10–30+), ideally at a high-growth technology company
  • Experience owning security budget, vendor selection, and board/exec-level reporting

Technical Depth

  • Deep expertise across infrastructure/cloud security (AWS, IAM, network security, encryption) and application security (SDLC integration, threat modeling, AppSec tooling)
  • Hands-on familiarity with modern security tooling: SIEM, EDR, CSPM, vulnerability management
  • Experience working with AI/ML-specific security risks (model security, data pipeline protection, prompt injection)

Governance & Compliance

  • Proven experience building and running compliance programs (SOC 2, ISO 27001, or equivalent) from the ground up
  • Comfortable as the face of security to customers during security reviews/audits, and to auditors during certification cycles

General

  • Bachelor’s degree in Computer Science, Information Technology, or related field; advanced degree a plus
  • Excellent written and verbal communication; able to flex between board-level summary and engineering-level depth

Why This Role

You’ll have meaningful ownership over the infrastructure that determines how quickly Snorkel can experiment with, evaluate, and productionize new AI systems. This isn’t a role focused on training a single model or maintaining traditional ML pipelines - you’ll build the platform that makes large-scale AI experimentation possible.

You’ll work on some of the hardest emerging infrastructure problems in AI: operating non-deterministic systems reliably, reproducing agent behavior across environments, evaluating long-running trajectories, scaling simulations and experiments, and turning rapidly evolving research workflows into robust production systems.

The architecture decisions made by this team will define how Snorkel builds and operates AI systems for years to come.

Snorkel is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel embraces diversity and provides equal employment opportunities to all employees and applicants for employment.

Actual compensation will be determined based on factors including skills, qualifications, experience, and geographic location.

Be Your Best at Snorkel

Joining Snorkel AI means becoming part of a company that has market proven solutions, robust funding, and is scaling rapidly—offering a unique combination of stability and the excitement of high growth. As a member of our team, you’ll have meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success. Whether you’re looking to deepen your technical expertise, explore leadership opportunities, or learn new skills across multiple functions, you’re fully supported in building your career in an environment designed for growth, learning, and shared success.

Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment. Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law. All employment is decided on the basis of qualifications, performance, merit, and business need.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Actual compensation will be determined based on factors including skills, qualifications, experience, and geographic location.

Salary range(s) for this role

$252,000—$370,000 USD

Be Your Best at Snorkel

Joining Snorkel AI means becoming part of a company that has market proven solutions, robust funding, and is scaling rapidly—offering a unique combination of stability and the excitement of high growth. As a member of our team, you’ll have meaningful opportunities to shape priorities and initiatives, influence key strategic decisions, and directly impact our ongoing success. Whether you’re looking to deepen your technical expertise, explore leadership opportunities, or learn new skills across multiple functions, you’re fully supported in building your career in an environment designed for growth, learning, and shared success.

Snorkel AI is proud to be an Equal Employment Opportunity employer and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. Snorkel AI embraces diversity and provides equal employment opportunities to all employees and applicants for employment. Snorkel AI prohibits discrimination and harassment of any type on the basis of race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local law. All employment is decided on the basis of qualifications, performance, merit, and business need.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.

Read the full description
Security Vigilant IT Security Manager – Portugal/Poland

Manages IT security operations and strategies for a globally distributed team across Portugal/Poland regions.

Mid Remote Posted about 13 hours ago Jobicy AI
What this role involves
This is not an offshoring back-office job for an international company. You will be a key player in our globally distributed team. We’re searching for a Vigilant IT Security Manager...
Read the full description
Security Cobalt Core Pentester

Conducts penetration testing and security assessments as part of a skilled pentester community.

Posted about 13 hours ago Jobicy AI
What this role involves
Who We Are The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the...
Read the full description
Security Cobalt Core Pentester – UK, Germany, Nordics

Conducts penetration testing and security assessments as part of a specialized pentester community across UK, Germany, and Nordic regions.

Senior Remote Posted about 13 hours ago Jobicy AI
What this role involves
Who We Are The Cobalt Core is a community of highly skilled security pentesters who are passionate about what they do and who are always striving to be at the...
Read the full description
Security GRC Manager

Manages governance, risk, and compliance programs to ensure organizational adherence to regulatory standards and security policies.

Mid Posted about 13 hours ago Jobicy AI
What this role involves
Mattermost is the leading collaborative workflow platform for defense, intelligence, security, and critical infrastructure. Trusted by the U.S. Department of War and Fortune 500s, our platform runs on-premises and in...
Read the full description
Security Senior Cloud Security Engineer

Designs, implements, and maintains cloud security infrastructure and protocols to protect institutional real estate platforms and data systems.

Senior Posted about 13 hours ago Himalayas
What this role involves
ABOUT GREYSTAR Greystar is a leading, fully integrated global real estate platform offering expertise in property management, investment management, development, and construction services in institutional-quality rental housing.
Read the full description
Security Public Facing Security Researcher

Conducts security research on blockchain protocols and smart contracts, communicating findings to external stakeholders and the Web3 community.

Posted about 20 hours ago Jobicy AI
What this role involves
About the Company Born from groundbreaking research at Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart contracts, and decentralized applications...
Read the full description
Security Security Analyst (Cyber Defense Analyst)

Monitors and defends against cyber threats, analyzes security incidents, and implements defensive measures to protect enterprise systems and infrastructure.

Posted 1 day ago Himalayas
What this role involves
AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.
Read the full description
Security Vulnerability Research Engineer

Researches and identifies software vulnerabilities in open source code and dependencies to help organizations manage security risks.

Mid Posted 1 day ago Jobicy AI
What this role involves
About Us Socket helps devs and security teams ship faster by cutting out security busywork. Thousands of orgs use Socket to safely find, audit, and manage open source code. Our...
Read the full description
Security SecOps Engineer I

Manages security operations, monitors infrastructure for threats, responds to incidents, and maintains security compliance systems.

Junior Posted 2 days ago Jobicy AI
What this role involves
LivePerson (NASDAQ:LPSN) is a Conversational AI company creating digital experiences that are Curiously Human. Everyperson is unique, and our technology makes it possible for companies, including leading brands like HSBC,...
Read the full description
Security Security Assistant at Assystem

Supports personnel security operations by processing vetting applications, monitoring clearances, liaising with external agencies, and maintaining security compliance controls.

Junior Hybrid Posted 2 days ago RemoteFirstJobs Product
What this role involves

Company Description

Today, Assystem is among the top three independent nuclear engineering firms worldwide. With over 60 years of experience in highly regulated sectors, the group supports public and industrial stakeholders in the execution of complex and strategic infrastructure projects, subject to high safety and security requirements.

Assystem mobilizes 8,000 experts in 13 countries and intervenes across the entire project lifecycle, in engineering, project management and digital solutions.

Job Description

🔐 Security Assistant

Reporting to the Personnel Security Manager, the Security Assistant will support the company’s Personnel Security activities, with a focus on security vetting, aftercare and security compliance.

📍 Location: Bolton

🏢 Working pattern: Hybrid – 2–3 days per week in the office

🔹 Key Responsibilities

🛡️ Process vetting applications for staff and contractors, providing guidance on all types of vetting.

🔄 Monitor security clearances and ensure renewals are completed promptly.

📋 Communicate changes to vetting policies and procedures.

🤝 Liaise with external agencies and verify internal and external clearances.

🔎 Conduct thorough checks and maintain effective Personnel Security controls.

💬 Act as the main contact for vetting and security enquiries, handling information sensitively and in line with data protection requirements.

🚨 Support security incident reporting, follow-up actions and lessons learned.

📁 Provide security support for key projects.

🎫 Manage site-specific security responsibilities, including issuing site passes.

📢 Support the wider Security Department with general security activities, communications and awareness campaigns.

Qualifications

🎓 Essential Experience & Qualifications

💻 Experienced user of Microsoft Office, particularly Word and Excel

⭐ Desirable Experience

🛡️ Previous experience in a similar security role

🎓 DISA Training

👤 Person Specification

⏰ Reliable and dependable

🚀 Self-motivated and proactive

🤝 Honest and trustworthy

📋 Well organised

🎯 Able to meet deadlines and prioritise workload

🔎 Methodical and accurate

🔐 Able to gain and maintain the appropriate security clearance

Additional Information

Due to the nature of work to be undertaken applicants will be required to meet certain residency criteria in order to attain a minimum level of UK security clearance if not already security cleared to a minimum SC level.

NOTICE TO CANDIDATES ON RECRUITMENT FRAUD - We are committed to safeguarding candidates from fraudulent activity associated with our recruitment process. Please note that we will never offer specialist CV writing services, request payment or ask for sensitive personal information during the recruitment process.

We are committed to equal treatment of candidates and promote, as well as foster all forms of diversity within our company. We believe that bringing together people with different backgrounds and perspectives is essential for creating innovative and impactful solutions. Skills, talent, and our people’s ability to dare are the only things that matter !. Bring your unique contributions and help us shape the future.

Read the full description
Security Senior Manager, Cyber Fusion Center at Avertium

Leads day-to-day security operations across a cyber fusion center, managing threat response, incident escalations, analyst teams, and continuous improvement initiatives.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers. Our unique “Assess, Design, Protect” methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. That’s why customers trust Avertium to deliver better security, improved compliance, and greater ROI.

The CFC Operations Manager is responsible for driving operational excellence across Avertium’s Cyber Fusion Center (CFC). This leader oversees security operations, threat-informed operations, threat response, escalations, service quality, workforce readiness, and continuous improvement initiatives to ensure customers receive exceptional protection and service outcomes.

The role serves as the primary operational leader for the Cyber Fusion Center, creating alignment across analysis, engineering, threat intelligence while ensuring that operational performance, customer experience, and strategic objectives are achieved. The CFC Operations Manager is a visible customer-facing leader who builds confidence with customers, helps navigate critical situations, and represents Avertium’s operational capabilities with professionalism and credibility.

Responsibilities:

  • Lead day-to-day Cyber Fusion Center operations across security analysis, incident response, escalations, threat-informed operations, and supporting engineering functions.

  • Drive excellence in operational performance, service delivery, customer outcomes, SLA attainment, quality standards, and team execution.

  • Establish and maintain accountability frameworks for case handling, escalation management, operational governance, and quality assurance.

  • Protect customers through Avertium’s Threat Informed Operations model by continuously improving detection effectiveness, analyst decision making, response quality, and operational readiness.

  • Drive continuous improvement initiatives that increase scalability, consistency, efficiency, and customer satisfaction.

  • Lead workforce readiness, technical training, leadership development, and operational enablement programs.

  • Take Cyber Fusion Operations to the next level by identifying opportunities to improve processes, technology utilization, automation, reporting, service quality, and organizational effectiveness.

  • Lead operational reviews, KPI reporting, workload management, backlog oversight, and leadership decision-making cadences.

  • Manage customer-impacting escalations, operational risks, and high-priority incidents while ensuring timely communication and successful resolution.

  • Partner closely with Sales, Service Delivery, Product, and Engineering teams to support customer retention, expansion opportunities, customer advocacy, and long-term customer success.

  • Drive operational maturity initiatives, establish best practices, and create organizational alignment across teams responsible for customer protection and service delivery.

  • Build organizational capability through workforce planning, leadership development, coaching, succession planning, and performance management.

  • Serve as Avertium’s operational executive with customers, providing leadership during business reviews, escalations, service discussions, operational planning sessions, and strategic customer engagements.

Qualifications:

  • 8+ years of experience in cybersecurity operations, managed security services, incident response, threat detection, or related disciplines.

  • 5+ years of experience leading security operations teams and managers.

  • Deep understanding of SOC, MDR, and XDR service delivery models.

  • Experience leading operational excellence, service quality, and customer protection initiatives.

  • Strong understanding of incident response, threat detection, threat hunting, and threat-informed defense concepts.

  • Experience managing customer-facing escalations and executive-level customer relationships.

  • Demonstrated success improving operational performance through process optimization, automation, metrics, and organizational leadership.

  • Strong analytical, organizational, and decision-making skills.

  • Ability to communicate effectively with technical teams, executives, and customers.

  • Experience working cross-functionally with Sales, Service Delivery, Product Management, Engineering, and Executive Leadership.

  • Proven capability to balance operational execution with strategic leadership.

  • Bachelor’s degree in Cybersecurity, Information Technology, Business, or equivalent experience preferred.

  • Industry certifications such as CISSP, GIAC, GCIH, GCIA, ITIL, PMP, or equivalent preferred.

  • #LI-CS1

In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.

Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Information Security Specialist at Halcyon

Senior Information Security Specialist manages third-party risk assessments, coordinates security testing and incident response, develops security policies, and ensures compliance with enterprise security frameworks.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

What we do:

Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.

Who we are:

Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.

As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we’ll work a plan to meet your needs.

The Role:

Halcyon is seeking a seasoned and collaborative Senior Information Security Specialist to support the advancement of our cybersecurity and GRC (Governance, Risk, and Compliance) programs. In this role, you will play a critical part in strengthening our enterprise-wide security posture by coordinating across teams, managing third-party risk, supporting compliance initiatives, and maturing internal security processes and documentation. Your responsibilities will span operational security, risk assessment, policy development, and incident response preparedness.

Responsibilities:

  • Perform and maintain third-party risk assessments and track vendor remediation activities.
  • Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests.
  • Develop, track, and follow up on corrective action plans for identified security gaps or audit findings.
  • Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations.
  • Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization.
  • Assist in developing, maintaining, and communicating information security policies, standards, and procedures.
  • Coordinate security incident response planning, disaster recovery testing, and business continuity exercises.
  • Monitor and support enforcement of technical and administrative security controls across the enterprise.
  • Stay current with evolving security and privacy regulations and frameworks (e.g., SOC 2, ISO 27001, TX-RAMP, FedRAMP).

Skills and Qualifications:

  • 5+ years of experience in information security, GRC, or IT risk management.
  • Strong understanding of cybersecurity concepts, controls, and risk frameworks.
  • Demonstrated experience with third-party risk management processes and tooling.
  • Proven ability to coordinate security testing and vulnerability management efforts.
  • Excellent communication, documentation, and cross-functional collaboration skills.
  • Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
  • Experience with regulatory compliance and audit support in fast-paced environments.
  • Hands-on participation in incident response or disaster recovery exercises is a plus.

Bonus Skills and Qualifications:

  • Experience with compliance platforms (e.g., Drata, Vanta).
  • Knowledge of security frameworks beyond SOC 2 and ISO 27001, such as NIST 800-53 or CIS Controls.
  • Familiarity with secure software development practices or DevSecOps principles.
  • Background in auditing or supporting third-party security assessments.
  • Experience with Microsoft 365 and/or Google Workspace security configuration.
  • Exposure to regulatory environments such as HIPAA, GDPR, or CCPA.
  • Certifications such as CISSP, CISA, CISM, Security+, or similar are a plus.

Benefits:

Halcyon offers the following benefits to eligible employees:

  • Comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents.

  • Short and long-term disability coverage, basic life and AD&D insurance plans.

  • Medical and dependent care FSA options.

  • 401k plan with a generous employer contribution.

  • Flexible PTO policy.

  • Parental leave.

  • Generous equity offerings.

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

The expected base salary range for this position is $120,000 - $160,000. Compensation varies based on a variety of factors which include (but are not limited to) role level, skills and competencies, qualifications, knowledge, location, and experience. In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offers, and equity awards.

In accordance with applicable state and federal laws, the range provided is Halcyon’s reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. Base pay is one part of the total package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and equity in the Company.

We understand it takes a diverse team of highly intelligent, passionate, curious, and creative people to develop the exceptional product we are building. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity employer.

Read the full description
Security Privacy & Security Program Manager at Nanit

Leads privacy and security compliance program, develops policies and controls, manages vendor risk assessments, and embeds privacy/security best practices across products and operations.

Mid Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Nanit:

Welcome to Nanit, the high-growth baby tech company that is changing the way parents experience parenthood through the world’s most advanced baby monitor and parenting products. In 2016, the Nanit baby monitor revolutionized the industry with computer-vision and machine-learning capabilities that helped parents understand their baby’s sleep patterns and allowed them to achieve better sleep quality. Now, the company has become the leader in the connected parenting space, with an incredible customer base of highly-engaged parents who look to Nanit as a source of information and expertise on their parenting journey.

About the Role:

We’re seeking a highly motivated and detail-oriented privacy and security professional to lead and evolve Nanit’s privacy and security compliance program. Reporting directly to the Chief Legal & Administrative Officer, you will build and operationalize the policies, controls, and processes that protect our customers’ data and keep Nanit ahead of an evolving regulatory landscape. You’ll partner closely with Legal, Product, Engineering, and business teams to embed privacy and security best practices into how Nanit builds and operates.

What You’ll Be Doing:

  • Develop, maintain and implement Nanit’s privacy and security policies, standards and processes to ensure compliance with applicable laws, regulations and industry frameworks (e.g., CCPA/CPRA and other U.S. state privacy laws, GDPR, COPPA, and relevant security frameworks such as SOC 2, ISO 27001).
  • Conduct and support regular privacy and security risk assessments, audits and gap analyses across systems, vendors, products and business processes, and drive remediation of identified gaps.
  • Collaborate with stakeholders across the organization to assess AI-related privacy, security and compliance risks.
  • Manage the third-party/vendor risk management program, including privacy and security due diligence, contract review support, ongoing monitoring, and enforcement of Nanit’s data protection requirements.
  • Partner with Product and Engineering teams to embed privacy-by-design and security-by-design principles into new features and products, including data mapping, privacy impact assessments (PIAs/DPIAs), and secure development practices.
  • Monitor emerging privacy and security regulatory developments and industry standards, and advise the Chief Legal & Administrative Officer and Chief Technology Officer and other business stakeholders on impact and required action.
  • Lead the company’s response to security and privacy inquiries from customers, partners and regulators, including questionnaires, audits and due diligence requests.
  • Support incident response efforts for privacy and security incidents, including investigation, documentation, remediation tracking and stakeholder communication.
  • Develop and deliver privacy and security metrics, dashboards and reporting for senior management and, as needed, the board of directors.
  • Design and deliver company-wide training and awareness programs on privacy, data security and compliance best practices.
  • Act as a thoughtful business partner who supports a fast-moving culture, flexible teamwork, and pragmatic, scalable solutions that support growth while protecting the company.

Who You Are:

  • Bachelor’s degree in a related field; relevant certifications (e.g., CIPP, CIPM, CISSP, CIPT, CISM) preferred.
  • 3-5+ years of experience in privacy program management, information security, or a related compliance function, ideally spanning both in-house and cross-functional environments.
  • Hands-on experience supporting or operating privacy and/or security programs aligned to frameworks such as SOC 2, ISO 27001⁄27701, NIST CSF, or similar.
  • Working knowledge of consumer privacy laws (e.g., CCPA/CPRA, GDPR, COPPA) and a willingness to build deeper subject-matter expertise over time.
  • Practical experience with, or exposure to, security incident response, vendor risk management, and identity/access management concepts across on-premise and cloud environments.
  • Able to rapidly interpret relevant laws, regulations and technical requirements, and translate them into practical, actionable and business-friendly guidance.
  • Excellent stakeholder management, communication and collaboration skills; able to explain complex privacy/security concepts to both technical and non-technical audiences.
  • Strong organizational skills, a problem-solving mindset, attention to detail, and the ability to exercise sound judgment in ambiguous environments.
  • Strong technical orientation with an understanding of modern cloud architectures and data flows, and the ability to leverage emerging technologies and AI-powered tools to strengthen privacy, security and compliance programs.

Why You’ll Love Working Here:

  • Hybrid in office schedule
  • Remote work from home month in August
  • Flexible PTO (we trust you to take the time you need)
  • Equity options so you can share in our growth
  • Paid parental leave for all new parents
  • Employee discounts on Nanit products
  • Work from home stipend
  • Monthly team events

EEO, Salary and Location:

This role can be offered as either hybrid or fully remote, with a preference for East Coast candidates.

Salary Range: $130,000 to $150,000 targeted salary plus equity, benefits and unlimited PTO. Nanit’s total compensation package includes access to healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, and basic life insurance. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We are proud to be an equal opportunity employer. We provide employment opportunities without regard to age, race, color, ancestry, national origin, religion, disability, sex, gender identity or expression, sexual orientation, veteran status, or any other protected class.

Read the full description
Security Senior Information Security Specialist at Halcyon

Manages third-party risk assessments, security testing coordination, compliance initiatives, and incident response planning to strengthen enterprise security posture.

Senior Remote Posted 3 days ago RemoteFirstJobs Product
What this role involves

What we do:

Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.

Who we are:

Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.

As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we’ll work a plan to meet your needs.

The Role:

Halcyon is seeking a seasoned and collaborative Senior Information Security Specialist to support the advancement of our cybersecurity and GRC (Governance, Risk, and Compliance) programs. In this role, you will play a critical part in strengthening our enterprise-wide security posture by coordinating across teams, managing third-party risk, supporting compliance initiatives, and maturing internal security processes and documentation. Your responsibilities will span operational security, risk assessment, policy development, and incident response preparedness.

Responsibilities:

  • Perform and maintain third-party risk assessments and track vendor remediation activities.
  • Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests.
  • Develop, track, and follow up on corrective action plans for identified security gaps or audit findings.
  • Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations.
  • Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization.
  • Assist in developing, maintaining, and communicating information security policies, standards, and procedures.
  • Coordinate security incident response planning, disaster recovery testing, and business continuity exercises.
  • Monitor and support enforcement of technical and administrative security controls across the enterprise.
  • Stay current with evolving security and privacy regulations and frameworks (e.g., SOC 2, ISO 27001, TX-RAMP, FedRAMP).

Skills and Qualifications:

  • 5+ years of experience in information security, GRC, or IT risk management.
  • Strong understanding of cybersecurity concepts, controls, and risk frameworks.
  • Demonstrated experience with third-party risk management processes and tooling.
  • Proven ability to coordinate security testing and vulnerability management efforts.
  • Excellent communication, documentation, and cross-functional collaboration skills.
  • Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
  • Experience with regulatory compliance and audit support in fast-paced environments.
  • Hands-on participation in incident response or disaster recovery exercises is a plus.

Bonus Skills and Qualifications:

  • Experience with compliance platforms (e.g., Drata, Vanta).
  • Knowledge of security frameworks beyond SOC 2 and ISO 27001, such as NIST 800-53 or CIS Controls.
  • Familiarity with secure software development practices or DevSecOps principles.
  • Background in auditing or supporting third-party security assessments.
  • Experience with Microsoft 365 and/or Google Workspace security configuration.
  • Exposure to regulatory environments such as HIPAA, GDPR, or CCPA.
  • Certifications such as CISSP, CISA, CISM, Security+, or similar are a plus.

Benefits:

Halcyon offers the following benefits to eligible employees:

  • Comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents.

  • Short and long-term disability coverage, basic life and AD&D insurance plans.

  • Medical and dependent care FSA options.

  • 401k plan with a generous employer contribution.

  • Flexible PTO policy.

  • Parental leave.

  • Generous equity offerings.

The Company reserves the right to modify or change these benefits programs at any time, with or without notice.

The expected base salary range for this position is $120,000 - $160,000. Compensation varies based on a variety of factors which include (but are not limited to) role level, skills and competencies, qualifications, knowledge, location, and experience. In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offers, and equity awards.

In accordance with applicable state and federal laws, the range provided is Halcyon’s reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. Base pay is one part of the total package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and equity in the Company.

We understand it takes a diverse team of highly intelligent, passionate, curious, and creative people to develop the exceptional product we are building. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity employer.

Read the full description
Security Privacy & Security Program Manager at Nanit

Leads privacy and security compliance program, develops policies and controls, manages risk assessments and vendor oversight to protect customer data and ensure regulatory compliance.

Lead Posted 3 days ago RemoteFirstJobs Product
What this role involves

About Nanit:

Welcome to Nanit, the high-growth baby tech company that is changing the way parents experience parenthood through the world’s most advanced baby monitor and parenting products. In 2016, the Nanit baby monitor revolutionized the industry with computer-vision and machine-learning capabilities that helped parents understand their baby’s sleep patterns and allowed them to achieve better sleep quality. Now, the company has become the leader in the connected parenting space, with an incredible customer base of highly-engaged parents who look to Nanit as a source of information and expertise on their parenting journey.

About the Role:

We’re seeking a highly motivated and detail-oriented privacy and security professional to lead and evolve Nanit’s privacy and security compliance program. Reporting directly to the Chief Legal & Administrative Officer, you will build and operationalize the policies, controls, and processes that protect our customers’ data and keep Nanit ahead of an evolving regulatory landscape. You’ll partner closely with Legal, Product, Engineering, and business teams to embed privacy and security best practices into how Nanit builds and operates.

What You’ll Be Doing:

  • Develop, maintain and implement Nanit’s privacy and security policies, standards and processes to ensure compliance with applicable laws, regulations and industry frameworks (e.g., CCPA/CPRA and other U.S. state privacy laws, GDPR, COPPA, and relevant security frameworks such as SOC 2, ISO 27001).
  • Conduct and support regular privacy and security risk assessments, audits and gap analyses across systems, vendors, products and business processes, and drive remediation of identified gaps.
  • Collaborate with stakeholders across the organization to assess AI-related privacy, security and compliance risks.
  • Manage the third-party/vendor risk management program, including privacy and security due diligence, contract review support, ongoing monitoring, and enforcement of Nanit’s data protection requirements.
  • Partner with Product and Engineering teams to embed privacy-by-design and security-by-design principles into new features and products, including data mapping, privacy impact assessments (PIAs/DPIAs), and secure development practices.
  • Monitor emerging privacy and security regulatory developments and industry standards, and advise the Chief Legal & Administrative Officer and Chief Technology Officer and other business stakeholders on impact and required action.
  • Lead the company’s response to security and privacy inquiries from customers, partners and regulators, including questionnaires, audits and due diligence requests.
  • Support incident response efforts for privacy and security incidents, including investigation, documentation, remediation tracking and stakeholder communication.
  • Develop and deliver privacy and security metrics, dashboards and reporting for senior management and, as needed, the board of directors.
  • Design and deliver company-wide training and awareness programs on privacy, data security and compliance best practices.
  • Act as a thoughtful business partner who supports a fast-moving culture, flexible teamwork, and pragmatic, scalable solutions that support growth while protecting the company.

Who You Are:

  • Bachelor’s degree in a related field; relevant certifications (e.g., CIPP, CIPM, CISSP, CIPT, CISM) preferred.
  • 3-5+ years of experience in privacy program management, information security, or a related compliance function, ideally spanning both in-house and cross-functional environments.
  • Hands-on experience supporting or operating privacy and/or security programs aligned to frameworks such as SOC 2, ISO 27001⁄27701, NIST CSF, or similar.
  • Working knowledge of consumer privacy laws (e.g., CCPA/CPRA, GDPR, COPPA) and a willingness to build deeper subject-matter expertise over time.
  • Practical experience with, or exposure to, security incident response, vendor risk management, and identity/access management concepts across on-premise and cloud environments.
  • Able to rapidly interpret relevant laws, regulations and technical requirements, and translate them into practical, actionable and business-friendly guidance.
  • Excellent stakeholder management, communication and collaboration skills; able to explain complex privacy/security concepts to both technical and non-technical audiences.
  • Strong organizational skills, a problem-solving mindset, attention to detail, and the ability to exercise sound judgment in ambiguous environments.
  • Strong technical orientation with an understanding of modern cloud architectures and data flows, and the ability to leverage emerging technologies and AI-powered tools to strengthen privacy, security and compliance programs.

Why You’ll Love Working Here:

  • Hybrid in office schedule
  • Remote work from home month in August
  • Flexible PTO (we trust you to take the time you need)
  • Equity options so you can share in our growth
  • Paid parental leave for all new parents
  • Employee discounts on Nanit products
  • Work from home stipend
  • Monthly team events

EEO, Salary and Location:

This role can be offered as either hybrid or fully remote, with a preference for East Coast candidates.

Salary Range: $130,000 to $150,000 targeted salary plus equity, benefits and unlimited PTO. Nanit’s total compensation package includes access to healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, and basic life insurance. Ultimately, in determining your pay, we’ll consider your location, experience, and other job-related factors.

We are proud to be an equal opportunity employer. We provide employment opportunities without regard to age, race, color, ancestry, national origin, religion, disability, sex, gender identity or expression, sexual orientation, veteran status, or any other protected class.

Read the full description
Security Security and Threat Operations Engineer at OnePay

Builds detections and monitoring workflows, analyzes threat patterns, and develops automation to protect fintech infrastructure and respond to security incidents.

Mid Posted 4 days ago RemoteFirstJobs Product
What this role involves

About OnePay

OnePay is the consumer fintech trusted by millions of Americans to make money better.

Our financial system is broken. High fees, low rates, and too few ways to actually grow your money. We’re fixing it. And we’re moving fast.

We’re an all-in-one financial services platform that brings together banking, high-yield savings, credit cards, point-of-sale lending, investing, and crypto in one place. We also partner with employers, HCM providers, gig platforms, and others to deliver embedded financial services to millions of employees and frontline workers.

We’re backed by Walmart, the world’s largest retailer, and Ribbit Capital, one of fintech’s most respected investors, giving us rare scale, distribution, and the opportunity to build something truly category-defining.

But what really sets OnePay apart is how we move. Our customers don’t have time to wait… and neither do we. This place moves fast, and we’re looking for people who are:

  • Ready to run

  • Hungry and driven by urgency

  • Exceptional at what they do, with low ego

  • Comfortable operating in motion

The Role

As a Security and Threat Operations Engineer at OnePay, your work will have a direct impact on protecting our fast-moving fintech environment. You will turn production signals into actionable detection, response, and hardening initiatives, partnering closely with Product Security, Platform Security, and Engineering teams. Your efforts will enable us to proactively identify, monitor, and stop compromised behaviors across OnePay’s products and infrastructure, ensuring the continued safety and trust of our business and customers. You will:

  • Build and tune detections, alerts, and monitoring workflows across cloud, application, identity, and edge environments.

  • Review traffic patterns across APIs, authentication flows, and WAF telemetry to identify malicious activity, abuse patterns, and anomalous behavior.

  • Use AI responsibly as a force multiplier for triage, analysis, and workflow automation, while helping define guardrails for AI-enabled systems.

  • Help operate OnePay’s vulnerability management program by triaging, prioritizing, and driving remediation for findings from Wiz, vulnerability scanning, and related workflows.

  • Develop Python-based tooling and automation to improve investigations, enrichment, response, and operational scale.

  • Partner with Product Security to translate threat models, security reviews, and product risks into production detections and response playbooks.

  • Investigate security events end to end, including triage, scoping, containment support, and follow-through on remediation.

  • Support vulnerability management and operational security practices in ways that align with PCI and SOC 2 expectations.

  • Participate in proactive threat hunting, detection improvement, and a 24x7 security incident response on-call rotation.

You Bring

  • 5+ years of experience in information security, threat detection, security operations, detection engineering, or incident response, ideally in a cloud-native or product-focused environment.

  • Strong experience investigating suspicious activity in web, API, authentication, and infrastructure telemetry, with the ability to distinguish attacker behavior from normal production noise.

  • Demonstrated ability to review traffic and event patterns for signs of malicious activity, fraud, account abuse, credential attacks, reconnaissance, and exploitation attempts.

  • Strong Python programming skills and the ability to write maintainable code for automation, enrichment, analysis, and security operations tooling.

  • Experience building and tuning detections in a SIEM or detection platform and working with observability and logging systems such as CloudWatch, Datadog, or similar platforms.

  • Experience operating or supporting a vulnerability management program, including triage, prioritization, remediation tracking, and stakeholder coordination.

  • Familiarity with cloud and application security findings from platforms such as Wiz, including CNAPP, runtime, code, and vulnerability scanning use cases.

  • Experience with at least one major cloud provider, preferably AWS.

  • Working knowledge of identity and access systems, modern authentication flows, and the security implications of internet-facing applications and APIs.

  • Strong understanding of threat modeling, risk prioritization, and practical security controls across applications, infrastructure, and cloud environments.

  • Practical experience using AI tools in security workflows, along with sound judgment about AI-specific risks such as prompt injection, data leakage, excessive tool access, and weak auditability.

  • Excellent analytical, communication, and cross-functional collaboration skills, especially in environments where security needs to move quickly with product and engineering teams.

  • Drive and proactivity - everyone here is a builder and executor

Tools We Use

We use Node and TypeScript on the server, leveraging the NestJS framework within a microservice-oriented architecture running on Kubernetes and AWS. On the client side, we build and ship product features for iOS, Android, and web platforms using React Native. We also embrace AI-assisted development, so engineers have their choice of Claude Code or Cursor to fit their workflow. While you don’t need experience with our exact stack, familiarity with modern software engineering practices will help you ramp up quickly.

What We Offer

  • Competitive base salary, stock options, and health benefits from Day 1

  • 401(k) plan with company match

  • Remote-friendly (US), flexible time off (FTO), and opportunities for growth

  • A high-growth, mission-driven, inclusive culture where your work has real impact

Standard Interview Process

Our process varies by role. Most candidates go through:

  • AI-assisted initial screen

  • Interview with Talent Partner

  • Technical or Hiring Manager Interview

  • Team Interview

  • Executive Interview

  • Offer!

Equal Employment Opportunity

To build technology and products that are used and loved by people and solve real-world problems, we need to build a team with many different perspectives and experiences. We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us at talent@onepay.com.

Read the full description