Latest remote Security Engineering jobs
Job results
Manages FedRAMP compliance for a cloud service provider by implementing security controls, supporting audits and remediation, maintaining SSP documentation, and coordinating authorization activities. Requires 5+ years of IT audit or compliance experience and hands-on FedRAMP ATO leadership.
Build and operate automated continuous security control monitoring, AWS evidence collection, and AI-enabled GRC workflows. The role requires at least five years of GRC experience, hands-on automation and AWS expertise, and the ability to defend automated controls and evidence to auditors.
Leads Fetch’s end-to-end information security program, including application security, vulnerability management, incident response, architecture, GRC, AI risk, and third-party risk. The role requires 7+ years of security experience, incident command capability, and people leadership.
Leads end-to-end response to sophisticated compromises, account takeovers, device threats, and related financial fraud for high-profile clients. Requires 5–8+ years of incident response or DFIR experience, broad device forensics expertise, strong client communication, and fraud-remediation experience.
Early-career cybersecurity professional implementing and monitoring security controls across Linux, Kubernetes, database, and AI infrastructure. Requires 1–3 years of hands-on technical experience, Linux and scripting skills, and interest in federal authorization and security engineering.
Investigates cyber incidents and insurance claims, assesses security controls, and advises customers and security leaders on prioritized risk improvements. The role requires 2–4 years of security experience, strong network threat knowledge, and familiarity with major security and compliance frameworks.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.
Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.
Lead Cloudflare's CCCS CSP ITS assessment and maintain CCCS requirements in the Common Control Framework. Requires 5+ years in security compliance, deep CCCS knowledge, and cross-functional collaboration with engineering, legal, and product teams.
Leads and scales the product security program for cloud-native, AI-powered SaaS products, combining strategy, team leadership, secure architecture, vulnerability management, and hands-on technical execution. Requires 8+ years in application or product security and significant people-management or technical-leadership experience.
Build and mature Virta’s application security program by securing GCP and Kubernetes environments, automating vulnerability and compliance processes, and embedding security across engineering. The role requires 5–7+ years of experience, strong cloud and application security expertise, and proficiency with Terraform and Go or Python.
Leads engineering for Wiz’s FedRAMP CR26 initiative, translating federal compliance requirements into scalable compliance-as-code, automation, and evidence-generation solutions. Requires 6+ years in security, DevOps, or systems engineering and deep experience with NIST, FedRAMP, and government cloud environments.
The Senior Security Engineer will secure Jasper’s AI systems, cloud infrastructure, software supply chain, and compliance workflows while building automation and security standards for a growing program. The role requires 8+ years of security engineering experience and hands-on expertise across AI, cloud, or GRC security.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Senior individual contributor responsible for improving cyber operations, resolving complex dual-use safety decisions, and building scalable reviewer, quality, vendor, and automation systems. Requires 8+ years of hands-on cybersecurity experience and strong operational judgment.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.
Own Socket’s compliance program as an engineered system, leading SOC 2 Type II, ISO 27001, risk and vendor programs, automated evidence pipelines, and customer assurance. The role requires deep audit ownership, ISO 27001 experience, automation skills, and the ability to build and lead a compliance function.
Own and scale Sardine’s security compliance and GRC function across major security, privacy, and resilience frameworks, including FedRAMP. The role leads audits, risk management, customer assurance, executive reporting, and a growing compliance team while partnering closely with technical and business stakeholders.
Own and scale Jasper’s governance, risk, and compliance program for AI-native SaaS products, leading audits, risk and vendor programs, policy management, and AI governance. The role requires 8+ years of GRC experience, expertise in major security frameworks, cloud and AI fluency, and strong cross-functional communication.
Build and operate Chainguard’s public-sector governance and trust capabilities, translating federal security requirements into automated controls, evidence systems, and risk-based decisions. The role requires hands-on federal, defense, or intelligence experience and strong technical fluency in cloud-native environments.
This role creates and tests red-team labs, ranges, and learning content that simulate real-world attacks and teach offensive-security concepts. It requires several years of penetration-testing or offensive-security experience, strong MITRE ATT&CK knowledge, and broad technical cybersecurity skills.
The IT Compliance Manager will lead SOX ITGC and ITAC design, testing, audit coordination, and remediation across complex cloud and SaaS environments. The role requires 7–10 years of IT audit or technology risk experience, strong control-framework expertise, and the ability to influence engineering and finance stakeholders.
The Incident Response Security Engineer will build detection, response, and security automation capabilities for large-scale cloud infrastructure. The role requires hands-on incident response and product security experience, cloud expertise, and strong development skills in Go or Python.
This role develops detection, incident-response processes, automation, and security tooling for large-scale cloud products and services. Candidates should have hands-on incident response and product security experience, cloud expertise, and strong development skills in Golang or Python.
The Security Engineer will own vulnerability management while hardening AWS environments, improving identity controls, and integrating application security into CI/CD. The role requires 2–4 years of security experience, hands-on AWS security knowledge, remediation workflow expertise, and strong cross-functional communication.
Leads corporate endpoint security architecture and automation, with emphasis on macOS, Terraform, GitOps, and scalable controls across device platforms. The role partners across security and IT, improves detection and auditability, and mentors engineers.
Executive leader responsible for setting strategy and leading Huntress’s global Threat Detection & Response organization across SOC, incident response, detection engineering, threat hunting, and adversary tactics. Requires 10+ years in security leadership and 5+ years managing managers and directors.
Develops and operates detection engineering systems across endpoint, cloud, container, and SaaS environments. The role requires at least six years in detection, incident response, or offensive security, strong attacker TTP knowledge, macOS expertise, and detection-as-code experience.
Security Engineer responsible for building detection and prevention controls, automating security operations, conducting threat hunts, and supporting incident response across a remote-first organization. Requires 3+ years of security or software development experience, cloud-native security expertise, and automation skills.
Build and lead application and product security practices across a 145-engineer organization, embedding secure defaults, CI guardrails, threat modeling, and vulnerability mitigation into product development. The role requires 6+ years of hands-on security experience, strong coding ability, and microservices expertise.
Build and lead product and infrastructure security for systems that move money, creating secure defaults, automation, access controls, and vulnerability management processes. The role requires strong software engineering, cloud infrastructure expertise, risk-based judgment, and the ability to operate independently as the senior security engineer.
Investigates and responds to security alerts, intrusions, malware, and suspicious cloud activity while providing remediation guidance. The role requires at least two years of SOC or DFIR experience and knowledge of endpoint telemetry, threat actor techniques, administration, networking, and web security.
Leads the Product Security team responsible for security posture management, governed security rollouts, and software supply chain security across GitLab’s software factory. The role combines technical security leadership, organizational adoption, audit readiness, team building, and external thought leadership.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
Build and lead Fireworks AI’s security operations function, owning detection engineering, incident response, threat intelligence, and SecOps workflows. The role requires 7+ years of security experience, hands-on EDR and cloud security expertise, strong Python automation skills, and the ability to grow an IC function into a team.
The Threat Intelligence Specialist investigates identity fraud and threat actors, conducts pivot-based OSINT, and collaborates with law enforcement agencies across EMEA. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.
Leads the maturation of an AWS cloud security program by designing and automating controls, integrating security into CI/CD workflows, and developing continuous compliance evidence. The role requires AWS security expertise and experience with infrastructure as code, automation, regulated SaaS, and cloud compliance initiatives.
Own the technical security function across cloud infrastructure, detection and response, application security, incident response, and automation. The role requires 8+ years of security engineering experience, deep AWS expertise, and the ability to lead security improvements across engineering teams.
Build and maintain scalable authorization infrastructure, libraries, frameworks and policy-driven solutions at Stripe. Requires 2+ years software development experience in security domain, strong collaboration skills, and preference for simple, scalable designs. Go/Java/Ruby and authorization experience preferred.
Owns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Owns security, privacy, compliance, and data-residency conversations for EMEA enterprise opportunities. The role designs secure cloud and BYOC architectures, leads threat modeling and readiness work, and enables field teams while engaging CISOs and security architects.
Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.
Leads security architecture, assessments, automation, and security-by-design practices for the Walrus team and broader ecosystem. The role requires 8+ years of security engineering experience, broad technical expertise, and Staff-level leadership.
Analyzes insureds’ cybersecurity posture, investigates incidents and claims, and recommends prioritized risk-reduction measures. The role requires 2–4 years of security experience, strong network and threat knowledge, familiarity with assessment tools and security frameworks, and a bachelor’s degree or equivalent experience.
The Senior Threat Engineer designs scalable threat-detection, decisioning, and response workflows, using investigation, automation, and operational data to improve accuracy and reduce manual review. The role requires significant cybersecurity operations experience and strong analytical, communication, and cross-functional collaboration skills.
Leads technical response to security events across cloud infrastructure, services, and applications, covering triage, containment, remediation, automation, and post-incident improvements. Requires 3+ years of cloud security incident response experience and expertise with SIEM, SOAR, and major cloud platforms.
Owns insider-risk investigations and advances data-loss prevention capabilities across people, devices, identities, and data movement. The role requires 4+ years of security investigations or DLP experience, strong case-management judgment, and familiarity with governance frameworks and SIEM tooling.
Leads customer incident response and digital forensics engagements, investigating breaches, containing threats, and recommending remediation. Requires 5+ years of experience, strong knowledge of forensic and EDR tools, AWS, security frameworks, and German and English communication.
Owns secure container image pipelines and automates vulnerability remediation for regulated, on-premises, and air-gapped deployments. The role requires deep container expertise, Kubernetes and Helm knowledge, Go or Python automation skills, and strong technical writing for auditors and customer security teams.