Latest remote Security Engineering jobs
Job results
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Build scalable security controls and services for MongoDB Atlas multi-cloud infrastructure, spanning runtime protection, cloud security posture, identity, observability, and secure infrastructure automation. The role requires 5+ years of software or SRE experience, strong Linux and networking fundamentals, cloud expertise, and Kubernetes security experience.
Leads AI security strategy, architecture, governance, and defensive controls across the organization while mentoring security engineers. Requires 9+ years of security engineering experience and deep knowledge of AI, AWS security services, identity protocols, and emerging AI attack frameworks.
Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.
Leads product security incident response for Snowflake’s AI and agentic products, developing detection, containment, remediation, and automation capabilities. Requires 5+ years in security, incident command experience, cloud expertise, and knowledge of AI/ML attack surfaces.
Maintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.
Build and operate OpenRouter’s third-party risk program, assessing model providers, subprocessors, and SaaS vendors across security, privacy, and AI regulatory requirements. The role requires 4+ years of vendor security risk experience, technical fluency, and strong independent judgment.
Leads infrastructure security strategy and execution across GitLab’s cloud platforms and self-managed offerings. The role requires deep cloud, Kubernetes, Infrastructure-as-Code, security tooling, threat modeling, and technical leadership experience.
Designs and governs enterprise identity architecture across workforce, customer, partner, non-human, and AI agent identities. The role requires 8+ years in IAM, deep CIAM and Auth0 experience, federation expertise, and the ability to implement secure, auditable controls in regulated environments.
Develop and maintain compliance frameworks, control libraries, automations, and product improvements that help customers meet security requirements efficiently. The role requires hands-on security program experience, knowledge of major compliance standards, and strong technical fluency with JSON and scripting.
Software engineer responsible for identifying, triaging, and coordinating remediation of vulnerabilities across company systems. The role requires at least two years of industry software engineering experience in security and strong collaboration and problem-solving skills.
Leads the design, automation, and operation of enterprise endpoint security across multi-cloud and SaaS environments. The role requires 5+ years of information security experience, software development skills, and expertise across Windows, macOS, and Linux endpoint platforms.
Build and operate product security systems across applications, APIs, infrastructure, and CI/CD, including AI-assisted code review and automated security controls. The role requires 5+ years in product or application security or software engineering, strong Python skills, and hands-on vulnerability assessment experience.
Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.
Builds and evolves AI-assisted threat detection, automation, and analytics at cloud scale. Requires 8+ years of security engineering experience, strong Python or Go skills, production software practices, cloud security expertise, and experience with large-scale telemetry and agentic workflows.
The Vulnerability Engineer will assess, reproduce, prioritize, and validate vulnerabilities across a SaaS environment, while maintaining scanning automation and partnering with Engineering on remediation. The role requires vulnerability-management experience, scripting skills, exploit validation, and knowledge of cloud, containers, and application security.
Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.
The first security leader will own Tremendous' end-to-end security posture, including product security, incident response, identity, vendor risk, and AI security. This player-coach role requires hands-on experience scaling security programs, strong engineering judgment, and the ability to build a future team.
Leads product security incident response, coordinated vulnerability disclosure, PSIRT maturity, and customer-facing communications. The role requires 5+ years of security-focused IT or engineering experience, strong cross-functional judgment, coding ability, and experience building incident response tooling, including AI-powered workflows.
The Senior Cloud Security Engineer will design secure, resilient AWS infrastructure, automate security controls, and partner with engineering teams on cloud risk, compliance, and remote-access challenges. Candidates should have at least five years of relevant experience and familiarity with IaC, security frameworks, and privacy regulations.
Researches and tracks sophisticated state-backed and financially motivated threats targeting cloud environments, using telemetry, infrastructure analysis, malware analysis, and threat intelligence techniques. Requires at least five years of security or threat research experience.
Strengthen MongoDB’s server products through product security assessments, threat modeling, vulnerability research, and security controls. The role requires application or product security experience, C++ expertise with low-level codebases, scripting ability, and strong cross-team communication.
Conducts penetration testing, red-team assessments, vulnerability research, and AI/LLM security testing across ClickHouse products, infrastructure, and cloud environments. Requires 7+ years of offensive and product-security experience plus hands-on expertise with cloud platforms, Kubernetes, Cilium, and security automation.
Senior individual contributor leading security architecture and automated controls across AWS, on-premises, and hybrid infrastructure. The role requires deep AWS security expertise, infrastructure-as-code and CI/CD experience, scripting ability, and cross-functional technical leadership.
Staff Application Security Engineer owning the AppSec/DevSecOps program at Censys. Design and implement secure SDLC practices, DevSecOps tooling in Kubernetes/GCP (incl. AI/ML pipelines), CI/CD security integrations, compliance controls, and provide technical leadership/mentorship to engineering teams. Requires 10+ years security engineering experience.
Lead Virta Health's Governance, Risk, and Compliance (GRC) function in an AI-first healthcare environment. Manage compliance automation with Vanta, support commercial RFPs/questionnaires, maintain HITRUST/HIPAA/SOC 2 certifications, conduct risk assessments, and drive security awareness while optimizing employee compliance workflows.
Security Engineer responsible for designing and managing corporate security controls across identity, endpoint, network, and vendor risk. Requires 5+ years in information security, deep IAM/EDR/MDM expertise, and experience with compliance frameworks to reduce risk and build security culture.
Build and mature AWS cloud security program and infrastructure for a cardiology platform company. Own security architecture, detection/response, HIPAA compliance, and infrastructure decisions balancing security, cost, and reliability.
The Threat Intelligence Specialist investigates identity fraud and threat-actor activity, conducts pivot-based OSINT, and supports urgent law enforcement operations across APAC hours. The role requires at least three years of relevant analytical experience, strong communication skills, and the ability to work autonomously across time zones.
Senior Product Security Engineer partnering with engineering and product teams to secure distributed cloud services through threat modeling, vulnerability management, security tooling, incident response, and automation. Requires substantial security engineering, cloud, Kubernetes, and development experience.
Own the architecture and implementation of Onebrief's GRC framework for defense/government compliance (FedRAMP, CMMC, RMF, SOC 2). Translate regulatory requirements into technical security controls in close partnership with engineering teams.
Lead Confluent's Detection & Response organization in Infrastructure Security. Define vision and roadmap for threat detection, investigation, and response across multi-cloud environments while building and mentoring a global distributed engineering team.
Senior Security Engineer responsible for architecting and securing Chainguard's multi-cloud infrastructure (primarily GCP), embedding security into developer platforms, and hardening environments for AI/agentic workflows using IaC and Kubernetes. Requires strong GCP expertise, DevOps background, and staff-level cloud security experience.
Support engineers in Identity and Access Management, AI, and Cloud security at Chainguard. Ideal for those with strong IT admin or software development foundations seeking to grow into security roles, with hands-on experience in at least one focus area.
Senior/Staff Security Researcher building scalable detection systems that combine program analysis, taint tracking, and LLMs to find and validate real vulnerabilities with minimal false positives. Requires strong appsec expertise, coding fluency in multiple languages, and experience with applied AI for security-critical automation.
Corporate Security Automation Engineer leading design, implementation, and optimization of security infrastructure using IaC (Terraform), automation, endpoint protection, DLP, and ZTNA in a fast-scaling fintech. Requires 5+ years IT experience with 3+ in enterprise cloud security, scripting, and security frameworks.
Senior Security Researcher driving offensive security insights at Censys using large-scale Internet scan data. Conduct original research on attack techniques and agentic AI, publish at top conferences, translate findings into product scanning/fingerprinting capabilities, and collaborate cross-functionally. Requires 5+ years hands-on pentesting/red teaming experience plus agentic AI tooling expertise.
Build and own a portfolio of specialized AI agents that autonomously discover, validate, and drive remediation of vulnerabilities across OpenAI's infrastructure, cloud, Kubernetes, web apps, and attack surface. Requires deep offensive security expertise, agent/systems building experience, and strong production engineering skills at Staff-Principal level.
Security GRC Program Manager serving as primary interface between Stripe's Security team and external auditors/regulators. Manage audits, maintain evidence repository, perform risk/control assessments across global frameworks, and support compliance initiatives.
Senior Advisor on the Security & Risk team responsible for incident response, operating and tuning detection tooling, applying Zero Trust and identity controls, and enabling secure product development in cloud and on-prem environments. Requires 6+ years cybersecurity operations experience, strong IAM/Zero Trust knowledge, and cloud security hands-on expertise.
The Senior Application Security Engineer builds security tooling and production code, embeds secure-by-design practices, leads threat modeling, and protects AI-integrated features. The role requires strong web application security, software engineering, CI/CD security, AWS, and infrastructure-as-code experience.
Senior engineer on Trust and Safety team building and maintaining abuse prevention systems, anomaly detection, and agentic AI tools for the GitLab SaaS platform. Requires strong Ruby/Rails software engineering background; security experience preferred but not required.
Staff Security Engineer who owns security problems end-to-end by identifying real risks, building direct controls, secure-by-default libraries, guardrails, and tooling. Requires 7+ years software engineering experience plus deep security expertise in threat modeling, auth, OWASP, cloud, and supply chain security. Healthcare/HIPAA/HITRUST and GCP experience preferred.
Own and scale Mozilla's web bug bounty program as the primary interface with external researchers. Lead triage, validation, remediation of reports, collaborate with SIRT on incidents, perform code reviews, and drive secure development improvements. Requires 3+ years security engineering experience and bug bounty or bug hunting background.
Lead Windows threat detection research and EDR sensor development for SMB customers. Requires deep Windows kernel expertise, reverse engineering, EDR bypass testing, and AI-augmented research to build innovative, automated defenses.
Senior Application Security Engineer identifies vulnerabilities via code/design reviews, penetration testing, and builds automation tools for SAST/DAST. Requires 5+ years AppSec experience, Python proficiency, and strong collaboration skills; bonus for Kotlin, Kubernetes, AWS.
Builds and maintains security platforms for detection, incident response, threat hunting, and red-team exercises. The role requires strong AWS security experience, Go proficiency, and a strong interest in security, with Kubernetes and SIEM/SOAR experience preferred.
Staff Application Security Engineer defining and driving secure architecture, SDLC, threat modeling, and AI/agentic security guardrails for a cloud-native SaaS platform. Requires 8+ years in appsec or software engineering with technical leadership experience.
Senior Staff Security Engineer owning the roadmap for an AI-driven vulnerability scanning, triage, and automated remediation platform. Requires 8+ years in security engineering with deep cloud/container expertise, offensive security experience, and proficiency in Python/Go/Rust.