Latest remote Security Engineering jobs
Job results
Product Security Engineer analyzes security issues through design reviews, code audits, and penetration tests, builds security tools and mitigations, provides guidance to engineers, and triages bug bounty reports. Requires 3+ years in vulnerability research, Rust/C experience, and automated security tooling.
Designs and improves secure cloud-native architectures, CI/CD pipelines, and infrastructure security on AWS and Kubernetes. Conducts threat modeling, security reviews, automates controls, and drives compliance programs like SOC2.
Designs, builds, and operates core cloud security infrastructure and controls for Stripe's engineering teams. Collaborates on secure cloud expansions, threat modeling, and integrations with AWS, Azure, or GCP; requires production software engineering experience and security mindset.
Conducts browser security audits, implements SERP mitigations like XSS prevention, manages SAST/DAST infrastructure, and leads red-team operations. Requires 7+ years in web security, advanced JavaScript, WebView experience, and vulnerability exploitation skills.
Conducts deep investigations into sophisticated threat actors misusing AI models and targeting OpenAI, leveraging OSINT, telemetry, and scripting to identify disruptions. Builds scalable tooling and automations to enhance detection and safety, partnering cross-functionally for impact.
Leads design and delivery of secure frameworks, guardrails, and workflow-native controls to prevent vulnerabilities in production, especially for AI-assisted development. Requires 8+ years in software/product security, staff-level impact, and proficiency in Go, Python, or JS/TS.
Leads end-to-end security strategy, architecture, operations, and culture for AI training data platform. Builds compliance programs (SOC 2, HIPAA), secures data pipelines, conducts technical reviews, and fosters security-aware culture. Requires 8+ years security experience with 2+ in leadership.
Owns the security posture of Docker Desktop through threat modeling, code and design reviews, vulnerability triage, and hands-on security improvements. The role requires senior security experience, strong Go proficiency, and deep knowledge of Linux and container runtime security.
Hands-on Application Security Lead owning security posture for a scaling SaaS platform. Focuses on multi-tenant isolation, threat modeling, API security, and multi-cloud architecture in distributed systems. Requires early security hire experience at SaaS/data infra companies with deep systems expertise.
Leads security team to build strategy, scale operations, and ensure compliance for AI-powered SaaS serving sensitive research data. Partners with engineering/product on secure development and fosters company-wide security culture. Requires 7+ years leadership in fast-growing SaaS.
Build scalable systems and data pipelines for security observability, enhancing detection, forensics, and compliance. Requires strong engineering in Python/Golang, Terraform, Azure, and data pipelines with a generalist SRE mindset.
Leads blue-team detection, incident response, vulnerability management, security automation, and risk mitigation for a SaaS platform. The role requires 5+ years of security engineering and operations experience, strong AWS and infrastructure-security knowledge, and the ability to mentor other engineers.
Cloud Security Engineer secures AWS and Kubernetes infrastructure using Terraform IaC, conducts threat modeling and audits, embeds security in CI/CD pipelines, and ensures compliance with standards like SOC 2 and HIPAA. Requires 5+ years experience with AWS and Kubernetes security expertise.
Integrates security into product design, conducts threat modeling and risk assessments, manages secure development pipelines, and triages vulnerabilities. Requires 5+ years in app security, Kubernetes expertise, and strong collaboration with engineering teams.
The Compliance Engineer will maintain APAC compliance certifications, conduct security risk assessments, support enterprise customer and sales security requests, and automate compliance monitoring across cloud environments. Experience with regulated industries, audits, public cloud compliance, and APAC privacy frameworks is required.
Senior Security Engineer builds software solutions and tools to mitigate risks, conducts security reviews and threat modeling, and leads incident response while mentoring teams to elevate organizational security maturity.
Secures ClickHouse’s multi-cloud infrastructure across AWS, Google Cloud, and Azure, with emphasis on Kubernetes, cloud security controls, vulnerability response, and automation. The role partners with engineering teams to harden customer-facing systems and scale security processes.
Security Engineer specializing in product security designs and implements AWS security controls, performs vulnerability assessments, integrates security into DevOps, and mentors engineers to protect cloud, mobile core, and app infrastructure. Requires 5+ years experience with 3+ in AWS.
Maintains US government compliance certifications like GovRAMP and FedRAMP, conducts risk assessments using NIST/CIS, builds documentation, and automates compliance tooling for cloud environments and CI/CD pipelines. Requires experience in regulated industries and compliance tools like Vanta.
Secures enterprise applications, integrations, data flows, and AI-adjacent use cases through security design reviews, risk assessment, and defining secure requirements. Partners with IT, Engineering, and stakeholders to enable scalable security practices. Requires 7+ years in security engineering.
Designs and builds scalable security controls and services for MongoDB Atlas multi-cloud infrastructure using Linux mechanisms, Kubernetes, and eBPF. Requires 5+ years experience in software/SRE with security focus, proficiency in systems programming, and cloud platforms.
Leads architecture and implementation of planet-scale security services like authN/Z, proxies, and key management for OpenAI's GPU clusters, multi-cloud infra, and AI models. Requires expertise in secure distributed systems, cloud platforms, and cross-team leadership.
Principal Security Engineer leads security for OpenAI's infrastructure including GPU clusters, multi-cloud, datacenters, and Kubernetes. Drives strategy, builds controls against advanced threats, and mentors teams with deep cloud and on-prem expertise.
Develops security features for Teleport's open core platform, focusing on application security, vulnerability fixes, and integrations like Device Trust and KMS storage. Requires Go or Rust, Linux systems engineering experience; cryptography a plus.
Own the product and infrastructure security roadmap as a hands-on individual contributor, covering threat modeling, vulnerability management, detection, incident response, assurance, and secure SDLC practices. Requires 8+ years of security experience and deep technical breadth.
Security Engineer drives security improvements across Figma's AI, platform, product, and anti-abuse teams through assessments, tooling development, threat detection, and incident response. Requires 5+ years engineering experience, strong security judgment, and proficiency in a general-purpose language.
Senior DevSecOps Engineer responsible for securing AWS and Kubernetes platforms, embedding automated security controls into CI/CD pipelines, leading threat modeling and incident response, and translating compliance requirements into scalable engineering guardrails. Requires 7+ years of security or cloud infrastructure experience.
Senior Developer builds Windows security features using Rust and other languages, develops secure libraries, resolves vulnerabilities, and leads secure coding practices. Requires 4+ years experience in Windows security development and cryptography.
Leads cloud security architecture, penetration testing, threat modeling, and secure-by-default practices for large-scale cloud-native applications. Requires 8+ years of application, product, or cloud security experience and strong expertise across cloud platforms, containers, and security tooling.
Build security tooling and enhancements to protect Pinterest's platform and users, focusing on secure development lifecycle, assessments, and AI threat mitigation. Requires 5+ years in application/product security and Python proficiency.
Leads security compliance and risk management projects, driving certifications like FedRAMP and PCI in a cloud-native environment. Requires 4+ years in security program management, cross-functional collaboration, and a bachelor's in CS or equivalent.
Senior Security Engineer owns security across infrastructure (GKE, GCP) and application stack, builds tooling/automation for secure-by-default development, leads threat modeling, red teaming, bug bounty, and incident response in a fast-paced startup. Requires 6+ years security engineering experience.
Security Engineer enhances AWS serverless infrastructure security, develops playbooks, improves compliance with SOC/HIPAA/HITRUST, and collaborates on secure CI/CD and app design. Requires 4+ years AWS experience and TypeScript proficiency.
Conduct manual penetration testing on web apps, APIs, networks, and iOS/Android mobile apps as part of a pentest team. Document findings, validate vulnerabilities, and focus on OWASP Top 10 for US-resident freelancers.
Performs manual penetration testing on web apps, APIs, networks, and iOS/Android mobile apps as part of a pentest team. Documents findings, validates vulnerabilities, and targets OWASP Top 10; not entry-level, freelance part-time role.
Leads SOC examinations, SOX compliance, IT control assessments, and remediation across security, technology, engineering, and finance teams. Requires 5+ years of external IT audit or technology risk experience, strong ICFR/SOX expertise, and familiarity with cloud environments.
Software engineer focused on security and privacy, improving Tailscale's security through feature development, audits, threat modeling, and spending 50% time writing code. Requires proficiency in Go or similar, security experience, and deep knowledge of vulnerabilities and cryptography.
Principal Engineer leads Authentication strategy at Databricks, crafting secure, scalable systems with 15+ years in distributed systems and data security expertise. Requires MS/PhD, leadership, and experience in identity management and access control.
Leads Security Operations engineering team, driving hiring, mentoring, roadmap refinement, and excellence in vulnerability management and incident response. Requires 8+ years technical experience with 3+ years leadership in distributed teams.
Security engineer on internal Red Team stress-testing blockchain infrastructure by hunting vulnerabilities, building Rust fuzzers, simulating economic attacks, and dissecting EVM internals. Requires Rust fluency, EVM expertise, and proven offensive security track record like CTFs or bug bounties.
Leads the development and evolution of the Application Security program, integrating security practices into SDLC through threat modeling, code reviews, and pen testing. Collaborates with engineering teams on web, mobile, and API security for a SaaS platform; requires 10+ years experience building AppSec from inception.
Analyzes software supply chain threats using AI scanners, conducts malware analysis and threat hunting, builds automation tools, and integrates research into products to protect open source ecosystems. Requires 3+ years in security operations and master's degree.
Senior Security Engineer builds threat detections, leads incident response, and automates security operations in cloud/SaaS environments. Requires 5+ years experience with SIEM, SOAR, Python, AWS/GCP.
Leads Blue Team in information protection, incident detection/response, and security services. Oversees vulnerability management, threat hunting, and cloud security in AWS environments. Requires 5+ years security engineering experience and technical leadership of remote teams.
Builds and scales automated patching infrastructure for high-impact vulnerabilities in npm packages, leads patch production, and develops detection workflows and APIs to secure the JavaScript open source ecosystem. Requires 3+ years engineering experience with Node.js, JS/TS, package managers, and security concepts.
Leads technical direction for secure AI infrastructure gateway, building scalable backend services with distributed systems expertise. Requires 10+ years backend experience, Go fluency, cloud platforms, and technical leadership in remote teams.
Assess client security postures, develop customized security programs using frameworks like NIST and SOC2, provide implementation guidance, and collaborate with auditors and internal teams to achieve compliance goals.
Develops and maintains cross-platform endpoint security agent for Windows, macOS, and Linux using Go and JavaScript. Handles system monitoring, threat detection, secure cloud communication, and compliance enforcement. Requires 5+ years systems programming experience and OS internals knowledge.
The Senior Security Engineer leads application and product security operations across CI/CD and cloud-native environments, integrating security into the software lifecycle and automating controls. The role requires 5+ years of security experience, strong vulnerability and cloud security knowledge, and hands-on security tooling expertise.
Principal-level Offensive Security Engineer conducts red/purple team operations and penetration testing on AI agent products like Codex and Operator, hunting vulnerabilities in app-infra-model interactions and collaborating with defensive teams to strengthen security.