Information Security Analyst remote jobs - 735 jobs
Senior Manager, Customer Trust & Field Security Specialist - Capital One Software (Remote)
Capital One 4.7
Remote job
About the Role:
We are seeking an experienced and detail-oriented Senior Manager with horizontal cybersecurity expertise to join our dynamic Customer Trust & Field Security team. This critical role acts as the security expert for our sales and business development efforts, bridging our technical security posture with the questions of prospective customers. You will be responsible for reviewing, interpreting, and responding to customer security-related inquiries, ensuring our responses are accurate, complete, and aligned with our security certifications and documentation. This position is pivotal in establishing and strengthening customer confidence in our cybersecurity, privacy, and compliance programs, influencing product direction and sales strategy to solve real-world security challenges. You will drive transparency, thought leadership, and strategic engagement, ensuring our security posture aligns with industry best practices while enabling business growth.
This is an opportunity to be a crucial part of our growth.
If you're a cybersecurity professional who enjoys the challenge of communicating technical concepts in a business context, we'd love to hear from you.
Key Responsibilities:
Customer Trust & Transparency: Scale and build upon existing programs like the Customer Trust Center, providing customers with self-service access to relevant security, privacy, and compliance information.
Customer Engagement: Act as a trusted technical and security advisor, engaging customer security teams and IT leaders to align on their cybersecurity & business needs. Serve as the internal subject matter expert on security for the GTM team, supporting sales and account managers in client-facing discussions and presentations.
Industry Thought Leadership: Represent the company externally in security and technology conversations, shaping best practices and positioning our solutions as industry-leading.
Go-to-Market & Sales Acceleration: Bridge the gap between technical value and business outcomes, aligning security messaging with sales and marketing strategies to drive adoption of our products.
Cross-functional Influence & Collaboration: Work closely with the engineering, legal, risk, cyber, and compliance teams to ensure our security responses are accurate and reflect our latest technical and regulatory standing.
RFI/RFP Response: Analyze and respond to cybersecurity sections of RFIs (Requests for Information) and RFPs (Requests for Proposal), providing detailed and precise information about our security controls, policies, and procedures.
Security Documentation: Maintain and update a knowledge base of our security posture, including security policies, certifications (e.g., SOC 2, ISO 27001), and compliance documentation.
Continuous Improvement: Identify trends in customer security inquiries to help improve our documentation and proactive communication strategies.
Third-Party Risk & Due Diligence: Support third-party risk and due diligence processes, helping customers efficiently evaluate our security posture.
Product Roadmap Contribution: Provide insights on emerging cybersecurity trends and customer expectations to contribute to the product roadmap.
Security Sales Playbook Development: Develop and standardize security sales playbooks, equipping sales teams with messaging, objection handling, and case studies, as applicable.
Why Join Us:
Impactful Role: Play a critical role in shaping our customer trust strategy, directly influencing business growth and sales success by building trust and demonstrating our commitment to security for our customers.
Collaborative Culture: Partner with diverse teams across the organization, from engineering to sales, in a fast-paced work environment.
Thought Leadership: Represent the company externally and contribute to industry best practices.
Customer-Centric Focus: Be part of a team dedicated to empowering organizations to confidently adopt our solutions.
Basic Qualifications:
At least 7 years of progressive experience in a cybersecurity or informationsecurity role, with a strong understanding of security frameworks and best practices, and a focus on horizontal expertise across various domains.
At least 4 years in customer-facingroles, acting as a trusted advisor to senior security and IT leaders.
Deep technical understanding of cybersecurity principles, data protection, privacy, and compliance frameworks. Familiarity with common cybersecurity concepts, including access control, encryption, network security, and incident response.
Excellent written and verbal communicationskills with the ability to translate complex technical information into clear, concise, and professional responses for both technical and non-technical audiences.
Meticulous and organized, with a proven ability to manage multiple projects and deadlines simultaneously and great attention to detail.
Ability to influence and collaborate effectively with cross-functional teams.
Preferred Qualifications:
Experience in developing and implementing scalable Customer Trust programs.
3+ years experience with Third Party Risk Management programs.
Strong business acumen and the ability to translate complex technical concepts into business value.
Professional certifications such as CISSP, CISM, CIPP/E, or CompTIA Security+
Experience with cloud services and cloud technologies (e.g., AWS, Microsoft Azure, GCP), cybersecurity technologies, data cloud platforms (e.g., Snowflake, Databricks).
At this time, Capital One will not sponsor a new applicant for employment authorization for this position.
The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked.
Remote (Regardless of Location): $204,900 - $233,800 for Sr. Manager, Solutions ArchitectureMcLean, VA: $225,400 - $257,200 for Sr. Manager, Solutions ArchitectureRichmond, VA: $204,900 - $233,800 for Sr. Manager, Solutions Architecture
Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter.
This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan.
Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website. Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level.
This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections 4901-4920; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries.
If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at ************** or via email at RecruitingAccommodation@capitalone.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.
For technical support or questions about Capital One's recruiting process, please send an email to **********************
Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site.
Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
$91k-115k yearly est. 2d ago
Looking for a job?
Let Zippia find it for you.
AI Security / Biosecurity Engineer, Center on AI, Security, and Technology
Rand Corporation 4.8
Remote job
AI Security / Biosecurity Engineer, RAND CAST page is loaded## AI Security / Biosecurity Engineer, RAND CASTlocations: San Francisco, CA: Pittsburgh, PA: Santa Monica, CA (Greater Los Angeles Area): Boston, MA: USA - Remotetime type: Full timeposted on: Posted Yesterdayjob requisition id: R3442**Job Type:**Term (Fixed Term)**Overview**is seeking technically excellent and mission-driven AI Security / Biosecurity Engineers to work across a number of our most critical and fast-paced AI security and biosecurity workstreams.RAND CAST works on pressing national security challenges related to emerging technologies. Our areas of focus include AI security, compute, biosecurity and bioresilience, and the intersection of AI and biotechnology.Emerging technologies, especially AI and biotechnology, have many promising beneficial and defensive applications. Given their dual-use nature, they also present a number of new security challenges. RAND CAST explores ambitious technical and policy approaches to solving these complex problems. We are a team of world-class technical and policy analysts, engineers, and scientists giving decision-makers the objective insights they need to navigate global emerging threats.**Position Description**We are looking for individuals who are driven by a bias for action; capable of developing and securing complex systems under high-stakes and fast-paced conditions; and can act as an owner, not just a contributor, with end-to-end ownership of critical, sensitive data infrastructure in a highly autonomous environment.We have a number of ongoing technical projects across our AI security and biosecurity teams. Candidates will discuss initial projects with program leads as part of the interview process.**Qualifications****Required:*** Professional experience in software engineering with a focus on backend engineering and/or data engineering.* Demonstrated ability to build robust and technically complex systems with a security-first mindset.* Experience operating, monitoring, and deploying systems using modern cloud infrastructure.* Preference for working in a fast-paced, autonomous environment.* Excellent communication skills, both written and verbal, tailored to technical and non-technical audiences* Fluency with MS Office suite**Preferred:*** Advanced knowledge of integrating Large Language Models (LLMs) into workflows.* Background in biosecurity, dual-use technology, or AI security and misuse.* Ability to scope cross-functional projects with internal customers and own their execution.* Experience with distributed data processing platforms.**Education Requirements**PhD in Biological Sciences, Computational Biology, Biotechnology, Bioinformatics, Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, InformationSecurity, Information Technology, Mathematics, Applied Mathematics, Physics, Applied Physics, Engineering Physics, Artificial Intelligence, Machine Learning, Engineering and Public Policy, Technology and Policy, National Security Policy, Policy Analysis, Political Science, International Relations, or similar is required.ORMaster's degree in the fields listed above with 3+ years of professional experience, is required.ORBachelor's degree in the fields listed above with at least 5+ years of professional experience, is required.Master's or PhD preferred.**Term**This position is structured as a two-year appointment with options to later extend the initial appointment and explore other opportunities for growth.**Security Clearance**Ability to obtain and maintain a U.S. government clearance is preferred.**Location**We are hiring for this position in San Francisco, CA; Washington, DC; Santa Monica, CA; Pittsburgh, PA; and Boston, MA. We offer a hybrid work arrangement, combining work from home and on-site options. Fully remote work will also be considered.**Salary Range**: $118,500 - $261,400Technical Resident, Associate II = $118,500 - $171,900Technical Resident, Specialist = $146,200 - $211,900Visiting Technical Expert = $167,300 - $261,400RAND considers a variety of factors when formulating an offer, including but not limited to, the specific role and associated responsibilities; a candidate's work experience, education/training, skills, expertise; and internal equity.The salary range includes base pay plus RAND's sabbatic pay (which provides additional compensation above base pay when vacation is taken). This position may be eligible for additional compensation. In addition, RAND provides strong benefits including health insurance coverage, life and disability insurance, savings plan, paid time-off and more.*Equal Opportunity Employer***RAND is a research organization that develops solutions to public policy challenges to help make communities throughout the world safer and more secure, healthier and more prosperous. RAND's research and analysis address issues that impact people everywhere, including security, health, education, sustainability, growth, and development.** **RAND has approximately 2,025 people from more than 50 countries working in offices in the United States, Europe and Australia, with annual revenues of $435.8 million.** **RAND is nonprofit, nonpartisan, and committed to the public interest. Our research is sponsored by government agencies, international organizations, and foundations. We rely on philanthropic support to pursue visionary ideas; address critical problems that are under-researched; and devise innovative approaches for solving acute, complex, or provocative policy challenges. RAND values objectivity and integrity in both its research processes and internal interactions. We emphasize a collegial environment that respects the contributions and dignity of all staff.**
#J-18808-Ljbffr
$167.3k-261.4k yearly 5d ago
Epic Cadence & Security Analyst
Onpoint Search Consultants 4.2
Remote job
What you will find ...
100% REMOTE
exceptional benefits (pension plan options)
top ranked hospital in the U.S.
What you will do ...
design & build Epic Cadence
build Epic Security
break-fix & support Epic Cadence & Security
optimize Decision Tree for scheduling
liaison with operational stakeholders
Wish list ...
5+ years Epic Cadence & Security build
REQUIRED Epic Cadence Certification
REQUIRED Epic Security Certification
recent Epic Security work
Decision Tree a plus
$80k-116k yearly est. 4d ago
Senior PM, AI Security & DLP Platform (Hybrid)
Nightfall
Remote job
A cloud data protection company based in California is seeking a Product Manager to drive development for endpoint DLP features. The ideal candidate will have 4-6 years of experience in product management at a SaaS startup, with strong communication skills and an execution-oriented mindset. This role offers the chance to work closely with engineering and sales teams, ensuring successful product adoption and customer satisfaction within a hybrid work environment.
#J-18808-Ljbffr
$95k-152k yearly est. 2d ago
Strategic Security GRC Analyst - Hybrid (SF/SJ)
Lambda Inc. 4.2
Remote job
A technology firm in AI infrastructure is seeking an experienced cybersecurity risk manager to validate security controls and manage compliance with various frameworks. The role requires at least 8 years of experience, focusing on risk management, audits, and collaboration with teams. Strong knowledge of cybersecurity frameworks like ISO 27001 and the ability to manage audits and security assessments is essential. This position is based in San Francisco or San Jose with a hybrid work model.
#J-18808-Ljbffr
$90k-132k yearly est. 6d ago
Staff Security Engineer
Parafin Inc.
Remote job
About Us:
At Parafin, we're on a mission to grow small businesses.
Small businesses are the backbone of our economy, but traditional banks often don't have their backs. We build tech that makes it simple for small businesses to access the financial tools they need through the platforms they already sell on.
We partner with companies like DoorDash, Amazon, Worldpay, and Mindbody to offer fast and flexible funding, spend management, and savings tools to their small business users via a simple integration. Parafin takes on all the complexity of capital markets, underwriting, servicing, compliance, and customer service for our partners.
We're a tight-knit team of innovators hailing from Stripe, Square, Plaid, Coinbase, Robinhood, CERN, and more - all united by a passion for building tools that help small businesses succeed. Parafin is backed by prominent venture capitalists including GIC, Notable Capital, Redpoint Ventures, Ribbit Capital, and Thrive Capital. Parafin is a Series C company, and we have raised more than $194M in equity and $340M in debt facilities.
Join us in creating a future where every small business has the financial tools they need.
About the Position
We're looking for an experienced security-focused engineer to help shape and scale Parafin's security posture across our cloud and platform environments. Our Security and Infrastructure team owns the foundational systems that power all of Parafin - from compute and networking to identity and compliance - and you'll play a central role in ensuring those systems are secure, reliable, and compliant.
In this role, you'll design and operate controls, tooling, and processes that keep our infrastructure resilient and compliant while enabling developers to move quickly and safely. You'll partner closely with teams across engineering and compliance to strengthen how we manage access, secure applications, monitor threats, and respond to incidents.
What You'll Be Doing
Lead efforts to improve Parafin's overall security posture across infrastructure, applications, and data systems.
Develop and maintain frameworks for identity, access management, and least-privilege enforcement.
Establish and operate best-in-class security monitoring, alerting, and incident response processes.
Partner with product and infrastructure engineers to embed secure-by-default patterns in our systems and applications.
Define and enforce standards for vulnerability management, secrets handling, and dependency integrity.
Collaborate with compliance and risk teams to build and maintain controls aligned with frameworks such as SOC 2, PCI DSS, and other fintech regulations.
Support audits and security assessments by ensuring controls are properly implemented and evidenced.
Contribute to security awareness and training efforts across engineering teams.
Influence long-term strategy on secure architecture, detection, and response automation.
What We're Searching For
8+ years of experience in security operations or application security, preferably in a cloud-native and regulated environment.
Strong understanding of AWS security, including IAM, VPC, and network segmentation best practices.
Experience with threat detection and response, vulnerability management, and incident response workflows.
Familiarity with Kubernetes and container security principles, including RBAC, admission controls, and runtime monitoring.
Knowledge of compliance frameworks (SOC 2, PCI DSS, ISO 27001) and how to operationalize them in engineering environments.
Strong communication and collaboration skills - comfortable working across engineering, product, and compliance teams.
We Prefer If You Have
Experience building or maturing a security operations or application security program at scale.
Background in security automation, threat modeling, or secure architecture reviews.
Familiarity with developer-focused security enablement - e.g., SAST/DAST integration, dependency scanning, or security education.
Experience in regulated or fintech environments where security and speed must coexist.
What We Offer
Salary Range: $235k - $280k
Equity grant
Medical, dental & vision insurance
Unlimited PTO
Work From Home flexibility
Commuter benefits
Free lunches
Paid parental leave
401(k)
Employee assistance program
If you require reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please contact us.
#J-18808-Ljbffr
$235k-280k yearly 2d ago
Corporate Security Engineer
Workos
Remote job
WorkOS builds tools and services for developers to help them implement authentication, identity, authorization, and overall enterprise readiness. We're a fully distributed team with employees across North American time zones. We're well‑funded, having raised $100m in funding from top investors including Greenoaks Capital, Lachy Groom, and Lightspeed Ventures. Our fast‑growing customer base includes rapidly growing SaaS companies like OpenAI, Cursor, Perplexity, Vercel, Plaid, and hundreds of others.
About the Security Team
The Security team at WorkOS is responsible for keeping our company and customer data safe. As a CorpSec Engineer, you'll focus on the internal side of security-ensuring our people, devices, and systems are secure by default. We support a remote‑first, fast‑moving engineering organization and need strong, pragmatic security systems that scale with us.
You'll work to improve access controls, endpoint security, and tooling across the company. This role is a mix of hands‑on execution and strategic thinking-perfect for someone who wants to shape how security works inside a modern startup.
Who we're looking for
Have experience with corporate security and endpoint management in a cloud‑native, remote‑friendly environment
Enjoy taking ownership of systems like Okta, MDM, and EDR and making them more reliable, secure, and easy to use
Can balance security best practices with the realities of usability and speed
Like designing scalable controls for access, identity, and device management
Are comfortable working independently and cross‑functionally with IT, Infra, and GRC
Are curious, proactive, and enjoy simplifying complexity
What you'll be doing
Own and improve our identity and access management systems (Okta, Google Workspace, etc.)
Administer and secure our MDM and endpoint protection tools (e.g. Kandji, EDRs)
Partner with Infra to implement controls for least privilege, audit logging, and change management
Develop automations and tooling for onboarding/offboarding, access reviews, and audit prep
Proactively identify security risks and lead the rollout of mitigations
Help shape security policies and practices that work well for engineers, not against them
Work with vendors and evaluate new tools as needed
Document systems and decisions clearly to support scale and clarity
Requirements
Experience with identity, access, and endpoint security tools (e.g. Okta, MDM, EDR)
Familiarity with cloud‑native IT/security operations and SaaS environments
Comfort working in a fast‑paced, high‑autonomy environment
A practical mindset and a bias for simplicity and security‑by‑default
Nice to have
Experience working at a startup or on a small security team
Familiarity with SOC 2, ISO 27001, or other compliance frameworks
Scripting or automation experience (e.g. Python, Bash, Terraform)
The annual US base salary falls within the range of $175,000 to $250,000. This range does not encompass the full spectrum of benefits such as equity, health insurance, vacation time, and paid parental leave. This salary range covers multiple levels of engineering roles and final compensation will be determined considering various factors, including experience, skills, and qualifications.
For candidates outside the US, including Canada, compensation is adjusted based on local market benchmarks.
Benefits (US Only)
At WorkOS, we offer resources that emphasize personal and familial well‑being. We offer healthcare coverage for you and your family, including medical, dental, and vision. We offer parental leave, paid‑time off and fully remote working arrangements.
Benefits include:
Competitive pay
Substantial equity grants
Healthcare insurance (Medical, Dental and Vision) for you and your family
401k matching
Wellness and fitness monthly allowances
PTO + paid holidays + unlimited sick leave
Autonomy and flexibility with remote work
Please inquire directly with our recruiting team for benefits available to those working outside the US.
Equal Opportunity Employer
WorkOS is an equal opportunity employer, committed to diversity and inclusiveness. We will consider all qualified applicants without regard to race, color, nationality, gender, gender identity or expression, sexual orientation, religion, disability or age.
#J-18808-Ljbffr
About Sift
At Sift, we're redefining how modern machines are built, tested, and operated. Our platform provides engineers with real-time observability over high-frequency telemetry, eliminating bottlenecks and enabling faster, more reliable development.
Sift was born from our work at SpaceX on Dragon, Falcon, Starlink, and Starship-where scaling telemetry, debugging flight systems, and ensuring mission reliability demanded new infrastructure. Founded by a team from SpaceX, Google, and Palantir, Sift is built for mission-critical systems where precision and scalability are non-negotiable.
About the Role
As Sift's founding Security & Compliance Engineer, you will not just maintain a security checklist; you will define the posture, architecture, and practices that keep our products and infrastructure secure in the most demanding environments.
You will be both hands-on and strategic, building controls, automating compliance, and working directly with customers, auditors, and internal teams to inspire confidence in our platform.
The Security & Compliance Engineer will own Sift's security posture end-to-end, blending technical security engineering with governance, risk, and compliance leadership. You will set the standard for how we protect our systems and data, ensuring we are ready to meet and exceed the expectations of aerospace, defense, and enterprise customers.
This is a high-visibility, high-ownership role: you will be Sift's first security hire, laying the foundation of our security program and growing it into a dedicated function as the company scales.
In This Role, You'll:Technical Security
Build secure CI/CD pipelines with embedded scanning.
Operate and tune SIEM/EDR (ELK, Datadog, Splunk, CrowdStrike, Prometheus, Grafana).
Secure multi-cloud environments (AWS GovCloud, Kubernetes, on-prem).
Implement zero-trust networking and modern SASE/ZTNA approaches.
Improve visibility and observability across networks and workloads.
Governance, Risk & Compliance (GRC)
Lead compliance initiatives: SOC 2, ISO 27001, NIST 800-171, FedRAMP, CMMC.
Manage third-party/vendor risk assessments.
Own internal/external audits and readiness for customer/government reviews.
Lead company-wide security awareness: phishing simulations, compliance workshops, and role-specific training.
The Skillset You'll Bring:Technical Skills
5+ years in cybersecurity, product security, or cloud security roles, ideally in high assurance or regulated industries.
Hands-on experience securing AWS or an equivalent cloud service provider (GovCloud preferred) and Kubernetes-based environments, with strong infrastructure as code practices.
Proven track record leading or supporting compliance initiatives such as SOC 2, NIST 800-171, CMMC, FedRAMP, or ISO 27001.
Deep understanding of network, endpoint, and identity security principles.
Experience with security tooling and integration into operational workflows.
Ability to translate compliance requirements into clear, actionable engineering work.
Experience managing third-party/vendor risk and customer-facing security reviews.
Soft Skills
Clear communicator with both technical and non-technical stakeholders.
Customer-facing presence for audits and enterprise assurance.
Collaborative partner to infra and product teams.
High ownership and adaptability in ambiguous, fast-moving environments.
Integrity and trustworthiness, handling sensitive data, and compliance matters with discretion.
Excited to operate as a team of one early on, with the vision to build and lead a security function over time.
Location:
Sift's headquarters is in El Segundo, CA. We collaborate in person twice a week-on Mondays and Thursdays-and come together for a full week every two months. While we prefer team members to be local, we're open to relocating candidates to LA or considering remote work from the San Francisco area for the right candidate.
Salary range: $170,000 - $220,000 per year. Plus equity and benefits.
Eligibility:
US Person Required: Must be a U.S. Citizen or Green Card Holder due to ITAR (International Traffic in Arms Regulations) / EAR (Export Administration Regulations) compliance requirements.
#J-18808-Ljbffr
Senior Security Engineer - Corporate Security
Rippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.
Take onboarding, for example. With Rippling, you can hire a new employee anywhere in the world and set up their payroll, corporate card, computer, benefits, and even third-party apps like Slack and Microsoft 365-all within 90 seconds.
Based in San Francisco, CA, Rippling has raised $1.4B+ from the world's top investors-including Kleiner Perkins, Founders Fund, Sequoia, Greenoaks, and Bedrock-and was named one of America's best startup employers by Forbes.
We prioritize candidate safety. Please be aware that all official communication will only be sent from @ Rippling.com addresses.
About the role
Rippling is looking for a Senior Security Engineer to join our Corporate Security team. Our mission is to reduce organizational risk by securing the tools and platforms Rippling employees use every day-SaaS apps, internal tools, endpoints, and email. We help the business make safer decisions by building secure defaults, automating away risky behavior, and working directly with stakeholders to understand and mitigate threats.
As a Senior Engineer on CorpSec, you'll drive projects that span technical execution, stakeholder engagement, and strategic planning. You'll work closely with the Detection and Response, IT products, Infrastructure, Legal, and Compliance teams to improve how we manage access, detect abuse, and remediate risk-often through automation and thoughtful process design.
What You'll Do
Lead end-to-end security projects that secure core enterprise systems like Google Workspace, Atlassian, Salesforce, and Slack.
Design and implement scalable access controls, including least privilege policies, automated approvals, and audit workflows.
Deploy and tune security tooling (e.g. email security platforms, CASB/SWG, SaaS DLP tools) to reduce risk across our corp environment.
Automate security workflows that reduce manual effort, close the loop on findings, and improve team efficiency.
Write one-pagers and RFCs that clarify risk, propose solutions, and drive alignment with cross-functional stakeholders.
Partner with Detection & Response to improve phishing protection and support incident investigations involving corp tools or user accounts.
Mentor teammates and contribute to the team's technical direction through design reviews and hands‑on collaboration.
Sample Projects You Might Work On
Rolling out a new email security solution and defining phishing detections in partnership with Detection & Response.
Building an approval system for Chrome extensions and auto‑whitelisting trusted ones using Google's API.
Automating Slack‑based remediation for publicly shared sensitive Google Docs.
Restricting 3rd‑party app access in Google Workspace and driving stakeholder alignment on exceptions.
Threat modeling Salesforce and improving visibility into high‑risk integrations and data access patterns.
What We're Looking For
5+ years of experience in security or software engineering, ideally with exposure to SaaS, corp IT, or access management.
Strong programming skills (e.g. Python, Go) and a track record of building automation that solves real problems.
Experience with one or more of: identity and access management, SaaS security tooling, DLP, insider threat detection, or phishing protection.
Clear, empathetic communication skills-especially when working with stakeholders outside of engineering.
Ability to turn ambiguous problems into scoped projects, define success metrics, and drive them to completion.
Comfortable owning projects end‑to‑end and proactively reducing blockers for others.
What Success Looks Like
You lead multi‑stakeholder projects that reduce security risk and are measurable, repeatable, and automated.
You deliver projects that enable safe default behaviours, reduce operational toil, or improve visibility into corp risk.
You can clearly communicate security trade‑offs to engineering and business teams, and drive alignment across orgs.
You build systems that last-flexible, reusable, and easy for others to extend or maintain.
Additional Information
Rippling is an equal opportunity employer. We are committed to building a diverse and inclusive workforce and do not discriminate based on race, religion, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, age, sexual orientation, veteran or military status, or any other legally protected characteristics. Rippling is committed to providing reasonable accommodations for candidates with disabilities who need assistance during the hiring process. To request a reasonable accommodation, please email accommodations@rippling.com.
Rippling highly values having employees working in‑office to foster a collaborative work environment and company culture. For office‑based employees (employees who live within a defined radius of a Rippling office), Rippling considers working in the office, at least three days a week under current policy, to be an essential function of the employee's role.
This role will receive a competitive salary + benefits + equity. The salary for US‑based employees will be aligned with one of the ranges below based on location; see which tier applies to your location here.
A variety of factors are considered when determining someone's compensation-including a candidate's professional background, experience, and location. Final offer amounts may vary from the amounts listed below.
The pay range for this role is:
159,000 - 278,250 USD per year (US Tier 1)
143,100 - 250,425 USD per year (US Tier 2)
135,150 - 236,513 USD per year (US Tier 3)
#J-18808-Ljbffr
$132k-184k yearly est. 6d ago
Senior Security Engineer
Metriport Inc.
Remote job
San Francisco, CA
Metriport is an open-source data intelligence platform that helps healthcare organizations access and exchange patient data in real-time. We integrate with all major US healthcare IT systems and tap into comprehensive medical data for 300+ million individuals.
We've found product-market fit with multi-million ARR, 100+ customers (including Strive Health, Circle Medical, and Brightside Health), backing from top VCs, and years of runway. We're ready to scale. We're a tight-knit, high-performing team of mostly former founders (including two YC alumni). We're engineering-heavy, operate with minimal bureaucracy and high autonomy, and hire based on competence, not prestige. We push hard-founders work six days a week from our SF office-but give everyone freedom to craft their schedule. We measure output and we're committed to sustainable intensity.
About you
In a nutshell, we're looking for a security engineer with the following specific qualities:
You're entrepreneurial-minded, with an olympian-level work ethic (nearly our entire engineering team consists of former founders).
You are passionate about security and are excited to own security related projects within the company end-to-end.
You are confident in your ability to build scalable systems across the full stack, and people usually come to you for technical guidance.
You believe you can solve any problem that comes at you, and don't shy away from diving deep into areas where you may lack domain expertise.
You have a strong sense of ownership over your work, and have demonstrated ability to lead others.
You know how to move fast - while still maintaining a strong security posture.
You care more about the end result and delivering value, rather than what new and frilly tech is being used under the hood for a given feature.
When someone scopes out a project with an ETA of 3 weeks, you ask yourself "why can't it be done in 3 days?".
You're a hacker at heart, and have a good sense of what rules should, and shouldn't, be broken.
What you'll be doing
After quickly ramping up using our comprehensive onboarding materials to get familiar with our domain, product, and codebase, the goal would be to get you shipping product directly to customers as quickly as possible. Specifically, day to day, this looks like:
Evangelizing security across Metriport's growing team - we will look to you for guidance, and training.
Driving full-stack security projects , big and small, end-to-end from ideation to production rollout. These projects could include things like:
Implement an enterprise-grade audit logging solution for a new national healthcare network infrastructure stack.
Implement fine grained RBAC on the API key access layer, and more robust roles on our UIs.
Help us revamp our internal security policies and put tools in place to keep the platform, and employees, secure while still allowing the team to be efficient.
Helping the engineering team with PR reviews with a security-focused lens.
Work with the Go to Market team to complete customer security assessments and questionnaires.
Work with the engineering team to harden security across the development lifecycle - think secret management, access controls, and vulnerability scanning.
Managing your own work in Linear.
Participating in bi-weekly sprint planning / retro sessions, and quarterly planning sessions.
Attending a daily 30 minute remote stand-up at 7:30am PST Mon-Fri (our only regular mandatory meeting).
Requirements
You have 6+ years experience in security engineering and informationsecurity.
You're located in San Francisco or the Bay Area (or willing to relocate).
Familiar with HIPAA compliant environments.
Experience rolling out and maintaining security frameworks like SOC 2, NIST, HITRUST, FedRAMP, etc.
Experience rolling out data protection technologies like SSO, MFA, VPN, FIPS, etc.
Experience with organizational secret management.
Experience implementing SCA, SAST, DAST in CICD workflows.
Experience with Mobile Device Management (MDM).
Proficiency in cloud security & networking on AWS - IAM, WAF, KMS, etc.
Proficiency in authentication, cryptography, encryption, and security protocols such as: mTLS, RSA, SSL, HMAC, RBAC, etc.
Bonus: experience with IHE profiles (ATNA, CT, XUA).
Benefits
Competitive equity + compensation package 🚀
Full family Platinum health insurance, dental, and vision coverage 🦷
401(k) retirement plan + matching 💰
Flexible work from home or in-office 🏢
Healthy lunches are complimentary when working in-office (and breakfast + dinners as needed) 🍏
Quarterly company off-sites with the team ⛷️
MacBook provided by us 💻
Unlimited PTO (we work hard, but trust you to take time you need to be at your best) 🧘♂️
Our tech
On the frontend, we use React - on the backend, we rely on Node.js and TypeScript for writing core business logic. We deploy a wide range of AWS cloud services (ie ECS, Fargate, Lambda, etc), and manage our infrastructure as code with AWS CDK. Data lives in PostgreSQL, DynamoDB, S3, Snowflake, FHIR servers, and more. We use Oneleet for security and compliance.
Metriport provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity, or gender expression. We are committed to a diverse and inclusive workforce and welcome people from all backgrounds, experiences, perspectives, and abilities.
#J-18808-Ljbffr
A leading security training provider is seeking a Senior Security Engineer for their content engineering team. This role supports security professionals, builds hands-on content, and integrates security into DevOps. Ideal candidates have over 5 years of experience in application security and are passionate about improving security practices. The position is remote-first with competitive compensation and benefits.
#J-18808-Ljbffr
$132k-184k yearly est. 4d ago
Remote Senior AppSec Engineer: Build Secure SDLC
Blockchain Works 4.1
Remote job
ZetaChain is looking for a Sr. Application Security or DevSecOps Engineer to enhance its security program. This role is crucial for safeguarding applications in the blockchain domain. You will actively shape security strategies while gaining experience across diverse crypto risks in a vibrant and innovative environment. If you possess a strong foundation in application security and are passionate about blockchain technology, you will thrive here.
#J-18808-Ljbffr
$139k-189k yearly est. 5d ago
Staff Blockchain Security Engineer
Gemini 4.9
Remote job
About the Company
Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in over 70 countries. Our mission is to unlock the next era of financial, creative, and personal freedom by providing trusted access to the decentralized future. We envision a world where crypto reshapes the global financial system, internet, and money to create greater choice, independence, and opportunity for all - bridging traditional finance with the emerging cryptoeconomy in a way that is more open, fair, and secure. As a publicly traded company, Gemini is poised to accelerate this vision with greater scale, reach, and impact.
The Department: Application Security The Role: Staff Blockchain Security Engineer
As a member of the Application Security (AppSec) team, you will share in the responsibility of protecting the company and our customers against application security threats. The AppSec team is focused on the advancement of modern application security practices and supports the engineering organization by finding, fixing, and preventing software security vulnerabilities.
As a Staff Blockchain Security Engineer on the Application Security team focusing on blockchain security, you will work closely with on-chain engineering and product teams to provide security recommendations and identify security issues throughout the on-chain software development lifecycle. You will lead security reviews of Web3 products, integrate secure development practices into our on-chain SDLC, and develop tooling to identify, mitigate, and monitor blockchain-specific threats.
This role is required to be in person twice a week at either our San Francisco, CA or New York City, NY office.
Responsibilities
Lead in-depth security reviews of smart contracts, blockchain protocols, and Web3 applications for architectural flaws, security vulnerabilities, and best practice violations
Collaborate and advise on-chain engineering teams on Web3 security best practices and vulnerability remediation
Design and implement secure on-chain SDLC processes for on-chain product teams
Develop, maintain, and improve security tooling for blockchain ecosystems (fuzzers, static analysis, etc.)
Partner with legal, compliance, and risk teams to address security, regulatory, and operational risks of blockchain features
Minimum Qualifications
8+ years of experience in application security, Web3 security, or similar roles
Strong background in Web3 security reviews such as smart contract audits, blockchain protocols, and dApps
Ability to perform design reviews, threat modeling, secure code reviews, or penetration testing with an attacker mindset
Strong background in application security best practices and familiarity with common vulnerabilities (e.g. SSRF, race conditions, privilege escalations, etc.)
Experience with secure key management and wallet systems
Familiarity with blockchain security tools (slither, echidna, etc)
Some background in development or scripting experience (Python, Scala, C++, JavaScript, etc.)
Familiarity with and ability to understand business objectives, business context, and security risk
Strong communication skills and the ability to collaborate on a cross-functional team
Preferred Qualifications
Experience with formal verification of smart contracts
Prior experience in cryptocurrency exchanges, DeFi platforms, or NFT marketplaces
Active contributor to blockchain security communities, bug bounty programs, or published exploit research
Ability to define and execute a long-term blockchain security roadmap in partnership with engineering leadership
It Pays to Work Here
The compensation & benefits package for this role includes:
Competitive starting salary
A discretionary annual bonus
Long-term incentive in the form of a new hire equity grant
Comprehensive health plans
401K with company matching
Paid Parental Leave
Flexible time off
Salary Range
The base salary range for this role is between $168,000 - $240,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate's compensation, we consider a number of factors including skillset, experience, job scope, and current market data.
In the United States, we offer a hybrid work approach at our hub offices, balancing the benefits of in-person collaboration with the flexibility of remote work. Expectations may vary by location and role, so candidates are encouraged to connect with their recruiter to learn more about the specific policy for the role. Employees who do not live near one of our hubs are part of our remote workforce.
At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.
#J-18808-Ljbffr
$168k-240k yearly 6d ago
Application Security Engineer - SF - Hybrid Preferred, Remote O.K.
Unit21, Inc. 4.3
Remote job
San Francisco, United States | Posted on 12/16/2025
At Unit21, we believe that combating financial crime demands a united front. Through our adaptable risk engine and versatile case manager, we identify and proactively mitigate risks related to money laundering, fraud, and other illicit activities. With a simple API and no-code interface, we empower fraud fighters and AML heroes to proactively detect and prevent fraud-without tapping engineering.
Job Description About the role
As a Senior Application Security Engineer, you will be a hands‑on builder responsible for protecting our platform, our customers, and their data. This is not a governance role; you will spend your time in the code, designing and implementing the systems that secure our products from the ground up. You will own critical security infrastructure, build automations to eliminate entire classes of vulnerabilities, and serve as a deep technical expert for our engineering organization. This role is for an engineer who is passionate about security and wants to solve complex security problems at scale through high‑quality, maintainable code.
What you'll be doing:
Design, code, and deploy automated security controls, services, and frameworks to prevent vulnerabilities at scale.
Build, own, and operate the tools and infrastructure for our application security program, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and secret scanning solutions.
Perform hands‑on threat modeling, security architecture reviews, and in‑depth code reviews (Python/TypeScript) for new products and critical features to ensure they are secure by design.
Conduct penetration tests and vulnerability assessments against our applications and APIs to proactively identify and remediate security weaknesses.
Develop custom tools and automation to streamline security operations and enhance our detection and response capabilities.
Act as a key member of our incident response team during security events.
Mentor and educate product engineers on secure coding best practices, acting as a subject‑matter expert and fostering a culture of security ownership.
What we're looking for: Experience
4+ years of hands‑on experience in a software engineering or application security role, with a proven track record of shipping code and building security solutions.
Demonstrated history of successful cross‑organizational efforts and the ability to drive complex technical projects to completion.
Programming & Scripting
Expert‑level proficiency in Python, including experience building security tools, automation scripts, or backend services.
Professional experience with Go or TypeScript is a significant plus.
Security Expertise
Deep, hands‑on knowledge of common application vulnerabilities, such as the OWASP Top 10, and their mitigation techniques.
Proven experience integrating, fine‑tuning, and operating security tools (e.g., SAST, DAST, SCA) within developer workflows.
Experience conducting manual penetration tests and vulnerability assessments on web applications and APIs.
Previous experience implementing protections for Generative AI systems is a significant plus.
Hands‑on experience securing public cloud environments (AWS or GCP).
Basic proficiency with Infrastructure as Code (e.g., Terraform) and containerization technologies (e.g., Docker, ECS, or Kubernetes), including best practices for securing them.
We have a dedicated infrastructure security engineer on staff, so we're not expecting as much depth there for this role - however, you should be familiar with the basics.
Compensation
The standard base pay range for this role is $155,000.00 - $175,000.00 Annually. This base pay range does not include variable compensation including potential commissions, bonuses or other financial or equity incentives.
Unit21 is an equal opportunity employer
We encourage all to apply, even if you do not meet each requirement above. We are building a diverse, inclusive workforce and hope you will join us!
What we can offer you:
Competitive salary and pre‑IPO stock options
100% company‑paid medical, dental and vision insurance (for employee)
Optional HSA and FSA medical reimbursement accounts
Unlimited paid time off
Generous leave programs for life events
401(k)
Charity matching
One‑time Home office set‑up stipend
Wellness Bundle: One Medical, Headspace, Gympass and Carrot Fertility
Happy hours and team‑building events
Great office space in the San Francisco Financial District
Fully stocked kitchen
Lunch and dinner provided in SF office at least 3x per week
A great company culture with a strong emphasis on diversity, equity and inclusion
About Unit21
Unit21 stops bad actors by leveraging data to deliver justice and safety in the world. We protect businesses against adversaries engaging in money laundering, fraud, and other sophisticated risks by offering no‑code infrastructure to model, detect, and remediate suspicious activity. Our customers range from large Fortune 500 companies to high‑potential, pre‑launch startups. We have reported over USD $2 billion in fraud and laundered money to the US government using our software.
We are a rapidly growing Series C startup, having raised close to $100 m from Google, Tiger Global, ICONIQ Capital, Jack Dorsey, Diane Greene, and other leading VCs. Our team believes deeply in fostering individual ownership, iterative product development, and empathetic communication. There are many challenging problems to solve in this industry, and a huge opportunity for our software to empower companies to define a new standard of eliminating bad behavior on their platforms.
We encourage people of all backgrounds to apply. Unit21 is committed to creating an inclusive culture, and we celebrate diversity of all kinds.
#J-18808-Ljbffr
$155k-175k yearly 2d ago
AI Security Engineer - Red Team (United States, Remote)
Lakera Inc.
Remote job
We're looking for an AI Security Engineer to join our Red Team and help us push the boundaries of AI security. You'll lead cutting‑edge security assessments, develop novel testing methodologies, and work directly with enterprise clients to secure their AI systems. This role combines hands‑on red‑teaming, automation development, and client engagement. You'll thrive in this role if you want to be at the forefront of an emerging discipline, enjoy working on nascent problems, and like both breaking things and building processes that scale.
Key Responsibilities
This is a highly cross‑functional position. AI security is still being defined, with best practices emerging in real‑time. You'll be building the frameworks, methodologies, and tooling that scale our services while staying adaptable to rapid changes in the AI landscape. This role is ideal for someone who wants to take their traditional cybersecurity expertise and apply it to the new frontier of AI security and safety. Your focus will span several key areas:
Service Delivery & Client Engagement
Lead end‑to‑end delivery of AI red‑teaming security assessment engagements with enterprise customers
Collaborate with clients to scope projects, define testing requirements, and establish success criteria
Conduct comprehensive security assessments of AI systems, including text‑based LLM applications and multimodal agentic systems
Author detailed security assessment reports with actionable findings and remediation recommendations
Present findings and strategic recommendations to technical and executive stakeholders through report readouts
Tooling & Methodology Development
Build upon and improve our established processes and playbooks to scale AI red‑teaming service delivery
Develop frameworks to ensure consistent, high‑quality service delivery
Find the tedious, repetitive stuff and automate it - you don't need to be a world‑class developer, just someone who can build tools that make the team more effective
Research & Innovation
Develop novel red‑teaming methodologies for emerging modalities: image, video, audio, autonomous systems
Stay ahead of the latest AI security threats, attack vectors, and defense mechanisms
Translate cutting‑edge academic and industry research into practical testing approaches
Collaborate with our research and product teams to continuously level up our methodologies
Required Qualifications Technical Expertise
3+ years of experience in cybersecurity with focus on red‑teaming, penetration testing, or security assessments
Experience with web application and API penetration testing preferred
Deep understanding of LLM vulnerabilities including prompt injection, data poisoning, and jailbreaking techniques
Practical experience with threat modeling complex systems and architectures
Proficiency in developing automated tooling to enable and enhance testing capabilities, improve workflows, and deliver deeper insights
Professional Skills
Proven track record of leading client‑facing security assessment projects from scoping through delivery
Excellent technical writing skills with experience creating executive‑level security reports
Strong presentation and communication skills for diverse audiences
Experience building processes, documentation, and tooling for service delivery teams
AI Security Knowledge
Understanding of AI/ML model architectures, training processes, and deployment patterns
Familiarity with AI safety frameworks and alignment research
Knowledge of emerging AI attack surfaces including multimodal systems and AI agents
Preferred Qualifications
Relevant security certifications (OSCP, OSWA, BSCP, etc.)
Hands‑on experience performing AI red‑teaming assessments, with a strong plus for experience targeting agentic systems
Demonstrated experience designing LLM jailbreaks
Active participation in security research and tooling communities
Background in threat modeling and risk assessment frameworks
Previous speaking experience at security conferences or industry events
What You'll Gain
Opportunity to shape the future of AI security as an emerging discipline
Work with cutting‑edge AI technologies and novel attack methodologies
Lead high‑visibility projects with enterprise clients across diverse industries
Collaborate with world‑class research team pushing boundaries of AI safety
Platform to establish thought leadership in AI security community
Competitive compensation package with equity participation
❗To remove your information from our recruitment database, please email privacy@lakera.ai. #J-18808-Ljbffr
$114k-163k yearly est. 2d ago
Staff Cloud Security Engineer - Hybrid, High Impact
Jobr.Pro
Remote job
A leading transportation company is seeking a Staff Software Engineer focusing on cloud security in San Francisco. You will design and implement security measures for cloud infrastructures and lead significant projects. Candidates need a minimum of 6 years of experience in relevant fields and expertise in modern programming languages and cloud service architecture. This role includes a hybrid work schedule with benefits like comprehensive health insurance and parental leave.
#J-18808-Ljbffr
$114k-163k yearly est. 5d ago
Senior Offensive Security Engineer
Menlo Ventures
Remote job
About the role
We are seeking a Senior Security Engineer to build and lead our Offensive Security program. In this role, you will attack Chime's services, applications, and infrastructure to discover security issues and report them to our internal technology teams. This position will offer you the opportunity to grow your technical and leadership skills while being part of a collaborative and dynamic team that finds joy in problem-solving and innovating together at Chime.
The ideal candidate will be an offensive cybersecurity professional with a passion for analyzing codebases, testing hypotheses, and designing tools to impact web applications and their infrastructure. This Engineer will work closely with teams throughout InformationSecurity, as well as provide technical leadership and advice to teams and leaders throughout Chime. You will be in direct contact with teams in a variety of business verticals, giving you first hand knowledge about how Chime is built and how it operates at a deep, technical level. Additionally, you will leverage the knowledge you gain about Chime to find new ways to break services, processes, and infrastructure throughout the company.
We're a small, dedicated team that's always thinking of innovative ways to tackle challenging security problems. We take on ambitious projects that have a significant impact on our members and help build a strong security culture within our company. The team encourages discussing the problems we are solving, the methods we use, and celebrating our accomplishments through public blogs and at conferences. If these resonate with the way you work, we'd love to hear from you.
The base salary offered for this role and level of experience will begin at $157,590 and up to $218,900. Full-time employees are also eligible for a bonus, competitive equity package, and benefits. The actual base salary offered may be higher, depending on your location, skills, qualifications, and experience.
In this role, you can expect to
Independently manage complete red team exercises.
Partner with Engineering, Product, IT, and other business functions to drive security improvement across the organization
Research emerging attack vectors, vulnerabilities and techniques
Utilize your offensive skills to identify weaknesses and build defenses against those who may point their attacks at Chime
Develop custom payloads and exploits
Emulate adversaries like cybercriminals and insider threats by attacking web applications, cloud platforms and supporting services(Kubernetes / Container Orchestration platforms etc.)
Collaborate closely with detection engineers to build high fidelity alerting based on emerging attack vectors and tactics, techniques and procedures
Participate in purple-team exercises to mature the security program
What are we looking for
4+ years of combined experience in either an offensive security, red teaming, or application security role.
Experience in conducting surreptitious cloud based attacks
Experience with developing custom tools and payloads which bypass defensive products, and remain undetected in a mature network environment
Ability to perform unsupervised red team engagements and experience with performing adversarial simulation
Ability to explain vulnerabilities and weaknesses to non-technical stakeholders
(Nice to have) Relevant certifications: OSCP (Offensive Security Certified Professional), OSCE (Offensive Security Certified Expert) and OSEE (Offensive Security Exploitation Expert), Certified Red Team Operator (CRTO), GIAC Red Team Professional certification (GRTP)
#LI-Hybrid #LI-JC1
A little about us
At Chime, we believe that everyone can achieve financial progress. We created Chime-a financial technology company, not a bank*-on the premise that core banking services should be helpful, easy, and free. Through our user-friendly tools and intuitive platforms, we empower our members to take control of their finances and work towards their goals. Whether it's starting a savings account, purchasing a first car or home, launching a business, or pursuing higher education, we're proud to have helped millions unlock their financial potential.
We're a team of problem solvers, dreamers, and builders with one shared obsession: our members. From day one, Chimers have worked tirelessly to out-hustle and out-execute competitors to bring our mission to life. Their grit and determination inspire us to work harder every day to deliver the very best experience possible. We each bring an owner's mindset to our work, refusing to be outdone and holding ourselves accountable to meet and exceed the highest bars for our teams, our company, and our members.
We believe in being bold, dreaming big, and taking risks, while also working together, embracing our diverse perspectives, and giving each other honest feedback. Our culture remains deeply entrepreneurial, encouraging every Chimer to see themselves as stewards of our mission to help everyday Americans unlock their financial progress.
We know that to achieve our mission, we must earn and keep people's trust-so we hold ourselves to the highest standards of integrity in everything we do. These aren't just words on a wall-our values are embedded in every aspect of our business, serving as a north star that guides us as we work to help millions achieve their financial potential.
Because if we don't-who will?
*Chime is a financial technology company, not a bank. Banking services provided by The Bancorp Bank, N.A. or Stride Bank, N.A., Members FDIC.
What we offer for our full-time, regular employees
Our in-office work policy is designed to keep you connected - with four days a week in the office and Fridays from home for those near one of our offices, plus team and company-wide events depending on location. Whether you're coming in regularly or are part of our fully remote program, you'll stay engaged with your work and teammates.**
In-office perks including backup child, elder, and/or pet care, plus a subsidized commuter benefit to support your regular commute**
Competitive salary based on experience**
401k match** plus great medical, dental, vision, life, and disability benefits
Generous vacation policy and company-wide Chime Days, bonus company-wide paid days off**
???? 1% of your time off to support local community organizations of your choice
Annual wellness stipend to use towards eligible wellness related expenses
Up to 24 weeks of paid parental leave for birthing parents and 12 weeks of paid parental leave for non-birthing parents
Access to Maven, a family planning tool, with $15k lifetime reimbursement for egg freezing, fertility treatments, adoption, and more.
In-person and virtual events to connect with your fellow Chimers-think cooking classes, guided meditations, music festivals, mixology classes, paint nights, etc., and delicious snack boxes, too!**
A challenging and fulfilling opportunity to join one of the most experienced teams in FinTech and help millions unlock financial progress**
**Perks also available to Chime Interns.
We know that great work can't be done without a diverse team and inclusive environment. That's why we specifically look for individuals of varying strengths, skills, backgrounds, and ideas to join our team. We believe this gives us a competitive advantage to better serve our members and helps us all grow as Chimers and individuals.
Chime is proud to be an Equal Opportunity Employer. We consider qualified applicants without regard to race, color, ancestry, religion, sex, national origin, sexual orientation, gender identity, age, marital or family status, disability, genetic information, veteran status, or any other legally protected basis under provincial, federal, state, and local laws, regulations, or ordinances. We will also consider qualified applicants with criminal histories in a manner consistent with the requirements of state and local laws, including the San Francisco Fair Chance Ordinance, Cook County Ordinance, NYC Fair Chance Act, and the LA City Fair Chance Ordinance, and consistent with Canadian provincial and federal laws. If you have a disability or special need that requires accommodation during any stage of the application process, please contact: ******************.
To learn more about how Chime collects and uses your personal information during the application process, please see the Chime Applicant Privacy Notice.
#J-18808-Ljbffr
A leading AI research company in San Francisco is hiring a Security Engineer, specializing in application security. Responsibilities include conducting security assessments, developing security tools, and collaborating with development teams to integrate security best practices throughout the software development lifecycle. The ideal candidate has extensive experience in cybersecurity and strong programming skills. This role offers a hybrid work model with relocation assistance.
#J-18808-Ljbffr
$125k-175k yearly est. 5d ago
Information Security Engineer
Unilin 4.6
Remote job
Within our Unilin Infrastructure team, we are looking for an InformationSecurity Engineer with strong technical expertise, entrepreneurship and a passion for applying innovative technology to strengthen our Unilin Group's cybersecurity posture.
You will be part of the Unilin InformationSecurity team, part of the global Mohawk cybersecurity organization, giving you exposure to international operations and standards. You will be working with leading security platforms andwill have a wide variety of responsibilities including incident management, vulnerability management, security assessments, awareness initiatives and several security projects.
As Informationsecurity engineer, you will:
Enhance and maintain cybersecurity operations processes, identifying gaps, analyzing trends, and recommending improvements to strengthen detection, response, and prevention capabilities.
Support incident management activities by assisting with investigations, coordinating mitigation efforts with the MDR partner, and ensuring that procedures are followed correctly to minimize business impact.
Maintain strong technical expertise in key platforms used across the environment, such as Palo Alto Cortex XDR, SIEM, and Tanium.
Contribute to the vulnerability management programme, including scanning, prioritization, and coordination of remediation efforts with IT and OT teams.
Support cybersecurity assessments, assisting with internal vulnerability assessments, penetration testing, and cyber exercises.
Contribute to cybersecurity awareness and training initiatives through the KnowBe4 platform, helping to strengthen the organization's overall security culture.
Lead or support cybersecurity projects that enhance the overall security posture of the Unilin Group
Who are you?
Bachelor's or Master's degree in IT, Computer Science, Engineering, or equivalent practical experience.
At least 5 years of experience in cybersecurity operations, system administration, or incident response.
Proven expertise in network and endpoint security and threat analysis.
Experience with tools such as Cortex XDR, Tanium, or Prisma is an advantage.
Strong analytical skills with a solution-oriented, hands-on mindset.
Independent and self-motivated, able to manage tasks and projects autonomously.
Proficient in English and Dutch; knowledge of French is a plus.
What can you expect?
A competitive remuneration package.
An extensive leave system and a flexible work schedule with the option of home working.
Luncheon vouchers, hospitalisation and group insurance.
Possibility of bike leasing.
We invest in your development and we believe in lifelong learning. In our state-of-the-art training centre The Dive you are bound to find training courses that will help you grow.
Countless possibilities to build your career.
An employer with a transparent sustainability strategy (for our planet, customers and employees).
In different locations we have a company restaurant with a varied menu.
Benefit from attractive discounts on our products.
Child care is an option during a number of school holidays.
Make the most of discounts at a number of partners through our Benefits at Work platform.
You will often find us at sporting events. You and your family can participate for free.
In short, you'll be working for a Top Employer!
Who are we?
Unilin is a global reference in interior design and construction with a strong focus on sustainability and innovation. Our floors, panels, insulation materials, and technologies can be found in the homes and workplaces of millions of people and public spaces around the world. Our brands Quick-Step, Pergo, and Moduleo probably ring a bell. Worldwide, around 7,900 employees work every day to push boundaries and innovate. Want to know more about our story? Be sure to check out our website.
#J-18808-Ljbffr
$100k-145k yearly est. 2d ago
AI Security Engineer, Enterprise (Hybrid)
Docusign, Inc. 4.4
Remote job
A leading e-signature company is looking for an AI Enterprise Security Engineer to design and implement security solutions for AI/ML tools. This role involves developing security strategies, conducting risk assessments, and ensuring compliance with regulations. Applicants should have over 5 years of security experience and strong knowledge of AI/ML concepts. The position allows for hybrid work arrangements, promoting a collaborative environment. Join the team and contribute to secure AI initiatives that support business objectives.
#J-18808-Ljbffr
$143k-194k yearly est. 2d ago
Learn more about information security analyst jobs
Work from home and remote information security analyst jobs
Nowadays, it seems that many people would prefer to work from home over going into the office every day. With remote work becoming a more viable option, especially for information security analysts, we decided to look into what the best options are based on salary and industry. In addition, we scoured over millions of job listings to find all the best remote jobs for an information security analyst so that you can skip the commute and stay home with Fido.
We also looked into what type of skills might be useful for you to have in order to get that job offer. We found that information security analyst remote jobs require these skills:
Incident response
Risk assessments
Windows
Siem
Data loss prevention
We didn't just stop at finding the best skills. We also found the best remote employers that you're going to want to apply to. The best remote employers for an information security analyst include:
Since you're already searching for a remote job, you might as well find jobs that pay well because you should never have to settle. We found the industries that will pay you the most as an information security analyst:
Professional
Finance
Technology
Top companies hiring information security analysts for remote work
Most common employers for information security analyst