Security Engineer Remote Jobs

28 Results

19d

Security Engineer

Master’s DegreeBachelor's degreeazurec++AWS

Abarca Health is hiring a Remote Security Engineer

What you’ll do

In a few words…

Abarca is igniting a revolution in healthcare.  We built our company on the belief that with smarter technology we are redefining pharmacy benefits, but this is just the beginning…

Our Infrastructure Operations team is critical for success at Abarca Health. They handle the days in and days out of the entire architecture of our systems from data processing to server updates and stability. The Information Security team's focus is to monitor, detect, investigate and respond to events that could lead to incidents. They are involved in planning and implementing preventative security measures and oversee the security operations, which includes protecting IT infrastructure, networks, data, edge devices and identify any exploitation, whether accidental or intentional.

The Security Engineer is a key member of the security team, which is instrumental in ensuring the security of our cloud infrastructure and protection of our sensitive data: PHI & PII data, per our information security policy. In this role, you shall help identify security gaps and drive remediation activities to close those gaps. You’ll play an integral role in defining and assessing the organization's security strategy, architecture, and practices as well as contributes to maturing the company's infrastructure security architecture and technology frameworks.

The fundamentals for the job…

  • Drive security related initiatives including but not limited to the creation and maintenance of security policies, implementation of security procedures and controls, and monitoring in conformance to the policy.
  • Deploy and manage applications to monitor cloud infrastructure security and intrusions.
  • Perform initial incident triage, determine scope, urgency, and potential impact of security incidents.
  • Provide guidance external auditors on compliance and to Engineering teams on security measures.
  • Perform security gap assessments and implement remediations.
  • Run periodic infrastructure vulnerability scans and pen testing and work with engineering teams on identified vulnerabilities for resolution.
  • Collaborate with network and infrastructure teams on securing and best practices for all our Azure, IBM Cloud, and on premises environments, as well as OS hardening, access logging, and patching.
  • Own the overall cloud infrastructure security program including driving incident response and resolution and adjust procedures as applicable.
  • Monitor industry security updates, changes, technologies, emerging threats, and best practices for continuous improvement.

What we expect of you 

The bold requirements…

  • Bachelors Degree or Master’s Degree in Computer Science, Information Security, or a related area. (In lieu of a degree, equivalent relevant experience may be considered.)
  • 3+ years of experience in Infrastructure and Information Security.
  • 3+ years working on Azure or AWS running multiple production workloads.
  • Experience with OS hardening techniques for Windows environments.
  • Experience with access logging, centralized logging, and monitoring/alerting of security log events.
  • Experience with applications for monitoring infrastructure security and detecting intrusions.
  • Experience designing and implementing access control models for privileged access in fast-paced cloud environments.
  • Experience with incident response, threat modeling, and mitigation, as well as common information security management frameworks such as ISO27001.
  • Experience with Azure security best practices and security controls using Azure services (AWS experience will be considered).
  • Experience with common internet protocols such as DNS, DHCP, SMTP, LDAP, etc.
  • Excellent oral and written communication skills.
  • We are proud to offer a flexible hybrid work model which will require certain on-site work days (Puerto Rico Location Only)

Nice to haves…

  • Security-related certification such as CISSP, CCSP, CEH, CISM, etc.
  • Experience with HCI technology.
  • Experience with OS hardening techniques for Linux.

Physical requirements…

  • Must be able to access and navigate each department at the organization’s facilities.
  • Sedentary work that primarily involves sitting/standing.

At Abarca we value and celebrate diversity. Diversity, equity, inclusion, and belonging are guiding principles of Abarca and ensure Abarca’s workforce reflects the communities it serves.  We are proud to provide equal employment opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, medical condition, genetic information, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

Abarca Health LLC is an equal employment opportunity employer and participates in E-Verify.  “Applicant must be a United States’ citizen. Abarca Health LLC does not sponsor employment visas at this time”

The above description is not intended to limit the scope of the job or to exclude other duties not mentioned. It is not a final set of specifications for the position. It’s simply meant to give readers an idea of what the role entails.

#LI-MH1 #LI-REMOTE

See more jobs at Abarca Health

Apply for this job

Databricks is hiring a Remote Senior Security Engineer (Incident Response)

Job Application for Senior Security Engineer (Incident Response) at Databricks

See more jobs at Databricks

Apply for this job

22d

Associate Security Engineer

TenableRemote, United States
azureapidockerpythonAWS

Tenable is hiring a Remote Associate Security Engineer

Description

Who is Tenable?

Tenable® is the Exposure Management company. 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 60 percent of the Fortune 500, 40 percent of the Global 2000, and large government agencies. Come be part of our journey! 

What makes Tenable such a great place to work? 

Ask a member of our team and they’ll answer, “Our people!” We work together to build and innovate best-in-class cybersecurity solutions for our customers; all while creating a culture of belonging, respect, and excellence where we can be our best selves. When you’re part of our #OneTenable team, you can expect to partner with some of the most talented and passionate people in the industry, and have the support and resources you need to do work that truly matters. We deliver results that exceed expectations and we win together!

Your Role:

Tenable is currently seeking an Associate Security Sales Engineer to support product demos and evaluations of small and medium sized sales opportunities. The Associate Security Sales Engineer is responsible for identifying and matching technology opportunities with the customer’s business issues and objectives. Assist in developing business value propositions around Tenable products and solutions. Drives sales with technical expertise, account management skills, sales ability, and a superior customer focus. 

Your Opportunity:

  • Become a Cyber Exposure, Vulnerability and Risk Management Subject Matter Expert and advisor to some of the world’s largest organizations
  • Meet with prospective clients to discover what their biggest security challenges and highest priority business drivers are
  • Map Tenable’s unique business value and differentiators to their challenges and business drivers
  • Perform custom portfolio demonstrations based on strong discovery questions and real intel
  • Partner with like-minded peers across Tenable to build exceptionally strong teams and shared knowledge
  • Influence product directions, make a difference, and be part of Tenable’s growth and leadership in the ever faster moving world of cyber exposure

What You'll Need:

  • Prior experience working in a security related technical pre-sales role
  • Understanding how to craft a custom demo vs delivering a canned demo
  • Skill and confidence in leading discussions from a deep technical level to the executive level
  • A strong self-starter attitude and determination to win
  • Solid teamwork skills, teamwork is everything at Tenable
  • Solid Interpersonal “smarts”
  • Willingness to travel where and when needed within your territory, typically around 10% on average

And Ideally:

  • Experience with Nessus and/or other network security technologies
  • Solid foundational knowledge of TCP/IP and network security concepts
  • Experience with Enterprise class operating systems at the security admin level
  • Demonstrable experience with modern compute infrastructures such as AWS, Azure, GCP, etc.
  • Docker and DevOps knowledge, API scripting, Python SDK would be a ++
  • Knowledge of compliance standards (e.g., PCI, NIST, FISMA, SOX, NERC)
  • BS in Computer Science or a related field or equivalent experience (i.e. 4+ years of direct SE experience)
  • CISSP, GIAC, CEH, Security+ or other security-related certifications

If you’ve reached this point, and you’re still not sure if you should apply…..Just do it! We’re human and we don’t fit a perfect mold. Having diverse backgrounds, experiences and perspectives, that’s a good thing! If you’re coming from outside of the cyber industry - great! If you’re looking to try something new - awesome! All we ask is you bring passion to all that you do, crave creativity and innovation, and embrace the hard work of gaining new skills and accepting big challenges.

We’re committed to promoting Equal Employment Opportunity (EEO) at Tenable - through all equal employment opportunity laws and regulations at the international, federal, state and local levels.

The base salary range for this position is $79,000.00 - $105,000.00 USD.  Compensation for the role will depend on a number of factors, including the candidate's qualifications, skills, competencies, location and experience, and may fall outside of the range shown.   Employees are also eligible for variable compensation in addition to base pay (commission for sales roles, bonus for non-sales roles), depending on company and individual performance.  Tenable also offers a variety of comprehensive and competitive benefits which include: medical, dental, vision, disability and life insurance; 401(k) retirement savings with company match; an employee stock purchase plan; an employee referral program; flexible spending accounts; an Employee Assistance Program (EAP); education assistance; parental leave; paid time off (PTO); company-paid holidays; health and wellness events; and community programs.

See more jobs at Tenable

Apply for this job

25d

Engineer, Network Security

BrightspeedCharlotte, NC, Remote
Designazure

Brightspeed is hiring a Remote Engineer, Network Security

Job Description

We are looking for an Engineer, Network Security to join our growing team. In this role, you will report directly to the Manager, Network Security. This SME role entails safeguarding all networks, including internal, customer-facing, and Telcom networks. You will actively engage in day-to-day security engineering and operations, serving as a technical authority in network security and possessing a deep understanding of security architecture. You will collaborate closely with IT and Network; and also contribute to diverse projects, demonstrating strong interpersonal skills to cultivate inter-organizational relationships. You will have effective management of project activities, including milestones and timelines, is also expected.

The primary functions of the Network Security Team include:

  • Design, deploy, configure, and maintain Palo Alto firewalls
  • Manage and administer Azure and GCP firewalls
  • Conduct regular reviews and audits of firewall configurations
  • Design, implement, and maintain DDoS mitigation solutions
  • Management of network authentication technologies like RADIUS and TACACS+
  • Manage network protection technologies like IDS and Honeypots

This position requires a strong background and understanding of all network and cloud security domains and works in both the Protect and Respond areas of the NIST CSF Framework. You will be required to make strong cyber security decisions while using a business risk analysis approach. Brightspeed is a cloud-first (Azure, GCP, and SaaS) company with a significant data center presence. This model will require you to consider security across a diverse portfolio of assets and networks. Brightspeed is also in a Zero Trust journey, which means the individual should be able to execute a multi-year program while ensuring network security and moving along the maturity curve. 

As an Engineer, Network Security, your duties and responsibilities will include:

  • Design, implement, and lead the comprehensive enterprise cybersecurity network protection programs, leveraging advanced expertise in Palo Alto firewalls
  • Conduct thorough reviews and design meticulous firewall rules to ensure strict adherence to corporate security policies
  • Design, review, and execute robust network security solutions aimed at safeguarding the integrity of Brightspeed networks
  • Serve as the SME of the Network Security team, accountable for ensuring the overall security posture of Brightspeed networks. This includes spearheading device hardening initiatives, monitoring baseline configurations, meeting compliance standards, implementing security best practices, and overseeing remediation efforts.
  • Assume ownership of all network protection applications and platforms, overseeing their management, upgrades, configurations, changes, and support
  • Collaborate closely with the SOC and incident response teams to effectively resolve network security incidents
  • Document, implement, and maintain all network security devices to uphold robust security standards while developing and implementing appropriate strategies for information security policies, standards, and procedures
  • Engage proactively in organizational projects as needed, offering valuable insights and specialized expertise in network security domains
  • Demonstrate exceptional interpersonal skills, including strong verbal and written communication abilities, enabling effective collaboration with diverse stakeholders
  • Oversee the management of the enterprise's Network Security Systems, encompassing Firewalls (including cloud firewalls), DDOS mitigations, RADIUS, and TACACS+ authentication support
    Participate in an on-call rotation to ensure 24/7 coverage of network security operations
  • Stay current on emerging cybersecurity threat landscape, vulnerabilities, and trends, and recommend proactive measures to enhance our security posture
  • Foster a culture of mentorship by guiding Network Security Analysts and actively participating in knowledge-sharing initiatives

Qualifications

WHAT IT TAKES TO CATCH OUR EYE:

  • Bachelor’s degree in Computer Science, Engineering, Cyber Security, or related field
  • Demonstrated expertise with firewall management and architecture spanning over 5+ years, with expertise in Palo Alto firewalls
  • Extensive background encompassing over 5+ years of hands-on experience in the Network Security field with versatility across various domains of network security
  • Proficiency in network security hardening methodologies
  • Experience in securing Office 365, Azure AD, and Email is essential
  • Proficiency with TACACS+, RADIUS, and DDOS mitigations
  • Ability to thrive in a fast-paced environment with multiple competing priorities
  • Meticulous attention to detail to ensure adherence to policies and standard procedures
  • Proven expertise in implementing security measures within GCP and Azure environments
  • Exceptional verbal and written communication skills
  • Proficient in TCP/IP routing and switching, as well as network design best practices
  • Experience in mitigating DDoS attacks, coupled with proficiency in DDoS attack defense, countermeasures, and packet analysis
  • Moderate understanding of BGP, OSPF, Switching topologies, and Cloud networking
  • Familiarity with zero-trust architectures is advantageous
  • Knowledge of incident response procedures is advantageous
  • Scripting experience is beneficial

BONUS POINTS FOR:

  • Palo Alto Networks Certified Network Security Engineer (PCNSE)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Ethical Hacker (CEH)

 

#LI-SS1

See more jobs at Brightspeed

Apply for this job

27d

Senior Security Engineer I

SamsaraRemote - US
slack

Samsara is hiring a Remote Senior Security Engineer I

Who we are

Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, which is a platform that enables organizations that depend on physical operations to harness Internet of Things (IoT) data to develop actionable insights and improve their operations. At Samsara, we are helping improve the safety, efficiency and sustainability of the physical operations that power our global economy. Representing more than 40% of global GDP, these industries are the infrastructure of our planet, including agriculture, construction, field services, transportation, and manufacturing — and we are excited to help digitally transform their operations at scale.

Working at Samsara means you’ll help define the future of physical operations and be on a team that’s shaping an exciting array of product solutions, including Video-Based Safety, Vehicle Telematics, Apps and Driver Workflows, Equipment Monitoring, and Site Visibility. As part of a recently public company, you’ll have the autonomy and support to make an impact as we build for the long term. 

Recent awards we’ve won include:

Glassdoor's Best Places to Work 2024

Best Places to Work by Built In 2024

Great Place To Work Certified™ 2023

Fast Company's Best Workplaces for Innovators 2023

Financial Times The Americas’ Fastest Growing Companies 2023

We see a profound opportunity for data to improve the safety, efficiency, and sustainability of operations, and hope you consider joining us on this exciting journey. 

Click hereto learn more about Samsara's cultural philosophy.

About the role:

The Senior Security Engineer - Enterprise Security is responsible for building, operating, and maintaining Samsara’s core security infrastructure. Reporting to the Manager of Enterprise Security, you will collaborate with a global team of engineers to build a world-class security engineering program utilizing modern principles across corporate and product infrastructure.

You take security seriously and strive to build low-friction solutions developed in close partnership with others. You are passionate about building automation and helping to drive insights around potentially malicious activity within production environments. You will use your familiarity with a diverse set of technologies and practices to build a leading program in our industry.

You should apply if:

  • You want to impact the industries that run our world: Your efforts will result in real-world impact—helping to keep the lights on, get food into grocery stores, reduce emissions, and most importantly, ensure workers return home safely.
  • You are the architect of your own career: If you put in the work, this role won’t be your last at Samsara. We set up our employees for success and have built a culture that encourages rapid career development, countless opportunities to experiment and master your craft in a hyper growth environment.
  • You’re energized by our opportunity: The vision we have to digitize large sectors of the global economy requires your full focus and best efforts to bring forth creative, ambitious ideas for our customers.
  • You want to be with the best: At Samsara, we win together, celebrate together and support each other. You will be surrounded by a high-caliber team that will encourage you to do your best. 

Click hereto learn more about Samsara's cultural philosophy. 

In this role, you will: 

  • Contribute to the development, deployment, and management of Samsara’s enterprise security program, including endpoint detection and response, vulnerability management, device trust, and SaaS posture management.
  • Be responsible for one or more key security systems or processes, working directly with stakeholders and vendors to ensure seamless integration and operation.
  • Write documentation and runbooks around key enterprise security needs.
  • Collaborate with Security Operations to provide subject matter expertise around security investigations and incident management.
  • Champion, role model, and embed Samsara’s cultural principles (Focus on Customer Success, Build for the Long Term, Adopt a Growth Mindset, Be Inclusive, Win as a Team) as we scale globally and across new offices

Minimum requirements for the role:

  • Significant (4+ years) experience working in enterprise security in the technology sector with demonstrated impact and career progression
  • Deep subject matter expertise within enterprise security, such as extensive experience managing endpoint security toolsets, device trust efforts, email security tooling, secure access service edge delivery, or SaaS posture and security
  • Proven history of planning and delivering high-impact, complex projects with clarity and independence
  • Willingness to collaborate and mentor more junior team members and cross-functional partners, including via documentation writing, code pairing, and other activities.

An ideal candidate also has:

  • Experience building out security programs using modern SaaS platforms such as Zscaler, Crowdstrike, Wiz, Splunk, and other tools.
  • Experience with securing common SaaS productivity tools such as Google Workspace, Slack, and Atlassian products in an enterprise environment.

Samsara’s Compensation Philosophy:Samsara’s compensation program is designed to deliver Total Direct Compensation (based on role, level, and geography) that is at or above market. We do this through our base salary + bonus/variable + restricted stock unit awards (RSUs) for eligible roles.  For eligible roles, a new hire RSU award may be awarded at the time of hire, and additional RSU refresh grants may be awarded annually. 

We pay for performance, and top performers in eligible roles may receive above-market equity refresh awards which allow employees to achieve higher market positioning.

The range of annual base salary for full-time employees for this position is below. Please note that base pay offered may vary depending on factors including your city of residence, job-related knowledge, skills, and experience.
$135,482$227,700 USD

At Samsara, we welcome everyone regardless of their background. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, protected veteran status, disability, age, and other characteristics protected by law. We depend on the unique approaches of our team members to help us solve complex problems. We are committed to increasing diversity across our team and ensuring that Samsara is a place where people from all backgrounds can make an impact.

Benefits

Full time employees receive a competitive total compensation package along with employee-led remote and flexible working, health benefits, Samsara for Good charity fund, and much, much more. Take a look at our Benefits site to learn more.

Accommodations 

Samsara is an inclusive work environment, and we are committed to ensuring equal opportunity in employment for qualified persons with disabilities. Please email accessibleinterviewing@samsara.com or click hereif you require any reasonable accommodations throughout the recruiting process.

Flexible Working 

At Samsara, we embrace a flexible working model that caters to the diverse needs of our teams. Our offices are open for those who prefer to work in-person and we also support remote work where it aligns with our operational requirements. For certain positions, being close to one of our offices or within a specific geographic area is important to facilitate collaboration, access to resources, or alignment with our service regions. In these cases, the job description will clearly indicate any working location requirements. Our goal is to ensure that all members of our team can contribute effectively, whether they are working on-site, in a hybrid model, or fully remotely. All offers of employment are contingent upon an individual’s ability to secure and maintain the legal right to work at the company and in the specified work location, if applicable.

Fraudulent Employment Offers

Samsara is aware of scams involving fake job interviews and offers. Please know we do not charge fees to applicants at any stage of the hiring process. Official communication about your application will only come from emails ending in ‘@samsara.com’ or ‘@us-greenhouse-mail.io’. For more information regarding fraudulent employment offers, please visit our blog post here.

Apply for this job

27d

Offensive Security Engineer

SquareSan Francisco, CA, Remote
azurerubylinuxpythonAWS

Square is hiring a Remote Offensive Security Engineer

Job Description

Block’s Offensive Security team is seeking a highly skilled and motivated Senior Offensive Security Engineer to join our team. In this role, you will play a critical role in proactively identifying and exploiting vulnerabilities within our systems and infrastructure, mimicking real-world attacker tactics. Your insights will be used to improve our overall security posture and ensure we stay ahead of evolving threats.

You will:

  • Lead and execute complex Red Team engagements, simulating real-world attacker scenarios to uncover critical vulnerabilities across our network and applications.
  • Identify, research, and exploit various vulnerabilities (including zero-days) to gain unauthorized access to systems and data.
  • Develop custom tools, scripts, and exploit code.
  • Document findings in a clear, concise, and actionable manner, including detailed reports with working proofs of concept and recommendations for remediation.
  • Collaborate with the Blue Team and security leadership to prioritize vulnerabilities, develop mitigation strategies, and improve overall security posture.
  • Participate in knowledge sharing by mentoring junior team members and presenting findings, including opportunities to present at external conferences.

Qualifications

You have:

  • Minimum 5+ years of experience in offensive security engagements.
  • Proven experience leading and executing Red Team engagements.
  • Expertise in various operating systems (Mac, Linux, etc.) and scripting languages (Python, Ruby, etc.).
  • Experience with exploit development and post-exploitation techniques.
  • Excellent communication, collaboration, and problem-solving skills.
  • Ability to work independently and manage multiple projects simultaneously.
  • Strong understanding of the threat landscape and attacker motivations.

Bonus points for:

  • Experience with responsible disclosure and publicly reported CVEs.
  • Experience in a cloud environment (AWS, Azure, GCP).
  • Experience in using C2s and developing and deploying custom C2 and implants.

See more jobs at Square

Apply for this job

29d

Staff Security Engineer - Detection and Response

FastlyUS (Remote)
agileDesignrubyc++linuxpythonAWS

Fastly is hiring a Remote Staff Security Engineer - Detection and Response

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and securing our customers’ applications as close to their end-users as possible — at the edge of the Internet. The platform is designed to take advantage of the modern internet, to be programmable, and to support agile software development. Fastly’s customers include many of the world’s most prominent companies, including Vimeo, Pinterest, The New York Times, and GitHub.

We're building a more trustworthy Internet. Come join us.

As a Staff Security Engineer on our Detection and Response team, you will help detect and respond to threats for one of the biggest online platforms in the world that handles massive amounts of traffic at very low latency.

We are looking for a teammate with expertise in both security engineering and operations and that values the complement between the two. You will have the opportunity to build and integrate tooling and detections, as well as investigate threats and lead incidents. As part of the larger Security organization, we make risk-informed decisions and prioritize automations to help us scale. As the lead engineer on our team, you will design, build, and mature our detection and response program, enabling rapid detection and effective response to threats against Fastly. You will lead large, complex, cross-team projects and mentor other security engineers on our growing team. 

What You'll Do:

  • Lead the design and implementation of a robust Detection Engineering program
  • Develop detections and other analytics to identify threats across cloud, corporate, and edge environments
  • Partner closely with Engineering, Security Architecture, Risk Management, Compliance, and other teams to prioritize detections and delivery of other security initiatives
  • Triage and investigate security threats and lead security incidents
  • Research, evaluate, implement, and maintain a variety of custom and commercial security tools, such as Endpoint Detection and Response (EDR), anti-phishing, and Security Information and Event Monitoring (SIEM)
  • Develop strategies, frameworks, designs, automations, metrics, and processes to support the maturity of the Detection and Response program
  • Develop and maintain incident response playbooks and other detection and response documentation
  • Conduct threat hunts to discover unknown malicious activity across our environment
  • Participate in our on-call rotations
  • Mentor other team members and contribute to larger Security initiatives

What We're Looking For: 

At Fastly we value a diversity of voices. The following is not a laundry list, but to be effective in this role you should possess most of the following and an interest in learning more about the rest:

  • Expertise in utilizing Splunk to include investigating threats, developing metrics and dashboards, normalizing data feeds, and integrating with other tools
  • Strong understanding of attacker tactics, techniques, and procedures (TTPs) and investigating advanced threats
  • Experience in implementing “Detection as Code”
  • Experience in securing, developing detections, and responding to incidents in one major public cloud infrastructure, such as Amazon Web Services (AWS) or Google Cloud Platform (GCP)
  • Experience in effectively leading large and complex security incidents from detection to remediation
  • Familiarity with modern security frameworks and best practices, such as the MITRE ATT&CK framework and NIST CSF
  • Proficiency in one or more general purpose programming languages such as Python, Ruby, Go, or Rust
  • Experience with Linux administration at scale, associated intrusion/manipulation techniques, and standard methodologies for system hardening and process isolation

We’ll be super impressed if you have experience in any of these: 

  • Built a Detection Engineering pipeline
  • Built and led threat hunts
  • Published research on detection engineering or threat intelligence
  • Developed automations to improve security operations
  • Familiarity with content delivery networks (CDN), edge cloud platforms, or other Fastly products and services

Work Hours:

  • This position will require you to be available during core business hours. 

Work Locations & Travel Requirements: 

This position is open to both hybrid and remote. 

The preferred locations for this position are:

  • San Francisco, CA
  • Los Angeles, CA
  • Denver, CO
  • New York City, NY 

Fastly currently embraces a largely hybrid model for most roles which allows employees flexibility to split their time between the office and home.  

We are willing to consider remote candidates in US (Remote).

This position may require travel as required by your role or requested by your manager.

Salary: 

The estimated salary range for this position is $167,790 to $209,740.

Starting salary may vary based on permissible, non-discriminatory factors such as experience, skills, qualifications, and location.

This role may be eligible to participate in Fastly’s equity and discretionary bonus programs.

Benefits: 

We care about you. Fastly works hard to create a positive environment for our employees, and we think your life outside of work is important too. We support our teams with great benefits that start on the first day of your employment with Fastly. Curious about our offerings? 

We offer a comprehensive benefits package including medical, dental, and vision insurance. Family planning, mental health support along with Employee Assistance Program, Insurance (Life, Disability, and Accident), a non-accrual vacation policy and up to 18 days of accrued paid sick leave are there to help support our employees. We also offer 401(k) (including company match) and an Employee Stock Purchase Program. For 2024, we offer 10 paid local holidays, 11 paid company wellness days. 

Why Fastly?

  • We have a huge impact. Fastly is a small company with a big reach. Not only do our customers have a tremendous user base, but we also support a growing number of open source projects and initiatives. Outside of code, employees are encouraged to share causes close to their heart with others so we can help lend a supportive hand.

  • We love distributed teams. Fastly’s home-base is in San Francisco, but we have multiple offices and employees sprinkled around the globe. As a new hire, you will be able to attend our IN-PERSON new hire orientation in our San Francisco office! It is an exciting week-long experience that we offer to new employees to build connections with colleagues across Fastly, participate in hands-on learning opportunities, and immerse yourself in our culture firsthand. 

  • We value diversity. Growing and maintaining our inclusive and diverse team matters to us. We are committed to being a company where our employees feel comfortable bringing their authentic selves to work and have the ability to be successful -- every day.

  • We are passionate. Fastly is chock full of passionate people and we’re not ‘one size fits all’. Fastly employs authors, pilots, skiers, parents (of humans and animals), makeup geeks, coffee connoisseurs, and more. We love employees for who they are and what they are passionate about.

We’re always looking for humble, sharp, and creative folks to join the Fastly team. If you think you might be a fit please apply!A fully completed application and resume or CV are required when applying.

Fastly is committed to ensuring equal employment opportunity and to providing employees with a safe and welcoming work environment free of discrimination and harassment. Our employment decisions are based on business needs, job requirements and individual qualifications.All qualified applicants will receive consideration for employment without regard to age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, family or parental status, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances.

Consistent with the Americans with Disabilities Act (ADA) and federal or state disability laws, Fastly will provide reasonable accommodations for applicants and employees with disabilities. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact your Recruiter, or the Fastly Employee Relations team atcandidateaccommodations@fastly.comor 501-287-4901. 

Fastly collects and processes personal data submitted by job applicants in accordance with our Privacy Policy. Please see our privacy notice for job applicants.

See more jobs at Fastly

Apply for this job

+30d

Splunk Security Engineer

2 years of experienceDesignazureAWS

BlueVoyant is hiring a Remote Splunk Security Engineer

Splunk Security Engineer - BlueVoyant - Career Page
+30d

Senior Enterprise Security Engineer

WebflowU.S. Remote
remote-firstDesignc++

Webflow is hiring a Remote Senior Enterprise Security Engineer

At Webflow, our mission is to bring development superpowers to everyone. Webflow is the leading visual development platform for building powerful websites without writing code. By combining modern web development technologies into one platform, Webflow enables people to build websites visually, saving engineering time, while clean code seamlessly generates in the background. From independent designers and creative agencies to Fortune 500 companies, millions worldwide use Webflow to be more nimble, creative, and collaborative. It’s the web, made better. 

We’re looking for a Senior Enterprise Security Engineer on Webflow's new Security and Compliance team, you will work with the Director of Product Security to help us meet current and future product security needs.

About the role 

  • Location: Remote-first (United States; BC & ON, Canada) 
  • Full-time 
  • Permanent
  • Exempt 
  • The cash compensation for this role is tailored to align with the cost of labor in different geographic markets. We've structured the base pay ranges for this role into zones for our geographic markets, and the specific base pay within the range will be determined by the candidate’s geographic location, job-related experience, knowledge, qualifications, and skills.
    • United States  (all figures cited below in USD and pertain to workers in the United States)
      • Zone A: $162,500 - $216,050
      • Zone B: $152,700 - $203,100
      • Zone C: $143,00 - $190,150 
    • Canada  (All figures cited below in CAD and pertain to workers in ON & BC, Canada)
      • CAD 184,600 - CAD 245,500
  • Please visit our Careers page for more information on which locations are included in each of our geographic pay zones. However, please confirm the zone for your specific location with your recruiter.

  • Reporting to the Director of Security 

 

As a Senior Enterprise Security Engineer you’ll … 

  • Collaborate primarily with the Information Technology (IT), Facilities, and People teams
  • You will be working to secure:
    • endpoints
    • corporate SaaS and internal tooling
    • corporate offices
  • Improve security related processes and procedures
  • Work to establish or improve security standards while balancing business strategies and requirements.
  • Support Webflow’s security current and future security frameworks such as SOC2
  • Participate in incident response and forensics
  • Support 3rd party risk

In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we'll help you incorporate them into your role.

About you 

You’ll thrive as a Senior Enterprise Security Engineer if you:

  • First and foremost, are a technologist, and have a broad fundamental understanding of the technology space with solid background in current IT trends and tooling.
  • Have 3+ years of experience evaluating and securing corporate IT environments with an eye to improve security design, continuous commitment to risk reduction and sustainable security.
  • Have experience securing MacOS endpoints, and working with tools such as Jamf and Crowdstrike
  • Have experience with IAM & IDP systems such as Okta
  • Have experience with incident response, and conducting endpoint forensics
  • Have a solid understanding of the corporate threat landscape, and intrusion patterns, and the itch to investigate for potential security issues
  • Have experience evaluating and securing corporate network environments
  • Love to share knowledge, and the gift of explaining complex security concepts with your colleagues.
  • Have an understanding of IT processes, and HR operations, tools and procedures
  • Have experience automating security processes and procedures
  • Are passionate about security in general, and always hungry to learn
  • Have experience working with a security framework such as SOC2 or ISO 2700

 

Our Core Behaviors:

  • Obsess over customer experience.We deeply understandwhatwe’re building andwhowe’re building for and serving. We define the leading edge of what’s possible in our industry and deliver the future for our customers.
  • Move with heartfelt urgency.We have a healthy relationship with impatience, channeling it thoughtfully to show up better and faster for our customers and for each other. Time is the most limited thing we have, and we make the most of every moment.
  • Say the hard thing with care.Our best work often comes from intelligent debate, critique, and even difficult conversations. We speak our minds and don’t sugarcoat things — and we do so with respect, maturity, and care.
  • Make your mark.We seek out new and unique ways to create meaningful impact, and we champion the same from our colleagues. We work as ateamto get the job done, and we go out of our way to celebrate and reward those going above and beyond for our customers and our teammates.

Benefits & wellness

  • Equity ownership (RSUs) in a growing, privately-owned company
  • 100% employer-paid healthcare, vision, and dental insurance coverage for employees and dependents (full-time employees working 30+ hours per week), as well as Health Savings Account/Health Reimbursement Account, dependent care Flexible Spending Account (US only), dependent on insurance plan selection where applicable in the respective country of employment; Employees may also have voluntary insurance options, such as life, disability, hospital protection, accident, and critical illness where applicable in the respective country of employment
  • 12 weeks of paid parental leave for both birthing and non-birthing caregivers, as well as an additional 6-8 weeks of pregnancy disability for birthing parents to be used before child bonding leave (where local requirements are more generous employees receive the greater benefit); Employees also have access to family planning care and reimbursement
  • Flexible PTO with a mandatory annual minimum of 10 days paid time off for all locations (where local requirements are more generous employees receive the greater benefit), and sabbatical program
  • Access to mental wellness and professional coaching, therapy, and Employee Assistance Program
  • Monthly stipends to support health and wellness, smart work, and professional growth
  • Professional career coaching, internal learning & development programs
  • 401k plan and pension schemes (in countries where statutorily required) financial wellness benefits, like CPA or financial advisor coverage
  • Discounted Pet Insurance offering (US only)
  • Commuter benefits for in-office employees

Be you, with us

At Webflow, equality is a core tenet of our culture. We are an Equal Opportunity (EEO)/Veterans/Disabled Employer and are committed to building an inclusive global team that represents a variety of backgrounds, perspectives, beliefs, and experiences. Employment decisions are made on the basis of job-related criteria without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by applicable law. Pursuant to the San Francisco Fair Chance Ordinance, Webflow will consider for employment qualified applicants with arrest and conviction records.

Stay connected

Not ready to apply, but want to be part of the Webflow community? Consider following our story on our Webflow Blog, LinkedIn, X (Twitter), and/or Glassdoor.

Please note:

To join Webflow, you'll need valid U.S. or Canadian work authorization depending on the country of employment.

If you are extended an offer, that offer may be contingent upon your successful completion of a background check, which will be conducted in accordance with applicable laws. We may obtain one or more background screening reports about you, solely for employment purposes.

For information about how Webflow processes your personal information, please reviewWebflow’s Applicant Privacy Notice

See more jobs at Webflow

Apply for this job

+30d

Senior Security Engineer

QlikHybrid Remote, King of Prussia, Pennsylvania
5 years of experienceazurerubyjavac++linuxpythonAWS

Qlik is hiring a Remote Senior Security Engineer

Description

What makes us Qlik?

 

AGartner® Magic Quadrant™ Leader for 13 years in a row, Qliktransforms complex data landscapes into actionable insights, driving strategic business outcomes. Serving over 40,000 global customers, our portfolio leverages pervasive data quality and advanced AI/ML capabilities that lead to better decisions, faster.

 

We excel in integration and governance solutions that work with diverse data sources, and our real-time analytics uncover hidden patterns, empowering teams to address complex challenges and seize new opportunities.

 

 

The Senior Security EngineerRole

 

Join our team at Qlik as a Senior Security Engineer and be part of shaping the future direction of our company. With approximately 38,000 customers worldwide, you'll have the opportunity to make a significant impact on our growth and success.

 

In this role, you'll work in an innovative, team-oriented environment, collaborating with talented individuals to continuously innovate and improve our security measures.

 

What makes this role interesting?

 

  • Impactful Contribution:Play a key role in supporting the investigation of security incidents, alerts, and events, ensuring the safety and integrity of our systems.
  • Innovative Environment:Join a dynamic and high-energy culture where innovation and collaboration are valued.
  • Professional Growth:Benefit from a flexible and exciting work environment, with ample opportunities to grow both professionally and personally.

 

Here’s how you’ll be making an impact:

 

  • Security Incident Investigation:Support the investigation of security incidents, alerts, and events, ensuring timely response and resolution.
  • Tool Implementation:Implement and support security-focused tools to enhance our security posture.
  • Vulnerability Management:Assist in managing the vulnerability program,identifying,and addressing potential security risks.
  • Company-wide Security Projects:Collaborate on company-wide projects to enhance security across all areas of our organization.
  • Penetration Testing:Assist in conducting penetration testing to identify and address potential vulnerabilities.
  • Proactive Security Measures:Perform proactive security checks andthreat-huntingactivities to safeguard our systems.
  • Incident Response:Support incident response efforts, ensuring swift and effective resolution of security incidents.

 

We’re looking for a teammate with:

 

  • Strong understanding of networking principles (OSI Model, Routing fundamentals, TCP/IP)
  • Advancedunderstanding of host operating systems and applications, including Microsoft Windows, Linux,and Mac
  • Experience in programming (Ex: Java or C++)
  • Experience with scripting languages such as Python, or Ruby
  • Understanding of network security principles
  • Incident response principles
  • Endpoint experience – AV, EDR
  • Minimum Years of Experience: 5 years of experience in Information Security
  • Vulnerability Management – Nessus, Qualys, Rapid 7
  • Basic Public Cloud experience – AWS, Azure, GCP
  • Qualifications – CCNA, CCNP, AWS Certified Securityisaplus.
  • Security certifications like CEH, CIH, OSCP, and CISSPareaplus.

 

Thelocationfor this role is:

 

The role is open to any US Qlik office or Remote, for the right candidate.

 

Join us in safeguarding the future of Qlik. Apply now to become an integral part of our security team!

 

 

More about Qlik and who we are:

 

Find out more about life at Qlik on social:Instagram,LinkedIn,YouTube, andX/Twitter, and to seeallotheropportunities to join usandour values, check outourCareers Page.

 

What else do we offer?

 

  • Genuine career progression pathwaysandmentoring programs
  • Culture of innovation, technology, collaboration, and openness
  • Flexible, diverse, and international work environment

 

Giving back is a huge part of our culture. Alongside an extra “change the world” dayplusanother for personal development, we also highly encourage participation in ourCorporate Responsibility Employee Programs

 

The anticipated base salary range for this role is$108,000.00 MIN – $148,000.00 Max.Final compensation offered by Qlik will be based on factors such as the candidate’s location, job-related skills, education, experience, and other business and organizational needs.Qlik offers a comprehensive benefits package.

 

Qlik is an Equal Opportunity/Affirmative Action Employer. We are committed to fostering a workplace that is diverse, equitable,and inclusive.

Qualified applicants will receive consideration for employment without regard to actual or perceived: race, color, religion, sex, sexual orientation, gender identity, pregnancy and related medical conditions, genetic information, national origin, age, marital status, protected veteran status, disability status or any other characteristic protected by applicable law. For United States applicants and employees, go to the US Department of Labor’s website to review the EqualEmployment Opportunity Posters, including the “Know Your Rights” and “Pay Transparency Nondiscrimination” posters.

If you need assistance applying for a role due to a disability, please submit your request via[email protected]. Any information you provide will be treated according to Qlik’s Recruitment Privacy Notice. Qlik may only respond to emails related to accommodation requests. Click here for machine-readable files related to Qlik’s US group health plan offerings that are being made available in response to the US federal Transparency in Coverage Rule and includes negotiated service rates and out-of-network allowed amounts between health plans and healthcare providers. The machine-readable files are formatted to allow researchers, regulators, and application developers to access and analyze data more easily.

 

Qlik is not accepting unsolicited assistance from search firms for this employment opportunity. Please, no phone calls or emails. All resumes submitted by search firms to any employee at Qlik via-email, the Internet or in any form and/or method without a valid written search agreement in place for this position will be deemed the sole property of Qlik. No fee will be paid in the event the candidate is hired by Qlikas a result ofthe referral or through other means.

See more jobs at Qlik

Apply for this job

Lampenwelt GmbH is hiring a Remote IT Security Engineer (f/m/d)

Stellenbeschreibung

Wir suchen einen engagierten IT Security Engineer (f/m/d), der unsere Sicherheitsarchitektur mit Leidenschaft stärkt. In deiner Rolle als Experte für IT Security spielst du eine zentrale Rolle bei der Identifizierung, Analyse und Minderung von Sicherheitsrisiken. Du arbeitest Hand in Hand mit verschiedenen Teams, um unsere Sicherheitsstrategien, überwiegend in Projekten, weiterzuentwickeln, zu implementieren und kontinuierlich zu verbessern und bist Sparringspartner in der täglichen Analyse von Security Alerts. 

Gelegentliche Vor-Ort-Einsätze sind erforderlich, ansonsten ist auch Remote-Arbeit möglich. 

 

Wo deine Skills gefragt sind

  • Weiterentwicklung, Implementierung und Überwachung von Security Policies, um die Einhaltung von Standards und Best Practices sicherzustellen 
  • Administration und Beratung hinsichtlich unserer Security Infrastruktur, inklusive IAM, Cloud-, Endpoint- und Network Security
  • Durchführung von Security Assessments, inklusive Risiko-, Schwachstellen- und Compliance-Management
  • Proaktives Incident Management, von der schnellen Reaktion auf Sicherheitsvorfälle bis hin zum Business Continuity Management
  • Förderung der Sicherheitskultur durch Unterstützung bei der Durchführung regelmäßiger Security Awareness Trainings und Penetrationstests sowie Sicherheitsscans
  • Stetige Weiterentwicklung und Verfeinerung der Shared LUQOM IT-Services mit Fokus auf IT Security

Qualifikationen

Lampenwelt ist der richtige Ort für dich, wenn du Veränderungen als Chance begreifst und neugierig auf das Unbekannte bist. Wenn du dich jeden Tag aufs Neue herausforderst, um die beste Lösung zu finden. Hier wird dir Verantwortung übertragen, damit du deine Ideen nicht nur einbringen, sondern auch selbst umsetzen kannst. Bei Lampenwelt gehen wir jeden Tag ein Stück weiter, handeln schnell, sind offen und setzen auf eine direkte und lösungsorientierte Kommunikation auf allen Ebenen. 

Was dir helfen wird, zukünftige Herausforderungen zu meistern 

  • Tiefgehendes Verständnis für IT-Sicherheitskonzepte und -technologien
  • Fundiertes Wissen über Netzwerktechnologien, Cloud- & On-Prem Security Lösungen, End Point Protection, Betriebssystemen und SIEM
  • Kenntnisse im Umfeld von Microsoft Defender von Vorteil, insbesondere im Bereich Defender for Endpoint, Cloud sowie Identity
  • Starkes Interesse an neuen Technologien und fortlaufender persönlicher sowie beruflicher Weiterentwicklung
  • Eigeninitiative und Teamgeist bei der Durchführung von IT-Projekten
  • Analytische, konzeptionelle, strukturierte und eigenständige Arbeitsweise
  • Ausgeprägte Teamfähigkeit, Kommunikationsstärke und Engagement
  • Abgeschlossene Ausbildung im IT-Bereich oder ein Studium in Wirtschaftsinformatik, Informatik oder einem verwandten Feld
  • Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift

See more jobs at Lampenwelt GmbH

Apply for this job

+30d

Sr. Security Engineer

InMarketRemote (US Only)
agileterraformmobilerubyc++kuberneteslinuxpythonAWSjavascript

InMarket is hiring a Remote Sr. Security Engineer

Title:Sr. Security Engineer                                        

Location:Remote - US ONLY

About inMarket

Since 2010, InMarket has been the leader in 360-degree consumer intelligence and real-time activation for thousands of today’s top brands. Through InMarket's data-driven marketing platform, brands can build targeted audiences, activate media in real time, and measure success in driving return on ad spend. InMarket's proprietary Moments offering outperforms traditional mobile advertising by 6x.* Our LCI attribution platform, which won the MarTech Breakthrough Award for Best Advertising Measurement Platform, was validated by Forrester to drive an average of $40 ROAS for our clients.
*Source: Wordstream US Google Display Benchmarks for Mobile Media

About the Role

Join the team responsible for protecting our customers, our data, and our company from malicious actors at all levels. We are an outcomes focused team, focused on enabling our internal customers for success by providing them with clear guidance and strong security controls. We're looking for an exceptional engineer to join the team at the center of security and safety here at InMarket.

Your Daily Impact as a Sr. Security Engineer
In this role you will be responsible for working with great depth and breadth to build safeguards, detections, and controls to protect InMarkets vast amounts of data. Here you’ll truly be at the front lines taking on meaningful work to defend our company and our peers.

You will be working and communicating closely with many technical teams to develop context and foresight into what our true risks are, and work towards holistic longlasting remediation with guidance and real world solutions. Our goal is to create a cohesive balance between risk, operational effectiveness, and compliance.

The ideal candidate for this team is someone who is a strong, interested, well rounded engineer with a passion for security as well as a natural collaborator who can understand business needs and develop security solutions that empathize with people's experiences.

Your Experience and Expertise

  • BS in computer science / cybersecurity, or equivalent experience
  • 5+ years of experience in engineering, information security operations or related IT operations
  • Strong experience in Linux administration
  • Strong development & scripting experience. (Javascript / Ruby, Python preferred)
  • Strong experience in AWS, GCP, or both
  • Good networking fundamentals

Nice to Haves 

  • Ability to provide a sample portfolio or work examples is highly preferred
  • Varied security engineering experience with a specialty in one or more areas of security such as: (Cloud Security, Vulnerability Management, Application Security, Penetration Testing / Offsec, DevSecOps, Third Party / SaaS Security, Identity and Access Management, Incident Response)
  • Experience performing security / architecture / code reviews
  • Hackthebox, CTF, or Hackathon experience
  • Good hands-on background in building tooling using many security products
  • Terraform / IaC experience
  • Kubernetes / Container experience
  • Controls and Standards knowledge (SOC2, NIST CSF, 800-53, CIS)
  • SOC2 audit experience
  • Familiar with Security Reference Architectures and actual best practices
  • Experience building out security tooling from common vendors
  • Active member or speaker in the security / technology community
  • Ability to work and multitask under high pressure situations
  • Excellent written and verbal communication skills. Ability to communicate highly complex security concepts to both technical and non-technical audiences

Finally, here are a few more reasons why we love this work and think that you will too:

  • This is a diverse role with unparalleled visibility where you’ll be able to learn new tech daily.
  • You will have the opportunity to shape the security function with the support and autonomy to actually do it.
  • Great support from executive leadership who understand the true value in security and genuinely back the mission.

Benefits Summary

  • Competitive salary, stock options, flexible vacation
  • Medical, dental and Flexible Spending Account (FSA)
  • Company Matched 401(k)
  • Unlimited PTO (Within reason)
  • Talented co-workers and management
  • Agile Development Program (For continued learning/professional development)
  • Generous Paid Parental Leave

 

For candidates in California, Colorado, and New York City, the Targeted Base Salary Range for this role is $130,000 to $175,000. 

Actual salaries will vary depending on factors including but not limited to work experience, specialized skills and training, performance in role, business needs, and job requirements. Base salary is subject to change and may be modified in the future. Base salary is just one component of InMarket’s total rewards package that also may include bonus, equity, and benefits.  Ask your recruiter for more information!

At InMarket we are committed to a culture that supports diversity, inclusion, belonging and equal opportunity. We celebrate all people and believe everyone deserves respect regardless of race, gender, sexual orientation, backgrounds, experiences, abilities or beliefs.

InMarket is an Equal Opportunity Employer (EOE). Qualified applicants are considered for employment without regard to age, race, color, religion, sex, national origin, sexual orientation, disability, or veteran status.

Privacy Notice for California Job Applicants: https://inmarket.com/ca-notice-for-job-applicants/

#LI-Remote

See more jobs at InMarket

Apply for this job

+30d

Lead Security Engineer

PindropUS - Remote
1 year of experience7 years of experience5 years of experienceremote-firstDesignapirubyc++dockerkubernetespython

Pindrop is hiring a Remote Lead Security Engineer

Lead Security Engineer

US Remote

Who we are

Are you passionate about innovating at the intersection of technology and personal security? At Pindrop, we recognize that the human voice is a unique personal identifier, increasingly susceptible to sophisticated fraud, including the threat of deepfakes. We're leading the way in developing cutting-edge authentication, fraud prevention, and deepfake detection. Our mission is to provide seamless and secure digital experiences, safeguarding the most personal aspect of our identity: our voice. Here, you'll be part of a team driven by values of Innovation, Customer Advocacy, Excellence, and Impact. We're not just creating a safer digital landscape by fortifying trust and integrity with those we serve, we’re also building a dynamic, supportive workplace where your contributions make a real difference.

Headquartered in Atlanta, GA, Pindrop is backed by world-class investors such as Andreessen-Horowitz, IVP, and CapitalG.

What you’ll do 

  • Lead and examine and secure systems, network, infrastructure and applications to assess and improve the current on premises and cloud security posture.
  • Lead administration, management and incident response of security tools and technologies such as EDR (Endpoint Detection & Response), SIEM (Security Information & Event Management), DLP (Data Loss Prevention), Vulnerability Management, Firewalls, WAF (Web Application Firewalls)
  • Support daily security operations (SecOps) functions such as configuring, monitoring and responding to security alerts. Assist with Incident Response, and investigations.
  • Build automation for security tools and SecOps functions such as compliance checks, alerts and reporting.
  • Lead security analysis, review and deployment of solutions (systems, network, infrastructure and applications) to protect Pindrop assets in the cloud and our data centers.
  • Lead technical security assessments, security reviews, code audits and offensive security exercises to test security controls and detection capabilities
  • Be aware of Information security standards such as ISO27001, SOC2, PCI and support internal and third party audits.
  • Provide thought leadership and technical direction based on security news, research, threats, attack vectors, technologies, certifications, laws and regulations and report on anything that could impact the company. 
  • Collaborate with stakeholders, provide security guidance and support and develop dashboards, reports, and alerts to meet their cybersecurity operational information requirements.    

Who you are

  • You are an engineer at heart with strong problem-solving, analytical, communication and interpersonal skills and who has knowledge or experience in several areas such as - defending against and/or mitigating system vulnerabilities (including enterprise level concerns, infrastructure, and host/endpoint), intrusion detection and incident response, network traffic analysis, scripting languages, software reverse engineering, network security devices (e.g., firewalls, intrusion and detection systems), cloud and compliance frameworks.
  • You continuously look for automation and programmatic efficiencies in security processes
  • You have excellent written and verbal communication skills and can communicate technical details in a clear, concise, understandable manner
  • You work independently and as part of a team with minimal supervision
  • You are resilient in the face of challenges, change, and ambiguity
  • You are optimistic and believe that you can make a problem into a solution
  • You are resourceful, excited to uncover innovative solutions and teach yourself something new when needed
  • You take accountability, do the things you say you’ll do, under-promise and over-deliver
  • You are nimble and adaptable when priorities change and continue to see the “forest through the trees” 

Your skill-set: 

  • At least 7 years of experience with administering and managing security technologies and tools such as EDR, SIEM, Vulnerability Management, SAST and DAST, Data Loss Prevention and File Integrity Monitoring tools.
  • At least 5 years of experience with Security Operations (SecOps), incident response, security investigations.
  • At Least 1 year of experience with a scripting or programming language: python, golang, ruby, bash, Java.
  • Strong understanding of  Networks, Cloud, Containers, API, Application Security, SDLC, Web security, Docker, and Kubernetes
  • Fundamental understanding of accepted security practices, known attack vectors and vulnerability assessment methodologies
  • Nice to have:
    • Prior experience as a software developer
    • Prior architectural experience
    • Knowledge of common information security standards, such as ISO 27001/27002, NIST, CIS, PCI DSS, ITIL, and COBIT.

What’s in it for you:

As a Pindropper, you join a rapidly growing company making technology more human with the power of voice. You will work alongside some of the best and brightest). We’re a passionate group committed to excellence - but that doesn’t stop us from enjoying the journey as a team with chess and poker tournaments, catered lunches and happy hours, wellness programming, and more. Because we take our jobs seriously, we add in time for rest with Unlimited PTO, Focus Thursday, and Company-wide Rest Days. 

Within 30 days you’ll

    • Complete onboarding and attend New Employee Orientation sessions with other new Pindroppers
    • Learning about Pindrop culture, values and teams
    • Building relationships with key stakeholders and the team

Within 60 days you’ll

    • Learning existing processes, tools and techniques
    • Learning SecOps best practices based on industry guidelines and comparing with current practices

Within 90 days you’ll

    • Defining SecOps best practices based on industry guidelines and planning to improve with current practices
    • Design and architect new security deployments and solutions.
    • Teach us something new

What we offer

As a part of Pindrop, you’ll have a direct impact on our growing list of products and the future of security in the voice-driven economy. We hire great people and take care of them. Here’s a snapshot of the benefits we offer:

  • Competitive compensation, including equity for all employees
  • Unlimited Paid Time Off (PTO)
  • 4 company-wide rest days in 2024 where the entire company rests and recharges!
  • Generous health and welfare plans to choose from - including one employer-paid “employee-only” plan!
  • Best-in-class Health Savings Account (HSA) employer contribution
  • Affordable vision and dental plans for you and your family
  • Employer-provided life and disability coverage with additional supplemental options
  • Paid Parental Leave - Equal for all parents, including birth, adoptive & foster parents
    • One year of diaper delivery for your newest addition to the family! It’s our way of welcoming new Pindroplets to the family!
  • Identity protection through Norton LifeLock
  • Remote-first culture with opportunities for in-person team events
  • New hire and recurring monthly home office allowance
  • When we need a break, we keep it fun with happy hours, ping pong and foosball, drinks and snacks, and monthly massages!
  • Remote and in-person team activities (think cheese tastings, chess tournaments, talent shows, murder mysteries, and more!)
  • Company holidays
  • Annual professional development and learning benefit
  • Pick your own Apple MacBook Pro
  • Retirement plan with competitive 401(k) match
  • Wellness Program including Employee Assistance Program, 24/7 Telemedicine

What we live by

At Pindrop, our Core Values are fundamental beliefs at the center of all we do. They are our guiding principles that dictate our actions and behaviors. Our Values are deeply embedded into our culture in big and small ways and even help us decide right from wrong when the path forward is unclear. At Pindrop, we believe in taking accountability to make decisions and act in a way that reflects who we are. We truly believe making decisions and acting with our Core Values in mind will help us to achieve our goals and keep Pindrop a great place to work:    

  • Audaciously Innovate - We continue to change the world, and the way people safely engage and interact with technology. As first principle thinkers, we challenge standards, take risks and learn from our mistakes in order to make positive change and continuous improvement. We believe nothing is impossible.
  • Evangelical Customers for Life - We delight, inspire and empower customers from day one and for life. We create a partnership and experience that results in a shared passion.   We are champions for our customers, and our customers become our champions, creating a universal commitment to one another. 
  • Execution Excellence - We do what we say and say what we do. We are accountable for making the tough decisions and necessary tradeoffs to deliver quality and effective solutions on time.
  • Win as a Company - Every time we win, we win as a company. Every time we lose, we lose as a company. We break down silos, support one another, embrace diversity and celebrate our successes. We are better together. 
  • Make a Difference - Every day we have the opportunity to make a positive impact. We operate with dedication, passion, and uncompromising integrity, creating a safer, more secure world.

Not sure if this is you?

We want a diverse, global team, with a broad range of experience and perspectives. If this job sounds great, but you’re not sure if you qualify, apply anyway! We carefully consider every application and will either move forward with you, find another team that might be a better fit, keep in touch for future opportunities, or thank you for your time.

Pindrop is an Equal Opportunity Employer

Here at Pindrop, it is our mission to create and maintain a diverse and inclusive work environment. As an equal opportunity employer, all qualified applicants receive consideration for employment without regard to race, color, age, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetic information, disability, marital and/or veteran status.

 

#LI-Remote

 

See more jobs at Pindrop

Apply for this job

+30d

Senior Security Engineer, Application Security

Designmobilec++kubernetesAWS

Oscar Health is hiring a Remote Senior Security Engineer, Application Security

Hi, we're Oscar. We're hiring a Senior Security Engineer, Application Security to join our Security team.

Oscar is the first health insurance company built around a full stack technology platform and a focus on serving our members. We started Oscar in 2012 to create the kind of health insurance company we would want for ourselves—one that behaves like a doctor in the family.

 

About the role

As a Senior Security Engineer, you will collaborate closely with cross-functional teams to proactively identify, address, and resolve security concerns across Oscar's comprehensive tech infrastructure, encompassing Web Applications, Mobile Apps, Networks, and Cloud systems. Your primary objective will be to safeguard classified information by thoroughly assessing and examining Oscar's applications and infrastructure by executing and documenting technical assessments based on esteemed industry standards (OWASP) and best practices, meticulously pinpointing security vulnerabilities within Oscar's owned assets. In addition, you will be responsible for presenting identified risks and providing guidance on best practices to prevent future vulnerabilities.

You will report to the Manager, Security Architecture.

 

Work Location

Oscar is a blended work culture where everyone, regardless of work type or location, feels connected to their teammates, our culture and our mission.

If you live within commutable distance to our New York City office (in Hudson Square), our Tempe office (off the 101 at University Ave), or our Los Angeles office (in Marina Del Rey), you will be expected to come into the office at least two days each week. Otherwise, this is a remote / work-from-home role.

You must reside in one of the following states: Alabama, Arizona, Colorado, Florida, Georgia, Illinois, Iowa, Kentucky, Maryland, Massachusetts, Michigan, Minnesota, New Hampshire, New Mexico, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, Tennessee, Texas, Utah, Vermont, Virginia, or Washington, D.C. Note, this list of states is subject to change. #LI-Remote

 

Pay Transparency

The base pay for this role is: $144,000 - $189,000 per year. You are also eligible for employee benefits, participation in Oscar’s unlimited vacation program, company equity grants and annual performance bonuses.

 

Responsibilities

  • Collaborate closely with cross-functional teams to proactively identify, address, and resolve security concerns across Oscar's comprehensive tech infrastructure, encompassing Web Applications, Mobile Apps, Networks, and Cloud systems, including proposing enhanced controls and procedural strategies to mitigate technical risks 
  • Demonstrate an in-depth comprehension of Oscar's technological landscape
  • Collaborate effectively with Security Leadership, providing insights into technical issues and their potential impacts
  • Engage in multiple-layers of oscars Technology stack to design security measures around protecting Oscars systems
  • Simplify intricate security concerns into actionable steps for effective remediation or risk mitigation
  • Compliance with all applicable laws and regulations
  • Other duties as assigned

 

What you may work on

Some sample projects in this role may include:

  • Execute and meticulously document technical assessments based on esteemed industry standards (OWASP) and best practices, meticulously pinpointing security vulnerabilities within Oscar's owned assets. This includes conducting Threat Modeling, Architecture/Design Reviews, Application and Cloud Security Testing (Red Teaming), and Manual Vulnerability Assessments.
  • Spearhead internal workshops involving cross-functional teams to analyze outcomes from technical assessments, devising comprehensive plans to mitigate identified risks effectively.
  • Define robust hardening and secure design standards, leveraging them to conduct thorough application security reviews in collaboration with developer teams.

 

Qualifications

  • 3+ years experience in Technology related field 
  • 2+ years experience in Security

 

Bonus Points

  • Familiarity with industry standards and compliance frameworks (such as SOC, SOX., NIST,, HIPAA) and experience in ensuring organizational adherence to these standards.
  • Hands-on experience in developing Web/Mobile Applications.
  • Hands-on experience in evaluating Web Applications, Cloud Environments, Mobile Applications, and Network security.
  • Proficiency in industry-standard methodologies and frameworks for security testing (OWASP, OSSTM, PTES).
  • Proficient familiarity with AWS and GCP.
  • Experience utilizing containers and container orchestration technology (Mesos and Kubernetes).
  • Possession of industry-recognized certifications pertaining to application/offensive security (OSCP, OSCE, OSWP, OSWA, OSWE, CSSLP).
  • Experience in assessing containers for potential security vulnerabilities.
  • Experience Threat Modeling

This is an authentic Oscar Health job opportunity. Learn more about how you can safeguard yourself from recruitment fraudhere

At Oscar, being an Equal Opportunity Employer means more than upholding discrimination-free hiring practices. It means that we cultivate an environment where people can be their most authentic selves and find both belonging and support. We're on a mission to change health care -- an experience made whole by our unique backgrounds and perspectives..

Pay Transparency: 

Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education, and experience.

Full-time employees are eligible for benefits including: medical, dental, and vision benefits, 11 paid holidays, paid sick time, paid parental leave, 401(k) plan participation, life and disability insurance, and paid wellness time and reimbursements.

Reasonable Accommodation:

Oscar applicants are considered solely based on their qualifications, without regard to applicant’s disability or need for accommodation. Any Oscar applicant who requires reasonable accommodations during the application process should contact the Oscar Benefits Team (accommodations@hioscar.com) to make the need for an accommodation known.

See more jobs at Oscar Health

Apply for this job

+30d

Senior Security Engineer

Publicis SapientHeredia, Costa Rica, Remote
apipython

Publicis Sapient is hiring a Remote Senior Security Engineer

Job Description

Objective:

To be responsible for orchestrating Publicis Groupe-wide security engineering operations and functions. The role must be able to translate the IT-risk requirements and constraints of the agencies into technical control requirements and specifications. Maintain and analyze web application firewall data and cloud security platforms.

Responsibilities:

  • On call rotation
  • Diagram high level infrastructure reference architecture and controls for engineering, operations, and management reference
  • Provide technical expertise to the risk management team to assess technical risk
  • Identify opportunities for process improvement to meet and exceed customer service expectations and improve overall risk posture
  • Utilize Threat Intelligence and Threat Models to create threat hypotheses
  • Prepare project documentation (guides, configuration documents, etc.)
  • Firewall rule analysis and firewall request approvals
  • Lead and provide clear guidance to multiple teams, ensuring results are aligned with business objectives and within planned timelines
  • Broad technical background with a knowledge-base in network security, and web applications
  • Establish relationships with various security technology and service vendors

Qualifications

  • Good working knowledge of various security technologies such as network and application firewalls, CNAPP and SSPM, and XDR systems
  • Expertise in network, host, and cloud-based analysis and investigation
  • Analyze and correlate threat assessment data
  • Tuning WAF, CNAPP, SSPM
  • Analyze network/security logs, root cause analysis
  • Prior experience with ThreatX Web Application Firewall
  • Prior experience with Wiz CNAPP
  • Prior experience with Adaptive shield SSPM
  • Extensive knowledge and experience working with a data centric environment, traditional datacenters and virtualized environments
  • System integration, administration, documentation, change control
  • Gather evidence for audits pertaining to security tools
  • API Automation to increase operational excellence and to enhance value from security tools
  • Experience with Python, Bash, Powershell scripting, and Lambda
  • Advanced English
  • IT Bachelor’s degree
  • Preferred certified in at least one or more of the following certifications: CISSP, CISA, CISM, GCIH, GPEN, or other accredited security credentials

Apply for this job

Clover Health is hiring a Remote Senior Security Engineer

Clover is reinventing health insurance by working to keep people healthier.

We value diversity — in backgrounds and in experiences. Healthcare is a universal concern, and we need people from all backgrounds and swaths of life to help build the future of healthcare. Clover's engineering team is empathetic, caring, and supportive. We are deliberate and self-reflective about the engineering team and culture that we are building, seeking engineers that are not only strong in their own aptitudes but care deeply about helping each other's growth.

As a Senior Security Engineer, you will forge and nurture trusted relationships with internal technology teams (Software Engineering, SRE, DS/ML, Product) and external customers (e.g., payers, accountable care organizations, integrated delivery networks). You will partner closely with the entire technology organization to architect, design, implement, and maintain system security and controls. This role will be an expert who understands the needs of software development, technical system design, and data/information security.

As a Senior Security Engineer, you will:

  • Serve as a SME for security related code and technical design reviews.
  • Identify and collaborate with eng and SRE to resolve areas of security vulnerability in our software, systems and infrastructure.
  • Serve as security point-of-contact for audit/certification programs such as HITRUST, SOC 2, and HIPAA
  • Assess and improve systems for compliance with security requirements, policies, guidelines and standards (see above)
  • Interface with external customers on CA security reviews and assessments
  • Monitor and regularly review our system for intrusions, threats, and anomalies
  • Work to improve our general security posture and processes ranging from secure development practices to SecDevOps
  • Lead the planning, definition and implementation of new security solutions or related development

You will love this job if:

  • You are passionate about transforming healthcare delivery through new technologies and want to make an impact.
  • You have a bias toward action and seek to intervene before issues arise.
  • You are comfortable navigating ambiguity and working in an evolving environment.
  • You are a problem solver and a team player. You love working within teams and helping them work more efficiently.
  • You are a strong communicator and able to influence behaviors to help drive desired outcomes.
  • You are empathetic and seek to build enduring relationships with our customers and users.
  • You are analytical and use data to drive actions and evaluate outcomes.

You should get in touch if:

  • You have strong knowledge and experience with software engineering, web services, APIs and cloud environments.
  • You have assessed the security of APIs and systems by analyzing authentication, authorization mechanisms, input validation, and potential vulnerabilities.
  • You have excellent written and verbal communication skills and are able to craft clear and comprehensive reports and research to present to engineering and other stakeholders.
  • You are able to think strategically while also managing work tactically.
  • You work autonomously but know when to inform, involve, or escalate topics or decisions.
  • You stay up-to-date with latest research on threats, attack vectors, and security trends and are keen to apply them to our environment
  • You demonstrate influence and are able to lead/mentor internal teams and customers toward shared goals and objectives.

Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. We are an E-Verify company.


About Clover: We are reinventing health insurance by combining the power of data with human empathy to keep our members healthier. We believe the healthcare system is broken, so we've created custom software and analytics to empower our clinical staff to intervene and provide personalized care to the people who need it most.

We always put our members first, and our success as a team is measured by the quality of life of the people we serve. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences and backgrounds, who share a passion for improving people's lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.


#LI-REMOTE

See more jobs at Clover Health

Apply for this job

+30d

Application Security Consultant

VeracodeBurlington, MA OR US Remote
agilejirajavac++jenkinsjavascriptPHP

Veracode is hiring a Remote Application Security Consultant

Application Security Consultant

Looking for an innovative, high-growth company in one of the hottest segments of the security market?  Look no further than Veracode! 

Veracode is recognized as a premier provider of SaaS-based software security solutions, transforming the way companies secure applications in today’s software driven world. We provide our customers with a solid foundation on which to build security into their modern agile development processes. Learn more about us at www.veracode.com!

Candidate will operate as member of application security consulting team delivering tactical mentorship and strategic consulting in terms of general application security awareness, secure development best-practices, and effective utilization of Veracode services. Ability to effectively communicate application security concepts to developers unskilled in these is essential, as is the ability to also function as a trusted advisor to security stakeholders within client organizations. Additional opportunities of the role include threat analysis and modelling, evaluation of effectiveness of compensating controls within and beyond application implementation logic, creation of client security program recommendations.  The role requires:

Required Skills:

  • 2+ years of recent software development experience-- either professionally or as an Open Source contributor, or an avid hobbyist.
  • Willingness and eagerness to learn new programming  languages on the job
  • Understanding of Application-level security and secure coding practices.
  • Proficiency in one of more of the following programming languages; C, Javascript, C++, C#, Java, or PHP Hands-on experience with one or more of the following: Visual Studio or Eclipse, Team City, Jira, Hudson, Jenkins, or Cruise Control. Archer, SAML/SSO, VMware Databases, Command Shell scripting.
  • Excellent “Client-side” manner
  • Client requirement gathering, prioritization and scoping experience.
  • Strong technical writing skills.
  • Strong oral communication skills in English and good presentation/teaching skills.
  • Excellent problem-solving and organizational skills.
  • Ability to apply these skills cooperatively in a collaborative team environment.
  • Additional Skills and Experiences:  Familiarity with CVSS, CWE, OWASP, WASC and SANS-25.Experience with source code analysis and interactive application security testing products, Penetration Testing. Understanding of common risk mitigation practices and technologies such as firewalls, ACLs and multi-factor access controls,; SaaS, Professional Services
  • Training/Mentoring experience also desired.
  • Written and conversational fluency in Spanish, including domain specific terminology for IT/Application Security/Programming is desired but not a requirement.
  •  
  • What we offer you
  • Outstanding Medical, Dental, and Vision Coverage to meet all your healthcare needs.
  • Wellness benefits to help you focus on what’s most important.
  • “Take What You Need” time off policy.
  • Extensive development and training offerings to help you grow your career at Veracode.
  • Generous 401k match to help save for your future.
  • Amazing community of professionals who take pride in what we do every day.

Compensation Transparency

In accordance with U.S. pay transparency laws, Veracode provides compensation transparency for roles based in the United States. Click here to view our compensation ranges by grade. Please note, specific compensation may be influenced by various factors including candidates experience, education, and work location.

Job Grade: Career

Employment opportunities are available to all applicants without regard to race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Fraudulent Recruitment Alert - Be Aware and Stay Informed

At Veracode, we prioritize a secure recruitment process. Unfortunately, fake recruitment and job offer scams are on the rise. They aim to deceive candidates through emails and calls to obtain sensitive information.

Here’s our recruitment promise to you:

  • Comprehensive Interview Process: We never extend job offers without a comprehensive interview process involving our recruitment team and hiring managers.
  • Offer Communications: Our job offers are not sent solely through email, and we will never ask you to pay for your own hardware.
  • Email Verification: Recruiting emails from Veracode will always originate from an “@veracode.com" email address.

If you have any doubts about the authenticity of an email, letter, or telephone communication claiming to be from Veracode, please reach out to us at careers@veracode.com before taking any further action.

See more jobs at Veracode

Apply for this job

+30d

Lead Security Engineer (REMOTE)

jirasalesforceDesignazure

Serigor Inc. is hiring a Remote Lead Security Engineer (REMOTE)

Lead Security Engineer (REMOTE) - Serigor Inc. - Career PageSee more jobs at Serigor Inc.

Apply for this job

+30d

Senior Security Engineer

MozillaRemote UK
terraformDesignazureapipythonAWS

Mozilla is hiring a Remote Senior Security Engineer

Mozilla’s Infrastructure Security team is growing! We are looking for security practitioners to reduce risk in our systems and applications, and ensure our products live up to Mozilla’s dedication to privacy and a joyful Internet. This position is remote-friendly and open to most locations in the US and Canada.

Why Mozilla?

Mozilla Corporation is the non-profit-backed technology company behind pioneering brands like Firefox, the privacy-minded web browser, and Pocket, the content discovery platform. More than 270 million people around the world use its products each month.

Along with 20,000+ volunteer contributors and collaborators all over the world, Mozilla Corporation’s staff are driven by our vision to be the trusted guide through a joyful internet. We design, build and distribute software that enables people to enjoy the internet on their terms.

About this team and role:

Working closely with partners across IT, Site Reliability Engineering (SRE), along with other departments across Mozilla, the Security Engineer ensures that systems and services are secured through the implementation of technical and administrative security controls.

What you'll do:

  • Protect the services our products like Firefox, Mozilla VPN, Pocket, etc depend on from attacks and abuses
  • Design, build and deploy security frameworks such as cloud security, intrusion detection, vulnerability and patch management, application security services, system hardening, etc.
  • Design, review and improve the security controls of the organization
  • Write, maintain, and expand security automation and monitoring tools
  • Work with developers and operations across the organization to keep infrastructure safe
  • Translate technical and administrative security controls into platform security standards.
  • Define, refine, publish and evangelize the resulting cost effective security standards, ensuring accurate translation into platform configurations.
  • Continually work to improve Mozilla’s security posture by partnering and supporting other parts of the cybersecurity organization.

Successful candidates will have meaningful experience in one or more areas like GCP/AWS/Azure cloud security techniques, data security methodologies, vulnerability management and have extensive experience with security in all varieties of infrastructure.

You will be hardening and guiding recommendations for Mozilla’s systems and networks, infrastructure, application security services, and company assets, while ensuring the mission of privacy and security is upheld at all times. This is a hands-on role, and you will collaborate with other teams to guide proper security practices throughout the company.

What you'll bring:

  • 3+ years of relevant hands-on experience in a cybersecurity domain designing, publishing and building security practices.
  • 3+ years of experience translating technical and administrative security controls into actionable platform configurations.
  • 3+ years of experience managing cybersecurity lifecycle management.
  • 3+ years of experience in any cybersecurity domain(s).
  • Strong infrastructure security knowledge, from high level architectural concepts down to the implementation.
  • Security architecture background and experience, public cloud and on-premise.
  • Cloud Architecture background
  • Experience with Terraform
  • Experience securing large-scale deployments in major cloud stacks (AWS, GCP, or Azure), including automating controls and use of API functions.
  • A significant role in the operation of vulnerability management 
  • Development skills primarily in Python and Go. You should feel comfortable operating the services for the code you write and documenting it for others.
  • Log aggregation and analysis techniques, and you're familiar with the concepts of common SIEM technology such as Splunk.
  • A B.S. in Computer Science or relevant certifications would be lovely, but passion, curiosity, and real-world experience are preferred.
  • Experience in ensuring compliance with CIS benchmarks

About Mozilla 

Mozilla exists to build the Internet as a public resource accessible to all because we believe that open and free is better than closed and controlled. When you work at Mozilla, you give yourself a chance to make a difference in the lives of Web users everywhere. And you give us a chance to make a difference in your life every single day. Join us to work on the Web as the platform and help create more opportunity and innovation for everyone online.

Commitment to diversity, equity, inclusion, and belonging

Mozilla understands that valuing diverse creative practices and forms of knowledge are crucial to and enrich the company’s core mission.  We encourage applications from everyone, including members of all equity-seeking communities, such as (but certainly not limited to) women, racialized and Indigenous persons, persons with disabilities, persons of all sexual orientations,gender identities, and expressions.

We will ensure that qualified individuals with disabilities are provided reasonable accommodations to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment, as appropriate. Please contact us at hiringaccommodation@mozilla.com to request accommodation.

We are an equal opportunity employer. We do not discriminate on the basis of race (including hairstyle and texture), religion (including religious grooming and dress practices), gender, gender identity, gender expression, color, national origin, pregnancy, ancestry, domestic partner status, disability, sexual orientation, age, genetic predisposition, medical condition, marital status, citizenship status, military or veteran status, or any other basis covered by applicable laws.  Mozilla will not tolerate discrimination or harassment based on any of these characteristics or any other unlawful behavior, conduct, or purpose.

Group: D

#LI-REMOTE

Req ID: R2307

To learn more about our Hiring Range System, please click this link.

Hiring Ranges:

Remote UK
£65,000£96,000 GBP

See more jobs at Mozilla

Apply for this job

+30d

Staff Software Engineer - Application Security

3P&T Security RecruitingEverett, WA, Remote
Designpythonjavascript

3P&T Security Recruiting is hiring a Remote Staff Software Engineer - Application Security

Job Description

They are looking for an experienced Staff Security Engineer to join their security team.  This role combines research, analysis, prevention, detection and forensics.  You will be engaged in everything from building safer and more security systems to detecting advanced (APT) attackers.  This role will require constant adaptation to new challenges that may arise in their ever-growing surface area.

In this role, you will:

  • Work with teams to discover and implement new detection capabilities and logging sources.
  • Be a thought leader in building our client's security road-map.
  • Be a security subject matter expert and respond to internal security engineering questions/requests.
  • Operate external bug bounty programs to source vulnerability information.
  • Architect, design and implement defensive systems that enhance their security.
  • Carefully balance security risk and product advancement.
  • Respond to security and privacy incidents, write incident reports, and participate in post-postmortems.
  • Perform penetration testing on their internal and external applications.
  • Integrate customer security requirements into product and system design.

Qualifications

Minimum required qualifications:

  • Bachelor's degree in Computer Science/Engineering or equivalent practical experience.
  • 8+ years of experience on security-focused teams.
  • Stellar programming/coding fundamentals.
  • Expertise working with web services deployed on Cloud providers.

The ideal candidate will also have:

  • Programming mastery in Go, Python, C/C++, JavaScript, TypeScript.
  • Demonstrated ability to ship production-quality software in a dynamic environment.
  • Strong communication skills and drive to collaborate across teams.
  • Deep knowledge with data privacy regulations and compliance e.g. SOC 2, GDPR, CCPA
  • Experience working with firmware and hardware security.

 

See more jobs at 3P&T Security Recruiting

Apply for this job