Security Engineer Remote Jobs

31 Results

12d

Associate Security Engineer

ScienceLogicReston, VA or Remote
Bachelor's degreeremote-firstDesignmobile

ScienceLogic is hiring a Remote Associate Security Engineer

To comply with U.S. federal government requirements, U.S. citizenship is required for this position.

Who we are…

In a world of constant change, we're leading the charge towards truly autonomous enterprises. Our cutting-edge platform harnesses the power of automation and generative AI to revolutionize how businesses manage and optimize their IT operations.

We're not just adapting to digital transformation—we're accelerating it. Our solutions bring business and operations leaders together, unlocking new levels of innovation, efficiency, and scalability. We empower organizations to deliver superior customer experiences and drive revenue growth in an always-on, always-mobile world.

At ScienceLogic, we're building the foundation for Autonomic IT—a future where IT operations are self-healing, self-optimizing, and aligned perfectly with business objectives. Our team of visionaries is reshaping the $18+ billion IT operations market, creating cost-optimized, efficient, and next-level capabilities for enterprises worldwide.

 

What we’re looking for...

This early career professional will join our small, collaborative team. You'll act as a security expert in the following ways: design and implement systems and procedures to sustain the security, integrity, and availability of the organization's data. Assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, and forms of access to te organization's systems and the data contained in them. Track security violations and identify trends or exposures that could be addressed by additional training, technical measures, or use of application tools to enhance security. May participate in ethical simulated attacks or security violations to assess the organization's data security measures.

 

What you’ll be doing…

  • Conduct platform or operating system vulnerability scans that assess exposure of system to attacks or hacking. Monitor Security Operations pager and respond to issues of potential viral activity, spam, phishing.
  • Administer controls and review their application to ensure that system's controls, policies, and procedures are operating effectively relative to the predicted effectiveness of the controls.
  • Investigate events or incidents of apparent security breaches and report to appropriate authorities using corporate procedures.
  • Confer and collaborate with internal and external auditors to ensure that appropriate controls are installed, operating properly, and being monitored and reported.
  • May plan and/or conduct tests of the core infrastructure and the contingency environment for critical business applications to ensure business continuity in the event of a computer security incident.
  • Aggregate metrics of operation of security controls, as well as apparent attacks, breaches, and other pertinent data; track trends and prepare for periodic security reports.
  • Measure and improve patch management procedures with appropriate teams.
  • Participate in projects designed to test defenses against hacking, denial of service, spam, break-ins, or similar attacks. May provide guidance to infrastructure or application staff participating in exercise.
  • Examine and/or test new methodologies or tools that could be adopted to enhance security of platforms, infrastructure, or access to data.

Qualities you possess…

  • Bachelor's Degree or equivalent experience
  • Problem solving skills complemented with experience in solving information security device and application issues with customers is a must.
  • Good verbal and written communication skills as well as attention to detail.
  • Exceptional customer service skills and interpersonal skills. Ability to work in small teams.
  • Understanding of threat agents, attack vectors, and attack patterns as well as compensating controls and design patterns needed to mitigate risk
  • Ability to create technical documentation and diagrams using Microsoft Visio, Excel, Word and PowerPoint
  • Knowledge of single sign-on integration with on premise and cloud toolset

 

Recommended Certifications or Skills

  • Security+
  • AssociateCISSP
  • AssociateSSCP
  • Associate CCSP
  • OS/Linux/WINDOWS/MAC
  • Directory Services
  • Microsoft Office
  • Network Protocols
  • Scripting Languages (Python/Bash/PowerShell)

Benefits & Perks

  • A remote-first culture - work from home or come into the office, it's totally up to you.
  • Comprehensive medical, dental and vision plans.
  • 401(k) plan with employer match.
  • Flexible Paid Time Off (FTO) so that you can take the time that you need to re-energize.
  • Volunteer Time Off (VTO) - take two days off per calendar year to volunteer with your preferred charitable organization.
  • 5-year Service Milestone Sabbatical.
  • Paid parental leave.
  • Generous employee referral bonus program.
  • Pet insurance.
  • HQ Office centrally located in Reston Town Center featuring a well-stocked kitchen with rotating snacks and beverages, and catered lunch on Thursdays.
  • Regular virtual company-wide events, including cooking classes, yoga, meditation and more.
  • The opportunity to learn and develop from some of the best and brightest minds in the industry!

Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At ScienceLogic, we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which you are applying.

Base Salary Range For This Role Is$65,000 - $75,000 

About ScienceLogic

ScienceLogic empowers intelligent, automated IT operations, freeing up time and resources, and driving business outcomes with actionable insights. ScienceLogic’s AIOps platform sees broadly across clouds and on-premises, enabling business service visibility with relationship mapping, and workflow automation to eliminate manual tasks. Trusted by thousands of organizations across the globe, ScienceLogic’s technology has been proven for scale by the world’s largest service providers, enterprises and government agencies.

 

www.sciencelogic.com

 

All ScienceLogic employees have the responsibility to protect information assets, adhere to access controls, report suspicious activity, and comply with security and privacy policies.

 

#LI-Remote

 

See more jobs at ScienceLogic

Apply for this job

15d

Senior Staff Security Engineer

Cobalt.ioRemote - U.S
Bachelor's degree5 years of experiencejiraslackc++kubernetespython

Cobalt.io is hiring a Remote Senior Staff Security Engineer

Sr. Staff Security Engineer, Remote U.S

Who We Are 

Cobalt was founded on the belief of a fundamental human aspiration: the desire to live better and safer. It all started in 2013, when our founders realized that pentesting can be better. Today our diverse, fully remote team is committed to helping organizations of all sizes with seamless, effective and collaborative Offensive Security Testing that empower organizations to OPERATE FEARLESSLY and INNOVATE SECURELY.

Our customers can start a pentest in as little as 24 hours and integrate with advanced development cycles thanks to the powerful combination of our SaaS platform coupled with an exclusive community of testers known as the Cobalt Core. Accepting just 5% of applicants, the Cobalt Core boasts over 400 closely vetted and highly skilled testers who jointly conduct thousands of tests each year and are at the forefront of identifying and helping remediate risk across a dynamically changing attack surface.

Cobalt is an Equal Opportunity Employer and we strive to build a diverse and inclusive workforce at our company. At Cobalt we aspire to engage with diverse individuals, communities, and organizations in order to continue to nurture our unique rich diverse culture. Join our team, and be your true self to do your best work. 

Description

Cobalt’s Information Security team is rapidly growing and seeks an experienced Staff Security Engineer with a strong security background, problem-solving abilities and an obsession in driving continuous improvement in a high performing organization.You should be able to adapt quickly to new situations and find creative ways to drive security initiatives through a mix of meticulous planning and influence across stakeholder teams. We’re looking for an individual who can build and maintain security tools, SIEM monitoring platforms and processes. A thirst for knowledge, a curious mind and a desire to stay abreast of security developments in a dynamic company is a must.

What You'll Do

  • Lead initiatives for security operations center (SOC), security monitoring and threat detection
  • Manage incident response, threat hunting processes and workflows
  • Use security tools and technology to detect and eradicate threats
  • Drive continuous improvements for SOC and SOAR processes
  • Evaluate complex business and technical requirements, communicating inherent risk and solutions to technical and non-technical business owners

You Have

  • 3-5 years of experience in managing SIEM and Security Monitoring tools required
  • Hands on knowledge of Google SecOps SIEM/SOAR Tool or equivalent SIEM Tool experience
  • Jira / Confluence for Ticket automation and documentation or equivalent ticket system
  • Cloud Security knowledge and experience, GCP and Kubernetes preferred
  • MITRE Kill Chain framework and threat hunting experience
  • Demonstrated leadership abilities in driving operational excellence and best practices
  • Ability to adapt to a hyper-growth pace and manage priorities
  • Experience delivering technical information to a less-technical audience in an impactful way
  • Experience providing mentorship and support to teams outside of InfoSec to enable them to get their job done while operating securely
  • Experience with Parameter 81 VPN 

Bonus If You Have

  • Hands on Crowdstrike EDR endpoint security or equivalent tool experience preferred
  • Hands on Cloudflare WAF and DDoS management or equivalent tool experience preferred
  • Scripting skills using Python or equivalent scripting language
  • Slack automation and ticketing workflows
  • Knowledge and experience of SOC2, ISO compliance frameworks, controls management, audit readiness

Why You Should Join Us

  • Grow in a passionate, rapidly expanding industry operating at the forefront of the Pentesting industry 
  • Work directly with experienced senior leaders with ongoing mentorship opportunities
  • Earn competitive compensation and an attractive equity plan
  • Save for the future with a 401(k) program (US) or pension (EU) 
  • Benefit from medical, dental, vision and life insurance (US) or statutory healthcare (EU)
  • Leverage stipends for:
    • Wellness
    • Work-from-home equipment & wifi
    • Learning & development
  • Make the most of our flexible, generous paid time off and paid parental leave 

Pay Range Disclosure(For US openings only)

 

Cobalt is committed to fair and equitable compensation practices. The salary range for this role is ($150,000 - $200,000) per year + equity + benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, and certifications.  The salary range may differ in other states and may be impacted by proximity to major metropolitan cities. 

 

Cobalt (the "Company") is an equal opportunity employer, and we want the best available persons for every job. The Company makes employment decisions only based on merit. It is the Company's policy to prohibit discrimination in any employment opportunity (including but not limited to recruitment, employment, promotion, salary increases, benefits, termination and all other terms and conditions of employment) based on race, color, sex, sexual orientation, gender, gender identity, gender expression, genetic information, pregnancy, religious creed, national origin, ancestry, age, physical/mental disability, medical condition, marital/domestic partner status, military and veteran status, height, weight or any other such characteristic protected by federal, state or local law. The Company is committed to complying with all applicable laws and providing equal employment opportunities. This commitment applies to all persons involved in the operations of the Company regardless of where the employee is located and prohibits unlawful discrimination by any employee of the Company.

Cobalt is an E-Verify employer. E-Verify is an Internet-based system operated by the Department of Homeland Security (DHS) in partnership with the Social Security Administration (SSA). It allows participating employers to electronically verify the employment eligibility of their newly hired employees in the United States.

See more jobs at Cobalt.io

Apply for this job

22d

Security Engineer

OmetriaPortugal, Remote
SalesterraformDesignmobileAWS

Ometria is hiring a Remote Security Engineer

We are looking for a Security Engineer. You’ll be directly responsible for safeguarding Ometria’s digital assets by actively managing risks to maintain a secure and resilient environment. You will work closely with our Product and Engineering teams to ensure that security and privacy best practices are followed whilst finding solutions to meet our business  goals.

Who are we?

Ometria is a Customer Data and Experience Platform built for retail marketers to be the fastest route to sustainable growth. Ometria helps marketers plan and launch their most profitable campaigns twice as fast, increasing their customer loyalty and CRM revenue with personalized marketing messages all throughout the customer journey.

Our platform combines the data unification and customer insight of a CDP with an experience platform, letting retail marketers easily and efficiently create experiences their customers love across email, mobile, on-site, social, direct mail and more.

Ometria is trusted by some of the fastest growing retail brands in the world such as Brooklinen, Davines, Steve Madden, and Sephora.

We have a team of over 120 Ometrians based in North America and Europe. We have raised $75m from leading venture capital funds across the world such as Infravia Capital Partners, Octopus Ventures, Summit Action, Sonae IM and many others

What you'll be doing:

Key Outcomes:

  • Work with the security, legal and people teams to pass the annual ISO 27001 and 27701 audit to reduce the likelihood / impact of incidents and to demonstrate the ‘respect for the trust we’ve been given’ as a business. 
  • Identify opportunities to upskill and educate on security and privacy best practices eg. present on tech strategy/tech session/all hands
  • Ensure privacy and security measures are integrated into all projects to reduce risk and minimise the chance of incidents 

Key Responsibilities:

  • Responding to alerts and security and privacy risk events
    • Alert triage
    • Identification and assessment of risks
    • Following security and privacy playbooks for any incidents
    • Writing incident reports
  • Building and maintaining expertise in security and privacy through learning and certifications
  • Sharing expertise with colleagues by:
    • Advising on project risk reduction through security and privacy by design practices
    • Helping with vulnerability triage and recommending appropriate fixes or mitigations
    • Recommending improvements to policies and processes of the company
  • Building trust in the company through participation in ISO 27001 and 27701 audits, working with penetration testers and external security researchers, and input into sales questionnaires and client vendor security reviews

About you:

  • Experienced - You will have previously worked for 3+ years developing in / administering an AWS cloud environment and can make improvements to AWS configurations. Prior experience using terraform would be an advantage.
  • Curious - you are excited about technology and like learning new things. You take proactive steps to educate yourself on what’s happening in the security and privacy industry, and how this can better inform our internal practices
  • Accountability - You work with a level of independence on tasks / projects that you are assigned and are able to identify challenges to minimise delay or impact. You work diligently to finish your work within agreed deadlines.
  • Analytical skill - You utilise evidence and data to methodically make informed decisions and are comfortable analysing large amounts of data. You are able to critically consider projects and identify security and privacy risks.
  • Business Focus- Ability to identify risk whilst pragmatically considering the commercial impact and necessary actions
  • Confident communicator -You contribute to Engineering scoping discussions and are confident giving  constructive feedback and challenging ideas with a wide variety of stakeholders. You feel comfortable presenting best practice updates and training to internal audiences.

The amazing people of Ometria are the core of our business. We believe in making it awesome to be here for all Ometrians and place a continued focus on making Ometria an inclusive, respectful and diverse environment. 

We're an equal opportunity employer and all applicants will be considered for employment without attention to ethnicity, age, religion, sexual orientation, gender identity, family or parental status, national origin, veteran, neurodiversity status or disability status.



See more jobs at Ometria

Apply for this job

TripActions is hiring a Remote Sr. Corporate Security Engineer

Job Application for Sr. Corporate Security Engineer at Navan{"@context":"schema.org","@type":"JobPosting","hiringOrganization":{"@type":"Organization","name":"Navan"},"title":"Sr. Corporate Security Engineer","datePosted":"2024-11-26","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, California, United States","addressRegion":"CA","addressCountry":null,"postalCode":null}},"description":"\u003cp\u003eWe are seeking a Senior Corporate Security Engineer to join our team. This role is integral to ensuring the security of our corporate environment across all devices, applications, and networks. The ideal candidate will have a deep understanding of enterprise IT security within a modern SaaS company and will be passionate about automating and scaling security processes. You will work on securing our corporate infrastructure, implementing cutting-edge security solutions, and collaborating with various teams to enhance our overall security posture.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eWhat You'll Do\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eManage Workforce IAM and identity governance (IGA): Oversee and optimize our Identity and Access Management systems, specifically leveraging Okta, to ensure secure and efficient user authentication and authorization and implement access management and approval automation workflows.\u003c/li\u003e\n\u003cli\u003eSecure Devices and Endpoints: Develop and implement security strategies for all corporate devices and endpoints to protect against unauthorized access and threats.\u003c/li\u003e\n\u003cli\u003eImplement Zero Trust Network Access: Design and deploy Zero Trust security models to enhance network security and safeguard company resources.\u003c/li\u003e\n\u003cli\u003eEnhance Email Security: Develop and maintain robust email security protocols to prevent phishing, spam, and other email-borne threats.\u003c/li\u003e\n\u003cli\u003eDeploy Data Loss Prevention (DLP) Solutions: Implement DLP strategies focusing on protecting PII and PCI data within SaaS applications like Google Workspace, Salesforce, and Box.\u003c/li\u003e\n\u003cli\u003eEnable Large-Scale Endpoint Management: Facilitate the deployment of secure operating systems and platforms at scale to reduce attack surfaces and improve endpoint management.\u003c/li\u003e\n\u003cli\u003eOrchestrate Security Posture Checks: Automate security checks for all new infrastructure deployments to ensure compliance with security standards.\u003c/li\u003e\n\u003cli\u003eImplement Endpoint State Attestation: Deploy tooling to continuously validate the security state of endpoints.\u003c/li\u003e\n\u003cli\u003eScale Proactive Security Controls: Extend security measures to new environments, including those acquired through mergers or acquisitions.\u003c/li\u003e\n\u003cli\u003eCollaborate on Physical Security: Work closely with the physical security team to integrate security measures and communicate effectively about potential risks and solutions.\u003c/li\u003e\n\u003cli\u003eStay Current with Industry Trends: Keep abreast of the latest security threats, technologies, and trends to proactively address potential vulnerabilities.\u003c/li\u003e\n\u003cli\u003eDevelop Custom Security Solutions: Contribute to the development of custom and open-source security tools tailored to our needs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eWhat We're Looking For\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExperience: Minimum of 5 years of experience in corporate security engineering within a SaaS or similar environment.\u003c/li\u003e\n\u003cli\u003eTechnical Expertise:\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eStrong knowledge of securing devices and endpoints.\u003c/li\u003e\n\u003cli\u003eProficiency with Okta for workforce Identity and Access Management; Okta Certification is a plus.\u003c/li\u003e\n\u003

See more jobs at TripActions

Apply for this job

26d

Security Engineer/Analyst

Marex SpectronLondon, GB - Remote - Hybrid
agilelinux

Marex Spectron is hiring a Remote Security Engineer/Analyst

Marex is a diversified global financial services platform, providing essential liquidity, market access and infrastructure services to clients in the energy, commodities and financial markets.

The Group provides comprehensive breadth and depth of coverage across four core services: Market Making, Clearing, Hedging and Investment Solutions and Agency and Execution. It has a leading franchise in many major metals, energy and agricultural products, executing around 50 million trades and clearing 205 million contracts in 2022. The Group provides access to the world’s major commodity markets, covering a broad range of clients that include some of the largest commodity producers, consumers and traders, banks, hedge funds and asset managers.

Marex was established in 2005 but through its subsidiaries can trace its roots in the commodity markets back almost 100 years. Headquartered in London with 36 offices worldwide, the Group has over 1,800 employees across Europe, Asia and America.

For more information visit www.marex.com

Marex has unique access across markets with significant share globally both on and off exchange. The depth of knowledge amongst its teams and divisions provides its customers with clear advantage, and its technology-led service provides access to all major exchanges, order-flow management via screen, voice and DMA, plus award-winning data, insights and analytics.

The Technology Department delivers differentiation, scalability and security for the business. Reporting to the COO, Technology provides digital tools, software services and infrastructure globally to all business groups. Software development and support teams work in agile ‘streams’ aligned to specific business areas. Our other teams work enterprise-wide to provide critical services including our global service desk, network and system infrastructure, IT operations, security, enterprise architecture and design.

The Information Security team reports to the CTO and is responsible for protecting Marex data and assets, as well as providing security advice. The team is relatively small; therefore, its members have a chance to experience various areas of security.

The Cyber Security Engineer will work in the team managed by the Cyber Security Manager providing cyber security services to entities across the Marex Group. The primary responsibility is to provide protection against cyber threats by proactive monitoring of control effectiveness, but also to respond to identified threats.

The role requires an experienced security professional capable of managing a wide range of tasks, such as automation, exploring new technologies or working with external partners.

Ability to effectively manage multiple priorities and knowledge of technology are key skills to be successful in this position.

Responsibilities:

• Performs vulnerability assessment scans and collaborates with other teams on remediation approach
• Monitors security toolset and controls to identify potential incidents, network intrusions, and malware events, etc., ensuring confidentiality, integrity, and availability of Marex’s critical systems
• Developing and documenting cyber security standards and procedures
• Collaborates with technology teams for incident handling, patching disciplines, and system hardening frameworks
• Collaborates with the Information Technology team on deployment, operation, and continual improvements of security solutions
• Automation of tasks and creation of analytical tools
• Keeping up to date with security news and trends
• Threat Intelligence and Hunting
• Responding and investigating security incidents and exceptions
• Providing relevant KPI and KRI metrics.

Competencies:

• Demonstrates curiosity.
• Resilient in a challenging, fast-paced environment.
• Excels at building relationships, networking and influencing others.
• Strategic collaborator with insight and agility, able to anticipate future challenges, ensuring operational effectiveness.

Skills and Experience:

• Solid, specialist experience in the field of Information Security.
• Comprehensive knowledge and expertise across multiple technologies and protocols, such as Entra, TLS, IDS, SIEM, DLP, WAF, DMARC, AV/EDR, XDR, CNAPP.
• Knowledge of security processes (like vulnerability management or penetration testing), standards (like CIS) and frameworks (like NIST)
• Good understanding of Windows, Linux and Cloud solutions
• Excellent communication skills, with the ability to effectively engage with stakeholders.

If you’re forging a career in this area and are looking for your next step, get in touch!

Marex is fully committed to being an inclusive employer and providing an inclusive and accessible recruitment process for all. We will provide reasonable adjustments to remove any disadvantage to you being considered for this role. We value the differences that a diverse workforce brings to the company. We welcome applications from candidates returning to the workforce. Also, Marex is committed to avoiding circumstances in which the appearance or possibility of conflicts of interest may exist within the hiring process.

If you would like to receive any information in a different way or would like us to do anything differently to help you, please include it in your application.


#LI-MH1

See more jobs at Marex Spectron

Apply for this job

+30d

Principal Firmware Security Engineer

Western DigitalRochester, MN, Remote
RustagileDesignpython

Western Digital is hiring a Remote Principal Firmware Security Engineer

Job Description

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Development of various cryptography-based security features such as data encryption, Secure Boot, and Device Attestation.
  • Integrate these security protocols and features into the SSD data and control flows to ensure a robust and secure system. Additionally, investigate and resolve any security protocol compatibility issues that may arise.
  • Investigating failures, documenting bug reports, and providing valuable assistance to product teams in identifying and resolving issues.
  • Debugging, optimizing, and validating the Firmware on SoC platforms, as well as bringing up of FPGA and ASIC.
  • Contribute to the Security Development Lifecycle of the Firmware by supporting its development at different stages, including design, threat analysis, implementation, validation, vulnerability testing, certification, and audit.

Qualifications

REQUIRED:

To qualify for this position, an ideal candidate would have/be

  • A degree in Computer Science, Electrical/Computer Engineering, Software Engineering, or a related field.
  • 8+ years of experience in embedded programming, with proficiency in C/C++ and one or more of the following: Python, Rust, Go.
  • Experience in firmware code review, CI/CD test and validation methodology, as well as static and dynamic code analysis. Familiarity with the Agile software development process life cycle is also desired.
  • Proficiency in failure analysis in debugging an embedded firmware application, using debuggers such as Lauterbach.
  • An engineer who can take ownership of given features and manage them from start to finish. Being self-motivated and driven is essential for this role.
  • Good communication skills and be able to work effectively with cross-functional teams.

What Sets You Apart

  • Detailed knowledge of RISC-V Instruction Set Architectures (ISA)
  • Technical expertise in applied cryptography and firmware/hardware security, including knowledge of data encryption, trusted execution environment, secure boot, and device attestation.
  • Knowledge of storage controller architectures and security protocols, such as TCG Opal/Ruby/Pyrite, IEEE 1667, SPDM, and IDE.
  • Familiarity with writing code in Github repository and it’s CI/CD testing framework.

See more jobs at Western Digital

Apply for this job

+30d

Senior Security Engineer

LatticeRemote - US
remote-firstslackc++

Lattice is hiring a Remote Senior Security Engineer

This is Engineering at Lattice

Lattice’s Engineering team is continuously working to better both our product and our craft. We use a modern, cutting-edge tech stack and love experimenting with new technologies. We strive for maintainable, robust, and performant code. We’re highly collaborative and continuously iterative and work closely with designers and product managers. We prioritize not only great technical architecture but also an amazing product experience.

As a critical member of Lattice's security team, you will play a pivotal role in auditing and strengthening our identity and access management (IAM) controls. Your responsibilities will include reviewing IAM configurations, pulling audit evidence and writing documentation, capturing configuration screenshots, and ensuring alignment with Lattice's security standards and compliance requirements. This role is ideal for someone with a deep technical understanding of IAM systems and a proactive approach to continuous improvement.

What You Will Do

  • Conduct in-depth audits of systems for IAM configurations, ensuring compliance with security standards by gathering audit evidence and capturing configuration screenshots.
  • Review and enhance IAM security controls across key corporate systems like Okta (identity and access management), Zscaler (network access controls), and CrowdStrike (endpoint access controls), recommending best practices for improved security.
  • Collaborate with IT and engineering teams to assess and optimize IAM configurations, ensuring they support secure, role-based access and effective incident detection.
  • Lead compliance initiatives and walkthroughs from a system perspective, including SOC2 audits, by preparing audit documentation specific to IAM controls and ensuring all evidence is properly documented and accessible.
  • Proactively manage IAM-related security alerts, triaging incidents to mitigate potential access threats and continually optimizing alert rules and thresholds.
  • Develop and maintain detailed documentation for IAM processes, controls, and evidence, ensuring they reflect current industry standards and Lattice security policies.

What You Will Bring to the Table

  • 5+ years of experience in security operations, auditing, or IT with a focus on identity and access management systems and security compliance.
  • Strong expertise in managing IAM tools and controls within platforms like Okta, Zscaler, and CrowdStrike, with a comprehensive understanding of secure configuration and role-based access control options.
  • Demonstrated ability to assess IAM configurations, recommend security improvements, and implement best practices for system hardening.
  • Knowledge of compliance frameworks (SOC2 preferred), authentication protocols, access management best practices, and role-based access control methods.

----

The estimated annual cash salary for this role is $166,000 - $207,500. This position is also eligible for incentive stock options, subject to the terms of Lattice’s applicable plans

Benefits: The Company offers the following benefits for this position, subject to applicable eligibility requirements: Medical insurance; Dental insurance; Vision insurance; Life, AD&D, and Disability Insurance; Emergency Weather Support; Wellness Apps; Paid Parental Leave, Paid Time off inclusive of holidays and sick time; Commuter & Parking Accounts; Lunches in the Office; Workplace Amenities Stipend, Internet and Phone Stipend; One time WFH Office Set-Up Stipend; 401(k) retirement plan; Financial Planning; Learning & Development Budget; Sabbatical Program; and Invest in Your People Fund

*Note on Pay Transparency:

Lattice provides an estimate of the compensation for roles that may be hired as required by state regulations. Compensation may vary based on (a) location, as Lattice factors in specific location when benchmarking compensation for most roles; (b) individual candidate skills and qualifications; and (c) individual candidate experience.

Additionally, Lattice leverages current market data to determine compensation, so posted compensation figures are subject to change as new market data becomes available. The salary, other compensation, and benefits information is accurate as of the date of this posting. Lattice reserves the right to modify this information at any time, subject to applicable law.

#LI-remote

About Lattice

Lattice is on a mission to build cultures where employees and their companies thrive. In an age where employees have more choices than ever before, businesses that put employees first are winning ????– and Lattice is building the tools to empower those people-centric companies.

Lattice is a people success platform that offers performance reviews, employee engagement surveys, real-time feedback, weekly check-ins, goal setting, and career planning in a way that allows companies to focus on employee development, growth, and engagement – yielding stronger employee retention, performance, and impact to the bottom line ????. Since launching in 2016, we have grown to over 5,000+ customers globally, including brands like Slack, Robinhood, and Gusto. 


Lattice is committed to equal treatment and opportunity in all aspects of recruitment, selection, and employment without regard to gender, race, religion, national origin, ethnicity, disability, gender identity/expression, sexual orientation, veteran or military status, or any other category protected under the law. Lattice is an equal opportunity employer; committed to a community of inclusion, and an environment free from discrimination, harassment, and retaliation.

By clicking the "Submit Application" button below, you consent to Lattice processing your personal information for the purpose of assessing your candidacy for this position in accordance withLattice's Job Applicant Privacy Policy.

Apply for this job

Databricks is hiring a Remote Senior Security Engineer (Incident Response)

Job Application for Senior Security Engineer (Incident Response) at Databricks

See more jobs at Databricks

Apply for this job

+30d

Senior Security Engineer

NuveiTel Aviv-Yafo,Tel Aviv District,Israel, Remote Hybrid
terraformDesignazuredockerkuberneteslinuxpythonAWS

Nuvei is hiring a Remote Senior Security Engineer

The world of payment processing is rapidly evolving, and businesses are looking for loyal and strategic partners, to help them grow.  

WE ARE NUVEI. Nuvei (NASDAQ: NVEI) (TSX: NVEI) is a Canadian fintech company accelerating the business of clients around the world. Nuvei’s modular, flexible, and scalable technology allows leading companies to accept next-gen payments, offer all payout options, and benefit from card issuing, banking, risk, and fraud management services. Connecting businesses to their customers in more than 200 markets, with local acquiring in 47 markets, 150 currencies, and 586 alternative payment methods, Nuvei provides the technology and insights for customers and partners to succeed locally and globally with one integration.  

At Nuvei, we live our core values, and we thrive on solving complex problems. We’re dedicated to continually improving our product and providing relentless customer service. We are always looking for exceptional talent to join us on the journey!  

We are seeking a highly skilled and motivated Senior Security Engineer to join our dynamic Technical Security Operations team. In this role, you will be responsible for designing, implementing, and maintaining robust security systems across a variety of platforms, protecting the company’s digital assets, and continuously evolving our security posture. You will collaborate closely with the CISO and other key stakeholders to ensure that security is deeply integrated into all aspects of the company’s infrastructure and operations. You will be reporting to the Technical Security Operations team leader. 

Key Responsibilities: 

  • Lead the implementation, configuration, and ongoing maintenance of a variety of advanced security technologies, including but not limited to EDR, Proxy, DLP, email protection, and other critical security solutions. 
  • Collaborate with the CISO and security leadership to align security strategies with business objectives, ensuring security requirements are properly designed and executed across the company’s infrastructure. 
  • Continuously monitor and analyze security systems, firewalls, logs, and relevant data sources to detect, analyze, and respond to potential security threats in real time. 
  • Regularly assess and refine the security architecture to ensure it meets current and emerging threats while aligning with best practices. 
  • Conduct thorough market research and spearhead proof of concept (POC) evaluations for new security tools, identifying opportunities to improve the organization’s overall security posture. 
  • Identify and assess emerging security threats through continuous monitoring, vulnerability assessments, and log analysis, proactively addressing risks before they materialize. 
  • Enhance internal security controls, including identity and access management (IAM), key management, security monitoring, and cloud security posture management (CSPM). 
  • Ensure security best practices and policies are adhered to across all systems and services. 

Required Qualifications: 

  • 5+ years of hands-on experience in security engineering, with deep expertise in multiple IT security domains. 

Proven expertise in the following areas: 

  • Data Loss Prevention (DLP) 
  • Endpoint Protection (EDR/XDR) 
  • Proxy Solutions (Forcepoint, Netskope) 
  • Identity Providers (Okta, Entra ID) 
  • Email Protection 
  • SIEM  
  • Threat Intelligence and Vulnerability Management 
  • Network Security (firewalls, VPNs, WAF, NAC) 
  • Directory Services (Active Directory, Azure AD) 
  • Sandbox Solutions 
  • Vulnerability Assessment Solutions (VAS) 
  • Cloud Security Posture Management (CSPM) 
  • Data Security Posture Management (DSPM) 
  • Static Application Security Testing (SAST) 
  • Dynamic Application Security Testing (DAST) 
  • Strong experience securing Windows, Linux, and macOS environments, with a comprehensive understanding of system security controls. 
  • Demonstrated expertise in both on-premises and cloud architecture security, with experience securing public cloud platforms (AWS, GCP, Azure). 
  • Advanced knowledge of network security, protocols, and the ability to secure complex network environments. 
  • Familiarity with host-based forensics, OS artifacts, and exploitation methods, with the ability to respond to security incidents effectively. 
  • Hands-on experience with scripting languages such as Bash, Python, or PowerShell, along with proficiency in infrastructure-as-code tools (Terraform, CloudFormation). 
  • Familiarity with compliance frameworks and certification programs (PCI-DSS, SOC II, ISO27001), with the ability to manage security audits and maintain compliance. 
  • Proven ability to lead cross-functional security initiatives, driving collaboration and widespread adoption of security best practices across teams. 
  • Passionate about staying ahead of the curve in cybersecurity trends, emerging threats, and security technologies. 

Preferred Qualifications: 

  • Experience with security design, threat modeling, and conducting security audits. 
  • Familiarity with containerization and cloud-native technologies (Kubernetes, Docker). 
  • Strong analytical and problem-solving skills, with attention to detail and a proactive approach to addressing complex security challenges
  • SOAR solutions. 

See more jobs at Nuvei

Apply for this job

+30d

Senior Security Engineer

PindropUS - Remote
Lambdaremote-firstazurelinuxpythonAWS

Pindrop is hiring a Remote Senior Security Engineer

Senior Security Analyst

US-Remote

Who we are

Are you passionate about innovating at the intersection of technology and personal security? At Pindrop, we recognize that the human voice is a unique personal identifier, increasingly susceptible to sophisticated fraud, including the threat of deepfakes. We're leading the way in developing cutting-edge authentication, fraud prevention, and deepfake detection. Our mission is to provide seamless and secure digital experiences, safeguarding the most personal aspect of our identity: our voice. Here, you'll be part of a team driven by values of Innovation, Customer Advocacy, Excellence, and Impact. We're not just creating a safer digital landscape by fortifying trust and integrity with those we serve, we’re also building a dynamic, supportive workplace where your contributions make a real difference.

Headquartered in Atlanta, GA, Pindrop is backed by world-class investors such as Andreessen-Horowitz, IVP, and CapitalG.

What you’ll do 

  • Represent security in internal and external meetings to discuss security analysis, findings and security/compliance responses. 
  • Review past incidents and identify attack trends. Finetune and reconfigure alerts based on prior incidents to improve detection.
  • Actively participate in the development, documentation, and implementation of new processes to expand and mature capabilities for the organization.
  • Identify and track internal and external assets to identify potential risks. Communicate these risks to internal and external stakeholders and build a plan of action.
  • Develop, update, and maintain a repository of cybersecurity threat information that may be used in conducting risk assessments and reports on cyber risk trends.
  • Build and maintain tools for automation of security events and reporting. Optimize and reconfigure tools to improve security processes.
  • Implement, maintain and monitor IDS/IPS rule sets, alerts and reports.
  • Perform investigations and improve detection processes on a wide variety of security events from various sources to determine whether they pose a threat to Pindrop
  • Identify, research and develop internal and open source tools used to improve security and threat intelligence workflows to support Pindrop's unique environment
  • Collaborate with internal and external teams to answer customer questionnaires, compliance audits.

Who you are

  • You are, hands-on problem solver that excels in dynamic fast paced environments, curious and always looking to learn., highly interested in how things work and gets excited by threat modeling and new exploits
  • You are resilient in the face of challenges, change, and ambiguity
  • You are optimistic and believe that you can make a problem into a solution
  • You are resourceful, excited to uncover innovative solutions and teach yourself something new when needed
  • You take accountability, do the things you say you’ll do, under-promise and over-deliver
  • You are nimble and adaptable when priorities change and continue to see the “forest through the trees” 

Your skill-set: 

  • 2+ years of security monitoring and incident response experience
  • Must have experience with Linux, Mac, and knowledge of Windows
  • Experience in configuration and maintenance of endpoint security solutions, eg. Crowdstrike, SentinelOne, Carbon Black.
  • Experience with security tools including SIEM, Metasploit, Splunk, Wireshark
  • In-depth knowledge of SIEM log ingestion and alert creation.
  • Hands-on experience with TCP/IP and networking
  • Ability to write scripts/code using Python or other scripting languages for automation
  • Knowledge of incident response and investigation tools and techniques
  • Experience with security operations in cloud platforms such as AWS, GCP, Azure etc.
  • Experience responding to security questionnaires and customer questions

Nice to have:

  • Experience with forensic analysis tools (commercial and open-source) and procedures desired
  • Experience with threat feeds and threat intelligence (e.g., STIX, TAXII, IOCs) desired
  • Experience with cloud logging applications, AWS Cloudtrail, VPC Flow Logs, Lambda, etc.

What’s in it for you:

As a Pindropper, you join a rapidly growing company making technology more human with the power of voice. You will work alongside some of the best and brightest. We’re a passionate group committed to excellence - but that doesn’t stop us from enjoying the journey as a team with chess and poker tournaments, catered lunches and happy hours, wellness programming, and more. Because we take our jobs seriously, we add in time for rest with Unlimited PTO, Focus Thursday, and Company-wide Rest Days.

Within 30 days:

  • You’ll focus on training and learning the basics of the company. This includes the company’s systems, procedures that should be adhered to, products and services, software, vendors, and/or clients.
  • You’ll have been introduced to your team, colleagues and have 1:1’s to assimilate into the company culture.
  • You will have the opportunity to learn the product in and out through training and a variety of resources. This then means that the majority of the things-to-do should fall along the lines of attending training sessions, gaining and mastering product knowledge, learning major corporate systems, meeting the members of your team, and getting the necessary access. 

Within 60 days:

  • You’ll have a good grasp of your working environment and you can now move onto more advanced tasks. 
  • You will start studying the best practices in the industry, create goals, meet up with your supervisor and get feedback on your performance, and build meaningful relationships with your co-workers along with taking on proper job responsibilities.  

Within 90 days

  • You’ll demonstrate a firm grasp of the company and confidence in your job function. Thus, you should be preparing to make breakthrough contributions to your team or department. 
  • The contributions may include finding new ways to improve security or coming up with ideas to save the company money. Instead of only identifying problems in the company, you should be at the forefront of brainstorming possible solutions. 
  • You will be able to spearhead new initiatives and collaborate with other teams for the good of the company. 

What we offer

As a part of Pindrop, you’ll have a direct impact on our growing list of products and the future of security in the voice-driven economy. We hire great people and take care of them. Here’s a snapshot of the benefits we offer:

  • Competitive compensation, including equity for all employees
  • Unlimited Paid Time Off (PTO)
  • 4 company-wide rest days in 2024 where the entire company rests and recharges!
  • Remote-first culture

What we live by

At Pindrop, our Core Values are fundamental beliefs at the center of all we do. They are our guiding principles that dictate our actions and behaviors. Our Values are deeply embedded into our culture in big and small ways and even help us decide right from wrong when the path forward is unclear. At Pindrop, we believe in taking accountability to make decisions and act in a way that reflects who we are. We truly believe making decisions and acting with our Core Values in mind will help us to achieve our goals and keep Pindrop a great place to work:    

  • Audaciously Innovate - We continue to change the world, and the way people safely engage and interact with technology. As first principle thinkers, we challenge standards, take risks and learn from our mistakes in order to make positive change and continuous improvement. We believe nothing is impossible.
  • Evangelical Customers for Life - We delight, inspire and empower customers from day one and for life. We create a partnership and experience that results in a shared passion.   We are champions for our customers, and our customers become our champions, creating a universal commitment to one another. 
  • Execution Excellence - We do what we say and say what we do. We are accountable for making the tough decisions and necessary tradeoffs to deliver quality and effective solutions on time.
  • Win as a Company - Every time we win, we win as a company. Every time we lose, we lose as a company. We break down silos, support one another, embrace diversity and celebrate our successes. We are better together. 
  • Make a Difference - Every day we have the opportunity to make a positive impact. We operate with dedication, passion, and uncompromising integrity, creating a safer, more secure world.

Not sure if this is you?

We want a diverse, global team, with a broad range of experience and perspectives. If this job sounds great, but you’re not sure if you qualify, apply anyway! We carefully consider every application and will either move forward with you, find another team that might be a better fit, keep in touch for future opportunities, or thank you for your time.

Pindrop is an Equal Opportunity Employer

Here at Pindrop, it is our mission to create and maintain a diverse and inclusive work environment. As an equal opportunity employer, all qualified applicants receive consideration for employment without regard to race, color, age, religion, sex, gender, gender identity or expression, sexual orientation, national origin, genetic information, disability, marital and/or veteran status.

#LI-Remote

See more jobs at Pindrop

Apply for this job

+30d

Security Engineer

AcquiaRemote - Costa Rica
EC29 years of experience6 years of experienceagile3 years of experienceterraformdrupaldockerMySQLkubernetesubuntulinuxpythonAWS

Acquia is hiring a Remote Security Engineer

Acquia empowers the world’s most ambitious brands to create digital customer experiences that matter. With open source Drupal at its core, the Acquia Digital Experience Platform (DXP) enables marketers, developers, and IT operations teams at thousands of global organizations to rapidly compose and deploy digital products and services that engage customers, enhance conversions, and help businesses stand out.

Headquartered in the U.S., Acquia is positioned as a market leader by the analyst community and is listed as one of the world’s top software companies by The Software Report. We are Acquia. We are a global company with employees located in more than 30 countries, and we’re building for the future.We want you to be a part of it!

Does the challenge of finding security flaws in custom application code get your mind racing? Can you think like an attacker to misuse and break cloud services? Do you have an interest in compliance and simplifying the process for achieving it? Join Acquia and help enhance the security of the largest sites and brands on the planet, whose Drupal apps are powered by our PaaS platform and SaaS services built on top of many thousands of AWS EC2 instances.

Job Responsibilities:

  • Be a Security Champion in an agile Security Engineering team owning and operating the services you build
  • Research, specify, and test cloud hosting architectures leveraging your web, database, and OS knowledge
  • Debug the toughest distributed systems production issues

Skills:

  • 2-6 years of related experience
  • Cloud security and compliance experience using AWS (e.g., Firewalls, IDS/IPS systems, DDOS prevention and PCI-DSS, HIPAA, FedRAMP, etc.)
  • Strong software development background using any general programming language
  • Understanding of Kubernetes
  • Passion for websites and website delivery architecture
  • Deep, working knowledge of LAMP stack--OS, web server, and database systems (Linux, Apache, and MySQL preferred)
  • Linux packages (e.g., Debian or RPM packages); RHEL and Ubuntu experience
  • Networking (e.g., TCP/IP, Routing, DNS, load balancing, HTTP caching, clustering, VPN, etc.)
  • Holistic understanding of the Internet and hosting from the network layer up through the application layer.
  • Excellent organizational and communication skills, both verbal and written
  • BS in Computer Science or equivalent experience
  • Ability to work effectively across multiple teams and drive results

Preferred Qualifications: 

  • Software development using Python or Go
  • Experience with threat modeling, especially for web application and web APIs
  • Configuration management (e.g., Terraform, CloudFormation, etc.)
  • Containerization:  Docker, LXC, etc.
  • Kubernetes: Hands-on, working experience securing K8s deployments according to “hard multi-tenancy” guidelines and methods.

All qualified applicants will receive consideration for employment without regard to race, color, religion, religious creed, sex, national origin, ancestry, age, physical or mental disability, medical condition, genetic information, military and veteran status, marital status, pregnancy, gender, gender expression, gender identity, sexual orientation, or any other characteristic protected by local law, regulation, or ordinance.

See more jobs at Acquia

Apply for this job

+30d

Offensive Security Engineer

MonzoCardiff, London or Remote (UK)
mobile

Monzo is hiring a Remote Offensive Security Engineer

???? We’re on a mission to make money work for everyone.

We’re waving goodbye to the complicated and confusing ways of traditional banking. 

With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers!

We’re not about selling products - we want to solve problems and change lives through Monzo ❤️

Hear from our team about what it's like working at Monzo


 

????London or Remote (UK) | ???? £35,000 - £50,000 + Benefits | Hear from the team

⭐ Our Offensive Security team

This role sits within our Offensive Security team, reporting into the Offensive Security Manager. But this team is a part of the wider Security collective here at Monzo, a power-house team of passionate security professionals all working to make Monzo as secure as possible for our customers.

At our core though, the Offensive Security team is made up of breakers, not makers. We find the vulnerabilities, prove exploitability, then work with the other teams to fix those problems. We aren’t developers though, so we give advice to mitigate issues but don’t start coding fixes ourselves.

????You’ll play a key role by…

The work we do within the Offensive Security team is varied, but all involve hacking in one way or another. A lot of our work is project-based, with focus placed on areas we consider weak. This might mean hacking some new internal software or testing a new feature in the apps for example.

We also do projects that simulate a real adversarial attack (a bit like red teaming), and cooperate with our defensive teams to improve capabilities and skills.

The biggest service we provide to the other teams is placing a security mindset in the room. Ask those “what ifs” and get people thinking like an attacker. And it always helps to have a proof of concept to show to others!

As an Offensive Security Engineer, you’ll first be covering the smaller projects the more senior engineers can’t get to. This could include:

  • Testing new features in the Monzo apps (mainly the mobile apps, but sometimes web apps too)
  • Testing internal and public web services that support our products, tools and systems
  • Doing network testing (like attacking our office networks or hunting for vulnerabilities in sensitive networks)
  • Supporting the security bounty program

As you get more familiar and confident within the team, we’ll encourage you to take on some bigger, more challenging projects to help with your career progression at Monzo. But you won’t be alone, and always have the support of the others in the team!

????We’d love to hear from you if…

First and foremost you:

  • Have an unending curiosity to understand how the security of systems work at all levels
  • Have a strong attacker mindset, always thinking “what if I did…” when testing a system

The following would be nice, but aren’t requirements:

  • At least 2 years experience in security testing (ideally internal testers or consultants)
  • An industry recognised qualification such as CREST CRT, CCT (APP or INF), OSCP, OSCE or other equivalent (don’t be put off if you don’t have any, experience is preferred!)

????What’s in it for you

????£35,000 - £50,000 ➕ share options.

????This role can be based in our London office, but we're open to distributed working within the UK (with ad hoc meetings in London) (Please note, we are notable to offer sponsorship or relocation to the UK for this role)

⏰We offer flexible working hours and trust you to work enough hours to do your job well, and at times that suit you and your team. 

????£1,000 learning budget each year to use on books, training courses and conferences.

????We will set you up to work from home; all employees are given Macbooks and for fully remote workers we will provide extra support for your work-from-home setup. 

➕ Plus lots more! Read our full list of benefits.

???? The application journey 

If shortlisted after your application, you’ll firstly have a chat with one of the Hiring Team. If successful following on from this ⬇️

  • Initial call with a member of the security team
  • Technical interview
  • Values and Collaboration interview

This process should take around 2-3 weeks - your schedule is really important to us, so we promise to be as flexible as possible! 

We have some guidelines on using Artificial Intelligence (AI) to ace an application and interview at Monzo ???? You can read them here.

You’ll hear from us throughout the application process, but if you’ve got any questions, please reach out to business-hiring@monzo.com. You can also use this email address to let us know if there’s anything we can do to make the process easier for you because of disability, neurodiversity or anything else.

We’ll only close this role once we have enough applications for the next stage. Please submit your application as soon as possible to make sure you don’t miss out! 

If you’d prefer to work part-time, please let us know and we'll make this happen if we can.

Equal opportunities for everyone

Diversity and inclusion are a priority for us and we’re making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we’re embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, 2023 Diversity and Inclusion Report and 2023 Gender Pay Gap Report.

We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status.

Linkedin Tags: #LI-REMOTE#LI-MY1


Equal opportunities for everyone

Diversity and inclusion are a priority for us and we’re making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we’re embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, 2023 Diversity and Inclusion Report and 2023 Gender Pay Gap Report.

We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status.

If you have a preferred name, please use it to apply. We don't need full or birth names at application stage ????

See more jobs at Monzo

Apply for this job

+30d

Security Engineer

SinchMelbourne,Victoria,Australia, Remote Hybrid
mobile

Sinch is hiring a Remote Security Engineer

Sinch, the Customer Communications Cloud, powers meaningful conversations at scale across messaging, voice, and email to help businesses deliver unified, personalized experiences that truly revolve around their customers — no matter the channels they use. Over 150,000 businesses, including 8 of the 10 largest tech companies in the world, rely on us for their customer communication needs, with over 700 billion customer engagements each year.

 

Providing innovative mobile messaging solutions that help businesses of all sizes – from SMBs to enterprise-level to better connect with customers. Our messaging solutions for alerts and notifications, billing and payments, appointment reminders, marketing, and staff scheduling are trusted by over 65,000 customers in industries such as healthcare, education, retail, and utilities. Sinch is the number one choice for easy and engaging business messaging.

 

We are seeking a Security Engineer to join our global team. In this role you will be responsible for designing, implementing, and maintaining security protocols to safeguard sensitive information, such as customer data and company intellectual property. Must have a deep understanding of networking and system architecture, as well as knowledge of current and emerging threats and technologies. The Security Engineer plays a crucial role in incident response and developing strategies to prevent future attacks. This position requires strong analytical and communication skills, as well as a commitment to staying up to date with the latest trends and best practices in cybersecurity.

 

Key responsibilities:

  • Responsible for assessing and understanding the threat landscape by working with other Cyber functions such as Offensive Security, Digital Forensics etc. and architecting solutions to calibrate risk consistent with risk tolerance.
  • Reviewing security intelligence information and researching emerging threats - to proactively identify and prevent potential threats. 
  • Build and/or tune Sinch security tools, such as EDR, email security, and vulnerability scanning and SIEM solution to ensure that alerts are effective and actionable.
  • Augment Incident Response team to ensure 24/7 coverage and operations. Responsibilities sometimes will require working evenings and weekends, sometimes with little or no advanced notice.
  • Be able to effectively communicate, both written and verbally, complex security and technical concepts to a wide variety of stakeholders and partners and build and leverage and earn the trust of stakeholders at all levels of the organization.
  • Establish and modify runbooks that provide other subject matter experts with a consistent manner of executing the processes.
  • Employing the security technologies to continuously monitor the company’s assets, conduct technical analysis of network traffic to identify anomalies and then taking action to respond to potential vulnerabilities and threats.  

 

The successful candidate will possess the following skills and attributes:

  • Proven experience in working on threat, vuln, fraud or compliance - ideally building or supporting cross-functional mitigation programs.
  • A background that involves creating a layered security perimeter in the context of a cloud- and container-based microservices.
  • Experience supporting (or building) a security operations function in startup environments, ideally serving as incident commander for security incidents.
  • Knowledge of networking fundamentals, including TCP/IP, OSI stack model, L2, L3 and L7 fundamentals and raw packet analysis. Fluency with common cryptographic modalities
  • Experience using tools like LogRhythm, Nessus, CASB manage threat telemetry.
  • One industry-recognized security certification (CEH, CISSP, CCSP, CISA) -- or the willingness to secure one within six months.

 

We dream big — for our company, our customers, and our employees — and we hire the best talent worldwide to help us bring our vision to life. We have a local presence in more than 60 countries — probably somewhere near you!

 

We are committed to building an engaged and talented workforce that represents an environment that is inclusive, supports flexibility and welcomes diversity.

 

Our values of Dream BigWin TogetherKeep it simple and Make it Happen are the foundation for fostering an environment where diversity of thinking, skills and experiences are embraced, delivering innovation and better business results.

 

We value our team by offering:

  • WHERE YOU WORK MATTERS: We understand the benefit of a flexible schedule where you can best impact both your personal and work life, so we offer a hybrid working arrangement, work from home set up reimbursement and a global mobility policy.
  • PUT FAMILY FIRST: We know that building a family take priority, therefore we offer a generous parental leave program: 26 weeks salary for primary care giver and 4 weeks salary for secondary care giver
  • CELEBRATE YOURESELF: By providing a day off for your birthday, we want you to take the time to celebrate the year you’ve had with your nearest and dearest.
  • TAKE A BREAK: Enjoy a generous annual leave program. We value balance and understand that performance at work requires time to rest at home and/or rejuvenate on vacation.
  • STAY HEALTHY: Physical wellness supports mental wellness, so we offer a monthly fitness reimbursement allowance and other wellness programs
  • TAKE THE NEXT STEP: Coaching and career development support, including access to a range of online professional development courses
  • CARE FOR YOURSELF: Take advantage of our free virtual counselling resources through our global Employee Assistance Program. Your mental health is as important as your physical health.
  • MAKE AN IMPACT: Support betterment in your community and beyond by taking paid time off to support a volunteer program of your choice.
  • TREAT YOURSELF: Access to Reward+ program that offers a wide range of discounts and deals across retail, entertainment and much more.

 

If you are looking for the next opportunity in your career and want to work for a people focused, growing tech company, then Apply Now.

See more jobs at Sinch

Apply for this job

+30d

Security Engineer

Clover HealthRemote - Canada
remote-firstDesignlinuxpython

Clover Health is hiring a Remote Security Engineer

Clover is reinventing health insurance by working to keep people healthier.

We value diversity — in backgrounds and in experiences. Healthcare is a universal concern, and we need people from all backgrounds and swaths of life to help build the future of healthcare. Clover's engineering team is empathetic, caring, and supportive. We are deliberate and self-reflective about the kind of engineering team and culture that we are building, seeking engineers that are not only strong in their own aptitudes but care deeply about supporting each other's growth.

As a Security Engineer, you will forge and nurture trusted relationships with internal technology teams (Software Engineering, SRE, DS/ML, Product) and external customers (e.g., payers, accountable care organizations, integrated delivery networks). You will partner closely with the entire technology organization to architect, design, implement, and maintain system security and controls. This ideal candidate for this role will understand the needs of software development, technical system design, and data/information security.

As a Security Engineer, you will:

  • Implement, operationalize and monitor security applications such as EDR, DLP, SAST, Vulnerability Management, and CSPM systems.
  • Serve as a SME for security related code and technical design reviews.
  • Identify and collaborate with engineering and SRE to resolve areas of security vulnerability in our software, systems and infrastructure.
  • Assess and improve systems for compliance with security requirements, policies, guidelines and standards
  • Interface with external customers on CA security reviews and assessments
  • Work to improve our general security posture and processes ranging from secure development practices to SecDevOps
  • Contribute to the planning, definition and implementation of new security solutions or related development

You will love this job if:

  • You are passionate about transforming healthcare delivery through new technologies and want to make an impact.
  • You have a bias toward action and seek to intervene before issues arise.
  • You are comfortable navigating ambiguity and working in an evolving environment.
  • You are a problem solver and a team player. You love working within teams and helping them work more efficiently.
  • You are a strong communicator and able to influence behaviors to help drive desired outcomes.
  • You are empathetic and seek to build enduring relationships with our customers and users.
  • You are analytical and use data to drive actions and evaluate outcomes.

You should get in touch if:

  • You have 1+ years of experience in a security role with priority on engineering.
  • You have experience investigating, and triaging incidents.
  • You have a basic understanding of operating systems (Linux, OSX, etc.) and networking fundamentals.
  • You have a strong understanding of at least one of the following technologies: Python, JavaScript/TypeScript, Shell Scripting (You will be tested on one).
  • You are comfortable with conducting code reviews for security vulnerabilities on a frequent basis.
  • You have assessed the security of APIs and systems by analyzing authentication, authorization mechanisms, input validation, and potential vulnerabilities.
  • You have excellent written and verbal communication skills and are able to craft clear and comprehensive reports and research to present to engineering and other stakeholders.
  • You stay up-to-date with the latest research on threats, attack vectors, and security trends and are keen to apply them to our environment.
  • You have knowledge of cybersecurity frameworks and standards (e.g., NIST, ISO, CIS).

Benefits Overview:

  • Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program and regular compensation reviews to recognize and reward exceptional contributions.
  • Physical Well-Being: We prioritize the health and well-being of our employees and their families by offering comprehensive group medical coverage that include coverage for hospitalization, outpatient care, optical services, and dental benefits.
  • Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, company holidays, access to mental health resources, and a generous annual leave policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location. 
  • Professional Development: We are committed to developing our talent professionally. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

  • Reimbursement for office setup expenses
  • Flexibility to work from home or from our office, enabling collaboration with global teams
  • Paid parental leave for all new parents
  • And much more!

About Clover: We are reinventing health insurance by combining the power of data with human empathy to keep our members healthier. We believe the healthcare system is broken, so we've created custom software and analytics to empower our clinical staff to intervene and provide personalized care to the people who need it most.

We always put our members first, and our success as a team is measured by the quality of life of the people we serve. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences and backgrounds, who share a passion for improving people's lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.


#LI-REMOTE

See more jobs at Clover Health

Apply for this job

+30d

Security Engineer

BugcrowdRemote - United States
golangBachelor's degreekotlinjiragitrubyc++pythonAWSjavascript

Bugcrowd is hiring a Remote Security Engineer

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform™. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch™ technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.

Job Summary 

The Security Engineer’s role is to aid the security efforts of Bugcrowd, while proactively making changes to further improve our security posture. 

To achieve this goal, we require a motivated team member who is willing to push their own boundaries and step out of their comfort zone.You will be challenged on a regular basis, especially because you are the last line of defense for one of the largest crowdsourced security platforms! The Security Engineer will provide mentoring to multiple junior security engineers and will work closely with other team members on a daily basis. 

**Please note this role will be working PST business hours

Essential Duties and Responsibilities

  • Aiding within the Incident Response process
  • Threat hunting
  • Developing patches and security controls within a Ruby on Rails application, Golang application, and Kotlin application
  • Communicating across multiple teams converting technical knowledge into palatable words for multiple audiences. 
  • Significant familiarity with AWS and network security controls
  • Identifying vulnerability root causes
  • Performing basic risk assessments and triaging
  • Educating developers on security best practices
  • Architecting solutions with developers to remediate any security concerns
  • Performing basic red team assessments (including but not limited to phishing, vishing, spoofing technologies, etc.)
  • Testing new features within the platform and services
  • Automating security tasks to increase workflow efficiency
  • Mentoring other team members

Education

  • Bachelor's Degree in a relevant field or commensurate experience
  • 3 - 5+ years of professional experience in a similar role or its equivalent.

Knowledge, Skills, and Abilities

  •  Experience with writing IR plans and operating within an IR practice (experience responding to incidents)
  • Working knowledge of Threat Intelligence and how it can be used to proactively create security controls (automation)
  • Familiarity with Pentesting techniques and OWASP Top 10
  • Ability to understand a vulnerability and work with developers to patch it
  • Scripting knowledge in at least one of: Bash, Python, JavaScript, Ruby
  • Self motivated and organized - must be able to operate from a calendar and be punctual
  • Cloud security experience or holds cloud certifications (AWS strongly preferred)
  • Experience with Identity and Access Management (IAM) controls
  • Ability to work autonomously within a global company, and critically think without intervention
  • Familiarity with git
  • Familiarity with a ticketing system / issue tracking system is a must (e.g: Jira)

Working Conditions & Physical Requirements

Sitting and / or standing - Must be able to remain in a stationary position 50% of the time

Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.

Environment - remote, work-from-home 100% of the time.

ADA Statement: Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.

Pay Range Disclosure:The base pay range for this role takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to Qualifications, Geographical Location, Education/certifications, Experience, Skill Sets, Training, and other business and organizational needs. 

A reasonable estimate of the current range for the position of Security Engineer base is: $97,000- $106,000.

This position may also be eligible to participate in a discretionary bonus program or commission plan, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Culture

  • At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.
  • We regularly hear from both customers and researchers that Bugcrowd feels like a family, and we strive to maintain that internally as well.
  • Our team consists of a broad range of people: musicians, adventure sports junkies, nature lovers, parents, cereal enthusiasts, night owls, cyclists, artists—you get the point.

At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

 

Disclaimer

This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.


Equal Employment Opportunity:

Bugcrowd is EOE, Disability/Age Employer. 

Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation. 


Apply at: https://www.bugcrowd.com/about/careers/

 

See more jobs at Bugcrowd

Apply for this job

+30d

Senior Security Engineer II

SignifydUnited States (Remote);
DevOPSBachelor's degreeBachelor degreeDesignazurejavapythonAWSjavascript

Signifyd is hiring a Remote Senior Security Engineer II

The Security Engineer at Signifyd assists cybersecurity operations and vulnerability management across the organization. This role works with other security engineers and analysts on the team by contributing integrations, implementations and reviews with our security systems. They setup, configure, and use these solutions to identify threats and vulnerabilities within our networks and applications then cross coordinate with other departments to ensure timely remediation. The Security Engineer reports to the Director, Head of Information Security and Compliance while supporting the Security Risk Manager with auditable evidence of control effectiveness.

Responsibilities

You will perform the following responsibilities alongside other members of the information security team:

  • Engineer data feeds, rules, and tuning for the system information and event manager (SIEM);

  • Triage security operations center (SOC) alerts as the Level II/III escalation support;

  • Triage secrets scanning, static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA) tools;

  • Triage cloud security posture management (CSPM), infrastructure as code (IaC) security scanning, and attack surface violations;

  • Identify patch management gaps using our vulnerability management software and collaborate with IT and Engineering teams on resolutions;

  • Perform internal security testing, assessments, and triaging of alerts from security tooling;

  • Conduct secure code reviews, secure design reviews, and threat modeling activities;

  • Support GRC activities through control evidence collection;

  • Contribute to operational support activities for all security capabilities. This includes preparing self service operational support documentation for developers and project teams, responding to internal support chat groups;

  • Contribute to design and development of observability metrics and monitoring capabilities for all security capabilities utilizing DevOps or SRE principles;

  • Support the creation and publication of metrics on security functions usage and remediation status for consumption by developers and project teams.

Requirements

  • Ability to automate or develop basic tasks in at least one programming language such as: Java, JavaScript, Python

  • Professional certifications such as WAPT, PPT, OSCP, etc and/or computer science degree;

  • 1+ years security engineer experience or 2+ years as a Security Analyst or equivalent;

  • Experience working with cloud technologies such as: AWS, GCP, Azure, Docker/Kubernetes.

#LI-Remote

Benefits in our US offices:

  • Discretionary Time Off Policy (Unlimited!)
  • 401K Match
  • Stock Options
  • Annual Performance Bonus or Commissions
  • Paid Parental Leave (12 weeks)
  • On-Demand Therapy for all employees & their dependents
  • Dedicated learning budget through Learnerbly
  • Health Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Account (FSA)
  • Short Term and Long Term Disability Insurance
  • Life Insurance
  • Company Social Events
  • Signifyd Swag

We want to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.

Signifyd provides a base salary, bonus, equity and benefits to all its employees. Our posted job may span more than one career level, and offered level and salary will be determined by the applicant’s specific experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.

USA Base Salary Pay Range
$90,000$135,000 USD

See more jobs at Signifyd

Apply for this job

+30d

Senior Security Engineer

Clover HealthRemote - Canada
remote-firstDesignpython

Clover Health is hiring a Remote Senior Security Engineer

Clover is reinventing health insurance by working to keep people healthier.

We value diversity — in backgrounds and in experiences. Healthcare is a universal concern, and we need people from all backgrounds and swaths of life to help build the future of healthcare. Clover's engineering team is empathetic, caring, and supportive. We are deliberate and self-reflective about the engineering team and culture that we are building, seeking engineers that are not only strong in their own aptitudes but care deeply about helping each other's growth.

As a Senior Security Engineer, you will forge and nurture trusted relationships with internal technology teams (Software Engineering, SRE, DS/ML, Product) and external customers (e.g., payers, accountable care organizations, integrated delivery networks). You will partner closely with the entire technology organization to architect, design, implement, and maintain system security and controls. This role will be an expert who understands the needs of software development, technical system design, and data/information security.

As a Senior Security Engineer, you will:

  • Implement, operationalize and monitor security applications such as EDR, DLP, Vulnerability Management, and CSPM systems.
  • Serve as a SME for security related code and technical design reviews.
  • Identify and collaborate with engineering and SRE to resolve areas of security vulnerability in our software, systems and infrastructure.
  • Serve as security point-of-contact for audit/certification programs such as HITRUST, SOC 2, and HIPAA
  • Assess and improve systems for compliance with security requirements, policies, guidelines and standards (see above)
  • Interface with external customers on CA security reviews and assessments
  • Monitor and regularly review our system for intrusions, threats, and anomalies
  • Work to improve our general security posture and processes ranging from secure development practices to SecDevOps
  • Contribute to the planning, definition and implementation of new security solutions or related development

You will love this job if:

  • You are passionate about transforming healthcare delivery through new technologies and want to make an impact.
  • You have a bias toward action and seek to intervene before issues arise.
  • You are comfortable navigating ambiguity and working in an evolving environment.
  • You are a problem solver and a team player. You love working within teams and helping them work more efficiently.
  • You are a strong communicator and able to influence behaviors to help drive desired outcomes.
  • You are empathetic and seek to build enduring relationships with our customers and users.
  • You are analytical and use data to drive actions and evaluate outcomes.

You should get in touch if:

  • Experience investigating, and triaging incidents.
  • Strong understanding of at least one of the following technologies: Python, JavaScript/TypeScript, Shell Scripting (You will be tested on one).
  • You are comfortable with conducting code reviews for security vulnerabilities on a frequent basis.
  • You have assessed the security of APIs and systems by analyzing authentication, authorization mechanisms, input validation, and potential vulnerabilities.
  • You have excellent written and verbal communication skills and are able to craft clear and comprehensive reports and research to present to engineering and other stakeholders.
  • You stay up-to-date with latest research on threats, attack vectors, and security trends and are keen to apply them to our environment
  • You demonstrate influence and are able to lead/mentor internal teams and customers toward shared goals and objectives.

Benefits Overview:

  • Financial Well-Being: Our commitment to attracting and retaining top talent begins with a competitive base salary and equity opportunities. Additionally, we offer a performance-based bonus program and regular compensation reviews to recognize and reward exceptional contributions.
  • Physical Well-Being: We prioritize the health and well-being of our employees and their families by offering comprehensive group medical coverage that include coverage for hospitalization, outpatient care, optical services, and dental benefits.
  • Mental Well-Being: We understand the importance of mental health in fostering productivity and maintaining work-life balance. To support this, we offer initiatives such as No-Meeting Fridays, company holidays, access to mental health resources, and a generous annual leave policy. Additionally, we embrace a remote-first culture that supports collaboration and flexibility, allowing our team members to thrive from any location. 
  • Professional Development: We are committed to developing our talent professionally. We offer learning programs, mentorship, professional development funding, and regular performance feedback and reviews.

Additional Perks:

  • Reimbursement for office setup expenses
  • Flexibility to work from home or from our office, enabling collaboration with global teams
  • Paid parental leave for all new parents
  • And much more!

About Clover: We are reinventing health insurance by combining the power of data with human empathy to keep our members healthier. We believe the healthcare system is broken, so we've created custom software and analytics to empower our clinical staff to intervene and provide personalized care to the people who need it most.

We always put our members first, and our success as a team is measured by the quality of life of the people we serve. Those who work at Clover are passionate and mission-driven individuals with diverse areas of expertise, working together to solve the most complicated problem in the world: healthcare.

From Clover’s inception, Diversity & Inclusion have always been key to our success. We are an Equal Opportunity Employer and our employees are people with different strengths, experiences and backgrounds, who share a passion for improving people's lives. Diversity not only includes race and gender identity, but also age, disability status, veteran status, sexual orientation, religion and many other parts of one’s identity. All of our employee’s points of view are key to our success, and inclusion is everyone's responsibility.


#LI-REMOTE

See more jobs at Clover Health

Apply for this job

Lampenwelt GmbH is hiring a Remote IT Security Engineer (f/m/d)

Stellenbeschreibung

Wir suchen einen engagierten IT Security Engineer (f/m/d), der unsere Sicherheitsarchitektur mit Leidenschaft stärkt. In deiner Rolle als Experte für IT Security spielst du eine zentrale Rolle bei der Identifizierung, Analyse und Minderung von Sicherheitsrisiken. Du arbeitest Hand in Hand mit verschiedenen Teams, um unsere Sicherheitsstrategien, überwiegend in Projekten, weiterzuentwickeln, zu implementieren und kontinuierlich zu verbessern und bist Sparringspartner in der täglichen Analyse von Security Alerts. 

Gelegentliche Vor-Ort-Einsätze sind erforderlich, ansonsten ist auch Remote-Arbeit möglich. 

 

Wo deine Skills gefragt sind

  • Weiterentwicklung, Implementierung und Überwachung von Security Policies, um die Einhaltung von Standards und Best Practices sicherzustellen 
  • Administration und Beratung hinsichtlich unserer Security Infrastruktur, inklusive IAM, Cloud-, Endpoint- und Network Security
  • Durchführung von Security Assessments, inklusive Risiko-, Schwachstellen- und Compliance-Management
  • Proaktives Incident Management, von der schnellen Reaktion auf Sicherheitsvorfälle bis hin zum Business Continuity Management
  • Förderung der Sicherheitskultur durch Unterstützung bei der Durchführung regelmäßiger Security Awareness Trainings und Penetrationstests sowie Sicherheitsscans
  • Stetige Weiterentwicklung und Verfeinerung der Shared LUQOM IT-Services mit Fokus auf IT Security

Qualifikationen

Lampenwelt ist der richtige Ort für dich, wenn du Veränderungen als Chance begreifst und neugierig auf das Unbekannte bist. Wenn du dich jeden Tag aufs Neue herausforderst, um die beste Lösung zu finden. Hier wird dir Verantwortung übertragen, damit du deine Ideen nicht nur einbringen, sondern auch selbst umsetzen kannst. Bei Lampenwelt gehen wir jeden Tag ein Stück weiter, handeln schnell, sind offen und setzen auf eine direkte und lösungsorientierte Kommunikation auf allen Ebenen. 

Was dir helfen wird, zukünftige Herausforderungen zu meistern 

  • Tiefgehendes Verständnis für IT-Sicherheitskonzepte und -technologien
  • Fundiertes Wissen über Netzwerktechnologien, Cloud- & On-Prem Security Lösungen, End Point Protection, Betriebssystemen und SIEM
  • Kenntnisse im Umfeld von Microsoft Defender von Vorteil, insbesondere im Bereich Defender for Endpoint, Cloud sowie Identity
  • Starkes Interesse an neuen Technologien und fortlaufender persönlicher sowie beruflicher Weiterentwicklung
  • Eigeninitiative und Teamgeist bei der Durchführung von IT-Projekten
  • Analytische, konzeptionelle, strukturierte und eigenständige Arbeitsweise
  • Ausgeprägte Teamfähigkeit, Kommunikationsstärke und Engagement
  • Abgeschlossene Ausbildung im IT-Bereich oder ein Studium in Wirtschaftsinformatik, Informatik oder einem verwandten Feld
  • Sehr gute Deutsch- und Englischkenntnisse in Wort und Schrift

See more jobs at Lampenwelt GmbH

Apply for this job

+30d

Staff Platform Security Engineer

GeminiRemote (USA)
remote-firstterraformDesignkuberneteslinuxpythonAWS

Gemini is hiring a Remote Staff Platform Security Engineer

About the Company

Gemini is a global crypto and Web3 platform founded by Tyler Winklevoss and Cameron Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we help you buy, sell, and store your bitcoin and cryptocurrency. 

At Gemini, our mission is to unlock the next era of financial, creative, and personal freedom.

In the United States, we have a flexible hybrid work policy for employees who live within 30 miles of our office headquartered in New York City and our office in Seattle. Employees within the New York and Seattle metropolitan areas are expected to work from the designated office twice a week, unless there is a job-specific requirement to be in the office every workday. Employees outside of these areas are considered part of our remote-first workforce. We believe our hybrid approach for those near our NYC and Seattle offices increases productivity through more in-person collaboration where possible.

The Department: Platform Security

In the emerging industry of digital assets, there is nothing more important than trust. The Gemini security team forms the backbone of trust. In fact, Gemini’s very first hires were security specialists and we continue to tackle unique challenges in the crypto space.  Our team ensures that our customers, clients, and employees are safe, secure, and supported.

The Platform Security team secures Gemini’s infrastructure through service hardening and by developing and supporting a suite of foundational tools. We provide secure-by-default infrastructure, consumable security services, and expert consultation to engineering teams for secure cloud and non-cloud infrastructure.

The Role: Staff Security Engineer

The Platform Security team covers a broad problem space that includes all areas of Gemini’s platform infrastructure. In the past, this team has focused specifically on cloud security and we continue to invest heavily in this area.  This role will bring additional depth and specialization in non-cloud infrastructure, containerization, and container orchestration security.  We also value expertise in neighboring areas of infrastructure and platform security engineering including: PKI, core cryptography, identity management, network security, etc.

Responsibilities:

  • Design, deploy, and maintain services/platforms for security and engineering teams
  • Build and improve security controls and capabilities at all layers of infrastructure
  • Partner with engineering teams on security architecture and implementation decisions
  • Collaborate with appsec, threat detection, incident response, GRC and similar security functions to identify, understand, and reduce security risk

Minimum Qualifications:

  • 6+ years of experience in the field
  • Significant experience with container orchestration technologies and relevant security considerations. We often use Kubernetes and EKS
  • Experience in SRE, systems engineering, or network engineering
  • Experience with distributed systems or cloud computing. We often use AWS
  • Significant software development experience. We often use Python or Go
  • Experience building and owning high-availability critical systems or cloud-based services
  • Able to self-scope, define, and manage short and long term technical goals
  • Familiarity with computer security principles and practices

Preferred Qualifications:

  • Experience securing AWS and Linux environments, both native and third-party
  • Experience designing and implementing cryptographic infrastructure such as PKI, secrets management, authentication, or secure data storage/transmission
  • Experience designing and implementing systems for identity and access management
  • Experience with configuration management and infrastructure as code. We often use Terraform
It Pays to Work Here
 
The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $172,000 - $215,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

Apply for this job

+30d

Corporate Security Engineer

GrammarlyGermany; Hybrid
remote-firstDesignjavapython

Grammarly is hiring a Remote Corporate Security Engineer

Grammarly offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation, and a strong team culture.

About Grammarly

Grammarly is the world’s leading AI writing assistance company, and it is trusted by over 30 million people and 70,000 teams. From instantly creating a first draft to perfecting every message, Grammarly helps people at 96% of theFortune 500 and teams at companies like Atlassian, Databricks, and Zoom get their point across—and get results—with best-in-class security practices that keep data private and protected. Founded in 2009, Grammarly is No. 14 on the Forbes Cloud 100, one of TIME’s 100 Most Influential Companies, one of Fast Company’s Most Innovative Companies in AI, and one of Inc.’s Best Workplaces.

The Opportunity

To achieve our ambitious goals, we’re looking for a Security Engineer to join our Detection and Response (DART) team.  As a key member of our organization, you will be instrumental in safeguarding our digital assets and ensuring our security posture remains robust against emerging threats. If you have a passion for cybersecurity, a keen eye for detail, and extensive experience in security operations, we want to hear from you!

Grammarly’s engineers and researchers have the freedom to innovate and uncover breakthroughs—and, in turn, influence our product roadmap. The complexity of our technical challenges is growing rapidly as we scale our interfaces, algorithms, and infrastructure. You can hear more from our team on our technical blog.

As a DART engineer, you will 

  • Design, implement, and fine-tune advanced detection mechanisms to identify potential security threats and vulnerabilities within our environment proactively.
  • Perform forensics and spearhead response efforts during security incidents. This includes triaging security alerts, taking relevant mitigation steps, and engaging with internal stakeholders to ensure swift resolution.
  • Continuously tune our alerting rules to reduce false positives and enhance our signal-to-noise ratio, ensuring our detection systems are both effective and efficient.
  • Participate in our team’s on-call rotation, providing expert guidance and rapid response to security incidents as they arise.
  • Assist with the definition, creation, and maintenance of SIEM (Security Information and Event Management) detection rules and dashboards to provide clear, actionable insights.
  • Streamline our security operations by authoring comprehensive runbooks, writing automation scripts, and building SOAR (Security Orchestration, Automation, and Response) capabilities to reduce manual intervention and improve response times.
  • Improve our overall Incident Response process and ensure our readiness against adversaries.
  • Actively work to burn down the detection backlog, enhancing our detection coverage and accuracy across all monitored systems and applications.
  • Develop advanced detection strategies and tactics.
  • Collaborate on project and roadmap planning.

Qualifications

  • Has a minimum of 10 years in cybersecurity, with a focus on detection and response.
  • Is proficient in SIEM platforms and scripting languages (Python) and has familiarity with SOAR tools.
  • Has hands-on experience combating adversaries of varying sophistication (script kiddies to APT).
  • Has a foundational understanding of Corporate Security, including Mac endpoint security and Crowdstrike EDR.
  • Has professional experience with a commercial SIEM (Sumologic preferred).
  • L1, L2 SOC experience or "SOC-less" model (MDR, etc.).
  • Can define detection strategies and multi-quarter roadmaps.
  • Has strong expertise in incident handling and forensic investigation, with a proven track record of managing complex security incidents.
  • Has excellent analytical and problem-solving skills, with the ability to think critically under pressure.
  • Demonstrates strong verbal and written communication skills, capable of interacting with technical and non-technical stakeholders alike.
  • Has relevant industry certifications such as CISSP, GCIA, GCIH, or equivalent.
  • Has excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
  • Has strong communication skills and can explain complex security issues in understandable terms.
  • Nurtures the talent in the team and raises the technical talent bar when recruiting for their team.

Compensation and Benefits

  • Grammarly offers all team members competitive pay along with a benefits package encompassing the following and more: 
  • Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching 
  • Paid parental leave
  • 20 days of paid time off per year, 12 days of paid holidays per year, two floating holidays per year, and flexible sick time 
  • Generous stipends (including those for caregiving, pet care, wellness, your home office, and more)
  • Annual professional development budget and opportunities
United States: 
Zone 1: $270,000 – $320,000/year (USD)

We encourage you to apply.

At Grammarly, we value our differences, and we encourage all to apply—especially those whose identities are traditionally underrepresented in tech organizations. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, ancestry, national origin, citizenship, age, marital status, veteran status, disability status, political belief, or any other characteristic protected by law. Grammarly is an equal opportunity employer and a participant in the US federal E-Verify program (US). We also abide by the Employment Equity Act (Canada).

#LI-AD3

#LI-Hybrid

 

Apply for this job