Security Engineer Remote Jobs

39 Results

+30d

Staff Platform Security Engineer

GeminiRemote (USA)
remote-firstterraformDesignkuberneteslinuxpythonAWS

Gemini is hiring a Remote Staff Platform Security Engineer

About the Company

Gemini is a global crypto and Web3 platform founded by Tyler Winklevoss and Cameron Winklevoss in 2014. Gemini offers a wide range of crypto products and services for individuals and institutions in over 70 countries.

Crypto is about giving you greater choice, independence, and opportunity. We are here to help you on your journey. We build crypto products that are simple, elegant, and secure. Whether you are an individual or an institution, we help you buy, sell, and store your bitcoin and cryptocurrency. 

At Gemini, our mission is to unlock the next era of financial, creative, and personal freedom.

In the United States, we have a flexible hybrid work policy for employees who live within 30 miles of our office headquartered in New York City and our office in Seattle. Employees within the New York and Seattle metropolitan areas are expected to work from the designated office twice a week, unless there is a job-specific requirement to be in the office every workday. Employees outside of these areas are considered part of our remote-first workforce. We believe our hybrid approach for those near our NYC and Seattle offices increases productivity through more in-person collaboration where possible.

The Department: Platform Security

In the emerging industry of digital assets, there is nothing more important than trust. The Gemini security team forms the backbone of trust. In fact, Gemini’s very first hires were security specialists and we continue to tackle unique challenges in the crypto space.  Our team ensures that our customers, clients, and employees are safe, secure, and supported.

The Platform Security team secures Gemini’s infrastructure through service hardening and by developing and supporting a suite of foundational tools. We provide secure-by-default infrastructure, consumable security services, and expert consultation to engineering teams for secure cloud and non-cloud infrastructure.

The Role: Staff Security Engineer

The Platform Security team covers a broad problem space that includes all areas of Gemini’s platform infrastructure. In the past, this team has focused specifically on cloud security and we continue to invest heavily in this area.  This role will bring additional depth and specialization in non-cloud infrastructure, containerization, and container orchestration security.  We also value expertise in neighboring areas of infrastructure and platform security engineering including: PKI, core cryptography, identity management, network security, etc.

Responsibilities:

  • Design, deploy, and maintain services/platforms for security and engineering teams
  • Build and improve security controls and capabilities at all layers of infrastructure
  • Partner with engineering teams on security architecture and implementation decisions
  • Collaborate with appsec, threat detection, incident response, GRC and similar security functions to identify, understand, and reduce security risk

Minimum Qualifications:

  • 6+ years of experience in the field
  • Significant experience with container orchestration technologies and relevant security considerations. We often use Kubernetes and EKS
  • Experience in SRE, systems engineering, or network engineering
  • Experience with distributed systems or cloud computing. We often use AWS
  • Significant software development experience. We often use Python or Go
  • Experience building and owning high-availability critical systems or cloud-based services
  • Able to self-scope, define, and manage short and long term technical goals
  • Familiarity with computer security principles and practices

Preferred Qualifications:

  • Experience securing AWS and Linux environments, both native and third-party
  • Experience designing and implementing cryptographic infrastructure such as PKI, secrets management, authentication, or secure data storage/transmission
  • Experience designing and implementing systems for identity and access management
  • Experience with configuration management and infrastructure as code. We often use Terraform
It Pays to Work Here
 
The compensation & benefits package for this role includes:
  • Competitive starting salary
  • A discretionary annual bonus
  • Long-term incentive in the form of a new hire equity grant
  • Comprehensive health plans
  • 401K with company matching
  • Paid Parental Leave
  • Flexible time off

Salary Range: The base salary range for this role is between $172,000 - $215,000 in the State of New York, the State of California and the State of Washington. This range is not inclusive of our discretionary bonus or equity package. When determining a candidate’s compensation, we consider a number of factors including skillset, experience, job scope, and current market data.

At Gemini, we strive to build diverse teams that reflect the people we want to empower through our products, and we are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Gemini is proud to be an equal opportunity workplace. If you have a specific need that requires accommodation, please let a member of the People Team know.

Apply for this job

+30d

Corporate Security Engineer

GrammarlyGermany; Hybrid
remote-firstDesignjavapython

Grammarly is hiring a Remote Corporate Security Engineer

Grammarly offers a dynamic hybrid working model for this role. This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that helps foster trust, innovation, and a strong team culture.

About Grammarly

Grammarly is the world’s leading AI writing assistance company, and it is trusted by over 30 million people and 70,000 teams. From instantly creating a first draft to perfecting every message, Grammarly helps people at 96% of theFortune 500 and teams at companies like Atlassian, Databricks, and Zoom get their point across—and get results—with best-in-class security practices that keep data private and protected. Founded in 2009, Grammarly is No. 14 on the Forbes Cloud 100, one of TIME’s 100 Most Influential Companies, one of Fast Company’s Most Innovative Companies in AI, and one of Inc.’s Best Workplaces.

The Opportunity

To achieve our ambitious goals, we’re looking for a Security Engineer to join our Detection and Response (DART) team.  As a key member of our organization, you will be instrumental in safeguarding our digital assets and ensuring our security posture remains robust against emerging threats. If you have a passion for cybersecurity, a keen eye for detail, and extensive experience in security operations, we want to hear from you!

Grammarly’s engineers and researchers have the freedom to innovate and uncover breakthroughs—and, in turn, influence our product roadmap. The complexity of our technical challenges is growing rapidly as we scale our interfaces, algorithms, and infrastructure. You can hear more from our team on our technical blog.

As a DART engineer, you will 

  • Design, implement, and fine-tune advanced detection mechanisms to identify potential security threats and vulnerabilities within our environment proactively.
  • Perform forensics and spearhead response efforts during security incidents. This includes triaging security alerts, taking relevant mitigation steps, and engaging with internal stakeholders to ensure swift resolution.
  • Continuously tune our alerting rules to reduce false positives and enhance our signal-to-noise ratio, ensuring our detection systems are both effective and efficient.
  • Participate in our team’s on-call rotation, providing expert guidance and rapid response to security incidents as they arise.
  • Assist with the definition, creation, and maintenance of SIEM (Security Information and Event Management) detection rules and dashboards to provide clear, actionable insights.
  • Streamline our security operations by authoring comprehensive runbooks, writing automation scripts, and building SOAR (Security Orchestration, Automation, and Response) capabilities to reduce manual intervention and improve response times.
  • Improve our overall Incident Response process and ensure our readiness against adversaries.
  • Actively work to burn down the detection backlog, enhancing our detection coverage and accuracy across all monitored systems and applications.
  • Develop advanced detection strategies and tactics.
  • Collaborate on project and roadmap planning.

Qualifications

  • Has a minimum of 10 years in cybersecurity, with a focus on detection and response.
  • Is proficient in SIEM platforms and scripting languages (Python) and has familiarity with SOAR tools.
  • Has hands-on experience combating adversaries of varying sophistication (script kiddies to APT).
  • Has a foundational understanding of Corporate Security, including Mac endpoint security and Crowdstrike EDR.
  • Has professional experience with a commercial SIEM (Sumologic preferred).
  • L1, L2 SOC experience or "SOC-less" model (MDR, etc.).
  • Can define detection strategies and multi-quarter roadmaps.
  • Has strong expertise in incident handling and forensic investigation, with a proven track record of managing complex security incidents.
  • Has excellent analytical and problem-solving skills, with the ability to think critically under pressure.
  • Demonstrates strong verbal and written communication skills, capable of interacting with technical and non-technical stakeholders alike.
  • Has relevant industry certifications such as CISSP, GCIA, GCIH, or equivalent.
  • Has excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
  • Has strong communication skills and can explain complex security issues in understandable terms.
  • Nurtures the talent in the team and raises the technical talent bar when recruiting for their team.

Compensation and Benefits

  • Grammarly offers all team members competitive pay along with a benefits package encompassing the following and more: 
  • Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching 
  • Paid parental leave
  • 20 days of paid time off per year, 12 days of paid holidays per year, two floating holidays per year, and flexible sick time 
  • Generous stipends (including those for caregiving, pet care, wellness, your home office, and more)
  • Annual professional development budget and opportunities
United States: 
Zone 1: $270,000 – $320,000/year (USD)

We encourage you to apply.

At Grammarly, we value our differences, and we encourage all to apply—especially those whose identities are traditionally underrepresented in tech organizations. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, ancestry, national origin, citizenship, age, marital status, veteran status, disability status, political belief, or any other characteristic protected by law. Grammarly is an equal opportunity employer and a participant in the US federal E-Verify program (US). We also abide by the Employment Equity Act (Canada).

#LI-AD3

#LI-Hybrid

 

Apply for this job

+30d

Security Engineer, Detection & Response

GrammarlyUnited States; Hybrid
remote-firstDesignswiftc++python

Grammarly is hiring a Remote Security Engineer, Detection & Response

Grammarly is excited to offer aremote-first hybrid working model. Grammarly team members in this role must be based inthe United States, and, depending on business needs, they must meet in person for collaboration weeks, traveling if necessary to the hub(s) where their team is based.

This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that fosters trust and unlocks creativity.

About Grammarly

Grammarly is the world’s leading AI writing assistance company trusted by over 30 million people and 70,000 teams. From instantly creating a first draft to perfecting every message, Grammarly helps people at 96% of theFortune 500 and teams at companies like Atlassian, Databricks, and Zoom get their point across—and get results—with best-in-class security practices that keep data private and protected. Founded in 2009, Grammarly is No. 14 on the Forbes Cloud 100, one of TIME’s 100 Most Influential Companies, one of Fast Company’s Most Innovative Companies in AI, and one of Inc.’s Best Workplaces.

The Opportunity

To achieve our ambitious goals, we’re looking for a Security Engineer to join our Detection and Response (DART) team.  As a key member of our organization, you will be instrumental in safeguarding our digital assets and ensuring our security posture remains robust against emerging threats. If you have a passion for cybersecurity, a keen eye for detail, and extensive experience in security operations, we want to hear from you!

Grammarly’s engineers and researchers have the freedom to innovate and uncover breakthroughs—and, in turn, influence our product roadmap. The complexity of our technical challenges is growing rapidly as we scale our interfaces, algorithms, and infrastructure. You can hear more from our team on our technical blog.

As a DART engineer, you will 

  • Design, implement, and fine-tune advanced detection mechanisms to proactively identify potential security threats and vulnerabilities within our environment.
  • Perform forensics and spearhead response efforts during security incidents. This includes triaging security alerts, taking relevant mitigation steps, and engaging with internal stakeholders to ensure swift resolution.
  • Continuously tune our alerting rules to reduce false positives and enhance our signal-to-noise ratio, ensuring our detection systems are both effective and efficient.
  • Participate in our team’s on-call rotation, providing expert guidance and rapid response to security incidents as they arise.
  • Assist with the definition, creation, and maintenance of SIEM (Security Information and Event Management) detection rules and dashboards to provide clear, actionable insights.
  • Streamline our security operations by authoring comprehensive runbooks, writing automation scripts, and building SOAR (Security Orchestration, Automation, and Response) capabilities to reduce manual intervention and improve response times.
  • Improve our overall Incident Response process and ensure our readiness against adversaries.
  • Actively work to burn down the detection backlog, enhancing our detection coverage and accuracy across all monitored systems and applications.
  • Develop advanced detection strategies and tactics.
  • Collaborate on project and roadmap planning.

Qualifications

  • Has a minimum of 10 years in cybersecurity, with a focus on detection and response.
  • Is proficient in SIEM platforms and scripting languages (Python) and has familiarity with SOAR tools.
  • Has hands-on experience combating adversaries of varying sophistication (script kiddies to APT).
  • Has a foundational understanding of Corporate Security, including Mac endpoint security and Crowdstrike EDR.
  • Has professional experience with a commercial SIEM (Sumologic preferred).
  • L1, L2 SOC experience or "SOC-less" model (MDR, etc.).
  • Can define detection strategies and multi-quarter roadmaps.
  • Has strong expertise in incident handling and forensic investigation, with a proven track record of managing complex security incidents.
  • Has excellent analytical and problem-solving skills, with the ability to think critically under pressure.
  • Demonstrates strong verbal and written communication skills, capable of interacting with technical and non-technical stakeholders alike.
  • Has relevant industry certifications such as CISSP, GCIA, GCIH, or equivalent.
  • Has excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
  • Has strong communication skills and can explain complex security issues in understandable terms.
  • Nurtures the talent in the team and raises the technical talent bar when recruiting for their team.

Compensation and Benefits

  • Grammarly offers all team members competitive pay along with a benefits package encompassing the following and more: 
  • Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching 
  • Paid parental leave
  • 20 days of paid time off per year, 12 days of paid holidays per year, two floating holidays per year, and flexible sick time 
  • Generous stipends (including those for caregiving, pet care, wellness, your home office, and more)
  • Annual professional development budget and opportunities

Grammarly takes a market-based approach to compensation, which means base pay may vary depending on your location. Our US locations are categorized into two compensation zones based on proximity to our hub locations. 

Base pay may vary considerably depending on job-related knowledge, skills, and experience. The expected salary ranges for this position are outlined below by compensation zone and may be modified in the future. 

United States: 
Zone 1: $270,000 – $320,000/year (USD)
Zone 2: $240,000 – $290,000/year (USD)

For more information about our compensation zones and locations where we currently support employment, please refer to this page. If a location of interest is not listed, please speak with a recruiter for additional information. 

We encourage you to apply

At Grammarly, we value our differences, and we encourage all to apply—especially those whose identities are traditionally underrepresented in tech organizations. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, ancestry, national origin, citizenship, age, marital status, veteran status, disability status, political belief, or any other characteristic protected by law. Grammarly is an equal opportunity employer and a participant in the US federal E-Verify program (US). We also abide by the Employment Equity Act (Canada).


#LI-PM1

#LI-Hybrid

 

Apply for this job

+30d

Senior Security Engineer

PodiumRemote, US
Bachelor's degreeDesignrubypythonAWSjavascriptPHP

Podium is hiring a Remote Senior Security Engineer

At Podium, our mission is to help local businesses win. Our lead conversion platform, powered by AI and integrations, helps local businesses convert leads faster, communicate easier, and make more sales. Every day, thousands of local businesses utilize our review management, communication, marketing, and payments products. 

Our work and focus on helping local businesses thrive has been recognized across the industry, including Forbes’ Next Billion Dollar Startups, Forbes’ Cloud 100, the Inc. 5000, and Fast Company’s World’s Most Innovative Companies.

At Podium, we believe in fostering a culture that thrives on hiring and developing exceptional talent. Our operating principles serve as a compass, guiding daily behavior and decision-making, and ensure we hire people who will thrive at Podium. If you resonate with our operating principles and are energized by our mission, Podium will be a great place for you!

The Role

As a Senior Security Engineer at Podium, you will play a key role in shaping and implementing our corporate security strategy. Reporting to the Director of Security and collaborating with audit and compliance teams, you will design, implement, and manage secure solutions that align with our architectural designs, best practices, and regulatory requirements. Your expertise will help us navigate the evolving threat landscape and ensure our security measures are robust and forward-thinking.

In this position, you will be responsible for architecting solutions that secure our business operations and enable innovation. You'll work closely with diverse teams, including IT infrastructure, application development, security operations, and end users, to protect our organization and its assets. Your role will also involve guiding less experienced team members and providing technical leadership.

What you will be doing:

  • Stay updated on new security threats and ensure our systems can defend against them.
  • Own cloud infrastructure security
  • Own AI security
  • Manage vulnerability management system
  • Research and recommend new security solutions to enhance our security posture.
  • Develop and enforce security team standards, policies, procedures, and processes.
  • Plan and execute incident response and postmortem exercises, creating measurable benchmarks.
  • Conduct table-top exercises for Business Continuity/Disaster Recovery (BC/DR) and Incident Response testing.
  • Drive security efficiencies through automation and integration across technology and security architecture.
  • Collaborate with IT, engineering, development, and business teams to ensure security measures are effective and do not impede business processes.
  • Perform engineering performance testing to ensure security solutions are robust.
  • Provide day-to-day support for hardware, software, and managed solutions, ensuring they meet security standards.
  • Lead security team meetings and participate in security projects to evaluate and improve our security infrastructure.
  • Assist with incident response and system stability issues as needed, including outside regular work hours.
  • Ensure compliance with privacy laws and work with various teams to secure business-to-business initiatives, third-party relationships, and outsourced solutions.
  • Respond to service and escalation tickets and develop security test plans.
  • Regularly participate in change management meetings and follow security engineering fundamentals and processes.

What you should have:

  • 6+ years of experience in cybersecurity, including compliance and risk management.
  • Experience with cloud environments (AWS, GCP).
  • Strong technical and analytical skills, with a system and network security engineering background.
  • Experience in cloud computing technologies, including software-, infrastructure-, and platform-as-a-service.
  • Extensive knowledge of security controls and technologies, such as SIEM, IDS/IPS, PKI, IDAM, antivirus, firewalls, EDR, threat intelligence platforms, security automation, and orchestration.
  • Proficiency in meeting vulnerability management and penetration testing requirements.
  • Excellent communication skills to articulate business risk from cybersecurity issues.
  • Experience managing various security monitoring tools and platforms.
  • A track record of integrity, excellence, curiosity, and adaptability.
  • Additional qualifications include proficiency in scripting languages (Python, JavaScript, PowerShell, PHP, or Ruby) and regulatory standards (ISO 27001, NIST, PCI DSS, HIPAA, GDPR, etc.).

What we hope you have:

  • Familiarity with state privacy laws and ability to think strategically and tactically.
  • Highly trustworthy, with solid leadership qualities and a proactive approach to anticipating threats.
  • Bachelor's degree in computer science, information assurance, MIS, related field, or equivalent experience.
  • Relevant certifications such as CISSP, CRISC, CGEIT, or related.

Benefits:

  • Open and transparent culture 
  • Life insurance, long and short-term disability coverage
  • Paid maternity and paternity leave
  • Fertility Benefits
  • Generous vacation time, plus three 4-day summer holiday weekends
  • Excellent medical, dental, and vision benefits
  • 401k Plan with competitive company matching
  • Bi-annual swag drops with cool Podium gear and apparel 
  • A stellar HQ (Utah) gym with local professional coaches and classes offered
  • Onsite HQ (Utah) child care center, subsidized for employees
  • Additional benefits for fully remote employees

Podium is an equal opportunity employer. Podium provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, national origin, sexual orientation, gender identity or expression, age, disability, genetic information, marital status or veteran status.

See more jobs at Podium

Apply for this job

TripActions is hiring a Remote Staff Security Engineer, Detection and Response

Job Application for Staff Security Engineer, Detection and Response at Navan

See more jobs at TripActions

Apply for this job

+30d

Lead Security Engineer (REMOTE)

jirasalesforceDesignazure

Serigor Inc. is hiring a Remote Lead Security Engineer (REMOTE)

Lead Security Engineer (REMOTE) - Serigor Inc. - Career PageSee more jobs at Serigor Inc.

Apply for this job

+30d

Staff Software Engineer - Application Security

3P&T Security RecruitingEverett, WA, Remote
Designpythonjavascript

3P&T Security Recruiting is hiring a Remote Staff Software Engineer - Application Security

Job Description

They are looking for an experienced Staff Security Engineer to join their security team.  This role combines research, analysis, prevention, detection and forensics.  You will be engaged in everything from building safer and more security systems to detecting advanced (APT) attackers.  This role will require constant adaptation to new challenges that may arise in their ever-growing surface area.

In this role, you will:

  • Work with teams to discover and implement new detection capabilities and logging sources.
  • Be a thought leader in building our client's security road-map.
  • Be a security subject matter expert and respond to internal security engineering questions/requests.
  • Operate external bug bounty programs to source vulnerability information.
  • Architect, design and implement defensive systems that enhance their security.
  • Carefully balance security risk and product advancement.
  • Respond to security and privacy incidents, write incident reports, and participate in post-postmortems.
  • Perform penetration testing on their internal and external applications.
  • Integrate customer security requirements into product and system design.

Qualifications

Minimum required qualifications:

  • Bachelor's degree in Computer Science/Engineering or equivalent practical experience.
  • 8+ years of experience on security-focused teams.
  • Stellar programming/coding fundamentals.
  • Expertise working with web services deployed on Cloud providers.

The ideal candidate will also have:

  • Programming mastery in Go, Python, C/C++, JavaScript, TypeScript.
  • Demonstrated ability to ship production-quality software in a dynamic environment.
  • Strong communication skills and drive to collaborate across teams.
  • Deep knowledge with data privacy regulations and compliance e.g. SOC 2, GDPR, CCPA
  • Experience working with firmware and hardware security.

 

See more jobs at 3P&T Security Recruiting

Apply for this job

+30d

Security Engineer

terraformSailPointDesignansibleazurec++kuberneteslinuxpython

Cloudflare is hiring a Remote Security Engineer

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. 

We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time at Cloudflare. Come join us! 

Available Locations: Lisbon, Portugal or Austin, Texas 

About the role 

As a Security Engineer, you will play a key role in designing, implementing, and managing security technologies and the supporting infrastructure.  You will  be responsible for ensuring systems are secure, highly available, fault tolerant, and scale to meet business needs.  

Work may include documenting new standard operating procedures, ensuring vendor recommended security baseline configurations are implemented, designing repeatable deployment patterns, performing disaster recovery testing, configuring new integrations, implementing a new technology, patching applications and operating systems, performing upgrades and other maintenance tasks, documenting the as-built architecture, and participate in investigations and service restorations. 

What You’ll Do

  • Design, implement, and maintain secure infrastructure across various environments (non-production and production).
  • Ensure resilient and secure designs are implemented and maintained.
  • Drive continuous improvement while maintaining multiple environments.
  • Engage in proactive risk management and incident response planning.
  • Develop or utilize automation to streamline repeatable tasks.Contribute to the creation and dissemination of knowledge about the designs within the company.

Qualifications

  • Experience with deploying and administering Kubernetes in an enterprise environment. 
  • Experience with deploying and administering Linux systems in an enterprise environment. 
  • Experience with deploying and administering Cloudflare products (access, tunnels, waf) Experience implementing, intergrading, and  supporting identity and access management (IAM) technologies. 
  • Experience deploying and administering enterprise solutions in GCP, Azure, and AWS.Experience implementing, integrating, and supporting application security tools within a CICD pipeline environment.
  • Experience with all aspects of network infrastructure. Experience in all aspects of Site Reliability Engineering (SRE).
  • Solid understanding of reliability engineering principles and a commitment to continuous improvement.Experience writing scripts, leveraging automation, and creating infrastructure as code to streamline processes.
  • Strong analytical skills focused on service availability with curiosity and thoroughness in problem-solving.
  • Ability to navigate ambiguity, bring clarity to complex situations, and collaborate effectively with various stakeholders.

Desired Skills

  • Proficient in managing IAM related technologies like SailPoint, Saviynt, OneLogin, Ping, Okta, Azure Active Directory, Cyberark, Dilenea, or Beyond Trust in diverse environments.
  • Proficient in managing Application Security related technologies like Veracode, Checkmarx, SonarQube, Snyk, Semgrep, Fortify, or Coverity integrated into CI/CD pipelines. 
  • Strong background in deploying and supporting infrastructure and security technologies.
  • Knowledge of scripting and automation tools (e.g., Python, Terraform, Ansible).
  • Excellent communication and collaboration skills.

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: We equip politically and artistically important organizations and journalists with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.

Athenian Project: We created Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration.

1.1.1.1: We released 1.1.1.1to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitmentand ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law.We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail athr@cloudflare.comor via mail at 101 Townsend St. San Francisco, CA 94107.

See more jobs at Cloudflare

Apply for this job

+30d

IAM Security Engineer

CloudflareHybrid or Remote
DevOPSterraformsalesforceansibleapic++typescriptkubernetespython

Cloudflare is hiring a Remote IAM Security Engineer

About Us

At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company. 

We realize people do not fit into neat boxes. We are looking for curious and empathetic individuals who are committed to developing themselves and learning new skills, and we are ready to help you do that. We cannot complete our mission without building a diverse and inclusive team. We hire the best people based on an evaluation of their potential and support them throughout their time at Cloudflare. Come join us! 

Available Locations: Hybrid from Austin, TX, Washington D.C., San Francisco, CA, Mexico City, MX

About the Department
The Identity and Access Management (IAM) team is dedicated to ensuring the secure and efficient management of user identities, access privileges, and authentication mechanisms across internal systems, applications, and data. Our mission is to safeguard the organization against unauthorized access, protect sensitive information, and enable seamless user experiences while adhering to industry best practices and compliance standards.

About the Role

As an Identity and Access Management (IAM) Security Engineer, you will play a crucial role in designing, implementing, and scaling identity and access management solutions for Cloudflare’s internal workforce and workloads. You will be responsible for safeguarding our systems, applications, and data by ensuring secure user access, authentication, and authorization mechanisms.

 

What You’ll Do

  • Design, build, test, and deploy IAM solutions across authentication, authorization, and accounting 
  • Leverage Cloudflare products to secure our identities
  • Build SSO integrations leveraging SAML, OIDC, OAuth, and SCIM
  • Build and manage the Identity Governance and Administration platform
  • Develop automated roles leveraging RBAC and ABAC
  • Build and manage an access certification platform 
  • Build and manage a Privileged Access Management (PAM) platform
  • Provide operational support of IAM systems including an on-call rotation that may include after hours calls

Desirable skills, knowledge and experience

Security engineers take part in a wide variety of tasks and projects in the team. One individual is not expected to know everything, but a working knowledge in several of the following areas is required: 

  • Strong understanding of identity federation (SAML, OAuth, OpenID Connect, etc.)
  • Experience implementing Identity Governance and Administration (IGA) solutions including lifecycle management, SCIM, birthright access (RBAC, ABAC), and access certifications
  • Experience with secure configuration of containerized application platforms (e.g. Kubernetes)
  • Advanced scripting experience (Python, TypeScript, Bash, etc.)
  • Experience implementing Zero Trust controls
  • Experience integrating with applications and SaaS solutions 
  • Experience with Identity and Access Management policy application and enforcement
  • Experience working with Identity Threat Detection & Response (ITDR)
  • Experience working with infrastructure as code and configuration management tools like Terraform, Ansible, etc.

Compensation

Compensation may be adjusted depending on work location.

  • For Colorado, Illinois, Maryland and Minnesota based hires: Estimated annual salary of $137,000 - $167,000.
  • For New York City, Washington, Washington D.C. and California (excluding Bay Area) based hires: Estimated annual salary of $154,000 - $188,000.
  • For Bay Area based hires: Estimated annual salary of $162,000 - $198,000.

Equity

This role is eligible to participate in Cloudflare’s equity plan.

Benefits

Cloudflare offers a complete package of benefits and programs to support you and your family.  Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun!  The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.

Health & Welfare Benefits

  • Medical/Rx Insurance
  • Dental Insurance
  • Vision Insurance
  • Flexible Spending Accounts
  • Commuter Spending Accounts
  • Fertility & Family Forming Benefits
  • On-demand mental health support and Employee Assistance Program
  • Global Travel Medical Insurance

Financial Benefits

  • Short and Long Term Disability Insurance
  • Life & Accident Insurance
  • 401(k) Retirement Savings Plan
  • Employee Stock Participation Plan

Time Off

  • Flexible paid time off covering vacation and sick leave
  • Leave programs, including parental, pregnancy health, medical, and bereavement leave

What Makes Cloudflare Special?

We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.

Project Galileo: We equip politically and artistically important organizations and journalists with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers--at no cost.

Athenian Project: We created Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration.

1.1.1.1: We released 1.1.1.1to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitmentand ensure that no user data is sold to advertisers or used to target consumers.

Sound like something you’d like to be a part of? We’d love to hear from you!

This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.

Cloudflare is proud to be an equal opportunity employer.  We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness.  All qualified applicants will be considered for employment without regard to their, or any other person's, perceived or actual race, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law.We are an AA/Veterans/Disabled Employer.

Cloudflare provides reasonable accommodations to qualified individuals with disabilities.  Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.  If you require a reasonable accommodation to apply for a job, please contact us via e-mail athr@cloudflare.comor via mail at 101 Townsend St. San Francisco, CA 94107.

See more jobs at Cloudflare

Apply for this job

+30d

Senior Security Engineer

ICEYEEspoo,Uusimaa,Finland, Remote
Design

ICEYE is hiring a Remote Senior Security Engineer

Role highlights:

  • Senior Security Engineer (IAM)
  • Finland
  • Permanent
  • Remote

Who are we?

ICEYE is the global leader in synthetic aperture radar (SAR) satellite operations for Earth Observation, persistent monitoring, and natural catastrophe solutions; owning and operating the world's largest SAR constellation. ICEYE is headquartered in Finland and operates from five international locations with more than 600 employees from nearly 60 countries, inspired by the shared vision of improving life on Earth by becoming the global source of truth in Earth Observation.

Our satellites acquire images of Earth at any time – even when it’s cloudy or dark – providing commercial and government partners with unmatched persistent monitoring capabilities. Information derived from our SAR images helps customers make data-driven decisions to address time-critical challenges in various sectors, such as maritime, disaster management, insurance, and finance.

Our team is a tight-knit group of experts across many disciplines (e.g., engineering, software development, radar technology, etc.). We’re innovative, driven people who strive for excellence in everything we do. Teamwork, curiosity, and having fun are core values at ICEYE, and contribute to Making the Impossible possible!!

Why should you work for us?

ICEYE is at the cutting edge of new technology and we are continuing to build and operate our commercial constellation of SAR satellites. Working with ICEYE, you will be part of making the impossible possible, whilst shaping the Earth Observation industry. You will work with varied, diverse and engaged colleagues to further the ICEYE mission. At ICEYE we realize that without great people we can not succeed, therefore you will be an integral, valued and appreciated colleague, with the ability to directly shape the vision and direction of the business. 

We actively support Continuous Professional Development, and will provide access to a range of avenues to allow you to succeed, including courses, training and attendance at conferences. ICEYE is a place where your development, your growth and your success is a priority. 

What is the role?

As a Senior Security Engineer at ICEYE, you will leverage your expertise in Identity and Access Management (IAM)  and access control model design to overhaul existing practices and develop robust solutions for securing a modern and rapidly evolving work environment. This role is part of our Security Engineering team, which is responsible for both building a secure self-service platform for most daily developer actions and working with developers and product managers on further adopting secure development practices. The goal for the team is to gather together blue and red team experts to work together on how to best solve the cat-and-mouse game that is modern cybersecurity. Because of the collaborative nature of the work, we seek individuals who excel in collaborative environments, seek continuous improvements and have the expertise to navigate the complexities of today's threat landscape.

A typical day for you will involve collaborating with platform and development oriented teams to assess and enhance our security posture. You will start your day by reviewing security events, conducting threat analysis, and performing vulnerability assessments. Throughout the day, you will design and implement access control models, manage IAM operations, and enforce the principle of least privilege for our cloud infrastructure and services. Your IAC wizardry and craftsmanship, combined with a passion for GitHub, will drive the definition, refinement, and automation of these security concepts and processes. You'll regularly evaluate the robustness of our security controls, report any identified gaps to your peers, and propose infrastructure enhancements. This feedback loop is integral to our continuous improvement approach.

You will serve as a reference for authentication and authorization design choices and implementation details across multiple projects.

What will you need to be successful in this role?

As a Senior Security Engineer, you will bring a blend of expertise and hands-on experience to enhance our security measures:

  • Solid expertise with IAM
  • Proficiency in securing API endpoints to prevent unauthorized access and mitigate potential vulnerabilities
  • Experience implementing Zero Trust principles
  • Experience with identity provider setup and management
  • Expertise in DevSecOps and a shift-left mentality, focusing on integrating security into every stage of the development lifecycle, along with strong automation skills
  • Understanding and managing public key infrastructure (PKI) systems

In addition to the above, it would be beneficial if you had the below attributes and skills: 

  • Strong understanding and hands-on experience with OAuth2.0, OIDC, and SCIM protocols
  • Experience implementing and managing security services within AWS environments
  • Experience managing identity management platforms such as Auth0, Okta, or FusionAuth
  • Knowledge of Istio and Spire/SPIFFE
  • Understanding of OPA (Open Policy Agent)
  • Experience with Kubernetes
  • Familiarity with HashiCorp Vault

What do we offer?

  • A job that matters in a dynamic Earth Observation environment with a scale-up approach
  • An independent role with a supportive and diverse work environment
  • Occupational healthcare, occupational and private insurance
  • A yearly benefit budget to spend as you wish (i.e. on sport, transport, bike benefit, wellness, lunch, etc.)
  • Phone subscription with iPhone of choice 
  • Relocation support (i.e. flight tickets, accommodation, relocation agency support)
  • Time for self-development, research, training, conferences, or certification schemes
  • Inspiring and collaborating offices and silent workspaces enable you to focus
  • A wide variety of the best coffee, tea, snacks, and sweets to accompany your daily space mission



Base salary range 

  • 6000 to 8000 EUR per month (gross) contingent on your experience level, and will be negotiated individually 

Diversity, equity, and inclusion

At ICEYE, we believe that diversity isn't just a buzzword – it's our greatest asset. 

We're committed to fostering an inclusive environment where every voice is not only heard but celebrated. We know that diverse perspectives breed innovation and creativity, which is why we actively seek out individuals from all walks of life, backgrounds, and experiences. 

Whatever your background, we want you to bring your authentic self to the table. Join us and be part of a team where differences are not only embraced but cherished, because together, we're stronger. 

Apply now to start your ICEYE journey, and help us continue to make the impossible possible together. 

Read more about ICEYE and working with us at iceye.com 

See more jobs at ICEYE

Apply for this job

+30d

Director of Engineering, Security

MonzoCardiff, London or Remote (UK)
Designc++AWS

Monzo is hiring a Remote Director of Engineering, Security

???? We’re on a mission to make money work for everyone.

We’re waving goodbye to the complicated and confusing ways of traditional banking. 

With our hot coral cards and get-paid-early feature, combined with financial education on social media and our award winning customer service, we have a long history of creating magical moments for our customers!

We’re not about selling products - we want to solve problems and change lives through Monzo ❤️

Hear from our team about what it's like working at Monzo


 

????London or Remote (UK) | ???? This is a unique role, we’re open to discussions around base salary + stock options + Benefits

Engineering at Monzo

We’re looking for a creative, entrepreneurial and impact-focused Engineering Director to join our Security team and help us build one of the best, most innovative and secure banks in the world. 

As an Engineering Director you’ll lead a team of engineers to review and understand evolving threat models, assess our security risk landscape and set ambitious multi-year strategies for keeping our customers, the business and our employees safe and secure both now and into the future. You’ll operate with autonomy and have a massive impact on our customers’ lives and Monzo’s success.

The Security collective designs and builds systems and infrastructure to detect, mitigate, prevent and protect Monzo’s customers, its staff and its physical and virtual infrastructure from malign individuals and organisations. 

The teams work across the stack, from building custom PKI infrastructure as part of our Zero Trust security model rollout, to creating innovative customer-facing features like Call Status that helps customers know for certain if Monzo is calling them. We’ve built Multi-Person Authorisation systems to protect AWS infrastructure from being changed by a single person with access to an admin account, all the way through building automated testing frameworks, fuzzers, linters and other engineering support tooling that allow engineers to build systems that are secure by default. 

You can read more about our industry leading Call Status feature here

You should apply if you have:

  • You have experience leading an organisation of 30+ software engineers and understand the importance of good organisational design on creating effective teams
  • You have experience managing a number of Engineering Managers and/or Senior Engineering Managers.
  • You’re comfortable using data to ground your thinking in analysis, can identify key metrics and their drivers and evaluate the success of your work.
  • You make good decisions in complex situations where there’s often no right answer
  • Proven track record in designing, developing and supporting operationally excellent, high availability systems which provide critical business function
  • Experience leading complex cross-functional engineering projects
  • Proven track record of developing and managing distributed systems
  • Deep experience in managing a portfolio of concurrent engineering projects running the gamut from short-term critical feature launches to long-term strategic initiatives.
  • You must have prior experience as an engineer at senior level or higher. 

Nice to have:

  • Broad knowledge across the Security domain 

The interview process:

Our interview process involves 3 main stages: 

  1. Recruiter Call (30 mins) You'll meet our Engineering Leadership Recruiter to discuss your experience and learn more about Monzo. They'll be your partner and guide throughout the interview process.
  2. Initial Call (1 hour) You'll meet with our VP of Engineering. They'll ask you about your previous experience, in particular people leadership, product delivery and technical leadership. They’ll ask example based questions (‘Tell me about a time when…’)
  3. Loop Stage - This is one stage with 4 interviews (totalling 4 hours) split between a collaboration with one of our engineers on a technical exercise, as well as execution and leadership interviews.

At all stages we’ll create space for you to ask as many questions as you have, you’re interviewing us as well!

Our average process takes around 3-4 weeks but we will always work around your availability. You will have the chance to speak to our recruitment team at various points during your process but if you do have any specific questions ahead of this please contact us on tech-hiring@monzo.com.

What’s in it for you:

????Base salary range for this role is dependent on experience + equity + stock options & benefits 

✈️ We can help you relocate to the UK  

✅ We can sponsor visas

????This role can be based in our London office, or we're open to distributed working within the UK (with ad hoc meetings in London).

⏰ We offer flexible working hours and trust you to work enough hours to do your job well, at times that suit you and your team.

????Learning budget of £1,000 a year for books, training courses and conferences

➕And much more, see our full list of benefits here


Equal opportunities for everyone

Diversity and inclusion are a priority for us and we’re making sure we have lots of support for all of our people to grow at Monzo. At Monzo, we’re embracing diversity by fostering an inclusive environment for all people to do the best work of their lives with us. This is integral to our mission of making money work for everyone. You can read more in our blog, 2023 Diversity and Inclusion Report and 2023 Gender Pay Gap Report.

We’re an equal opportunity employer. All applicants will be considered for employment without attention to age, ethnicity, religion, sex, sexual orientation, gender identity, family or parental status, national origin, or veteran, neurodiversity or disability status.

If you have a preferred name, please use it to apply. We don't need full or birth names at application stage ????

See more jobs at Monzo

Apply for this job

+30d

Senior Security Engineer

ICEYEWarsaw,Masovian Voivodeship,Poland, Remote Hybrid
Design

ICEYE is hiring a Remote Senior Security Engineer

Role highlights:

  • Senior Security Engineer
  • Warsaw, Poland
  • Permanent
  • Hybrid

Who are we?

ICEYE is the global leader in synthetic aperture radar (SAR) satellite operations for Earth Observation, persistent monitoring, and natural catastrophe solutions; owning and operating the world's largest SAR constellation. ICEYE is headquartered in Finland and operates from five international locations with more than 600 employees from nearly 60 countries, inspired by the shared vision of improving life on Earth by becoming the global source of truth in Earth Observation.

Our satellites acquire images of Earth at any time – even when it’s cloudy or dark – providing commercial and government partners with unmatched persistent monitoring capabilities. Information derived from our SAR images helps customers make data-driven decisions to address time-critical challenges in various sectors, such as maritime, disaster management, insurance, and finance.

Our team is a tight-knit group of experts across many disciplines (e.g., engineering, software development, radar technology, etc.). We’re innovative, driven people who strive for excellence in everything we do. Teamwork, curiosity, and having fun are core values at ICEYE, and contribute to Making the Impossible possible!!

Why should you work for us?

ICEYE is at the cutting edge of new technology and we are continuing to build and operate our commercial constellation of SAR satellites. Working with ICEYE, you will be part of making the impossible possible, whilst shaping the Earth Observation industry. You will work with varied, diverse and engaged colleagues to further the ICEYE mission. At ICEYE we realise that without great people we can not succeed, therefore you will be an integral, valued and appreciated colleague, with the ability to directly shape the vision and direction of the business. 

We actively support Continuous Professional Development, and will provide access to a range of avenues to allow you to succeed, including courses, training and attendance at conferences. ICEYE is a place where your development, your growth and your success is a priority. 

What will you do in this role?

As a Senior Security Engineer you will be dedicated to protecting company assets. Responsibilities include developing a SOC toolset, monitoring, alerting, and playbook creation in a rapidly expanding company environment.

Senior Security Engineer will deeply understand SOC operations and the unique challenges of securing a modern hybrid work environment. This role is within the Security team, offering opportunities for collaboration and growth in an engaging work environment. You should demonstrate strong problem-solving skills and organizational prowess, along with expertise in navigating the complexities of today's threat landscape.

  • You will develop new security solutions and maintain existing ones to protect the company better.
  • Help build an automated SOC toolset including:
    • Tuning EDR;
    • Defining and implementing correct endpoint/server logging and ensuring coverage of all assets;
    • Ensuring all logs are optimally streamed to SIEM;
    • Ensuring all systems meet securing logging requirements;
    • Tuning SIEM logs and troubleshooting them (indexing, normalization, acceleration);
    • Creating alerts for specific TTPs and activity;
    • Creating and maintaining SOAR playbooks to automate incident workflows for common/known alerts;
    • Setting up Threat Intel gathering and integrating it into our SOAR playbooks;
    • Creating and maintaining Detection-as-Code setup to store detection logic in a code repository.
  • Help with Zero Trust, PAM, Passwordless setup, and maintenance.
  • Investigate alerts/incidents and create relevant automation and/or additional detection.
  • Identify any publicly known vulnerabilities as well as new security issues that might arise from operational and functional risks.
  • Participate in design, implementation, and review phases and lead a technical discussion concerning security mechanisms presented in a high-level and low-level design of new solutions.
  • Support the team in ongoing projects.

Required:

  • Proven experience (5+ years) in security engineering, SOC operations, system administration, or other cyber security-relevant roles.
  • Curious, with up-to-date knowledge across the cybersecurity landscape
  • Knowledge of EDR, SIEM, and SOAR tooling and implementation experience for SOC use cases, including monitoring, alerting, and playbooks.
  • Experience working with modern security principles like Privileged Access Management, Passwordless, and Zero Trust Architecture.
  • Experience in monitoring various OSes and network devices.
  • Scriptwriting skills - Bash/Python/Powershell and experience in writing scripts for monitoring.
  • Strong communication and interpersonal skills, with the ability to explain technical concepts to non-technical stakeholders.
  • Ability to work independently and collaboratively in a fast-paced, dynamic environment.

Preferred:

  • Experience with Cloud monitoring, cloud policy/alerting tools, and related best practices.
  • Base salary range for this position is 15000-23000 PLN per month (gross) contingent on your experience level, and will be negotiated individually.

Poland

  • A job that matters in a dynamic Earth Observation environment with a scale-up approach
  • An independent role with a supportive and diverse work environment
  • A yearly benefit budget to spend as you wish (MyBenefit i.e. on sport, transport, wellness, lunch, tourism, etc.)
  • Relocation support (i.e. flight tickets, accommodation, relocation agency support etc.)
  • Time for self-development, research, training, conferences, or certification schemes
  • Polish language lessons
  • Occupational and private healthcare and life insurance 
  • Inspiring and collaborating offices and silent workspaces enable you to focus
  • A wide variety of the best coffee, tea, snacks, and sweets to accompany your daily space mission

Finland

  • A job that matters in a dynamic Earth Observation environment with a scale-up approach
  • An independent role with a supportive and diverse work environment
  • Occupational healthcare, occupational and private insurance
  • A yearly benefit budget to spend as you wish (i.e. on sport, transport, bike benefit, wellness, lunch, etc.)
  • Phone subscription with iPhone of choice 
  • Relocation support (i.e. flight tickets, accommodation, relocation agency support)
  • Time for self-development, research, training, conferences, or certification schemes
  • Inspiring and collaborating offices and silent workspaces enable you to focus
  • A wide variety of the best coffee, tea, snacks, and sweets to accompany your daily space mission

See more jobs at ICEYE

Apply for this job

+30d

Security Engineer, Corporate Security

GrammarlyUnited States; Hybrid
remote-firstDesignjavac++python

Grammarly is hiring a Remote Security Engineer, Corporate Security

Grammarly is excited to offer a remote-first hybrid working model. Team members work primarily remotely in the United States, Canada, Ukraine, Germany, or Poland. Certain roles have specific location requirements to facilitate collaboration at a particular Grammarly hub.

All roles have an in-person component: Conditions permitting, teams meet 2–4 weeks every quarter at one of Grammarly’s hubs in San Francisco, Kyiv, New York, Vancouver, and Berlin, or in a workspace in Kraków.This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that fosters trust and unlocks creativity.

Grammarly team members in this role must be based in the United States, and they must be able to collaborate in person 2 weeks per quarter, traveling if necessary to the hub(s) where the team is based.

The opportunity 

Grammarly is the world’s leading AI writing assistance company, trusted by over 30 million people and 70,000 professional teams every day. From instantly creating a first draft to perfecting every message, Grammarly’s product offerings help people at 96% of theFortune500 get their point across—and get results. Grammarly has been profitable for over a decade because we’ve stayed true to our values and built an enterprise-grade product that’s secure, reliable, and helps people do their best work—without selling their data. We’re proud to be one of Inc.’s best workplaces, a Glassdoor Best Place to Work, one of TIME’s 100 Most Influential Companies, and one of Fast Company’s Most Innovative Companies in AI.

Trust is critical to Grammarly’s mission. The Enterprise Security team’s mission is to defend Grammarly’s corporate assets from all threats through risk reduction. Enterprise Security reduces risk to Grammarly by advising, supporting, building, operating, and assuring multiple critical preventive and reactive security controls in tight collaboration with teams and stakeholders across the company.

Grammarly’s engineers and researchers have the freedom to innovate and uncover breakthroughs—and, in turn, influence our product roadmap. The complexity of our technical challenges is growing rapidly as we scale our interfaces, algorithms, and infrastructure. You can hear more from our team on our technical blog.

Your impact

As a Security Engineer on the enterprise security team, you will be entrusted with the crucial responsibility of safeguarding Grammarly's corporate environment, where our amazing employees work their magic every day. From our versatile laptop fleet (Mac and Windows) to our innovative SaaS apps and other Corporate Infrastructure, you will play a vital role in ensuring our success and keeping our valuable assets secure. With a confident and thoughtful approach, you'll build and implement solutions that raise the security bar for our corporate infrastructure. If you love working on both security and operations, we are excited to have you join our dynamic team!

In this role, the Security Engineer will:

  • Contribute to designing and developing engineering solutions that support enterprise-wide security initiatives, such as Zero Trust.
  • Collaborate with our Governance Risk and Compliance (GRC) team to help develop enterprise security standards, guidelines, and policies.
  • Design, build, maintain, tune, and enhance the effectiveness of our Enterprise Security controls in a wide range of security domains, including:
    • Endpoint Detection and Response (EDR)
    • Email Security
    • Ransomware Resilience
    • Data Loss Prevention (DLP)/Insider Risk
    • Conditional Access
    • Vendor/Business Process Outsourcing (BPO) Security
    • Device Posture and Attestation, Shadow IT
    • Threat and Vulnerability Management (TVM)
    • Identity and Access Management (IAM)
    • Public Key Infrastructure (PKI)
  • Perform risk assessments and security assurance (threat modeling, code review as necessary) on a range of systems that support Grammarly’s business operations:
    • Operating Systems and commercial/open-source desktop applications
    • Internally developed Enterprise Infrastructure Services
    • Third-Party Software as a Service (SaaS) solutions
    • Network Infrastructure (ZTNA, CASB, VPN)
  • Drive the remediation of security vulnerabilities identified through assessments.
  • Build security automation to secure our corporate infrastructure.
  • Evaluate cutting-edge Enterprise Security technology designed to increase our security posture.

We’re looking for someone who

  • Embodies our EAGER values—is ethical, adaptable, gritty, empathetic, and remarkable.
  • Is inspired by our MOVE principles, which are the blueprint for how things get done at Grammarly: move fast and learn faster, obsess about creating customer value, value impact over activity, and embrace healthy disagreement rooted in trust.
  • Is able to collaborate in person 2 weeks per quarter, traveling if necessary to the hub where the team is based.
  • Is excited to build security controls to safeguard our systems and services.
  • Has working experience in Security Assurance: Penetration Testing, Code Review, Threat Modeling.
  • Is familiar with programming languages such as Python, Java, or Go for automation purposes.
  • Has a strong understanding of cybersecurity threats, vulnerabilities, and mitigations.
  • Is knowledgeable about the best practices and technologies of cloud security.
  • Has excellent problem-solving skills, with the ability to work independently and handle multiple tasks.
  • Has strong communication skills and can explain complex security issues in understandable terms.
  • Nurtures the talent in the team and raises the technical talent bar when recruiting for their team.

Support for you, professionally and personally

  • Professional growth:We believe that autonomy and trust are key to empowering our team members to do their best, most innovative work in a way that aligns with their interests, talents, and well-being. We support professional development and advancement with training, coaching, and regular feedback.
  • A connected team: Grammarly builds a product that helps people connect, and we apply this mindset to our own team. Our remote-first hybrid model enables a highly collaborative culture supported by our EAGER (ethical, adaptable, gritty, empathetic, and remarkable) values. We work to foster belonging among team members in a variety of ways. This includes our employee resource groups, Grammarly Circles, which promote connection among those with shared identities, such as BIPOC and LGBTQIA+ team members, women, and parents. We also celebrate our colleagues and accomplishments with global, local, and team-specific programs. 

Compensation and benefits

Grammarly offers all team members competitive pay along with a benefits package encompassing the following and more: 

  • Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching 
  • Paid parental leave
  • Twenty days of paid time off per year, eleven days of paid holidays per year, and unlimited sick days 
  • Home office stipends
  • Caregiver and pet care stipends
  • Wellness stipends
  • Admission discounts
  • Learning and development opportunities

Grammarly takes a market-based approach to compensation, which means base pay may vary depending on your location. Our US and Canada locations are categorized into compensation zones based on each geographic region’s cost of labor index. For more information about our compensation zones and locations where we currently support employment, please refer to this page. If a location of interest is not listed, please speak with a recruiter for additional information. 

Base pay may vary considerably depending on job-related knowledge, skills, and experience. The expected salary ranges for this position are outlined below by compensation zone and may be modified in the future. 

United States: 
Zone 1: $320,000 - $380,000/year (USD)
Zone 2: $290,000 - $340,000/year (USD)

We encourage you to apply

At Grammarly, we value our differences, and we encourage all—especially those whose identities are traditionally underrepresented in tech organizations—to apply. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, ancestry, national origin, citizenship, age, marital status, veteran status, disability status, political belief, or any other characteristic protected by law. Grammarly is an equal opportunity employer and a participant in the US federal E-Verify program (US). We also abide by the Employment Equity Act (Canada).

Please note that EEOC is optional and specific to US-based candidates.

#LI-PM1

#LI-Hybrid

All team members meeting in person for official Grammarly business or working from a hub location are strongly encouraged to be vaccinated against COVID-19.

 

Apply for this job

+30d

Security Engineer, Platform Security

GrammarlyUnited States; Hybrid
MLS3remote-firstterraformnosqlDesignjavac++elasticsearchpython

Grammarly is hiring a Remote Security Engineer, Platform Security

Grammarly is excited to offer a remote-first hybrid working model. Grammarly team members in this role must be based in the United States”, and, depending on business needs, they must meet in person for collaboration weeks, traveling if necessary to the hub(s) where their team is based.

This flexible approach gives team members the best of both worlds: plenty of focus time along with in-person collaboration that fosters trust and unlocks creativity.

About Grammarly

Grammarly is the world’s leading AI writing assistance company trusted by over 30 million people and 70,000 teams. From instantly creating a first draft to perfecting every message, Grammarly helps people at 96% of theFortune 500 and teams at companies like Atlassian, Databricks, and Zoom get their point across—and get results—with best-in-class security practices that keep data private and protected. Founded in 2009, Grammarly is No. 7 on the Forbes Cloud 100, one of TIME’s 100 Most Influential Companies, one of Fast Company’s Most Innovative Companies in AI, and one of Inc.’s Best Workplaces.

The Opportunity

To achieve our ambitious goals, we’re looking for a Security Engineer, Platform Security to join our Trust & Enterprise team. 

We’re looking for a Security Engineer to join our Platform Security team to achieve our ambitious goals. This person will substantially impact maintaining the trust of the millions of users who rely on Grammarly product offerings daily. They will drive security improvements across our cloud and data platform while empowering engineering teams to operate fast and safely.

Grammarly’s engineers and researchers have the freedom to innovate and uncover breakthroughs—and, in turn, influence our product roadmap. The complexity of our technical challenges is growing rapidly as we scale our interfaces, algorithms, and infrastructure. You can hear more from our team on our technical blog.

Your impact

As a Security Engineer - Platform Security, you will:

  • Collaborate closely with product and engineering teams to integrate robust security features directly into our platform.
  • Design and implement advanced tooling and processes to comprehensively monitor and secure our platform infrastructure.
  • Facilitate cross-team efforts among Cloud and Data Platform engineering groups to enhance security without compromising development speed.
  • Develop and implement security processes to identify, evaluate, and mitigate security risks across our AI products.
  • Design and Implement Just-In-Time (JIT) and role-based access controls to safeguard our production environment and customer data effectively.
  • Craft and apply a strategic cloud and infrastructure security framework, contributing to the program's strategic direction and roadmap.
  • Engage in proactive collaboration with diverse teams, from full-stack developers to ML engineers and data scientists, ensuring the integration of security best practices into every phase of the development lifecycle.

We’re looking for someone who

  • Embodies our EAGER values—is ethical, adaptable, gritty, empathetic, and remarkable.
  • Is inspired by our MOVE principles: move fast and learn faster; obsess about creating customer value; value impact over activity; and embrace healthy disagreement rooted in trust.
  • Is able to meet in person for their team’s scheduled collaboration weeks, traveling if necessary to the hub where their team is based.
  • Possesses a proven track record in enhancing security across various data platforms, including Databricks, NoSQL, ElasticSearch, S3, and Kafka.
  • Operates primarily as a 'security builder,’ working alongside engineering teams. This includes designing, implementing, and operating services with a strong focus on security.
  • Has significant experience deploying Cloud and Data Infrastructure through Terraform, CloudFormation, or Cloud Development Kit (CDK), and proficiency in programming languages such as Python, Java, and Go.

Compensation and Benefits

Grammarly offers all team members competitive pay along with a benefits package encompassing the following and more: 

  • Excellent health care (including a wide range of medical, dental, vision, mental health, and fertility benefits)
  • Disability and life insurance options
  • 401(k) and RRSP matching 
  • Paid parental leave
  • 20 days of paid time off per year, 12 days of paid holidays per year, two floating holidays per year, and unlimited sick days 
  • Generous stipends (including those for caregiving, pet care, wellness, your home office, and more)
  • Annual professional development budget and opportunities

Grammarly takes a market-based approach to compensation, which means base pay may vary depending on your location. Our US locations are categorized into two compensation zones based on proximity to our hub locations.

Base pay may vary considerably depending on job-related knowledge, skills, and experience. The expected salary ranges for this position are outlined below by compensation zone and may be modified in the future.

United States: 
Zone 1: $280,000 - $399,000/year (USD)
Zone 2: $250,000 - $350,000/year (USD)
 
For more information about our compensation zones and locations where we currently support employment, please refer to this page. If a location of interest is not listed, please speak with a recruiter for additional information.

We encourage you to apply

At Grammarly, we value our differences, and we encourage all to apply—especially those whose identities are traditionally underrepresented in tech organizations. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, ancestry, national origin, citizenship, age, marital status, veteran status, disability status, political belief, or any other characteristic protected by law. Grammarly is an equal opportunity employer and a participant in the US federal E-Verify program (US). We also abide by the Employment Equity Act (Canada).

#LI-PM1

#LI-Hybrid

 

Apply for this job

+30d

Sr. Security Detection Engineer

DatabricksRemote - California
MLc++python

Databricks is hiring a Remote Sr. Security Detection Engineer

Job Application for Sr. Security Detection Engineer at Databricks

See more jobs at Databricks

Apply for this job

Cobalt.io is hiring a Remote Security Engineer (Part-time contract) Remote North America

Who We Are 

Cobalt was founded on the belief that pentesting can be better. Our pentests start in as little as 24 hours and integrate with modern development cycles thanks to the powerful combination of a SaaS platform coupled with an exclusive community of testers known as the Cobalt Core. Accepting just 5% of applicants, the Core boasts over 400 closely vetted and highly skilled testers who jointly conduct thousands of tests each year. 

Our award-winning, fully remote team is committed to helping agile businesses remediate risk quickly and innovate securely. Today, over 1,000 customers use Cobalt to run pentests on demand via Pentest as a Service, AKA PtaaS, a space which Cobalt pioneered (you could even say we wrote the book on it) and continues to lead. 

Description

This role provides critical support to Cobalt TPMs and Cobalt Core Pentesters by leveraging their technical security expertise. This role is occasionally customer facing. This role will report to the Technical Security Advisor and Head of Cybersecurity Services.

What You'll Do

  • This role will provide technical support for engagement escalations. This includes reviewing logs and assessing historical performance for pentesters involved in engagements with associated escalations. 
  • This role will provide technical support for engagements as needed, such as (but not limited to) infrastructure related activities for various engagement types and logging.
  • This role will conduct regular audits of pentest engagements performed by Cobalt Core, including reviewing findings, updates, and logs.
  • This role will provide technical security enablement for TPMs
  • This role will support our AE/CSM teams with customer related technical questions
  • This role will collaborate with Delivery and Community on guidelines, communications, and enablement for pentesters. 
  • This role will support platform content by developing and improving checklists and report templates.

You Have

  • 4+ years professional pentesting experience, must include web app pentesting
  • 2+ years customer facing experience
  • Strong communication skills
  • Responsive and the ability to delivery quality at speed

Bonus If You Have

  • Project or program management experience

Diversity at Cobalt

With over 45 nationalities already at Cobalt (and counting) we respect and celebrate diversity! We’re proudly committed to equal employment opportunities regardless of your gender, religion, age, sexual orientation, ethnicity, disability, or place of origin. We support each other and are grateful for each Cobalter's contribution to our mission — let's make security dance! 

Please apply even if you don't think you meet all of the criteria above but are still interested in the job. Nobody checks every box, and we're looking for someone excited to join the team.

Why You Should Join Us

  • Grow in a passionate, rapidly expanding industry operating at the forefront of the Pentesting industry 
  • Work directly with experienced senior leaders with ongoing mentorship opportunities
  • Earn competitive compensation and an attractive equity plan
  • Save for the future with a 401(k) program (US) or pension (EU) 
  • Benefit from medical, dental, vision and life insurance (US) or statutory healthcare (EU)
  • Leverage stipends for:
    • Wellness
    • Work-from-home equipment & wifi
    • Learning & development
  • Make the most of our flexible, generous paid time off and paid parental leave 
  • Work remotely from anywhere in the US, the UK, or Germany

See more jobs at Cobalt.io

Apply for this job

+30d

Senior Security Engineer, Trust & Safety

WebflowU.S. Remote
Webflowremote-firstc++python

Webflow is hiring a Remote Senior Security Engineer, Trust & Safety

At Webflow, our mission is to bring development superpowers to everyone. Webflow is the leading visual development platform for building powerful websites without writing code. By combining modern web development technologies into one platform, Webflow enables people to build websites visually, saving engineering time, while clean code seamlessly generates in the background. From independent designers and creative agencies to Fortune 500 companies, millions worldwide use Webflow to be more nimble, creative, and collaborative. It’s the web, made better. 

As the Operations Engineer of Trust & Safety, you will report to the Director of Security, and play an essential role in keeping our platform safe.  You will understand and enforce Webflow standards and policies regarding Developer and User activity on our platform. You will lead geographically and functionally diverse teams through challenging circumstances and you will engage deeply with our XFN teams across Policy, Product, Engineering and others to help develop and execute solutions. Protecting our Webflow’s community is important to you.

About the role

  • Location: Remote-first (United States; BC & ON, Canada) 
  • Full-time 
  • Permanent
  • Exempt 
  • The cash compensation for this role is tailored to align with the cost of labor in different geographic markets. We've structured the base pay ranges for this role into zones for our geographic markets, and the specific base pay within the range will be determined by the candidate’s geographic location, job-related experience, knowledge, qualifications, and skills.
    • United States(all figures cited below in USD and pertain to workers in the United States)
      • Zone A: $162,500 - $216,050
      • Zone B: $152,700 - $203,100
      • Zone C: $143,00 - $190,150 
    • Canada(All figures cited below in CAD and pertain to workers in ON & BC, Canada)
      • CAD 184,600 - CAD 245,500
  • Please visit our Careers page for more information on which locations are included in each of our geographic pay zones. However, please confirm the zone for your specific location with your recruiter.

As the Senior Security Engineer, Trust & Safety, you will … 

  • Work with Trust & Safety team members to drive initiatives to support the strategic goals of Webflows Trust & Safety mission.
  • Work to scale Trust & Safety operations with tooling and process improvements
  • Coordinate with Webflow’s legal, security, operations and product teams, as well as external vendors, to develop and implement risk management strategies for Webflow’s platforms.
  • Drive operational execution of Product launches as they pertain to Trust & Safety
  • Wear a strategic hat to solve potential problems and stay one step ahead of roadblocks and abuse strategies.
  • Evaluate processes and craft recommendations to improve efficiency
  • Collaborate cross-functionally to develop core playbooks for Trust & Safety operations and establish best practices
  • Build, maintain, and regularly communicate detailed reporting for other leaders across the company who will use your team's insights to inform and improve their own operations and strategy

About you

You’ll thrive as (a) Senior Security Engineer, Trust & Safety if you have the following:

  • Minimum of 3+ or more years of full stack web application software development experience building tooling for Trust & Safety
  • Ability to work effectively and cross-functionally with all levels of management, both internally and externally
  • A passion for data analysis and reporting
  • Expertise in process improvement to identify and enhance operational efficiencies.
  • Project management skills (PMP or other project management certification a plus)
  • Data Analysis: Strong analytical skills are required, preferably with experience in using data analysis tools or software. 
  • You should be capable of interpreting complex data, identifying trends, and making data-driven decisions.
  • Ideal experience includes coding experience in NodeJS and/or Python

In the context of this role, individuals may be exposed to potentially disturbing & sensitive content (e.g., graphic, violent, sexual, or egregious), and will need a level of resilience and maturity. We care for our employees' safety and well-being and ensure that they have the support and resources needed to execute the responsibilities of their roles through our comprehensive wellness and health benefits programs.

If you don’t meet 100% of the above qualifications, you should still seriously consider applying. Studies show that you can still be considered for a role if you meet just 50% of the role’s requirements.

Our Core Behaviors:

  • Obsess over customer experience. We deeply understand what we’re building and who we’re building for and serving. We define the leading edge of what’s possible in our industry and deliver the future for our customers
  • Move with heartfelt urgency. We have a healthy relationship with impatience, channeling it thoughtfully to show up better and faster for our customers and for each other. Time is the most limited thing we have, and we make the most of every moment
  • Say the hard thing with care. Our best work often comes from intelligent debate, critique, and even difficult conversations. We speak our minds and don’t sugarcoat things — and we do so with respect, maturity, and care
  • Make your mark. We seek out new and unique ways to create meaningful impact, and we champion the same from our colleagues. We work as a team to get the job done, and we go out of our way to celebrate and reward those going above and beyond for our customers and our teammates

Benefits & wellness

Equity ownership (RSUs) in a growing, privately-owned company100% employer-paid healthcare, vision, and dental insurance coverage for employees and dependents (full-time employees working 30+ hours per week), as well as Health Savings Account/Health Reimbursement Account, dependent care Flexible Spending Account (US only), dependent on insurance plan selection where applicable in the respective country of employment; Employees may also have voluntary insurance options, such as life, disability, hospital protection, accident, and critical illness where applicable in the respective country of employment12 weeks of paid parental leave for both birthing and non-birthing caregivers, as well as an additional 6-8 weeks of pregnancy disability for birthing parents to be used before child bonding leave (where local requirements are more generous employees receive the greater benefit); Employees also have access to family planning care and reimbursementFlexible PTO with a mandatory annual minimum of 10 days paid time off for all locations (where local requirements are more generous employees receive the greater benefit), and sabbatical programAccess to mental wellness and professional coaching, therapy, and Employee Assistance ProgramMonthly stipends to support health and wellness, smart work, and professional growthProfessional career coaching, internal learning & development programs401k plan and pension schemes (in countries where statutorily required) financial wellness benefits, like CPA or financial advisor coverageDiscounted Pet Insurance offering (US only)Commuter benefits for in-office employees

Temporary employees are not eligible for paid holiday time off, accrued paid time off, paid leaves of absence, or company-sponsored perks unless otherwise required by law.

Remote, together

At Webflow, equality is a core tenet of our culture. We are an Equal Opportunity (EEO)/Veterans/Disabled Employer and are committed to building an inclusive global team that represents a variety of backgrounds, perspectives, beliefs, and experiences. Employment decisions are made on the basis of job-related criteria without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by applicable law. Pursuant to the San Francisco Fair Chance Ordinance, Webflow will consider for employment qualified applicants with arrest and conviction records.

Wellbeing Statement

Trust & Safety recognizes that keeping our platform safe for Webflow communities is no ordinary job. It can be rewarding, psychologically demanding, and emotionally taxing. This is why we are sharing the potential  risks and implications for this unique line of work from the start: so our candidates are well informed before proceeding.

 

We are committed to the wellbeing of all our employees and promise to provide comprehensive and evidence-based programs, to promote and support physical and mental wellbeing throughout each employee's journey with us. 

 

Stay connected

Not ready to apply, but want to be part of the Webflow community? Consider following our story on our Webflow Blog, LinkedIn, X (Twitter), and/or Glassdoor

Please note:

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Upon interview scheduling, instructions for confidential accommodation requests will be administered.

Based on the San Francisco Fair Chance Ordinance, Webflow will consider for employment qualified applicants with arrest and conviction records.

To join Webflow, you'll need a valid right to work authorization depending on the country of employment.

If you are extended an offer, that offer may be contingent upon your successful completion of a background check, which will be conducted in accordance with applicable laws. We may obtain one or more background screening reports about you, solely for employment purposes.

For information about how Webflow processes your personal information, please reviewWebflow’s Applicant Privacy Notice



See more jobs at Webflow

Apply for this job

+30d

Security Engineer

Deutsche Telekom IT SolutionsDebrecen, Hungary, Remote
linuxpython

Deutsche Telekom IT Solutions is hiring a Remote Security Engineer

Job Description

Within DT-Technik, we are looking for an ambitious and experienced colleague in the security area (T-SRC) for the Security Operations Center Technik (SOCT) squad. The Squad SOCT offers comprehensive services for the security of DT Technik's networks and systems.

  • Security monitoring in SIEM (Security Information and Event Management), Elastic Endpoint Protection (EPP) and other sources.
  • Monitor and investigate security events and incidents using established processes and procedures
  • Categorizing and reporting incidents following established procedures
  • Create and update incident logs, ensuring accurate and thorough documentation
  • Prepare lessons learned reports to enhance incident response processes
  • Maintaining and updating detection rulesets following established processes
  • Development and operation of automatic end-to -end test chain for cyber attack detection rules (SIEM, IDS, EPP)
  • Bug fixing and optimisation of the tested detection rules
  • Development of missing detection rules

Qualifications

  • IT Security experience
  • Technical knowledge and experience with at least one well-known SIEM or security analytics solution
  • Solid knowledge of Windows and Linux operation systems
  • General knowledge of web security, network protocols, devices, services, and related technologies (TCP/IP, Firewall, IPS/IDS, web proxy)
  • Understanding of host-based security tools such as anti-virus and EDR
  • In-depth knowledge of cybersecurity principles, technologies and best practices
  • Demonstrated understanding of threat landscapes, attack vectors, and vulnerabilities
  • Experience in programming and/or scripting languages (Powershell, Python)
  • Strong analytical and problem-solving skills, ability to analyze logs of various devices, solutions
  • Reliable English communication skills (both written and verbal)

See more jobs at Deutsche Telekom IT Solutions

Apply for this job

+30d

Sr. Security Engineer

ScienceLogicReston, VA or Remote
Bachelor's degreeremote-firstDesignc++

ScienceLogic is hiring a Remote Sr. Security Engineer

What we’re looking for…

ScienceLogic is looking for a Senior Security Engineer who will design and implement systems and procedures to sustain the security, integrity, and availability of the organization's data. Assess risk of exposure of proprietary data through weaknesses in platforms, access procedures, and forms of access to the organization's systems and the data contained in them. Track security violations and identify trends or exposures that could be addressed by additional training, technical measures, or use of application tools to enhance security. May participate in ethical simulated attacks or security violations to assess the organization's data security measures.

 

What you’ll be doing…

  • Conduct platform or operating system vulnerability scans that assess exposure of system to attacks or hacking. Monitor Security Operations pager and respond to issues of potential viral activity, spam, phishing.
  • Administer controls and review their application to ensure that system's controls, policies, and procedures are operating effectively relative to the predicted effectiveness of the controls.
  • Investigate events or incidents of apparent security breaches and report to appropriate authorities using corporate procedures.
  • Collaborate with internal and external auditors to ensure that appropriate controls are installed, operating properly, and being monitored and reported.
  • May plan and/or conduct tests of the core infrastructure and the contingency environment for critical business applications to ensure business continuity in the event of a computer security incident.
  • Aggregate metrics of operation of security controls, as well as apparent attacks, breaches, and other pertinent data; track trends and prepare for periodic security reports.
  • Measure and improve patch management procedures with appropriate teams.
  • Participate in projects designed to test defenses against hacking, denial of service, spam, break-ins, or similar attacks. May provide guidance to infrastructure or application staff participating in exercise.
  • Examine and/or test new methodologies or tools that could be adopted to enhance security of platforms, infrastructure, or access to data.
  • Other duties as required.

 

Qualities you possess…

 

  • US Citizenship with the ability to obtain a public trust clearance required.
  • Bachelor's Degree or equivalent required.
  • Applicable certifications are desired.
  • 5+ years of related experience in an IT Security related field.
  • 5+ years of experience as system or network administrator or a support specialist in a SOC environment.
  • Solid understanding of basic fundamentals in TCP/IP and the OSI model as well as common routing protocols.
  • Experience with SOC 2 and/or ISO 27001 audits and certifications.
  • Experience working with Firewalls and IDS technologies .
  • Problem solving skills complimented with experience in solving information security device and application issues with customers is a must.
  • SOC/NOC experience desired. Good verbal and written communication skills as well as attention to detail.
  • Exceptional customer service skills and interpersonal skills. Ability to work in small teams.
  • Must be able to resolve highly complex and technical business problems.
  • Understanding of threat agents, attack vectors, and attack patterns as well as compensating controls and design patterns needed to mitigate risk.
  • Possesses a broad domain level of expertise to resolve complex issues and performs detailed network analysis across a broad range of network and other technologies both on premise as well as cloud and hosted environments.
  • Demonstrated skills on technical procedures development (equipment configuration) for testing and implementation of design changes.
  • Create technical documentation and diagrams using Microsoft Visio, Excel, Word and PowerPoint.
  • Knowledge of single sign-on integration with on premise and cloud toolset.
  • Knowledgeable of Network Design and Project Management methodologies.
  • Excellent presentation/verbal communication skills.

 

Recommended Certifications or Skills

  • Security+
  • Associate CISSP
  • Associate SSCP
  • Associate CCSP
  • OS/Linux/Windows/macOS
  • Directory Services
  • Microsoft Security Center, Intune, Defender
  • Network Protocols
  • Scripting Languages (Python/Bash/PowerShell)

 

 

 

Benefits & Perks

  • A remote-first culture - work from home or come into the office, it's totally up to you.
  • Comprehensive medical, dental and vision plans.
  • 401(k) plan with employer match.
  • Flexible Paid Time Off (FTO) so that you can take the time that you need to re-energize.
  • Volunteer Time Off (VTO) - take two days off per calendar year to volunteer with your preferred charitable organization.
  • 5-year Service Milestone Sabbatical.
  • Paid parental leave.
  • Generous employee referral bonus program.
  • Pet insurance.
  • HQ Office centrally located in Reston Town Center featuring a well-stocked kitchen with rotating snacks and beverages, and catered lunch on Thursdays.
  • Regular virtual company-wide events, including cooking classes, yoga, meditation and more.
  • The opportunity to learn and develop from some of the best and brightest minds in the industry!

 

Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At ScienceLogic, we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or any other applicable legally protected characteristics in the location in which you are applying.

 

 

About ScienceLogic

We empower intelligent and automated IT operations.

The ScienceLogic SL1 platform enables companies to digitally transform themselves by removing the difficulty of managing complex, distributed IT services. We use patented discovery techniques to find everything in your IT environment, so you get visibility across all technologies and vendors running anywhere in your data centers or clouds

 

www.sciencelogic.com

 

All ScienceLogic employees have the responsibility to protect information assets, adhere to access controls, report suspicious activity, and comply with security and privacy policies.

 

See more jobs at ScienceLogic

Apply for this job