Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. 🚀
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
Security Engineer performs hands-on coding, incident response, threat-hunting, and policy development to secure backend systems and infrastructure.
About Eneba
At Eneba, we’re building an open, safe and sustainable marketplace for the gamers of today and tomorrow. Our marketplace supports close to 20m+ active users (and growing fast!), provides a level of trust, safety and market accessibility unparalleled to none. We’re proud of what we’ve accomplished in such a short time and look forward to sharing this journey with you. Join us as we continue to scale, diversify our portfolio, and grow with the evolving community of gamers.
You will join a growing security team where you can take meaningful ownership of the practices and policies you help develop. You will work closely with backend engineering and other departments to integrate practical security requirements across the company.
As a Security Engineer, you’ll cover a broad range of operational and strategic security work rather than a single narrow specialty. In your first few months, you’ll focus on learning Eneba’s tech stack and understanding how our services and systems fit together. That foundation is essential before you can secure those systems effectively.
Day-to-day, you can expect to:
Hands-on coding and security implementation work make up the largest part of the role today, alongside incident response and threat-hunting responsibilities.
Review and triage security submissions and incident reports.
Evaluate and respond to bug bounty reports, including remediation follow-through
Build, operate, and improve incident response and remediation processes.
Write and maintain security policies and documentation.
Communicate security requirements and risks clearly to non-technical departments
Review application monitoring and logs to catch and investigate anomalies
Support access governance and permission-management processes.
The tech stack is the same one our backend teams work with. You’re not expected to know all of it on day one, but you should expect to be learning how to use most of it within your first 3 months, and you’ll also be working across other languages and systems used throughout the company as your role demands.
Code
PHP/Symfony
Golang
GraphQL
gRPC
CQRS, commands via saga/temporal, queries via GraphQL
Microservices architecture
Service orchestration withSaga /temporal.io
Databases
InfluxDB
Redis
ElasticSearch
MariaDB
MySQL
Infrastructure
Kubernetes
Helm
AWS
Terraform
Prometheus
Strong written and verbal communication skills - this is our highest priority, since you’ll regularly need to explain technical risk to non-technical audiences
Solid PHP knowledge
Security knowledge, or a clearly demonstrated interest in security (bug bounties, CTFs, security blogs, following the security community)
A background in IT, backend engineering, or a related technical field
Self-sufficiency - comfort taking ownership of tasks and making progress without constant guidance.
Ownership mentality and strong problem-solving skills
Openness to learning and working across multiple systems, languages, and technologies rather than staying in one lane
Nice to have
Experience with monitoring tools and application monitoring
Familiarity with the OWASP Top 10
€58,000 - €69,000 a year
What it’s like to work at Eneba
*Opportunity to join our Employee Stock Options program.
*Opportunity to help scale a unique product.
*Various bonus systems: performance-based, referral, additional paid leave, personal learning budget.
*Paid volunteering opportunities.
*Work location of your choice: office, remote, opportunity to work and travel.
*Personal and professional growth at an exponential rate supported by well-defined feedback and promotion processes.
*Please attach CV’s in English.
*To find out about how we handle your personal data, make sure to check out our Candidate Privacy Notice https://www.eneba.com/candidate-privacy-notice
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Develops and implements security measures to protect applications from vulnerabilities and threats throughout the software development lifecycle.
Manages identity and privileged access management systems, monitors security risks, and ensures infrastructure stability and scalability.
Manages cyber compliance programs and governance frameworks to ensure organizational adherence to security standards and regulatory requirements.
Conducts security assessments and compliance evaluations using NIST frameworks, develops security documentation (SSPs, SARs, POA&Ms), and verifies implementation of security controls for federal and commercial clients.
TestPros delivers innovative independent IT assessment solutions to critical challenges facing the nation and the world. We support the U.S. Federal Government and Commercial clients within the continental USA. TestPros is dedicated to making lives better, safer and more secure.
TestPros is looking for Security Controls Assessors with experience performing on risk management programs for U.S. Federal and commercial clients by utilizing NIST, RMF, and FISMA compliance frameworks.
Start: Future projects late 2026 or 2027 (not an immediate job opening)
Type: Part-time consulting
Overview
Specifically, we are looking for professionals with experience in conducting NIST 800-53 Rev 5 based Authority To Operate (ATO) support.
Responsibilities and Duties:
You should be able to deliver on the following expertly and consistently:
Qualifications and Skills:
Rate: $50-95/hr (1099 or Corp. To Corp.). This range represents a good-faith estimate and is not a guarantee; final compensation is determined by factors such as experience, qualifications, and government contract labor rate requirements and may fall outside the stated range.
Equal Opportunity Employer
TestPros is an equal-opportunity employer and does not discriminate in employment based on race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or any other non-merit factor.
Offer Considerations
TestPros considers several factors when extending an offer, including but not limited to, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, geographic location, education, and certifications.
Federal Compliance
As a federal contractor, TestPros is subject to all federal and state mandates and/or other customer requirements.
Design and implement CyberArk integrations with enterprise applications, identity platforms, and cloud services to strengthen security infrastructure.
Manages compliance frameworks (SOC 2, ISO 27001, etc.) and responds to security questionnaires from enterprise customers and regulated organizations.
Who we are
At Domino, we build software that helps the largest, AI-driven organizations build and operate advanced data science and AI solutions at scale. Our platform integrates a streamlined model development environment, MLOps capabilities, and novel features for collaboration, reuse, and reproducibility — all of which make data science teams more productive, reduce time to value, and ensure compliance. Our customers — like Johnson & Johnson, GSK, Bristol Myers, UBS, FINRA and the US Navy — are using our software to solve some of the most important challenges in the world, such as developing new medicines, securing our financial markets, or protecting our country. Backed by Sequoia Capital, Coatue Management, NVIDIA, Snowflake and other leading investors, we have been in business for a decade but are still a small team operating with the spirit of a startup. Especially in the world of AI today, we believe that the future is still being invented — and we want to be the ones building it. For more information, visit www.domino.ai
What we are building
The Quality & Compliance team at Domino is…
What your impact will be
In your first year, you will:
What we look for in this role
What we value
#LI-Remote
Conducts security assessments, triages vulnerabilities, and builds AI-powered automation tools to streamline security operations for Cloudflare's products.
About Us
At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies. Cloudflare protects and accelerates any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks. Cloudflare was named to Entrepreneur Magazine’s Top Company Cultures list and ranked among the World’s Most Innovative Companies by Fast Company.
At Cloudflare, we’re not looking for people who wait for a polished roadmap; we’re looking for the builders who see the cracks in the Internet that everyone else has simply learned to live with. We value candidates who have the instinct to spot a “normalized” problem and the AI-native curiosity to create a solution using the latest tools. Our culture is built on iteration, leveraging AI to ship faster today to make it better tomorrow, while ensuring that every improvement, no matter how small, is shared across the team to lift everyone up. If you’re the type of person who values curiosity over bureaucracy, and that AI is a partner in solving tough problems to keep the Internet moving forward, you’ll fit right in.
Available Locations: Austin, TX
As a Product Security Engineer, you will support security assessments and vulnerability operations for Cloudflare’s core software products. In this role, you will analyze system architecture, threat model new features, and ensure that product-related security findings are accurately triaged, routed to the correct engineering owners, and mitigated within our SLAs.
On any given day, you might conduct a deep-dive security review on a new feature design, triage a complex bug bounty submission, or work directly with engineering teams to resolve vulnerabilities from different sources like bug bounties, SAST, fuzzing and penetration tests. You will also work autonomously to identify areas where our manual processes slow down. You will write code and integrate AI/LLM solutions to automate initial triage and data enrichment, building tools that help the team handle security findings at scale. In short, your work will sit at the intersection of Product Security, Vulnerability Operations, and internal AI Tooling. Ideally, you have experience in conducting academic/vulnerability research with a focus on systems security.
Responsibilities
Bonus points
Equity
This role is eligible to participate in Cloudflare’s equity plan.
Benefits
Cloudflare offers a complete package of benefits and programs to support you and your family. Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future and make life a little easier and fun! The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.
Health & Welfare Benefits
Financial Benefits
Time Off
What Makes Cloudflare Special?
We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.
Project Galileo: Since 2014, we’ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers–at no cost.
Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project, we’ve provided services to more than 425 local government election websites in 33 states.
1.1.1.1: We released1.1.1.1 to help fix the foundation of the Internet by building a faster, more secure and privacy-centric public DNS resolver. This is available publicly for everyone to use - it is the first consumer-focused service Cloudflare has ever released. Here’s the deal - we don’t store client IP addresses never, ever. We will continue to abide by our privacy commitment and ensure that no user data is sold to advertisers or used to target consumers.
Sound like something you’d like to be a part of? We’d love to hear from you!
Please note that applicants who progress to the offer stage of the interview process may be asked to attend an in-person interview within one of the Cloudflare Offices or Cloudflare Hubs. More details about this will be available at that stage of the interview process.
This position may require access to information protected under U.S. export control laws, including the U.S. Export Administration Regulations. Please note that any offer of employment may be conditioned on your authorization to receive software or technology controlled under these U.S. export laws without sponsorship for an export license.
Cloudflare is proud to be an equal opportunity employer. We are committed to providing equal employment opportunity for all people and place great value in both diversity and inclusiveness. All qualified applicants will be considered for employment without regard to their, or any other person’s, perceived or actualrace, color, religion, sex, gender, gender identity, gender expression, sexual orientation, national origin, ancestry, citizenship, age, physical or mental disability, medical condition, family care status, or any other basis protected by law. We are an AA/Veterans/Disabled Employer.
Cloudflare provides reasonable accommodations to qualified individuals with disabilities. Please tell us if you require a reasonable accommodation to apply for a job. Examples of reasonable accommodations include, but are not limited to, changing the application process, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment. If you require a reasonable accommodation to apply for a job, please contact us via e-mail at hr@cloudflare.com or via mail at 101 Townsend St. San Francisco, CA 94107.
Embeds security into federal software delivery by conducting risk assessments, supporting ATO compliance efforts, and maintaining FISMA/FedRAMP security postures for VA systems.
Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.
We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.
What you’ll be doing:
What you’ll bring:
Experience supporting ATO and RMF processes including documentation and continuous monitoring
Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks
Experience securing cloud environments such as AWS GovCloud or Azure Government
Familiarity with vulnerability scanning tools such as Nessus or ACAS
Familiarity with SIEM platforms such as Splunk or ELK Stack
Some scripting or automation experience in Python, Bash, or PowerShell is a plus
CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus
Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team
Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams
Performs other related duties as assigned.
Requirements:
Education:
Benefits:
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:
Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©
Compensation:
At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.
United States Wage Range: $110,000 – $145,000
Embed security into federal software delivery by integrating security requirements into development workflows, supporting ATO processes, and conducting risk assessments aligned with NIST and VA standards.
Oddball believes that the best products are built when companies understand and value the things they are working on. We value learning and growth and the ability to make a big impact at a small company. We believe that we can make big changes happen and improve the daily lives of millions of people by bringing quality software to the federal space.
We’re looking for a Security Engineer to join our VA team, embedding security into software delivery and helping maintain the compliance posture of systems that directly serve Veterans.
What you’ll be doing:
What you’ll bring:
Experience supporting ATO and RMF processes including documentation and continuous monitoring
Solid understanding of NIST SP 800-53, FISMA, and FedRAMP frameworks
Experience securing cloud environments such as AWS GovCloud or Azure Government
Familiarity with vulnerability scanning tools such as Nessus or ACAS
Familiarity with SIEM platforms such as Splunk or ELK Stack
Some scripting or automation experience in Python, Bash, or PowerShell is a plus
CISSP, CAP, CEH, CISM, or DoD 8570 certification is a plus
Thrives in a remote, collaborative Agile environment and genuinely enjoys working closely with a cross-functional team
Communicates clearly and openly, whether writing compliance documentation or coordinating with engineering teams
Performs other related duties as assigned.
Requirements:
Education:
Benefits:
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities:
Oddball is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact an Oddball HR representative to request such an accommodation by emailing hr@oddball.io
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or © consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35©
Compensation:
At Oddball, it’s important each employee is compensated competitively and fairly. In alignment with state legal requirements. A range for the included position is listed below. Be advised, actual offer details are determined by job category, job location, and candidate skill level.
United States Wage Range: $110,000 – $145,000
Security engineer designs and manages IAM infrastructure, Okta environments, and SaaS data governance while enforcing least privilege access controls.
Headquarters: Argentina
URL: http://solvd.com
Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes.
Following the acquisition of Tooploox, a premier AI and product development company, Solvd now offers true end-to-end delivery—from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively.
We are looking for a Mid-Tier Security Engineer specializing in Identity and Access Management (IAM) and Data Governance to join our Cyber Security team. In this role, you won't just be managing user tickets; you will be the engineer designing, implementing, and securing our identity perimeter and SaaS ecosystem.
You will own our Okta environment and drive data governance strategies across our core SaaS applications (e.g., Google Workspace, Microsoft 365, Slack, Salesforce, GitHub). Your goal is to ensure seamless user lifecycle management while aggressively enforcing the principle of least privilege and monitoring data exposure.
Identity & Access Management (IAM) Engineering
Okta Architecture & Admin: Act as the primary engineer for Okta, managing advanced configurations including custom authorization servers, adaptive MFA, and conditional access policies.
Lifecycle Automation: Design and maintain automated joiner-mover-leaver (JML) workflows using Okta Workflows, SCIM, or custom API scripts to eliminate manual provisioning errors.
Federation & Protocols: Standardize and implement SSO integrations utilizing SAML 2.0, OIDC, and OAuth 2.0, ensuring secure token exchange and scoping.
Data Governance & SaaS Security
Least Privilege Enforcement: Design, audit, and refine Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) models across all enterprise SaaS platforms.
Data Exposure Mitigation: Monitor and remediate unauthorized data sharing, public file exposure, and "shadow IT" API integrations within our SaaS ecosystem.
Access Reviews & Compliance: Lead quarterly user access reviews (UARs) and provide evidentiary support for security frameworks such as SOC 2 Type II, ISO 27001, and GDPR.
SaaS Security Posture Management (SSPM): Leverage SSPM tools or native security centers to continuously audit and harden SaaS application configurations.
Monitoring & Incident Response
Threat Detection: Analyze Okta System Logs and SaaS audit logs to detect anomalous behavior (e.g., impossible travel, credential stuffing, unauthorized data exfiltration).
SIEM Integration: Collaborate with the SOC team to ensure critical IAM and SaaS logs are correctly ingested into our SIEM for real-time alerting.
Experience: 3–5 years of dedicated experience in a Security Engineering, IAM, or Systems Engineering role with a heavy security focus.
Okta Mastery: Strong engineering-level knowledge of Okta (Okta Certified Administrator or Certified Consultant preferred).
Security Mindset: Proven track record of implementing data governance principles, data loss prevention (DLP), and zero-trust access models.
Core Protocols: Deep understanding of networking and identity protocols: TCP/IP, HTTP, SAML, OAuth, OIDC, and SCIM.
Scripting: Proficiency in Python, PowerShell, or Bash to interact with REST APIs for custom security tooling and automation.
Log Analysis: Experience querying logs (Splunk, ELK, SQL, or cloud-native SIEMs) to investigate identity-related security incidents.
When you join Solvd, you'll…
Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.
Be part of a global team with equal opportunities for collaboration across continents and cultures.
Thrive in an inclusive environment that prioritizes continuous learning, innovation, and ethical AI standards.
Ready to make an impact?
If you're excited to build things that matter, champion responsible AI, and grow with some of the industry’s sharpest minds. Apply today and let’s innovate together.
Solvd is an equal opportunity employer.
To apply: https://weworkremotely.com/remote-jobs/solvd-security-engineer-ii-iam-saas-governance
Embeds security practices across product development, builds CI/CD security guardrails, designs secure architectures, and enables engineering teams to adopt secure-by-design practices.
✨ About Voyage Privé
Born in France in 2006, Voyage Privé has grown from an ambitious startup into becoming the Europe’s leading travel tech platform. Operating across 9 markets with tens of millions of users, we’re not just another e-commerce success story - we’re a tech powerhouse revolutionizing online travel.
What makes us unique? A mission-driven culture where performance meets impact. Our innovative campus brings together tech talent, professional athletes, students, and artists, creating an ecosystem where digital innovation drives both business growth and positive change.
We’re now at an inflection point, upgrading our entire technical foundation with cloud architecture, AI, and real-time systems to become a reference and top-of-mind platform for luxury travel, known by travelers for its for excellent offer and customer experience, and by our providers as a high-performance business development partner.
🎯 Your Mission
As a Security Engineer, you’ll play a key role in shaping the security and resilience of Voyage Privé’s technology platform.
You’ll work closely with Engineering, Product, and Platform teams to embed security practices into every stage of product development, deliver measurable impact, and help us scale efficiently while maintaining a strong security posture.
You’ll have the opportunity to build many security foundations from scratch — from internal tooling to CI/CD guardrails — and influence key architectural and technical decisions as we redesign our platform for scale.
Your key responsibilities will include:
💡 What We’re Looking For
We’re looking for builders who move fast, think big, and care deeply about creating impact that lasts
Your profile:
⚡ Our Recruitment Process
We believe in a fast, transparent, and human recruitment process.
Here’s what you can expect:
📍Location : Aix en Provence or remote, France
📅 Start Date : The sooner, the better
📄 Contract Type : Full-time / Permanent
❤️ You’ll Love Joining Us
Our HQ in the South of France offers an exceptional environment - natural, cultural, and digital - on a modern and eco-responsible campus.
🌴 Prefer flexibility? We offer a hybrid model for all other positions with 3 mandatory on-site days per week plus 4 fully remote weeks per year.
🤝Put meaning back into your work and join a unique ecosystem that connects worlds often far apart: business, sports, education, and social impact, through projects like Ecole des XV, Provence Rugby, VP Green, Les Tremplins, and Chez Pierre.
💪 Forget your gym subscription! Access our large on-site fitness center morning, noon, and night - or challenge your colleagues to a padel match on our private court.
🎉 Live to the rhythm of Voyage Privé’s signature mix of business and fun: Company Breaks, Carnival, Annual Convention, meetups and talks… plus free tickets to every Provence Rugby home match and live music nights at the Dalida Institute.
✈️ And because travel is in our DNA : enjoy up to 20% off our exclusive getaway offers.
Join us and make your next career move a journey worth taking. 🌍
Develops and implements application security practices, conducts security assessments, and manages vulnerability remediation within the software development lifecycle.
Conducts application security reviews, implements secure SDLC initiatives, and supports security monitoring across the company's software development lifecycle.
About FareHarbor
At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.
With over 20,000 clients across 90+ countries—we’re the largest in our industry and shaping the future of travel, together.
Our team is an ‘Ohana of 700+ people around the world. We’re passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.
FareHarbor Core Values:
Why FareHarbor?
Founding FareHarbor required unwavering passion. Turning a start-up into the world’s leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, we’ve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.
And since day one, we’ve known that our real success lies in our people—the Ohana.
With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to work—to believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.
From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we can’t wait to see all that’s to come.
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.
To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.
Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.
Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.
CENSUS’ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.
We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.
Key Responsibilities
Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.
Design and support the implementation of secure Azure cloud architectures.
Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.
Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.
Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.
Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).
Ensure that the implemented solutions align with the product’s security architecture, requirements and threat model.
Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.
Document and present product security risks in both technical and business contexts.
Minimum Qualifications
MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.
3 + years of experience in IT or Cybersecurity
2 + years of experience in cloud applications or cloud security related roles – preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.
Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).
Problem solving skills, analytical thinking and willingness to learn/grow.
Proficient in English.
Required Skills
Experience with:
Designing, implementing and auditing cloud platform security architecture and engaged technologies.
The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).
Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.
Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.
DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.
Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.
Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.
Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).
Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.
Nice-to-Have Skills
Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.
Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.
Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).
Familiarity with debugging, instrumenting and profiling software running on cloud platforms.
Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.
Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.
Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.
Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.
Experienced in working with international teams in other regions and time zones worldwide.
#LI-Remote
Application Security Engineer who conducts security reviews, implements secure SDLC practices, and supports security monitoring across the platform.
About FareHarbor
At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.
With over 20,000 clients across 90+ countries—we’re the largest in our industry and shaping the future of travel, together.
Our team is an ‘Ohana of 700+ people around the world. We’re passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.
FareHarbor Core Values:
Why FareHarbor?
Founding FareHarbor required unwavering passion. Turning a start-up into the world’s leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, we’ve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.
And since day one, we’ve known that our real success lies in our people—the Ohana.
With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to work—to believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.
From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we can’t wait to see all that’s to come.
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.
To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.
Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.
Designs and audits Azure cloud security architectures, conducts threat modeling and risk assessments, and implements security controls for enterprise and cloud-native environments.
CENSUS’ bespoke cybersecurity services are driven by a talented team of Security Engineers, Consultants, and Researchers whose work goes beyond traditional security assessment. Bolstered by the technology-focused expertise of our Technical Leads and our deep industry knowledge, our Security Engineers/Architects are tasked with implementing and assessing the security design of cutting-edge technologies.
We are seeking technically strong and detail-oriented professionals to expand our Technology & Operations team and join our ongoing mission to deliver comprehensive and top-tier cybersecurity services to our valued clients. In this role, you will leverage your experience in Microsoft Azure to develop Azure security architectures, execute design security reviews and conduct risk assessments across cloud-native, hybrid, and enterprise environments.
Key Responsibilities
Analyze product security requirements and apply industry-recognized methodologies to translate them into effective Azure security controls.
Design and support the implementation of secure Azure cloud architectures.
Audit externally developed product security designs, document missing security controls and lead efforts to analyze and implement security improvements.
Conduct threat modeling, attack surface analysis and attack tree creation for applications, services, workloads and AI-enabled solutions running on Microsoft Azure.
Research, review, compare and propose Microsoft technologies that meet client requirements and align with their strategic objectives.
Validate CI/CD pipelines and audit deployment configurations across various hosting environments (native, hybrid, etc.).
Ensure that the implemented solutions align with the product’s security architecture, requirements and threat model.
Perform comprehensive security posture assessments through source code auditing, functional testing, fuzz testing, and other relevant methodologies.
Document and present product security risks in both technical and business contexts.
Minimum Qualifications
MSc or BSc. in Electrical Engineering, Computer Science, Computer Engineering or equivalent.
3 + years of experience in IT or Cybersecurity
2 + years of experience in cloud applications or cloud security related roles – preferably Microsoft Azure. Experience can be an engineering / development position (e.g., consumer or enterprise), an assessment / consultancy role, an equivalent role in other engineering organizations or a combination of them.
Proven experience in developing or auditing security solutions for cloud platforms (public, private or hybrid Cloud Service Providers).
Problem solving skills, analytical thinking and willingness to learn/grow.
Proficient in English.
Required Skills
Experience with:
Designing, implementing and auditing cloud platform security architecture and engaged technologies.
The Azure ecosystem and its security features (Microsoft Entra ID, Azure RBAC, Privileged Identity Management, Service Accounts, Workload / VM Identities, TLS / PKI / Certificates Management, Azure Storage, Key Vault, managed HSM, etc.).
Developing & comprehending source code, discerning business logic and identifying security flaws in Web- and Cloud-relevant languages, such as Python, C#, Go, Java, Ruby, Rust, JavaScript or related frameworks.
Application authentication, authorization, identity, access management, and secrets management technologies, such as OAuth, MFA, SSO, JWT, PKI, Cloud IAM, password-less authentication, HashiCorp Vault, etc.
DevSecOps practices, including secure CI/CD pipeline design, automated security testing, infrastructure-as-code security, container/image scanning, dependency management, and policy-as-code enforcement e.g. Azure Policy, Bicep/Terraform.
Secure systems hardening across on-premises, hybrid, and cloud environments, including operating systems, network services, virtualization platforms, Kubernetes clusters, cloud workloads, and baseline configuration standards such as CIS Benchmarks.
Applying Secure SDLC principles, including security requirements definition, secure design reviews, threat modeling, secure coding guidance, code review support, vulnerability remediation and security gate integration throughout the development lifecycle.
Designing and assessing secure AI agent architectures on Microsoft Azure, including Azure AI Foundry, Azure OpenAI, agent orchestration patterns, tool integration, grounding with enterprise data and secure retrieval-augmented generation (RAG).
Securing AI agents with enterprise controls such as Microsoft Entra ID, scoped agent identities, least-privilege Azure RBAC, private networking, secrets protection, telemetry, evaluation, guardrails and responsible AI controls.
Nice-to-Have Skills
Applied cryptography and cryptographic protocols, such as E2E protection, authenticated encryption, mTLS, Key Exchange / Agreement, Key Derivation, Key Wrapping and Remote Key Attestation.
Cloud confidential computing, virtualization, enclaves, containers, and workload attestation technologies.
Identifying and mitigating security vulnerabilities on software running on cloud platforms (OWASP Web Top10 vulnerabilities, data encryption, transport layer protections, insecure configurations, secrets management, etc.).
Familiarity with debugging, instrumenting and profiling software running on cloud platforms.
Familiarity with enterprise security baselines, hardening automation, compliance-as-code, and configuration management tooling across both traditional infrastructure and cloud-native platforms.
Familiarity with developer enablement practices, including security champions programs, secure coding training, reusable security patterns, and practical guidance for embedding security into engineering workflows.
Familiarity with operationalizing AI agents in enterprise environments, including lifecycle management, monitoring, prompt and tool risk assessment, data leakage prevention, auditability, and integration with Microsoft 365 Copilot or Teams-based workflows.
Familiarity with SIEM architecture and applications, including log source onboarding, data normalization, detection use-case design, correlation rules, alert triage workflows, SOAR integrations, and operational tuning for cloud, hybrid and enterprise environments.
Experienced in working with international teams in other regions and time zones worldwide.
#LI-Remote
Designs and implements security controls across compliance, cloud infrastructure, and IT systems to strengthen organizational security posture.
Designs, deploys, and maintains Microsoft Entra ID and Active Directory solutions for enterprise identity and access management across a global workforce.
About AbbVie
AbbVie’s mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people’s lives across several key therapeutic areas including immunology, oncology, and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at www.abbvie.com. Follow @abbvie on LinkedIn, Facebook, Instagram, X and YouTube.
Join AbbVie’s Information Security & Risk Management (ISRM) team as an IAM Directory Services Engineer, where we empower our partners to succeed by delivering the knowledge, tools, and support needed to leverage data and technology securely and effectively. As part of our Identity & Access Management (IAM) team, you will play a pivotal role in shaping and executing our enterprise-wide IAM strategy.
The ideal candidate will have deep expertise in Microsoft Entra ID (formerly Azure AD), Active Directory, Certificate Services, supporting related authentication tools, and PowerShell scripting experience to design, implement, and manage Directory and Authentication solutions for our global workforce of 80,000 users.
Responsibilities:
Preferred:
Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law:
Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company’s sole and absolute discretion unless and until paid and may be modified at the Company’s sole and absolute discretion, consistent with applicable law.
AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled.
US & Puerto Rico only - to learn more, visit https://www.abbvie.com/join-us/equal-employment-opportunity-employer.html
US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more:
https://www.abbvie.com/join-us/reasonable-accommodations.html
Designs, implements, and secures enterprise network infrastructure using Aruba and HPE technologies while managing firewalls, VPNs, and security controls.
Headquarters: Remote
URL: https://www.toptal.com/
We're looking for a Network Security Engineer to design, implement, and secure enterprise network infrastructure built on Aruba and HPE technologies. This is a hands-on role spanning both network engineering and security — you'll be responsible for building reliable network architecture while ensuring it's hardened against modern threats. If you can move fluidly between network design and security enforcement, this role is built for that.
Design, configure, and maintain enterprise network infrastructure using Aruba and HPE hardware and platforms
Implement and manage network security controls, including firewalls, VPNs, and access control policies
Monitor network traffic and security events to identify and respond to potential threats
Conduct network security assessments and vulnerability analysis
Design and enforce network segmentation, VLANs, and wireless security architecture
Troubleshoot network performance, connectivity, and security incidents
Maintain documentation for network architecture, configurations, and security policies
Collaborate with IT and security teams to align network infrastructure with broader security standards
Support compliance efforts related to network and IT security requirements
Stay current on emerging network security threats and Aruba/HPE platform capabilities
Strong hands-on experience with Aruba networking and security products
Experience with HP Enterprise (HPE) infrastructure and platforms
Solid background in IT security, including threat identification and mitigation
Strong network engineering skills, including routing, switching, and wireless architecture
Practical experience implementing network security best practices and controls
Ability to troubleshoot complex network and security issues independently
Strong documentation and communication skills for cross-functional collaboration
Relevant certifications (e.g., Aruba Certified, HPE certifications, Security+, CCNA/CCNP Security)
Experience with network access control (NAC) solutions
Familiarity with SIEM tools and security monitoring platforms
Experience supporting compliance frameworks (e.g., PCI-DSS, HIPAA, ISO 27001)
To apply: https://weworkremotely.com/remote-jobs/toptal-network-security-engineer-aruba-hpe-remote