Create an account for powerful AI tools, award-winning courses, and access to our vibrant community.
Already have an account?
Join 250,000+ professionals and teams at Microsoft, Shopify, and even NASA. đ
Already have an account? Login
Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.
1 What roles are you open to?
2 Experience level
3 Work style
Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.
Category
DevSecOps engineer integrates security practices into development and deployment pipelines for Army contracting systems.
Partners with enterprise stakeholders to translate privacy, security, and AI compliance requirements into operational controls and governance processes.
Triages and validates security vulnerability submissions from researchers, communicates with clients and researchers, and escalates critical security incidents for bug bounty programs.
We are Bugcrowd. Since 2012, weâve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platformâ˘. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch⢠technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the worldâs biggest companiesâ bug bounty programs. Here are just a few of the reasons why we are the best:
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowdâs clients or researchers when additional information is required. ASEs also handle Incident Response â escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Culture
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowdâs Privacy Policy, which you may review here:Â https://www.bugcrowd.com/privacy.
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:Â https://www.bugcrowd.com/about/careers/
Triages and validates security vulnerability submissions from researchers, assesses severity, and communicates with clients and security teams on bug bounty programs.
We are Bugcrowd. Since 2012, weâve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platformâ˘. Our network of hackers brings diverse expertise to uncover hidden weaknesses, adapting swiftly to evolving threats, even against zero-day exploits. With unmatched scalability and adaptability, our data and AI-driven CrowdMatch⢠technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd, visit www.bugcrowd.com. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst, Rally Ventures, Costanoa Ventures, and others.
Job Summary
At Bugcrowd, we handle application security assessment at an epic scale. As an Application Security Engineer (ASE) you will curate and manage the incoming security vulnerability submissions to some of the worldâs biggest companiesâ bug bounty programs. Here are just a few of the reasons why we are the best:
Essential Duties & Responsibilities
An ASE is responsible for the ongoing triage and validation services of Bugcrowd managed programs. Under the direction of the Director of Technical Operations, you will take incoming submission data and curate it for validity, accuracy, and severity as well as communicate directly with Bugcrowdâs clients or researchers when additional information is required. ASEs also handle Incident Response â escalating and communicating about the highest severity bugs to clients. ASEs need to have strong knowledge of OWASP Top Ten type vulnerabilities. They also usually require a strong skill set in one scripting/development language, often to assist with the design or development of tooling for improving the triage/validation process. The ASE position is perfect for security professionals looking to take their skills to the next level.
Education, Experience, Skills, & Abilities
Working Conditions
The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
Sitting and/or standing - Must be able to remain in a stationary position 50% of the time
Carrying and /or lifting - Must be able to carry / move laptop as needed throughout the work day.
Environment - remote, work-from-home 100% of the time.
ADA Statement
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ada@bugcrowd.com.
Culture
At Bugcrowd, we are solving security threats and vulnerabilities that are relevant to everyone, therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.
Disclaimer
This position has access to highly confidential, sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.
The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).
Background checks may include Social Security verification, prior employment verification, personal and professional references, educational verification, and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required bylaw.
Any personal data you submit in connection with your application will be processed in compliance with Bugcrowdâs Privacy Policy, which you may review here:Â https://www.bugcrowd.com/privacy.
Equal Employment Opportunity:
Bugcrowd is EOE, Disability/Age Employer.
Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.
Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact HR at ADA at bugcrowd.com.
Apply at:Â https://www.bugcrowd.com/about/careers/
Builds automation, orchestration, and AI-driven detection and response capabilities for the organization's security operations.
Monitors security alerts, investigates incidents, and responds to threats within the SOC environment.
Monitor and respond to security alerts, provide technical guidance to clients, manage vulnerabilities, and maintain security infrastructure across applications and infrastructure.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers.âŻOur unique âAssess, Design, Protectâ methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. Thatâs why customers trust Avertium to deliver better security, improved compliance, and greater ROI.
The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network. The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives. The CS Analyst will provide security analytics and assistance with security support requests.
In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.
Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Security engineer embedded in an AI platform company who conducts threat modeling, designs secure architectures, and builds automated security controls for enterprise AI systems.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (US Full-time employees)
Generous PTO, plus company holidays
Medical, dental, and vision coverage for you and your family
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Flexible spending account and dependent FSA options
Health savings account for eligible plans with company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation, company stock options and 401k
WRITER is an equal-opportunity employer and is committed to diversity. We donât make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
By submitting your application on the application page, you acknowledge and agree to WRITERâs Global Candidate Privacy Notice.
Builds security foundations for enterprise AI systems by conducting threat modeling, designing secure architectures, and embedding security controls across the platform.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our London office, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (UK full-time employees):
Generous PTO, plus company holidays
Comprehensive medical and dental insurance
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Competitive pension scheme and company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation and company stock options
Directs cybersecurity strategy, GRC program, and security infrastructure while overseeing risk management, compliance, and cross-functional security initiatives across the organization.
Business Wire, a Berkshire Hathaway company, is the global market leader in press release distribution and regulatory disclosure. We are on a mission to redefine how organizations connect with their audiences - and thatâs just the beginning!
Organizations, large and small, depend on us to accurately publicize market-moving news and multimedia, and generate social engagements that develop interactions with their target audiences.
About the Role
The Cybersecurity Director is responsible for providing strategic leadership across Business Wireâs cybersecurity function, providing strategy, overseeing security architecture and infrastructure, guiding cybersecurity-related risk decisions across the organization, and advancing and managing a comprehensive Governance, Risk, and Compliance (GRC) program.
This role works collaboratively with all areas of the business to ensure that we maintain a robust and highly effective Information Security program for our existing solutions while also supporting the buildout of new client solutions hosted in our data centers and the cloud. This role provides oversight of our external cyber defense partner and drives efforts in cloud security, application security, identity and access strategies, Zero Trust, vulnerability management, email security, data protection, privacy requirements, and emerging technology risksâincluding AI.
This role is additionally responsible for establishing a robust security governance framework, ensuring compliance with internal and external audit requirements, fostering a security-first culture across the organization, and collaborating with cross-functional teams to integrate risk management practices into all business operations.
What Youâll Do
What Youâll Need
Business Wire will not sponsor a new applicant for employment authorization for this position.
What We Offer
The base salary range for this position is $230K to $245K/year. Offered salary will be determined by several factors, including but not limited to: applicantâs education, experience, knowledge, skills and abilities, as well as internal equity and alignment with geographic market data. Business Wire reserves the right to modify this salary range at any time.
Business Wireâs total rewards include:
A pre-employment background check will be required after the acceptance of an offer. Business Wire is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Business Wire will also consider for employment qualified applicants with arrest and conviction records.
CyberSecurity Analyst monitors SIEM alerts, responds to security incidents, provides technical guidance to clients, and maintains security measures across applications, web, and infrastructure.
Avertium is a cyber fusion and MXDR leader, delivering comprehensive security and compliance services to mid-market and enterprise customers.âŻOur unique âAssess, Design, Protectâ methodology addresses and improves security strategy, reduces attack surface risk, strengthens compliance, and provides continuous threat protection. Avertium maximizes customer security investments and enables customers to focus on growth, innovation, and business outcomes, while assuring that their security infrastructure is resilient and adaptive to evolving threats. Thatâs why customers trust Avertium to deliver better security, improved compliance, and greater ROI.
The CyberSecurity Analyst is a trusted technical advisor working with an active Center of Excellence. The CS Analyst works closely with the client to provide proactive support assistance to reduce or prevent security issues from occurring on the client network. The CS Analyst will administer and maintain security measures focused on application, web and infrastructure security for the client. The CS Analyst is responsible for working with key client contacts at multiple levels of the organization to identify and align business and IT Security objectives. The CS Analyst will provide security analytics and assistance with security support requests.
In addition to a career in the challenging world of cyber security, Avertium offers competitive salaries, full benefits, unlimited paid time off, participation in 401(k), and opportunities for professional growth and development. We offer the opportunity to work with cutting-edge security technologies in a stimulating work environment.
Avertium provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Builds application security foundations for enterprise AI systems, conducting threat modeling, designing secure architectures, and embedding security controls across the platform.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our New York City, San Francisco, or Seattle offices, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
Minimum 4 years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (US Full-time employees)
Generous PTO, plus company holidays
Medical, dental, and vision coverage for you and your family
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Flexible spending account and dependent FSA options
Health savings account for eligible plans with company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation, company stock options and 401k
WRITER is an equal-opportunity employer and is committed to diversity. We donât make hiring or employment decisions based on race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other basis protected by applicable local, state or federal law. Under the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
By submitting your application on the application page, you acknowledge and agree to WRITERâs Global Candidate Privacy Notice.
Security engineer builds and maintains application security controls, threat models AI systems, and embeds security practices across the enterprise AI platform.
WRITER is where the worldâs leading enterprises orchestrate AI-powered work. Our vision is to expand human capacity through superintelligence. And weâre proving itâs possible â through powerful, trustworthy AI that unites IT and business teams together to unlock enterprise-wide transformation. With WRITERâs end-to-end platform, hundreds of companies like Mars, Marriott, Uber, and Vanguard are building and deploying AI agents that are grounded in their companyâs data and fueled by WRITERâs enterprise-grade LLMs. Valued at $1.9B and backed by industry-leading investors including Premji Invest, Radical Ventures, and ICONIQ Growth, WRITER is rapidly cementing its position as the leader in enterprise generative AI.
Founded in 2020 with office hubs in San Francisco, New York City, Seattle, Austin, Chicago, and London, our team thinks big and moves fast, and weâre looking for smart, hardworking builders and scalers to join us on our journey to create a better future of work with AI.
This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, youâll be building the security foundations that protect the AI systems powering some of the worldâs most recognizable brands. Youâll work at the intersection of application security, AI infrastructure, and developer enablementâpartnering with engineering teams to embed security into every line of code while ensuring our platform remains both powerful and trustworthy.
The opportunity is massive: youâll help define how enterprise AI applications are secured, from threat modeling our LLM architectures to building automated security controls that scale across our growing platform. This isnât about saying ânoââitâs about finding creative ways to say âyes, and hereâs how we do it securely.â Youâll tackle challenges that most security engineers never encounter: securing AI agents, protecting training data pipelines, and designing controls for systems that didnât exist a few years ago.
This role is hybrid from our London office, reporting to the head of security engineering.
Build security into the DNA of our AI platform by conducting threat modeling sessions with product teams, designing secure architectures for new features, and ensuring security considerations shape product decisions from day oneânot after the fact
Own and evolve our application security program including establish and maintain SAST/DAST scanning in CI/CD pipelines, conducting security code reviews for critical changes, and building automation that catches vulnerabilities before they reach production
Partner with engineering teams to establish and champion secure coding standards, creating reusable security patterns and libraries that make it easier for developers to build securely by default
Design and recommend security features and products that help secure customer environments. You are the advocate and the vision for how we protect and secure customers..
Integrate and leverage AI agents to help increase velocity for the security team and the overarching engineering org to ensure that we are proactive in minimizing risk while we build products
Lead security assessments and penetration testing of WRITERâs applications, AI services, and APIs, identifying vulnerabilities across our tech stack and working collaboratively with teams to remediate issues at scale
Design and implement security controls for protecting data pipelines, model training environments, and customer-facing AI agents
Stay ahead of emerging threats in the AI/ML security landscape, researching attack vectors specific to LLMs and generative AI, and proactively building defenses against novel risks
4+ years of hands-on experience in application security engineering, with a proven track record of securing large-scale production systemsâbonus points if youâve worked in fast-growing startups or high-growth environments
Understanding of developer experience and developer workflows for shipping features and products. You care deeply about reducing risk while considering velocity of engineers.
Technical expertise in at least two programming languages (Python, Java, Go, JavaScript/TypeScript) and the ability to read and review code across multiple languages, understanding both business logic and security implications
Knowledge of security tools and methodologies including SAST/DAST solutions, vulnerability management platforms, security testing frameworks, and DevSecOps practicesâyou know which tools to use and when automation beats manual review
Excellent communication skills that allow you to translate complex security concepts into clear recommendations for both technical and non-technical audiencesâyou can explain why something matters and motivate teams to action
A builderâs mindset that looks for opportunities to automate, scale, and empower rather than create bottlenecksâyou understand that security enables the business, not blocks it
Alignment with WRITERâs values of Connect (building strong relationships across teams), Challenge (pushing the boundaries of whatâs possible in AI security), and Own (taking end-to-end responsibility for the security of our platform)
đŠ Benefits & perks (UK full-time employees):
Generous PTO, plus company holidays
Comprehensive medical and dental insurance
Paid parental leave for all parents (16 weeks)
Fertility and family planning support
Early-detection cancer testing through Galleri
Competitive pension scheme and company contribution
Annual work-life stipends for:
Wellness stipend for gym, massage/chiropractor, personal training, etc.
Learning and development stipend
Company-wide off-sites and team off-sites
Competitive compensation and company stock options
Designs and implements application security strategies, conducts threat assessments, and leads security architecture initiatives to protect company systems and data.
Leads financial crimes prevention and compliance strategy for an AI-native banking platform serving business owners.
Senior Security Consultant advises organizations on vulnerability management and exposure reduction strategies using Tenable's security platform.
Builds and leads a security engineering team, designs the security program, makes technical decisions, and manages hiring while staying hands-on with security implementation.
OUR ORIGIN STORY đ
In 2011 SkySlope started as an idea born at the kitchen table of our CEO, with just him and two others. Headquartered in Sacramento, California, we have since grown out of our previous 3 offices and many of our close to 150 employees are spread all across the United States. Those 150 employees support close to 300,000 users across 5,000 offices nationwide and now in Canada as well. Included in that is 8 out of the 15 largest Real Estate Brokerages in the nation.
But, despite being happy with what weâve achieved we know that as industry leaders in our space thereâs a lot of work left to be done. All of the growth and success that has happened is a result of us obsessing over building cutting edge software that makes the Real Estate world a better place. We know this only happens by hiring people who donât just come up with out of the box ideas but hiring people who actually see those ideas through and bring them to life. As weâve grown, weâve been fortunate enough to hire plenty of people who possess that quality and realize itâs equally important to hire people who can pair that skill with empathy, collaboration, and a keen sense of urgency. If youâre looking to join a company where you can have real impact and surround yourself with an incredible team of people then look no further.
SKYSLOPEâS CORE VALUES đŞđť
These are the principles that helped us get to where we are and they are the principles that will guide us to where we want to go in the future. You can apply them to your professional life, your personal life, to any business and any situation. In no specific hierarchy, our core values are:
Awareness | Execution | Obsession | Ownership | Humility | Radical Candor | Urgency | Greatness | Inches I Fun
Learn more about our core values from our CEO, Tyler Smith here!
Purpose: The purpose of the Security Engineering Manager is to build and lead SkySlopeâs dedicated security engineering team in pursuit of making life better for every real estate agent, broker and service provider. This is a player-coach role: they will design the security engineering program, own its execution, hire and grow the team that delivers it, and stay hands-on in the technical work throughout. SkySlope is making a significant, sustained investment in security engineering, and this role is the foundation of that investment.
Why This Role: This is a genuine greenfield leadership opportunity. You are not inheriting someone elseâs program, tooling decisions, or org chart. You will design the program, pick the tools, hire the team, and set the standards, with direct executive sponsorship and a Director of Engineering who currently leads the security function and is invested in your success. SkySlope is also an aggressively pro-AI engineering organization: we treat AI as a security force multiplier for review, triage, and detection engineering, operating within guardrails you will help define. If you want to build a modern security program from first principles, with AI in the toolbox rather than on the threat slide, this is that role.
Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Responsible for designing and executing SkySlopeâs security engineering program.
Own the security roadmap across its major domains: identity and credential standards (short-lived, machine-identity-based credentials and OIDC federation), least-privilege authorization, secrets management, managed-device standards, attack-surface governance, secure SDLC (commit signing and org-wide SAST, dependency and secret scanning), centralized logging and detection, vulnerability disclosure, and AI governance.
Sequence and prioritize the program pragmatically, targeting the highest risk reduction per unit of engineering effort first.
Own the security-debt register: maintain security work as a visible, prioritized engineering backlog rather than an audit artifact.
Own security tooling and vendor decisions, including evaluation, selection, and build-vs-buy judgment.
Deliver clear, honest executive reporting on program status, risk posture, and progress.
Responsible for hands-on technical leadership (player-coach).
Lead and participate directly in architecture and design reviews for security-relevant work.
Contribute hands-on where it matters most: proofs of concept, detection logic, automation, and reviews.
Set and uphold the technical bar for security engineering work across the team.
Responsible for hiring and growing the security team.
Hire security engineers across levels and build an effective, collaborative team.
Coach and mentor each direct report through personal and performance management, including growing an early-career engineer into a strong contributor.
Build a team culture where security work is engineering work: shipped, measured, and iterated.
Responsible for partnering across the organization.
Work with DevOps, IT, and product engineering teams to embed security standards into how work already gets done â paved roads over gates.
Communicate early and often, building trust between security and the rest of engineering.
Ensure security guidance is concrete and actionable, not theoretical.
Responsible for making AI a security force multiplier.
Apply AI tooling to security review, triage, and detection engineering, and define the guardrails under which it operates.
Shape SkySlopeâs AI governance standards in partnership with engineering leadership.
Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.
Security program milestones defined, communicated, and delivered
Security-debt register established and demonstrably burning down
Team hired, retained, and growing (manager and peer observations)
Quality and clarity of executive reporting
Strong senior/staff-level individual contributor background in security engineering, infrastructure engineering, or platform engineering; you have personally built the kinds of systems you will now lead
Demonstrated ability to design and drive a security program or comparable cross-cutting technical initiative from ambiguity to delivery
Working depth in modern cloud security practice: cloud IAM, credential federation, secrets management, secure SDLC, and detection/logging (we run multi-cloud: primarily AWS, a growing GCP footprint, and a small amount of Azure; depth in one cloud and fluency across the rest is fine)
Strong coaching and mentoring skills, with a track record of growing engineers, including those early in their careers
Sound judgment on tooling and vendor decisions, including knowing when to build and when to buy
Clear, direct communicator with executives and with engineers, in writing and in person
Enthusiasm for using AI as a working tool in security engineering; we want practitioners who are energized by this, not skeptical of it
Pragmatism: bias toward risk reduction that ships over frameworks that impress
We care about demonstrated ability, not certifications or credentials. If youâve built and led this kind of work, we want to talk to you regardless of which letters follow your name.
This position has 2-4 direct reports, including security engineers at multiple levels.
$180,000 - $200,000 a year
Medical Insurance â Company pays flat dollar amount towards premium
There are 3 plan options
Our Medical Insurance plans are provided through United Healthcare
The United Healthcare HMO is only offered to California residents
Eligibility begins 1st of the month following date of hire
Per Paycheck (24 pay periods a year)
Employee costs per tier are as follows:
UHC HDHP/HSA
Employee Only $58.92
Employee + Child $147.30
Employee + Spouse $175.78
Employee + Family $259.24
UHC PPO
Employee Only $104.10
Employee + Child $244.63
Employee + Spouse $289.91
Employee + Family $422.63
UHC HMO (CA residents only)
Employee Only $84.56
Employee + Child $198.71
Employee + Spouse $235.49
Employee + Family $343.29
Dental Insurance â Company pays 75% of monthly premium only on Base Plan
This PPO plan is administered through Principal
Eligibility begins 1st of the month following date of hire
Principal Dental Base Plan
Employee Only $4.19
Employee + Child $11.73
Employee + Spouse $8.50
Employee + Family $17.20
Principal Dental Buy-Up Plan
Employee Only $6.65
Employee + Child $19.53
Employee + Spouse $13.51
Employee + Family $28.35
Vision Insurance â Company pays 100% of monthly premium
This plan is administered through Principal (VSP choice network)
Eligibility begins 1st of the month following date of hire
Basic Life and AD&D Insurance (with additional Voluntary Plans available) â Company paid plan with a guarantee issue amount of $25,000.
Plan is administered through Principal
Eligibility begins 1st of the month following date of hire
Pricing varies for additional coverage, based upon age, coverage and dependent classification
Voluntary Short & Long Term Disability Insurance Plans â Optional plans to help protect your financial well-being.
Plan is administered through Principal
Eligibility begins 1st of the month following date of hire
Pricing varies, based upon age
Voluntary Accident insurance- Optional plans available to purchase that pays you a cash benefit to help with your expenses if you or a covered family member is injured due to an accident.
Employee Only $4.39
Employee + Spouse $6.73
Employee + Child(ren) $7.49
Employee + Family $11.50
Voluntary Hospital Indemnity- Optional plans available to purchase that pays you a cash benefit to help with your expenses if you or a covered family member is admitted to the hospital
Employee Only $6.85
Employee + Spouse $17.43
Employee + Child(ren) $11.41
Employee + Family $22.84
Voluntary Critical Illness- Optional plans available to purchase to help with your expenses if you or a covered family member is diagnosed with a covered critical illness.
Pricing varies, based upon age
Flexible Spending Account â A tax savings account you put money into that you use to pay for certain out-of-pocket health care and dependent care costs.
Plan is administered through Discovery Benefits
Eligibility begins 1st of the month following date of hire, if you sign up by the 25th of the month
Health Savings Account (HSA)â A tax savings account for employees enrolled in a High Deductible Health Plan. You can put money into this account to pay for certain out-of-pocket health care costs
Plan is administered through Discovery Benefits
Eligibility begins 1st of the month following date of hire, if you sign up by the 25th of the month
Must be enrolled in the UHC HDHP/HSA medical plan with SkySlope to be eligible
SkySlope contributes $300 to an individual HSA and $600 to a family HSA
401(k) Plan â Company will match $0.50 on each $1.00 contributed up to the first 6% of eligible earnings
Plan is administered through Principal
Eligibility begins first pay date after 90 days of employment
Auto-enrollment after eligibility at 3% of gross annual earnings
Defer between 1% and 40% of eligible contribution
Employee Stock Purchase Plan - Company match equal to 33.3333% of dollars contributed to the plan, based upon the average purchase price for the quarter.
Plan administered through Fidelity
Eligibility begins first pay date after 90 days of employment
May contribute after-tax dollars from 3% to 15% of base earnings
Paid Time Off (PTO) â Company provides 120 hours (equivalent of 15 days) of PTO for new hires
PTO accrual begins after 90 days of employment
16 Paid Holidays
11 observed, 5 floating (used for personal holidays)
List of observed holidays published annually
Eligibility begins on your first day of employment
Bereavement Leave â Company will provide you with the following off to grieve the loss of a loved one.
5 paid days of leave for an immediate family member. This is a spouse, child, parent, grandparent.
1 paid day of leave for a close non-family member.
Discounts through Fidelity - Purchasing discounts for wireless, car rentals, hotels and moreâŚ
Pet Insurance through Nationwide- 50%, 70% reimbursement plans available through Nationwide with options for wellness. SkySlope contributes $20 a month, per pet, up to 2 pets towards the cost of the plan
Paid Parental Leave - All full-time regular employees are eligible for SkySlopeâs Paid Parental Leave program, which provides employees with up to six (6) weeks of pay following the birth or placement of a new child. Paid Parental Leave must be taken within the first 6 months of the birth or placement of a new child. Employees will be paid at their regular rate of pay based upon their normal work schedule, up to a maximum of forty (40) hours per week.
Dayforce Wallet- All full-time regular employees will have access to sign up for Dayforce Wallet. Dayforce Wallet is a program provided by our payroll provider that allows employees to access their pay on-demand as soon as it is earned, without waiting for their standard payday.
Waldorf University discounts and perks- 10% off tuition for employees and their families, free text books, and scholarship opportunities available
Child Literacy Assistance Program discount- Discounted annual membership to Luminous Minds, an online resource center created to help with child literacy struggles. $85 for 1 year membership as a SkySlope Employee.
$1,000 Employee Referral bonuses- SkySlope will give every referrer $1,000 (post-tax) after a referee passes their 90 day mark.
In addition to the above you also receive other perks like our Annual Employee Appreciation Day and additional internal company events.
SkySlope, is an Equal Opportunity employer. All qualified applicants will receive
consideration for employment without regard to race, color, religion, sex, age, disability, protected veteran status,
national origin, sexual orientation, gender identity or expression (including transgender status), genetic
information or any other characteristic protected by applicable law.
We sincerely thank you for taking the time to review our open positions and hope youâll take the time to submit a concise and thoughtful application.
Still thinking about applying? Waiting to hear back from us? Check out our social media in the meantime!
SkySlope | Facebook | Instagram | YouTube | LinkedIn | Twitter
Your privacy is important to us. Learn more about what data is collected and how we use it here.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Designs and implements security detection systems and incident response procedures to identify and mitigate threats.
Analyzes and manages security threats and vulnerabilities using the HackerOne platform and community of security researchers.
Develops and implements security measures to protect applications from vulnerabilities and threats.