Remote Dev Jobs
21 jobs available

ToptalRemote2d ago
Headquarters: Summary We are seeking an elite, hands-on Senior Security Compliance Consultant (SOC 2 & GRC Specialist) to lead a critical, company-wide SOC 2 Type II audit readiness initiative. In this strategic engagement, you will perform comprehensive gap analyses, assess existing security controls, design robust compliance workflows, and drive cross-functional teams toward audit completion. The ideal candidate brings a proven track record in GRC frameworks, control mapping, evidence automation, and policy development. Utilizing automated compliance platforms such as Sprinto, you will build repeatable compliance processes, validate technical controls, and ensure a seamless audit experience across the entire organization. General Information (About the Client) Our client is a fast-scaling, cloud-native technology platform committed to maintaining enterprise-grade trust, security, and data privacy. To support their rapid commercial growth and enterprise sales pipeline, they are establishing a formal, highly disciplined security governance model. They operate a modern, cloud-first environment where compliance is treated not as a passive checklist, but as an active, automated operational advantage. By leveraging modern GRC platforms and fostering a security-conscious culture, they provide an empowering environment for compliance experts to drive real architectural and procedural improvements. Tasks and Deliverables SOC 2 Readiness & Gap Analysis: Conduct a thorough assessment of existing technical and operational security controls, pinpointing compliance gaps and building an actionable remediation roadmap. Control Design & Implementation: Author, refine, and operationalize security controls, policies, and procedures aligned with SOC 2 Trust Services Criteria (TSC) and PCI DSS standards. Automated Evidence Collection: Lead evidence-gathering workflows using automated GRC tooling (Sprinto), ensuring all technical artifacts, access logs, and policy attestations are vali
ExpelRemote1w ago
Headquarters: Remote Are you a detection engineer who wants to bring real depth of expertise into a new and growing function and use it to deliver security excellence to customers? Expel's professional services practice is just getting started, and we're looking for the technical expert who'll deliver the work that gets customers ready to thrive under our co-managed SIEM model. You'll bring hands-on skill to a team that's finding its stride, help it grow, and have a real runway to grow into a lead yourself. Here's the work. Customers come to us with SIEMs that should be surfacing threats but are instead consuming their teams: ingestion costs climbing year over year, engineers buried in alert noise and broken pipelines, and detection blind spots leaving real gaps. You're the engineer who turns that around: authoring and tuning detection content that satisfies real security use cases, closing coverage gaps, migrating detection logic off legacy platforms, and helping optimize what customers ingest and pay for, so their SIEM becomes a force multiplier again, not a management burden. And because this function evolves right alongside our customers and the market, the work won't stand still. Expect it to grow into deeper integrations, automated and AI-assisted tooling, and security strategies our customers need next. What Expel can do for you Give you a ground-floor seat in a new professional services function, where your expertise directly shapes the quality of what we deliver to customers Provide real runway for professional development as the function grows Put you on complex, high-stakes detection and SIEM problems across a wide range of customer environments Let you work across leading SIEM platforms, including Splunk, Microsoft Sentinel, and CrowdStrike NG SIEM, plus emerging AI-assisted tooling Give you visibility and partnership across the organization, including Sales, Detection Engineering, our SOC, and Customer Success Accelerate your career by letting you own m
StratEdge It consulting INC · 🇺🇸 United StatesRemote1w ago
Title: Remote Mainframe Security Engineer with strong expertise in CA Top Secret (TSS) Location: REMOTE Duration: 12 Months Contract Client: IBM Rate: $60/hr on C2C Visa: Native Video Interviews Manager Notes We are looking someone with a little deeper knowledge such as Reporting to SIM/Soc, MFA and SSO experience and some ICSF skills. However, they can be learned with the right guidance. The customer is also looking for AS 400 skills handling the QSECOFR role. Plus point- Those who can speak S…
HuntressRemote1w ago
Headquarters: Remote Ireland Reports to: Director, Security Operations Center Location: Remote Ireland Compensation Range: €115,200 to €133,000 base plus bonus and equity What We Do: Cybercrime is growing, and more businesses are getting hit by threats that used to target only the biggest organizations. That pushes defenders like us to operate at the highest level, and it deepens our need for good people who want to make a meaningful impact. Founded in 2015 by former NSA cyber operators, Huntress is a remote-first team working to make enterprise-grade cybersecurity accessible to businesses of all sizes. We work closely with security teams and service providers protecting complex environments, often without the time or headcount to handle it all. That’s why we build our technology in-house and back it with a 24/7 human-led Security Operations Center (SOC). As a result, our platform is never disconnected from the experts who manage it, ensuring our customers' protection. Huntress now secures more than 5M endpoints and 14M identities worldwide. Those numbers keep growing because more businesses rely on us to help carry the load and operate with more confidence. Every day, you can see that commitment in how we stand with our customers and how we show up for each other. What You’ll Do: The Huntress Security Operations Center is a global team of security analysts dedicated to investigating and responding to incidents on our partners’ networks 24/7, 365 days a year. Daily activities consist of providing investigation, containment, and response actions across millions of endpoints. This role is accountable for defining and streamlining processes, workflows, and playbooks that enable effective day-to-day operations. As Huntress continues to grow, we are laser-focused on scaling our operations and force-multiplying our human analysts by 10X. This position is responsible for enabling analysts to meet our mission and achieve internal Service Level Objectives for response times.

ToptalRemote1mo ago
Headquarters: Remote URL: https://www.toptal.com/ About the Role We're looking for a DevOps Engineer to design, build, and maintain secure, scalable cloud environments for a growing organization expanding its cloud capabilities. You'll take ownership of infrastructure-as-code practices, deployment automation, and environment stability across development, staging, and production — working closely with engineering teams to keep everything running smoothly, securely, and cost-effectively. This is a hands-on opportunity to shape core cloud infrastructure with direct, visible impact on engineering velocity and platform reliability. What You'll Do Design, build, and maintain scalable cloud infrastructure using Terraform and AWS Automate deployment processes and optimize existing CI/CD pipelines Collaborate with development teams to provision, configure, and troubleshoot development, staging, and production environments Monitor infrastructure performance, manage access and security policies, and implement cloud cost optimization best practices What You Bring Strong hands-on experience with AWS core services, including EC2, S3, VPC, IAM, RDS, and EKS/ECS Deep expertise in Infrastructure as Code using Terraform Proficiency with CI/CD tools such as GitHub Actions, GitLab CI, or Jenkins Solid experience with containerization technologies, including Docker and Kubernetes Familiarity with scripting languages such as Bash or Python for operational automation Understanding of networking, security best practices, and monitoring tools such as Datadog, Prometheus, or Grafana Nice to Have Experience supporting multiple engineering teams across parallel environments Background in cost optimization or FinOps practices for cloud infrastructure Exposure to compliance or security frameworks relevant to cloud environments (e.g., SOC 2, HIPAA) To apply: https://weworkremotely.com/remote-jobs/toptal-devops-engineer-python
Primer.io · 🇬🇧 United KingdomRemote57y ago
An Introduction to Primer Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform. Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we're building the payments layer the world's best companies rely on. Watch our showcase > Read up on our $100m Series C Learn more about our culture > Primer is looking for a Security Engineer to help us detect, investigate, and respond to threats across our cloud infrastructure. You'll take ownership of a meaningful slice of our detection and response capability — tuning what our SIEM catches, building the automation that speeds up how we react, and being a first responder when something looks wrong. What you'll be doing Plan and deliver detection and response work end-to-end — from a new detection rule to a fully automated response — within your area of ownership. Build, tune and maintain detections across our SIEM (Elastic) and AWS environment, closing gaps that existing coverage misses. Own an investigation queue: triage, investigate, escalate and resolve security incidents, and write up findings clearly enough to stand on their own. Build runbooks and automations (Python, and no-code tools like Zapier or Tines) to cut manual work out of triage and response. Make and document risk decisions in your area, and know when to pull in others. Support our compliance programme by keeping the controls you own audit-ready and contributing evidence for audits (e.g. SOC 2, PCI DSS). Use Terraform and Python to build and maintain the infrastructure behind your detections and tooling. Join our on-call rotation for incident response and monitoring. What we're looking for Hands-on experience building and tuning detections in a SIEM (Elastic preferred; Splunk, Sentinel or similar also welcome) Experience with AWS and cloud-native detection and response Comfortable
Eraneos · 🇩🇪 Hamburg, GermanyRemote57y ago
What you can expect from us We are the cybersecurity experts of the globally operating Eraneos group based in Germany. We primarily advise DAX and Fortune 500 companies on cybersecurity topics such as OT security, risk assessment or compliance. We offer prospective employees an international work environment with a highly agile team and creative start-up methods and an attractive payment package. As Principal Cybersecurity (all genders), you will take entrepreneurial responsibility for the growth and development of our Cybersecurity business: Develop and execute a growth strategy for Cybersecurity consulting and services Identify and acquire new key accounts while expanding existing client relationships Position our Cybersecurity offerings in the market and help shape our portfolio (e.g., Security Strategy, Governance, Risk & Compliance, Cloud Security, SOC & MDR, OT/IoT Security) Lead complex proposal processes (RFI/RFP), including proposal development, pricing strategy, and contract negotiations at C-level Collaborate closely with the Cybersecurity Leadership Team and other consulting practices to develop integrated service offerings Build and maintain strategic partnerships with technology vendors, resellers, and ecosystem partners Represent the company at industry events, conferences, and relevant committees You act as a trusted advisor to our clients, combining strategic consulting expertise with a strong commercial mindset. Who you are You hold an outstanding university degree, ideally in the STEM field You have extensive experience (10+ years) in Cybersecurity, ideally in consulting or a comparable role with a strong business development focus You have a proven track record in building and growing client accounts, as well as selling complex Cybersecurity services and solutions You possess strong knowledge of the Cybersecurity market, including threat landscapes, regulations, technologies, and vendor ecosystems, as well as the needs of large enterprises and mi
Localstack · 🇬🇧 United KingdomRemote57y ago
LocalStack - the Local Cloud Sandbox for Developers and AI Agents We are a fast-growing Series A startup building cutting-edge technology to revolutionize cloud development processes and support highly efficient dev&test feedback loops. We’ve closed our last $25mil round in Q4 2024, led by Notable Capital , CRV and Heavybit . LocalStack is a local cloud development platform. LocalStack makes it easier, faster, and less expensive for software teams to ship reliable, high-quality applications to the cloud. The cloud was built to run software, not to support AI-native development workflows. As the world's leading local cloud development platform, LocalStack provides secure local sandboxes that simulate cloud environments, enabling AI agents and software developers to find and fix risks faster and more effectively than they can in the cloud. Our customer base ranges from SMBs to Global Fortune 500 companies. Our clients include companies like NASA, Harness, IBM, Workday, Comcast, Apple, 3M, Block and many more. We are sustainably growing our globally distributed teams across GTM, operations and engineering. In 2025 we almost doubled in size and continue to grow across all areas in 2026. LocalStack is headquartered in Zurich/Switzerland 🇨🇭, with a small engineering office in Vienna/Austria 🇦🇹 and remote team members from 25 countries including 🇺🇸the US, 🇫🇷FR, 🇬🇧UK, 🇨🇦CA, 🇪🇸ES, and many more! 👉Check our Notion Candidate Handbook and our GitHub ! ✅ What you will be working on/responsible for Own the internal cloud infrastructure and serve as the primary point of contact for cloud operations and infrastructure requests. Manage and continuously improve our multi-account cloud environment, ensuring security, governance, and compliance best practices are consistently applied. Support and maintain compliance with SOC 2 Type II and ISO 27001 , ensuring audit evidence is prepared continuously rather than only during audit periods. Operate and improve our identity a
Constructor · Remote - EMEARemote57y ago
About You As Director of Information Security, you will own Constructor's security program end-to-end — protecting our platform, our customers' data, and our team. You'll report to the CIO and serve as the company's senior security leader, responsible for everything from compliance frameworks and incident response to hands-on prospect engagements and internal policy. This is a high-autonomy role where you'll shape strategy and execute it yourself in a lean, engineering-driven organization. About Us Constructor is the only search and product discovery platform tailor-made for enterprise ecommerce where conversions matter. Constructor's AI-first solutions make it easier for shoppers to discover products they want to buy and for ecommerce teams to deliver highly personalized experiences that drive impressive results. Optimizing specifically for ecommerce metrics like revenue, conversion rate and profit, Constructor generates consistent $10M+ lifts for some of the biggest brands in ecommerce, such as Sephora, Petco, home24, Maxeda Brands, Birkenstock and The Very Group. Constructor is a U.S. based company that was founded in 2015 by Eli Finkelshteyn and Dan McCormick. About the Position The Director of Information Security’s responsibilities will include: Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board Access governance — Run quarterly access reviews across all systems; ensure least-priv
APT-ONE GmbH · 🇩🇪 Berlin, GermanyRemote57y ago
Die APT-ONE GmbH in Berlin ist ein auf Cyber Security spezialisiertes Beratungshaus. Wir schützen die IT-, OT-, Cloud- und KI-Systeme unserer Kunden wirksam vor digitalen Bedrohungen. Unser Ansatz ist anders: KI-gestützte Werkzeuge übernehmen Discovery, Routine-Analysen und Mustererkennung – unsere Berater:innen validieren, interpretieren und konzentrieren sich auf Strategie und maßgeschneiderte Lösungen. Das ergibt tiefere Analysen und belastbare Entscheidungsgrundlagen in kürzerer Zeit, bei 40–60 % weniger Aufwand für Routinearbeit. KI nur mit höchster Sensibilität für Kundendaten: Datenschutz steht über jedem Effizienzgewinn. KI ausschließlich auf vertraglich abgesicherten, datenschutzkonformen Plattformen, minimierte und anonymisierte Daten, niemals Kundendaten im Modelltraining. Diesen Umgang – und die Bereitschaft, unsere Prozesse und Produkte kontinuierlich mit KI weiterzuentwickeln – erwarten wir von allen Berater:innen. Bei uns bist du richtig, wenn: du ein attraktives Fixgehalt plus überdurchschnittliche Gewinnbeteiligung willst. du ortsunabhängig an hochrelevanten Projekten in Security Operations und KI-Sicherheit arbeiten willst. du KI als Hebel siehst und Sicherheitsberatung neu denken willst – ohne Kompromisse beim Datenschutz. du deine Expertise in SOC-Plattformen, Detection Engineering und Automatisierung ausbauen willst. Aufgaben Entwurf und Weiterentwicklung von Sicherheitsarchitekturen über IT-, OT-, Cloud- und KI-Systeme hinweg Design sicherer Cloud- und Hybrid-Architekturen (Azure, AWS, GCP) inkl. Landing Zones, Identity- und Netzwerkdesign, Verschlüsselung und Security Baselines Erstellung von Zielarchitekturen, Security-Roadmaps und Migrationspfaden – insbesondere für Cloud-Transformationen und Multi-Cloud-Szenarien Durchführung von Threat Modeling, Architektur-Reviews und Risikoanalysen für Anwendungen, Netzwerke, Cloud-Workloads und Plattformen Design von Netzwerk- und Perimetersicherheit inkl. Segmentierung, Firewalling und Zero Trust Netwo
APT-ONE GmbH · 🇩🇪 Berlin, GermanyRemote57y ago
Die APT-ONE GmbH in Berlin ist ein auf Cyber Security spezialisiertes Beratungshaus. Wir schützen die IT-, OT-, Cloud- und KI-Systeme unserer Kunden wirksam vor digitalen Bedrohungen. Unser Ansatz ist anders: KI-gestützte Werkzeuge übernehmen Discovery, Routine-Analysen und Mustererkennung – unsere Berater:innen validieren, interpretieren und konzentrieren sich auf Strategie und maßgeschneiderte Lösungen. Das ergibt tiefere Analysen und belastbare Entscheidungsgrundlagen in kürzerer Zeit, bei 40–60 % weniger Aufwand für Routinearbeit. KI nur mit höchster Sensibilität für Kundendaten: Datenschutz steht über jedem Effizienzgewinn. KI ausschließlich auf vertraglich abgesicherten, datenschutzkonformen Plattformen, minimierte und anonymisierte Daten, niemals Kundendaten im Modelltraining. Diesen Umgang – und die Bereitschaft, unsere Prozesse und Produkte kontinuierlich mit KI weiterzuentwickeln – erwarten wir von allen Berater:innen. Schwerpunkt dieser Rolle ist Detection Engineering: SIEM- und XDR-Plattformen, Log-Qualität, Detectionas-Code und Automatisierung – sicher in KQL, Sigma und MITRE ATT&CK. Bei uns bist du richtig, wenn: du ein attraktives Fixgehalt plus überdurchschnittliche Gewinnbeteiligung willst. du ortsunabhängig an hochrelevanten Projekten in Security Operations und KI-Sicherheit arbeiten willst. du KI als Hebel siehst und Sicherheitsberatung neu denken willst – ohne Kompromisse beim Datenschutz. du deine Expertise in SOC-Plattformen, Detection Engineering und Automatisierung ausbauen willst. Aufgaben Aufbau, Betrieb und Weiterentwicklung von SOC-Plattformen (SIEM, SOAR, EDR/XDR) Onboarding neuer Logquellen inklusive Parsing, Normalisierung und Sicherstellung der Datenqualität Entwicklung und Optimierung von Detection-Regeln und Use Cases (Sigma, KQL, SPL) auf Basis von MITRE ATT&CK Automatisierung von Analyse- und Response-Prozessen durch Playbooks und Skripting (Python, PowerShell) Aufbau von Detection-as-Code-Pipelines inkl. Versionierung, Testing un
Pencil · 🇬🇧 United KingdomRemote57y ago
Job Description At Pencil, we are driving innovation in advertising technology through our state-of-the-art SaaS product, which harnesses Generative AI to redefine content creation. Our mission is to make AI the default in advertising without replacing creative people. To achieve this, we need to make sure that our technology isn’t just in the hands of big brands - we need to try to help small businesses and creative individuals too. We're looking for a Security & Trust Specialist to join Pencil at a pivotal moment of growth. This is a hands-on, technical role for someone with a background in desktop support, IT systems administration or a similar technical operations role who is now building a career in security. You'll own the day-to-day security operations that keep Pencil safe — endpoints, identity and access, cloud and SaaS security — and you're happy to lend a hand with practical IT and device issues where needed. You'll work directly with our Head of Security & Trust, who will support your growth into the audit, compliance and vendor-risk side of the role over time. Key responsibilities: Administer and secure endpoints (MDM/Intune, patching, encryption, device compliance), and be willing to pitch in on practical desktop support and device issues when the team needs a hand. Own day-to-day identity and access management — joiner/mover/leaver processes, least-privilege access and quarterly access reviews across Google Workspace, Microsoft 365, GCP and other SaaS tools. Monitor security alerts and logs, escalate promptly, and help investigate and document security events (suspicious logins, compromised credentials, device loss, cloud misconfiguration). Support compliance evidence collection in Vanta for SOC 2, ISO 27001 and ISO 42001, working alongside the Head of Security & Trust rather than owning audit strategy yourself. Help gather evidence for vendor and customer security questionnaires, and flag anything that needs escalating. Identify and implement practic
secupay AG · PulsnitzRemote57y ago
Festanstellung | Vollzeit | Remote | Deutschland Als SOC-Analyst/SIEM Engineer stärken Sie unsere IT-Sicherheit durch wirksames Monitoring, präzise Analysen und die kontinuierliche Weiterentwicklung unserer SIEM- und Security-Monitoring-Landschaft Aufgaben Sie überwachen und analysieren sicherheitsrelevante Ereignisse aus SIEM, EDR, Firewall, Netzwerk, Servern, Cloud-Diensten und weiteren IT-Systemen Sie bewerten und priorisieren Security Alerts nach Kritikalität, Risiko und möglicher Auswirkung auf den Geschäftsbetrieb Sie entwickeln und optimieren Korrelationsregeln, Detection Use Cases, Dashboards und Reports Sie unterstützen bei der Untersuchung, Eindämmung und Nachbearbeitung von IT-Sicherheitsvorfällen Sie dokumentieren Vorfälle, Analyseergebnisse, Entscheidungen und Maßnahmen nachvollziehbar und prüfbar Sie arbeiten eng mit IT-Infrastruktur, IT Operations, Informationssicherheit, Datenschutz und externen Security-Partnern zusammen Sie wirken an Sicherheitsprojekten, Tool-Einführungen und der Weiterentwicklung der Security-Monitoring-Landschaft mit Qualifikation Sie verfügen über mehrjährige Berufserfahrung in IT-Security, Security Operation, SIEM Engineering oder IT-Infrastruktur Sie kennen Security Monitoring, Log-Analyse, SIEM-Betrieb und Incident Detection sehr gut Sie bringen mehrjährige Erfahrung mit FortiSIEM mit Sie kennen idealerweise weitere SIEM- und Security-Tools wie Microsoft Sentinel, Splunk, Elastic, QRadar oder vergleichbare Lösungen Sie verfügen über Kenntnisse in Windows, Linux, Netzwerken, Firewalls, Active Directory, Cloud-Diensten und Endpoint Security Sie entwickeln sich kontinuierlich weiter und bringen die Bereitschaft mit, relevante Schulungen und Zertifizierungen zu absolvieren Sie analysieren komplexe technische Sachverhalte strukturiert, präzise und risikoorientiert Sie arbeiten verantwortungsbewusst, diskret und ruhig in zeitkritischen Situationen Sie verfügen über fließende Deutschkenntnisse und über Englischkenntnisse Benefits V
secupay AG · PulsnitzRemote57y ago
Festanstellung | Vollzeit | Hybrid / Remote mit gelegentlichen Treffen in Pulsnitz Als Informationssicherheitsbeauftragter übernehmen Sie eine zentrale Rolle bei der Weiterentwicklung unseres Informationssicherheitsmanagements und sorgen dafür, dass Sicherheitsanforderungen wirksam, prüfungsfähig und nachvollziehbar umgesetzt werden. Aufgaben Sie steuern und entwickeln das Informationssicherheitsmanagementsystem der secupay AG inklusive Richtlinien, Standards, Verfahren, Rollen und Kontrollrahmen weiter Sie beraten Vorstand, Führungskräfte, Fachbereiche, IT und Security Office/SOC zu Informationssicherheit und sicheren Systemen, Anwendungen, Prozessen und Dienstleistern Sie leiten Sicherheitsanforderungen aus DORA, ZAG-MaRisk, BaFin- und EBA-Vorgaben, DSGVO, ISO/IEC 27001, TISAX und PCI DSS ab und überwachen deren Umsetzung Sie begleiten Audits, Assessments, Managementbewertungen, Zertifizierungen und Prüfungen inklusive prüfungsfähiger Nachweise Sie bewerten Sicherheitsvorfälle, Schwachstellen, Bedrohungen und Testergebnisse und unterstützen Notfallmanagement, Wiederanlauf und digitale operationale Resilienz Sie konzipieren Awareness- und Schulungsmaßnahmen und arbeiten eng mit IKT-Risikomanagement, IT-Compliance, Datenschutz, Auslagerungsmanagement, Revision und weiteren Kontrollfunktionen zusammen Qualifikation Als leidenschaftlicher Sicherheitsexperte kennen Sie die Regelwerke aus dem Effeff und können sie in die Praxis übersetzen. Sie arbeiten selbstständig und eigenverantwortlich, können aber auch andere für gemeinsame Ziele gewinnen und begeistern. Sie bringen mehrjährige relevante Berufserfahrung im Bereich Informationssicherheit mit Sie verfügen über sehr gute Kenntnisse im Informationssicherheitsmanagement sowie in ISO/IEC 27001 und PCI DSS Sie kennen relevante regulatorische Anforderungen, insbesondere DORA, ZAG-MaRisk, DSGVO, BaFin- und EBA-Vorgaben Sie bringen Erfahrung in Audit-, Zertifizierungs-, Assessment- und Nachweisprozessen mit Sie verfügen über
Blockchain · 🇬🇧 London, United KingdomRemote57y ago
<div class="content-intro"><p><strong>Blockchain</strong> is connecting the world to the future of finance. As the most trusted and fastest-growing global crypto company, it helps millions of people worldwide safely access cryptocurrency. Since its inception in 2011, Blockchain has earned the trust of over 90 million wallet holders and more than 40 million verified users, facilitating over $1 trillion in crypto transactions.</p></div><p>Blockchain.com is looking for an experienced <strong>Chief Information Security Officer (CISO)</strong> to lead our global cyber security organization as we continue to scale and prepare for our next phase of growth, including our journey toward becoming a US public company.</p> <p>Reporting to the CTO, the CISO will define and execute the company's global cybersecurity strategy, ensuring the security, resilience and integrity of our platform while enabling rapid product innovation. This executive will be a trusted advisor to the leadership team and Board, partnering closely with Engineering, Product, Infrastructure, Legal, Compliance and Finance.</p> <p>The CISO will oversee the Security Engineering, Security Operations and Security GRC teams and collaborate closely with IT, SRE and the broader engineering team.</p> <p><strong>WHAT YOU WILL DO</strong></p> <ul> <li>Define and execute Blockchain.com's global cybersecurity strategy aligned with business objectives and IPO readiness.</li> <li>Foster a culture of security across the company by being a strong business-enabler.</li> <li>Lead and scale the Security Engineering, SOC and Security GRC organizations.</li> <li>Partner with executive leadership and the internal audit team on cybersecurity strategy, enterprise risk and regulatory readiness.</li> <li>Strengthen our cloud, application and infrastructure security across a global digital asset platform.</li> <li>Devise robust operational flows & technical systems to safeguard client and company funds.</li> <li>Drive incident response
Pleo · 🇬🇧 United KingdomRemote57y ago
About Pleo Messy spend management is tricky business. And tedious processes are a lose-lose situation for all involved, not just finance. At Pleo, we're changing that. We build spend solutions that make managing money seamless, empowering, and surprisingly effective for finance teams and employees alike - with a vision to help all businesses ‘go beyond’. The word ‘Pleo’ actually means ‘more than you’d expect’, and living by that mantra has been the secret to our success over the last 10 years. Now, we’re at a pivotal moment in our journey; every move we make has a direct impact on our 40,000+ customers, our business, and our collective success. We need people who take pride in uncovering customer needs, who turn complex problems into simple solutions, challenge the way things are done (respectfully), and always aim high. With great ambitions driving us forward, we can’t say we’ve got this whole thing figured out. And frankly, that’s half the fun! What we can say is that we’re a driven, progressive, and, importantly, a kind bunch of 850+ people from over 100 nationalities, all committed to delivering the future of business spending, together. About the role We're looking for a Lead Security Operations Engineer to join our Cybersecurity team at Pleo. In this role, you'll define and deliver the SecOps roadmap, building the detection, response, and investigation capability that protects a fast-growing fintech. If you're excited about owning a security operations function end to end, from framework-based strategy through to the code that makes it run, then this is the opportunity for you! Who you'll be working with and reporting to You'll report to our VP of Fraud & Security and work closely with Fraud, DevSecOps, Engineering, and Risk & Compliance. Our team is highly collaborative and dedicated to protecting Pleo's customers and their money. You'll also have the chance to partner with teams across the organisation and to bring less experienced security engineers up with
Secfix · Remote-EuropeRemote57y ago
Remote (+/- 2hrs from Germany GMT+1). C1 or C2 English is essential At Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work. Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader. We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital. About the Role We're hiring a Senior Information Security Specialist to strengthen our compliance function as Secfix scales into more frameworks, mid-market customers, and a growing compliance team. This role sits at the intersection of compliance delivery, content, and team support. You'll own the compliance knowledge that lives inside our platform, mentor our junior compliance specialists, support our customer success team, and act as the senior compliance voice for customers, auditors, and product. You'll work closely with our co-founder & CISO and our CS Lead. This is a high-impact role with real influence on how Secfix delivers compliance: both as a service to customers and as content inside our app. What You'll Do: You will own one of the most important pillars of Secfix: the quality and breadth of our compliance offering . We don't (and can't afford to) micro-manage. We've built strong foundations and will give you full context on what works. You can test new approaches, but at the end of the day, you have full ownership of how you deliver results (with a strong support network from within and outside the company). You will: Own and drive the compliance roadmap inside the Secfix platform across different compliance frameworks (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 4200
Hexa · RemoteRemote57y ago
About Waniwani Waniwani builds the infrastructure that distributes insurance and banking products through AI assistants. We raised an $8M seed led by Seedcamp and work with large European banks and insurers. Each enterprise deal has to be scoped, architected, and deployed into a regulated environment. This role owns the layer between a signed deal and a live deployment. The role Customer workshops, discovery, and requirements (35%). Run technical discovery and workshops with each client, and translate their needs into clear, buildable product requirements for our sales, ops, and engineering teams. Flag what we need to build to support a given setup, such as client self-hosting. Solution architecture and documentation (35%). Design the end-to-end MCP flow and integration architecture for each client, including hosted versus on-premise scenarios, and produce the technical documentation enterprise clients require (BPI France alone is roughly 50 docs). Procurement, security, and delivery oversight (30%). Use our existing compliance library (SOC 2 program, DPAs, prior questionnaire answers) to complete security questionnaires, handle security committees and data-residency questions, and drive procurement to completion. Oversee the MCP deployment itself, which our freelancer network implements. Across all three, you build the reusable kit that makes this repeatable: scoping templates, architecture patterns, and a procurement answer library. Objectives 90 days: own scoping and procurement response for active deals, with the reusable kit used on at least one live deal end to end. 6 months: run the full signed-to-live pipeline, including architecture decisions and procurement ownership, without founders in the critical path. 12 months: a repeatable delivery process with patterns reused across clients, and a case for the first hire under this role. Requirements You are technically credible: you read code, reason fluently about integrations and the MCP and agent stack, and can
Ant-Tech · 🇬🇧 London, United KingdomRemote57y ago
Tasks Description Join a stellar team of leaders and experts in fintech, blockchain, cryptography, infrastructure, and security to build the next generation of core banking systems. We're hiring an IT Manager to lead the internal systems and infrastructure for our remote-first, global team. You will be responsible for ensuring our team has the secure, efficient tools, hardware, and support required to operate, while managing our IT stack, overseeing procurement, and maintaining our high security and compliance standards. This role blends strategic leadership with hands-on execution, requiring technical proficiency, security expertise, and the resilience to grow in a fast-paced environment. You'll report to the CISO and work closely with Engineering, Security, and Operations to support our growth internationally. Responsibilities Manage and optimize our Google Workspace environment. Oversee procurement, configuration, and shipping of company material to all employees. Lead the IT portion of the employee lifecycle, ensuring seamless access management and equipment logistics. Manage software and hardware vendors, optimizing for performance and cost. Support our SOC 1, SOC 2 Type II, ISO 27001, ISO 22301 and CCSS initiatives by maintaining records of IT procedures and ensuring compliance across all systems. Provide technical assistance to team members, resolving technical issues promptly. Manage and scale our MDM solutions to ensure fleet-wide security and automation. Develop and maintain playbooks, runbooks, and scalable IT processes as we grow. Support to team in the use of IA tools and MCP connectors Requirements Requirements 6+ years of experience in IT Management or a similar internal systems role. Expertise in Google Admin and Google Workspace security tools. Experience managing IT for a remote-first workforce across multiple time zones. Strong understanding of MDM solutions (e.g., Jamf) and endpoint security. Knowledge of cybersecurity best practices and experien
Secfix · Remote-EuropeRemote57y ago
Remote (+/- 2hrs from Germany GMT+1). C1 or C2 English is essential At Secfix, we’re at the forefront of automating security compliance in Europe. We help companies get and stay ISO 27001, GDPR, TISAX, and SOC 2 fast and easy and reduce hundreds of hours of manual work. Secfix is run by a 100% remote team with hubs in Munich, Berlin and London. We’re a high-performing team looking for passionate, execution-focused, owners to help us automate security and compliance for modern companies and become the European compliance automation leader. We’ve just raised our $12M Series A and are backed by top VCs, including Alstin Capital, Neosfer (Commerzbank), and Bayern Capital. About the Role We're hiring a Senior Information Security Specialist to strengthen our compliance function as Secfix scales into more frameworks, mid-market customers, and a growing compliance team. This role sits at the intersection of compliance delivery, content, and team support. You'll own the compliance knowledge that lives inside our platform, mentor our junior compliance specialists, support our customer success team, and act as the senior compliance voice for customers, auditors, and product. You'll work closely with our co-founder & CISO and our CS Lead. This is a high-impact role with real influence on how Secfix delivers compliance: both as a service to customers and as content inside our app. What You'll Do: You will own one of the most important pillars of Secfix: the quality and breadth of our compliance offering . We don't (and can't afford to) micro-manage. We've built strong foundations and will give you full context on what works. You can test new approaches, but at the end of the day, you have full ownership of how you deliver results (with a strong support network from within and outside the company). You will: Own and drive the compliance roadmap inside the Secfix platform across different compliance frameworks (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 4200