Auto-apply to these security jobs

We've scanned millions of jobs. Simply select your favorites, and we can fill out the applications for you.

OpenAI logo
OpenAINew York City, NY
About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We're looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Perform Security Assessments: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software. Develop and Implement Security Tools: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats. Collaborate with Development Teams: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines. Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies. Vulnerability Management: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts. Incident Response Support: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents. Stay Current on Security Trends: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications. You might thrive in this role if you: Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles. Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response. Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks. Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods. Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI's Affirmative Action and Equal Employment Opportunity Policy Statement. Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link. OpenAI Global Applicant Privacy Policy At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Posted 30+ days ago

Gartner logo
GartnerStamford, CT

$116,000 - $163,000 / year

Hiring near our Irving, TX Center of Excellence with a flexible environment. About Gartner IT: Join a world-class team of skilled engineers who build creative digital solutions to support our colleagues and clients. We make a broad organizational impact by delivering cutting-edge technology solutions that power Gartner. Gartner IT values its culture of nonstop innovation, an outcome-driven approach to success, and the notion that great ideas can come from anyone on the team. About the role Gartner information security teams are a group of passionate information security professionals dedicated to Protecting, Detecting, and Responding to threats. Our team is filled with lifelong learners who are consistently researching ways to better defend and stay ahead of the threats of tomorrow. We are a collaborative group, where good ideas come together whether they come from the most experienced or the newest members of the team. As a Lead Purple Team Engineer on the Security Operations team, you will spearhead collaborative offensive and defensive security initiatives to identify and validate vulnerabilities in Gartner's security controls, procedures and infrastructure. You will use your extensive knowledge of attacker tools and techniques (red team) to improve our capability to detect and respond to threats (blue team). You will play a key role in defending Gartner's network and intellectual properties. Our team is filled with lifelong learners who are consistently researching ways to better defend and stay ahead of the threats of tomorrow. We are a collaborative, flexible group, where good ideas are brought forth and acted upon, whether they come from the most experienced or the newest members of the team. What you will do: Lead Purple Team operations by designing, planning and executing purple team exercises and activities that simulate real-world attack scenarios to test and improve detection and response capabilities. Work closely with teams such as the Security Operations Center (SOC), Threat Intelligence, and Detection Engineering to help identify and remediate gaps in existing controls Develop new, and tune existing attack emulations based on use-cases and strategy, drawing from threat intelligence and current events Play a key role in Threat Modeling exercises Assist and support SOC analysts during ad-hoc Incident Response activities Build and maintain tools and scripts to support purple team activities, including automation of attack simulations and telemetry analysis Assist in the development of innovative and cutting-edge detection content aligned with ATT&CK, Cyber Kill Chain, and various other cyber security frameworks Bring your own ideas and solutions to a fast-paced, growing, and evolving team centered around operational excellence Act as a mentor to junior team members, promote knowledge sharing and contribute to the strategic direction of the Security Operations team. What you will need: 5+ years of relevant Information Security or Penetration Testing experience Deep understanding of offensive techniques and tools Knowledge of MITRE ATT&CK, Cyber Kill Chain or other behavioral information security frameworks Python, Bash, PowerShell or other scripting language experience Bachelor's in Computer Science, Information Security, Engineering, or commensurate experience in Information security is preferred Extensive experience in purple/red teaming with a strong technical foundation in offensive security and adversary emulation. Ability to design, build and scale automated security validation processes Experience with Attack Emulation Platforms Background in cybersecurity incident analysis and investigation Experience utilizing security tools such as EDR (including live response), web proxy, WAF and email security tools Knowledge of cloud environments (AWS, Azure, GCP) Digital Forensics and Incident Response (DFIR) skills Ability to query using various query languages such as SPL, SQL, KQL Ability to communicate effectively and possess excellent prioritization skills. Ability to automate tasks and code solutions to repetitive problems (Python, PowerShell, Bash) Nice to have: Penetration Testing skills Experience working closely with defenders/Blue Team to identify and resolve problems Experience implementing integrations between tools utilizing APIs Experience using SIEM or XDR for log analysis and alert creation Relevant certifications such as OSCP are a plus Threat Hunting experience Who you are: Passion for security and solving tomorrow's problems Willingness to learn new technology platforms Strong team player Innovation mindset - Takes opportunities to make existing processes more efficient and thinks "automation first" Don't meet every single requirement? We encourage you to apply anyway. You might just be the right candidate for this, or other roles! What you will get: Competitive compensation. Limitless growth and learning opportunities. Ongoing mentorship and apprenticeship; Leadership courses, development programs, technical courses, certification opportunities and more! A collaborative and positive culture - join a diverse team of professionals that are as smart and driven as you. A chance to make an impact - your work will contribute directly to our strategy. Enjoy the flexibility of working from home and the energy of collaborating with peers in our dynamic offices. 20+ PTO days plus holidays and floating holidays in your first year. Extensive medical, dental insurance and vision plan. 401K with corporate match, immediate vesting. Health-and-wellness-related allowance programs. Parental leave. Tuition reimbursement. Employee Stock Purchase Plan. Employee Assistance Program. Gartner Gives Charity Match. And much more! #LI-RG2 #LI-Hybrid #LI-Technology Who are we? At Gartner, Inc. (NYSE:IT), we guide the leaders who shape the world. Our mission relies on expert analysis and bold ideas to deliver actionable, objective business and technology insights, helping enterprise leaders and their teams succeed with their mission-critical priorities. Since our founding in 1979, we've grown to 21,000 associates globally who support ~14,000 client enterprises in ~90 countries and territories. We do important, interesting and substantive work that matters. That's why we hire associates with the intellectual curiosity, energy and drive to want to make a difference. The bar is unapologetically high. So is the impact you can have here. What makes Gartner a great place to work? Our vast, virtually untapped market potential offers limitless opportunities - opportunities that may not even exist right now - for you to grow professionally and flourish personally. How far you go is driven by your passion and performance. We hire remarkable people who collaborate and win as a team. Together, our singular, unifying goal is to deliver results for our clients. Our teams are inclusive and composed of individuals from different geographies, cultures, religions, ethnicities, races, genders, sexual orientations, abilities and generations. We invest in great leaders who bring out the best in you and the company, enabling us to multiply our impact and results. This is why, year after year, we are recognized worldwide as a great place to work. What do we offer? Gartner offers world-class benefits, highly competitive compensation and disproportionate rewards for top performers. In our hybrid work environment, we provide the flexibility and support for you to thrive - working virtually when it's productive to do so and getting together with colleagues in a vibrant community that is purposeful, engaging and inspiring. Ready to grow your career with Gartner? Join us. Gartner believes in fair and equitable pay. A reasonable estimate of the base salary range for this role is 116,000 USD - 163,000 USD. Please note that actual salaries may vary within the range, or be above or below the range, based on factors including, but not limited to, education, training, experience, professional achievement, business need, and location. In addition to base salary, employees will participate in either an annual bonus plan based on company and individual performance, or a role-based, uncapped sales incentive plan. Our talent acquisition team will provide the specific opportunity on our bonus or incentive programs to eligible candidates. We also offer market leading benefit programs including generous PTO, a 401k match up to $7,200 per year, the opportunity to purchase company stock at a discount, and more. The policy of Gartner is to provide equal employment opportunities to all applicants and employees without regard to race, color, creed, religion, sex, sexual orientation, gender identity, marital status, citizenship status, age, national origin, ancestry, disability, veteran status, or any other legally protected status and to seek to advance the principles of equal employment opportunity. Gartner is committed to being an Equal Opportunity Employer and offers opportunities to all job seekers, including job seekers with disabilities. If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to use or access the Company's career webpage as a result of your disability. You may request reasonable accommodations by calling Human Resources at +1 (203) 964-0096 or by sending an email to ApplicantAccommodations@gartner.com. Job Requisition ID:103382 By submitting your information and application, you confirm that you have read and agree to the country or regional recruitment notice linked below applicable to your place of residence. Gartner Applicant Privacy Link: https://jobs.gartner.com/applicant-privacy-policy For efficient navigation through the application, please only use the back button within the application, not the back arrow within your browser.

Posted 30+ days ago

A logo
A & AssociatesBoston, MA
A&A is looking for a Security Guard to join our team. The Security Guard is responsible for protecting the client and assigned property from any criminal activity or trespassing. The ideal candidate will have strong written and verbal communication, excellent observational skills and previous surveillance experience, preferably in a law enforcement environment. This person should have the ability to remain calm in high-pressure situations while exhibiting patience and a superb attention to detail. Responsibilities: Surveillance – Patrol the grounds or buildings as assigned, regularly. If suspicious activity is detected, refer to the local authorities. Review surveillance cameras and monitor crowds as needed. Establish and review the identification required to enter the building or property. Verify all doors, windows and gates are secure on the property on a rotating schedule. Escort released employees off the property as well as any other trespassers. Investigation – Respond to any alerts of suspicious activity. If a person is under suspicion of criminal activity, secure the environment and person, and report to the local authorities. Perform other related duties as assigned Requirements: High school diploma or equivalent is required Security guard training certification preferred Physically able to lift up to 50 pounds, stand or sit for long periods, and detain an individual if necessary Powered by JazzHR

Posted 30+ days ago

A logo
A & AssociatesPeoria, IL
We are looking for a vigilant and dedicated Security Guard to join our security team. The successful candidate will be responsible for maintaining a safe and secure environment across our premises by monitoring activities, enforcing safety protocols, and responding promptly to incidents. This role is vital in safeguarding personnel, property, and assets, ensuring peace of mind for all stakeholders. The ideal candidate will possess strong observational skills, a proactive attitude, and a commitment to safety standards. 1st and 2nd shifts. Duties Conduct regular patrols of designated areas to monitor for suspicious activity or safety hazards. Enforce security policies and procedures to prevent unauthorized access or theft. Maintain detailed incident reports and logs of daily activities, observations, and security breaches. Collaborate with law enforcement agencies during investigations or emergencies. Manage conflict situations professionally, de-escalating disputes and ensuring safety for all parties involved. Control access points by verifying identification and issuing visitor passes as required. Conduct loss prevention activities by identifying potential thefts or vandalism. Assist with crowd control during events or high-traffic periods to ensure orderly conduct. Requirements Strong understanding of conflict management techniques and loss prevention strategies. Ability to respond calmly and effectively during emergencies or stressful situations. Familiarity with security protocols, law enforcement procedures, and incident reporting standards. Excellent observational skills with keen attention to detail. Effective communication skills to interact professionally with colleagues, clients, and the public. This position offers an opportunity to contribute significantly to the safety of our community while working in a structured environment that values vigilance and professionalism. We welcome applicants committed to maintaining high standards of security and safety across diverse settings. Benefits: Dental insurance Health insurance Paid time off Vision insurance Powered by JazzHR

Posted 30+ days ago

A logo
A & AssociatesWest Palm Beach, FL

$16+ / hour

With offices throughout the Unites States, A & Associates is a company that can be trusted to provide a diverse level of services with excellence, diligence and integrity. “Quality In Everything We DO” is far more than our mantra, it is our standard!! Explore a career with A & Associates, one of the leading providers for temporary, temp-to-hire, permanent placement services and security guard services. MUST HAVE A VALID SECURITY LICENSE CLASS D We are looking for a competent Security Officer to undertake the surveillance of our premises and protection of our staff and visitors. You will be responsible for detecting any suspicious behavior and preventing vandalism, thefts or other criminal behavior. A security officer must be well-trained in surveillance and dealing with perpetrators. The ideal candidate will inspire respect and authority as well as possess a high level of observation. The goal is to help the company in maintaining excellent working conditions by keeping our facilities safe and problem-free. Responsibilities Patrol premises regularly to maintain order and establish presence Monitor and authorize entrance of vehicles or people in the property Remove wrongdoers or trespassers from the area Secure all exits, doors and windows after end of operations Check surveillance cameras periodically to identify disruptions or unlawful acts Investigate people for suspicious activity or possessions Respond to alarms by investigating and assessing the situation Provide assistance to people in need Submit reports of daily surveillance activity and important occurrences Skills Proven experience as security officer or guard Knowledge of legal guidelines for area security and public safety Familiarity with report writing Excellent surveillance and observation skills Tech-savvy with experience in surveillance systems Trained in First Aid/BLS and self-defense Registered as a security officer High School diploma is required MUST HAVE A VALID SECURITY LICENSE CLASS D MUST HAVE A PROFESSIONAL APPEARANCE B 2300065 Job Type: Full-time Pay: $15.50 per hour Benefits: Dental insurance Health insurance Paid time off Vision insurance Schedule: 8 hour shift Night shift Overnight shift License/Certification: SECURITY LICENSE (Required) Ability to Commute: Palm Beach County Ability to Relocate: N/A Work Location: In person Powered by JazzHR

Posted 30+ days ago

A logo
A & AssociatesPortland, OR
A&A Security is looking for a Security Guard to join our team. The Security Guard is responsible for protecting the client and assigned property from any criminal activity or trespassing.   The ideal candidate will have strong written and verbal communication, excellent observational skills and previous surveillance experience, preferably in a law enforcement environment.  This person should have the ability to remain calm in high-pressure situations while exhibiting patience and a superb attention to detail. Responsibilities:  Surveillance –  Patrol the grounds or buildings as assigned, regularly. If suspicious activity is detected, refer to the local authorities. Review surveillance cameras and monitor crowds as needed. Establish and review the identification required to enter the building or property.  Verify all doors, windows and gates are secure on the property on a rotating schedule. Escort released employees off the property as well as any other trespassers.   Investigation – Respond to any alerts of suspicious activity. If a person is under suspicion of criminal activity, secure the environment and person, and report to the local authorities. Perform other related duties as assigned. Requirements: High school diploma or equivalent is required Security guard training certification preferred  Physically able to lift up to 50 pounds, stand or sit for long periods, and detain an individual if necessary   About A&A Security: A&A Security is a Security organization dedicated to providing top notch security services to their clients.  Our employees enjoy a work culture that promotes "quality in everything we do." A&A Security benefits include health, vision, and dental insurances. Powered by JazzHR

Posted 30+ days ago

Watermark Risk Management International logo
Watermark Risk Management InternationalArlington, VA
Come make your mark with Watermark! 🎖️ FOUNDED BY USAF VETERANS in 2007, we are proud to be a Service-Disabled Veteran Owned Small Business. 🌎 SUBJECT MATTER EXPERTS specializing in security and risk management. We’re intimately familiar with DOD security programs and mission requirements. ⭐ OUR CORE VALUES drive every action we take as a company. We strive to exhibit PERSPECTIVE, PASSION, COMMUNICATION, INTEGRITY AND ETHICS, and BALANCE in all we do. 💲 COMPETITIVE BENEFITS PACKAGE to address our employees’ physical, mental, emotional, and financial well-being. This includes 100% employer- paid medical insurance, ample paid leave, a free employee assistance program, and a competitive 401k savings plan. At Watermark, our people come first! Security Operations Physical Security Specialist In this role you will…. Conduct assessments of Emergency Management (EM); Chemical, Biological, Nuclear, Radiological, and High-Yield Explosives (CBRNE); and Continuity of Operations (COOP), and Exercise programs to protect personnel, critical assets, and missions from hazards and threats that may impact the installation, facility, or asset. Support installation personnel in the development of the All-hazards Threat Assessment (AHTA). Evaluates the installation's ability to respond to threats and hazards. Experience Requirements: Understanding of pre-assessment phase activities (e.g. Mission Analysis and Pre-Site Survey) Assessment phase activities to include onsite vulnerability and risk assessments Post assessment phase activities (e.g., Post Analysis, Report Writing, and Major Command follow-up) Experience in conducting All-Hazards Assessments using a risk-based approach is highly desired but not required. Experience working in an Air Force Emergency Management unit is highly desired but not required. Education Requirements: Bachelor’s or equivalent and minimum of 3-5 years experience in a civilian or military emergency management or CBRN position. Security Clearance Requirements: TS/SCI Other Requirements: May be required to move equipment/files weighing up to 50 pounds Requires ability to consistently perform repetitive tasks including filing and scanning May require sedentary work at least 50% of the time Reports to a physical location which occasionally requires the ability to traverse between buildings Ability to manage stress with a high degree of maturity/professionalism Demonstrated critical thinking and leadership skills and the ability to work well with others Effective verbal and written communication skills Other duties as assigned This position is contingent on funding. Watermark provides salary ranges with job postings in states where it is legally required; any other salary ranges associated with our postings are third party estimates and may not be an accurate reflection of Watermark’s total compensation package. Multiple considerations are taken into account when determining the final salary/hourly rate, including but not limited to, Contract Wage Determination, education and certifications, relevant work experience, related skills and competencies, as well as Federal Government Contract Labor Categories. Central to Watermark’s employment philosophy is the wellbeing of our employees which is why we offer a robust benefits package and wellness program alongside of annual base compensation. Watermark is an equal opportunity employer. All terms and conditions of employment are established without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, veteran status, or any other protected category under applicable federal, state, and local laws. Powered by JazzHR

Posted 30+ days ago

A logo
A & AssociatesClemmons, NC

$18+ / hour

Pay: $18.00 per hour Job description: Job Overview We are looking for a dedicated and experience Security Professional who is vigilant and has strong observation skills. We are looking for a team of Security Officers who work well amongst stressful environments, and great as a team. Duties Monitor Access Control Complete Hourly Logs, and Report Incidents Respond to emergency situations Be able to complete computer reports, paper reports Be able to utilize technology (phones, tablets, computers) Gate Inspections Gate Access Controls Respond to Client/Patron calls to Security Cell Respond promptly to alarms and incidents, assessing situations and taking appropriate action. Enforce rules and regulations to maintain order and safety within the location Provide first aid assistance when necessary, ensuring the well-being of individuals on site. Document all incidents, observations, and activities in detailed reports for future reference. Collaborate with law enforcement agencies when required during investigations or emergencies. Participate in ongoing training programs to enhance skills in conflict management, surveillance techniques, and emergency response. Qualifications Must possess VALID ACTIVE DRIVER'S LICENSE to complete patrols Traffic Control and Direction Experience is recommended Previous experience in security or law enforcement is preferred but not mandatory. Strong understanding of loss prevention strategies and techniques. Certification in First Aid and CPR is highly recommended. Excellent conflict management skills with the ability to remain calm under pressure. Must possess a valid security certificate or equivalent credentials. Ability to work flexible hours, including nights and weekends if necessary. Strong observational skills with attention to detail. Military experience is a plus but not required. Join our team as a Security Officer where your commitment to safety will be valued and your skills will contribute significantly to our mission of providing a secure environment for all. Job Types: - Temporary - November to January - Temp to Full Time Benefits: (After 60 Days) Dental insurance Health insurance Vision insurance Schedule: 12 hours - overnight 5pm to 5am 3 days on, 4 days off Application Question(s): - Do you have a Security License? - Do you have a Driver's License? License/Certification: Security Certificate Required Security License Required Powered by JazzHR

Posted 1 day ago

Leidos logo
LeidosLorton, Virginia

$65,650 - $118,675 / year

The Digital Modernization Sector at Leidos is seeking an Associate Industrial Security Representative/Assistant Facility Security Officer (AFSO) in Lorton, VA. he position will be a part of the Leidos Defense/Intel IT Business Area. The ISR/AFSO will work under the guidance of the Leidos Defense & Intel IT, Business Area Security Manager in the application of Leidos security standards and practices to existing government and Leidos facilities identified by the contract(s). The ISR/AFSO will assist the Facility Security Officer (FSO) in implementing the industrial security program and ensure security requirements are met for the facility and Leidos, Inc. The ISR/AFSO will work to achieve day-to-day objectives with moderate impact on the work area/project team. Work independently on larger, moderately complex projects/assignments. Set objectives for your own area to meet the objectives or goals of projects and assignments. May assist other professionals with tasks and assignmentsThe ISR/AFSO is responsible for assisting in implementing the industrial security program and ensuring company and customer security requirements are met. Primary Responsibilities Administer day-to-day security programs, personnel processing, program reviews, document control system, audits & self-inspections, violation investigations & reports, receipt/dispatch/destruction/mail logs, visit certs, etc. Serves as the Assistant Access Control Officer and be responsible for badge access, visitor logs and key inventory. Assist the FSO and Senior Security Representative (SSR) with the implementation and execution of the physical requirements to meet ICD and DHS requirements. Implement the industrial security program and ensure company and customer security requirements are met. Interface with all levels of Leidos personnel and government management personnel to ensure contract security compliance with National Industrial Security Operating Manual (NISPOM), DoD Manual 5205.07, Contract Security Classification Specification (DD254) and Program Classification Guides. Perform self-inspections, participate in government telephonic and in-person reviews and inspections. Responsible for maintaining security program compliance to include managing NISS facility profiles, submitting change condition packages, FCL Sponsorship packages, and responding to FCL packages Conduct Personnel Security processing actions including requesting, reviewing, approving, and submitting clearances packages up to and including SCI nomination packages in accordance with customer requirements. Maintain Personnel Security databases to track new employee security clearance actions and annual security training completion status. Take independent action when warranted or in the absence of the FSO. Bring security risks to the attention of the FSO, SSR and Program Managers. Provide clear guidance to company employees and recommend modifications to operations policies or procedures as appropriate. Provide research and technical support to projects, produces solutions and documentation, and monitors project tasks and schedules Work as a team player, demonstrate flexibility, and excellent organizational skills. Familiarity with COMSEC related duties and responsibilities under NSA CSS 3-16. Demonstrate leadership and decision-making ability within the scope of the position. Exhibit mentoring, team building and coaching ability. Assist with Proposal Writing and Contract Closeouts. Fulfill additional duties as required set forth by the Business Area Security Manager, FSO and SSR Basic Qualifications Typically requires a BA degree and 4+ years of prior relevant experience or master’s degree with 2 years of prior relevant experience. Additional years of relevant experience will be considered in lieu of a degree. Prior experience as an Assistant Facility Security Officer Working knowledge of the NISPOM, other relevant DoD security guidance as well as the Intelligence Community Directive (ICD) standards The position requires a self-motivated candidate that is capable of working in an independent or team environment with minimal direction, customer service orientated. Commitment to security - creating and delivering the highest value to customers. Ability to interpret company and government security policies and apply them to program operations. Understanding of Physical Security requirements for OSS, SCIFs, and collateral Restricted Areas. Along with working knowledge of SF-86, SF-312, DD-254, SF700, SF702 and other required forms. Understanding of security databases, DISS, NISS and SIMS Experience creating and conducting initial security briefings, debriefings, indoctrinations, pre/post foreign travel briefings and refresher briefings, as appropriate. Ability to develop and establish an effective security awareness, training, and education program. Execute the requirements set forth in the Technology Control Plan (TCP) and Standard Practice Procedures (SPP). Communicates with parties within and outside of work area, which may include external constituents depending upon the area. Requires ability to influence others outside of work area on policies, practices, and procedures. Demonstratable experience communicating information security and risk-related concepts effectively to both technical and non-technical audiences. Strong problem-solving and analytical skills and demonstrate poise and ability to act calmly and competently in high-pressure, high-stress situations. Attention to detail and a high level of accuracy are a must. Must be able to work in a constantly changing regulatory environment Must be highly organized with excellent oral and written communication skills. Computer literacy: Proficient in Microsoft Suite to include Word, Excel, Outlook, and Access. Excellent time management and multitasking skills. Prior experience in Personnel and Industrial Security. Candidate must possess an active TS/SCI. Preferred Qualifications• FSO training certificate for possessing facilities from DCSA• Knowledge of Access Control and Intrusion Detection Systems• Must have a solid background in industrial security and a proven track record of ensuring compliance and protecting sensitive information.• Experience conducting Security incident inquiries. If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: September 15, 2025 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $65,650.00 - $118,675.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Posted 3 weeks ago

SpaceX logo
SpaceXHawthorne, CA

$130,000 - $175,000 / year

SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars. SECURITY ENGINEER (SECURITY OPERATIONS) SpaceX is targeted by sophisticated adversaries determined to disrupt or obtain the cutting-edge technology it develops. SpaceX is hiring a security engineer to join the security operations team to build the capabilities needed to detect and respond to these adversaries. The environment in which you will operate is used to launch rockets and control spacecraft. You will be tasked with developing the tooling and data delivery mechanisms the security operations team will use to catch these threat actors in this environment before they can disrupt or deny SpaceX’s mission. Your output will be developing solutions to address visibility gaps while bolstering the resilience of internally developed tooling to ensure maximum uptime for detecting threats. Your work may involve creating automation workflows to drive down time to triage security detections, developing a service to pull in new datasets or enrich existing ones, and finally helping the SOC respond and address visibility gaps from an incident. If you are interested in detecting and disrupting sophisticated threat actors in order to secure SpaceX’s mission to Mars, let’s talk! RESPONSIBILITIES: Build and improve existing security detection mechanisms and automation frameworks that directly drive what the Security Operations Center. Engage with relevant owners of high-risk systems and services to identify and prioritize detection gaps. Investigate anomalous or suspicious behavior in the environment as it is identified in the detection engineering process. Participate in adversary emulation activities to identify detection gaps in the environment. BASIC QUALIFICATIONS: 2+ years of professional experience in incident response, security operations, or security engineering role in lieu of a degree; OR a bachelor’s degree in security engineering, computer science, cyber security, engineering, math, or other STEM discipline. Experience with any modern programming language (including but not limited to Python, Go, C++, Rust). PREFERRED SKILLS AND EXPERIENCE: Experience performing Incident Response related tasks or being a part of a role directly contributing to a CSIRT team. Experience building Extract, Transform, and Load (ETL) pipelines from diverse systems to optimize logging formats for threat detection. Demonstrated ability to support and manage services in a Kubernetes (k8s) environment, ensuring high availability and reliability through monitoring, alerting, and infrastructure automation. Knowledge of traditional Security Operations environments and response procedures, including modern security information and event management (SIEM) systems. Knowledge of common attack trends or techniques, and the evidence sources needed to investigate. Familiarity with enterprise security controls and best practices for Windows, Linux, and/or macOS systems. ADDITIONAL REQUIREMENTS: Must be able to work extended hours and weekends as needed. COMPENSATION AND BENEFITS: Pay Range: Security Engineer/Level I: $130,000.00 - $150,000.00/per year Security Engineer/Level II: $145,000.00 - $175,000.00/per year Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience. Base salary is just one part of your total rewards package at SpaceX. You may also be eligible for long-term incentives, in the form of company stock, stock options, or long-term cash awards, as well as potential discretionary bonuses and the ability to purchase additional stock at a discount through an Employee Stock Purchase Plan. You will also receive access to comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short and long-term disability insurance, life insurance, paid parental leave, and various other discounts and perks. You may also accrue 3 weeks of paid vacation and will be eligible for 10 or more paid holidays per year. Employees accrue paid sick leave pursuant to Company policy which satisfies or exceeds the accrual, carryover, and use requirements of the law. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceX is an Equal Opportunity Employer; employment with SpaceX is governed on the basis of merit, competence and qualifications and will not be influenced in any manner by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability or any other legally protected status. Applicants wishing to view a copy of SpaceX’s Affirmative Action Plan for veterans and individuals with disabilities, or applicants requiring reasonable accommodation to the application/interview process should reach out to EEOCompliance@spacex.com .

Posted 30+ days ago

Replit logo
ReplitFoster City, California
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide and over 500,000 business users, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are looking for a highly skilled PSIRT Engineer to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires strong technical ability to reproduce vulnerabilities , deep understanding of web/app/cloud exploit classes, and experience operating bug bounty and coordinated disclosure programs. You will work closely with Engineering, Cloud Security, SecOps, SRE, and IT teams to ensure vulnerabilities are fixed quickly and communicated responsibly. What You’ll Do Vulnerability Intake, Triage & Validation Manage intake from bug bounty platforms (HackerOne preferred), customer reports, automated scanners, pentest reports, and coordinated disclosure channels. Independently validate, reproduce, severity-score, and document findings. Identify duplicates and maintain a clean vulnerability records pipeline. Assess relevance and exploitability using OWASP, cloud misconfiguration patterns, and identity/authentication/authorization risks (Oauth, OIDC). Remediation Coordination & SLA Management Work with Engineering, SecOps, IT, SRE, and Cloud Security to confirm product impact and drive remediation. Provide detailed reproduction steps, proof-of-concepts, and technical analyses. Track SLAs, remediation progress, regression testing, and systemic improvements. Support SOC 2, ISO 27001, and pentest evidence needs as part of vulnerability lifecycle governance. Bug Bounty & Vulnerability Disclosure Program Management Design and evolve the bug bounty program, including scope, rules, and reward structures. Manage platform selection, private vs. public launches, and community engagement. Communicate clearly with researchers, provide clarifications, and handle feedback or disputes. Determine reward payouts, bonus decisions, and recognition for top contributors. Coordinated Disclosure & CVE Management Lead the coordinated vulnerability disclosure process for internal and external findings. Negotiate disclosure timelines with researchers and partners. Coordinate CVE assignments and publications, and prepare customer/public advisories. Required Skills Experience running or triaging for bug bounty programs (HackerOne ideally). Strong ability to triage, validate, and reproduce vulnerabilities independently. Deep understanding of web/app/cloud vulnerability classes, OWASP Top 10, misconfigurations, authN/Z issues, etc. Familiarity with cloud platforms (GCP preferred) and SaaS architectures. Strong understanding of CI/CD workflows, code structure, and software engineering fundamentals. Nice to Have Scripting or automation experience (Python, Go, Bash). Pentesting background or exposure to offensive security work. Familiarity with compliance frameworks such as SOC 2 and ISO 27001. Experience authoring public advisories or CVE writeups. Hands-on experience with SIEM, Cloud Logging, and investigative tooling. This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🚗 Commuter Benefits 📱 Monthly Wellness Stipend 🧑‍💻 Autonoumous Work Environement 🖥 In Office Set-Up Reimbursement 🏝 Flexible Time Off (FTO) + Holidays 🚀 Quarterly Team Gatherings ☕ In Office Amenities Want to learn more about what we are up to? Meet the Replit Agent Replit: Make an app for that Replit Blog Amjad TED Talk Interviewing + Culture at Replit Operating Principles Reasons not to work at Replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Posted 2 weeks ago

Snap logo
SnapSanta Monica, California

$178,000 - $313,000 / year

Snap Inc is a technology company. We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to express themselves, live in the moment, learn about the world, and have fun together. The Company’s three core products are Snapchat , a visual messaging app that enhances your relationships with friends, family, and the world; Lens Studio , an augmented reality platform that powers AR across Snapchat and other services; and its AR glasses, Spectacles . Snap Engineering teams build fun and technically sophisticated products that reach hundreds of millions of Snapchatters around the world, every day. We’re deeply committed to the well-being of everyone in our global community, which is why our values are at the root of everything we do. We move fast, with precision, and always execute with privacy at the forefront. We’re looking for a Security Engineer to join our Enterprise Infrastructure Security (EIS) team! What you’ll do: You will help design and operate the security controls that protect our corporate devices, applications, and infrastructure. Our team’s scope is broad. We’re looking for someone with deep expertise in a few areas and the curiosity to learn and collaborate across the rest: Build and maintain execution control tooling such as endpoint agents, binary allowlisting, and related enforcement systems while driving resilient device posture through configuration standards, hardening, and continuous validation across endpoints, BYOD, browsers, IoT, lab, network, and IT systems Architect and deploy device trust capabilities by defining and enforcing policies that validate device posture, health, and identity, ensuring only trusted devices can access internal and SaaS applications Secure corporate and SaaS applications, including Google Workspace, by establishing baseline configurations, enforcing access governance, managing browser policies, and ensuring secure communication and data sharing across collaboration platforms Build and operate enterprise vulnerability and risk management platforms, establishing patching and configuration standards, managing exceptions, and reducing attack surface across operating environments Design and operate secure networking and Zero Trust access controls, ensuring that device trust, identity, and network segmentation principles are consistently enforced across corporate and SaaS environments Partner with IT and identity platform teams to define security requirements for IAM, IDP, and SSO integrations, ensuring strong authentication, least-privilege access, and alignment with Zero Trust principles across corporate and SaaS environments Implement and enforce secure network architectures and firewall policies to protect on-premise infrastructure, maintaining resilient security across datacenters, PoP sites, and manufacturing environments Conduct security reviews and partner with cross-functional teams to evaluate new and existing systems, including AI tools and features, providing actionable mitigation guidance that upholds access control boundaries, protects sensitive data, and enables the business to move securely, while also managing exception handling and formal risk acceptance processes Knowledge, Skills & Abilities: Proven experience designing, building, and maintaining corporate security controls, with depth in areas such as device posture management, endpoint agents/binary allowlisting, or SaaS application security Advanced knowledge of operating system internals and hardening, with competency across two or more of the following: macOS, Windows, Linux, mobile (iOS/Android), IoT, or cloud environments (AWS, GCP) Strong understanding of corporate networking concepts and protocols (e.g., VPNs, firewalls, DNS, TLS, identity-aware networking) and their role in enforcing device and application security Experience conducting security design reviews and providing actionable mitigation guidance that balances business enablement with risk reduction Strong development or scripting skills (Python, Go, or equivalent) for building integrations, automating workflows, and scaling security platforms Minimum Qualifications: Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field 6+ years of experience in the field of corporate or enterprise security, or other similar security engineering role Preferred Qualifications: Background evaluating and securely enabling emerging technologies, including AI tools and features, with a focus on upholding access control boundaries and data protection requirements Familiarity with securing lab, IoT, and ancillary systems, including applying hardening standards, monitoring, and access controls across heterogeneous environments Excellent verbal and written communication skills, with high attention to detail Work record of collaborating with internal and external stakeholders at all levels of a company If you have a disability or special need that requires accommodation, please don’t be shy and provide us some information . "Default Together" Policy at Snap: At Snap Inc. we believe that being together in person helps us build our culture faster, reinforce our values, and serve our community, customers and partners better through dynamic collaboration. To reflect this, we practice a “default together” approach and expect our team members to work in an office 4+ days per week. At Snap, we believe that having a team of diverse backgrounds and voices working together will enable us to create innovative products that improve the way people live and communicate. Snap is proud to be an equal opportunity employer, and committed to providing employment opportunities regardless of race, religious creed, color, national origin, ancestry, physical disability, mental disability, medical condition, genetic information, marital status, sex, gender, gender identity, gender expression, pregnancy, childbirth and breastfeeding, age, sexual orientation, military or veteran status, or any other protected classification, in accordance with applicable federal, state, and local laws. EOE, including disability/vets. We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance and the Los Angeles Fair Chance Initiative for Hiring, where applicable). Our Benefits : Snap Inc. is its own community, so we’ve got your back! We do our best to make sure you and your loved ones have everything you need to be happy and healthy, on your own terms. Our benefits are built around your needs and include paid parental leave, comprehensive medical coverage, emotional and mental health support programs, and compensation packages that let you share in Snap’s long-term success! Compensation In the United States, work locations are assigned a pay zone which determines the salary range for the position. The successful candidate’s starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. The starting pay may be negotiable within the salary range for the position. These pay zones may be modified in the future. Zone A (CA, WA, NYC) : The base salary range for this position is $209,000-$313,000 annually. Zone B : The base salary range for this position is $199,000-$297,000 annually. Zone C : The base salary range for this position is $178,000-$266,000 annually. This position is eligible for equity in the form of RSUs.

Posted 30+ days ago

OpenAI logo
OpenAISeattle, Washington
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software. Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats. Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines. Threat Modeling and Risk Assessment : Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies. Vulnerability Management : Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts. Incident Response Support : Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents. Stay Current on Security Trends : Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications. You might thrive in this role if you: Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles. Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response. Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks. Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods. Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement . Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form . No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link . OpenAI Global Applicant Privacy Policy At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Posted 30+ days ago

Chautauqua Institution logo
Chautauqua InstitutionChautauqua, New York

$19 - $22 / hour

The mission of the Community Safety & Security department is to serve and protect all who come to the grounds. Our safety and security professionals ensure the safety of our patrons and staff through the impartiality, respect and compassion enforcement of Chautauqua’s rules and regulations. The department is staffed and operates twenty-four hours a day, 7 days a week throughout the year. In addition to the full-time and part-time summer season positions, work may also be available pre-season and post-season. About Your Compensation Compensation for this position starts at $19.00/Hour and, with demonstrated experience and qualifications, candidates may earn up to $22.00/Hour. For candidates who meet the work experience and licensing requirements, Chautauqua Institution may pay for the armed security officer required classes and training to obtain the New York State security guard training and registration. About Your Work Day Enforcing the Chautauqua Institution's on-grounds rules and regulations. Initiates preliminary investigations into incidents Writes reports and ensures accuracy of necessary documentation. Respond to patron inquiries and requests in a timely, friendly and professional manner. Patrols assigned area(s) to observe and identify potential safety and security risks . Respond to emergency situations including as sisting the Chautauqua Fire and EMS department. Parking enforcement. Traffic and pedestrian control. Assist with the security of event talent. Staff gate entry points. Security screening of patrons at significant events. About the Referral Program Chautauqua Institution’s Referral Bonus Program is a talent solution to recruit, develop, and retain a diverse workforce that encompasses all the skills and experience necessary to deliver on our goals and objectives. Chautauqua Institution will provide a $500 referral bonus (less taxes) for active employees referring a new candidate who is hired and remains employed for at least 90-days from the first physical date of work. In the case of seasonal positions working less than 6-months, the new candidate must remain actively employed for at least 30-days from the first physical date of work and until the closing date of the season. The closing date of the season is the last Sunday in August. About Your Schedule Chautauqua Institution and Chautauqua Hotel Company offer flexible schedules, full and part-time, for seasonal employment during summer operations starting annually each June and concluding in August. Seasonal employment may be available earlier (pre-season) and beyond season (post-season) based on business needs and candidate availability. Schedules typically include evenings, weekends, and/or holidays as a requirement. While you will confirm your final schedule with management at the time of an interview and offer of employment, you should generally anticipate the following schedule options for this position: Schedules are typically either a four or eight-hour shift with a start time that varies between 7:00 a.m. and 11:00 p.m. for a total of 20-40 hours per week. Scheduled hours may include evenings, weekends, and holidays based on business needs. Work is available pre/post the summer season. About Living on the Grounds No employer-provided housing is available for this position. Applicants should plan to secure independent housing or reside within a commutable distance. About Chautauqua Institution Chautauqua Institution is a not-for-profit global convener of dialogue on the most significant issues of the day through engagement across four pillars of the arts, education, religion, and recreation. The Chautauqua community is located on the shores of Chautauqua Lake in southwestern New York State and comes alive each summer with a unique mix of visual and performing arts, lectures, interfaith worship/programs, and recreational activities. Chautauqua Institution owns and operates Chautauqua Hotel Company , a comprehensive hotel, food & beverage, conferencing, and events organization. Discovering Your Chautauqua Experience There are countless ways that our talent will engage with our mission, vision, and diverse communities, and you are invited to immerse yourself in our programming as a gateway to this experience. Employees will receive a traditional Chautauqua gate pass, free of cost, which provides access to many of our programs at the Amphitheater. Our Commitment to IDEA Chautauqua Institution values Inclusion, Diversity, Equity, and Accessibility (IDEA) as a priority in our strategic plan, 150 Forward . One of our five core values is “The dignity and contributions of all people.” We are committed to creating conditions where everyone can engage as complete and valued participants in the Chautauqua experience. The Institution is an equal-opportunity employer committed to equitable and inclusive hiring practices. Applicants and employees will not be discriminated against based on any status protected under federal, state, or local law. We especially welcome applications from those who can demonstrate experience, engagement, and professional expertise in IDEA. Joining Our Talent Community Join our talent community online at CHQ.org/employment . You are encouraged to learn more about Chautauqua Institution at CHQ.org and view the 150 Forward Strategic Plan at 150fwd.CHQ.org

Posted 2 weeks ago

OpenAI logo
OpenAISan Francisco, California
About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments. We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization. The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. In this role, you will: Perform Security Assessments : Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software. Develop and Implement Security Tools : Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats. Collaborate with Development Teams : Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines. Threat Modeling and Risk Assessment : Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies. Vulnerability Management : Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts. Incident Response Support : Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents. Stay Current on Security Trends : Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications. You might thrive in this role if you: Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles. Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response. Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks. Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods. Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences About OpenAI OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity. We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic. For additional information, please see OpenAI’s Affirmative Action and Equal Employment Opportunity Policy Statement . Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations. To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form . No response will be provided to inquiries unrelated to job posting compliance. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link . OpenAI Global Applicant Privacy Policy At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Posted 30+ days ago

StubHub logo
StubHubLos Angeles, California

$200,000 - $250,000 / year

StubHub is on a mission to redefine the live event experience on a global scale. Whether someone is looking to attend their first event or their hundredth, we’re here to delight them all the way from the moment they start looking for a ticket until they step through the gate. The same goes for our sellers. From fans selling a single ticket to the promoters of a worldwide stadium tour, we want StubHub to be the safest, most convenient way to offer a ticket to the millions of fans who browse our platform around the world. About the team: StubHub Cloud & Infrastructure Security Engineering is seeking a senior engineer to enhance our security posture within the cloud and infrastructure domains. The perfect candidate will possess extensive experience in cloud security architecture, network security, and infrastructure automation, as well as a familiarity with container and operating system security. Location: Hybrid (3 days in office/2 days remote) – New York, NY or Santa Monica, CA or Aliso Viejo, CA What You'll Do: Develop secure Cloud Account Architectures, focusing primarily on AWS, while understanding and navigating the trade-offs of various cloud architectures. Design and implement network security strategies that leverage security groups, NACLS, routing domains, and multi-tiered subnet architectures to ensure a defense-in-depth approach. Manage critical security logging and monitoring infrastructure for cloud-native and third-party data sources, ensuring their efficient shipping to Data Lakes and integration with visualization platforms. Operate and manage Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platforms (CWPP), such as Wiz, Orca, Palo Alto Networks Prisma, and Rapid7 ICS. Deploy configurations and infrastructure using Infrastructure as Code (IaC) frameworks, such as Terraform, Cloud Formation, and Pulumi. Develop and implement governance strategies for infrastructure deployment that integrate security best practices and enhance developer productivity. Architect and implement workload identity services, such as SPIRE (Spiffe), in a heterogeneous multi-cloud environment. Architect and maintain PKI and secrets management platforms to ensure secure storage and access to sensitive information. Write and maintain production-quality APIs to automate security processes, benefiting infrastructure and developer workflows. What You've Done: Expert level experience in AWS cloud account architecture. Expert level knowledge in Network Security, including experience with AWS networking primitives: Security Groups, Network Access Control Lists (NACLS), Subnetting, Routing, and egress traffic filtering mechanisms. Expert level proficiency in Identity & Access Management (IAM) Security, including experience with architecting AWS IAM roles & policy architectures for both human and machine access. Expert level communication skills and the ability to work effectively across teams. Expert level experience deploying and maintaining configurations and infrastructure using Terraform. Expert level experience with modern CSPM and CWPP tools (e.g., Wiz, Orca, Prisma, or Rapid7). Intermediate level experience with Secrets / key Management Platforms (e.g., AWS KMS, AWS Secrets Manager, Hashicorp Vault). Expert level experience in building and implementing IaC governance strategies that combine security best practices while enabling developer productivity. Intermediate level experience in architecting & managing Spire (Spiffe) and Service Mesh services. Intermediate level proficiency in Python or Go, and Bash scripting. Intermediate level experience in container & operating system hardening. Intermediate level experience in building & maintaining Web Application Firewalls. Intermediate level familiarity with security frameworks (e.g., PCI DSS, CIS, ISO 27001, NIST CSF). Preferred Skills and Qualifications: Intermediate level experience in architecting & implementing internal PKI & Secrets Management services. Intermediate level knowledge of Kubernetes (K8s) Security foundations, including admission controllers, K8s Network Policies, K8s RBAC, and K8s Ingress architectures. Intermediate level proficiency in DDoS mitigation techniques using AWS Shield, CDN traffic scrubbing, and origin protection mechanisms. Intermediate level proficiency in Azure. What We Offer: Accelerated Growth Environment : An environment designed for swift skill and knowledge enhancement, where you have the autonomy to lead experiments and tests on a massive scale. Top Tier Compensation Package : Competitive base, equity, and upside that tracks with your impact. Flexible Time Off : Enjoy unlimited Flex Time Off, giving you the flexibility to manage your schedule and take time to recharge as needed. Comprehensive Benefits Package : Prioritize your well-being with a comprehensive benefits package, featuring 401k, and premium Health, Vision, and Dental Insurance options. The anticipated gross base pay range is below for this role. Actual compensation will vary depending on factors such as a candidate’s qualifications, skills, experience, and competencies. Base annual salary is one component of StubHub’s total compensation and competitive benefits package, which includes equity, 401(k), paid time off, paid parental leave, and comprehensive health benefits. Salary Range $200,000 — $250,000 USD About Us StubHub is the world’s leading marketplace to buy and sell tickets to any live event, anywhere. Through StubHub in North America and viagogo, our international platform, we service customers in 195 countries in 33 languages and 49 available currencies. With more than 300 million tickets available annually on our platform to events around the world -- from sports to music, comedy to dance, festivals to theater -- StubHub offers the safest, most convenient way to buy or sell tickets to the most memorable live experiences. Come join our team for a front-row seat to the action. For California Residents: California Job Applicant Privacy Notice found here We are an equal opportunity employer and value diversity on our team. We do not discriminate on the basis of race, color, religion, sex, national origin, gender, sexual orientation, age, disability, veteran status, or any other legally protected status.

Posted 2 weeks ago

Figure logo
FigureSan Jose, California

$150,000 - $350,000 / year

Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot, Figure 02, is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It’s time to build. We are looking for a Security Engineer to join the Security & Privacy team at Figure, focusing on security of the robot as well as associated backend services. We are looking for excellent security engineers who have experience in breaking and building complex software systems, with experience in AI and embedded systems. Responsibilities Conduct security assessments of applications, embedded systems, back-end services, and business integrations, as well as build tooling for a secure development lifecycle Design technical solutions to mitigate security weaknesses on the robot and our service stack. Work with teams across the company to implement them. Build frameworks and systems to prevent classes of vulnerabilities Hunt for vulnerabilities and insecure coding patterns on our product stack (backend services and robot internal systems) Be a champion for security and user privacy Requirements Experience in several of the following application security domains: penetration testing, vulnerability research, security assessment, secure coding practices, security architecture & design, hardware security Strong software engineering (not scripting or automation) skills in C/C++, Rust, Golang, Python or similar Experience with securing embedded systems, including secure boot, secure identity, OTA, or others Solid foundation in web security, mobile security, or cryptography Ability to collaborate with internal and external stakeholders whilst prioritizing tasks and work independently under minimal supervision. BS in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field 3+ years of experience in the field of application security or related security role Passion for learning and helping others Excellent verbal and written communication skills, with high attention to detail The US base salary range for this full-time position is between $150,000 - $350,000 annually. The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components/benefits depending on the specific role. This information will be shared if an employment offer is extended.

Posted 30+ days ago

G logo
Galois, Inc.Arlington, VA
Requirements About Galois Who We Are: Galois tackles the hardest problems in computer science. Our mission is to assure trust in critical systems that protect the privacy and integrity of information in the real world. From building digital engineering tools that make space exploration safer to verifying cryptographic libraries that protect some of the world’s most valuable data, Galois develops technology to guarantee the trustworthiness of systems where failure is unacceptable. What We Do: We believe trustworthy systems are built on a formal mathematical foundation. Our researchers apply formal analysis techniques to the design and verification of critical software systems, allowing us to model, analyze, and mathematically prove that a system behaves exactly as intended under all circumstances. With clients including DARPA, NASA, AWS, and the DoD / DoW, we leverage our cutting-edge research to deliver high assurance solutions and tools that enhance security, reliability, and operational efficiency across sectors including aerospace & defense, healthcare, semiconductors, and fintech. Life at Galois: People are the foundation of Galois’s success. As an employee-owned company, we care not only about the technologies we develop, but also the path we take to create them. Galois operates under a highly collaborative organizational model that encourages leadership and teamwork and respects the individuals. For more on our culture and organizational structure, visit Life at Galois . About the Role The Industrial Security Team Lead/Senior Facility Security Officer (FSO) is responsible for further developing and maintaining Galois’ industrial security program and ensuring company and customer security requirements are met. The successful candidate will lead a team of security professionals across Galois locations and interface with all levels of Galois personnel and government management personnel to ensure contract security compliance with National Industrial Security Operating Manual (NISPOM), Contract Security Classification Specifications (DD254) and Program Classification Guides. The position requires a self-motivated candidate that is capable of leading a distributed team of other security professionals as well as working independently with minimal direction. The FSO must possess the confidence to make critical security decisions concerning high value contracts and to implement security procedures that will prevent unauthorized access to company and government facilities or information. The candidate will be required to conduct security self-inspections, apply risk mitigation methodologies, support customer assessments, and implement security measures to meet requirements. Responsibilities Report directly to Galois’ General Counsel and other senior level executives on security matters across the organization Lead and collaborate with other Galois’ FSOs to establish and maintain facility and information security requirements across all Galois facilities. Provide oversight and direction to other Galois functional areas on security related matters. Manage and maintain compliance with the industrial security program for Galois’ Arlington, VA facility in accordance with the NISPOM as well as other secure areas and facilities (Open Storage Spaces (OSS)), as needed including preparing and maintaining accreditation documentation for each (e.g. UL certifications, open storage area approval checklists, and mitigation plans). Use 32 CFR 2001.53 and other technical specifications to design new secure spaces or develop modifications and construction security plans for secure areas based on their accreditation status and Sponsor requirements as needed. Account for, control, transmit, package and safeguard COMSEC information and administer periodic software and cryptographic key updates. Support IT staff in maintaining appropriate accreditation documentation for all information systems within Galois secure areas and address any shortcomings. Implement OPSEC plans as needed. Conduct security self-inspections, apply risk mitigation methodologies, support customer assessments, and implement security measures to meet emerging requirements. Conduct Personnel Security processing actions including requesting, reviewing, approving, and submitting clearances packages up to and including SCI nomination Process Prime and Sub DD254s. Escort uncleared personnel and visitors. Generate and oversee a security education training and awareness program for Galois staff Ensure proper protection and corrective measures are taken when an incident or vulnerability is discovered. Support Galois technical staff via coordination and visitor management (e.g., sending and receiving clearances through visitor approval requests (VARs)). Key Qualifications 8 to 10 years of experience working in Industrial Security, Special Programs, security management, military or government information security programs. 5 to 7 years experience leading a team of experienced security professionals. Active and transferable U.S. government issued TS/SCI security clearance prior to state date. Willingness to pursue a polygraph if needed. Candidates must be professional, capable of independent engagement, and skilled in leading and collaborating with peers and personnel both within the security team and without. Candidates must be highly organized with excellent communication, time management, and multitasking skills. Expert understanding of and experience implementing 32 CFR Part 117 (NISPOM). Strong understanding of physical security requirements for collateral Restricted Areas. Thorough understanding and working experience with government and corporate security databases such as NISS, DISS, eAPP, etc. Experience creating, modifying, and conducting initial security briefings, debriefings, indoctrinations, pre/post foreign travel briefings, and refresher briefings. Ability to develop and establish an effective security awareness, training, and education program. Assist in executing the requirements set forth in the Technology Control Plan (TCP) for foreign visitors. Demonstrable experience influencing both technical and non-technical personnel on policies, practices and procedures. Demonstrable experience communicating information security and risk-related concepts effectively to both technical and non-technical audiences. Completion of all required FSO training courses with certificate of successful completion for possessing facilities from DCSA. Experience working in Special Programs and Sensitive Compartmented Information operations. Willingness to regularly travel to other Galois locations to oversee the set-up of new secure areas and/or collaborate with other Galois security professionals. Preferred Qualifications: Prior ISSO/ISSM experience CSSO training certificate CPSO training certificate Understanding of physical security requirements for OSS, SAP, and SCIF areas. Ability to manage and maintain compliance with the industrial security program for Special Access Programs (SAP) and Sensitive Compartmented Information Facilities (SCIF)) as needed including preparing and maintaining accreditation documentation for each (e.g. UL certifications, open storage area approval checklists, TEMPEST checklists, and mitigation plans). Location This role requires the ability to work in-person from Galois' office location in Arlington, VA. Compensation and Benefits Compensation is based on the value of your results, not your value as an employee or person. The compensation process, individual salaries, and criteria for salary changes are transparent to the entire company. For more information about our forward-looking and transparent approach to pay, visit this page . We offer a robust benefits package to provide for your and your family’s well-being, including: Employee Stock Ownership Plan (ESOP) 401(k) retirement plan with 5% employer match and immediate vesting Fully paid medical insurance plans and dental and vision reimbursement plan Health Savings Account (HSA) with generous employer contributions Mental health and wellbeing support through our employee assistance program 5 weeks of paid time off and 9 days of paid company holidays each year 16 weeks of fully paid parental leave (available for birth, adoption, and fostering) 1 week of fully paid “Blue Sky” innovation time each year to pursue your interests For more information on our benefits, visit our Careers page . Equal Employment Opportunity Galois is an Equal Opportunity Employer and does not discriminate in employment opportunities or practices based on disability, veteran status, or any other characteristic protected by applicable federal, state, or local law. Consistent with the Americans with Disabilities Act (ADA) and federal and state laws, it is the policy of Galois, Inc. to provide reasonable accommodation when requested by a qualified applicant or employee with a disability, unless such accommodation would cause an undue hardship. If you require reasonable accommodation in completing the employment application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please contact peopleoperations@galois.com.

Posted 30+ days ago

A logo
AG Consulting Partners, Inc.Seattle, WA

$160,000 - $250,000 / year

We are actively seeking two senior candidates who are authorized to work in the United States without visa sponsorship or E-Verify requirements. This role is fully onsite, five (5) days per week, and candidates must be located within a commutable distance (approximately 30 miles) of the client campus in downtown Seattle, WA . Role Overview The ideal candidate brings deep domain expertise and is able to articulate decision rationale effectively, contributing to the development of both technical and business solutions. As a recognized subject matter expert, the Hardware Security Engineer is frequently consulted on cross-functional initiatives and operates independently with minimal oversight. This role earns trust and respect from engineering teams and senior stakeholders through consistent leadership, accountability, and strategic insight, while ensuring delivery excellence across the program lifecycle. Please note: This is a 12-month engagement and requires being onsite five (5) days per week in Seattle, WA . Candidates must reside within a 30-mile radius of the client campus and be authorized to work in the U.S. without sponsorship. As a Hardware Security Engineer for AG Consulting Partners, a typical day might include the following: Analyzing System-on-a-Chip (SoC) security architectures to validate secure boot chains, root-of-trust enforcement, anti-rollback protections, and cryptographic controls at the silicon level. Validating hardware security requirements through hands-on testing of physical devices, evaluation boards, and chip samples across development and production lifecycles. Executing hardware security testing techniques, including fault injection attempts, debug interface probing (JTAG/BDM), and resistance validation against physical attacks. Reviewing schematics, board layouts, and hardware designs to ensure correct implementation of secure key storage, tamper mitigations, and debug access restrictions. Verifying manufacturing security processes by assessing secure provisioning flows, key injection procedures, and production lifecycle state transitions. Inspecting manufactured hardware samples to detect unauthorized component substitution, malicious modification, or deviations from approved security designs. Assessing cryptographic implementations (RSA, AES, HMAC, PQC) embedded in hardware and firmware to confirm secure key handling and isolation. Collaborating with silicon vendors, OEMs, and manufacturing partners to remediate security findings and validate corrective actions at the device and chip level. Identifying systemic hardware security risks by correlating lab results, manufacturing data, and field observations across large-scale device deployments. Documenting security assessments, validation outcomes, and risk mitigation plans in technical reports and communicating findings to engineering and leadership stakeholders. This job is for you if you: You love turning ambiguous, cross-functional ideas into clear roadmaps and driving them through to delivery across multiple workstreams. You are energized by influencing without authority and building strong, trust-based relationships with senior leaders, engineers, and business partners. You are comfortable diving into complex technical domains, asking sharp questions, and connecting the dots between infrastructure, applications, data, and operations. You instinctively think in metrics and outcomes, using data to guide decisions, manage risk, and measure program success. You thrive in a matrixed environment, calmly navigating competing priorities, resolving conflict, and keeping stakeholders aligned. You care deeply about operational excellence and service quality, and you design programs with the end customer and long-term sustainability in mind. You enjoy working independently with high ownership, while actively fostering transparency, collaboration, and accountability across teams. Requirements You have: 5+ years of experience in hardware security, embedded systems security, or similar Bachelor's degree in Electrical Engineering, Computer Engineering, Computer Science, or related technical field Strong knowledge of secure boot implementations, cryptography (RSA, AES, HMAC, PQC), and hardware security architectures (e.g. ARM TrustZone or Intel SGX) Experience with manufacturing security processes, including secret provisioning and secure production flows Knowledge of debug interface security (JTAG, BDM), anti-rollback mechanisms, and fault injection protection Familiarity with circuit design, physical attack mitigation techniques, and consumer electronic devices Experience with hardware security testing tools and methodologies You might also have: Master's degree in relevant technical field or equivalent advanced experience Experience with DRM implementations and content protection systems Knowledge of side-channel attack analysis and associated countermeasures Experience with penetration testing or hacking consumer electronic devices Experience writing technical documents, project plans and progress reports to leadership and to stakeholders Benefits AG Consulting Partners, Inc. is a Redmond-based boutique consulting firm. Our mission is to embrace the entrepreneurial spirit to relentlessly deliver an exceptional experience and results for our people and our clients. We take care of our people. Our excellent benefits to full-time employees include competitive salary, medical, dental, vision, PTO, 401k matching, education reimbursement, wellness allowances, community and philanthropic events, and flexible career paths. See what our employees have to say about our company Working at AG Consulting Partners | Glassdoor We’re humbled to be consistently acknowledged by local and national organizations for our success, including Consulting Magazine, Puget Sound Business Journal, and Inc. 5000. We look forward to welcoming you to our team of amazing consultants and partners! Learn more about our firm at https://agconsultingpartners.com Note: Applicants must be authorized to work for any employer in the U.S. We are unable to provide assistance or sponsorship for employment Visas and Visa extensions at this time. The compensation for this position is tailored to reflect your unique skill set, relevant experience, and the current dynamics of the job market. We strive to ensure that our compensation package is competitive and fair, taking into account various factors to provide a rewarding opportunity for our team members. The annual salary range for this role is: $160,000 - 250,000 annual (W2 on top of benefits)

Posted 3 weeks ago

Ramp logo
RampNew York City, New York
About Ramp At Ramp, we’re rethinking how modern finance teams function in the age of AI. We believe AI isn’t just the next big wave. It’s the new foundation for how business gets done. We’re investing in that future — and in the people bold enough to build it. Ramp is a financial operations platform designed to save companies time and money. Our all-in-one solution combines payments, corporate cards, vendor management, procurement, travel booking, and automated bookkeeping with built-in intelligence to maximize the impact of every dollar and hour spent. More than 50,000 businesses, from family-owned farms to e-commerce giants to space startups, have saved $10B and 27.5M hours with Ramp. Founded in 2019, Ramp powers the fastest-growing corporate card and bill payment platform in America, and enables over $100 billion in purchases each year. Ramp’s investors include Lightspeed Venture Partners, Thrive Capital, Sands Capital, General Catalyst, Founders Fund, Khosla Ventures, Sequoia Capital, Greylock, Redpoint, and ICONIQ, as well as over 100 angel investors who were founders or executives of leading companies. The Ramp team comprises talented leaders from leading financial services and fintech companies—Stripe, Affirm, Goldman Sachs, American Express, Mastercard, Visa, Capital One—as well as technology companies such as Meta, Uber, Netflix, Twitter, Dropbox, and Instacart. Ramp has been named to Fast Company’s Most Innovative Companies list and LinkedIn’s Top U.S. Startups for more than 3 years, as well as the Forbes Cloud 100 , CNBC Disruptor 50 , and TIME Magazine’s 100 Most Influential Companies . About the Role Ramp’s Enterprise Security team is responsible for keeping our people, data, and internal tools safe while enabling a fast‑moving, AI‑driven business. As a Senior Security Analyst (Corporate Security) , you’ll own and scale core security programs across identity, endpoints, SaaS, and data. You’ll be the primary driver for Insider Risk, DLP, SaaS posture, and endpoint security across both our corporate and FedRAMP‑aligned environments—designing strategy, implementing controls, and measuring outcomes. Ramp is agent‑first: we rely heavily on AI assistants and automated workflows. You’ll ensure those capabilities are securely rolled out to the business, not blocked. Hybrid in NYC: This role is based in New York City and requires working in‑person at our HQ (near Madison Square Park) at least 2 days per week . This is a senior, hands‑on individual contributor role (IC5), not a people‑management or SOC Tier 1 position. What You’ll Do Own core enterprise security programs Lead and continuously improve Insider Risk and DLP across Ramp—from policies and detections to playbooks, case handling, and stakeholder training. Secure SaaS at scale Manage and harden our SaaS stack (SSPM/CASB and native controls): Remediate misconfigurations Remove stale accounts/admins Enforce key rotation and safe OAuth scopes Gate risky apps and integrations Run sovereign / FedRAMP‑aligned environments Operate sovereign Google Workspace and Okta tenants with strict access, monitoring, and logging. Partner with GRC to ensure controls align to NIST 800‑53/800‑171 and FedRAMP‑aligned requirements without slowing down the business. Modernize identity & access Work with IT and Security Engineering to enforce: Phishing‑resistant MFA Device‑aware and context‑aware access Least privilege and just‑in‑time (JIT) patterns SCIM‑based lifecycle management Strong break‑glass access patterns and reviews Harden endpoints and network Help keep our macOS and Windows fleets secure at scale using EDR, MDM, and disk encryption; drive patch SLAs; and enforce ZTNA/SSE policies (e.g., Cloudflare WARP) for secure access to internal resources. Measure, review, and improve Define and track key metrics (coverage, policy efficacy, MTTD/MTTR, configuration drift). Run regular control health reviews and drive remediation with partner teams. Automate and simplify Use scripting, APIs, or workflow tools to reduce manual toil in enterprise security operations (e.g., account hygiene, access reviews, configuration checks, alert triage). Partner & communicate Collaborate closely with IT, Engineering, Legal, People, and GRC. Write clear docs, runbooks, and decision records that make it easy for others to operate and build on your work. What You Need Experience level 3+ years in enterprise/corporate security engineering or operations, with hands‑on ownership of security controls for identity, endpoints, SaaS, or data. You’re comfortable being the primary owner of programs, not just following an existing playbook. Eligibility U.S. citizenship is required for this role due to the nature of our sovereign / FedRAMP‑aligned environments. Technical background Practical experience implementing and tuning Insider Risk, DLP, SaaS posture, or endpoint security in a cloud‑first environment. Hands‑on administration of a modern identity provider and collaboration suite— Okta and Google Workspace are ideal , but similar experience (e.g., Azure AD / Entra ID, Microsoft 365) is highly relevant. Familiarity with tools and concepts like EDR, MDM, SSPM/CASB, DSPM, and ZTNA/SSE , and experience hardening macOS and/or Windows at scale. Experience aligning controls to at least one security framework or regulated environment (e.g., FedRAMP, NIST 800‑53/171, SOC 2, ISO 27001 ) and translating requirements into practical enterprise controls. How you work You can spot gaps, design pragmatic remediations, and drive them to completion across multiple teams. You’re comfortable using automation (scripts, workflows, or low‑code tools) to make security more scalable and less manual. You communicate clearly—whether you’re writing a runbook, summarizing risk tradeoffs, or explaining a control choice to non‑security partners. You enjoy partnering with IT and Engineering to get things shipped, not just documented. Nice-to-Haves Experience operating sovereign or public‑sector / regulated tenants (e.g., FedRAMP, StateRAMP, or similar). Background scaling security in a high‑growth, cloud‑first startup or scale‑up environment (ideal but not required ). Experience securing or enabling AI/agent workflows inside an enterprise. Intermediate scripting skills (e.g., Python, Bash, PowerShell) for automation and integrations. Relevant certifications (e.g., CISSP, CISM, Security+, GIAC ) or equivalent real‑world depth. Benefits (for U.S.-based full-time employees) 100% medical, dental & vision insurance coverage for you Partially covered for your dependents One Medical annual membership 401k (including employer match on contributions made while employed by Ramp) Flexible PTO Fertility HRA (up to $5,000 per year) WFH stipend to support your home office needs Wellness stipend Parental Leave Relocation support to NYC or SF (as needed) Pet insurance Referral Instructions If you are being referred for the role, please contact that person to apply on your behalf. Other notices Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. Ramp Applicant Privacy Notice

Posted 2 weeks ago

OpenAI logo

Security Engineer, Application Security

OpenAINew York City, NY

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Job Description

About the Team

Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI's technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.

About the Role

As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.

We're looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.

The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.

In this role, you will:

  • Perform Security Assessments: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.

  • Develop and Implement Security Tools: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.

  • Collaborate with Development Teams: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.

  • Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.

  • Vulnerability Management: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.

  • Incident Response Support: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.

  • Stay Current on Security Trends: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.

You might thrive in this role if you:

  • Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.

  • Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.

  • Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.

  • Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.

  • Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences

About OpenAI

OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.

We are an equal opportunity employer, and we do not discriminate on the basis of race, religion, color, national origin, sex, sexual orientation, age, veteran status, disability, genetic information, or other applicable legally protected characteristic.

For additional information, please see OpenAI's Affirmative Action and Equal Employment Opportunity Policy Statement.

Background checks for applicants will be administered in accordance with applicable law, and qualified applicants with arrest or conviction records will be considered for employment consistent with those laws, including the San Francisco Fair Chance Ordinance, the Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act, for US-based candidates. For unincorporated Los Angeles County workers: we reasonably believe that criminal history may have a direct, adverse and negative relationship with the following job duties, potentially resulting in the withdrawal of a conditional offer of employment: protect computer hardware entrusted to you from theft, loss or damage; return all computer hardware in your possession (including the data contained therein) upon termination of employment or end of assignment; and maintain the confidentiality of proprietary, confidential, and non-public information. In addition, job duties require access to secure and protected information technology systems and related data security obligations.

To notify OpenAI that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance.

We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this link.

OpenAI Global Applicant Privacy Policy

At OpenAI, we believe artificial intelligence has the potential to help people solve immense global challenges, and we want the upside of AI to be widely shared. Join us in shaping the future of technology.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall