<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>11b88e19-a73</externalid>
      <Title>Data Centre Security Compliance Public Sector Specialist</Title>
      <Description><![CDATA[<p>About Us</p>
<p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world&#39;s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</p>
<p>We protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks.</p>
<p>Key Responsibilities</p>
<p><strong>Public Sector &amp; Compliance Governance</strong></p>
<ul>
<li>Serve as the Subject Matter Expert (SME) on NIST 800-53 control families and FedRAMP requirements.</li>
<li>Manage Cloudflare&#39;s continuous monitoring program, inclusive of annual assessments and significant change requests.</li>
<li>Collect, validate, and organize FedRAMP evidence and artifacts to present to auditors, FedRAMP customers, and the FedRAMP PMO.</li>
<li>Help guide our overall security policy and governance architecture to ensure alignment with evolving government regulations.</li>
</ul>
<p><strong>Audit Lifecycle Management</strong></p>
<ul>
<li>Orchestrate end-to-end audit activities for standards such as PCI, SOC2, ISO, NIST, and FedRAMP.</li>
<li>Coordinate with auditors to manage data center access, compliance certificate collection, and evidence defense.</li>
<li>Work cross-functionally with Engineering, Legal, Product, and Operational teams to maintain management and technical controls.</li>
<li>Support compliance and regulatory projects, including implementation of new legislation / regulation.</li>
</ul>
<p><strong>Identity &amp; Access Management (IAM) Operations</strong></p>
<ul>
<li>Execute monthly Periodic Access Reviews (PARs): Compare portal user lists against ACLs to ensure least-privilege access is maintained across all data centers.</li>
<li>Manage the lifecycle of portal access: Auditing access, provisioning/deprovisioning users, and maintaining accurate documentation.</li>
<li>Oversee physical access requests to data centers and ensure strict adherence to security policies.</li>
<li>Drive the resolution of daily DCSC Jira tickets for portal access, physical access, audits, and site decommissioning.</li>
<li>Automate and streamline access review processes where possible, utilizing standard communication templates to site managers.</li>
</ul>
<p><strong>Partner Relations &amp; Reporting</strong></p>
<ul>
<li>Own, influence, and orchestrate relationships within the partner Offering teams that can help drive Cloudflare offerings and strategic positioning.</li>
<li>Monitor and implement changes to individual accountability regime requirements (such as UK, Ireland, Singapore and Australia).</li>
<li>Maintain centralized documentation, databases, dashboards, and reporting mechanisms to track compliance health.</li>
</ul>
<p>Requirements</p>
<ul>
<li>3-6 years working in Security Compliance, Information Security, or Risk Management.</li>
<li>Deep familiarity with all NIST 800-53 control families and FedRAMP requirements.</li>
<li>Ability to work closely with auditors and articulate technical concepts.</li>
<li>Experience in auditing of network, operating system, and application security.</li>
<li>Proven experience managing an audit throughout the full audit lifecycle (from readiness to final report).</li>
<li>Familiarity with additional security standards and frameworks such as ISO 27000, SOC 2, PCI DSS, ISMAP and IRAP.</li>
<li>Ability to work cross-functionally with internal stakeholders and strong communications skills.</li>
<li>High tolerance for ambiguity and ability to work efficiently and independently in a fast-paced, high-volume environment.</li>
<li>Some travel may be required to engage with regulators and auditors.</li>
<li>Certifications: CISSP, CIPP, CIPM, CIPT, CISA, or CRISC.</li>
<li>A relevant professional experience working with technology partners, alliances, or third-party vendors, ideally in the following disciplines: Data center Security Compliance, Access Management, audit administration at a leading high-tech company; offering management.</li>
<li>Technical skills including the ability to understand (1) product roadmaps; (2) market trends and factors; and (3) complex partner requirements.</li>
<li>Strong technical proficiency with spreadsheet software (Excel/Google Sheets) including pivot tables and VLOOKUPs for data reconciliation.</li>
<li>Organized &amp; Disciplined, with a strong focus on driving outcomes.</li>
</ul>
<p>Preferred</p>
<ul>
<li>Prior experience with Data Centre Security Compliance disciplines and audit programs and past history working at a hyperscaler or high-growth tech company.</li>
<li>Superb organizational skills and demonstrated history managing complex processes including audit cycles, Facts gathering and analytical skills.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>NIST 800-53 control families, FedRAMP requirements, Identity &amp; Access Management (IAM), Audit Lifecycle Management, Security Compliance, Information Security, Risk Management, CISSP, CIPP, CIPM, CIPT, CISA, CRISC, Data center Security Compliance, Access Management, audit administration, product roadmaps, market trends and factors, complex partner requirements</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Cloudflare</Employername>
      <Employerlogo>https://logos.yubhub.co/cloudflare.com.png</Employerlogo>
      <Employerdescription>Cloudflare operates one of the world&apos;s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</Employerdescription>
      <Employerwebsite>https://www.cloudflare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/cloudflare/jobs/7477769</Applyto>
      <Location>Hybrid</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>734f15ea-25f</externalid>
      <Title>Corporate Counsel – Privacy Commercial</Title>
      <Description><![CDATA[<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>
<p>Accelerate your career by joining Okta, the World’s Identity Provider, as a member of our Cybersecurity &amp; Privacy Legal team. We free everyone to safely use any technology , anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.</p>
<p>As Corporate Counsel – Privacy Commercial, you will lead a small privacy commercial team responsible for advising and supporting commercial legal and sales organisations on privacy and data protection, primarily drafting and negotiating data processing addenda, information security exhibits and related commercial documents with some of the biggest names across every industry that trust Okta to help their organisations work faster, boost revenue and stay secure.</p>
<p>You will work on cutting-edge projects in a cloud-first, SaaS environment where you can apply your experience providing strong legal support to help Okta deliver world-class products to our thousands of global customers.</p>
<p>Responsibilities: Advise, draft and negotiate privacy and data protection terms associated with outbound cloud service Master Subscription Agreements, Data Processing Addenda, Information Security Exhibits and other documentation related to sales transactions, while partnering closely with Okta’s Commercial Legal team. Provide day-to-day legal support surrounding privacy and data protection-related contract requests and respond promptly and effectively to legal questions from internal clients with pragmatic and business-oriented guidance. Support the procurement team in drafting and negotiating privacy and data protection-related terms associated with vendor agreements. Support the investigation of potential privacy and security incidents, including analysing relevant legal and regulatory responsibilities, and providing guidance to internal clients on mitigation, remediation, and resolution efforts. Develop, implement and maintain standards, processes, runbooks and guidance surrounding privacy and data protection-related issues for Go-to-Market transactions, and partnering closely with members of the Legal, Security, Compliance and Engineering teams, among other key stakeholders. Build critical relationships in order to effectively provide practical and strategic advice to assist the business in meeting its objectives, while ensuring privacy and information security compliance. Advise on recommended courses of action and legal risk, with the ability to judge when to escalate identified issues as appropriate. Assist in the maintenance and review of various privacy and security programs and processes, including updates to privacy and security policies, plans, procedures, standards, certifications and customer-facing documentation. Ensure compliance with all applicable global privacy and data protection laws, such as the General Data Protection Regulation, United States’ federal and state regulations and other global legal frameworks by monitoring and staying up to speed and a thought leader on global privacy and data protection laws and frameworks. Maintain an understanding of technical controls and assist in the creation of audit and monitoring frameworks to support stable, controlled operations. Review privacy and data protection-related marketing and other external communications content for accuracy and completeness. Support the management of outside counsel and consultants and contribute to other interesting legal projects, as needed.</p>
<p>Requirements: 4+ years of relevant law firm and/or in-house experience, including at least 2 years working primarily on privacy and data protection-related transactional matters, preferably at a SaaS technology company. Familiarity and comfort with the culture of a fast-paced enterprise software company and knowledge of SaaS products. Experience working with highly-regulated customers, especially those in the financial services industry, preferred. Excellent written and verbal communication, presentation, drafting and negotiation skills. Sound and practical legal and business judgment, as well as the ability to think strategically and develop strong working relationships with key internal clients. Knowledge in global privacy, data protection and security frameworks, including GDPR, CCPA, CPRA, HIPAA, NIST, ISO, FedRAMP and PCI-DSS. Ability to maintain strong working relationships with a variety of internal clients and business partners from a variety of functions. A self-motivated individual with grit who takes initiative and is comfortable rolling up their sleeves. Team-oriented with a sense of humour and high emotional intelligence. Ability to organise, prioritise and manage deadlines. Strong academic background and J.D. from highly-regarded school. Certified Information Privacy Professional (Europe, U.S., Canada and/or Asia) or Certified Information Privacy Manager is a plus.</p>
<p>Benefits: The annual base salary range for this position for candidates located in Ireland is between €115,000-€158,000 EUR. Okta offers equity (where applicable), bonus, and comprehensive healthcare coverage and financial benefits including paid time off and parental leave in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit: https://rewards.okta.com/irl.</p>
<p>The Okta Experience: Supporting Your Well-being Driving Social Impact Developing Talent and Fostering Connection + Community</p>
<p>We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, colour, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants &amp; Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice. Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at https://www.okta.com/legal/personnel-policy.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>legal, privacy, data protection, GDPR, CCPA, CPRA, HIPAA, NIST, ISO, FedRAMP, PCI-DSS</Skills>
      <Category>Legal</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a software company that provides identity and access management solutions.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7657666</Applyto>
      <Location>Dublin, Ireland</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>361c2ea1-943</externalid>
      <Title>Federal Senior Security Assurance Engineer</Title>
      <Description><![CDATA[<p>As a Senior Security Assurance Engineer, you will help lead compliance certification efforts for the U.S. Federal Government, such as FedRAMP, DISA CC SRG, etc. You will develop Databricks ATO packages, ensure audit readiness and security compliance across the organisation by working cross-functionally with other teams, collect and manage evidence for audits, lead continuous monitoring and authorisations, support other Security Assurance Team certifications, reports, and activities as needed, support security compliance reviews of new features, build relationships with other Databricks teams to accomplish Security Assurance goals, and develop and maintain strong relationships with external auditors and certification bodies to facilitate smooth audit processes.</p>
<p>The ideal candidate will have a Bachelor&#39;s degree in Computer Science or a related field, or equivalent experience, with 5+ years of security compliance or audit-related experience, FedRAMP and/or DISA SRG auditing (3PAO) or implementation (CSP) experience, NIST 800-53 and RMF experience, a comprehensive understanding of security controls across all domains, a general understanding of key technical security controls in cloud environments (AWS, Azure, GCP), strong written and verbal communication skills, and experience working effectively across the spectrum of individual contributors and senior leadership within an organisation.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>FedRAMP, DISA CC SRG, NIST 800-53, RMF, Cloud security, Security compliance, Audit management</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a data intelligence platform to unify and democratize data, analytics, and AI. It has over 10,000 organisational clients worldwide.</Employerdescription>
      <Employerwebsite>https://databricks.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/8435970002</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>9863df78-b6e</externalid>
      <Title>Renewals Manager, Public Sector</Title>
      <Description><![CDATA[<p>As a Renewal Manager, you will help GitLab retain and grow a complex book of US Public Sector accounts across Federal, State and Local, and Education customers. This role sits at the intersection of customer success and sales.</p>
<p>You will own the renewal process from early outreach through booking, mitigate renewal risk before it becomes urgent, and identify opportunities for expansion, services, and training that deepen customer value. You will work closely with Account Executives, Customer Success Managers, and distributor and channel partners to deliver accurate, on-time renewals in a fast-moving remote environment.</p>
<p>This is a strong fit if you enjoy managing a high volume of work with precision, operating effectively in a remote environment, and helping customers navigate complex procurement and compliance requirements.</p>
<p>In your first year, you will build trust across your book of business, bring discipline to pipeline and forecasting, and create consistent renewal motions that support customer success, risk mitigation, and long-term adoption of GitLab in the US public sector.</p>
<p>Responsibilities:</p>
<ul>
<li>Own the full renewal cycle for a high-volume portfolio of US Public Sector accounts, from early engagement through quoting, negotiation, procurement, and booking.</li>
</ul>
<ul>
<li>Manage renewal quotes, order forms, and amendments in alignment with GitLab policies and public sector procurement requirements, including FedRAMP considerations and relevant contracting vehicles.</li>
</ul>
<ul>
<li>Maintain accurate pipeline and forecast data in Salesforce, including stages, close dates, amounts, and risk status.</li>
</ul>
<ul>
<li>Assess adoption signals, usage trends, and customer context to identify renewal risk early. Build and track mitigation plans with account teams and customer success partners, with clear owners, timelines, and next steps.</li>
</ul>
<ul>
<li>Coordinate customer check-ins focused on realized value, deployment health, and upcoming renewal milestones.</li>
</ul>
<ul>
<li>Identify opportunities for expansion, cross-sell, professional services, training, and consolidation within your book of business.</li>
</ul>
<ul>
<li>Work cross-functionally with Account Executives, Customer Success Managers, Solution Architects, Professional Services, distributors, and channel partners to move renewals and growth opportunities forward.</li>
</ul>
<p>Requirements:</p>
<ul>
<li>Experience owning renewals, account management, or customer success motions for complex SaaS accounts in a customer-facing B2B environment.</li>
</ul>
<ul>
<li>Experience working through a distributor or channel partner ecosystem, with the ability to manage the commercial and relationship complexity of partner-led transactions.</li>
</ul>
<ul>
<li>Familiarity with the US Public Sector, including Federal, State, Local, or Education buying processes, contracting vehicles, and compliance-related requirements.</li>
</ul>
<ul>
<li>Excellent organizational skills with the ability to manage many concurrent opportunities, stakeholders, and deadlines while maintaining accuracy.</li>
</ul>
<ul>
<li>Proficiency using Salesforce or a similar CRM platform for pipeline management, forecasting, and activity tracking.</li>
</ul>
<ul>
<li>Working knowledge of contract renewal processes and tools such as CPQ tools, subscription management systems, or billing platforms.</li>
</ul>
<ul>
<li>Clear written and verbal communication skills for customers, partners, and internal stakeholders, including executive audiences.</li>
</ul>
<ul>
<li>A self-directed and team-oriented approach, with the ability to work effectively in a fully remote, asynchronous environment.</li>
</ul>
<p>About the team:</p>
<p>The US Public Sector team enables government and education organizations as they modernize how they build and deliver software. We work with customers navigating complex procurement environments while helping them adopt GitLab as the one DevSecOps platform , improving collaboration, reducing manual processes, and delivering secure software faster.</p>
<p>We partner closely across sales, customer success, services, and the channel ecosystem, operating asynchronously in a remote environment to support public sector missions with consistency and transparency.</p>
<p>A key focus is helping agencies and institutions balance security, compliance, and operational efficiency as they scale digital transformation with GitLab.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$59,500-$105,000 USD</Salaryrange>
      <Skills>Renewals management, Account management, Customer success, Salesforce, CPQ tools, Subscription management systems, Billing platforms, FedRAMP, Public sector procurement</Skills>
      <Category>Sales</Category>
      <Industry>Technology</Industry>
      <Employername>GitLab</Employername>
      <Employerlogo>https://logos.yubhub.co/about.gitlab.com.png</Employerlogo>
      <Employerdescription>GitLab is an intelligent orchestration platform for DevSecOps, trusted by over 50 million registered users and more than 50% of the Fortune 100.</Employerdescription>
      <Employerwebsite>https://about.gitlab.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/gitlab/jobs/8470271002</Applyto>
      <Location>Remote, US</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>38a5c86c-54e</externalid>
      <Title>Senior Compliance Engineer</Title>
      <Description><![CDATA[<p>JOB TITLE: Senior Compliance Engineer LOCATION: Costa Mesa, California, United States DEPARTMENT: Corporate Technology : Information Security : Corporate Assurance</p>
<p>As a Senior Compliance Engineer at Anduril Industries, you will be responsible for driving automation, compliance, and security engineering principles into the design, integration, and operation of Anduril&#39;s internal systems. This is a technically hands-on role that requires a strong DevSecOps background with deep expertise in cloud infrastructure security, embedded systems security, and federal compliance frameworks.</p>
<p><strong>Key Responsibilities</strong></p>
<ul>
<li>Design, develop, and maintain Infrastructure as Code (IaC) and Policy as Code (PaC) that enforce compliance with NIST SP 800-171 and 800-53, CMMC, and other applicable frameworks, enabling developers to deploy CMMC-certified applications using pre-packaged, compliant infrastructure templates.</li>
<li>Architect, build, and deploy robust, scalable security controls across Anduril&#39;s corporate, development, and production cloud environments (AWS, Azure, GCP) and on-premise environments.</li>
<li>Develop and automate IaC pipelines for managing and scaling cloud deployments securely and efficiently, including automated pipelines for deploying infrastructure, applications, and updates.</li>
<li>Build automation for procedural compliance controls, generating compliance and audit artifacts at scale without manual intervention.</li>
<li>Develop security models that integrate Continuous Monitoring (ConMon), DISA STIG scanning, and compliance reporting into a unified, automated workflow.</li>
</ul>
<p><strong>Compliance Engineering &amp; Framework Implementation</strong></p>
<ul>
<li>Analyze, interpret, and operationalize federal and industry cybersecurity regulations, including NIST SP 800-171 and 800-53, CMMC, FedRAMP, and SOC 2, translating regulatory language into actionable engineering guidance and enforceable technical controls.</li>
<li>Evaluate system architectures and configurations to ensure alignment with required security controls for moderate-impact information systems.</li>
<li>Interface directly with infrastructure teams to verify and enforce compliance across existing on-premise and cloud stacks, identifying gaps and driving remediation.</li>
</ul>
<p><strong>Cross-Functional Collaboration &amp; Enablement</strong></p>
<ul>
<li>Partner with engineers, the DevSecOps Team, and the Automation Team to implement and verify security controls in both corporate and product software environments.</li>
<li>Act as a force multiplier by embedding security best practices into the workflows of infrastructure, application, and product teams, particularly for environments holding mission-critical data.</li>
</ul>
<p><strong>Strategic &amp; Advisory</strong></p>
<ul>
<li>Develop strategies and implementation plans for compliance-related matters, advising management on risk posture, regulatory changes, and investment priorities.</li>
<li>Institute best-practice procedures for compliance and risk mitigation across the organization.</li>
</ul>
<p><strong>Required Qualifications</strong></p>
<ul>
<li>3+ years of professional experience in Cloud Security, DevSecOps, Site Reliability Engineering (SRE), or a related security engineering role.</li>
<li>Background in one or more of the following disciplines: Systems Security Engineering, Cybersecurity, Systems Engineering, Software Engineering, Computer Engineering, or Computer Science.</li>
<li>Proven experience building and securing complex cloud environments at scale.</li>
<li>3+ years of hands-on experience working with compliance frameworks such as CMMC, NIST SP 800-171 and/or 800-53, and FedRAMP.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Cloud Security, DevSecOps, Site Reliability Engineering, Systems Security Engineering, Cybersecurity, Systems Engineering, Software Engineering, Computer Engineering, Computer Science, Compliance Frameworks, NIST SP 800-171, NIST SP 800-53, CMMC, FedRAMP</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anduril Industries</Employername>
      <Employerlogo>https://logos.yubhub.co/anduril.com.png</Employerlogo>
      <Employerdescription>Anduril Industries is a defense technology company that designs, builds, and sells advanced technology systems for the U.S. and allied military.</Employerdescription>
      <Employerwebsite>https://www.anduril.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/andurilindustries/jobs/5087188007</Applyto>
      <Location>Costa Mesa, California, United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>b5ce114e-dac</externalid>
      <Title>Cloud Engineer – Factory Systems and Operational Technology</Title>
      <Description><![CDATA[<p>Anduril Industries is a defence technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology and business model of the 21st century&#39;s most innovative companies to the defence industry, Anduril is changing how military systems are designed, built and sold.</p>
<p>The company&#39;s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a real-time, 3D command and control centre.</p>
<p>As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion and networking technology to the military in months, not years.</p>
<p>We are seeking a mission-driven Cloud Infrastructure Engineer to take a leading role in designing and implementing world-class defensive controls. This is a high-impact role with the autonomy to shape security architecture and protect the technology that is changing the future of defence.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Design and Own Security Architecture: Architect, build and deploy robust, scalable security controls for our corporate, development and production cloud environments (AWS, Azure, GCP).</li>
</ul>
<ul>
<li>Automate Everything: Develop and automate infrastructure-as-code (IaC) to manage and scale our cloud deployments securely and efficiently.</li>
</ul>
<ul>
<li>Proactively Defend: Continuously monitor, identify and remediate security weaknesses and configuration drift across our entire cloud footprint.</li>
</ul>
<ul>
<li>Be a Force Multiplier: Partner with infrastructure, application and product teams to embed security best practices into their workflows and secure environments holding mission-critical data.</li>
</ul>
<ul>
<li>Enable Scale and Reliability: Engineer systems and processes that ensure our platforms are highly available, resilient and prepared for rapid growth.</li>
</ul>
<ul>
<li>Serve as a Cloud Security Expert: Act as the go-to subject matter expert for teams across Anduril, providing guidance, mentorship and paved-road solutions for building securely in the cloud.</li>
</ul>
<p>Requirements:</p>
<ul>
<li>Proven experience building and securing complex cloud environments, typically gained through 3+ years in a Cloud Security, DevOps or SRE role.</li>
</ul>
<ul>
<li>Deep proficiency in at least one major cloud provider (AWS, Azure or GCP).</li>
</ul>
<ul>
<li>Strong hands-on experience with Infrastructure as Code (e.g., Terraform, CloudFormation, Bicep).</li>
</ul>
<ul>
<li>Solid programming/scripting ability in one or more languages (e.g., Python, Go, Rust).</li>
</ul>
<ul>
<li>Firm understanding of public cloud networking principles (e.g., VPCs, subnets, routing, security groups).</li>
</ul>
<ul>
<li>Must be a U.S. Person and eligible to obtain and maintain a U.S. Top Secret security clearance.</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience hardening and monitoring Kubernetes clusters (EKS, GKE, AKS).</li>
</ul>
<ul>
<li>Experience with cloud security posture management (CSPM) or threat detection tooling.</li>
</ul>
<ul>
<li>Familiarity with CI/CD pipelines and securing the software supply chain.</li>
</ul>
<ul>
<li>Knowledge of compliance frameworks such as FedRAMP, MRL, SOC 2 or CMMC.</li>
</ul>
<ul>
<li>On-premises network engineering experience.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$129,000-$193,000 USD</Salaryrange>
      <Skills>Cloud Security, DevOps, SRE, Infrastructure as Code, Terraform, CloudFormation, Bicep, Python, Go, Rust, Public Cloud Networking, VPCs, Subnets, Routing, Security Groups, Kubernetes, Cloud Security Posture Management, Threat Detection Tooling, CI/CD Pipelines, Software Supply Chain Security, Compliance Frameworks, FedRAMP, MRL, SOC 2, CMMC, On-Premises Network Engineering</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anduril Industries</Employername>
      <Employerlogo>https://logos.yubhub.co/anduril.com.png</Employerlogo>
      <Employerdescription>Anduril Industries is a defence technology company that designs, builds and sells advanced military systems.</Employerdescription>
      <Employerwebsite>https://www.anduril.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/andurilindustries/jobs/5087348007</Applyto>
      <Location>Costa Mesa, California, United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>bcabf282-157</externalid>
      <Title>Technical Support Engineer - Federal (Night Shift)</Title>
      <Description><![CDATA[<p>We are looking for a performance-driven Sr. Federal Technical Support Engineer to join our team. As a Senior Federal Technical Support Engineer, you will be part of a frontline team supporting the identity infrastructure of the U.S. Federal Government. You will manage customer issues from initial contact through troubleshooting and root cause identification to final resolution. You will act as a bridge between the customer and the company, ensuring a deep understanding of business impacts and driving timely problem resolution. You will consistently meet or exceed KPIs related to response quality, timeliness, and the overall customer experience. You will serve as the primary point of contact for internal and external stakeholders to ensure issues are resolved as expediently as possible. You will partner with the Engineering team to collect detailed information and document bugs for product issues impacting the customer base.</p>
<p>In this role, you will have a deep specialization in Identity and Access Management (IAM) and FedRAMP High/Moderate environments. You will have hands-on experience supporting IAM solutions, including deep familiarity with protocols such as SAML, SSO, LDAP, and WS-Federation. You will have advanced knowledge of Active Directory, Entra ID (Azure AD), and Okta. You will be an expert in troubleshooting synchronization errors, managing complex group membership logic, and overseeing cross-platform identity lifecycle management. You will have experience supporting major SaaS applications, including Office 365, Google Workspace, Salesforce, and Workday. You will have proven ability to isolate and resolve network-layer impediments. You will be skilled in leveraging diagnostic utilities such as Wireshark, Fiddler, and DNS lookup tools to identify root causes. You will have excellent relationship management skills with the ability to remain calm, composed, and articulate during high-pressure customer situations. You will be a quick study with the ability to master new technologies rapidly in a fast-paced environment. You will have strong analytical and organizational skills; comfortable working both as a collaborative teammate and an independent contributor with minimal supervision. You will have a genuine passion for solving complex problems and advocating for customer success.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$114,000-$157,300 USD</Salaryrange>
      <Skills>Identity &amp; Access Management (IAM), FedRAMP High/Moderate environments, SAML, SSO, LDAP, WS-Federation, Active Directory, Entra ID (Azure AD), Okta, Troubleshooting synchronization errors, Managing complex group membership logic, Overseeing cross-platform identity lifecycle management, Supporting major SaaS applications, Office 365, Google Workspace, Salesforce, Workday, Network-layer impediments, Diagnostic utilities, Wireshark, Fiddler, DNS lookup tools</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a software company that provides identity and access management solutions.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7819794</Applyto>
      <Location>Bellevue, Washington; Chicago, Illinois; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6bc635c8-b18</externalid>
      <Title>Staff Security Analyst, Customer Assurance</Title>
      <Description><![CDATA[<p>Secure Every Identity instituting AI is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>
<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>
<p>The Okta Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution by identifying and resolving risks to the employees, product, and most importantly, our customers. The Security Trust &amp; Culture team works to enhance customer trust in Okta’s identity services . We serve as a strategic resource working closely with Okta’s go-to-market teams.</p>
<p>As a Staff level analyst of Customer Assurance, you will support prioritising and efficiently responding to questions about our security programme and other due diligence related requests. You will act as a critical bridge between our customers and our internal engineering teams, ensuring Okta’s security posture is communicated effectively.</p>
<p>Tasks will include training local Sales teams, managing complex escalations in the regional market, and driving technological changes to help Customer Assurance scale its efforts globally. This position requires a unique combination of skills including an ability to coordinate the analysis of technical issues, to communicate clearly about security-relevant topics with both internal and external customers, to collaborate with internal business units to ensure execution of time-sensitive projects, and to present to upper management or the broader organisation as required.</p>
<p>The ideal candidate will have experience with SaaS cloud security risk assessment and a solid understanding of the core principles of identity management. If you want to make a difference in the security programme of a global cloud provider, we want you on board.</p>
<p>Job Duties and Responsibilities:</p>
<p>Serve as the critical bridge between Okta’s customers and internal Engineering/Product Security teams. You must be able to unpack complex customer security concerns, hold in-depth technical discussions with internal engineering to align on solutions, and translate Okta’s security architecture back to the customer to resolve high-stakes inquiries.</p>
<p>Take end-to-end ownership of highly technical security questionnaires and due-diligence requests, Partner seamlessly with internal subject matter experts,including our specialised Federal/FedRAMP teams,to ensure accurate, timely, and high-quality responses for highly regulated customers.</p>
<p>Drive technological changes within Customer Assurance by identifying and implementing AI and automation strategies to streamline workflows, scale global efforts, and reduce response times.</p>
<p>Train and empower regional Go-To-Market and Sales teams on standard engagement protocols, ensuring they can leverage Customer Assurance resources smoothly to accelerate deals.</p>
<p>Collaborate with the Security Trust &amp; Culture team and Regional CSOs to develop, publish, and maintain forward-facing security collateral, FAQs, and field communications.</p>
<p>Work within a global team, participating or leading global handoffs between American timezones and European or Asian, when required for large security or industry events.</p>
<p>Requirements:</p>
<p>Bachelor’s degree in Computer Science or Management Information Systems, or equivalent work experience in technology or information security fields</p>
<p>Minimum 3 years information security, project management, or related experience</p>
<p>A strong, fundamental understanding of core Security principles, architectures, and operations.</p>
<p>Understanding of IT and cloud methodologies, information security, privacy, identity management, risk assessments and IT regulation and compliance standards</p>
<p>Strong oral, written, and presentation skills</p>
<p>Strong written and verbal communication skills, with a proven ability to distill complex technical concepts into clear, concise responses for both technical customers and internal executive stakeholders.</p>
<p>Helpful Certifications / Skills:</p>
<p>Okta Certified Professional/Administrator</p>
<p>Certificate of Cloud Security Knowledge (CCSK) and/or Certificate of Cloud Auditing Knowledge (CCAK)</p>
<p>Certified Information Security Auditor (CISA)</p>
<p>Experience with generative AI tools or process automation platforms is a strong plus.</p>
<p>Familiarity with Federal or highly regulated compliance frameworks (e.g., FedRAMP, StateRAMP, NIST 800-53, or DoD IL4/IL5)</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$148,000-$203,500 USD</Salaryrange>
      <Skills>Okta Certified Professional/Administrator, Certificate of Cloud Security Knowledge (CCSK) and/or Certificate of Cloud Auditing Knowledge (CCAK), Certified Information Security Auditor (CISA), generative AI tools or process automation platforms, Federal or highly regulated compliance frameworks (e.g., FedRAMP, StateRAMP, NIST 800-53, or DoD IL4/IL5)</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta provides identity and access management solutions for businesses.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7743848</Applyto>
      <Location>Bellevue, Washington; Chicago, Illinois; New York, New York; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>3ad8987a-19b</externalid>
      <Title>Staff Compliance Analyst - Federal</Title>
      <Description><![CDATA[<p>We are looking for a Staff Federal Security Compliance Analyst to join our Federal Security and Compliance team. As a Staff Federal Security Compliance Analyst, you will serve as a lead of our compliance strategy, safeguarding and strengthening our position as a leading IDaaS provider for the public sector. Your mission is to bridge the gap between engineering, product, and federal regulatory bodies, driving the maintenance of our FedRAMP and DoD authorizations, leading complex audits, and mentoring junior analysts to ensure a security-first culture.</p>
<p>The responsibilities listed below represent the core functions of this role:</p>
<ul>
<li>Strategic Audit Leadership: Lead end-to-end FedRAMP and DoD audits, serving as the primary point of contact for external 3PAOs and government agencies.</li>
<li>Continuous Monitoring Strategy: Oversee and evolve the continuous monitoring (ConMon) program. Design sophisticated reporting mechanisms for vulnerability management and risk posture for executive leadership.</li>
<li>Engineering Advisory: Act as a senior consultant to Engineering and Product teams, translating complex NIST 800-53 requirements into actionable technical specifications for cloud-native environments.</li>
<li>Impact Assessment &amp; Risk Management: Lead the assessment of high-impact changes to federal systems. Ensure that system evolutions maintain a rigorous security posture without sacrificing innovation.</li>
<li>Cross-Functional Alignment: Drive synchronization between GRC, Security, Marketing, Sales, Engineering, and Product to ensure federal requirements are integrated into the broader corporate roadmap.</li>
<li>Programmatic Gap Analysis: Proactively identify and lead initiatives to close gaps between current capabilities and future regulatory requirements (e.g., emerging NIST standards, new DoD mandates, or IL6 requirements).</li>
<li>Evidence Automation &amp; FedRAMP 20x Readiness: Drive the build-out and support of automated evidence collection and control validation. Lead the transition toward &quot;FedRAMP 2.0&quot; standards (including OSCAL integration), defining and monitoring Key Security Indicators (KSIs) to provide real-time compliance visibility.</li>
</ul>
<p>Minimum Required Knowledge, Skills, and Abilities:</p>
<ul>
<li>Education: Bachelor’s degree in Computer Science, MIS, Cybersecurity, or a related technical field.</li>
<li>Experience: 7+ years of experience in security compliance, with at least 4-5 years specifically focused on the FedRAMP/NIST 800-53 framework.</li>
<li>Automation &amp; Compliance Engineering: Demonstrated experience with automation tools or scripting (e.g., Python, Go, or SQL) for automated evidence collection. Familiarity with API-based control validation and OSCAL-based tooling (e.g., Trestle, LULA, or similar GRC automation frameworks).</li>
<li>Technical Depth: Deep understanding of cloud-native infrastructure (IaaS, PaaS, SaaS) and how infrastructure components (networking, OS, databases) support a distributed cloud application.</li>
<li>Framework Mastery: Expert-level knowledge of NIST SP 800-53, FedRAMP High/Moderate, and DoD SRG (IL4, IL5, and familiarity with IL6).</li>
<li>Operational Knowledge: Proven experience with access management, CI/CD pipelines, disaster recovery, and encryption/key management in a cloud context.</li>
<li>Analytical Leadership: Ability to analyze complex &quot;edge-case&quot; security scenarios and provide remediation paths that align with both business goals and regulatory requirements.</li>
<li>Communication: Exceptional presentation skills with the ability to explain technical compliance risks to non-technical executive stakeholders.</li>
</ul>
<p>Preferred Certifications &amp; Skills:</p>
<ul>
<li>Advanced Certifications: CISSP (highly preferred), CISA, or CCSK.</li>
<li>Cloud Expertise: AWS Certified Solutions Architect or Cloud Practitioner.</li>
<li>Tooling: Expert-level proficiency with JIRA, ServiceNow, and Okta.</li>
<li>Technical Background: Prior experience in a DevOps, Security Engineering, or Systems Administration role is a significant plus.</li>
</ul>
<p>Additional requirements:</p>
<ul>
<li>This position requires the ability to access federal environments and/or have access to protected federal data. As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$161,000-$221,000 USD</Salaryrange>
      <Skills>Automation &amp; Compliance Engineering, Cloud-native infrastructure, API-based control validation, OSCAL-based tooling, NIST SP 800-53, FedRAMP High/Moderate, DoD SRG (IL4, IL5), Access management, CI/CD pipelines, Disaster recovery, Encryption/key management, CISSP, CISA, CCSK, AWS Certified Solutions Architect, Cloud Practitioner, JIRA, ServiceNow, Okta</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a cloud-based identity and access management company that provides solutions for Identity-as-a-Service (IDaaS) providers.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7571077</Applyto>
      <Location>Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>be5eaf8f-2fb</externalid>
      <Title>Senior Corporate Counsel – Cybersecurity</Title>
      <Description><![CDATA[<p>Secure Every Identity, from AI to Human</p>
<p>Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>
<p>This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>
<p>As a Senior Corporate Counsel – Cybersecurity, you will lead the cybersecurity legal team, helping build a scalable global cybersecurity practice. You will apply your experience when providing legal guidance on cybersecurity and privacy issues and drafting and negotiating information security exhibits, data processing addenda and related commercial documents with some of the biggest names across every industry that trust Okta to help their organisations work faster, boost revenue, and stay secure.</p>
<p>Responsibilities:</p>
<ul>
<li>Lead a team of talented, high-performing cybersecurity legal professionals and serve as a point of escalation to provide cybersecurity legal expertise and guidance to executives, cross-functional leaders and other stakeholders throughout the organisation.</li>
</ul>
<ul>
<li>Advise, draft and negotiate cybersecurity and privacy terms associated with outbound cloud service Master Subscription Agreements, Information Security Exhibits, Data Processing Addendums and other documentation related to sales transactions, while partnering closely with Okta’s Commercial Legal team.</li>
</ul>
<ul>
<li>Provide day-to-day legal support surrounding cybersecurity and privacy-related contract requests and respond promptly and effectively to legal requests from internal clients with pragmatic and business-oriented guidance.</li>
</ul>
<ul>
<li>Provide advice and guidance to Okta Security, Engineering, Product, executives, and other stakeholders on compliance with applicable security and privacy laws and regulations, such as the General Data Protection Regulation, United States’ federal and state regulations, security/privacy by design, frameworks and industry certifications.</li>
</ul>
<ul>
<li>Support the investigation of potential security and privacy incidents, including analysing relevant legal and regulatory responsibilities, and providing guidance to internal clients on mitigation, remediation and resolution efforts.</li>
</ul>
<ul>
<li>Develop, implement and maintain standards, processes, runbooks and guidance surrounding cybersecurity and privacy-related issues for Go-to-Market transactions, and partnering closely with members of the Legal, Security, Compliance and Engineering teams, among other key stakeholders.</li>
</ul>
<ul>
<li>Build critical relationships in order to effectively provide practical and strategic advice to assist the business in meeting its objectives, while ensuring information security and privacy compliance. Advise on recommended courses of action and legal risk, with the ability to judge when to escalate identified issues as appropriate.</li>
</ul>
<ul>
<li>Assist in the maintenance and review of various security and privacy programs and processes, including updates to security and privacy policies, plans, procedures, standards, certifications and customer-facing security and privacy documentation.</li>
</ul>
<ul>
<li>Support the procurement team in drafting and negotiating cybersecurity and privacy terms associated with vendor agreements.</li>
</ul>
<ul>
<li>Maintain an understanding of technical controls and assist in the creation of audit and monitoring frameworks to support stable, controlled operations.</li>
</ul>
<ul>
<li>Review cybersecurity and privacy-related marketing and other external communications content for accuracy and completeness.</li>
</ul>
<ul>
<li>Support the management of outside counsel and consultants, and contribute to other interesting legal projects, as needed.</li>
</ul>
<p>Required Skills and Experience:</p>
<ul>
<li>8+ years of relevant law firm and/or in-house experience, including at least 2 years working primarily on cybersecurity and privacy-related transactional matters, preferably at a SaaS technology company.</li>
</ul>
<ul>
<li>Familiarity and comfort with the culture of a fast-paced enterprise software company and knowledge of SaaS products.</li>
</ul>
<ul>
<li>Experience working with highly-regulated customers, especially those in the financial services industry, preferred.</li>
</ul>
<ul>
<li>Excellent written and verbal communication, presentation, drafting and negotiation skills.</li>
</ul>
<ul>
<li>Sound and practical legal and business judgment, as well as the ability to think strategically and develop strong working relationships with key internal clients.</li>
</ul>
<ul>
<li>Knowledge in global security, privacy and data protection frameworks, including NIST, ISO, FedRAMP, PCI-DSS, GDPR, CCPA, CPRA and HIPAA.</li>
</ul>
<ul>
<li>Ability to maintain strong working relationships with a variety of internal clients and business partners from a variety of functions.</li>
</ul>
<ul>
<li>A self-motivated individual with grit who takes initiative and is comfortable rolling up their sleeves. Team-oriented with a sense of humour and high emotional intelligence. Ability to organise, prioritise, and manage deadlines.</li>
</ul>
<ul>
<li>Strong academic background and J.D. from highly-regarded school, active bar admission.</li>
</ul>
<p>The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between $212,000-$292,000 USD</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$212,000-$292,000 USD</Salaryrange>
      <Skills>cybersecurity, privacy, transactional matters, SaaS technology company, global security, privacy and data protection frameworks, NIST, ISO, FedRAMP, PCI-DSS, GDPR, CCPA, CPRA, HIPAA</Skills>
      <Category>Legal</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a software company that provides identity and access management solutions.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7675356</Applyto>
      <Location>Bellevue, Washington; Chicago, Illinois; New York, New York; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>408f8d1b-01b</externalid>
      <Title>Senior Solutions Engineer, Majors</Title>
      <Description><![CDATA[<p>About Us</p>
<p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</p>
<p>We protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks.</p>
<p><strong>Available Location:</strong></p>
<p>Available locations: Denver, CO</p>
<p><strong>What you&#39;ll do as a Senior Solutions Engineer, Majors Accounts</strong></p>
<p>The Solution Engineering organization is responsible for the technical sale of the Cloudflare solution portfolio, ensuring maximal business value, fit-for-purpose solution design and adoption roadmap for our customers. Reporting to the Solution Engineering Manager, the Majors Accounts Solutions Engineer is a Senior level role.</p>
<p>You are a customer-facing technologist within the Cloudflare Solutions Engineering team. You have strong experience in large account pre-sales management as well as excellent verbal and written communications skills suited for executive-level engagement. You are comfortable speaking about the Cloudflare vision and mission with C-level customer executives.</p>
<p>Your role will be to build passionate champions within the technology ranks at your accounts, drive sales for identified opportunities, and leverage your relationships with these technical champions to build a revenue pipeline where no opportunities yet exist. You will work within a high-profile pursuit team dedicated to certain strategic accounts, working closely with the majors account executives attached to these accounts.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Build and maintain long-term technical relationships with the technical buyers (executives, managers, and individual contributors) at your assigned accounts, becoming a trusted advisor to those stakeholders.</li>
<li>Deeply understand the business-critical issues that your accounts are facing, and provide meaningful solution designs to facilitate technical validation of Cloudflare as a part of the customer’s infrastructure, including the coordination of Cloudflare colleagues throughout the sales and procurement cycle.</li>
<li>Identify and drive technical conversations in every possible line of business within the accounts, engaging key technical buyers with the purpose of uncovering new areas of potential revenue &amp; showing value to all possible parts of your accounts.</li>
<li>Empower customers in their security and network transformation journeys, helping them to define strategies and architect necessary security controls aligned with Cloudflare product suites.</li>
<li>Be the voice of the customer internally at Cloudflare, engaging with and influencing Cloudflare’s Product and Engineering teams to meet your customers’ needs.</li>
<li>Represent and evangelize Cloudflare externally at Developer, Community, Technology, Cybersecurity, and other industry events with thought leadership and expertise.</li>
</ul>
<p><strong>Desirable Skills, Knowledge, and Experience</strong></p>
<ul>
<li>Polished communication and executive presentation skills with the ability to drive a discussion with a broad range of stakeholders (from the web developer to the CISO).</li>
<li>Relationship building: a proven track record of building deep technical relationships with engineers and senior executives in large and strategic accounts. Experience in managing various stakeholder relationships to build consensus on security solutions/projects.</li>
<li>Experience managing technical sales within large accounts.</li>
<li>Developing champion-style relationships</li>
<li>Driving technical wins</li>
<li>Assisting with technical validation</li>
<li>A deep understanding of core industry components of Cloudflare solutions (and a desire to learn more):</li>
</ul>
<p>Internet security technologies including DDoS and DDoS mitigation, Firewalls, TLS, VPN, DLP     Networking technologies including TCP, UDP, DNS, IPv4 + IPv6, BGP routing, GRE, SD-WAN, MPLS, Global Traffic Management     HTTP technologies including reverse proxy (e.g., WAF and CDN), forward proxy (secure web gateway), serverless application development     Zero-trust network access (ZTNA &amp; SASE) concepts including identity management and authentication     Cloud computing technologies such as AWS, GCP, Azure, and others     Some scripting or programming experience with one or more of JavaScript, Python, Golang, BASH     Understanding of, or experience with, regulatory requirements such as FedRAMP, GDPR, PCI DSS, HIPAA, SOC-2, ISO/IEC.</p>
<p><strong>Compensation</strong></p>
<p>Compensation may be adjusted depending on work location.</p>
<p>For Denver, Colorado-based hires: Estimated annual salary of $208,000 - $254,000. This role is eligible to earn incentive compensation under Cloudflare’s Sales Compensation Plan. The estimated annual salary range includes the on-target incentive compensation that may be attained in this role under the Sales Compensation Plan.</p>
<p><strong>Equity</strong></p>
<p>This role is eligible to participate in Cloudflare’s equity plan.</p>
<p><strong>Benefits</strong></p>
<p>Cloudflare offers a complete package of benefits and programs to support you and your family. Our benefits programs can help you pay health care expenses, support caregiving, build capital for the future, and make life a little easier and fun!</p>
<p>The below is a description of our benefits for employees in the United States, and benefits may vary for employees based outside the U.S.</p>
<p>Health &amp; Welfare Benefits Medical/Rx Insurance Dental Insurance Vision Insurance Flexible Spending Accounts Commuter Spending Accounts Fertility &amp; Family Forming Benefits On-demand mental health support and Employee Assistance Program Global Travel Medical Insurance</p>
<p>Financial Benefits Short and Long Term Disability Insurance Life &amp; Accident Insurance 401(k) Retirement Savings Plan Employee Stock Participation Plan</p>
<p>Time Off Flexible paid time off covering vacation and sick leave Leave programs, including parental, pregnancy health, medical, and bereavement leave</p>
<p><strong>What Makes Cloudflare Special?</strong></p>
<p>We’re not just a highly ambitious, large-scale technology company. We’re a highly ambitious, large-scale technology company with a soul. Fundamental to our mission to help build a better Internet is protecting the free and open Internet.</p>
<p>Project Galileo: Since 2014, we&#39;ve equipped more than 2,400 journalism and civil society organizations in 111 countries with powerful tools to defend themselves against attacks that would otherwise censor their work, technology already used by Cloudflare’s enterprise customers,at no cost.</p>
<p>Athenian Project: In 2017, we created the Athenian Project to ensure that state and local governments have the highest level of protection and reliability for free, so that their constituents have access to election information and voter registration. Since the project’s inception, we’ve protected over 20 million registered voters and helped to safeguard the integrity of elections in several states.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$208,000 - $254,000</Salaryrange>
      <Skills>DDoS and DDoS mitigation, Firewalls, TLS, VPN, DLP, TCP, UDP, DNS, IPv4 + IPv6, BGP routing, GRE, SD-WAN, MPLS, Global Traffic Management, reverse proxy, WAF and CDN, forward proxy, secure web gateway, serverless application development, Zero-trust network access, identity management, authentication, cloud computing, AWS, GCP, Azure, scripting, programming, JavaScript, Python, Golang, BASH, regulatory requirements, FedRAMP, GDPR, PCI DSS, HIPAA, SOC-2, ISO/IEC</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Cloudflare</Employername>
      <Employerlogo>https://logos.yubhub.co/cloudflare.com.png</Employerlogo>
      <Employerdescription>Cloudflare is a technology company that provides cloud-based services for security, performance, and reliability. It runs one of the world&apos;s largest networks that powers millions of websites and other Internet properties.</Employerdescription>
      <Employerwebsite>https://www.cloudflare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/cloudflare/jobs/7374554</Applyto>
      <Location>Distributed</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>27d6fab4-848</externalid>
      <Title>Staff Product Security Engineer</Title>
      <Description><![CDATA[<p>Job Title: Staff Product Security Engineer</p>
<p>Location: United States</p>
<p>Department: Security</p>
<p>Job Description:</p>
<p>This role can be based remotely anywhere in the United States. The Product Security Team&#39;s mission is to left-shift SDLC (Security Development Lifecycle) processes for all code written in Databricks (for customer use or supporting customers internally) to reduce the likelihood of introducing new vulnerabilities in production and minimize the count and effect of externally identified vulnerabilities on Databricks Services.</p>
<p>You will be an individual contributor on the product security team at Databricks, managing SDLC functions for features and products within Databricks. This would include, but is not limited to, security design reviews, threat models, manual code reviews, exploit writing, and exploit chain creation. You will also support IR and VRP programs when there is a vulnerability report or a product security incident.</p>
<p>You will work with a global team, spread across various locations in the US and EMEA.</p>
<p>The impact you will have:</p>
<ul>
<li>Full SDLC support for new product features being developed in ENG and non-ENG teams. This would include threat modeling, design review, manual code review, exploit writing, etc.</li>
</ul>
<ul>
<li>Work with other security teams to provide support for incident response and vulnerability response as and when needed.</li>
</ul>
<ul>
<li>Work with the results of SAST tools to help evaluate and identify false positives and file defects for real issues.</li>
</ul>
<ul>
<li>Work on DAST tools and related automation for auto-assessment and defect filing.</li>
</ul>
<ul>
<li>Maintain the automation framework and add new features as needed to support different security compliances that Databricks may want to get into – FedRamp, PCI, HIPAA, etc.</li>
</ul>
<ul>
<li>Prioritize security from a risk management perspective, rather than an absolute textbook version.</li>
</ul>
<ul>
<li>Help develop and implement security processes to improve the overall productivity of the product security organization and the SDLC process in general</li>
</ul>
<p>What we look for:</p>
<ul>
<li>3-10 years&#39; experience with the threat modeling process and ability to find design problems based on a block diagram of data flow.</li>
</ul>
<ul>
<li>Solid understanding on at least two of the following domains: web security, cloud security, systems security, and applied cryptography.</li>
</ul>
<ul>
<li>Proficient with one or more of programming languages (Python/Java/Scala/JavaScript) and ability to read code to identify security defects.</li>
</ul>
<ul>
<li>Strong skills on scripting and automation on exploits.</li>
</ul>
<ul>
<li>Fuzzing skills are good to have.</li>
</ul>
<ul>
<li>Exploit writing skills are a positive and greatly required.</li>
</ul>
<p>Pay Range Transparency:</p>
<p>Databricks is committed to fair and equitable compensation practices. The pay range(s) for this role is listed below and represents the expected base salary range for non-commissionable roles or on-target earnings for commissionable roles. Actual compensation packages are based on several factors that are unique to each candidate, including but not limited to job-related skills, depth of experience, relevant certifications and training, and specific work location. Based on the factors above, Databricks anticipated utilizing the full width of the range. The total compensation package for this position may also include eligibility for annual performance bonus, equity, and the benefits listed above.</p>
<p>For more information regarding which range your location is in visit our page here.</p>
<p>Zone 1 Pay Range: $190,000 - $261,250 USD</p>
<p>Zone 2 Pay Range: $171,000 - $235,200 USD</p>
<p>Zone 3 Pay Range: $161,500 - $222,100 USD</p>
<p>Zone 4 Pay Range: $152,000 - $209,000 USD</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$190,000 - $261,250 USD</Salaryrange>
      <Skills>threat modeling, security design reviews, manual code reviews, exploit writing, exploit chain creation, incident response, vulnerability response, SAST tools, DAST tools, automation, FedRamp, PCI, HIPAA, risk management, security processes, productivity, SDLC process, web security, cloud security, systems security, applied cryptography, programming languages, scripting, fuzzing</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a unified platform for data, analytics, and AI. It was founded by the original creators of Lakehouse, Apache Spark, Delta Lake, and MLflow.</Employerdescription>
      <Employerwebsite>https://databricks.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/7882009002</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>abaa6feb-362</externalid>
      <Title>Staff Security Software Engineer</Title>
      <Description><![CDATA[<p>We are seeking a Staff Security Software Engineer to join our Security Continuous Monitoring team. As a member of this team, you will help build and scale Databricks Security systems built on top of the Databricks platform. Your responsibilities will include designing, testing, and implementing data pipelines to assess security configurations of Cloud, SaaS, and on-premise tooling.</p>
<p>You will also design and deploy robust supporting security tools for managing and assessing security state, integrate with third-party applications, and interact with cloud APIs (AWS, Azure, GCP, Terraform). Additionally, you will plan and lead end-to-end projects supporting data collection and integration with vulnerability and threat detection efforts.</p>
<p>To succeed in this role, you will need 8+ years of software engineering experience, with 4+ years specifically in security-related engineering. You should have experience with Python, Git/GitHub, and CI/CD automation, and Terraform. Expertise in securing at least one major cloud environment (AWS, Azure, GCP) is also required. Experience with software security and systems that handle sensitive data, as well as data correlation engine, is preferred.</p>
<p>As a leader on our team, you will be expected to mentor peers, drive strategic initiatives, and influence the organization&#39;s security direction. You should have excellent communication skills, with the ability to collaborate effectively across teams and present complex ideas clearly to stakeholders at all levels.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Python, Git/GitHub, CI/CD automation, Terraform, Cloud security, Software security, Data correlation engine, FedRAMP Moderate/High experience</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a unified platform for data, analytics, and AI. It has over 10,000 organizations as clients worldwide.</Employerdescription>
      <Employerwebsite>https://databricks.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/7932280002</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>eec951b9-d96</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re seeking a Security Engineer at the senior-level or above to own the product security and authorization lifecycle for Saronic&#39;s autonomous surface vessels. You will serve as the responsible security engineer for one or more vessel programs, owning the security posture from design through production, authorization, and operational deployment.</p>
<p>This is a hands-on security engineering role; not a GRC or project management role. You&#39;ll identify the frameworks that apply, architect the vessel&#39;s security to satisfy them, and drive authorization to completion. Where standards don&#39;t yet exist, you&#39;ll define them.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Own the security posture for one or more vessel programs from architecture through fielding, serving as the responsible security engineer for the product</li>
<li>Drive threat modeling across vessel subsystems including embedded compute, communications, navigation, propulsion controls, sensor fusion, and C2 interfaces and define security architectures, trust boundaries, and segmentation strategies based on findings</li>
<li>Identify and mitigate security risks unique to autonomous maritime platforms, including GPS/GNSS spoofing, RF interference, sensor manipulation, supply chain compromise, and physical access threats</li>
<li>Own the end-to-end authorization lifecycle for vessel programs, from initial security planning through ATO or equivalent customer authorization milestones</li>
<li>Navigate DoD cybersecurity authorization frameworks including RMF, CSRMC, and service-specific requirements across Navy, Coast Guard, Marine Corps, and joint programs</li>
<li>Prepare and maintain authorization artifacts, security documentation, and evidence packages that satisfy Authorizing Officials and program offices</li>
<li>Identify and map applicable compliance frameworks for each vessel and customer segment including NIST SP 800-53, NIST SP 800-171, CMMC 2.0, FedRAMP, IEC 62443, IMO MASS Code, and IACS UR E26/E27 and proactively define Saronic&#39;s compliance posture where standards are still emerging</li>
<li>Engage directly with government program offices, Authorizing Officials, DOT&amp;E evaluators, and classification societies as a credible technical representative of Saronic&#39;s security posture</li>
<li>Support cybersecurity testing and evaluation efforts, including preparation for operational test events, red team assessments, and cooperative vulnerability assessments</li>
<li>Partner with supply chain and manufacturing teams to address hardware provenance, firmware integrity, and anti-tamper requirements for production vessels</li>
<li>Work with Legal and Contracts to ensure security and compliance requirements are accurately reflected in customer agreements, proposals, and contract deliverables</li>
</ul>
<p>Required Qualifications:</p>
<ul>
<li>6+ years of hands-on experience in product security, systems security engineering, authorization engineering, or a closely related security engineering role for defense or high-assurance platforms</li>
<li>Strong understanding of DoD cybersecurity authorization processes (RMF, ATO/IATT, CSRMC, continuous ATO) with experience contributing to or driving systems through authorization</li>
<li>Working knowledge of NIST SP 800-53, NIST SP 800-171, and CMMC 2.0 and their application to weapons systems, autonomous platforms, or similarly complex defense products</li>
<li>Experience with threat modeling, security architecture, or risk assessment for cyber-physical systems, embedded systems, or operational technology environments</li>
<li>Strong technical foundation, able to read architecture diagrams, evaluate security controls at a systems level, and hold credible technical conversations with hardware, software, and cloud engineers</li>
<li>Ability to clearly communicate with both technical and non-technical stakeholders, including production of security documentation and authorization artifacts</li>
<li>Ownership mindset with the ability to operate in ambiguity, define the path forward, and move work to completion across teams</li>
<li>Ability to obtain and maintain a security clearance</li>
</ul>
<p>Preferred Qualifications:</p>
<ul>
<li>Experience as a product security lead, systems security engineer, or authorization lead for a defense platform or program of record</li>
<li>Direct experience engaging with government Authorizing Officials, program offices, or DOT&amp;E as a technical security representative</li>
<li>Experience in defense technology startups, DARPA programs, or organizations that move at speed within the defense acquisition system</li>
<li>Familiarity with maritime-specific frameworks including IMO MASS Code, IACS UR E26/E27, IEC 62443, or classification society autonomous vessel rules</li>
<li>Understanding of autonomous systems security challenges including communications security, electronic warfare hardening, GPS/GNSS resilience, and AI/ML system security</li>
<li>Experience with ITAR/EAR compliance, supply chain security, or manufacturing security for defense products</li>
<li>Familiarity with the defense acquisition lifecycle and how authorization milestones integrate into program schedules</li>
</ul>
<p>Additional Information:</p>
<ul>
<li>Benefits: Medical Insurance, Dental and Vision Insurance, Time Off, Parental Leave, Competitive Salary, Retirement Plan, Stock Options, Life and Disability Insurance, Pet Insurance</li>
<li>This role requires access to export-controlled information or items that require “U.S. Person” status.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>product security, systems security engineering, authorization engineering, threat modeling, security architecture, risk assessment, cyber-physical systems, embedded systems, operational technology environments, NIST SP 800-53, NIST SP 800-171, CMMC 2.0, RMF, CSRMC, ATO/IATT, continuous ATO, FedRAMP, IEC 62443, IMO MASS Code, IACS UR E26/E27, product security lead, systems security engineer, authorization lead, defense platform, program of record, government Authorizing Officials, program offices, DOT&amp;E, technical security representative, defense technology startups, DARPA programs, organizations, defense acquisition system, maritime-specific frameworks, ITAR/EAR compliance, supply chain security, manufacturing security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Saronic Technologies</Employername>
      <Employerlogo>https://logos.yubhub.co/saronictech.com.png</Employerlogo>
      <Employerdescription>Saronic Technologies is a leader in revolutionizing defense autonomy at sea, developing state-of-the-art solutions for the Department of Defense.</Employerdescription>
      <Employerwebsite>https://www.saronictech.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/saronic/6e800df8-6173-4f13-863e-b8803017f317</Applyto>
      <Location></Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>734a57ad-497</externalid>
      <Title>Security Engineer</Title>
      <Description><![CDATA[<p>We&#39;re seeking a senior-level Security Engineer to own the design, implementation, and continuous improvement of security guardrails across our cloud infrastructure. You willaki, you&#39;ll build the systems and patterns that enable every team at Saronic to move fast and ship with confidence, with security baked in from the start. You will be the technical authority on how we architect, govern, and defend our AWS environments across commercial and GovCloud.</p>
<p><strong>Key Responsibilities</strong></p>
<ul>
<li>Own the security architecture for Saronic&#39;s AWS environments, including multi-account strategy, network segmentation, identity architecture, and data protection across commercial AWS and AWS GovCloud</li>
</ul>
<ul>
<li>Design and maintain secure-by-default Terraform modules and IaC standards that teams adopt as the standard path, enforcing least privilege, secure defaults, and compliance requirements</li>
</ul>
<ul>
<li>Implement preventive controls (SCPs, permission boundaries, policy-as-code) and detective controls (Config rules, CloudTrail analysis, GuardDuty) as a unified, layered security model</li>
</ul>
<ul>
<li>Design and enforce IAM patterns across AWS accounts, services, and workloads including least-privilege policies, permission boundaries, cross-account access, federation, and service-to-service authentication</li>
</ul>
<ul>
<li>Implement and govern secrets management using tools such as AWS Secrets Manager or Vault, integrated into CI/CD and runtime environments</li>
</ul>
<ul>
<li>Partner with DevOps and Platform Engineering to embed security into CI/CD pipelines, infrastructure provisioning, and deployment workflows</li>
</ul>
<ul>
<li>Build automated compliance validation into infrastructure pipelines and replace manual security gates with automated guardrails wherever possible</li>
</ul>
<ul>
<li>Create self-service security tooling and patterns that allow teams to operate with speed and autonomy while maintaining compliance</li>
</ul>
<ul>
<li>Integrate logging, monitoring, and alerting across cloud infrastructure to validate control effectiveness and detect misconfigurations or threats</li>
</ul>
<ul>
<li>Build and tune cloud-native detections using CloudTrail, GuardDuty, Config, and SIEM integrations</li>
</ul>
<ul>
<li>Support incident response for cloud security events, drive root-cause analysis, and translate findings into improved guardrails and controls</li>
</ul>
<p><strong>Required Qualifications:</strong></p>
<ul>
<li>6+ years of hands-on experience in cloud security engineering, infrastructure security, DevSecOps, or a closely related security engineering role</li>
</ul>
<ul>
<li>Expert-level proficiency with Terraform, including module design, state management, policy-as-code, and managing complex multi-environment configurations</li>
</ul>
<ul>
<li>Deep expertise in AWS security services and architecture, including IAM, Organizations, SCPs, Control Tower, CloudTrail, Config, GuardDuty, Security Hub, KMS, and VPC security</li>
</ul>
<ul>
<li>Demonstrated experience building security guardrails and reusable infrastructure patterns that engineering teams adopt without friction</li>
</ul>
<ul>
<li>Strong experience with CI/CD pipeline security, IaC review processes, and automated compliance validation</li>
</ul>
<ul>
<li>Experience operating in AWS GovCloud or FedRAMP-regulated cloud environments</li>
</ul>
<ul>
<li>Strong proficiency in Python, Go, Rust, or equivalent languages for building security automation and tooling</li>
</ul>
<ul>
<li>Ability to obtain and maintain a security clearance</li>
</ul>
<p><strong>Preferred Qualifications:</strong></p>
<ul>
<li>Experience in defence, aerospace, robotics, autonomy, or other high-assurance environments</li>
</ul>
<ul>
<li>Experience designing multi-account AWS landing zones and organisational security architectures from the ground up</li>
</ul>
<ul>
<li>Hands-on experience with Kubernetes security, container security, and service mesh security in cloud-native environments</li>
</ul>
<ul>
<li>Familiarity with NIST SP 800-171, NIST SP 800-53, FedRAMP, or Cloud Computing SRG Impact Levels</li>
</ul>
<ul>
<li>Experience with infrastructure drift detection, automated remediation, and continuous compliance monitoring</li>
</ul>
<ul>
<li>Relevant certifications such as AWS Security Specialty, AWS Solutions Architect Professional, HashiCorp Terraform Associate/Engineer, CCSP, or CISSP</li>
</ul>
<p><strong>Additional Information</strong></p>
<p>Benefits: Medical Insurance: Comprehensive health insurance plans covering a range of services. Saronic pays 100% of the premium for employees and 80% for dependents. Dental and Vision Insurance: Coverage for routine dental check-ups, orthodontics, and vision care. Saronic pays 100% of the premium under the basic plan for employees and 80% for dependents. Time Off: Generous PTO and Holidays. Parental Leave: Paid maternity and paternity leave to support new parents. Competitive Salary: Industry-standard salaries with opportunities for performance-based bonuses. Retirement Plan: 401(k) plan. Stock Options: Equity options to give employees a stake in the company’s success. Life and Disability Insurance: Basic life insurance and short- and long-term disability coverage. Pet Insurance: Discounted pet insurance options including 24/7 Telehealth helpline. Additional Perks: Free lunch benefit and unlimited free drinks and snacks in the office</p>
<p>This role requires access to export-controlled information or items that require “U.S. Person” status. As defined by U.S. law, individuals who are any one of the following are considered to be a “U.S. Person”: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3).</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Terraform, AWS security services, IAM, Organizations, SCPs, Control Tower, CloudTrail, Config, GuardDuty, Security Hub, KMS, VPC security, Python, Go, Rust, CI/CD pipeline security, IaC review processes, automated compliance validation, AWS GovCloud, FedRAMP-regulated cloud environments, Kubernetes security, container security, service mesh security, NIST SP 800-171, NIST SP 800-53, FedRAMP, Cloud Computing SRG Impact Levels, infrastructure drift detection, automated remediation, continuous compliance monitoring, AWS Security Specialty, AWS Solutions Architect Professional, HashiCorp Terraform Associate/Engineer, CCSP, CISSP</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Saronic Technologies</Employername>
      <Employerlogo>https://logos.yubhub.co/saronictechnologies.com.png</Employerlogo>
      <Employerdescription>Saronic Technologies develops state-of-the-art solutions for defence autonomy at sea.</Employerdescription>
      <Employerwebsite>https://www.saronictechnologies.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/saronic/18310005-a24b-4f4c-9538-465df614c4fa</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>23839818-2ff</externalid>
      <Title>Client Platform Engineer</Title>
      <Description><![CDATA[<p><strong>Compensation</strong></p>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p><strong>About the Team</strong></p>
<p>OpenAI’s Platform and Infrastructure Engineering organization advances the mission of deploying artificial general intelligence (AGI) for the benefit of all by delivering secure, scalable, and resilient technology solutions. Our team builds and maintains robust infrastructure that safeguards OpenAI’s data and systems while ensuring employees are well-equipped and seamlessly connected. By prioritizing security, reliability, and user-centric solutions, we empower OpenAI employees to drive impactful AI research, corporate operations, and product innovation.</p>
<p><strong>About the Role</strong></p>
<p>As a Client Platform Engineer at OpenAI, you will play a pivotal role in securing, enhancing, and maintaining our endpoint management infrastructure across macOS, Windows, iOS, and Android devices. Your focus will be on building scalable, automated solutions that ensure seamless deployments, advanced security configurations, and efficient operational workflows. You will collaborate closely with IT, Security, and Engineering teams to implement modern endpoint management practices using automation, Infrastructure-as-Code (IaC), and monitoring strategies. This role offers an opportunity to work with cutting-edge tools and contribute to building a security-first, automation-driven endpoint ecosystem.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Design, build, implement, and maintain scalable and performant endpoint management infrastructure to facilitate best-in-class security of the OpenAI fleet comprised of macOS, Windows, iOS, and Android endpoints.</li>
</ul>
<ul>
<li>Deliver critical endpoint management efficiencies and capabilities through bespoke software development and implementation of both industry-standard open source tooling and first-party software solutions.</li>
</ul>
<ul>
<li>Employ modern Infrastructure-as-Code (IaC) methodologies, develop GitOps-driven solutions to deliver consensus-based fleet management capabilities at scale.</li>
</ul>
<ul>
<li>Build and maintain CI/CD pipelines for fleet management infrastructure, deploying to progressively tested environments across multiple clouds (Azure, AWS, GCP).</li>
</ul>
<ul>
<li>Drive initiatives to adopt emerging CPE technologies, industry best practices, and optimize processes for scalability and operational efficiency.</li>
</ul>
<ul>
<li>Partner with cross-functional teams to ensure seamless endpoint user experiences while maintaining strict security standards and continually increasing the bar.</li>
</ul>
<p><strong>You may be a fit for this role if you have:</strong></p>
<ul>
<li>Proficiency in a modern programming language (Python, Golang, Ruby, etc.)</li>
</ul>
<ul>
<li>Extensive hands-on experience with Jamf PRO and Microsoft Intune to ensure comprehensive secure fleet management as well as experience with similar cloud identity providers.</li>
</ul>
<ul>
<li>Demonstrated success and experience with open source endpoint management tooling for configuration management, mobile device management, application management, and telemetry such as Salt, Puppet, Munki, Nano/MicroMDM, osquery, Autopkg, WinGet, etc.</li>
</ul>
<ul>
<li>History of developing and delivering secure, reliable, scalable, and technology solutions.</li>
</ul>
<ul>
<li>Deep knowledge and experience managing corporate infrastructure at scale with Infrastructure-as-Code (IaC) practices &amp; GitOps workflows (Terraform, Ansible, Chef, etc.)</li>
</ul>
<ul>
<li>Experience integrating and operating fleet management infrastructure with CI/CD pipelines and DevOps workflows.</li>
</ul>
<ul>
<li>Proven track record of deploying and operating fleet management infrastructure in public cloud environments (Azure, AWS, GCP).</li>
</ul>
<ul>
<li>A self-starter with strong analytical and problem-solving skills.</li>
</ul>
<p><strong>You might thrive in this role if you have:</strong></p>
<ul>
<li>Deep experience with open-source fleet management tools and frameworks.</li>
</ul>
<ul>
<li>Experience with containerization technologies such as Docker and Kubernetes.</li>
</ul>
<ul>
<li>Familiarity with compliance frameworks such as SOC 2, ISO 27001, FedRAMP, and NIST.</li>
</ul>
<ul>
<li>Strong soft skills, including stakeholder communication and cross-functional collaboration.</li>
</ul>
<ul>
<li>Relevant professional certifications such as CISSP, CISA, CISM, CCSP.</li>
</ul>
<ul>
<li>A security thought leader with contributions to CPE open-source projects or technical communities.</li>
</ul>
<p><strong>About OpenAI</strong></p>
<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass and value the many different perspectives, voices, and experiences that form the full spectrum of humanity.</p>
<p>We are an equal opportunity employer, and we do not discriminate on the basis of</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>Full time</Jobtype>
      <Experiencelevel></Experiencelevel>
      <Workarrangement>Remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Python, Golang, Ruby, Jamf PRO, Microsoft Intune, Salt, Puppet, Munki, Nano/MicroMDM, osquery, Autopkg, WinGet, Terraform, Ansible, Chef, Docker, Kubernetes, Deep experience with open-source fleet management tools and frameworks, Experience with containerization technologies such as Docker and Kubernetes, Familiarity with compliance frameworks such as SOC 2, ISO 27001, FedRAMP, and NIST, Strong soft skills, including stakeholder communication and cross-functional collaboration, Relevant professional certifications such as CISSP, CISA, CISM, CCSP, A security thought leader with contributions to CPE open-source projects or technical communities</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. It is a company that pushes the boundaries of the capabilities of AI systems and seeks to safely deploy them to the world through its products.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/720bd7ae-2d65-4f1c-b01a-86278dedabde</Applyto>
      <Location>Remote - US</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>8ae6102f-700</externalid>
      <Title>GRC Automation Engineering Lead</Title>
      <Description><![CDATA[<p><strong>About the Role</strong></p>
<p>We are seeking a GRC Automation Lead to join our GRC organisation and build the technical foundation for how we scale our risk and compliance programs. In this role, you will lead the team that designs and implements automated workflows, data pipelines, and integrations that transform manual compliance processes into scalable engineering systems.</p>
<p>This is a greenfield opportunity to establish the team, architecture, and integrations that will define how we approach governance, risk, and compliance at Anthropic. The core challenge is a data problem: compliance information lives across dozens of systems—cloud infrastructure, identity providers, HR platforms, ticketing tools, code repositories—and your job is to design systems that bring it together, normalise it, and make it actionable.</p>
<p>At Anthropic, you&#39;ll also have a unique advantage: the ability to design AI-powered workflows where Claude acts as an extension of your team, handling tasks that would traditionally require additional headcount or manual effort. You&#39;ll need ingenuity to identify where agentic AI can accelerate evidence collection, interpret unstructured data, triage compliance gaps, and augment human judgment in risk assessments.</p>
<p>Working closely with Security, IT, and Engineering teams, you&#39;ll translate compliance and regulatory requirements into solutions that support audit programs including SOC 2, ISO, HIPAA, and FedRAMP, building systems that combine traditional automation with AI capabilities to achieve scale that wouldn&#39;t otherwise be possible.</p>
<p><strong>Responsibilities:</strong></p>
<ul>
<li>Lead the team that establishes foundational GRC processes and architecture. Design and build automated workflows for risk management and compliance, creating scalable systems that enable continuous monitoring as Anthropic grows.</li>
</ul>
<ul>
<li>Build data pipelines that aggregate risk, control, and asset information from across our technology stack. This means solving hard data integration problems: mapping disparate schemas, handling inconsistent data quality, and creating unified views of compliance posture through dashboards and reporting tools.</li>
</ul>
<ul>
<li>Inform GRC platform strategy and implementation: in partnership with other programs, evaluate, select, and deploy tooling that meets our compliance requirements.</li>
</ul>
<ul>
<li>Translate written policies and compliance requirements into policy-as-code—working with Engineering and Security teams to express requirements as enforceable rules, automated checks, and continuous validation rather than static documents.</li>
</ul>
<ul>
<li>Establish feedback loops between policy and implementation: surface where technical controls diverge from written requirements, identify where policies need to evolve based on infrastructure realities, and ensure that compliance requirements are expressed in terms engineers can act on.</li>
</ul>
<ul>
<li>Design and deploy agentic AI workflows that extend team capacity, using Claude to automate evidence analysis, monitor control effectiveness, draft audit responses, interpret policy documents, and handle other tasks that require reasoning over unstructured information.</li>
</ul>
<ul>
<li>Design and maintain integrations connecting GRC tooling with cloud infrastructure, identity management systems, HRIS platforms, ticketing systems, version control, and CI/CD pipelines—working with engineers to implement integrations that enable automated evidence collection and continuous compliance validation.</li>
</ul>
<ul>
<li>Build and lead the GRC Automation function as we scale: hiring team members, establishing practices, and defining the technical roadmap for governance and compliance automation at Anthropic.</li>
</ul>
<p><strong>You may be a good fit if you:</strong></p>
<ul>
<li>Have 3-4+ years of experience managing technical individual contributors or systems-focused teams, with a proven track record of building or scaling small teams (2-5 people) in security, compliance, automation, or operations functions.</li>
</ul>
<ul>
<li>Are a systems thinker first. You understand how complex environments work: how data flows between systems, where integration points exist, what breaks when systems don&#39;t talk to each other. Your strength is designing the right architecture and environment for security monitoring, not necessarily implementing it yourself.</li>
</ul>
<ul>
<li>Have 5+ years of experience designing automated workflows, data pipelines, or system integrations, whether through traditional development, low-code platforms, GRC tools, or process automation. We care about your ability to solve integration problems, not your programming language proficiency.</li>
</ul>
<ul>
<li>Proficiency to write production level code in at least one programming language (e.g., Python, Rust, Go)</li>
</ul>
<ul>
<li>Have a relentless focus on data integration: you understand how to pull data from multiple sources, normalise it, join it meaningfully, and surface insights. You&#39;re comfortable reasoning about messy, inconsistent data and designing systems that handle edge cases gracefully.</li>
</ul>
<ul>
<li>Understand APIs and integration patterns conceptually: REST APIs, webhooks, authentication flows, polling vs. push architectures, and can evaluate systems based on how well they expose data and support automation, even if you&#39;re not writing the integration code yourself.</li>
</ul>
<ul>
<li>Can work independently with minimal guidance, taking ownership of complex problems from design through implementation while managing ambiguity inherent in early-stage programs.</li>
</ul>
<ul>
<li>Have strong analytical and problem-solving skills, with the ability to break down complex problems into manageable parts and develop creative solutions.</li>
</ul>
<ul>
<li>Are able to communicate complex technical ideas to both technical and non-technical stakeholders, with a strong focus on collaboration and teamwork.</li>
</ul>
<ul>
<li>Are passionate about staying up-to-date with industry trends and emerging technologies, with a willingness to learn and adapt to new tools and techniques.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>GRC, Automation, Data Pipelines, System Integrations, APIs, Integration Patterns, REST APIs, Webhooks, Authentication Flows, Polling vs. Push Architectures, Data Integration, Data Normalisation, Data Joining, Data Modelling, Data Analysis, Data Visualisation, Agile Methodologies, Scrum, Kanban, Continuous Integration, Continuous Deployment, Continuous Monitoring, Cloud Infrastructure, Identity Providers, HR Platforms, Ticketing Tools, Code Repositories, Version Control, CI/CD Pipelines, GRC Tools, Policy-as-Code, Automated Checks, Continuous Validation, Feedback Loops, Policy Implementation, Technical Controls, Policy Evolution, Infrastructure Realities, Compliance Requirements, Engineer Communication, Technical Ideas, Collaboration, Teamwork, Industry Trends, Emerging Technologies, Learning, Adaptation, New Tools, New Techniques, Python, Rust, Go, Java, C++, JavaScript, TypeScript, SQL, NoSQL, Cloud Computing, DevOps, Security, Compliance, Risk Management, Audit Programs, SOC 2, ISO, HIPAA, FedRAMP, GRC Platforms, GRC Tools, Policy Management, Compliance Management, Risk Management, Audit Management, Compliance Automation, GRC Automation, Policy Automation, Compliance Orchestration, Risk Orchestration, Audit Orchestration, Compliance Intelligence, Risk Intelligence, Audit Intelligence, Compliance Analytics, Risk Analytics, Audit Analytics, Compliance Reporting, Risk Reporting, Audit Reporting, Compliance Dashboarding, Risk Dashboarding, Audit Dashboarding</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Anthropic</Employername>
      <Employerlogo>https://logos.yubhub.co/anthropic.com.png</Employerlogo>
      <Employerdescription>Anthropic is a technology company that aims to create reliable, interpretable, and steerable AI systems. It has a quickly growing team of researchers, engineers, policy experts, and business leaders.</Employerdescription>
      <Employerwebsite>https://job-boards.greenhouse.io</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/anthropic/jobs/4980335008</Applyto>
      <Location>San Francisco, CA | New York City, NY | Seattle, WA</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
  </jobs>
</source>