<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>11b88e19-a73</externalid>
      <Title>Data Centre Security Compliance Public Sector Specialist</Title>
      <Description><![CDATA[<p>About Us</p>
<p>At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world&#39;s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</p>
<p>We protect and accelerate any Internet application online without adding hardware, installing software, or changing a line of code. Internet properties powered by Cloudflare all have web traffic routed through its intelligent global network, which gets smarter with every request. As a result, they see significant improvement in performance and a decrease in spam and other attacks.</p>
<p>Key Responsibilities</p>
<p><strong>Public Sector &amp; Compliance Governance</strong></p>
<ul>
<li>Serve as the Subject Matter Expert (SME) on NIST 800-53 control families and FedRAMP requirements.</li>
<li>Manage Cloudflare&#39;s continuous monitoring program, inclusive of annual assessments and significant change requests.</li>
<li>Collect, validate, and organize FedRAMP evidence and artifacts to present to auditors, FedRAMP customers, and the FedRAMP PMO.</li>
<li>Help guide our overall security policy and governance architecture to ensure alignment with evolving government regulations.</li>
</ul>
<p><strong>Audit Lifecycle Management</strong></p>
<ul>
<li>Orchestrate end-to-end audit activities for standards such as PCI, SOC2, ISO, NIST, and FedRAMP.</li>
<li>Coordinate with auditors to manage data center access, compliance certificate collection, and evidence defense.</li>
<li>Work cross-functionally with Engineering, Legal, Product, and Operational teams to maintain management and technical controls.</li>
<li>Support compliance and regulatory projects, including implementation of new legislation / regulation.</li>
</ul>
<p><strong>Identity &amp; Access Management (IAM) Operations</strong></p>
<ul>
<li>Execute monthly Periodic Access Reviews (PARs): Compare portal user lists against ACLs to ensure least-privilege access is maintained across all data centers.</li>
<li>Manage the lifecycle of portal access: Auditing access, provisioning/deprovisioning users, and maintaining accurate documentation.</li>
<li>Oversee physical access requests to data centers and ensure strict adherence to security policies.</li>
<li>Drive the resolution of daily DCSC Jira tickets for portal access, physical access, audits, and site decommissioning.</li>
<li>Automate and streamline access review processes where possible, utilizing standard communication templates to site managers.</li>
</ul>
<p><strong>Partner Relations &amp; Reporting</strong></p>
<ul>
<li>Own, influence, and orchestrate relationships within the partner Offering teams that can help drive Cloudflare offerings and strategic positioning.</li>
<li>Monitor and implement changes to individual accountability regime requirements (such as UK, Ireland, Singapore and Australia).</li>
<li>Maintain centralized documentation, databases, dashboards, and reporting mechanisms to track compliance health.</li>
</ul>
<p>Requirements</p>
<ul>
<li>3-6 years working in Security Compliance, Information Security, or Risk Management.</li>
<li>Deep familiarity with all NIST 800-53 control families and FedRAMP requirements.</li>
<li>Ability to work closely with auditors and articulate technical concepts.</li>
<li>Experience in auditing of network, operating system, and application security.</li>
<li>Proven experience managing an audit throughout the full audit lifecycle (from readiness to final report).</li>
<li>Familiarity with additional security standards and frameworks such as ISO 27000, SOC 2, PCI DSS, ISMAP and IRAP.</li>
<li>Ability to work cross-functionally with internal stakeholders and strong communications skills.</li>
<li>High tolerance for ambiguity and ability to work efficiently and independently in a fast-paced, high-volume environment.</li>
<li>Some travel may be required to engage with regulators and auditors.</li>
<li>Certifications: CISSP, CIPP, CIPM, CIPT, CISA, or CRISC.</li>
<li>A relevant professional experience working with technology partners, alliances, or third-party vendors, ideally in the following disciplines: Data center Security Compliance, Access Management, audit administration at a leading high-tech company; offering management.</li>
<li>Technical skills including the ability to understand (1) product roadmaps; (2) market trends and factors; and (3) complex partner requirements.</li>
<li>Strong technical proficiency with spreadsheet software (Excel/Google Sheets) including pivot tables and VLOOKUPs for data reconciliation.</li>
<li>Organized &amp; Disciplined, with a strong focus on driving outcomes.</li>
</ul>
<p>Preferred</p>
<ul>
<li>Prior experience with Data Centre Security Compliance disciplines and audit programs and past history working at a hyperscaler or high-growth tech company.</li>
<li>Superb organizational skills and demonstrated history managing complex processes including audit cycles, Facts gathering and analytical skills.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>NIST 800-53 control families, FedRAMP requirements, Identity &amp; Access Management (IAM), Audit Lifecycle Management, Security Compliance, Information Security, Risk Management, CISSP, CIPP, CIPM, CIPT, CISA, CRISC, Data center Security Compliance, Access Management, audit administration, product roadmaps, market trends and factors, complex partner requirements</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Cloudflare</Employername>
      <Employerlogo>https://logos.yubhub.co/cloudflare.com.png</Employerlogo>
      <Employerdescription>Cloudflare operates one of the world&apos;s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies.</Employerdescription>
      <Employerwebsite>https://www.cloudflare.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/cloudflare/jobs/7477769</Applyto>
      <Location>Hybrid</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>78eb6171-ae5</externalid>
      <Title>Staff Technical Program Manager, Security</Title>
      <Description><![CDATA[<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk. The Okta Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution through identifying and resolving risks to the employees, product, and most importantly, our customers. With the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business. As a Staff Technical Program Manager supporting the Cyber Defense team, you will play a critical role in driving large-scale security projects. You will partner with our global Cyber Defense Operations and Engineering teams to design, build, and enhance the capabilities we use to protect Okta and our customers. This role requires exceptional leadership skills, demonstrated by an ability to influence and align stakeholders at all levels - from individual engineers to leadership. You’ll drive effective teamwork, resolve conflict, negotiate priorities, and foster a culture of shared commitment to a common goal. The ideal candidate has extensive experience in cybersecurity and a proven track record of managing technical programs in a fast-paced, cloud-native environment. This position requires strong leadership, ownership and autonomy, and executive communication skills, with the ability to translate complex technical challenges into clear, actionable plans. Job Duties and Responsibilities: Manage large scale, complex initiatives across multiple teams; taking a hands-on and proactive approach to manage dependencies, unblock progress, define timelines, communicate commitments, and introduce efficiencies Operate with a high degree of autonomy and discretion, defining the path forward for complex technical and operational challenges with minimal guidance Unify and drive effective teamwork, communication, collaboration, and commitments across multiple disparate groups with competing priorities Anticipate and mitigate risks by having close involvement with team goals and challenges, applying past experience, and keeping the big picture in mind Lead the introduction of new processes and improvements to mature Cyber Defense capabilities and improve operational efficiency Develop and maintain metrics and dashboards to report on program status using Jira and other tools Collaborate across Okta to drive transparency of security programs Minimum REQUIRED Knowledge, Skills, and Abilities: Bachelor’s degree or higher in Computer Science or Management Information Systems, or equivalent experience 5+ years of experience in technical program management, with at least 3 years focused on cybersecurity Demonstrated ability to create structure and clarity from ambiguous, high-level directives, translating them into concrete and actionable roadmaps Extensive working experience with security or engineering teams Working knowledge of technical terms and concepts used in information security, privacy, risk and contingency planning Exceptional communication and collaboration skills with the ability to influence and align stakeholders across all levels Experience working with Atlassian products, specifically Jira and Confluence Strong analytical and problem-solving skills and the ability to “think-out-of-the-box” Strong oral and written communication skills Able to work independently and as part of a distributed, global team Helpful Certifications / Skills: Certified ScrumMaster (CSM) Program Management Professional (PMP) Security certifications such as CISSP, CISM, or other relevant credentials Technical background in security engineering, security operations, or incident response Familiarity with Okta’s products and services #LI-HYBRID #LI-SH1 P17983_3404596 Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit: https://rewards.okta.com/can. The annual base salary range for this position for candidates located in Canada is between:$131,000-$180,400 CAD The Okta Experience - Supporting Your Well-Being - Driving Social Impact - Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants &amp; Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice. Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at https://www.okta.com/legal/personnel-policy.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$131,000-$180,400 CAD</Salaryrange>
      <Skills>technical program management, cybersecurity, Jira, Confluence, Atlassian products, security or engineering teams, information security, privacy, risk and contingency planning, communication and collaboration skills, influence and align stakeholders, cloud-native environment, security engineering, security operations, incident response</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta provides identity and access management solutions.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7775832</Applyto>
      <Location>Toronto, Ontario, Canada; Vancouver, Canada</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>85f63ecb-5fc</externalid>
      <Title>Staff Security Engineer</Title>
      <Description><![CDATA[<p>Secure Every Identity, from AI to Human</p>
<p>Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.</p>
<p>This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>
<p><strong>Staff Security Engineer</strong></p>
<p>Okta is The World’s Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.</p>
<p>At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.</p>
<p>Join our team! We’re building a world where Identity belongs to you.</p>
<p><strong>Responsibilities</strong></p>
<p>The Staff Security Engineer is a key role for strengthening the organisation&#39;s security posture. You&#39;ll be responsible for performing security assessments of third-party integrations and connected apps, with a focus on mitigating API-related security risks. This position is vital for ensuring a &#39;secure-by-design&#39; approach for critical systems within the organisation.</p>
<p><strong>What You Will Do</strong></p>
<ul>
<li>Lead Technical Security Reviews: Perform in-depth security reviews and threat modelling for complex enterprise applications and third-party integrations.</li>
</ul>
<ul>
<li>Operationalize AI for Security: Take the lead in deploying and managing AI for Security use cases, such as integration security reviews, to automate and scale security operations.</li>
</ul>
<ul>
<li>Risk Analysis &amp; Documentation: Analyse and document API permissions and risk levels for major integrations (e.g., Salesforce, Slack, Google) to ensure they meet internal standards.</li>
</ul>
<ul>
<li>Develop Workflow Processes: Collaborate with stakeholders to design and implement repeatable security review workflows, such as the Salesforce API Integration Review.</li>
</ul>
<ul>
<li>Vulnerability &amp; Control Gap Mitigation: Identify potential vulnerabilities and security control gaps in connected apps and recommend technical mitigation strategies to stakeholders.</li>
</ul>
<ul>
<li>Report &amp; Visualize Posture: Contribute to and maintain metrics and dashboards that demonstrate the organisation&#39;s overall security posture for leadership.</li>
</ul>
<p><strong>What You Bring</strong></p>
<ul>
<li>Deep Technical Expertise: Proven experience in information security, specifically within application and enterprise security domains.</li>
</ul>
<ul>
<li>API &amp; Integration Specialist: Strong background in assessing and mitigating risks associated with third-party APIs and connected application ecosystems.</li>
</ul>
<ul>
<li>Advanced Security Principles: Understanding of &#39;secure-by-design&#39; principles and the &#39;least privilege&#39; model.</li>
</ul>
<ul>
<li>Practical Threat Modelling: Hands-on experience identifying attack vectors and conducting risk assessments for complex systems.</li>
</ul>
<ul>
<li>Tooling &amp; AI Proficiency: Experience working with security platforms for analysing application permissions and an interest or background in applying AI to streamline security tasks.</li>
</ul>
<ul>
<li>Collaborative Influencer: Exceptional communication skills with a track record of aligning multiple teams toward shared security goals.</li>
</ul>
<ul>
<li>Education: A Bachelor&#39;s degree in Computer Science, information security, or a related field.</li>
</ul>
<p><strong>Benefits</strong></p>
<p>In addition to the annual base salary range for this position, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$141,000-$193,000 CAD</Salaryrange>
      <Skills>information security, application security, enterprise security, API security, integration security, threat modelling, risk analysis, security review workflows, vulnerability mitigation, security control gap mitigation, security posture visualization</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta is a software company that provides identity and access management solutions. It has a global presence with over 20 offices worldwide.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7397934</Applyto>
      <Location>Toronto, Ontario, Canada</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>6bc635c8-b18</externalid>
      <Title>Staff Security Analyst, Customer Assurance</Title>
      <Description><![CDATA[<p>Secure Every Identity instituting AI is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.</p>
<p>We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>
<p>The Okta Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution by identifying and resolving risks to the employees, product, and most importantly, our customers. The Security Trust &amp; Culture team works to enhance customer trust in Okta’s identity services . We serve as a strategic resource working closely with Okta’s go-to-market teams.</p>
<p>As a Staff level analyst of Customer Assurance, you will support prioritising and efficiently responding to questions about our security programme and other due diligence related requests. You will act as a critical bridge between our customers and our internal engineering teams, ensuring Okta’s security posture is communicated effectively.</p>
<p>Tasks will include training local Sales teams, managing complex escalations in the regional market, and driving technological changes to help Customer Assurance scale its efforts globally. This position requires a unique combination of skills including an ability to coordinate the analysis of technical issues, to communicate clearly about security-relevant topics with both internal and external customers, to collaborate with internal business units to ensure execution of time-sensitive projects, and to present to upper management or the broader organisation as required.</p>
<p>The ideal candidate will have experience with SaaS cloud security risk assessment and a solid understanding of the core principles of identity management. If you want to make a difference in the security programme of a global cloud provider, we want you on board.</p>
<p>Job Duties and Responsibilities:</p>
<p>Serve as the critical bridge between Okta’s customers and internal Engineering/Product Security teams. You must be able to unpack complex customer security concerns, hold in-depth technical discussions with internal engineering to align on solutions, and translate Okta’s security architecture back to the customer to resolve high-stakes inquiries.</p>
<p>Take end-to-end ownership of highly technical security questionnaires and due-diligence requests, Partner seamlessly with internal subject matter experts,including our specialised Federal/FedRAMP teams,to ensure accurate, timely, and high-quality responses for highly regulated customers.</p>
<p>Drive technological changes within Customer Assurance by identifying and implementing AI and automation strategies to streamline workflows, scale global efforts, and reduce response times.</p>
<p>Train and empower regional Go-To-Market and Sales teams on standard engagement protocols, ensuring they can leverage Customer Assurance resources smoothly to accelerate deals.</p>
<p>Collaborate with the Security Trust &amp; Culture team and Regional CSOs to develop, publish, and maintain forward-facing security collateral, FAQs, and field communications.</p>
<p>Work within a global team, participating or leading global handoffs between American timezones and European or Asian, when required for large security or industry events.</p>
<p>Requirements:</p>
<p>Bachelor’s degree in Computer Science or Management Information Systems, or equivalent work experience in technology or information security fields</p>
<p>Minimum 3 years information security, project management, or related experience</p>
<p>A strong, fundamental understanding of core Security principles, architectures, and operations.</p>
<p>Understanding of IT and cloud methodologies, information security, privacy, identity management, risk assessments and IT regulation and compliance standards</p>
<p>Strong oral, written, and presentation skills</p>
<p>Strong written and verbal communication skills, with a proven ability to distill complex technical concepts into clear, concise responses for both technical customers and internal executive stakeholders.</p>
<p>Helpful Certifications / Skills:</p>
<p>Okta Certified Professional/Administrator</p>
<p>Certificate of Cloud Security Knowledge (CCSK) and/or Certificate of Cloud Auditing Knowledge (CCAK)</p>
<p>Certified Information Security Auditor (CISA)</p>
<p>Experience with generative AI tools or process automation platforms is a strong plus.</p>
<p>Familiarity with Federal or highly regulated compliance frameworks (e.g., FedRAMP, StateRAMP, NIST 800-53, or DoD IL4/IL5)</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$148,000-$203,500 USD</Salaryrange>
      <Skills>Okta Certified Professional/Administrator, Certificate of Cloud Security Knowledge (CCSK) and/or Certificate of Cloud Auditing Knowledge (CCAK), Certified Information Security Auditor (CISA), generative AI tools or process automation platforms, Federal or highly regulated compliance frameworks (e.g., FedRAMP, StateRAMP, NIST 800-53, or DoD IL4/IL5)</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta provides identity and access management solutions for businesses.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7743848</Applyto>
      <Location>Bellevue, Washington; Chicago, Illinois; New York, New York; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>5f7c499a-533</externalid>
      <Title>Senior Software Engineer, Security</Title>
      <Description><![CDATA[<p>As a Senior Software Engineer in the Security organization at CoreWeave, you will design, build and deploy services, platforms and tools that help provide common foundational capabilities that various security programs and initiatives rely on to keep CoreWeave secure.</p>
<p>Automation to eliminate manual steps involved in understanding security risks, remediating and preventing them would be the charter. The work sits at the intersection of engineering systems and regulatory requirements, translating requirements into scalable, reliable, production grade infrastructure. Often this means building production infrastructure from scratch in many cases, and would need end to end ownership of systems including design, development, testing and deployment including implementing effective integration pipelines (CI/CD) and offering a reliable production system that should be highly available and function at scale.</p>
<p>You will partner closely with various security teams including GRC, platform engineering, and security domain teams to translate business needs into durable technical needs, while retaining full engineering ownership of how those systems are designed, built, and operated.</p>
<p>In this role, you will:</p>
<ul>
<li>Design and build scalable systems.</li>
<li>Develop control integrations and data pipelines to normalize security telemetry across IAM, logs, scanners, and CCM/GRC tools.</li>
<li>Build metrics engines, dashboards, and insights pipelines that provide real-time visibility into compliance health and emerging risks.</li>
</ul>
<p>On this team, you will:</p>
<ul>
<li>Tackle security &amp; compliance puzzles at cutting-edge scale and complexity</li>
<li>Collaborate with brilliant engineers who are redefining compliance adherence for cloud infrastructure.</li>
<li>You&#39;ll have the freedom and responsibility to innovate, experiment, and influence how we establish assurance pipelines.</li>
</ul>
<p>Investing in our people is one of our top priorities, and we value candidates who can bring their diversified experiences to our teams. Here are some qualities we’ve found compatible with our team. We&#39;d love to talk about whether this aligns with your experience and interests and what you’re excited to work on next.</p>
<p>Who You Are:</p>
<p>Minimum Qualifications</p>
<ul>
<li>A Bachelor’s degree in Information Security, Computer Science, or a related field or equivalent job experience.</li>
<li>At least 7+ years of hands-on experience in programming languages like Go.</li>
<li>At least 3+ years of hands-on experience deploying and managing Kubernetes clusters in a production environment.</li>
<li>Experience building high qps and critical distributed systems.</li>
<li>Familiarity with modern CI/CD practices and Infrastructure-as-Code tooling.</li>
<li>Proven experience building and deploying containerized applications.</li>
<li>Strong experience with technical architectures involving data flows, event driven architecture, access controls, retention, and third-party integrations.</li>
<li>Strong hands-on experience with cloud infrastructure (AWS, GCP).</li>
</ul>
<p>Preferred:</p>
<ul>
<li>Information Security Engineering experience.</li>
<li>Expertise in major compliance and security frameworks (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, NIST, CSF).</li>
<li>Background in building automation for distributed cloud environments at scale.</li>
<li>Experience with remote-access solutions like Teleport (real bonus points if you’ve submitted PRs on their product).</li>
<li>Understanding of the SSO protocols, specifically OIDC and SAML.</li>
<li>Hands-on experience with PKI and mTLS.</li>
</ul>
<p>If you&#39;re eager to elevate compliance into a creative, strategic force within a fast-paced, forward-thinking company, we&#39;d love to hear from you!</p>
<p>The base salary range for this role is $165,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).</p>
<p>What We Offer</p>
<p>The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs, including:</p>
<ul>
<li>Medical, dental, and vision insurance</li>
<li>100% paid for by CoreWeave</li>
<li>Company-paid Life Insurance</li>
<li>Voluntary supplemental life insurance</li>
<li>Short and long-term disability insurance</li>
<li>Flexible Spending Account</li>
<li>Health Savings Account</li>
<li>Tuition Reimbursement</li>
<li>Ability to Participate in Employee Stock Purchase Program (ESPP)</li>
<li>Mental Wellness Benefits through Spring Health</li>
<li>Family-Forming support provided by Carrot</li>
<li>Paid Parental Leave</li>
<li>Flexible, full-service childcare support with Kinside</li>
<li>401(k) with a generous employer match</li>
<li>Flexible PTO</li>
<li>Catered lunch each day in our office and data center locations</li>
<li>A casual work environment</li>
<li>A work culture focused on innovative disruption</li>
</ul>
<p>Our Workplace</p>
<p>While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.</p>
<p>California Consumer Privacy Act - California applicants only</p>
<p>CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: careers@coreweave.com.</p>
<p>Export Control Compliance</p>
<p>This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$165,000 to $242,000</Salaryrange>
      <Skills>Go, Kubernetes, Cloud infrastructure, CI/CD practices, Infrastructure-as-Code tooling, Containerized applications, Technical architectures, Data flows, Event driven architecture, Access controls, Retention, Third-party integrations, Information Security Engineering, Compliance and security frameworks, Automation for distributed cloud environments, Remote-access solutions, SSO protocols, PKI and mTLS</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>CoreWeave</Employername>
      <Employerlogo>https://logos.yubhub.co/coreweave.com.png</Employerlogo>
      <Employerdescription>CoreWeave is a cloud computing company that provides a platform for building and scaling AI applications.</Employerdescription>
      <Employerwebsite>https://www.coreweave.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/coreweave/jobs/4651859006</Applyto>
      <Location>Sunnyvale, CA</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>946d6893-cbb</externalid>
      <Title>Infrastructure Security Engineer (USA)</Title>
      <Description><![CDATA[<p>As a member of the Infrastructure Security Team within the Product Security Department, you will work with teams across GitLab to ensure that the components that comprise our cloud infrastructure are built with the resiliency and security expectations that our customers depend on to power their software factories.</p>
<p>We’re looking for an Intermediate Infrastructure Security Engineer to further our automation efforts in support of our GitLab Dedicated for Government product offering. You’ll have the opportunity to contribute to tooling that operates our FedRAMP environment, identify and develop remediations for infrastructure vulnerabilities, and partner with more senior engineers to review upcoming project architectures to ensure that they are built to the rigorous standards we hold.</p>
<p>Support the Public Sector SRE team as a stable counterpart, identify and help mitigate security issues, misconfigurations, and vulnerabilities related to GitLab’s cloud, container and Kubernetes infrastructure, build tooling to increase our visibility into environments to expedite vulnerability detection, own efforts securing GitLab&#39;s FedRAMP environment, support other security teams as an Infrastructure SME, document best practices and remediations to help engineers learn from common vulnerability types, partner with senior engineers to review new architectures and projects and provide feedback cross-functionally, fulfill the Product Security Division Mission of securing GitLab Infrastructure with our own product (“dogfooding”).</p>
<p>To be successful in this role, you will need to have hands-on experience with public cloud providers (ex. AWS, GCP, Azure), development experience with Ruby, Python, Go, experience with Infrastructure-as-Code (IaC) tools (ex. Terraform, Ansible, Chef), knowledge of the Linux operating system, familiarity with containers (Docker) and orchestration platforms (Kubernetes), an interest in Information Security, demonstrated experience working collaboratively with cross-functional teams, proficiency to communicate over a text-based medium (Slack, GitLab Issues, Email) and can succinctly document technical details, share our values, and work in accordance with those values.</p>
<p>Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$103,600-$185,000 USD</Salaryrange>
      <Skills>public cloud providers, Ruby, Python, Go, Infrastructure-as-Code (IaC) tools, Linux operating system, containers (Docker), orchestration platforms (Kubernetes), Information Security</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>GitLab</Employername>
      <Employerlogo>https://logos.yubhub.co/about.gitlab.com.png</Employerlogo>
      <Employerdescription>GitLab is an intelligent orchestration platform for DevSecOps, used by over 50 million registered users and more than 50% of the Fortune 100.</Employerdescription>
      <Employerwebsite>https://about.gitlab.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/gitlab/jobs/8459132002</Applyto>
      <Location>Remote, US</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>783da6f9-774</externalid>
      <Title>Senior Counsel, Professional Services GTM</Title>
      <Description><![CDATA[<p>We&#39;re looking for a Senior Counsel to join our growing go-to-market legal team. As a Senior Counsel, you will be responsible for reviewing and negotiating partner and customer agreements globally, focusing on balancing/mitigating risk for the company while continuing to enable our rapid revenue growth.</p>
<p>You will cultivate strong relationships with field sales by providing sound, strategic counsel to support ongoing go-to-market efforts. You will help maintain and update our legal agreements, with particular focus on professional services, ensuring that terms and internal policies are positioned to continue enabling rapid revenue growth and maintaining long-term stability for the company.</p>
<p>As a solutions-oriented business partner, you will provide pragmatic, sound legal counsel to internal Databricks clients and our growing customer base based on your understanding of Databricks&#39; technology, professional services offerings, information security architecture, and data privacy/compliance policies.</p>
<p>You will work cross-functionally with our business partners (e.g., Finance, Information Security, Product, and privacy) to align, communicate, and enforce applicable policies and controls in our global contracting processes.</p>
<p>We are looking for a minimum of seven (7) years of technology transactions experience, either at a law firm and/or in-house Attorney role. You should have relevant commercial transactional experience working for and/or supporting cloud-based software companies, including an understanding of professional service delivery to support consumption growth.</p>
<p>Substantial experience drafting, negotiating, and closing complex professional services agreements and a strong understanding of contractual issues related to information security, data privacy, artificial intelligence, and intellectual property is required.</p>
<p>You should have proven ability to successfully navigate and counsel on complex legal issues while balancing and/or mitigating material risk. You should be able to prioritize competing demands and be responsive to client expectations in a fast-paced environment within a limited time period.</p>
<p>Outstanding written and verbal communication skills are essential. A growth mindset, strong attention to detail, excellent critical thinking, and problem-solving abilities are also required.</p>
<p>Experience and/or strong interest in mentoring and guiding junior legal team members is a plus. A JD and good standing to practice law in the relevant jurisdiction are necessary.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$219,800-$302,300 USD</Salaryrange>
      <Skills>Commercial legal transactional experience, Professional services experience, Cloud-based software companies, Information security, Data privacy, Artificial intelligence, Intellectual property</Skills>
      <Category>Legal</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a unified platform for data, analytics, and AI. It was founded by the original creators of Lakehouse, Apache Spark, Delta Lake, and MLflow.</Employerdescription>
      <Employerwebsite>https://databricks.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/8199401002</Applyto>
      <Location>Bellevue, Washington; Mountain View, California; San Francisco, California; Seattle, Washington</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>4d64bed7-54a</externalid>
      <Title>Commercial Counsel</Title>
      <Description><![CDATA[<p>We&#39;re looking for an experienced commercial attorney to join Databricks&#39; growing commercial and go-to-market legal team. As Legal Counsel, you will be joining a team of legal professionals responsible for reviewing and negotiating customer agreements and providing legal support for Databricks&#39; revenue-generating activities.</p>
<p>You will report to the Director &amp; AGC, Commercial Legal. You have 4+ years of relevant commercial legal transactional experience with a focus on complex technology transactions. You have meaningful experience negotiating SaaS commercial transactions and strong knowledge/experience counseling on legal issues related to data privacy, information security, artificial intelligence, and intellectual property, including open source software.</p>
<p>The impact you will have:</p>
<ul>
<li>Become an important member of the commercial and go-to-market legal team responsible for reviewing and negotiating commercial customer agreements. Focus on balancing/mitigating risk for the company while continuing to enable our rapid revenue growth.</li>
</ul>
<ul>
<li>Cultivate strong relationships with field sales by providing sound, strategic counsel to close sales transactions and support ongoing go-to-market efforts.</li>
</ul>
<ul>
<li>Help maintain and update our legal agreements, ensuring that terms and internal policies are positioned to continue enabling rapid revenue growth and maintaining long-term stability for the company.</li>
</ul>
<ul>
<li>Serve as a solutions-oriented business partner by providing pragmatic, sound legal counsel to internal Databricks clients and our growing customer base based on your understanding of Databricks&#39; technology, product portfolio, information security architecture, and data privacy/compliance policies.</li>
</ul>
<ul>
<li>Work cross-functionally with our business partners (e.g., Finance, Information Security, Product, and Privacy) to align, communicate, and enforce applicable policies and controls to our global contracting processes.</li>
</ul>
<p>What we look for:</p>
<ul>
<li>Minimum of four (4) years of technology transactions experience either at a law firm and/or in-house Attorney role.</li>
</ul>
<ul>
<li>Relevant commercial transactional experience working for and/or supporting cloud-based software companies, including an understanding of consumption/commit-based business models and the quarterly sales cadence.</li>
</ul>
<ul>
<li>Demonstrated experience drafting, negotiating, and closing complex software sell-side transactions and a strong understanding of contractual issues related to information security, data privacy, artificial intelligence, and intellectual property, including open source software.</li>
</ul>
<ul>
<li>Proven ability to successfully navigate and counsel on complex legal issues while balancing and/or mitigating material risk.</li>
</ul>
<ul>
<li>Able to prioritize competing demands and be responsive to client expectations in a fast-paced environment within a limited time period.</li>
</ul>
<ul>
<li>Outstanding written and verbal communication skills.</li>
</ul>
<ul>
<li>Growth mindset, strong attention to detail, excellent critical thinking, and problem-solving abilities.</li>
</ul>
<ul>
<li>Teaming approach with a focus on building a strong interlock with clients, business partners, and key stakeholders.</li>
</ul>
<ul>
<li>JD and good standing to practice law in the relevant jurisdiction</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$172,900-$237,700 USD</Salaryrange>
      <Skills>Commercial legal transactional experience, Complex technology transactions, SaaS commercial transactions, Data privacy, Information security, Artificial intelligence, Intellectual property, Open source software</Skills>
      <Category>Legal</Category>
      <Industry>Technology</Industry>
      <Employername>Databricks</Employername>
      <Employerlogo>https://logos.yubhub.co/databricks.com.png</Employerlogo>
      <Employerdescription>Databricks is a data and AI company that provides a data and AI platform to unify and democratize data, analytics, and AI.</Employerdescription>
      <Employerwebsite>https://databricks.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/databricks/jobs/8459031002</Applyto>
      <Location>Bellevue, Washington; Denver, Colorado; Seattle, Washington; Washington, D.C.</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>22e2b8bb-55b</externalid>
      <Title>Cybersecurity Officer</Title>
      <Description><![CDATA[<p>As the Cybersecurity Officer for Waymark, you will be responsible for advancing our core mission through the development of robust programs encompassing information security. As an organization working with patients and providers to improve health outcomes, it is critical to build and maintain appropriate systems and safeguards designed to protect the integrity and confidentiality of information.</p>
<p>You are technical, a strong operator, and strategic thinker, looking to build, improve, and scale reliable security processes whenever possible. Your leadership of the information security program at Waymark will include all facets of cybersecurity, and the associated user experience of our remote teams, and community-based care workers. You will be responsible for security policy and implementation and operation of technical and administrative safeguards to support those policies. You will use your experience to inform sound judgement to achieve the appropriate management of security risks in a manner consistent with the company’s values. You will use your in-depth knowledge of security in a modern cloud based organization, to identify and address risks to the company, through a combination of hands-on technical contributions and directing and overseeing staff with security responsibilities. You will interact with the broader executive leadership team to communicate evolving needs, matching the security strategy to the size and stage of growth of the company and the information we safeguard.</p>
<p>This is a remote friendly position that can be located anywhere in the United States.</p>
<p><strong>Key Responsibilities &amp; Duties</strong></p>
<ul>
<li>Oversee the internal cybersecurity program, road map, and strategy, which includes developing and implementing procedures and policies designed to protect Waymark communications, systems, and assets from internal and external threats and that safeguards health information.</li>
<li>Oversee and manage Waymark’s MSSP and outsourced IT vendor, including responsibility for security and IT budgets, and IT tools used by Waymark.</li>
<li>Partner with Product, Engineering, Legal, and Compliance leadership to determine risks and deploy risk management processes, supporting Waymark’s secure software development lifecycle and ensuring that our internally developed products and services meet the expectations of our patients, customers and regulators</li>
<li>Own, define and oversee the necessary security operational functions such as Identity Management, Vulnerability Management, Incident Response, Security Awareness, and Vendor Risk Management</li>
<li>Serve as Waymark’s HIPAA Security Officer, ensuring compliance with the HIPAA Security Rule, working closely with the legal team to document, review, maintain, and implement standards, policies, and procedures within security disciplines.</li>
<li>Lead the strategy, implementation, and maintenance of industry-standard security certifications, including SOC2 Type II.</li>
<li>Conduct research, analysis, and correlation across a wide variety of source data to identify and prevent compromise of our networks, host systems, and data.</li>
<li>Track and report on network security to the Waymark executive leadership team</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$140,000 - $185,000</Salaryrange>
      <Skills>BSCS or equivalent experience in an operational security role, 10+ years of experience in security and/or information assurance roles, and risk management, Knowledge of information security management frameworks, such as NIST cybersecurity framework, Experience and/or ability to learn and apply hands-on skills in a cloud native production environment, Experience implementing cloud security technologies, including encryption, network security, intrusion detection, and could monitoring, Key industry certifications in information security, such as CISSP, CISM and CISA, Experience in a startup of 100 - 500 people, Experience with securing a production SaaS product hosted in AWS, Experience conducting or managing technical audit engagements, or directly responding to auditor inquiries</Skills>
      <Category>IT</Category>
      <Industry>Healthcare</Industry>
      <Employername>Waymark</Employername>
      <Employerlogo>https://logos.yubhub.co/waymark.com.png</Employerlogo>
      <Employerdescription>Waymark is a healthcare provider that works with patients and providers to improve health outcomes. It has a team of healthcare providers, technologists, and builders.</Employerdescription>
      <Employerwebsite>https://www.waymark.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/waymark/jobs/4675847005</Applyto>
      <Location>US - Remote</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>7d12908d-085</externalid>
      <Title>Member of Compliance, TPRM</Title>
      <Description><![CDATA[<p>At Anchorage Digital, we are building the world&#39;s most advanced digital asset platform for institutions to participate in crypto.</p>
<p>The mission of this role is to support the design and enhancement of the Third Party Risk Management program, across both regulated and non-regulated entities, ensuring alignment with regulatory requirements (OCC, FFIEC, MAS, DORA, Federal Reserve, NY DFS, etc) as well as industry leading practices.</p>
<p>This role will also identify program enhancements in support of emerging risks impacting outsourced products / services.</p>
<p>This role will particularly contribute to the execution and optimization of due diligence and ongoing monitoring risk assessments with focus on Information Technology and Information Security as well as Quality Control process enhancement.</p>
<p><strong>Responsibilities</strong></p>
<p>Lead and manage the Third Party Findings Management process across key risk impact categories with specific focus on: weekly, monthly and quarterly status reporting to track findings to closure in partnership with Risk SMEs, and creation of documentation to support Third Party Risk Management program evolution leveraging industry leading practices.</p>
<p>Drive the optimization of the Due Diligence and Ongoing Monitoring risk assessment process across regulated and non-regulated Anchorage Digital legal entities to include reviews of the following key risk impact categories: Financial, Business Continuity, Information Security, as well as additional risk reviews based on risk and complexity of product / service being outsourced.</p>
<p>Lead and manage the TPRM Quality Control process across regulated and non-regulated Anchorage Digital legal entities, including maintaining the schedule of reviews to be performed, assessing the status of in-progress reviews, analyzing findings to identify common themes or trends for training and development, documentation and reporting to key stakeholders specific to review closure activities.</p>
<p>Assist on various TPRM Projects as needed with minimal supervision required</p>
<p><strong>Complexity and Impact of Work</strong></p>
<p>Manage and enhance Procedures related to the Third Party Findings Management process and support the standardization of findings management across regulated and non-regulated legal entities.</p>
<p>Create and manage Procedures related to the Third Party Risk Management Quality Control process and support the implementation of Quality Control across regulated and non-regulated legal entities.</p>
<p><strong>Organizational Knowledge</strong></p>
<p>Collaborate across the organization to understand business requirements in support of TPRM Program to include regulated and non-regulated legal entities in alignment with TPRM program evolution.</p>
<p><strong>Communication and Influence</strong></p>
<p>Independently create and consistently refine summaries, reports, and governance documentation associated with the Third Party Risk Management Program</p>
<p>Independently and consistently refine summaries, reports and governance documentation to support Third Party Findings Management program evolution.</p>
<p>Effectively communicate with stakeholders such as Risk Subject Matter Experts (SMEs) and relevant Relationship Owners and Relationship Managers.</p>
<p><strong>You may be a fit for this role if you have:</strong></p>
<p>Regulated Financial Institution experience Third Party Findings Management experience Information Security assessment experience TPRM Quality Control experience</p>
<p>Although not a requirement, bonus points if:</p>
<p>You previously directly worked with Financial Service regulators to include Office of the Comptroller of the Currency (OCC), New York Department of Financial Services (NY DFS), Federal Financial Institutions Examination Council (FFIEC), Monetary Authority of Singapore (MAS), and other regulatory bodies</p>
<p>You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Third Party Risk Management, Financial Institution experience, Information Security assessment, TPRM Quality Control, Risk Management</Skills>
      <Category>Finance</Category>
      <Industry>Finance</Industry>
      <Employername>Anchorage Digital</Employername>
      <Employerlogo>https://logos.yubhub.co/anchorage.com.png</Employerlogo>
      <Employerdescription>Anchorage Digital is a crypto platform that enables institutions to participate in digital assets through custody, staking, trading, governance, settlement, and the industry&apos;s leading security infrastructure.</Employerdescription>
      <Employerwebsite>https://anchorage.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.lever.co/anchorage/cc0ae37a-0c44-4574-8c4c-ddaa0edefc47</Applyto>
      <Location>United States</Location>
      <Country></Country>
      <Postedate>2026-04-17</Postedate>
    </job>
    <job>
      <externalid>d63f049e-ad7</externalid>
      <Title>Security Lead, Agentic Red Team</Title>
      <Description><![CDATA[<p>Job Title: Security Lead, Agentic Red Team</p>
<p>We&#39;re a team of scientists, engineers, and machine learning experts working together to advance the state of the art in artificial intelligence. Our mission is to close the &#39;Agentic Launch Gap&#39;; the critical window where novel AI capabilities outpace traditional security reviews.</p>
<p>As the Security Lead for the Agentic Red Team, you will direct a specialized unit of AI Researchers and Offensive Security Engineers focused on adversarial AI and agentic exploitation. Operating as a technical player-coach, you will architect complex, multi-turn attack scenarios while managing cross-functional partnerships with Product Area leads and Google security to influence launch criteria.</p>
<p>Key Responsibilities:</p>
<ul>
<li>Direct Agile Offensive Security: Lead a specialized red team focused on rapid, high-impact engagements targeting production-level AI models and systems.</li>
<li>Perform Complex AI Exploitation: Develop and carry out advanced attack sequences that focus on vulnerabilities unique to GenAI, such as escalating privileges through tool usage, poisoning data, and executing multi-turn prompt injections.</li>
<li>Design Automated Validation Systems: Collaborate with Google teams to engineer &#39;Auto RedTeaming&#39; solutions that transform manual vulnerability discoveries into robust, automated regression testing frameworks.</li>
<li>Engineer Technical Countermeasures: Create innovative defense-in-depth frameworks and control systems to mitigate agentic logic errors and non-deterministic model behaviors.</li>
<li>Manage Threat Intelligence Assets: Develop and oversee an evolving inventory of exploit primitives and agent-specific attack patterns used to establish release criteria and evaluate model security benchmarks.</li>
<li>Establish Security Scope: Collaborate with Google for conventional infrastructure protection, allowing the team to concentrate solely on agentic logic, model inference, and AI-centric exploits.</li>
</ul>
<p>About You:</p>
<ul>
<li>Bachelor&#39;s degree in Computer Science, Information Security, or equivalent practical experience.</li>
<li>Experience in Red Teaming, Offensive Security, or Adversarial Machine Learning.</li>
<li>Deep technical understanding of LLM architectures and agentic workflows (e.g., chain-of-thought reasoning, tool usage).</li>
<li>Proven ability to work in a consulting capacity with product teams, driving security improvements in fast-paced release cycles.</li>
<li>Experience managing or technically leading small, high-performance engineering teams.</li>
</ul>
<p>In addition, the following would be an advantage:</p>
<ul>
<li>Hands-on experience developing exploits for GenAI models (e.g., prompt injection, adversarial examples, training data extraction).</li>
<li>Familiarity with AI safety benchmarks and evaluation frameworks.</li>
<li>Experience writing code (Python, Go, or C++) to build automated security tools or fuzzers.</li>
<li>Ability to communicate complex probabilistic risks to executive stakeholders and engineering teams effectively.</li>
</ul>
<p>The US base salary range for this full-time position is between $248,000 - $349,000 + bonus + equity + benefits.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange>$248,000 - $349,000 + bonus + equity + benefits</Salaryrange>
      <Skills>Bachelor&apos;s degree in Computer Science, Information Security, or equivalent practical experience, Experience in Red Teaming, Offensive Security, or Adversarial Machine Learning, Deep technical understanding of LLM architectures and agentic workflows, Proven ability to work in a consulting capacity with product teams, Experience managing or technically leading small, high-performance engineering teams, Hands-on experience developing exploits for GenAI models, Familiarity with AI safety benchmarks and evaluation frameworks, Experience writing code (Python, Go, or C++) to build automated security tools or fuzzers, Ability to communicate complex probabilistic risks to executive stakeholders and engineering teams effectively</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Google DeepMind</Employername>
      <Employerlogo>https://logos.yubhub.co/deepmind.com.png</Employerlogo>
      <Employerdescription>Google DeepMind is a team of scientists, engineers, and machine learning experts working together to advance the state of the art in artificial intelligence.</Employerdescription>
      <Employerwebsite>https://deepmind.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/deepmind/jobs/7560787</Applyto>
      <Location>Mountain View, California, US; New York City, New York, US</Location>
      <Country></Country>
      <Postedate>2026-03-16</Postedate>
    </job>
    <job>
      <externalid>742bbeff-45a</externalid>
      <Title>Senior Software Engineer</Title>
      <Description><![CDATA[<p>For over 31,000 growing businesses and HR teams seeking a comprehensive, all-in-one HR suite, Workable emerges as the premier solution. We uniquely combine the world’s most widely adopted Applicant Tracking System (Workable Recruiting) with a full-spectrum employee management system (Workable HR). At Workable, we empower companies to focus on what truly matters: hiring the right people and fostering their growth.</p>
<p>We&#39;re growing fast so we&#39;re looking for a Senior Software Engineer to join our Product team! We are proud of our strong engineering culture and the dogged emphasis on customer-centric design. We&#39;re working on all sorts of exciting areas of application development: web, mobile, infrastructure, performance, UI/UX design, integrations with dozens of web services, API development, modern front-end frameworks, scalability, video, natural language processing, data science and usability engineering.</p>
<p>Agile methodology and test-driven development are not things we read about in blogs, it&#39;s what we do every day! Our technology stack consists of Rails, Node, Python and Java apps based on PostgreSQL, MongoDB, RabbitMQ, Redis and Elastic deployed on Kubernetes and GCP. We&#39;re looking for developers in all fields of SaaS application development. We have several teams working on different areas from the core application to mobile/tablet applications, integrations, natural language processing, data science and video technology. We will find the right team for you depending on your skills and technology interests.</p>
<p><strong>Responsibilities:</strong></p>
<ul>
<li>Develop and maintain software systems in production</li>
<li>Strong background in relational database theory and excellent knowledge of Relational Databases (Postgres, MySQL, SQL server, Oracle)</li>
<li>Familiarity with NOSQL storage (MongoDB, Redis, Elastic, etc.)</li>
<li>Firm grasp of multi-threading, object-oriented design and asynchronous programming</li>
<li>Skilled in testing (unit/integration)</li>
<li>BS/MS degree in Computer Science, Engineering or a related subject</li>
<li>Being passionate about web technologies</li>
</ul>
<p><strong>Benefits:</strong></p>
<ul>
<li>Comprehensive Health Coverage: A robust health insurance plan that includes coverage for your dependents.</li>
<li>Competitive Compensation: An attractive salary paired with a performance-based bonus plan.</li>
<li>Flexible Work Model: Enjoy the best of both worlds with a hybrid setup—two days working from home and three in the office.</li>
<li>Top-Tier Tools: Apple gear and access to the latest productivity tools to help you excel.</li>
<li>Stay Connected: A mobile data plan to keep you online wherever you are.</li>
<li>Delicious Perks: Fresh, tasty food at the office to fuel your productivity.</li>
<li>Relocation Bonus: To help you settle in smoothly in Athens.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Ruby, Node, Python, Java, PostgreSQL, MongoDB, RabbitMQ, Redis, Elastic, Kubernetes, GCP, Agile methodology, Test-driven development, Modern frontend frameworks, State-of-the-art information security practices, Kafka, Amazon AWS platform, Elasticsearch</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Workable</Employername>
      <Employerlogo>https://logos.yubhub.co/j.com.png</Employerlogo>
      <Employerdescription>Workable is a comprehensive, all-in-one HR suite for over 31,000 growing businesses and HR teams.</Employerdescription>
      <Employerwebsite>https://apply.workable.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://apply.workable.com/j/5656BF6FBE</Applyto>
      <Location>Athens</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>99adb2e6-c30</externalid>
      <Title>Cyber Security Engineering, Staff Engineer</Title>
      <Description><![CDATA[<p>You are an accomplished information security professional with extensive experience in risk management, governance, and compliance. Your deep understanding of computer and network security, coupled with familiarity with regulatory and legal requirements, enables you to proactively identify and address vulnerabilities across complex enterprise environments.</p>
<p>You thrive in collaborative settings, working seamlessly with cross-functional teams such as Finance, Legal, Audit, and HR, and are adept at implementing innovative security solutions that elevate organisational posture. Your analytical mindset is matched by your critical thinking skills, allowing you to assess potential threats, evaluate risk mitigation strategies, and communicate findings clearly to executive leadership and stakeholders globally.</p>
<p>You are passionate about advancing risk management programs, enhancing compliance, and tracking enterprise security risks to keep pace with the ever-evolving cybersecurity landscape. Your commitment to continuous learning ensures you stay ahead of industry trends and regulatory changes, making you a valuable partner in Synopsys&#39; growth and transformation.</p>
<p>You take ownership of your work, demonstrate high ethical standards, and enjoy tackling complex challenges unique to the Synopsys business and systems architecture. Your ability to translate technical concepts into actionable business solutions empowers the organisation to achieve its strategic goals securely and efficiently.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Conduct security risk assessments of suppliers, partners, and internal systems, rating risks and recommending mitigation controls.</li>
<li>Identify, document, monitor, and report on risk register items, KPIs/KRIs, and security control efficacy.</li>
<li>Present security risks and findings to diverse audiences, including risk owners, senior management, and global stakeholders.</li>
<li>Collaborate with business groups to implement new solutions, processes, and remediate outstanding security issues.</li>
<li>Work closely within the GRC team to detect potential security weaknesses and develop creative solutions tailored to Synopsys&#39; systems architecture.</li>
<li>Provide guidance on control implementations, governance frameworks, and corporate security policies.</li>
<li>Conduct third-party (vendor) risk assessments and communicate requirements to internal and external partners.</li>
<li>Maintain, enforce, and track the Synopsys Information Security Exception process.</li>
<li>Stay current with industry, regulatory, and legal requirements relevant to security, compliance, and privacy.</li>
</ul>
<p><strong>Requirements</strong></p>
<ul>
<li>Bachelor&#39;s degree in Computer Science, Information Systems, or a related field (or equivalent experience).</li>
<li>5-7 years of hands-on experience in information security, risk management, or compliance.</li>
<li>In-depth knowledge of certification and attestation programs (ISO 27001, SOC 2 Type II, ISO 31000).</li>
<li>Practical experience with security control frameworks (ISO 27001, NIST 800-53, SOC 2 Type II, NIST CSF).</li>
<li>Excellent organisational skills and attention to detail, with the ability to prioritise multiple projects.</li>
<li>Effective communication skills with internal/external customers, executive managers, and global teams.</li>
<li>Ability to interpret compliance requirements and provide meaningful risk analysis.</li>
</ul>
<p><strong>Benefits</strong></p>
<p>We offer a comprehensive range of health, wellness, and financial benefits to cater to your needs. Our total rewards include both monetary and non-monetary offerings. Your recruiter will provide more details about the salary range and benefits during the hiring process.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>information security, risk management, compliance, ISO 27001, SOC 2 Type II, NIST 800-53, security control frameworks</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Synopsys</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.synopsys.com.png</Employerlogo>
      <Employerdescription>Synopsys is a leading provider of electronic design automation (EDA) software and services. The company has a global presence with over 10,000 employees.</Employerdescription>
      <Employerwebsite>https://careers.synopsys.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://careers.synopsys.com/job/greece/cyber-security-engineering-staff-engineer/44408/91865642480</Applyto>
      <Location>Greece</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>8dc7d87b-14d</externalid>
      <Title>Expert EHSE Management/Projects (m/w/d)</Title>
      <Description><![CDATA[<p>FUCHS LUBRICANTS GERMANY GmbH is a leading manufacturer of high-quality lubricants and chemical specialties for the German and international market. We are looking for an Expert EHSE Management/Projects (m/w/d) to join our team in Mannheim.</p>
<p><strong>Your Key Responsibilities:</strong></p>
<ul>
<li>Manage our FLG sites in all matters related to energy, environment, health and safety, and information security management</li>
<li>Conduct internal audits and accompany external audits according to ISO 14001, ISO 45001, ISO 50001, and TISAX</li>
<li>Follow up and ensure the implementation of measures from audits and the management review</li>
<li>Support the maintenance and development of our Legal Compliance Management System</li>
<li>Collaborate closely with the Quality Management department</li>
<li>Take responsibility and participate in the expansion of information security</li>
</ul>
<p><strong>What We Are Looking For:</strong></p>
<ul>
<li>Technical degree or equivalent</li>
<li>Certified 1st &amp; 2nd Party Auditor (ISO 19011) with valid proof</li>
<li>In-depth knowledge of the standards ISO 14001, ISO 45001, and ISO 50001</li>
<li>First experiences in the field of information security are an advantage</li>
<li>Independent, structured working style and high self-motivation</li>
<li>Very good German and English language skills</li>
<li>Proficient in MS Office</li>
</ul>
<p><strong>What We Offer:</strong></p>
<ul>
<li>Balance between private and professional life (e.g., flexible working hours, part-time work, 30 days of annual leave, and possibility of taking time off)</li>
<li>Secure future prospects in a dynamic, globally operating company</li>
<li>Salary and benefits in line with requirements and performance</li>
<li>Opportunities for individual further education and training</li>
<li>Company pension scheme, disability insurance, and long-term account</li>
<li>Occupational health management (e.g., cooperation with fitness studios, action days, company sports, and social counseling)</li>
<li>FUCHS promotes equal opportunities. Applications from disabled people will be given special consideration if they are equally qualified.</li>
</ul>
<p><strong>How to Apply:</strong></p>
<p>If you have any questions, Alexandra Freund will be happy to answer them for you under Alexandra.Freund.EXT@fuchs.com. Join our team and let&#39;s move the world together! [jobs.fuchs.com](https://jobs.fuchs.com/)</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>mid</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>ISO 14001, ISO 45001, ISO 50001, Information Security, Auditing, Quality Management, German, English, MS Office</Skills>
      <Category>Engineering</Category>
      <Industry>Manufacturing</Industry>
      <Employername>FUCHS LUBRICANTS GERMANY GmbH</Employername>
      <Employerlogo>https://logos.yubhub.co/jobs.fuchs.com.png</Employerlogo>
      <Employerdescription>FUCHS LUBRICANTS GERMANY GmbH is a leading manufacturer of high-quality lubricants and chemical specialties for the German and international market.</Employerdescription>
      <Employerwebsite>https://jobs.fuchs.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.fuchs.com/job/Mannheim-Expert-EHSE-ManagementProjects-%28mwd%29-BW-68169/1369472133/</Applyto>
      <Location>Mannheim</Location>
      <Country></Country>
      <Postedate>2026-03-09</Postedate>
    </job>
    <job>
      <externalid>e2099e08-e30</externalid>
      <Title>GRC Lead (Governance, Risk, and Compliance)</Title>
      <Description><![CDATA[<p><strong>Compensation\n\n- Compensation is determined based on career level, with the base salary for this role ranging from $208K – $300K • Offers Equity\n\n## About the role\n\nWe are looking for a <strong>GRC Lead</strong> to serve as the <strong>Technical Lead</strong> for our compliance and risk management ecosystem. You will architect the systems and processes that automate trust, guiding a team of GRC specialists while partnering deeply across the organization. We need a pragmatic operator who understands that GRC exists to enable the business—balancing rigorous standards with the velocity of a high-growth startup.\n\n## What You&#39;ll Do\n\n### Technical Leadership &amp; Mentorship\n\n- <strong>Team Leadership:</strong> Act as the technical anchor for the GRC team. You will mentor GRC analysts and engineers, setting the standard for quality, technical depth, and operational efficiency.\n\n- <strong>Program Architecture:</strong> Own the technical vision for Replit’s GRC program, moving the team from manual workflows toward &quot;Compliance-as-Code&quot; and automated evidence collection.\n\n- <strong>Thought Leadership:</strong> Champion a culture of security and privacy across the company, educating teams on _why_ controls exist rather than just enforcing them.\n\n### Cross-Functional Collaboration\n\n- <strong>Engineering &amp; Architecture:</strong> Partner with Architects and Engineering Leads to &quot;bake in&quot; compliance requirements early in the design phase. You will translate complex technical implementations into narratives that satisfy frameworks without slowing down development.\n\n- <strong>Legal &amp; Privacy:</strong> Work closely with Legal Counsel to interpret and implement requirements for Privacy (GDPR, CCPA) and emerging <strong>AI-specific regulations</strong> (e.g., EU AI Act).\n\n- <strong>Sales &amp; GTM:</strong> Enable the Sales team by managing the <strong>Customer Trust Center</strong> and handling complex security questionnaires. You will serve as a subject matter expert in customer calls to build confidence with enterprise prospects.\n\n- <strong>Auditor Relationships:</strong> Own and cultivate the primary relationship with external auditors. You will serve as the bridge between auditors and internal teams, ensuring requests are reasonable, clear, and relevant to our tech stack.\n\n### Risk Management &amp; Strategic Compliance\n\n- <strong>Risk Register Owner:</strong> You will own the <strong>Cybersecurity Risk Register</strong>. You will be responsible for identifying, quantifying, and tracking risks, distinguishing between theoretical compliance gaps and meaningful business risks.\n\n- <strong>Framework Evolution:</strong> Manage and evolve our compliance posture across <strong>SOC 2, ISO 27001</strong>, and prepare the organization for future certifications in regulated markets (e.g., <strong>FedRAMP, ITAR, PCI, HIPAA</strong>).\n\n- <strong>Pragmatic Governance:</strong> Apply judgment to operate in &quot;gray areas&quot; when appropriate. You will prioritize issues that represent real security or business risk over &quot;compliance theater.&quot;\n\n### Automation &amp; Efficiency\n\n- <strong>Control Automation:</strong> Drive the shift from manual evidence collection to continuous monitoring. You will identify opportunities to automate audit work, ensuring GRC scales with the business.\n\n- <strong>Third-Party Risk:</strong> Architect a scalable framework for assessing third-party vendors and AI model providers, ensuring our supply chain remains secure without creating administrative bottlenecks.\n\n## Required Skills &amp; Experience\n\n- <strong>8+ years</strong> of experience in GRC or Information Security\n\n- <strong>Leadership Experience:</strong> Proven experience mentoring other GRC professionals or leading complex cross-functional projects.\n\n- <strong>Technical Fluency:</strong> Ability to speak the language of engineering, cloud (GCP/AWS), and security architecture. You can anticipate how architectural decisions impact risk and compliance.\n\n- <strong>Regulatory Breadth:</strong> Deep experience with SOC 2, ISO 27001, PCI, HIPPA, and Privacy laws.\n\n- <strong>Collaborative Communication:</strong> Strong ability to explain risk and tradeoffs to technical (Engineers), legal, and commercial (Sales/Execs) stakeholders.\n\n- <strong>Automation Mindset:</strong> Experience with GRC automation tools (e.g., Vanta, Drata) and a bias toward reducing manual toil.\n\n## Bonus Qualifications\n\n- Familiarity with FedRAMP, ITAR, or AI regulation is a strong plus.\n\n## What We Value\n\n- <strong>Pragmatism:</strong> You distinguish between &quot;checking a box&quot; and reducing risk. You focus on outcomes over optics.\n\n- <strong>Business Enablement:</strong> You understand that your role is to help Replit sell to the enterprise safely, not to say &quot;no&quot; to innovation.\n\n- <strong>Solutions-Oriented Leadership:</strong> You are collaborative and low-ego. You prefer fixing root causes and empowering teams over enforcing rigid bureaucracy.\n\n- <strong>Clarity:</strong> You can take a complex regulation and explain exactly what it means for a specific engineering team in plain English.\n\n_This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday._\n\n## Full-Time Employee Benefits Include:\n\n💰 Competitive Salary &amp; Equity\n\n💹 401(k) Program with a 4% match\n\n⚕️ Health, Dental, Vision and Life Insurance\n\n🩼 Short Term and Long Term Disability\n\n🚼 Paid Parental, Medical, Caregiver Leave\n\n🚗 Commuter Benefits\n\n📱 Monthly Wellness Stipend\n\n🧑‍💻 Autonomous Work Environment\n\n🖥 In Office Set-Up Reimbursement\n\n🏝 Flexible Time Off (FTO) + Holidays\n\n🚀 Quarterly Team Gatherings\n\n☕ In Office Amenities</strong></p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>Full time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>Hybrid</Workarrangement>
      <Salaryrange>$208K – $300K</Salaryrange>
      <Skills>GRC, Information Security, Leadership, Technical Fluency, Regulatory Breadth, Collaborative Communication, Automation Mindset</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Replit</Employername>
      <Employerlogo>https://logos.yubhub.co/replit.com.png</Employerlogo>
      <Employerdescription>Replit is an agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/replit/3475841f-c994-4443-b83d-4b8a5b1dd8f2</Applyto>
      <Location>Foster City, CA (Hybrid) In office M,W,F</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>f7bc3829-4cd</externalid>
      <Title>IT Auditor, Sr Associate/Staff</Title>
      <Description><![CDATA[<p><strong>Overview</strong></p>
<p>At Synopsys, we drive the innovations that shape the way we live and connect. Our technology is central to the Era of Pervasive Intelligence, from self-driving cars to learning machines. We lead in chip design, verification, and IP integration, empowering the creation of high-performance silicon chips and software content.</p>
<p><strong>Job Description</strong></p>
<p>We are seeking a motivated and detail-oriented audit professional with a strong interest in technology, information security, and risk management. You will be responsible for planning and executing IT and/or Information Security audits in accordance with the annual audit plan. You will also perform IT risk assessments to identify key risks and support the development and refinement of the annual IT audit plan.</p>
<p><strong>Responsibilities</strong></p>
<ul>
<li>Planning and executing IT and/or Information Security audits in accordance with the annual audit plan.</li>
<li>Performing IT risk assessments to identify key risks and support the development and refinement of the annual IT audit plan.</li>
<li>Evaluating the design and operating effectiveness of IT General Controls (ITGCs) and, where applicable, IT Application Controls.</li>
<li>Supporting SOX compliance activities, including walkthroughs, control testing, issue identification, and remediation follow-up.</li>
<li>Conducting audits over key systems and platforms, including ERP and cloud-based applications (e.g., SAP and/or Salesforce).</li>
<li>Collaborating with business, IT, and Information Security stakeholders to understand processes, risks, and controls.</li>
<li>Preparing clear, concise audit documentation, reports, and presentations that communicate findings, risks, and recommendations.</li>
<li>Tracking and validating remediation of audit findings and control deficiencies.</li>
<li>Staying current on emerging technology risks, regulatory expectations, and industry best practices related to IT and cybersecurity.</li>
</ul>
<p><strong>Benefits</strong></p>
<p>At Synopsys, innovation is driven by our incredible team around the world. We feel honored to work alongside such talented and passionate individuals who choose to make a difference here every day. We&#39;re proud to provide the comprehensive benefits and rewards that our team truly deserves.</p>
<ul>
<li>Health &amp; Wellness: Comprehensive medical and healthcare plans that work for you and your family.</li>
<li>Time Away: In addition to company holidays, we have ETO and FTO Programs.</li>
<li>Family Support: Maternity and paternity leave, parenting resources, adoption and surrogacy assistance, and more.</li>
<li>ESPP: Purchase Synopsys common stock at a 15% discount, with a 24 month look-back.</li>
<li>Retirement Plans: Save for your future with our retirement plans that vary by region and country.</li>
<li>Compensation: Competitive salaries.</li>
</ul>
<p><strong>Team</strong></p>
<p>You will join a collaborative and forward-thinking Internal Audit team that partners closely with the business and technology functions. The team values quality, integrity, and open communication, and provides opportunities to work across a broad range of systems, processes, and risks. You&#39;ll gain exposure to senior stakeholders, develop your technical and audit expertise, and play a meaningful role in strengthening the organization&#39;s control environment.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>IT audit, information security, risk management, SOX compliance, ERP, cloud-based applications, SAP, Salesforce, IT General Controls, IT Application Controls, auditing, risk assessment, control testing, issue identification, remediation follow-up, auditing documentation, reporting, presentation, emerging technology risks, regulatory expectations, industry best practices, CISA, CIA, CISSP, auditing software, risk management software</Skills>
      <Category>Finance</Category>
      <Industry>Technology</Industry>
      <Employername>Synopsys</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.synopsys.com.png</Employerlogo>
      <Employerdescription>Synopsys is a technology company that develops and maintains software used in chip design, verification, and manufacturing.</Employerdescription>
      <Employerwebsite>https://careers.synopsys.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://careers.synopsys.com/job/bengaluru/it-auditor-sr-associate-staff/44408/92463617200</Applyto>
      <Location>Bengaluru</Location>
      <Country></Country>
      <Postedate>2026-03-08</Postedate>
    </job>
    <job>
      <externalid>aa015612-5ff</externalid>
      <Title>Product &amp; Solutions Lead, Safety and Security</Title>
      <Description><![CDATA[<p><strong>Job Posting</strong></p>
<p><strong>Product &amp; Solutions Lead, Safety and Security</strong></p>
<p><strong>Location</strong></p>
<p>San Francisco</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Department</strong></p>
<p>Intelligence &amp; Investigations</p>
<p><strong>Compensation</strong></p>
<ul>
<li>$288K – $425K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>
<p><strong>About the Team</strong></p>
<p>The Intelligence &amp; Investigations (I2) team detects and disrupts abuse and strategic risks so people can use AI safely. We translate real-world signals, investigations, and external threat intelligence into practical mitigations, operating guidance, and partner-ready support that improves safety outcomes across the AI ecosystem.</p>
<p><strong>About the Role</strong></p>
<p>As a Product &amp; Solutions Lead focused on safety and security, you will build and operate 0–1 products, services, and technical solution packages that help developers and public institutions move from experimentation to durable, trusted outcomes—while maintaining public safety, transparency, and respect for privacy and rights.</p>
<p>This role balances two modes of delivery:</p>
<ol>
<li>Bespoke products and technical solutions for strategic internal and external partners, and</li>
</ol>
<ol>
<li>Scalable product and solution packages that can be reused broadly across partners and deployments.</li>
</ol>
<p>Training is a component of scale, but not the center of gravity. You will also ship reference implementations, playbooks, evaluation kits, and repeatable operating models that partners can adopt and operate.</p>
<p>You will work directly with engineers and a multidisciplinary group of safety and geopolitical analysts, and data and quantitative scientists to convert complex, evolving challenges into solutions that teams can adopt in high-stakes environments.</p>
<p>This role is based in San Francisco, CA (hybrid, 3 days/week). Relocation support is available.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Own the 0–1 roadmap for safety and security solution offerings: define the target users, problem statements, tools, operating models, success metrics, and the set of reusable deliverables we ship.</li>
</ul>
<ul>
<li>Design and ship bespoke technical solutions for priority partners (internal and external), then abstract what works into reusable patterns and toolkits.</li>
</ul>
<ul>
<li>Build partner-ready technical artifacts: solution blueprints, reference architectures, evaluation and monitoring guidance, incident/response playbooks, and deployment checklists.</li>
</ul>
<ul>
<li>Package open-source and proprietary capabilities into adoption-ready solutions (e.g., reference implementations, configuration patterns, validated workflows).</li>
</ul>
<ul>
<li>Maintain a consistent delivery model across engagements: intake, scoping, governance alignment, execution cadence, and retrospectives that improve the offering over time.</li>
</ul>
<ul>
<li>Translate evolving threats into actionable guidance and updates for solution packages (e.g., scams/fraud patterns, cyber-enabled threats, ecosystem abuse trends).</li>
</ul>
<ul>
<li>Develop lightweight enablement components as needed: targeted technical modules, hands-on labs, and readiness assessments that accelerate adoption of the solutions.</li>
</ul>
<ul>
<li>Define and instrument impact measurement: adoption milestones, readiness indicators, reliability and safety posture improvements, and partner satisfaction with outputs.</li>
</ul>
<ul>
<li>Partner closely across engineering, safety, geopolitical analysis, and quantitative teams to ensure solutions are technically credible, threat-informed, and measurable.</li>
</ul>
<ul>
<li>Communicate crisply and decision-readily to internal and external stakeholders: progress, trade-offs, risks, and recommendations.</li>
</ul>
<p><strong>You might thrive in this role if you:</strong></p>
<ul>
<li>Have 6+ years in product, technical program leadership, solutions, or platform operations, especially in safety, security, risk, integrity, or enterprise/public-sector contexts.</li>
</ul>
<ul>
<li>Have built 0–1 solution offerings (product plus services or productized services): taking ambiguous needs, shipping something concrete, then scaling it into a repeatable model.</li>
</ul>
<ul>
<li>Have a builder’s mindset: comfortable incubating early-stage ideas, testing them with partners, and evolving them into durable, repeatable safety and security solutions.</li>
</ul>
<ul>
<li>Can go deep with engineers and still produce partner-ready artifacts that are clear</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$288K – $425K</Salaryrange>
      <Skills>product leadership, technical program leadership, solutions, platform operations, safety, security, risk, integrity, enterprise/public-sector contexts, product development, solution development, technical writing, communication, project management, team leadership, collaboration, problem-solving, analytical skills, data analysis, data visualization, machine learning, artificial intelligence, cybersecurity, threat intelligence, incident response, compliance, regulatory affairs, cloud computing, containerization, DevOps, agile development, scrum, kanban, continuous integration, continuous deployment, continuous testing, test automation, security testing, penetration testing, vulnerability assessment, compliance testing, regulatory testing, data protection, information security, cybersecurity frameworks, risk management, compliance management, regulatory compliance, data governance, information governance, data quality, data integrity, data validation, data verification, data certification, data assurance, data security, data encryption, data masking, data tokenization, data anonymization, data pseudonymization, data aggregation, data fusion, data integration, data warehousing, data mart, data lake, data catalog, data governance, data quality, data integrity, data validation, data verification, data certification, data assurance, data security, data encryption, data masking, data tokenization, data anonymization, data pseudonymization, data aggregation, data fusion, data integration, data warehousing, data mart, data lake, data catalog</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is a technology company that focuses on developing and applying artificial intelligence in a way that benefits humanity. It was founded in 2015 and has since grown to become one of the leading AI research and development companies in the world.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/c664cc09-d996-450c-8683-ad591ac27c11</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>23a792a8-cc4</externalid>
      <Title>Vendor Security Program Manager</Title>
      <Description><![CDATA[<p><strong>Job Posting</strong></p>
<p><strong>Vendor Security Program Manager</strong></p>
<p><strong>Location</strong></p>
<p>San Francisco; New York City; Seattle; Washington, DC</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Location Type</strong></p>
<p>Hybrid</p>
<p><strong>Department</strong></p>
<p>Security</p>
<p><strong>Compensation</strong></p>
<ul>
<li>SF, Seattle and NYC: $207K – $335K • Offers Equity</li>
<li>Zone A: $186K – $301.5K • Offers Equity</li>
<li>Zone B: $165.6K – $268K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>
<p><strong>About the Team</strong></p>
<p>The Vendor Security team sits at the core of our mission to ensure our technology benefits humanity safely and securely. We provide security assurances and robust compliance frameworks for our technology, people, and products. Our mission is to build trust with the world in our products and company. Our work is technical yet highly operational, strategically aligning with security and engineering teams to navigate and mitigate risks proactively. We prioritize impact, enable innovation, and foster a culture of continuous compliance and security awareness.</p>
<p><strong>About the Role</strong></p>
<p>As a Program Manager within the Vendor Security team, you will play a crucial role in protecting our organisation against external risks posed by suppliers, vendors, partners, and hardware manufacturers. Your responsibilities will include conducting comprehensive security assessments, building a program to manage global supply chain and vendor risks, and driving security initiatives across all of our third-party relationships. You will be analytical, detail-oriented, and proactive, capable of translating complex security evaluations into clear, actionable strategies.</p>
<p>The role is expected to operate with a strong point of view on risk. You will be responsible not only for identifying and documenting vendor and supply-chain risk, but for helping the company make informed trade-offs between speed, scale, and security. This role requires exceptional organisational skills, the ability to effectively communicate across different business functions, and a strong commitment to operational excellence in a dynamic environment.</p>
<p>This role may be based out of one of our US offices (San Francisco, Seattle, NYC or DC.) We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li>Be the interface for Security to the rest of the organisation for vendors.</li>
</ul>
<ul>
<li>Own vendor security risk decisions and escalation paths, including clearly documenting risk acceptance, mitigation plans, and executive-level trade-offs when security requirements cannot be fully met.</li>
</ul>
<ul>
<li>Conduct deep, evidence-based security assessments of third parties, including review of architectures, configurations, controls, logs, and operational practices - moving beyond questionnaires and attestations to validate real-world security posture of vendors.</li>
</ul>
<ul>
<li>Assess and manage security risk across a diverse vendor landscape, including SaaS providers, cloud and infrastructure partners, hardware manufacturers, chip suppliers, and other strategic or high-impact suppliers.</li>
</ul>
<ul>
<li>Develop, build, and continuously improve the vendor security program and security supply chain risk management function at OpenAI.</li>
</ul>
<ul>
<li>Develop, propose, and implement effective controls to mitigate identified vendor risks.</li>
</ul>
<ul>
<li>Build and maintain collaborative partnerships with key internal stakeholders including Infrastructure Security, Product, Engineering, Legal, Procurement, and Threat Intelligence to ensure comprehensive security coverage of the vendor and third-party supply chain.</li>
</ul>
<ul>
<li>Streamline and automate vendor and supply chain security processes to increase efficiency and reduce manual overhead.</li>
</ul>
<p><strong>You might thrive in this role if you have:</strong></p>
<ul>
<li>Proven experience conducting third-party or supply chain security assessments, including building and scaling a vendor management security program.</li>
</ul>
<ul>
<li>An in-depth understanding of information security principles and controls, including data protection, access management, proactive and reactive security measures, and application security.</li>
</ul>
<ul>
<li>Comfort operating in ambiguity, with the ability to form defensible security opinions even when information is incomplete or uncertain.</li>
</ul>
<ul>
<li>Strong analytical and problem-solving skills, with the ability to identify and mitigate complex security risks.</li>
</ul>
<ul>
<li>Excellent communication and interpersonal skills, with the ability to effectively collaborate with cross-functional teams and stakeholders.</li>
</ul>
<ul>
<li>Strong organisational and project management skills, with the ability to prioritise tasks and manage multiple projects simultaneously.</li>
</ul>
<ul>
<li>A strong commitment to operational excellence and continuous improvement, with a focus on delivering high-quality results in a dynamic environment.</li>
</ul>
<ul>
<li>A passion for security and a desire to make a meaningful impact in the field.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$207K – $335K • Offers Equity</Salaryrange>
      <Skills>information security principles and controls, data protection, access management, proactive and reactive security measures, application security, third-party or supply chain security assessments, vendor management security program, security risk management, compliance frameworks, security awareness, operational excellence, project management, communication and interpersonal skills, cloud security, infrastructure security, threat intelligence, security analytics, incident response, security testing, penetration testing, security consulting, security training, security awareness training</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is a technology company that focuses on developing artificial intelligence (AI) systems. It was founded in 2015 and is headquartered in San Francisco, California.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/fb1e823e-cfcc-4293-8893-cc77e467c561</Applyto>
      <Location>San Francisco; New York City; Seattle; Washington, DC</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>544e96bb-5c3</externalid>
      <Title>Security Engineer, Application Security</Title>
      <Description><![CDATA[<p><strong>Security Engineer, Application Security</strong></p>
<p><strong>Location</strong></p>
<p>New York City</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Location Type</strong></p>
<p>Hybrid</p>
<p><strong>Department</strong></p>
<p>Security</p>
<p><strong>Compensation</strong></p>
<ul>
<li>$260K – $385K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p><strong>About the Team</strong></p>
<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>
<p><strong>About the Role</strong></p>
<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>
<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>
<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>
</ul>
<ul>
<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>
</ul>
<ul>
<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>
</ul>
<ul>
<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>
</ul>
<ul>
<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>
</ul>
<ul>
<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>
</ul>
<ul>
<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>
</ul>
<p><strong>You might thrive in this role if you:</strong></p>
<ul>
<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>
</ul>
<ul>
<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>
</ul>
<ul>
<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>
</ul>
<ul>
<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>
</ul>
<ul>
<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>
</ul>
<p><strong>About OpenAI</strong></p>
<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are building a team of talented engineers, researchers, and designers who share our vision and values.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$260K – $385K • Offers Equity</Salaryrange>
      <Skills>information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. It is a privately held company.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/ec5a5d98-6314-44d9-9466-8d4d7ee866f6</Applyto>
      <Location>New York City</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>90d20db9-de4</externalid>
      <Title>Security Engineer, Application Security</Title>
      <Description><![CDATA[<p><strong>Job Posting</strong></p>
<p><strong>Security Engineer, Application Security</strong></p>
<p><strong>Location</strong></p>
<p>San Francisco</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Location Type</strong></p>
<p>Hybrid</p>
<p><strong>Department</strong></p>
<p>Security</p>
<p><strong>Compensation</strong></p>
<ul>
<li>$260K – $385K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p>This role is at-will and OpenAI reserves the right to modify base pay and other compensation components at any time based on individual performance, team or company results, or market conditions.</p>
<p><strong>About the Team</strong></p>
<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>
<p><strong>About the Role</strong></p>
<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>
<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>
<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>
</ul>
<ul>
<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>
</ul>
<ul>
<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>
</ul>
<ul>
<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>
</ul>
<ul>
<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>
</ul>
<ul>
<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>
</ul>
<ul>
<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>
</ul>
<p><strong>You might thrive in this role if you:</strong></p>
<ul>
<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>
</ul>
<ul>
<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>
</ul>
<ul>
<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>
</ul>
<ul>
<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>
</ul>
<ul>
<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>
</ul>
<p><strong>About OpenAI</strong></p>
<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve this, we are committed to advancing the state-of-the-art in AI research and development.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$260K – $385K • Offers Equity</Salaryrange>
      <Skills>information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. The company was founded in 2015 and has since grown to become a leading player in the field of artificial intelligence.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/0322d6d8-6588-4209-a304-83e768063a25</Applyto>
      <Location>San Francisco</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>659bf794-7b5</externalid>
      <Title>Security Engineer, Application Security</Title>
      <Description><![CDATA[<p><strong>Security Engineer, Application Security</strong></p>
<p><strong>Location</strong></p>
<p>Seattle</p>
<p><strong>Employment Type</strong></p>
<p>Full time</p>
<p><strong>Department</strong></p>
<p>Security</p>
<p><strong>Compensation</strong></p>
<ul>
<li>$260K – $385K • Offers Equity</li>
</ul>
<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance related bonus for eligible employees and benefits.</p>
<ul>
<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>
</ul>
<ul>
<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>
</ul>
<ul>
<li>401(k) retirement plan with employer match</li>
</ul>
<ul>
<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>
</ul>
<ul>
<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>
</ul>
<ul>
<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick and safe time (1 hour per 30 hours worked)</li>
</ul>
<ul>
<li>Mental health and wellness support</li>
</ul>
<ul>
<li>Employer-paid basic life and disability coverage</li>
</ul>
<ul>
<li>Annual learning and development stipend to fuel your professional growth</li>
</ul>
<ul>
<li>Daily meals in our offices, and meal delivery credits as eligible</li>
</ul>
<ul>
<li>Relocation support for eligible employees</li>
</ul>
<ul>
<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>
</ul>
<p>More details about our benefits are available to candidates during the hiring process.</p>
<p><strong>About the Team</strong></p>
<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture.</p>
<p><strong>About the Role</strong></p>
<p>As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.</p>
<p>We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge. You will also provide security guidance to developers and other stakeholders, fostering a culture of security awareness within the organization.</p>
<p>The role is preferred to be based in San Francisco, Seattle or New York City but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees.</p>
<p><strong>In this role, you will:</strong></p>
<ul>
<li><strong>Perform Security Assessments</strong>: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.</li>
</ul>
<ul>
<li><strong>Develop and Implement Security Tools</strong>: Design, develop, and implement security tools, frameworks, and methodologies to protect applications against security threats.</li>
</ul>
<ul>
<li><strong>Collaborate with Development Teams</strong>: Work closely with development teams to ensure security best practices are integrated throughout the software development lifecycle (SDLC), including secure coding guidelines.</li>
</ul>
<ul>
<li><strong>Threat Modeling and Risk Assessment</strong>: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.</li>
</ul>
<ul>
<li><strong>Vulnerability Management</strong>: Track, analyze, and manage vulnerabilities in applications, providing guidance and support for remediation efforts.</li>
</ul>
<ul>
<li><strong>Incident Response Support</strong>: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.</li>
</ul>
<ul>
<li><strong>Stay Current on Security Trends</strong>: Continuously stay updated on the latest security threats, vulnerabilities, and technologies to enhance security measures in applications.</li>
</ul>
<p><strong>You might thrive in this role if you:</strong></p>
<ul>
<li>Extensive experience in information security, cybersecurity, or a related field, with a significant portion of that experience in leadership or management roles.</li>
</ul>
<ul>
<li>Deep understanding of security technologies, tools, and best practices, including experience with secure coding practices, threat modeling, risk assessments, and incident response.</li>
</ul>
<ul>
<li>Experience in application security, software development, or related areas with a strong understanding of secure coding practices and application security frameworks.</li>
</ul>
<ul>
<li>Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.</li>
</ul>
<ul>
<li>Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and non-technical audiences</li>
</ul>
<p><strong>About OpenAI</strong></p>
<p>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. We push the boundaries of the capabilities of AI systems and seek to safely deploy them to the world through our products. AI is an extremely powerful tool that must be created with safety and human needs at its core, and to achieve our mission, we must encompass</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$260K – $385K • Offers Equity</Salaryrange>
      <Skills>information security, cybersecurity, secure coding practices, threat modeling, risk assessments, incident response, application security, software development, secure coding guidelines, security protocols, encryption methods, programming languages, security tools, Burp Suite, OWASP ZAP, Python, Java, C++, security frameworks, security best practices</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>OpenAI</Employername>
      <Employerlogo>https://logos.yubhub.co/openai.com.png</Employerlogo>
      <Employerdescription>OpenAI is an AI research and deployment company dedicated to ensuring that general-purpose artificial intelligence benefits all of humanity. The company was founded in 2015 and has since grown to become a leading player in the field of artificial intelligence.</Employerdescription>
      <Employerwebsite>https://jobs.ashbyhq.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://jobs.ashbyhq.com/openai/1e110226-448a-4c0b-b0e4-d0f5df579fbf</Applyto>
      <Location>Seattle</Location>
      <Country></Country>
      <Postedate>2026-03-06</Postedate>
    </job>
    <job>
      <externalid>3443a031-482</externalid>
      <Title>Senior DevOps Engineer (AI)</Title>
      <Description><![CDATA[<p>We are seeking a Senior DevOps Engineer (AI) to lead the DevOps, deployment, and integration aspects of our AI-powered products. This is a high-ownership role for someone who enjoys operating independently, solving complex problems, and helping teams run smoothly at scale.</p>
<p><strong>What you&#39;ll do</strong></p>
<p>Act as the primary interface between the research team and the deployment ecosystem, ensuring seamless transition from innovation to production.</p>
<ul>
<li>Own interactions with external AI and LLM providers to facilitate integration and optimize performance across platforms.</li>
<li>Lead information security and compliance approvals for product deployments, maintaining high standards of data protection and privacy.</li>
<li>Design, build, and evolve the build and development environment, including robust CI/CD pipelines for automation and reliability.</li>
<li>Manage releases end-to-end, from scheduling and execution to closure, ensuring timely and high-quality product delivery.</li>
<li>Drive porting efforts and cross-platform support, broadening product reach and enabling scalability across cloud environments.</li>
</ul>
<p><strong>What you need</strong></p>
<ul>
<li>Strong proficiency in Git, CI/CD, and version control workflows.</li>
<li>Expertise in operating systems and cloud deployments (Azure, GCP, AWS).</li>
<li>Hands-on experience with Docker/Kubernetes and infrastructure-as-code practices.</li>
<li>Ability to design and build distributed systems at scale.</li>
<li>Proficiency in Python or another scripting language for automation.</li>
<li>Experience in model inferencing frameworks (vLLM, TGI) is highly desirable.</li>
</ul>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>employee</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>onsite</Workarrangement>
      <Salaryrange></Salaryrange>
      <Skills>Git, CI/CD, version control workflows, operating systems, cloud deployments, Docker/Kubernetes, infrastructure-as-code, Python, scripting language, model inferencing frameworks, AI, LLM, information security, compliance approvals, data protection, privacy</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Synopsys</Employername>
      <Employerlogo>https://logos.yubhub.co/careers.synopsys.com.png</Employerlogo>
      <Employerdescription>Synopsys drives the innovations that shape the way we live and connect. Our technology is central to the Era of Pervasive Intelligence, from self-driving cars to learning machines.</Employerdescription>
      <Employerwebsite>https://careers.synopsys.com</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://careers.synopsys.com/job/dublin/senior-devops-engineer-ai/44408/92358709552</Applyto>
      <Location>Dublin, Leinster, Ireland</Location>
      <Country></Country>
      <Postedate>2026-03-04</Postedate>
    </job>
  </jobs>
</source>