All active GRC roles based in California.
Pick a job to read the details
Tap any role on the left — its description and apply link will open here.
Roku is the #1 TV streaming platform in the U.S., Canada, and Mexico, and we've set our sights on powering every television in the world. Roku pioneered streaming to the TV. Our mission is to be the TV streaming platform that connects the entire TV ecosystem. We connect consumers to the content they love, enable content publishers to build and monetize large audiences, and provide advertisers unique capabilities to engage consumers.
From your first day at Roku, you'll make a valuable - and valued - contribution. We're a fast-growing public company where no one is a bystander. We offer you the opportunity to delight millions of TV streamers around the world while gaining meaningful experience across a variety of disciplines.
Roku is seeking a Technology Audit Manager to join its Finance & IT Compliance team. This role will lead and evolve Roku’s technology SOX compliance program, partnering closely with Engineering, Security, Product, and Finance teams to ensure scalable, high-quality controls across a rapidly growing and complex engineering environment.
You will operate at the intersection of audit, technology, and automation, overseeing internal controls across enterprise systems, cloud infrastructure, data platforms, and cybersecurity. You will also drive controls-by-design for system implementations and business process transformations A key priority for this role is modernizing the IT SOX program through AI-powered automation and continuous auditing to improve precision, coverage, and efficiency.
This is a high-impact, hands-on role for a proactive and driven professional who excels in fast-paced environments, collaborates effectively across teams, and brings the vision and execution focus to scale and modernize the compliance function alongside company growth. The ideal candidate brings strong experience in IT SOX and technology audits, along with a builder mindset, the ability to navigate ambiguity, and a track record of influencing cross-functional stakeholders. You should be equally comfortable diving into control details, partnering with engineering teams on system design, and driving strategic initiatives that enhance the overall control environment.
For California Only - The estimated annual salary for this position is between $170,000 and 187,000 annually. Compensation packages are based on factors unique to each candidate, including but not limited to skill set, certifications, and specific geographical location. This role is eligible for health insurance, equity awards, life insurance, disability benefits, parental leave, wellness benefits, and paid time off.
Roku fosters an inclusive and collaborative environment where teams work in the office Monday through Thursday. Fridays are flexible for remote work except for employees whose roles are required to be in the office five days a week or employees who are in offices with a five day in office policy.
Roku is committed to offering a diverse range of benefits as part of our compensation package to support our employees and their families. Our comprehensive benefits include global access to mental health and financial wellness support and resources. Local benefits include statutory and voluntary benefits which may include healthcare (medical, dental, and vision), life, accident, disability, commuter, and retirement options (401(k)/pension). Employees are supported in taking time off, in accordance with local leave policies and other personal needs to support their evolving work and life needs. It's important to note that not every benefit is available in all locations or for every role. For details specific to your location, please consult with your recruiter.
Roku welcomes applicants of all backgrounds and provides reasonable accommodations and adjustments in accordance with applicable law. If you require reasonable accommodation at any point in the hiring process, please direct your inquiries to EmployeeRelations@Roku.com.
Roku is a great place for people who want to work in a fast-paced environment where everyone is focused on the company's success rather than their own. We try to surround ourselves with people who are great at their jobs, who are easy to work with, and who keep their egos in check. We appreciate a sense of humor. We believe a fewer number of very talented folks can do more for less cost than a larger number of less talented teams. We're independent thinkers with big ideas who act boldly, move fast and accomplish extraordinary things through collaboration and trust. In short, at Roku you'll be part of a company that's changing how the world watches TV.
We have a unique culture that we are proud of. We think of ourselves primarily as problem-solvers, which itself is a two-part idea. We come up with the solution, but the solution isn't real until it is built and delivered to the customer. That penchant for action gives us a pragmatic approach to innovation, one that has served us well since 2002.
To learn more about Roku, our global footprint, and how we've grown, visit https://www.weareroku.com/factsheet.
By providing your information, you acknowledge that you want Roku to contact you about job roles, that you have read Roku's Applicant Privacy Notice, and understand that Roku will use your information as described in that notice. If you do not wish to receive any communications from Roku regarding this role or similar roles in the future, you may unsubscribe at any time by emailing WorkforcePrivacy@Roku.com.
Ready to apply?
Apply to Roku
Share this job
Why join us
Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-native automation and world-class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most. Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek.
Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.
Engineering at Brex
Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.
What you’ll do
As a Security Operations Engineer at Brex, you will focus on preventing, detecting and responding to security threats across Brex's corporate and cloud environments. You will use existing systems and develop tools to improve our security capabilities. Our team is responsible for functions across corporate security, detection & response and infrastructure security domains; and we perform systems engineering and automation to support those functions.
Security Operations is part of our wider Trust & IT organization which means you will have the opportunity to work closely with Application Security, Corporate Engineering, GRC and IT and to improve security configurations, drive positive employee behaviors and generally work to prevent events from becoming incidents. You will also help build and maintain our team’s open source project Substation and have the opportunity to contribute to the Brex Tech Blog. You’ll be part of a team that actively contributes to the wider security community and has a commitment to mentorship and engineering excellence.
We’re looking for individuals with a strong background and interest in detecting, responding to, and resolving security incidents and security challenges. You should be comfortable dealing with lots of moving pieces, changing priorities, and new technologies, while having a keen eye for detail. Most importantly, you should be enthusiastic about working with a variety of backgrounds, roles, and people across Brex. Building a world-class financial service requires world-class security.
Where you’ll work
This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!
Responsibilities
Requirements
Bonus points
Compensation
The expected salary range for this role is $192,000 - $240,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.
Brex LLC is a wholly owned subsidiary of Capital One, N.A.
Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.
Ready to apply?
Apply to Brex
Why join us
Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets. By combining global corporate cards and banking with intuitive spend management, bill pay, and travel software, Brex enables founders and finance teams to accelerate operations, gain real-time visibility, and control spend effortlessly. Brex’s AI-native automation and world-class service eliminate manual expense and accounting tasks for customers so they can focus on what matters most. Tens of thousands of the world's best companies run on Brex, including DoorDash, Coinbase, Robinhood, Zoom, Plaid, Reddit, and SeatGeek.
Working at Brex allows you to push your limits, challenge the status quo, and collaborate with some of the brightest minds in the industry. We’re committed to building a diverse team and inclusive culture and believe your potential should only be limited by how big you can dream. We make this a reality by empowering you with the tools, resources, and support you need to grow your career.
Engineering
Engineering at Brex is about building systems that scale with speed and intention. Our teams span Software, Data, Security, and IT, and operate with high autonomy and deep collaboration. We tackle hard technical problems, own our outcomes, and push for excellence at every level — from architecture to deployment. It’s an environment where engineering is a craft, and builders become leaders.
What you’ll do
Brex’s Governance, Risk, and Compliance function is at an exciting and pivotal point in our maturity journey and we’re seeking a team member who can seamlessly bridge compliance expertise with technical execution. As a Senior GRC Engineer, you will drive critical GRC processes that mitigate risk, keep us compliant, and build trust with our customers and partners. You'll evolve the technical foundation of our Trust program by automating security controls, building integrations between security tools and GRC platforms, and creating scalable processes that enable Brex to maintain compliance efficiently as we expand into new markets. You'll work at the intersection of security, engineering, and compliance — translating regulatory requirements into technical solutions and building automation that eliminates manual toil.
You'll leverage your deep understanding of SOC 2, PCI DSS, ISO 27001, AI governance frameworks, and others to both design controls for emerging compliance requirements and mature existing programs through automation and continuous monitoring. You’ll support Trust Assurance, Third Party Risk Management, and other Security Risk Management initiatives. Working with our Engineering, Infrastructure, and Product teams, you'll translate compliance frameworks into technical controls and build automated systems that help us achieve world-class security as Brex expands.
Your contributions will directly accelerate Brex's maturity. You'll design workflows using Tines, build integrations between security and GRC systems, and create dashboards for security metrics. You'll implement controls across the technology stack, support multiple audits (SOC 2, PCI DSS, SOX/ITGC, FINRA, ISO), and contribute to AI governance framework implementation (ISO 42001, NIST AI RMF, EU AI Act).
You'll have autonomy to build innovative solutions, collaborating cross-functionally to implement controls that enable growth while communicating technical concepts effectively across the organization.
Where you’ll work
This role will be based in our San Francisco office. We are a hybrid environment that combines the energy and connections of being in the office with the benefits and flexibility of working from home. We currently require a minimum of three coordinated days in the office per week, Monday, Wednesday and Thursday. As a perk, we also have up to four weeks per year of fully remote work!
Responsibilities
Requirements
Bonus points
Compensation
The expected salary range for this role is $153,600 - $192,000. However, the starting base pay will depend on a number of factors including the candidate’s location, skills, experience, market demands, and internal pay parity. Depending on the position offered, equity and other forms of compensation may be provided as part of a total compensation package.
Brex LLC is a wholly owned subsidiary of Capital One, N.A.
Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Brex recruiters will only reach out via LinkedIn or email with a brex.com domain. Any outreach claiming to be from Brex via other sources should be ignored.
Ready to apply?
Apply to Brex
Share this job
Archer is an aerospace company based in San Jose, California building an all-electric vertical takeoff and landing aircraft with a mission to advance the benefits of sustainable air mobility. We are designing, manufacturing, and operating an all-electric aircraft that can carry four passengers while producing minimal noise.
Our sights are set high and our problems are hard, and we believe that diversity in the workplace is what makes us smarter, drives better insights, and will ultimately lift us all to success. We are dedicated to cultivating an equitable and inclusive environment that embraces our differences, and supports and celebrates all of our team members.
We are seeking a SAP Security & Platform Systems Engineer. This specialized role is responsible for the secure architecture and technical integration of our SAP S/4HANA RISE environment. The ideal candidate will bridge the gap between traditional SAP Security and modern Cloud Platform administration, ensuring robust, compliant, and well-connected SAP systems.
What You'll Do:
What You'll Need:
Please note that this job description is intended to provide a general overview of the position and does not include an exhaustive list of responsibilities and qualifications.
At Archer we aim to attract, retain, and motivate talent that possess the skills and leadership necessary to grow our business. We drive a pay-for-performance culture and reward performance that supports the Company’s business strategy. For this position we are targeting a base pay between $152,100 - $190,100. Actual compensation offered will be determined by factors such as job-related knowledge, skills, and experience.
We are an equal-opportunity employer committed to creating a diverse and inclusive workplace. All qualified applicants will receive equal consideration for employment without regard to race, color, creed, religion, sex, gender identity, sexual orientation, national origin, disability, uniform service, Veteran status, age, or any other protected characteristic per federal, state, or local law, including those with a criminal history, in a manner consistent with the requirements of applicable state and local laws.
By applying, you agree to be bound by our candidate privacy policy.
Ready to apply?
Apply to Archer
About Zscaler
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.
We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.
Role
We are looking for a Staff Information Systems Engineer based in San Jose (Hybrid, 3 days in office), reporting to the Manager, End User Engineering in the IT Digital Employee Experience department.
The Staff Information Systems Engineer (End-User Computing) defines and drives the strategy and architecture for Zscaler’s secure, cloud-first employee workspace across Windows, macOS, BYOD, and mobile (iOS & Android), ensuring devices are compliant, resilient, and scalable. The role connects End User Engineering(Digital Employee Experience) objectives to day-to-day execution by leading automation, self-service, and zero-touch deployment initiatives, integrating core platforms, and mentoring engineers to improve productivity, reduce risk, and modernize the end-user experience.
What you’ll do (Role Expectations)
Who You Are (Success Profile)
What We’re Looking for (Minimum Qualifications)
What Will Make You Stand Out (Preferred Qualifications)
#LI-YC2 #LI-Hybrid
Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.
The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
Ready to apply?
Apply to Zscaler
Share this job
About Zscaler
Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location.
Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability.
We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity.
Role
We are looking for a Cybersecurity Risk Management Principal to join our team. This is a hybrid role, going in to the San Jose, CA office 3 days a week. You'll be reporting to the Sr. Director, Enterprise Risk Management within the Security GRC department. You will serve as a technical leader and subject matter expert, conducting sophisticated risk assessments and maintaining the strategic risk register to protect our global infrastructure. You'll bridge the gap between deep technical adversary tactics and high-level business impact to drive remediation across the enterprise.
What you’ll do (Role Expectations)
Lead comprehensive cyber risk assessments using qualitative and quantitative methods, such as FAIR, to identify and articulate threats to business stakeholders
Build and maintain a dynamic cyber risk register, ensuring prioritized risks and mitigation strategies are tracked and socialized with executive leadership
Run the day-to-day operations for Security Policy Exceptions and Risk Acceptance processes to ensure compliance and balanced risk-taking
Partner with Internal Audit, Compliance, and Security teams to embed risk management frameworks deeply into the enterprise risk lifecycle
Apply the MITRE ATT&CK framework to analyze adversary techniques and translate that intelligence into actionable enhancements for the organization’s security posture
Who You Are (Success Profile)
You thrive in ambiguity. You're comfortable building the path as you walk it. You thrive in a dynamic environment, seeing ambiguity not as a hindrance, but as the raw material to build something meaningful.
You act like an owner. Your passion for the mission fuels your bias for action. You operate with integrity because you genuinely care about the outcome. True ownership involves leveraging dynamic range: the ability to navigate seamlessly between high-level strategy and hands-on execution.
You are a problem-solver. You love running towards the challenges because you are laser-focused on finding the solution, knowing that solving the hard problems delivers the biggest impact.
You are a high-trust collaborator. You are ambitious for the team, not just yourself. You embrace our challenge culture by giving and receiving ongoing feedback—knowing that candor delivered with clarity and respect is the truest form of teamwork and the fastest way to earn trust.
You are a learner. You have a true growth mindset and are obsessed with your own development, actively seeking feedback to become a better partner and a stronger teammate. You love what you do and you do it with purpose.
What We’re Looking for (Minimum Qualifications)
Bachelor’s degree in Cybersecurity, IT, Computer Science, or a related field
10+ years of experience in cybersecurity risk management with a focus on risk assessments and threat modeling
Proficiency in the FAIR framework for risk quantification and the MITRE ATT&CK framework
Expert-level communication skills with the ability to translate complex technical risks into clear, actionable insights for business audiences
A results-driven approach to security risk management with a proven track record of solving complex security challenges
What Will Make You Stand Out (Preferred Qualifications)
Advanced certifications such as CISA, CISSP, CISM, CRISC, or FAIR
A Master’s degree in a technical or business-aligned field
Prior experience leading a Compliance or Cyber Risk management function within the technology industry
#LI-BH1 #LI-Hybrid
Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training.
The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits.
At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure.
Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including:
Learn more about Zscaler’s Future of Work strategy, hybrid working model, and benefits here.
By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines.
Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link.
Pay Transparency
Zscaler complies with all applicable federal, state, and local pay transparency rules.
Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.
Ready to apply?
Apply to Zscaler
You will serve as the technical lead for the sales team, focusing on solving complex security challenges for prospective customers across our SouthWest Region (CA, NV, AZ, & NM). The mission of this role is to drive successful product evaluations and provide expert technical guidance to secure new business within the regional market. You will bridge the gap between technical functionality and strategic business value to ensure high customer satisfaction and deal closure.
Responsibilities
Minimum Qualifications
Preferred Qualifications
#LI-LW1 #LI-REMOTE
Axonius is committed to fair and equitable compensation packages. A candidate’s salary will be based on qualifications and relevant experience. In addition to a competitive salary, our packages include stock options and attractive benefits.
About Axonius:
Axonius transforms cyber asset intelligence into actionability. With the Axonius Asset Cloud, customers preemptively tackle high-risk and hard-to-spot threat exposures, misconfigurations, and overspending. The integrated platform brings together data from every system in an organization’s IT infrastructure to optimize mission-critical risk, performance, and cost measures via actionable intelligence.
Covering cyber assets, software, SaaS applications, identities, vulnerabilities, infrastructure, and more, Axonius is the one place to go for Security, IT, and GRC teams to continuously drive actionability across the organization. Cited as one of the fastest-growing cybersecurity startups, with accolades from CNBC, Forbes, and Fortune, Axonius supports millions of assets for leading customers across industries and around the world.
Axonius makes it a priority to invest in our people with competitive compensation and benefits, growth opportunities, community-building, and so much more. Learn more about benefits at Axonius.
At Axonius we support a diverse and inclusive workplace and believe in equal employment opportunity. We welcome people of different backgrounds, experiences, abilities and perspectives to apply. All qualified applicants will receive consideration for employment without regard to race, color, ancestry, religion, age, sex, gender identity, national origin, sexual orientation, citizenship, marital status, disability, or Veteran status.
By submitting your application to us, you acknowledge that your personal data will be processed in accordance with our Global Job Candidate Privacy Notice.
Ready to apply?
Apply to Axonius
Share this job
At Zone 5 Technologies, we're redefining what's possible in unmanned aircraft systems. Our team of engineers and innovators is developing cutting-edge autonomous solutions that push the boundaries of UAS technology - solving complex challenges that matter.
We're building the future of UAS capabilities, and we're looking for exceptional talent to join us. If you're driven by hard problems, energized by rapid innovation, and ready to make an impact on next-generation flight systems, you belong here.
The EHS Specialist executes day-to-day environmental, health, and safety programs across Zone 5 Technologies manufacturing operations. Working under the direction of the Director of Operational Excellence (OpEx), this role is the hands-on technical owner of compliance activities, hazard assessments, industrial hygiene monitoring, incident documentation, and safety training delivery. The Specialist does not set EHS strategy or manage staff but is independently accountable for ensuring that established programs are properly implemented, records are meticulously maintained, and emerging hazards or compliance gaps are identified and escalated promptly.
The ideal candidate brings solid field-level EHS knowledge and is comfortable operating in the complex hazard environment unique to aerospace manufacturing, including composite and beryllium materials, energetic materials, RF/EMF, ionizing radiation, and classified program areas with the discipline and attention to detail required in a regulated defense contractor environment.
Key Responsibilities:
Regulatory Compliance & Permitting Support
• Conduct routine compliance inspections and walkthroughs to verify adherence to Local, State, and Federal requirements; document findings and initiate corrective action requests
• Maintain EHS compliance records, permit documentation, and regulatory filing calendars; prepare draft permit reports and renewal packages for EHS Manager review and submission
• Collect and compile data for required regulatory reports including Tier II, TRI Form R, EPCRA Section 313, OSHA 300/300A logs, and stormwater monitoring reports
• Support hazardous waste management operations: waste characterization, manifest preparation, container labeling and inspection, and LQG/SQG recordkeeping in compliance with RCRA
• Assist in preparing for and supporting regulatory agency inspections and third-party audits; gather evidence packages, escort inspectors on the floor, and document inspection findings under manager supervision
• Monitor compliance calendars and alert the Director of OpEx to upcoming deadlines, permit renewals, and reporting obligations
Hazard Identification & Risk Management
• Conduct Job Hazard Analyses (JHAs) for new and modified manufacturing tasks, maintenance activities, and non-routine operations; coordinate reviews with supervisors and document approvals
• Perform industrial hygiene monitoring tasks: collect air samples, conduct noise dosimetry surveys, and administer ergonomic assessments using established protocols; submit samples and compile results for EHS Manager interpretation
• Assist in day-to-day specialized hazard programs under established procedures: RF/EMF, composite and carbon fiber exposure controls, beryllium awareness, confined space entry, and LOTO/LOTOTO
• Maintain and update the chemical inventory and SDS/GHS library; review incoming chemical requests against approved substances list and flag new hazards.
• Support classified area EHS controls: conduct periodic inspections of controlled-access areas in coordination with the FSO and program security teams; document findings and corrective actions
• Participate in Process Hazard Analysis (PHA) reviews as an EHS technical contributor alongside engineering and operations teams
• Administer the respiratory protection program: coordinate fit-testing scheduling, maintain fit-test records, verify proper respirator selection, and track medical clearance status
Emergency Preparedness & Incident Management
• Maintain site emergency response plan (ERP) documents, contact lists, emergency equipment inventories, and evacuation maps; coordinate annual reviews with the Director of OpEx.
• Support incident investigations by conducting scene preservation, photographing physical evidence, gathering witness accounts, and entering findings into the EHS management system; conduct root cause analysis (RCA).
• Track and follow up on corrective and preventive actions (CAPAs) arising from incidents, near-misses, inspections, and audits; verify completion and document closure evidence
• Maintain OSHA 300/300A injury and illness logs with accuracy; flag recordability questions to the Director of OpEx for determination
• Coordinate emergency response drills and tabletop exercises: schedule participants, set up scenarios, document exercise outcomes, and track corrective actions
• Serve as a trained first responder resource during hazmat spill events and facility emergencies.
Training & Safety Culture
• Deliver EHS training sessions for new hires, annual refreshers, and specialized hazard-specific programs; manage attendance records and completion documentation in the LMS
• Administer the near-miss and hazard reporting program: process submissions, acknowledge reporters, route items for investigation, and track closure
• Develop training aids, visual safety communications, toolbox talk materials, and job aids for manufacturing floor audiences under guidance
• Partner with supervisors and engineers to reinforce EHS requirements during daily operations, pre-job briefings, and toolbox talks
Environmental Sustainability & Stewardship
• Track and compile facility waste stream data: hazardous waste generation volumes, universal waste, non-hazardous solid waste, and recycling; maintain monthly logs for regulatory reporting
• Monitor air emissions sources and stormwater management controls; collect samples and document inspections per permit requirements
• Maintain the chemical management program: track chemical inventory quantities, ensure proper storage segregation, and support substitution evaluations for hazardous substances
Program Administration & Reporting
• Maintain the EHS management system (EHSMS) with current inspection records, incident data, training completions, chemical inventory, and corrective action status
• Compile EHS metrics and leading/lagging indicator data (injury rates, inspection completion, training compliance, near-miss frequency) for EHS Manager review and dashboard reporting
• Maintain organized EHS files, permit binders, and program documentation in compliance with recordkeeping retention requirements
• Research regulatory updates and emerging EHS best practices; summarize findings for EHS Manager review
Required Qualifications:
• 3–5 years of hands-on EHS experience in a manufacturing, defense, or industrial environment
• Working knowledge of OSHA 29 CFR 1910 General Industry standards and basic EPA environmental compliance requirements
• Experience conducting JHAs, safety inspections, and incident investigations in a manufacturing setting
• Familiarity with industrial hygiene sampling methods, PPE selection, and hazardous materials handling
• Strong attention to detail and accuracy in regulatory recordkeeping and documentation
• Effective written and verbal communication skills; ability to deliver training and interact with production floor personnel
• Ability to obtain and maintain a U.S. Government Secret security clearance
Preferred Qualifications:
• Bachelor’s degree in Occupational Health & Safety, Environmental Science, Industrial Hygiene, Engineering, or closely related field (or Associate’s degree with equivalent experience)
• Associate Safety Professional (ASP) working toward CSP, OSHA 30-Hour General Industry, or HAZWOPER (24 or 40 hour) certification
• Experience in aerospace, defense, or government contracting environments
• Familiarity with RF/EMF safety standards (IEEE C95.1, ICNIRP), laser safety (ANSI Z136.1), or beryllium/composite hazard programs
• Experience with energetic materials, pyrotechnics, or propellant handling per DDESB standards
• EHSMS / GRC platform experience (KPA, Cority, Vector solutions, VelocityEHS, or equivalent)
Core Competencies:
Technical
• OSHA General Industry compliance inspection and recordkeeping
• Job Hazard Analysis (JHA) and Process Hazard Analysis (PHA) support
• Industrial hygiene sampling: air monitoring, noise dosimetry, ergonomic assessment
• Hazardous waste characterization, manifesting, and RCRA recordkeeping
• Incident investigation support and CAPA tracking
• EHS training delivery and LMS administration
• EHSMS data entry, metrics compilation, and compliance calendar management
Behavioral
• Attention to detail and accuracy in a regulated documentation environment
• Field presence and credibility on the manufacturing floor
• Proactive identification and escalation of hazards and compliance gaps
• Reliability and follow-through on corrective action commitments
• Collaborative approach with supervisors, engineers, and security personnel
• Composure and sound judgment during emergency response situations
Work Environment & Physical Requirements:
• Primarily manufacturing floor, regular exposure to noise, chemical vapors, vibration, and temperature extremes
• Required to wear PPE including respirators (fit-test required), hearing protection, chemical-resistant gloves, and safety glasses.
• Ability to lift up to 35 lbs; prolonged standing, walking, and climbing across large production floor and rooftop/utility areas
• Must be able to work in controlled-access areas following applicable security protocols
• Occasional off-hours response required for environmental releases, serious incidents, emergency drills, or after-hours sampling
What's in it for you:
Benefits:
Why Join Zone 5 Technologies?
If you are passionate about unmanned aircraft technology and want to be a part of a dynamic and growing company, we would love to hear from you. Apply today and join the Zone 5 Technologies team!
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
Zone 5 Technologies is a federal contractor and participates in E-Verify to confirm employment eligibility. As required by law, we will verify the identity and employment authorization of all new employees using the E-Verify system. Learn more about your rights and responsibilities under E-Verify: https://www.e-verify.gov.
Ready to apply?
Apply to Zone 5 Technologies
Share this job
We’re in an unbelievably exciting area of tech and are fundamentally reshaping the data storage industry. Here, you lead with innovative thinking, grow along with us, and join the smartest team in the industry.
This type of work—work that changes the world—is what the tech industry was founded on. So, if you're ready to seize the endless opportunities and leave your mark, come join us.
THE ROLE
The Senior Manager, Security Operations – Detection Engineering & Incident Response will lead and evolve Pure’s Security Operations (SecOps) function across Detection Engineering, Threat Intelligence, and Incident Response (CIDR). The mission is to transform SecOps into a proactive, intelligence-driven, and outcome-oriented program that measurably reduces enterprise risk and strengthens security posture across cloud, SaaS, infrastructure, and endpoint environments.
This role sits at the intersection of detection, incident response, threat hunting, attack surface management, and platform security. You’ll build and mature a high-signal detection and response system — from telemetry pipelines to actionable alerts — ensuring every detection maps to real attacker behavior and closes meaningful risk paths.
You’ll partner closely with leaders across GRC, Product Security, Infrastructure, IAM, and Engineering to operationalize risk-informed detections, mature IR processes, and drive measurable improvements in security posture.
WHAT YOU’LL DO
Lead and mature the Detection Engineering and CIDR functions across threat detection, response workflows, incident triage, and automation
Build and maintain a comprehensive detection inventory categorized by threat type, log source, MITRE mapping, and detection method
Drive continuous validation through red team, purple team, and atomic testing
Own key SecOps metrics such as MTTD, MTTR, and alert quality to improve signal-to-noise ratio and detection confidence
Oversee ingestion of telemetry (AWS, Azure, SaaS, endpoint, network) into Splunk and SOAR pipelines
Ensure incident response workflows are automated, repeatable, and outcome-focused
Lead post-incident reviews and root-cause analyses, tracking corrective actions to closure
Correlate threat intelligence, detection gaps, and hunt findings into prioritized roadmap updates
Drive detection-to-remediation loops by partnering with ASM, Infra, IAM, AppSec, and GRC teams
Produce dashboards that connect technical posture to business risk and ownership metrics
Lead scenario-based tabletops, detection drills, and incident simulations
We are primarily an in-office environment and therefore, you will be expected to work from the Santa Clara, CA office in compliance with Pure’s policies, unless you are on PTO, work travel, or other approved leave.
WHAT YOU BRING
10+ years in cybersecurity, including 5+ years in detection, incident response, or SecOps leadership
Proven experience leading detection engineering and incident response teams at enterprise scale
Deep expertise with:
SIEM (Splunk preferred), SOAR (Tines, XSOAR), and EDR (CrowdStrike)
Cloud telemetry and detection (CloudTrail, GuardDuty, VPC flow)
Threat modeling, MITRE ATT&CK, and TTP-to-detection lifecycle
Experience with detection-as-code practices, version control, and CI/CD pipelines
Hands-on skills validating detections through replay, simulation, and log mining
Familiarity with frameworks such as CIS Controls, NIST 800-53, and SOC 2
Ability to translate complex security data into clear, executive-level insights
Proven cross-team collaboration with Infra, GRC, Product Security, and App teams
Strong written and verbal communication with an emphasis on clarity and measurable outcomes
Preferred Qualifications
Experience operating in hybrid cloud and SaaS-heavy environments
Understanding of attacker behavior, threat intel feeds, and threat hunting workflows
Familiarity with secrets detection, data exfiltration indicators, and IAM anomaly detection
Certifications such as CISSP, GCIH, GCIA, OSCP, AWS Security, or equivalent
#LI-ONSITE
#LI-TH3
Salary ranges are determined based on role, level and location. For positions open to candidates in multiple geographical locations, the base salary range is reflective of the labor market across the applicable locations.
This role may be eligible for incentive pay and/or equity.
There is no application deadline and we accept applications on an ongoing basis until the job is filled.
WHAT YOU CAN EXPECT FROM US:
And because we understand the value of bringing your full and best self to work, we offer a variety of perks to manage a healthy balance, including flexible time off, wellness resources, and company-sponsored team events. Check out purebenefits.com for more information.
ACCOMMODATIONS AND ACCESSIBILITY:
Candidates with disabilities may request accommodations for all aspects of our hiring process. For more on this, contact us at TA-Ops@purestorage.com if you’re invited to an interview.
OUR COMMITMENT TO A STRONG AND INCLUSIVE TEAM:
We’re forging a future where everyone finds their rightful place and where every voice matters. Where uniqueness isn’t just accepted but embraced. That’s why we are committed to fostering the growth and development of every person, cultivating a sense of community through our Employee Resource Groups and advocating for inclusive leadership.
Everpure is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other characteristic legally protected by the laws of the jurisdiction in which you are being considered for hire.
Join us and bring your best.
Bring your bold.
Pure and simple.
Ready to apply?
Apply to Everpure
Share this job
About Moloco:
Moloco builds some of the most powerful AI advertising solutions in the world. Our name—short for "machine learning company"—reflects our core mission: democratizing access to the advanced AI that has historically been reserved for tech giants. Led by machine learning pioneers who built some of the most successful ad systems at Google, including YouTube's monetization engine and key search advertising technologies, we're transforming how businesses grow and compete in the digital economy.
Built with AI from day one, Moloco’s planet-scale machine learning platform powers a suite of solutions for advertising growth and monetization. Moloco Ads is an AI-powered platform that delivers real business outcomes for mobile app marketers through performance-based user acquisition. Moloco Commerce Media enables retailers and marketplaces to build revenue-generating ad businesses that balance user experience and advertiser performance.
Moloco is headquartered in Silicon Valley, with offices in Seattle, New York, San Francisco, Seoul, Beijing, Singapore, Gurgaon, Tokyo, Shanghai, London, Tel Aviv, and Berlin.
Moloco is a truly rewarding place to work and in an exciting period of growth, which you could be a part of. Join us today and apply now!
The Impact You’ll Be Contributing to Moloco:
The Program Manager within the Enterprise Compliance Office (ECO) drives execution of Moloco’s global compliance priorities by translating strategy into structured, measurable, and repeatable delivery. You’ll lead high-impact, cross-functional programs, bring structure to ambiguity, and build scalable systems that enable the business to grow across multiple regions and regulatory environments. You’ll gain deep exposure to how a modern and global compliance organization operates while developing expertise at the intersection of compliance, operations, and data-driven execution.
This role will report to the Enterprise Compliance Officer & Associate General Counsel (Employment & Ethics) and will partner cross-functionally across Legal, Security/GRC, Product, Engineering, People, Finance, and Business teams to coordinate complex global compliance initiatives, manage dependencies, and ensure that our most important compliance commitments are delivered on time with high quality. In addition to core program management responsibilities, this role incorporates targeted analytical capabilities to strengthen evidence readiness, data quality, and operational rigor across compliance workflows.
This role is based near our Menlo Park, CA office and follows a hybrid in-office schedule.
The Opportunity:
How Do I Know if the Role is Right For Me?
Compensation & Benefits
U.S.-based employees have access to medical, dental, and vision insurance, a 401(k) plan with company match, short-term and long-term disability coverage, basic life insurance, and well-being benefits and perks. U.S.-based employees also receive up to 12 scheduled paid holidays per calendar year and one Thrive Day off per quarter. Additionally, all employees have Flexible Time Off (FTO).
The successful candidate may be eligible for a bonus and equity awards. Eligibility and amounts are determined by performance and the terms of the applicable plans.
The location for this role is listed above. For base pay range purposes, location-based compensation is grouped into the following regions. Your region is determined by your assigned work location.
Salary Ranges:
Moloco Thrive: Benefits and Well-Being:
We take care of you and create the conditions for you to do the best work of your career. Through a lens of inclusion, we offer innovative benefits that empower our employees to take care of themselves and their families so they can do the best work of their lives.
Moloco Values:
Additional Resources:
AI Use in Interviews
Our interview process is designed to get to know the real you. Unless a round specifically includes AI as part of what's being assessed, we ask that candidates engage without AI assistance. Please review our AI Use in Interviews Policy before your interview to understand what to expect. Failure to comply with this policy may impact your candidacy.
Equal Opportunity:
Creating a diverse workforce and a culture of inclusion and belonging is core to our existence. To reach our goals, diversity of talent and thought is a critical component of how we operate as an organization. Our workforce is our superpower, and we know that fostering a culture of inclusion, authenticity, and belonging gives us the greatest opportunity to achieve our vision to become the scaling engine for the Internet economy.
Moloco is an equal opportunity employer. We highly value diversity in our current and future employees and do not discriminate (including in our hiring and promotion practices) on the basis of race, color, creed, religion, national origin, age, sex and gender, gender expression and identity, sexual orientation, marital status, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by law.
Candidate Privacy Notice:
Your privacy matters to us. By applying, you acknowledge that you’ve reviewed our Candidate Privacy Notice.
Ready to apply?
Apply to Moloco
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
If you want to be a part of a dynamic, forward-thinking Governance, Risk and Compliance organization focused on building a best-in-class, cutting edge governance program, come join the Security Governance Team at Okta. As a critical foundation of GRC, the Security Governance team’s mission is to provide the documentation, policy adherence, and advisory backbone needed to drive secure operations and behaviors at Okta and position the company as a global leader in security best practices. We are seeking a dedicated and detail-oriented Principal Data Security Engineer to join our team. The ideal candidate will drive Okta’s internal data security strategy and uplift capabilities for safeguarding sensitive information throughout the company.
The Principal Data Security Engineer will be the business owner of Okta’s data protection tool suite and will be responsible for envisioning, implementing, and maturing data security strategies across Okta, including enforcement of data retention, authoring and implementing data encryption and obfuscation minimums, establishing secure key management best practices, uplifting data handling controls and safeguards, and automating security workflows. This role demands a high level of technical expertise and deep experience with data security applications and services, such as Okta, Crowdstrike, and Palo Alto Networks. This role will work closely with a wide array of internal stakeholders, such as Data Loss Prevention (DLP) Engineering, Defensive Cyber Operations, Defensive Cyber Engineering, and Legal, as well as technology and cloud support teams. This role requires a thorough understanding of DLP technologies such as data security posture management (DSPM), endpoint detection and response (EDR), and cloud access security broker (CASB) as well as significant working experience in the data security and protection domain.
The right candidate will have experience operating in a mature security control environment, will have a strong background in managing mature data security and privacy functions in corporate settings, and will possess a proven track record of successfully implementing complex projects in cross-collaborative teams. The ideal Principal Data Security Engineer will be able to identify and drive appropriate data security strategy that mitigates Okta’s key security risks, including recommending enhancements such as compensating controls and other preventative measures.
The Principal Data Security Engineer will have strong familiarity with security compliance frameworks (e.g., NIST, ISO, PCI) and will be competent in summarizing complex scenarios for management review. If you are a self-starter who wants to make a difference in a global cloud security company, come help us lead the way.
#LI-SM1
#LI-HYBRID
P16924_3342877
Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.
The Okta Experience
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.
Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at https://www.okta.com/legal/personnel-policy/.
Ready to apply?
Apply to Okta
Share this job
Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.
The Corporate Assurance Team manages enterprise cybersecurity governance, risk, and compliance (GRC) by implementing and operationalizing global compliance frameworks across Anduril's corporate and product environments. The team serves as the bridge between regulatory requirements and engineering execution, ensuring that Anduril's rapidly evolving technology stack meets the highest standards of security and compliance.
The Compliance Engineer is a technically hands-on role responsible for driving automation, compliance, and security engineering principles into the design, integration, and operation of Anduril's internal systems. This individual will be instrumental in securing Anduril's software development process by translating complex compliance requirements into scalable, automated, and developer-friendly solutions.
The ideal candidate brings a strong DevSecOps background with deep expertise in cloud infrastructure security, embedded systems security, and federal compliance frameworks. They are equally comfortable writing Terraform modules as they are interpreting NIST controls, and they thrive at the intersection of security policy and engineering execution.
This is not a paperwork-driven compliance role. This is a builder's role. You will architect and automate compliance infrastructure that enables Anduril's engineering teams to deploy secure, compliant applications by default — removing bottlenecks rather than creating them.
WHY THIS ROLE MATTERS
At Anduril, compliance is not a checkbox — it is an engineering discipline. The Compliance Engineer plays a critical role in ensuring that Anduril can move fast without compromising the security and regulatory posture required to serve national defense missions. By building compliance into the foundation of our infrastructure, you will directly enable engineering teams to focus on what they do best: building transformative technology that protects those who protect us.
KEY RESPONSIBILITIES
Infrastructure & Automation
Compliance Engineering & Framework Implementation
Cross-Functional Collaboration & Enablement
Strategic & Advisory
Education & Experience
Technical Skills
Soft Skills & Competencies
Eligibility
The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including:
At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.
Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.
To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:
No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.
@anduril.com address.Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.
What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.
To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/.
By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.
Ready to apply?
Apply to Anduril Industries
Share this job
Flex is a growth-stage, NYC headquartered FinTech company that is creating the best rent payment experience. It’s hard to believe that it’s 2026 and paying rent on time is expensive, inflexible, and difficult. We’re here to change that! Flex enables our users to pay rent throughout the month on a schedule that better fits their finances and budget. Our mission is to empower as many renters as possible with flexibility over their most significant recurring expense. After deliberately keeping a stealth profile as we built up unprecedented investor support and an enthusiastic user base, we are looking for motivated individuals to help us keep our mission growing. Will you be a part of the team?
The Role
We are looking for an Associate Director, Third-Party Risk Management (TPRM) to own the TPRM pillar at Flex. This is not a program management role. It is a pillar ownership role: you set the risk posture, define the operating model, and are accountable for outcomes across a vendor population that touches every part of the business.
You will lead a small team, establish the direction for how Flex evaluates and monitors third-party risk, and make the calls on where speed and rigor need to be balanced. You will design AI-enabled workflows that scale the team's capacity without sacrificing auditability or regulatory defensibility. And you will hold Flex's third-party risk position across the organization, shaping decisions in Product, Engineering, Finance, and Procurement rather than responding to requests from them.
This role is right for someone who has owned TPRM at a mature, regulated institution and also built something from the ground up at a high-growth fintech. Someone comfortable with ambiguity, confident in their risk judgment, and ready to be handed the reins.
What You’ll Do
What We’re Looking For
Nice to Have
Flex takes a market-based approach to pay, ensuring compensation is commensurate with a candidate's experience and our internal leveling guidelines. For candidates located in our Tier 1 markets (NYC/ SF), the base salary pay range for this role is $176,000—$220,000 USD. For all other U.S. locations, Flex utilizes a geographic pay differential based on a cost of labor index. If you are located outside of the Tier 1 states listed above, your starting pay will be adjusted to align with the market conditions of your specific geographic zone. Please speak with your recruiter for additional information regarding the specific range for your location.
We understand that it takes a diverse team of highly intelligent, curious, determined, empathetic, and self aware people to grow a successful company. Our HQ is located in New York City, but we have employees located throughout the US, Australia, Canada and South America. We are growing quickly, but deliberately, with a focus on building an inclusive culture. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity workplace.
Offices
Roles posted in New York, San Francisco, and Salt Lake City are hybrid positions with on-site expectations of 2-3 days per week in our local offices. For candidates outside of these areas, you may be eligible for our relocation assistance program.
Benefits
For full-time U.S. employees we offer:
For full-time non-U.S. employees, we offer:
Ready to apply?
Apply to Flex
Share this job
The Opportunity
As a Security Sales Specialist, you'll partner with Enterprise Account Executives to drive adoption of Datadog’s Security platform across key accounts. This is a high-impact role focused on positioning our Security solutions (Cloud SIEM, Cloud Workload Security, CSPM, and more) into new and existing customers—expanding our footprint and helping customers modernize their security stack in the cloud.
What You'll Do
Act as the subject matter expert (SME) for Datadog Security products across a targeted account patch
Collaborate closely with Enterprise AEs to support net new logo acquisition and expansion in strategic accounts
Own and drive the security sales cycle from discovery to technical close, working closely with Sales Engineers
Evangelize Datadog’s security story to security leaders (CISO, Security Architects, SecOps)
Work cross-functionally with Datadog's partner, channel, and alliance teams to drive joint go-to-market motions
Co-sell effectively with AEs and partners, contributing to deal strategy, solution alignment, and stakeholder engagement
Stay informed on security trends and competitive offerings to differentiate Datadog
Requirements
Proven success selling into security buyers (CISO, SecOps, GRC, etc.)
Experience co-selling in a matrixed environment, supporting or partnering with AEs and cross-functional teams
Strong understanding of the partner/channel sales model, including how to navigate and influence joint selling motions
Familiarity with modern security solutions such as SIEM, CSPM, CWPP, container/Kubernetes security
Ability to build strong relationships with internal stakeholders, partners, and customer technical teams
Datadog offers a competitive salary and equity package, and may include variable compensation. Actual compensation is based on factors such as the candidate's skills, qualifications, and experience. In addition, Datadog offers a wide range of best in class, comprehensive and inclusive employee benefits for this role including healthcare, dental, parental planning, and mental health benefits, a 401(k) plan and match, paid time off, fitness reimbursements, and a discounted employee stock purchase plan.
About Datadog:
Datadog is the leading observability and security platform for the AI era, providing businesses with unified visibility across the technology stack to manage complexity at scale. It brings applications, infrastructure, data, models, and security into one place, using AI to detect and resolve issues before they impact customers. Trusted globally by Fortune 500 companies and high-growth AI leaders, Datadog enables businesses to move faster with clarity and confidence. Learn more about #DatadogLife on Instagram, LinkedIn, and Datadog Learning Center.
Equal Opportunity at Datadog:
Datadog is proud to offer equal employment opportunity to everyone regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, and other characteristics protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. Here are our Candidate Legal Notices for your reference.
Datadog endeavors to make our Careers Page accessible to all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please complete this form. This form is for accommodation requests only and cannot be used to inquire about the status of applications.
Privacy and AI Guidelines:
Any information you submit to Datadog as part of your application will be processed in accordance with Datadog’s Applicant and Candidate Privacy Notice. For information on our AI policy, please visit Interviewing at Datadog AI Guidelines.
Ready to apply?
Apply to Datadog
Share this job
Revolution Medicines is a late-stage clinical oncology company developing novel targeted therapies for patients with RAS-addicted cancers. The company’s R&D pipeline comprises RAS(ON) inhibitors designed to suppress diverse oncogenic variants of RAS proteins. The company’s RAS(ON) inhibitors daraxonrasib (RMC-6236), a RAS(ON) multi-selective inhibitor; elironrasib (RMC-6291), a RAS(ON) G12C-selective inhibitor; zoldonrasib (RMC-9805), a RAS(ON) G12D-selective inhibitor; and RMC-5127, a RAS(ON) G12V-selective inhibitor, are currently in clinical development. As a new member of the Revolution Medicines team, you will join other outstanding professionals in a tireless commitment to patients with cancers harboring mutations in the RAS signaling pathway.
The Opportunity:
We are seeking an experienced and strategic leader to serve as Director, Information Sciences Governance, Risk & Compliance (IS GRC), reporting directly to the VP, IS Security, Risk, and Compliance. This person will be responsible for leading and maturing the IS GRC program, ensuring that IS governance processes, technology risk management practices, third-party risk management, and compliance activities effectively support business objectives and protect the organization.
As a key leader within Information Sciences, this individual will partner closely with Security, Infrastructure, Enterprise Applications, Data & Analytics, Legal, Privacy, Quality, Finance, HR, Procurement, and other cross-functional stakeholders to establish a scalable and pragmatic IS GRC framework. They will help the organization navigate a dynamic regulatory, technology, and business environment by strengthening controls, driving compliance readiness, improving risk visibility, managing third-party risk, and enabling informed decision-making across IS.
This role is ideal for a leader who can balance strategic program development with operational execution, build trusted partnerships across the organization, and translate regulatory, technical, and control requirements into practical processes that enable the business.
Key Responsibilities:
IS GRC Program Leadership: Lead and evolve the Information Sciences Governance, Risk & Compliance program, including policies, standards, risk frameworks, compliance processes, and reporting.
IS Governance: Develop, implement, and maintain governance structures, policies, standards, and procedures to support IS objectives, regulatory obligations, and internal accountability.
Technology Risk Management: Establish and manage processes to identify, assess, prioritize, track, and report key IS, cybersecurity, data, third-party, and operational risks. Partner with stakeholders to develop mitigation and remediation plans.
Third-Party Risk Management: Lead and mature the third-party risk management program for Information Sciences, including risk assessment and oversight of vendors, service providers, and technology partners. Partner with Procurement, Legal, Security, Privacy, and business stakeholders to evaluate third-party controls, contractual requirements, and remediation plans to ensure third-party services meet company risk and compliance expectations.
Compliance Management: Oversee IS compliance initiatives related to applicable laws, regulations, contractual obligations, and internal policies. Coordinate control assessments, compliance reviews, and readiness efforts for audits and inspections.
Internal Controls: Partner with IS and business teams to design, document, evaluate, and improve IT and IS-related controls and monitor their effectiveness over time.
Policy and Standards Management: Drive the development, review, communication, and maintenance of IS policies, standards, baselines, and related procedures to ensure consistency, usability, and alignment with company requirements.
Audit and Assessment Support: Coordinate and support internal and external audits, risk assessments, and evidence requests related to Information Sciences systems, processes, and controls. Track observations and corrective actions through closure.
Cross-Functional Partnership: Build strong relationships across the business to understand technology risks, compliance obligations, and operational challenges, and to promote a culture of accountability and continuous improvement.
Metrics and Reporting: Develop meaningful dashboards, metrics, and executive reporting to communicate IS program health, compliance posture, risk trends, and remediation progress to senior leadership.
Training and Awareness: Promote awareness of IS governance, risk, and compliance responsibilities across Information Sciences and the broader organization through communication, training, and stakeholder engagement.
Continuous Improvement: Stay informed about emerging regulations, industry trends, and best practices in IT/IS governance, cybersecurity compliance, privacy, and risk management, and incorporate them into program enhancements.
This person will also coordinate with existing service delivery teams in Information Sciences to ensure that high levels of service and support are maintained.
Required Skills, Experience and Education:
Bachelor’s degree or equivalent and a minimum of 10+ years of experience in Information Technology, Information Sciences, governance, risk management, compliance, internal audit, cybersecurity compliance, or related functions, including leadership experience in a regulated industry.
Proven track record of building, managing, and scaling IS or IT GRC programs in complex organizations.
Experience partnering across IS, security, legal, privacy, quality, procurement, finance, and business teams to drive risk-informed and compliant technology practices.
Strong understanding of IT governance, technology risk management, internal controls, policy management, third-party risk management, and compliance operations.
Experience working in regulated environments and with relevant frameworks and requirements such as SOX, GxP, GDPR/CCPA, ISO 27001, HITRUST, cybersecurity, privacy, IT general controls, vendor risk management, and audit readiness, as applicable.
Experience supporting or leading control design, risk assessments, remediation activities, and audit or certification readiness efforts related to ISO 27001, HITRUST, or other relevant compliance frameworks.
Ability to translate regulatory, audit, and control requirements into practical, business friendly IS processes, standards, and guidance.
Entrepreneurial spirit; thrives in a fast-paced, high-growth, midsize company environment.
Comfortable handling ambiguity and navigating through evolving processes, priorities, and organizational needs.
Highly organized, with strong attention to detail and accuracy.
Committed to meeting and exceeding high standards for quality and continuous improvement.
Builds rapport and credibility as an effective strategic partner.
Fosters team collaboration, breaks down silos, and is able to influence without authority.
Skilled at conflict resolution, negotiation, and driving alignment across diverse stakeholder groups.
Acts with urgency and sound judgment. Enjoys enabling others and solving complex problems.
Ability to manage multiple initiatives, activities, and priorities simultaneously and autonomously.
Strong written and verbal communication, presentation, and facilitation skills, with the ability to distill complex information for senior leadership.
Preferred Skills:
Master’s degree or equivalent in Information Technology, Business, Risk Management, Cybersecurity, or a related field.
Relevant certifications such as CISA, CISM, CRISC, CISSP, CGEIT, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, HITRUST CCSFP, or similar are preferred.
Experience leading or supporting ISO 27001 and/or HITRUST implementation, certification, surveillance, or readiness programs is strongly preferred.
Experience leading or supporting IT/IS governance, cybersecurity compliance, privacy, audit, or risk programs in the pharmaceutical, biotechnology, life sciences, or other highly regulated industries.
Experience with third-party risk management, policy governance platforms, GRC tooling, control automation, and audit management solutions is a plus.
Experience developing and operationalizing IS policies, standards, procedures, and control frameworks across enterprise applications, infrastructure, cloud environments, and data platforms is desirable.
Experience developing executive-level reporting and dashboards for IT or IS risk and compliance programs is desirable.
Experience standing up or maturing enterprise IT governance, security governance, third-party risk management, or technology compliance monitoring programs is a plus.
Experience working with cross-functional stakeholders to align security, privacy, compliance, and business requirements into scalable operational processes is preferred.
#LI-Hybrid #LI-YG1
The base pay salary range for this full-time position for candidates working onsite at our headquarters in Redwood City, CA is listed below. The range displayed on each job posting is intended to be the base pay salary range for an individual working onsite in Redwood City and will be adjusted for the local market a candidate is based in. Our base pay salary ranges are determined by role, level, and location. Individual base pay salary is determined by multiple factors, including job-related skills, experience, market dynamics, and relevant education or training.
Please note that base pay salary range is one part of the overall total rewards program at RevMed, which includes competitive cash compensation, robust equity awards, strong benefits, and significant learning and development opportunities.
Revolution Medicines is an equal opportunity employer and prohibits unlawful discrimination based on race, color, religion, gender, sexual orientation, gender identity/expression, national origin/ancestry, age, disability, marital status, medical condition, and veteran status.
Revolution Medicines takes protection and security of personal data very seriously and respects your right to privacy while using our website and when contacting us by email or phone. We will only collect, process and use any personal data that you provide to us in accordance with our CCPA Notice and Privacy Policy. For additional information, please contact privacy@revmed.com.
We are aware of recent recruitment scams in which individuals or organizations falsely represent themselves as being affiliated with Revolution Medicines. These scams may appear as false job advertisements or unsolicited contacts through communication or chat platforms, email, phone, or text message.
Please note that Revolution Medicines does not extend unsolicited employment offers and will never ask candidates to provide financial information, purchase equipment, or pay fees as part of the hiring process. All legitimate communication from Revolution Medicines will come from an official @revmed.com email address.
If you believe you’ve been contacted by someone impersonating a Revolution Medicines recruiter, please report it to careers@revmed.com so we can share these impersonations with our IT team for tracking and awareness.
Ready to apply?
Apply to Revolution Medicines
Share this job
ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.
ID.me is seeking a Technical Program Manager – Security Assurance to serve as the operational backbone of our external compliance programs. You will co-own the end-to-end lifecycle of controls, policies, and program-specific documentation for FedRAMP, ISO 27001, and SOC 2, with additional contributions to Kantara accreditation.
You will drive cross-functional alignment independently, owning outcomes rather than tasks. A unique requirement of this role is high proficiency with AI tools; our team utilizes purpose-built AI agents for evidence validation, control evaluation, and finding management. Fluency in AI-assisted workflows is essential.
This role is based out of our Mountain View, CA or McLean, VA offices and requires full-time in-office attendance.
#LI-JS1
ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.
ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.
Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.
ID.me participates in E-Verify.
Ready to apply?
Apply to ID.me
Share this job
ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.
ID.me is seeking a GRC Engineer to design, build, and operate AI agents that automate the compliance lifecycle across FedRAMP, ISO 27001, SOC 2, and Kantara accreditation programs.
This role is a technologist that focuses on solving GRC domain problems with automation and AI.. You will write code and build tooling to scale GRC capabilities and reduce the compliance burden.. You will own engineering AI capabilities while also have the skillset to dive into compliance issues as another set up hands..
The primary initial challenge is automated evidence collection. You will develop programmatic methods to extract evidence from source systems, feed it into evaluation agents, and enable continuous monitoring to replace traditional annual snapshots with ongoing automated assurance.
This role is based out of our Mountain View, CA or McLean, VA offices and requires full-time in-office attendance
#LI-JS1
ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.
ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.
Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.
ID.me participates in E-Verify.
Ready to apply?
Apply to ID.me
Share this job
Postman is the world’s leading API platform, used by more than 45 million+ developers and 500,000 organizations, including 98% of the Fortune 500. Postman is helping developers and professionals across the globe build the API-first world by simplifying each step of the API lifecycle and streamlining collaboration—enabling users to create better APIs, faster.
The company is headquartered in San Francisco and has offices in Boston, New York, Austin, Tokyo, London, and Bangalore - where Postman was founded. Postman is privately held, with funding from Battery Ventures, BOND, Coatue, CRV, Insight Partners, and Nexus Venture Partners. Learn more at postman.com or connect with Postman on X via @getpostman.
P.S: We highly recommend reading The "API-First World" graphic novel to understand the bigger picture and our vision at Postman.
The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not checkbox-checkers. We hold active SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA compliance postures, and we are pursuing FedRAMP High and CMMC Level 2 authorization. Our security stack includes Wiz, SentinelOne, Okta, Jamf, and 1Password, and we operate across a multi-cloud environment.
The Offensive Security team is the "red" pulse of this organization. We don't just find bugs — we simulate the adversary to ensure our defenses hold up under real-world pressure. We focus on continuous security validation, AI-augmented adversary emulation, and offensive AI security research at Postman's scale.
We are looking for a Senior Manager, Offensive Security who is as much a strategist as they are a hacker. You will own the strategic direction of Postman's offensive security program — including building out a dedicated Offensive AI Security capability from the ground up — and operate as a key partner to CISO leadership on threat-informed defense strategy.
This is not a role where you inherit a mature program and keep the lights on. You will shape what offensive security looks like at Postman for the next three years, with a specific mandate to make us an industry leader in adversarial testing of AI systems, agentic workflows, and LLM integrations.
You will lead a team that doesn't just "report" vulnerabilities but "demonstrates" them, using live exploits to build a deep, visceral security culture across the entire engineering organization.
Set Strategic Direction: Define and execute the multi-year offensive security roadmap, aligning Red Team, Purple Team, and continuous validation capabilities to Postman's evolving threat landscape and business priorities.
Build the Offensive AI Security Practice: Stand up and scale a dedicated offensive capability targeting AI/ML systems. This includes adversarial testing of LLM integrations, agentic workflows (MCP, tool-use chains), RAG pipelines, and model-serving infrastructure. You will define the methodology, tooling, and engagement frameworks from the ground up.
Develop AI Threat Intelligence: Track and operationalize the rapidly evolving AI threat landscape — OWASP LLM Top 10, MITRE ATLAS, emerging attack research on agentic systems — translating external research into internal red team playbooks and detection hypotheses for Security Operations.
Red Team AI Systems at Depth: Go beyond checkbox assessments. Lead structured adversarial campaigns against Postman's LLM deployments, AI agents, and model pipelines — targeting prompt injection, tool-use abuse, data exfiltration via context manipulation, training data poisoning, model manipulation, and trust boundary violations in multi-agent architectures.
Architect Autonomous Testing: Design and deploy AI-based penetration testing platforms and autonomous agents to perform continuous security validation across our API ecosystem.
Continuous Validation: Move from manual pentesting to Continuous Offensive Security, integrating automated breach and attack simulation (BAS) into CI/CD pipelines, including AI model deployment pipelines.
Lead & Cultivate: Build, manage, and scale a high-performing team of offensive security engineers — including specialized AI red team operators — providing mentorship, career development, and succession planning.
Recruit for the Future: Identify and hire talent at the intersection of offensive security and AI/ML — a rare and competitive talent market. Build a pipeline that includes internal development paths for existing security engineers to cross-skill into AI red teaming.
Drive Security Culture through "The Show": Lead live "Exploitable Demonstrations" — technical proof-of-concepts presented to engineering teams that show exactly how a vulnerability could be leveraged, turning abstract risks into tangible learning moments. Place particular emphasis on demystifying AI-specific attack vectors for non-ML engineers.
Executive Communication: Translate offensive findings into business-level risk narratives for executive leadership, the board, and external stakeholders. Partner with GRC on audit evidence and compliance posture derived from offensive operations, including AI-specific risk frameworks (ISO 42001).
Cross-Functional Partnership: Operate as a senior technical leader across Product Security, Security Operations, and Engineering, ensuring offensive findings — especially from AI red team engagements — drive measurable improvements in detection, response, and architecture.
Experience: Minimum of 8 years in offensive security (penetration testing, red teaming, vulnerability research, or exploit development) with at least 4 years in a people management or leadership capacity, including experience managing managers or tech leads.
AI/ML Offensive Depth: Demonstrated experience attacking AI/ML systems — whether through adversarial ML research, LLM red teaming, agentic system exploitation, or building offensive tooling for AI targets. You understand the difference between prompt injection and indirect prompt injection, know what a tool-use confusion attack looks like, and can articulate why RAG poisoning is a supply chain problem.
Strategic Acumen: Demonstrated ability to build and scale an offensive security program from the ground up or significantly mature an existing one. Experience setting OKRs, managing budgets, and presenting to executive leadership.
Adversarial Mindset: Deep understanding of the modern threat landscape and how to apply it to cloud-native, API-first environments — extended to AI-native architectures.
AI Offensive Tooling Fluency: Hands-on experience with AI-augmented pentesting tools (e.g., PentestGPT, Horizon3, custom LLM-based fuzzing) and purpose-built AI red team frameworks (e.g., Microsoft PyRIT, Garak, custom harnesses). Understanding of how to manage non-deterministic AI outputs in both offensive tooling and target systems.
Pragmatic Storytelling: You believe that a well-executed exploit demo is more effective than a 50-page PDF. You can present a complex exploit chain — including an AI-specific attack path — to a room of developers in a way that is inspiring, not condescending.
Engineering Fluency: You prefer building an automated "exploit-as-code" validator over performing the same manual test twice. You can architect evaluation harnesses and adversarial test suites for ML models.
Industry Presence: Track record of contributions to the offensive security or AI security community — conference talks (DEF CON, Black Hat, BSides, RSA), tool releases, published research, CVEs, or active participation in OWASP, MITRE, or similar working groups.
Certifications: OSCP, OSCE, OSEP, GXPN, GPEN, CRTP, or equivalent hands-on offensive certifications. AI/ML-specific credentials (e.g., GIAC GMAI) are a differentiator.
Cloud Security Expertise: Deep familiarity with AWS security primitives, cloud-native attack paths, and container/Kubernetes exploitation.
API Security Depth: Experience with API-specific attack methodologies — BOLA, BFLA, mass assignment, GraphQL abuse, gRPC exploitation — reflecting Postman's core product domain.
Compliance Awareness: Familiarity with how offensive security outputs map to SOC 2 Type II, ISO 27001, ISO 42001, FedRAMP, or CMMC control evidence. You don't run GRC, but you know how to feed it.
The reasonably estimated base salary for this role ranges from $275,000 to $300,000, plus a competitive equity package. Actual compensation is based on the candidate's skills, qualifications, and experience.
In addition to Postman's pay-on-performance philosophy, and a flexible schedule working with a fun, collaborative team, Postman offers a comprehensive set of benefits, including full medical coverage, flexible PTO, wellness reimbursement, and a monthly lunch stipend. Along with that, our wellness programs will help you stay in the best of your physical and mental health. Our frequent and fascinating team-building events will keep you connected, while our donation-matching program can support the causes you care about. We’re building a long-term company with an inclusive culture where everyone can be the best version of themselves.
At Postman we value in person collaboration. We are in office 5 days a week for all roles based out of our hubs in San Francisco Bay Area, Boston, Austin, Tokyo and London. For roles based in Bangalore, employees currently work in the office three days a week and will transition to five days per week by the end of the year. We were thoughtful in our approach which is based on collaboration and grounded in feedback from our workforce, leadership team, and peers. The benefits of our in office model will be shared knowledge, brainstorming sessions, communication, and building trust in-person that cannot be replicated via zoom.
At Postman, we create with the same curiosity that we see in our users. We value transparency and honest communication about not only successes, but also failures. In our work, we focus on specific goals that add up to a larger vision. Our inclusive work culture ensures that everyone is valued equally as important pieces of our final product. We are dedicated to delivering the best products we can.
Postman is an Equal Employment Opportunity and Affirmative Action Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status. Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Postman does not accept unsolicited headhunter and agency resumes. Postman will not pay fees to any third-party agency or company that does not have a signed agreement with Postman.
Ready to apply?
Apply to Postman
Share this job
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society.
Our goal at OneTrust is to bring the power of trust to companies all over the world. Using cutting-edge technology and a real-world approach to compliance, privacy, security, ethics, and third-party risk, we’ve created a no-nonsense platform to help supercharge the global push for trust.
For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.
We are embracing an office-first culture, encouraging three days a week in office for most roles, with meaningful opportunities to collaborate and celebrate in person.
Each role may have specific requirements or flexibility depending on the scope of the position, so we encourage you to verify this with your recruiter during your first interview.
As an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity RSUs, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.
Check out the following to learn more about OneTrust and its people:
You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy Overview. You can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.
Recruitment fraud warning: OneTrust is aware of scams involving false offers of employment with our company. The fraudulent jobs, interviews and job offers use fake websites, email addresses, group chat and text messages. Be aware that we never ask candidates for personal information, IDs or bank information during the interview process. We do not interview prospective candidates via instant message or group chat, and do not require candidates to purchase products or services, or process payments on our behalf as a condition of any employment offer. Please note that any legitimate interview availability requests will come directly from a OneTrust recruiter with an "@onetrust.com" email address. You may also receive legitimate emails from "@us.greenhouse-mail.io". Recruiters will only reach out to candidates who have applied for a role through our ATS (Greenhouse) or prospects via LinkedIn InMail. Job offers will come from a recruiter and may have a "@docusign.net" email address. For more information or if you have been targeted please reach out to askrecruiting@onetrust.com.
When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new category. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career.
OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.
Ready to apply?
Apply to OneTrust
Share this job
Who we are
Aurora’s mission is to deliver the benefits of self-driving technology safely, quickly, and broadly.
The Aurora Driver will create a new era in mobility and logistics, one that will bring a safer, more efficient, and more accessible future to everyone.
At Aurora, you will tackle massively complex problems alongside other passionate, intelligent individuals, growing as an expert while expanding your knowledge. For the latest news from Aurora, visit aurora.tech or follow us on LinkedIn.
Aurora is looking for a Staff Technical Program Manager (TPM) to lead complex security initiatives that span multiple engineering teams and security pillars. In this role, you will partner closely with security leaders, engineering teams, and technical architects to turn security strategy into concrete programs that improve the resilience and safety of Aurora’s systems.
This role reports to the Security PMO within Aurora’s OneTech organization and sits in the Business Operations pillar. Programs in this role typically span multiple engineering teams and security pillars and may run for several quarters, requiring coordination across senior engineering and security leaders.
In this role you will
Required qualifications
Desirable qualifications
The base salary range for this position is $181,000-$262,000. Aurora’s pay ranges are determined by role, level, and location. Within the range, the successful candidate’s starting base pay will be determined based on factors including job-related skills, experience, qualifications, relevant education or training, and market conditions. These ranges may be modified in the future. The successful candidate will also be eligible for an annual bonus, equity compensation, and benefits.
#LI-KS1
#Mid-Senior
Working at Aurora
At Aurora, we bring together extraordinarily talented and experienced people united by the strength of our values. We operate with integrity, set outrageous goals, and build a culture where we win together — all without any jerks.
We believe in-person work increases collaboration, empathy and our ability to lead effectively. As a result, we operate in a hybrid work environment where Aurorans are in office at least 3 days per week.
Our Careers page provides insight into what it is like to work at Aurora, and you can find all the latest updates in our Newsroom.
Our commitment to safety
At the core of everything we do is our commitment to safety. Building best-in-class self-driving technology will take time, and we believe that each employee at Aurora has a role in contributing to safety, every step of the way. Aurora expects commitment to our safety policies from every employee, and seeks candidates who take an active responsibility, can contribute to building an atmosphere of trust, and invest in the organization’s long-term success by prioritizing working safely, no matter what.
Our commitment to inclusion
Aurora considers candidates without regard to their race, color, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, pregnancy status, parent or caregiver status, ancestry, political affiliation, veteran and/or military status, physical or mental disability, or any other status protected by federal or state law. Aurora considers qualified applicants with criminal histories, consistent with applicable federal, state, and local law. We are also committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. If you need assistance or an accommodation due to a disability, you may contact us at careersiteaccommodations@aurora.tech.
For California applicants, information collected and processed as part of your application and any job applications you choose to submit is subject to Aurora’s California Employment Privacy Policy.
Ready to apply?
Apply to Aurora Innovation
Share this job
About Applied IntuitionWe are an in-office company, and our expectation is that employees primarily work from their Applied Intuition office 5 days a week. However, we also recognize the importance of flexibility and trust our employees to manage their schedules responsibly. This may include occasional remote work, starting the day with morning meetings from home before heading to the office, or leaving earlier when needed to accommodate family commitments.
We are seeking a multifaceted Corporate Security Engineer who will lead everything that protects our endpoints, networks, collaboration platforms and enterprise data. You will partner closely with IT Infrastructure, Detection & Response, and GRC teams to ensure security controls are effective, scalable, and aligned with business operations. In this role, you are expected to define the roadmap, make architectural decisions, and represent Corporate Security across the company.
Compensation at Applied Intuition for eligible roles includes base salary, equity, and benefits. Base salary is a single component of the total compensation package, which may also include equity in the form of options and/or restricted stock units, comprehensive health, dental, vision, life and disability insurance coverage, 401k retirement benefits with employer match, learning and wellness stipends, and paid time off. Note that benefits are subject to change and may vary based on jurisdiction of employment.
Applied Intuition pay ranges reflect the minimum and maximum intended target base salary for new hire salaries for the position. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, interview performance, and the level and scope of the position.
Please reference the job posting’s subtitle for where this position will be located. For pay transparency purposes, the base salary range for this full-time position in the location listed is: $180,000 - $230,000 USD annually.
Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
Applied Intuition is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a) and 41 CFR 60-741.5(a) and that these laws are incorporated herein by reference. These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity or national origin. These regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. The parties also agree that, as applicable, they will abide by the requirements of Executive Order 13496 (29 CFR Part 471, Appendix A to Subpart A), relating to the notice of employee rights under federal labor laws.
Ready to apply?
Apply to Applied Intuition
Share this job
About Applied IntuitionWe are an in-office company, and our expectation is that employees primarily work from their Applied Intuition office 5 days a week. However, we also recognize the importance of flexibility and trust our employees to manage their schedules responsibly. This may include occasional remote work, starting the day with morning meetings from home before heading to the office, or leaving earlier when needed to accommodate family commitments.
We are seeking a multifaceted Enterprise Security Lead who will lead everything that protects our endpoints, networks, collaboration platforms and enterprise data. You will partner closely with IT Infrastructure, Detection & Response, and GRC teams to ensure security controls are effective, scalable, and aligned with business operations. In this role, you are expected to define the roadmap, make architectural decisions, and represent Corporate Security across the company.
Compensation at Applied Intuition for eligible roles includes base salary, equity, and benefits. Base salary is a single component of the total compensation package, which may also include equity in the form of options and/or restricted stock units, comprehensive health, dental, vision, life and disability insurance coverage, 401k retirement benefits with employer match, learning and wellness stipends, and paid time off. Note that benefits are subject to change and may vary based on jurisdiction of employment.
Applied Intuition pay ranges reflect the minimum and maximum intended target base salary for new hire salaries for the position. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, interview performance, and the level and scope of the position.
Please reference the job posting’s subtitle for where this position will be located. For pay transparency purposes, the base salary range for this full-time position in the location listed is: $180,000 - $230,000 USD annually.
Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
Applied Intuition is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a) and 41 CFR 60-741.5(a) and that these laws are incorporated herein by reference. These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity or national origin. These regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. The parties also agree that, as applicable, they will abide by the requirements of Executive Order 13496 (29 CFR Part 471, Appendix A to Subpart A), relating to the notice of employee rights under federal labor laws.
Ready to apply?
Apply to Applied Intuition
Share this job
About Applied IntuitionWe are an in-office company, and our expectation is that employees primarily work from their Applied Intuition office 5 days a week. However, we also recognize the importance of flexibility and trust our employees to manage their schedules responsibly. This may include occasional remote work, starting the day with morning meetings from home before heading to the office, or leaving earlier when needed to accommodate family commitments.
We are looking for a multifaceted Risk and Compliance Lead to lead our security compliance initiatives across the organization. You will be responsible for ensuring adequate security controls to identify and mitigate risk across the organization. Additionally, you will collaborate with legal, engineering, operations and customers, as necessary, to ensure the state of compliance is well communicated.
Compensation at Applied Intuition for eligible roles includes base salary, equity, and benefits. Base salary is a single component of the total compensation package, which may also include equity in the form of options and/or restricted stock units, comprehensive health, dental, vision, life and disability insurance coverage, 401k retirement benefits with employer match, learning and wellness stipends, and paid time off. Note that benefits are subject to change and may vary based on jurisdiction of employment.
Applied Intuition pay ranges reflect the minimum and maximum intended target base salary for new hire salaries for the position. The actual base salary offered to a successful candidate will additionally be influenced by a variety of factors including experience, credentials & certifications, educational attainment, skill level requirements, interview performance, and the level and scope of the position.
Please reference the job posting’s subtitle for where this position will be located. For pay transparency purposes, the base salary range for this full-time position in the location listed is: $160,000 - $190,000 USD annually.
Don’t meet every single requirement? If you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyway. You may be just the right candidate for this or other roles.
Applied Intuition is an equal opportunity employer and federal contractor or subcontractor. Consequently, the parties agree that, as applicable, they will abide by the requirements of 41 CFR 60-1.4(a), 41 CFR 60-300.5(a) and 41 CFR 60-741.5(a) and that these laws are incorporated herein by reference. These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity or national origin. These regulations require that covered prime contractors and subcontractors take affirmative action to employ and advance in employment individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disability. The parties also agree that, as applicable, they will abide by the requirements of Executive Order 13496 (29 CFR Part 471, Appendix A to Subpart A), relating to the notice of employee rights under federal labor laws.
Ready to apply?
Apply to Applied Intuition
Mill is a waste prevention technology company reimagining what it means to eliminate waste, starting with food. We build smart systems and infrastructure for homes, businesses, and municipalities that transform food scraps from landfill-bound waste into valuable resources, including chicken feed. Tens of thousands of Mill’s residential food recyclers are already helping households divert millions of pounds of food scraps every year, paving the way for our upcoming launch of Mill Commercial—the industry’s first end-to-end solution for managing, understanding, and preventing food waste in commercial environments (e.g. grocery, restaurants, food services). At Mill, we are passionate about building easy-to-use, beautifully designed technologies that keep food in the food system and out of landfills.
We're hiring a Security & IT Lead to own information security and compliance programs across Mill. This is a senior individual contributor role.
You'll be the security authority for the company — setting the standard for how Mill protects data, manages risk, and earns the trust of employees, customers, and enterprise partners. You'll also serve as Mill's internal technical authority over our managed IT provider — ensuring the quality, reliability, and scalability of IT services, not just their security posture. You'll own our compliance frameworks, lead our SOC 2 program, and ensure Mill's internal and external systems are secured to a high standard. This role requires someone who is self-directed, cross-functional, and equally comfortable in technical and policy-oriented work.
Information Security. Own Mill's information security posture end-to-end — across internal systems (identity and access management, endpoint protection, SaaS tools) and external/customer-facing platforms. Define and enforce security policies, access controls, and data classification standards. Serve as the primary escalation point for security incidents. Manage security tooling across the stack including phishing simulation, endpoint management, and access governance platforms. Conduct regular access reviews, risk assessments, and vulnerability reviews.
Compliance Programs. Lead Mill's SOC 2 program from roadmap through audit readiness and ongoing maintenance — coordinating cross-functional tasks, owning policy documentation, and managing relationships with external auditors. Maintain and evolve Mill's Policy & Procedure Library with regular reviews. Field security questionnaires from enterprise customers and prospective partners. Evaluate and scope additional compliance frameworks as the business grows (ISO 27001, CCPA, etc.).
IT Operations & Oversight. Act as the internal technical owner of Mill's relationship with our managed IT provider. Define SLAs, review architecture decisions, approve changes, and hold the provider accountable for service quality, reliability, and cost-effectiveness. Own the IT roadmap — including network infrastructure, endpoint fleet, collaboration tooling, and onboarding/offboarding workflows. Evaluate new tools and vendors for both operational fit and security risk. Ensure IT standards (network design, device management, VPN, etc.) meet Mill's needs as we scale.
AI & Emerging Technology. Contribute a security perspective to Mill's AI adoption efforts — reviewing AI tools for data handling risk, contributing to acceptable use policies, and ensuring Mill's AI governance posture keeps pace with adoption.
The estimated base salary range for this position is $185k to $210k, which does not include the value of benefits or a potential equity grant. A wide range of factors are considered in making compensation decisions, including but not limited to skill sets, market conditions, experience and training, licensure and certifications, and business and organizational needs.
Ready to apply?
Apply to Mill
Share this job
Sr Manager, InfoSec Governance Risk and Compliance (GRC)
(San Francisco Bay Area, California, United States)
Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.
COMPANY OVERVIEW
At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration.
We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities.
Learn more at www.ivalua.com. Follow us on LinkedIn and Twitter.
THE OPPORTUNITY
CONTEXT:
Our InfoSec team is dedicated to building, maintaining, and continuously improving Ivalua’s Information Security program globally. We provide peace of mind and assurance of protection and safety to our customers. In this fast-growing environment, the GRC program is critical to ensuring compliance with industry standards and certifications, managing risks, and supporting business growth.
ROLE:
We are currently looking for an experienced InfoSec Governance Risk and Compliance (GRC) Sr Manager to lead a global team and own the GRC program worldwide. Reporting to the InfoSec leadership, you will manage and develop a high-performing team, drive compliance efforts, and serve as a subject matter expert on security frameworks and standards.
WHAT YOU WILL DO WITH US
YOUR PROFILE
If you have the below experience and strengths this role could be for you:
Skills and Experience:
Soft Skills:
WHAT HAPPENS NEXT
If your application fits this specific position’s needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals – apply today!
Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you!
Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role.
Interviews will be conducted virtually via video or on-site with face-to-face meetings.
LIFE AT IVALUA
Powered by People - Powered by You!
United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/
Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us.
Ivalua’s core values include a priority on Care & Grow People. We take matters like pay equity very seriously and strive to reward our employees appropriately and fairly for their talents.
The compensation range for this position reflects the cost of labor across our US locations and is based upon careful and continual market research. In addition to location, compensation may also vary based upon job-related knowledge, skills, and experience.
Title: Manager, InfoSec Governance Risk and Compliance (GRC)
Range minimum: USD 112000
Range maximum: USD 208000
Additional compensation / rewards: Ivalua also offers exceptional benefits including medical, dental, vision and transportation.
#LI-SG1
#LI-HYBRID
Ready to apply?
Apply to Ivalua
About this opportunity:
We are looking for an experienced Senior Manager, IT Infrastructure to lead the team through the architecture, design, and implementation of infrastructure technologies that will be critical in providing the technology platform Freenome needs to scale its business. This role will involve new technology implementations and managing the support of current infrastructure including working with supporting vendors.
The Senior Manager, IT infrastructure will have a deep and broad knowledge of networking, virtualization, server, storage, and operating system technologies, both on-premise as well as in the GCP cloud. This position will work closely with the Information Security team to ensure a compliant and secure infrastructure environment.
The role reports to the Director, IT. This role will be a Hybrid role.
What you’ll do:
Must haves:
Nice to haves:
Benefits and additional information:
The US target range of our base salary for new hires is $180,975 - $232,575. You will also be eligible to receive equity, cash bonuses, and a full range of medical, financial, and other benefits depending on the position offered. Please note that individual total compensation for this position will be determined at the Company’s sole discretion and may vary based on several factors, including but not limited to, location, skill level, years and depth of relevant experience, and education. We invite you to check out our career page @ freenome.com/job-openings/ for additional company information.
Freenome is proud to be an equal-opportunity employer, and we value diversity. Freenome does not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
Applicants have rights under Federal Employment Laws.
#LI-HYBRID
Ready to apply?
Apply to FreenomeShare this job
Job Purpose:
BTIG is seeking an Associate who will help lead and evolve the governance engine of a global, mid-sized investment bank to support our next phase of growth. You will report directly to the CISO and be responsible for security assurance, compliance operations, and technology risk management. You will help maintain control readiness, perform testing and evidence collection, and support risk and vendor assessments for internally developed systems and SaaS applications. Your work will directly protect the firm's reputation and enable its business. We don’t expect you to know every regulatory framework on day one. We do expect you to write exceptionally well, ask smart questions, and possess the grit to see difficult tasks through completion.
Duties & Responsibilities:
IT Governance, Risk and Compliance (GRC)
Operational Support
AI & Innovation
Requirements & Qualifications:
Important Notes:
About BTIG:
BTIG is a global financial services firm specializing in institutional trading, investment banking, research and related brokerage services. With an extensive global footprint and more than 700 employees, BTIG, LLC and its affiliates operate out of 20 cities throughout the U.S., and in Europe, Asia and Australia. BTIG offers execution, expertise and insights for equities, equity derivatives, ETFs and fixed income, currency and commodities. The firm’s core capabilities include global execution, portfolio, electronic and outsource trading, investment banking, prime brokerage, capital introduction, corporate access, research and strategy, commission management and more.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability status. BTIG is an equal opportunity employer Minorities/Females/People with Disabilities/Protected Veterans/Sexual Orientation/Gender Identity.
Compensation:
Disclaimer: https://www.btig.com/disclaimer.aspx.
Ready to apply?
Apply to BTIGCookies & analytics
This site uses cookies from third-party services to deliver its features and to analyze traffic.