Writing.io Jobs

Find the best remote jobs. Answer a few questions and we'll deploy a powerful assistant to help you search, create alerts, and more.

1 What roles are you open to?

2 Experience level

3 Work style

Did you know? If memory is enabled, Writing.io can remember your job search preferences and help you to improve your resume, craft customized outreach and more.

Security Security Engineer at Primer

Builds product security infrastructure through threat modeling, security reviews, compliance, and AppSec tooling for a payments platform.

Mid Posted about 20 hours ago RemoteFirstJobs Product
What this role involves

An Introduction to Primer

Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.

Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we’re building the payments layer the world’s best companies rely on.

Watch our showcase >

Read up on our $100m Series C

Learn more about our culture >

Which team will you be joining?

You’ll help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You’d be the second hire, and the person that function finally gets to share the work with.

This is a hands-on delivery role, and a genuinely formative one. You’ll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams. You’ll have a clear direction to work within and someone senior to learn from, while still owning your projects end to end.

Security at Primer sits close to the engineering teams it protects rather than off to one side, so you’ll spend real time embedded with the people building Cloud, Infra, and product. For someone who wants to go deep in product security with room to grow, there are few better seats than being the second engineer in a function that’s only now scaling.

What will you be doing?

  • Running security reviews and threat modelling on features and systems across Primer’s product, and turning findings into clear, actionable guidance for the teams shipping them

  • Independently planning and delivering your own security projects, from initial design through to rollout

  • Building tooling and automation that makes future reviews faster and cheaper to run

  • Coordinating penetration testing and tracking remediation through to closure

  • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows

  • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM

  • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for

  • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

What we’re looking for

  • Working experience in product or application security: you’ve done security reviews or threat modelling and can spot the risks that matter

  • The ability to read and write code, not just review it. You’re comfortable building small tools and automation rather than only filing findings

  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly

  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer

  • Clear communication with engineers who aren’t security specialists, since most of your impact lands through their work

Nice to have:

  • Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them

  • Background in payments, fintech, or another regulated, high-stakes domain

  • Interest in areas like supply chain security, detection engineering, or AI security

You may not like it here

  • It’s remote-first and high autonomy. You’ll get direction, but nobody checks your progress daily. If you need close structure, this will be uncomfortable

  • You’ll move between proactive project work and reactive BAU, and priorities will shift as audits and incidents land. Tolerating that change is part of the role.

✅ A typical interview process

  • An initial intro call with a Talent Partner

  • An interview with the Hiring Manager

  • Challenge Stage - Contextualised to the role

  • A final, values-alignment interview

What’s the culture like at Primer?

We’re building a culture where people can do their best work and be proud of the impact they have. You’ll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.

We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and co-working space access worldwide.

The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there’s a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It’s never something you face alone.

Our benefits

🌍 We are fully remote and globally distributed; and have been since day one

💰 Competitive share options

🌴 Uncapped holiday, with 25 days minimum to be taken

🗣️ Co-working space access

📅 Workations & Company Retreat

💻 The best equipment for your role

🏠 £500 towards your home office setup

🔎 Generous learning budget

🏥 Private Medical Insurance

📈 A broad set of additional perks and benefits ( depending on location)

Don’t meet every single requirement?

At Primer, we’re dedicated to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience doesn’t align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.

Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.

Read the full description
Security Staff, Security Engineer at Fullscript

Staff-level security engineer who designs and implements security solutions across applications and platforms while mentoring teams and shaping security strategy.

Lead Posted about 20 hours ago RemoteFirstJobs Product
What this role involves

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.

Join us and shape the future of care.

The Opportunity

We’re looking for a Staff Security Engineer to join Fullscript’s Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You’ll work closely with engineering teams to design and implement security solutions that scale across Fullscript’s products and platforms. As a Staff-level engineer, you’ll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You’ll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We’re looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you’ll do

  • Lead the design and implementation of security solutions across Fullscript’s applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript’s long-term security posture.

What you bring to the table

  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.

Bonus if you have

  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.

What we can offer you

  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career

Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More

www.fullscript.com

@fullscriptHQon instagram

@fullscript on YouTube

FullScripton LinkedIn

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Security Engineer at Primer

Conducts security reviews, threat modeling, and compliance work for a payments platform while building AppSec tooling and automation.

Mid Posted about 20 hours ago RemoteFirstJobs Product
What this role involves

An Introduction to Primer

Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.

Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we’re building the payments layer the world’s best companies rely on.

Watch our showcase >

Read up on our $100m Series C

Learn more about our culture >

Which team will you be joining?

You’ll help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You’d be the second hire, and the person that function finally gets to share the work with.

This is a hands-on delivery role, and a genuinely formative one. You’ll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams. You’ll have a clear direction to work within and someone senior to learn from, while still owning your projects end to end.

Security at Primer sits close to the engineering teams it protects rather than off to one side, so you’ll spend real time embedded with the people building Cloud, Infra, and product. For someone who wants to go deep in product security with room to grow, there are few better seats than being the second engineer in a function that’s only now scaling.

What will you be doing?

  • Running security reviews and threat modelling on features and systems across Primer’s product, and turning findings into clear, actionable guidance for the teams shipping them

  • Independently planning and delivering your own security projects, from initial design through to rollout

  • Building tooling and automation that makes future reviews faster and cheaper to run

  • Coordinating penetration testing and tracking remediation through to closure

  • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows

  • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM

  • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for

  • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

What we’re looking for

  • Working experience in product or application security: you’ve done security reviews or threat modelling and can spot the risks that matter

  • The ability to read and write code, not just review it. You’re comfortable building small tools and automation rather than only filing findings

  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly

  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer

  • Clear communication with engineers who aren’t security specialists, since most of your impact lands through their work

Nice to have:

  • Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them

  • Background in payments, fintech, or another regulated, high-stakes domain

  • Interest in areas like supply chain security, detection engineering, or AI security

You may not like it here

  • It’s remote-first and high autonomy. You’ll get direction, but nobody checks your progress daily. If you need close structure, this will be uncomfortable

  • You’ll move between proactive project work and reactive BAU, and priorities will shift as audits and incidents land. Tolerating that change is part of the role.

✅ A typical interview process

  • An initial intro call with a Talent Partner

  • An interview with the Hiring Manager

  • Challenge Stage - Contextualised to the role

  • A final, values-alignment interview

What’s the culture like at Primer?

We’re building a culture where people can do their best work and be proud of the impact they have. You’ll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.

We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and co-working space access worldwide.

The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there’s a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It’s never something you face alone.

Our benefits

🌍 We are fully remote and globally distributed; and have been since day one

💰 Competitive share options

🌴 Uncapped holiday, with 25 days minimum to be taken

🗣️ Co-working space access

📅 Workations & Company Retreat

💻 The best equipment for your role

🏠 £500 towards your home office setup

🔎 Generous learning budget

🏥 Private Medical Insurance

📈 A broad set of additional perks and benefits ( depending on location)

Don’t meet every single requirement?

At Primer, we’re dedicated to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience doesn’t align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.

Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.

Read the full description
Security Security Engineer at Primer

Security engineer performs threat modeling, security reviews, compliance work, and builds AppSec tooling for a payments infrastructure platform.

Mid Posted about 20 hours ago RemoteFirstJobs Product
What this role involves

An Introduction to Primer

Primer is the unified infrastructure for global payments. We give finance and payments teams the visibility and control to reduce complexity, improve performance, and capture more revenue - all from a single platform.

Backed by Sofina, Peak XV Partners, ICONIQ, Tencent, Accel, and Balderton, we’re building the payments layer the world’s best companies rely on.

Watch our showcase >

Read up on our $100m Series C

Learn more about our culture >

Which team will you be joining?

You’ll help build the entire product security surface for a company processing payments at scale: threat modelling, security review, compliance, incident escalation, and the multi-year AppSec roadmap. You’d be the second hire, and the person that function finally gets to share the work with.

This is a hands-on delivery role, and a genuinely formative one. You’ll help set the security strategy and architecture; you take real ownership of the work that turns it into reality, reviews, research, automation, and the day-to-day partnership with engineering teams. You’ll have a clear direction to work within and someone senior to learn from, while still owning your projects end to end.

Security at Primer sits close to the engineering teams it protects rather than off to one side, so you’ll spend real time embedded with the people building Cloud, Infra, and product. For someone who wants to go deep in product security with room to grow, there are few better seats than being the second engineer in a function that’s only now scaling.

What will you be doing?

  • Running security reviews and threat modelling on features and systems across Primer’s product, and turning findings into clear, actionable guidance for the teams shipping them

  • Independently planning and delivering your own security projects, from initial design through to rollout

  • Building tooling and automation that makes future reviews faster and cheaper to run

  • Coordinating penetration testing and tracking remediation through to closure

  • Supporting the recurring compliance work (SOC2, PCI), including evidence collection and remediation tracking against fixed audit windows

  • Contributing to AppSec roadmap initiatives across areas like application threats, AI security, supply chain security, and ASPM

  • Picking up proactive security work, threat research and hands-on investigation, that a one-person function has never had the capacity for

  • Working alongside Cloud, Infra, and GRC on the security aspects of their projects

What we’re looking for

  • Working experience in product or application security: you’ve done security reviews or threat modelling and can spot the risks that matter

  • The ability to read and write code, not just review it. You’re comfortable building small tools and automation rather than only filing findings

  • Sound judgement about risk. You can weigh a real threat against a theoretical one and explain your reasoning clearly

  • The ability to plan and deliver your own work independently once you understand the direction, while knowing when to pull in the senior engineer

  • Clear communication with engineers who aren’t security specialists, since most of your impact lands through their work

Nice to have:

  • Exposure to compliance frameworks like SOC2 or PCI, or genuine appetite to learn them

  • Background in payments, fintech, or another regulated, high-stakes domain

  • Interest in areas like supply chain security, detection engineering, or AI security

You may not like it here

  • It’s remote-first and high autonomy. You’ll get direction, but nobody checks your progress daily. If you need close structure, this will be uncomfortable

  • You’ll move between proactive project work and reactive BAU, and priorities will shift as audits and incidents land. Tolerating that change is part of the role.

✅ A typical interview process

  • An initial intro call with a Talent Partner

  • An interview with the Hiring Manager

  • Challenge Stage - Contextualised to the role

  • A final, values-alignment interview

What’s the culture like at Primer?

We’re building a culture where people can do their best work and be proud of the impact they have. You’ll be working with people who are mission-driven, smart, and reflective, and who are genuinely invested in building exceptional products and delivering success for our merchants.

We work remotely, and have done since day one. We believe that building a successful, profitable company goes beyond proximity. We invest in our relationships through great remote working practices and thoughtfully designed face-to-face time, including workations, our annual company retreat, and co-working space access worldwide.

The work is challenging. Scaleups are a challenge, and building category-defining products is a challenge. But there’s a meaningful difference between a challenge and a struggle. At Primer, the right challenge comes with the right support: strong onboarding, a collaborative environment, and a team that is genuinely invested in your success. It’s never something you face alone.

Our benefits

🌍 We are fully remote and globally distributed; and have been since day one

💰 Competitive share options

🌴 Uncapped holiday, with 25 days minimum to be taken

🗣️ Co-working space access

📅 Workations & Company Retreat

💻 The best equipment for your role

🏠 £500 towards your home office setup

🔎 Generous learning budget

🏥 Private Medical Insurance

📈 A broad set of additional perks and benefits ( depending on location)

Don’t meet every single requirement?

At Primer, we’re dedicated to building a diverse, inclusive, and authentic workplace. If you’re excited about this role but your experience doesn’t align perfectly with every qualification listed, we encourage you to apply. You may be the right candidate for this or other roles.

Primer is committed to the equal treatment of all current and prospective employees and adopts a zero-tolerance approach to discrimination, regardless of age, disability, sex, sexual orientation, pregnancy and maternity, race or ethnicity, religion or belief, gender identity, marriage and civil partnership, or any other background or belief.

Read the full description
Security Staff, Security Engineer at Fullscript

Staff-level security engineer designs and implements security solutions across products, leads technical initiatives, and mentors engineering teams on embedding security in the SDLC.

Lead Posted about 20 hours ago RemoteFirstJobs Product
What this role involves

About Fullscript

We’re an industry-leading health technology company on a mission to help people get better. We started in 2011 with one simple idea. Make it easier for practitioners to access the products they trust so they can deliver better care.

That simple idea grew into a platform that powers every part of care. Today, more than 125,000 practitioners use Fullscript for clinical insights, lab interpretations, patient analytics, education, and access to high-quality supplements. Over 10 million patients rely on Fullscript to stay connected to their care plans and follow through on treatment.

We build tools that make care smarter and more human. Tools that save time, simplify decisions, and help practitioners stay closely connected to the people they care for. When everything they need is in one place, they can focus on what matters most: helping people get better.

This is your invitation.

Bring your ideas, your grit, and your care for people.

Join us and shape the future of care.

The Opportunity

We’re looking for a Staff Security Engineer to join Fullscript’s Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application security, or product security.

You’ll work closely with engineering teams to design and implement security solutions that scale across Fullscript’s products and platforms. As a Staff-level engineer, you’ll own complex technical initiatives, help shape security strategy, and influence how security is built into the software development lifecycle. You’ll be expected to balance hands-on execution with technical leadership, mentoring engineers and helping teams solve security challenges in a way that supports both business objectives and engineering velocity.

We’re looking for someone who has owned systems end-to-end; from application development and infrastructure decisions through security design and implementation; Understands how to build secure, scalable solutions in production environments. The ideal candidate is deeply technical, highly collaborative, and energized by solving difficult problems that span multiple teams, systems, and domains.

What you’ll do

  • Lead the design and implementation of security solutions across Fullscript’s applications, platforms, and AI-powered systems.
  • Partner with engineering teams to embed security throughout the software development lifecycle, including architecture reviews, threat modeling, secure coding practices, and design reviews.
  • Drive application security, product security, and vulnerability management initiatives from concept through implementation.
  • Own complex security challenges that span multiple teams, balancing technical requirements, business priorities, and engineering constraints to deliver scalable solutions.
  • Mentor engineers and security practitioners, raising the bar for secure software development and helping teams make sound security decisions.
  • Influence technical strategy and security standards through hands-on engineering, technical leadership, and cross-functional collaboration.
  • Stay ahead of emerging threats, security technologies, and AI-specific risks to help shape Fullscript’s long-term security posture.

What you bring to the table

  • 8+ years of software engineering experience designing, building, and operating production systems.
  • 3+ years of recent experience in application security, product security, security engineering, or a related security discipline.
  • Deep understanding of secure software development, modern application architectures, APIs, and cloud-native environments.
  • Experience owning complex technical initiatives from problem definition through delivery, including working across multiple teams and stakeholders.
  • Proven ability to influence technical direction, mentor engineers, and drive adoption of security best practices.
  • Strong hands-on experience with security tooling, automation, vulnerability management, and security assessments.
  • Excellent communication skills, strong technical judgment, and a continuous learning mindset.

Bonus if you have

  • Experience securing Ruby on Rails, Node.js, JavaScript, GraphQL, or similar application ecosystems.
  • Experience with AWS cloud security and cloud-native security controls.
  • Experience with threat modeling methodologies such as STRIDE, PASTA, or similar frameworks.
  • Experience with vulnerability management, application security posture management, or developer security tooling.
  • Familiarity with GitHub, GitLab, Wiz, static analysis tools, secret scanning, or related security platforms.
  • Experience conducting penetration testing, security research, or ethical hacking activities.
  • Experience protecting healthcare, regulated, or sensitive customer data.

What we can offer you

  • Remote-first flexibility to work where you work best, with North America (Ottawa, Toronto, or Calgary) preferred for this role.
  • Flexible PTO and competitive pay, because work-life balance matters
  • RRSP/401k match and stock options to invest in your future
  • Premium benefits package with customizable coverage, paramedical services, and an HSA.
  • Fullscript discounts to save on high-quality wellness products
  • Continuous learning opportunities to grow your skills and career

Fullscript shares salary ranges to support transparency and help candidates make informed decisions. The range shown reflects base salary only and does not include stock options, wellness stipends, or other benefits that are part of Fullscript’s total rewards package.

Final compensation depends on experience, skills, and location. We review pay regularly to stay aligned with market data and internal equity. Benefits and total rewards may vary by region.

Why Fullscript

Great work happens when people feel supported, trusted, and inspired. At Fullscript, we stay curious and keep finding smarter ways to make care better. We grow together, take on new challenges, and focus on impact. We put people first, work as a team, and leave egos at the door.

What to Know Before You Apply

We’re grateful for the interest in joining Fullscript. To make sure your application reaches our hiring team, please apply directly through our careers page.

A quick note: Due to the high volume of applications, we’re not able to respond to phone or email inquiries about application status. If there’s a match, our team will reach out directly.

Fullscript is an equal opportunity employer committed to creating an inclusive workplace. Accommodations are available upon request at [email protected].

All offers are contingent on successful background checks conducted in compliance with federal, state, and provincial laws.

We use AI tools to support parts of the hiring process, including screening and reviewing responses. Final hiring decisions are always made by people and follow all applicable privacy and employment laws in Canada and the U.S.

Learn More

www.fullscript.com

@fullscriptHQon instagram

@fullscript on YouTube

FullScripton LinkedIn

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Network and Cybersecurity SME

Provides infrastructure support and cybersecurity expertise for NIH-contracted work, managing network security and IT infrastructure.

Senior Remote Posted about 20 hours ago Jobicy AI
What this role involves
ECS is seeking an experienced Network and Cybersecurity SME to work remotely providing infrastructure support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other tasks...
Read the full description
Security Network and Cybersecurity Delivery Lead

Leads network and cybersecurity infrastructure delivery for government contracts, managing technical implementation and team oversight.

Lead Remote Posted about 20 hours ago Jobicy AI
What this role involves
ECS is seeking an experienced Network and Cybersecurity Delivery Lead to work remotely providing infrastructure support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other...
Read the full description
Security System Administrator (Cyber Infrastructure)

Manages cyber infrastructure systems and provides infrastructure support for government research contracts, ensuring secure and reliable IT operations.

Mid Remote Posted about 20 hours ago Jobicy AI
What this role involves
ECS is seeking an experienced Cyber Infrastructure System Administrator to work remotely providing infrastructure support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other tasks...
Read the full description
Security Computer Security System Specialist

Provides cybersecurity support and manages security systems for a government contract supporting NIH research operations.

Mid Remote Posted about 20 hours ago Jobicy AI
What this role involves
ECS is seeking an experienced Computer Security System Specialist to work remotely providing cybersecurity support for the work performed under this contract for NIH NIAID Enabling and Advancing Technologies (NEAT). All other tasks...
Read the full description
Security Cybersecurity Pentester

Conducts penetration testing and security assessments to identify and remediate vulnerabilities in systems and applications.

Posted about 20 hours ago Himalayas
What this role involves
Powering the world’s payments ecosystemACI powers the payments ecosystem – globally, and you power ACI.
Read the full description
Security Red Team Operator I

Conducts offensive security testing and adversarial simulations to identify vulnerabilities in government and critical infrastructure systems.

Junior Posted about 20 hours ago Himalayas
What this role involves
SIXGEN’s mission is to deliver agile, mission-ready cybersecurity solutions that empower government and critical infrastructure organizations to stay ahead of advanced cyber threats.
Read the full description
Security Sr Security Operations Engineer, Detection and Response

Detects, investigates, and responds to security threats and incidents across the organization's systems and networks.

Senior Posted 1 day ago Jobicy AI
What this role involves
Who we are At Fortis Games we aspire to make great games that bring people together while redefining how game companies work. We believe in building a sense of belonging...
Read the full description
Security Security Analyst 3rd Level

Investigates complex security incidents, performs deep analysis, escalates critical issues, and coordinates communication between customers and internal teams.

Senior Posted 1 day ago Himalayas
What this role involves
deine mission • Komplexe Security Incidents landen bei dir - du gehst in die Tiefe, analysierst sauber und triffst fundierte Entscheidungen • Als Eskalationsinstanz bringst du Ruhe in kritische Situationen und hältst die Kommunikation zwischen Kund:innen und internen Teams klar und strukturiert • In Kundenterminen (z.
Read the full description
Security Senior Cybersecurity Engineer at Mize CPAs Inc.

Senior engineer who owns cybersecurity control domains, deploys and tunes security tools, and mentors junior engineers across identity, network, cloud, and endpoint security.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Work with a Top 20 CPA and advisory firm that Accounts for Anything.  Aprio has 40 U.S. office locations, as well as international office locations and more than 3,200 team members that speak 60+ languages across the globe.  By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.

Join Aprio’s Information Technology team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a Senior Cybersecurity Engineer to join their dynamic team.

Aprio’s Cybersecurity Engineering team builds and operates the controls that make the firm defensible: identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Senior Cybersecurity Engineer is the senior individual contributor on that team — the engineer who takes a control domain from “documented” to “running cleanly in production,” sets the standard for how it’s done, and pulls the Mid and Associate engineers up with them. This is a hands-on engineering role that also leads cross-team initiatives.

This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws.

What You’ll Do:

  • You will own the operational health of one or two engineering domains, lead cross-team initiatives that touch multiple control areas, and design the patterns the rest of the team executes against.
  • You’re the engineer who can take a tool from “purchased” to “deployed, tuned, and instrumented,” the partner Cloud Ops and Identity call when they need a security pattern that actually works, and the senior who makes the Mid and Associate engineers better through pairing, code review, and clear standards.
  • You’ll also be a senior voice in architecture and decision conversations alongside the Principal Engineer and the Manager.

Key Responsibilities:

  • Domain ownership: Own the operational health of one or two engineering domains (identity, network/segmentation, cloud security baselines, monitoring/logging, encryption/key management, endpoint, vulnerability management, configuration management). Keep them measurably healthy and improving.
  • Cross-team initiatives: Lead initiatives that span Security, IT, Identity, Cloud Operations, and delivery teams — controlled rollouts, control set hardening, tool migrations. Land them without breaking production.
  • Architecture and standards: Design new control patterns and reference architectures. Write the decision records, runbooks, and standards the team executes against and the auditors review.
  • Controlled rollouts: Lead the end-to-end deployment of new control sets (e.g., bringing a new EDR online, hardening a new cloud account, standing up new logging pipelines) — pilot, measure, expand, document.
  • Mentorship: Pair with Mid and Associate engineers, run design reviews, give substantive code/config review, and grow the next tier. Quality of output from less senior engineers is part of your scope.
  • Operational partnership: Be the senior partner Cloud Ops, Identity, IT Service Management, GRC, and the SOC call when they need security engineering input. Solve problems with them, not at them.
  • Detection/response engineering support: Partner with Detection Engineering and the SOC on logging coverage, telemetry quality, and the engineering pieces of response (privileged access tooling, isolation capabilities, evidence capture).
  • Evidence and audit readiness: Produce control evidence and architecture documentation that holds up under audit and peer review. Keep your domains’ evidence map current.
  • Automation: Push toward repeatable, codified controls (IaC, policy-as-code, automated evidence collection) instead of one-off manual work.

What Success Looks Like:

First 30–60 days: You can operate your priority domains safely on Aprio’s tooling, you’ve assessed current control posture, and you’ve published a prioritized remediation backlog for at least one domain.

By 90 days: You’re leading at least one cross-team initiative, you’ve published or substantially revised at least one architecture pattern or decision record, and you’re an active mentor to the Mid and Associate engineers.

By 6–12 months: Your domains have measurably improved control health (less drift, cleaner evidence, faster remediation, fewer escalations). At least one controlled rollout has landed cleanly. Less senior engineers on the team are visibly better because of how you work with them.

Required Qualifications:

  • 5+ years in security engineering, with hands-on responsibility for implementing controls across identity, network, cloud, endpoint, and/or monitoring.
  • Strong fundamentals in IAM, network segmentation, encryption / key management, and centralized logging / monitoring.
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in a security-engineering capacity.
  • Ability to produce clear architecture documentation, runbooks, and decision records that hold up under audit and peer review.
  • Excellent written and verbal communication; able to explain tradeoffs across Security, IT, and delivery audiences in plain language.
  • Comfortable mentoring less senior engineers and owning quality-of-output for one or more domains.

Preferred Qualifications

  • Regulated-environment experience (CMMC, NIST 800-171, NIST 800-53, FedRAMP-aligned, SOC 2, ISO 27001, HIPAA, PCI).
  • Infrastructure-as-code experience (Terraform, Bicep, Pulumi) and policy-as-code (Sentinel, OPA).
  • Security tooling integration experience (SIEM, EDR, vulnerability scanning, IAM, secrets management).
  • Industry certifications (one or more): CISSP, CCSP, GIAC (e.g., GCED, GPEN, GCWN), AZ-500, AWS Security Specialty.
  • Experience supporting a SOC’s detection/response engineering needs.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience

$100,000 - $125,000 a year

The salary range for this opportunity is stated above. As such, an actual salary may fall closer to one or the other end of the range, and in certain circumstances, may wind up being outside of the listed salary range.

The application window is anticipated to close on July 27th and may be extended as needed.

Why work for Aprio:

Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.

Perks/Benefits we offer for full-time team members:

- Medical, Dental, and Vision Insurance on the first day of employment

- Flexible Spending Account and Dependent Care Account

- 401k with Profit Sharing

- 9+ holidays and discretionary time off structure

- Parental Leave – coverage for both primary and secondary caregivers

- Tuition Assistance Program and CPA support program with cash incentive upon completion

- Discretionary incentive compensation based on firm, group and individual performance

- Incentive compensation related to origination of new client sales

- Top rated wellness program

- Flexible working environment including remote and hybrid options

What’s in it for you:

- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.

- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience.  We call it the Aprio Way.  This shared mindset creates lasting relationships between team members and with clients.

- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.

- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.

- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.

- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.

EQUAL OPPORTUNITY EMPLOYER

Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.

Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Manager, Security GRC - Compliance Onboarding & Readiness at HubSpot

Leads a GRC team while personally executing control designs, compliance onboarding workflows, and technical security assessments to ensure HubSpot's products are secure by design and audit-ready.

Lead Remote Posted 2 days ago RemoteFirstJobs Product
What this role involves

1086155

Manager, Security GRC - Compliance Onboarding & Readiness

Location: United States - Remote, Flex, or Office

About the Role

HubSpot is seeking a Manager, Security GRC on our Compliance Onboarding & Readiness team. This role is a critical part of how HubSpot approaches trust, security, and governance. Instead of focusing on reactive audit defense, our team acts as a proactive design and engineering partner. We shift compliance engineering “left” to ensure our rapidly expanding product surface, including usage-based billing systems, advanced AI capabilities, and scaling infrastructure, is fundamentally secure by design and audit-ready.

This is a hands-on, “player-coach” role. Reporting directly to the Senior Manager, you will lead and mentor a dedicated team of GRC professionals, while also acting as a high-impact individual contributor (IC). You are someone who loves to get into the weeds: executing proactive control designs, performing technical walkthroughs, mapping controls to complex cloud environments, and directly authoring robust control documentation alongside your team.

You will drive the day-to-day operationalization of our High-Risk Control Testing and Compliance Onboarding charters, moving HubSpot away from point-in-time evidence gathering and toward continuous compliance automated by telemetry.

What You’ll Do

Be an Active Player-Coach & Lead the Team

  • Direct People Management: Lead, develop, and mentor a talented sub-team of GRC professionals. Evolve their capabilities in risk-based judgment and technical engineering partnership.
  • Hands-on Execution (IC Work): Actively lead by example. You will personally conduct high-impact control walkthroughs, draft complex process narratives, design baseline control mappings for new architectures, and directly test our most critical systems.
  • Stabilization & Backlog Burnout: Guide and support the team through its immediate operational maturity phases, and partnering cross-functionally to systematically burn down the legacy issues backlog.

Operationalize the Compliance “Front Door”

  • Shift Compliance Left: Manage and scale our centralized compliance onboarding intake process. Partner early with Product, Engineering, and FinOps during the design and architecture stages (pre-coding) to embed security and compliance controls before production release.
  • Minimize Friction: Maintain predictable, frictionless compliance paths for engineering stakeholders so compliance acts as an operational accelerator rather than a bottleneck.

Drive High-Risk Control Testing & Continuous Assurance

  • Execute Deep-Dive Testing: Personally lead and oversee rigorous internal testing of HubSpot’s highest-risk controls, prioritizing Identity and Access Management (IAM), privileged access, data protection, change management, and AI governance.
  • Continuous Monitoring Telemetry: Partner to design and build automated dashboards, transitioning the team’s evidence collection from manual spreadsheets to continuous data streams.
  • Define Early-Warning Signals: Build out and monitor key control health indicators (OKIs/PKIs) to identify and remediate control degradation long before audit windows open.

Foster Collaborative Partnerships & Seamless Hand-offs

  • Proactive Pre-Audit Alignment: Lead proactive reviews to validate control design, helping system owners address gaps collaboratively before audit cycles begin.
  • Frictionless Partner Handoffs: Partner deeply with our Compliance Audit Execution team to transition ready, thoroughly vetted control packages for external testing, replacing traditional siloed boundaries with smooth, cooperative handoffs.
  • Shared Posture Insights: Actively feed readiness metrics and testing signals into the broader Security Governance and Risk ecosystem to build a unified, transparent view of security health across HubSpot.

What We’re Looking For

Required Experience & Technical Rigor

  • Demonstrated experience in Security GRC, IT Compliance, or IT Audit, ideally within a fast-paced, public SaaS environment.
  • Hands-On Player-Coach Leadership: Experience managing, mentoring, or leading GRC professionals, combined with a strong desire and demonstrated ability to execute as an individual contributor. You must love rolling up your sleeves to build.
  • Deep Control Expertise: Strong understanding of SOX 404 control design, risk-based scoping, testing, and proactive issue management within modern engineering environments (AWS, microservices, CI/CD pipelines).
  • First-Principles Architect Mindset: You look at compliance as a systems-engineering challenge, not a checklist. You have experience implementing controls that are automated, scalable, and lightweight for developers.
  • Exceptional Communication & HubSpot Culture Fit: You are empathetic, remarkably clear, and direct. You can explain complex regulatory “whys” to engineering leaders.

Preferred Experience

  • Familiarity with emerging technology frameworks, specifically AI governance structures (such as ISO 42001) alongside traditional frameworks (SOC 1⁄2, ISO 27001, NIST).
  • Experience supporting product transitions to usage-based billing or microservices-based financial data pipelines.
  • Professional certifications such as CISA, CRISC, CISSP, or equivalent experience.

Why HubSpot

At HubSpot, security is a core value. We believe that to “Grow Better,” we must protect the operational and financial integrity of our platform with airtight, auditor-proof logic—while ensuring our teams can move fast and innovate with confidence. You’ll be joining a highly collaborative, deeply supportive GRC organization that treats governance as a modern product rather than a bureaucratic constraint. If you are inspired to build a secure-by-design compliance ecosystem at scale, we’d love to talk to you!

Pay & Benefits

The cash compensation below includes base salary, on-target commission for employees in eligible roles, and annual bonus targets under HubSpot’s bonus plan for eligible roles. In addition to cash compensation, some roles are eligible to participate in HubSpot’s equity plan to receive restricted stock units (RSUs). Some roles may also be eligible for overtime pay. Individual compensation packages are tailored to your skills, experience, qualifications, and other job-related reasons.

This resource will help guide how we recommend thinking about the range you see. Learn more about HubSpot’s compensation philosophy.

Benefits are also an important piece of your total compensation package. Explore the benefits and perks HubSpot offers to help employees grow better.

At HubSpot, fair compensation practices aren’t just about checking off the box for legal compliance. It’s about living out our value of transparency with our employees, candidates, and community.

Annual Cash Compensation Range:

$146,200—$233,900 USD

We know the confidence gap and impostor syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.

If you need accommodations or assistance due to a disability, please reach out to us using this form.

At HubSpot, we value both flexibility and connection. Whether you’re a Remote employee or work from the Office, we want you to start your journey here by building strong connections with your team and peers. If you are joining our Engineering team, you will be required to attend a regional HubSpot office for in-person onboarding. If you join our broader Product team, you’ll also attend other in-person events, such as your Product Group Summit and other gatherings, to continue building on those connections.

If you require an accommodation due to travel limitations or other reasons, please inform your recruiter during the hiring process. We are committed to supporting candidates who may need alternative arrangements

Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Germany Applicants: (m/f/d) - link to HubSpot’s Career Diversity page here.

India Applicants: link to HubSpot India’s equal opportunity policy here.

About HubSpot

HubSpot (NYSE: HUBS) is an AI-powered customer platform with all the software, integrations, and resources customers need to connect marketing, sales, and service. HubSpot’s connected platform enables businesses to grow faster by focusing on what matters most: customers.

At HubSpot, bold is our baseline. Our employees around the globe move fast, stay customer-obsessed, and win together. Our culture is grounded in four commitments: Solve for the Customer, Be Bold, Learn Fast, Align, Adapt & Go!, and Deliver with HEART. These commitments shape how we work, lead, and grow.

We’re building a company where people can do their best work. We focus on brilliant work, not badge swipes. By combining clarity, ownership, and trust, we create space for big thinking and meaningful progress. And we know that when our employees grow, our customers do too.

Recognized globally for our award-winning culture by Comparably, Glassdoor, Fortune, and more, HubSpot is headquartered in Cambridge, MA, with employees and offices around the world.

Explore more:

  • HubSpot Careers
  • Life at HubSpot on Instagram

HubSpot may use AI to help screen or assess candidates, but all hiring decisions are always human. More information can be found here. By submitting your application, you agree that HubSpot may collect your personal data for recruiting, global organization planning, and related purposes. We may use CLEAR ID Verification during the hiring process to confirm your identity and help maintain a safe, secure, and trusted experience for all candidates. Refer to HubSpot’s Recruiting Privacy Notice for details on data processing and your rights.

Read the full description
Security Cybersecurity Engineer at Mize CPAs Inc.

Builds and operates cybersecurity controls including identity, network segmentation, cloud security, endpoint protection, and vulnerability management for a large CPA firm.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

Work with a Top 20 CPA and advisory firm that Accounts for Anything.  Aprio has 40 U.S. office locations, as well as international office locations and more than 3,200 team members that speak 60+ languages across the globe.  By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.

Join Aprio’s Information Technology team and you will help clients maximize their opportunities.  Aprio is a progressive, fast-growing firm looking for a Cybersecurity Engineer to join their dynamic team.

Aprio’s Cybersecurity Engineering team builds and operates the controls that protect the firm — identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Cybersecurity Engineer is the mid-tier individual contributor on that team: the engineer trusted to take a well-scoped project, run it end-to-end, and deliver a clean, documented, operational result. This role is hands-on and execution-focused, with a growing depth in one or two control domains and a clear path toward Senior Engineer.

This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws.

What You’ll Do

  • You will own small-to-medium engineering projects end-to-end, configure and operate control sets without direct oversight, and partner closely with Senior and Principal engineers on the larger initiatives that cross multiple domains.
  • You’re the engineer who can pick up a control implementation, deliver it, document it, and hand it off cleanly to operations.
  • You’ll start to grow real depth in a domain you care about — identity, endpoint, vulnerability, cloud security, or logging — and you’ll be a working partner to Associate engineers on day-to-day execution.

Key Responsibilities

  • Project ownership: Take small-to-medium engineering projects end-to-end — scoping, design partnership with a Senior, build, test, deploy, document, and hand off to operations. Deliver them on time without surprises.
  • Control implementation and operation: Configure and operate security controls across identity, network, cloud, endpoint, logging/monitoring, encryption/key management, and vulnerability management. Execute against approved patterns and standards.
  • Domain depth: Develop deepening expertise in at least one control domain (e.g., endpoint, identity, vulnerability management, cloud security, IAM, monitoring). Become a real go-to on that domain for the team.
  • Vulnerability and patch operations: Run vulnerability and patch workflows — scan, prioritize, remediate, validate. Track remediation against SLA and close the loop.
  • Change support: Participate in change reviews, assess security impact for in-scope systems, implement approved changes, and validate post-change posture.
  • Evidence and documentation: Produce clean operational documentation — runbooks, change records, evidence artifacts — that holds up under audit and peer review.
  • Detection and response support: Partner with the SOC and Detection Engineering on logging coverage, telemetry quality, and the engineering pieces of response (access tooling, isolation capabilities, evidence capture).
  • Associate mentorship: Pair with Associate engineers on day-to-day execution. Review their tickets, walk them through the toolset, and grow them toward independence.
  • Automation and tooling: Contribute scripts and automation to reduce manual toil (validation checks, evidence collection, repeatable deployments) under the guidance of Senior+ engineers.

What Success Looks Like

First 30–60 days: Tooling and tenant familiarity is complete. You’re executing standard tasks (access requests, configuration changes, vuln workflows, evidence collection) on your own and logging clean work.

By 90 days: You’ve owned at least one small-to-medium project end-to-end — a vulnerability project, a hardening change, a logging coverage gap, or a tool configuration — and the result is documented, evidenced, and handed off cleanly.

By 6–12 months: You’re the go-to on at least one domain, you’re trusted to execute approved patterns without close oversight, Associate engineers are routinely paired with you, and you’re a working partner on at least one cross-team initiative led by a Senior or Principal engineer.

Required Qualifications

  • 3+ years in security engineering, cloud engineering, or security operations with hands-on responsibility for implementing controls.
  • Strong fundamentals in at least one of: identity and access management, network segmentation, vulnerability management, cloud security, endpoint security, centralized logging.
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in an engineering capacity.
  • Comfortable executing vulnerability and patch workflows (scan, prioritize, remediate, validate).
  • Ability to write clear operational documentation — runbooks, evidence artifacts, change records.
  • Strong collaboration skills across Security, IT, and delivery teams.
  • Comfortable mentoring Associate Engineers on day-to-day work

Preferred Qualifications

  • Regulated-environment exposure (CMMC, NIST 800-171, FedRAMP-aligned, SOC 2, ISO 27001).
  • Scripting / automation experience (Python, PowerShell, Bash); infrastructure-as-code familiarity a plus.
  • Security certifications (Security+, SSCP, GSEC, AZ-500, AWS Security Specialty, or cloud/security engineering equivalents).
  • Familiarity with incident-response procedures and evidence handling.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience

$80,000 - $90,000 a year

The salary range for this opportunity is stated above. As such, an actual salary may fall closer to one or the other end of the range, and in certain circumstances, may wind up being outside of the listed salary range.

The application window is anticipated to close on July 27th and may be extended as needed.

Why work for Aprio:

Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.

Perks/Benefits we offer for full-time team members:

- Medical, Dental, and Vision Insurance on the first day of employment

- Flexible Spending Account and Dependent Care Account

- 401k with Profit Sharing

- 9+ holidays and discretionary time off structure

- Parental Leave – coverage for both primary and secondary caregivers

- Tuition Assistance Program and CPA support program with cash incentive upon completion

- Discretionary incentive compensation based on firm, group and individual performance

- Incentive compensation related to origination of new client sales

- Top rated wellness program

- Flexible working environment including remote and hybrid options

What’s in it for you:

- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.

- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience.  We call it the Aprio Way.  This shared mindset creates lasting relationships between team members and with clients.

- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.

- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.

- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.

- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.

EQUAL OPPORTUNITY EMPLOYER

Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.

Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Software Engineer at Avaloq

Develops and maintains application security frameworks, CI/CD pipelines, and vulnerability management tools while consulting teams on security best practices.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

Company Description

Founded and headquartered in Switzerland, Avaloq is continuously expanding its global footprint with around 2,500 colleagues in 10 countries, and more than 160 clients in 35 countries. We are an industry-leading provider of wealth management technology and services for financial institutions around the world, including private banks and wealth managers, investment managers, as well as retail and neo banks. Our research led approach and continual innovation is powered by the passion and creativity of our colleagues.

We are always looking for talented people to join us on our mission to orchestrate the financial ecosystem and democratize access to wealth management. Avaloq offers the opportunity to work closely with some of the world’s leading financial institutions as we jointly develop and shape careers. Championing a collaborative, supportive and flexible work environment empowers our colleagues to reach their full potential.

Job Description

The Avaloq Security team is an international team of analysts, senior and expert software engineers and architects. The Avaloq Security team develops and maintains central application security frameworks and tools for all companywide technology stacks and consults the business teams on best practice implementations for context specific security requirements. It furthermore operates the group-wide application security assessments, monitors the security vulnerabilities and supports the business teams in related risk mitigation plans.

Your key tasks

  • Analyse, design, and develop requirements in collaboration with Product Development, customers, business analysts, and software partners.
  • Design, implement, and maintain internal CI/CD pipelines and automated tools to support vulnerability management, security reporting, and efficient development workflows.
  • Contribute to and collaborate across departments on cross-functional projects.
  • Check and maintain the daily automated build process, analysing security warnings and providing guidance or fixes as required.
  • Monitor third-party library enrolment, updates, and removals using in-house tools and Mend (or similar solutions).
  • Evaluate and validate detected vulnerabilities, assess exploitability, provide expert analysis on false positives, and develop potential fixes.
  • Maintain configuration control and ensure accuracy of the release baseline.
  • Coordinate security-related actions across multiple teams to ensure the high quality and security of Avaloq products.
  • Prepare and distribute documentation and reports related to security risks, findings, and remediation progress.
  • Conduct periodic reviews to verify compliance with internal security policies, guidelines, and best practices.
  • Participate in internal technical discussions, sharing knowledge on security implementation, vulnerabilities, and opportunities for improvement.

Qualifications

  • University degree in IT, Mathematics, Physics, or a related technical discipline.
  • Must have at least 3-5 years of relevant work experience
  • Strong experience in designing, implementing, and maintaining internal CI/CD pipelines and automation tooling.
  • Senior-level engineering expertise with hands-on skills in Python, Java, JavaScript, Gradle, Jenkins (or other CI/CD tools).
  • Knowledge of containerized applications and experience with Kubernetes and/or OpenShift (or similar container orchestration platforms).
  • Deep understanding of security concepts, industry standards, and best practices.
  • Practical experience with vulnerability management tools and automated security scanning solutions.
  • Ability to communicate technical information effectively to non-technical stakeholders.
  • Exposure to financial markets and understanding of financial products is an advantage.
  • Strong analytical capabilities, attention to detail, and commitment to delivering high-quality results.
  • Positive, collaborative mindset with the ability to promote best practices across the organization.

Additional Information

We realize that managing work life balance is a challenge we all face in our daily lives and in order to support with this we are pleased to offer hybrid and flexible working for most of our Avaloqers to maintain work life balance and still continue our fantastic Avaloq culture in our global offices.

In Avaloq we are proud to embrace diversity and understand the success of our business is built on the power of different opinions, we are whole heartedly committed to fostering an equal opportunity environment and inclusive culture where you can be your true authentic self.

We hire, compensate and promote regardless of origin, age, gender identity, sexual orientation or any other fantastic traits that make us all unique, we have done our best to write this advert in an inclusive and neutral way.

Please be aware that we will not accept speculative CV submissions for any of our roles from recruitment agencies, and any unsolicited candidate submissions will be exempt from any payment expectations.

#LI-Hybrid

Read the full description
Security Senior Cybersecurity Engineer at Mize CPAs Inc.

Senior cybersecurity engineer who builds and operates security controls including identity, network segmentation, cloud security, and endpoint management while mentoring junior engineers.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Work with a Top 20 CPA and advisory firm that Accounts for Anything.  Aprio has 40 U.S. office locations, as well as international office locations and more than 3,200 team members that speak 60+ languages across the globe.  By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.

Join Aprio’s Information Technology team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a Senior Cybersecurity Engineer to join their dynamic team.

Aprio’s Cybersecurity Engineering team builds and operates the controls that make the firm defensible: identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Senior Cybersecurity Engineer is the senior individual contributor on that team — the engineer who takes a control domain from “documented” to “running cleanly in production,” sets the standard for how it’s done, and pulls the Mid and Associate engineers up with them. This is a hands-on engineering role that also leads cross-team initiatives.

This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws.

What You’ll Do:

  • You will own the operational health of one or two engineering domains, lead cross-team initiatives that touch multiple control areas, and design the patterns the rest of the team executes against.
  • You’re the engineer who can take a tool from “purchased” to “deployed, tuned, and instrumented,” the partner Cloud Ops and Identity call when they need a security pattern that actually works, and the senior who makes the Mid and Associate engineers better through pairing, code review, and clear standards.
  • You’ll also be a senior voice in architecture and decision conversations alongside the Principal Engineer and the Manager.

Key Responsibilities:

  • Domain ownership: Own the operational health of one or two engineering domains (identity, network/segmentation, cloud security baselines, monitoring/logging, encryption/key management, endpoint, vulnerability management, configuration management). Keep them measurably healthy and improving.
  • Cross-team initiatives: Lead initiatives that span Security, IT, Identity, Cloud Operations, and delivery teams — controlled rollouts, control set hardening, tool migrations. Land them without breaking production.
  • Architecture and standards: Design new control patterns and reference architectures. Write the decision records, runbooks, and standards the team executes against and the auditors review.
  • Controlled rollouts: Lead the end-to-end deployment of new control sets (e.g., bringing a new EDR online, hardening a new cloud account, standing up new logging pipelines) — pilot, measure, expand, document.
  • Mentorship: Pair with Mid and Associate engineers, run design reviews, give substantive code/config review, and grow the next tier. Quality of output from less senior engineers is part of your scope.
  • Operational partnership: Be the senior partner Cloud Ops, Identity, IT Service Management, GRC, and the SOC call when they need security engineering input. Solve problems with them, not at them.
  • Detection/response engineering support: Partner with Detection Engineering and the SOC on logging coverage, telemetry quality, and the engineering pieces of response (privileged access tooling, isolation capabilities, evidence capture).
  • Evidence and audit readiness: Produce control evidence and architecture documentation that holds up under audit and peer review. Keep your domains’ evidence map current.
  • Automation: Push toward repeatable, codified controls (IaC, policy-as-code, automated evidence collection) instead of one-off manual work.

What Success Looks Like:

First 30–60 days: You can operate your priority domains safely on Aprio’s tooling, you’ve assessed current control posture, and you’ve published a prioritized remediation backlog for at least one domain.

By 90 days: You’re leading at least one cross-team initiative, you’ve published or substantially revised at least one architecture pattern or decision record, and you’re an active mentor to the Mid and Associate engineers.

By 6–12 months: Your domains have measurably improved control health (less drift, cleaner evidence, faster remediation, fewer escalations). At least one controlled rollout has landed cleanly. Less senior engineers on the team are visibly better because of how you work with them.

Required Qualifications:

  • 5+ years in security engineering, with hands-on responsibility for implementing controls across identity, network, cloud, endpoint, and/or monitoring.
  • Strong fundamentals in IAM, network segmentation, encryption / key management, and centralized logging / monitoring.
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in a security-engineering capacity.
  • Ability to produce clear architecture documentation, runbooks, and decision records that hold up under audit and peer review.
  • Excellent written and verbal communication; able to explain tradeoffs across Security, IT, and delivery audiences in plain language.
  • Comfortable mentoring less senior engineers and owning quality-of-output for one or more domains.

Preferred Qualifications

  • Regulated-environment experience (CMMC, NIST 800-171, NIST 800-53, FedRAMP-aligned, SOC 2, ISO 27001, HIPAA, PCI).
  • Infrastructure-as-code experience (Terraform, Bicep, Pulumi) and policy-as-code (Sentinel, OPA).
  • Security tooling integration experience (SIEM, EDR, vulnerability scanning, IAM, secrets management).
  • Industry certifications (one or more): CISSP, CCSP, GIAC (e.g., GCED, GPEN, GCWN), AZ-500, AWS Security Specialty.
  • Experience supporting a SOC’s detection/response engineering needs.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience

$100,000 - $125,000 a year

The salary range for this opportunity is stated above. As such, an actual salary may fall closer to one or the other end of the range, and in certain circumstances, may wind up being outside of the listed salary range.

The application window is anticipated to close on July 27th and may be extended as needed.

Why work for Aprio:

Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.

Perks/Benefits we offer for full-time team members:

- Medical, Dental, and Vision Insurance on the first day of employment

- Flexible Spending Account and Dependent Care Account

- 401k with Profit Sharing

- 9+ holidays and discretionary time off structure

- Parental Leave – coverage for both primary and secondary caregivers

- Tuition Assistance Program and CPA support program with cash incentive upon completion

- Discretionary incentive compensation based on firm, group and individual performance

- Incentive compensation related to origination of new client sales

- Top rated wellness program

- Flexible working environment including remote and hybrid options

What’s in it for you:

- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.

- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience.  We call it the Aprio Way.  This shared mindset creates lasting relationships between team members and with clients.

- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.

- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.

- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.

- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.

EQUAL OPPORTUNITY EMPLOYER

Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.

Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Cybersecurity Engineer at Mize CPAs Inc.

Design, build, and operate cybersecurity controls including identity, network, cloud, endpoint, and vulnerability management systems for a large CPA firm.

Mid Posted 2 days ago RemoteFirstJobs Product
What this role involves

Work with a Top 20 CPA and advisory firm that Accounts for Anything.  Aprio has 40 U.S. office locations, as well as international office locations and more than 3,200 team members that speak 60+ languages across the globe.  By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.

Join Aprio’s Information Technology team and you will help clients maximize their opportunities.  Aprio is a progressive, fast-growing firm looking for a Cybersecurity Engineer to join their dynamic team.

Aprio’s Cybersecurity Engineering team builds and operates the controls that protect the firm — identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Cybersecurity Engineer is the mid-tier individual contributor on that team: the engineer trusted to take a well-scoped project, run it end-to-end, and deliver a clean, documented, operational result. This role is hands-on and execution-focused, with a growing depth in one or two control domains and a clear path toward Senior Engineer.

This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws.

What You’ll Do

  • You will own small-to-medium engineering projects end-to-end, configure and operate control sets without direct oversight, and partner closely with Senior and Principal engineers on the larger initiatives that cross multiple domains.
  • You’re the engineer who can pick up a control implementation, deliver it, document it, and hand it off cleanly to operations.
  • You’ll start to grow real depth in a domain you care about — identity, endpoint, vulnerability, cloud security, or logging — and you’ll be a working partner to Associate engineers on day-to-day execution.

Key Responsibilities

  • Project ownership: Take small-to-medium engineering projects end-to-end — scoping, design partnership with a Senior, build, test, deploy, document, and hand off to operations. Deliver them on time without surprises.
  • Control implementation and operation: Configure and operate security controls across identity, network, cloud, endpoint, logging/monitoring, encryption/key management, and vulnerability management. Execute against approved patterns and standards.
  • Domain depth: Develop deepening expertise in at least one control domain (e.g., endpoint, identity, vulnerability management, cloud security, IAM, monitoring). Become a real go-to on that domain for the team.
  • Vulnerability and patch operations: Run vulnerability and patch workflows — scan, prioritize, remediate, validate. Track remediation against SLA and close the loop.
  • Change support: Participate in change reviews, assess security impact for in-scope systems, implement approved changes, and validate post-change posture.
  • Evidence and documentation: Produce clean operational documentation — runbooks, change records, evidence artifacts — that holds up under audit and peer review.
  • Detection and response support: Partner with the SOC and Detection Engineering on logging coverage, telemetry quality, and the engineering pieces of response (access tooling, isolation capabilities, evidence capture).
  • Associate mentorship: Pair with Associate engineers on day-to-day execution. Review their tickets, walk them through the toolset, and grow them toward independence.
  • Automation and tooling: Contribute scripts and automation to reduce manual toil (validation checks, evidence collection, repeatable deployments) under the guidance of Senior+ engineers.

What Success Looks Like

First 30–60 days: Tooling and tenant familiarity is complete. You’re executing standard tasks (access requests, configuration changes, vuln workflows, evidence collection) on your own and logging clean work.

By 90 days: You’ve owned at least one small-to-medium project end-to-end — a vulnerability project, a hardening change, a logging coverage gap, or a tool configuration — and the result is documented, evidenced, and handed off cleanly.

By 6–12 months: You’re the go-to on at least one domain, you’re trusted to execute approved patterns without close oversight, Associate engineers are routinely paired with you, and you’re a working partner on at least one cross-team initiative led by a Senior or Principal engineer.

Required Qualifications

  • 3+ years in security engineering, cloud engineering, or security operations with hands-on responsibility for implementing controls.
  • Strong fundamentals in at least one of: identity and access management, network segmentation, vulnerability management, cloud security, endpoint security, centralized logging.
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in an engineering capacity.
  • Comfortable executing vulnerability and patch workflows (scan, prioritize, remediate, validate).
  • Ability to write clear operational documentation — runbooks, evidence artifacts, change records.
  • Strong collaboration skills across Security, IT, and delivery teams.
  • Comfortable mentoring Associate Engineers on day-to-day work

Preferred Qualifications

  • Regulated-environment exposure (CMMC, NIST 800-171, FedRAMP-aligned, SOC 2, ISO 27001).
  • Scripting / automation experience (Python, PowerShell, Bash); infrastructure-as-code familiarity a plus.
  • Security certifications (Security+, SSCP, GSEC, AZ-500, AWS Security Specialty, or cloud/security engineering equivalents).
  • Familiarity with incident-response procedures and evidence handling.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience

$80,000 - $90,000 a year

The salary range for this opportunity is stated above. As such, an actual salary may fall closer to one or the other end of the range, and in certain circumstances, may wind up being outside of the listed salary range.

The application window is anticipated to close on July 27th and may be extended as needed.

Why work for Aprio:

Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.

Perks/Benefits we offer for full-time team members:

- Medical, Dental, and Vision Insurance on the first day of employment

- Flexible Spending Account and Dependent Care Account

- 401k with Profit Sharing

- 9+ holidays and discretionary time off structure

- Parental Leave – coverage for both primary and secondary caregivers

- Tuition Assistance Program and CPA support program with cash incentive upon completion

- Discretionary incentive compensation based on firm, group and individual performance

- Incentive compensation related to origination of new client sales

- Top rated wellness program

- Flexible working environment including remote and hybrid options

What’s in it for you:

- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.

- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience.  We call it the Aprio Way.  This shared mindset creates lasting relationships between team members and with clients.

- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.

- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.

- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.

- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.

EQUAL OPPORTUNITY EMPLOYER

Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.

Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description
Security Senior Cybersecurity Engineer at Mize CPAs Inc.

Senior Cybersecurity Engineer designs, deploys, and operates security controls including identity, network segmentation, cloud security, and vulnerability management while mentoring junior engineers.

Senior Posted 2 days ago RemoteFirstJobs Product
What this role involves

Work with a Top 20 CPA and advisory firm that Accounts for Anything.  Aprio has 40 U.S. office locations, as well as international office locations and more than 3,200 team members that speak 60+ languages across the globe.  By bringing together proven expertise, deep understanding, and strategic foresight for fast-growing industries, Aprio ensures clients are prepared for wherever life or business may take them. Discover a top-rated culture, vast growth opportunities and your next big career move with Aprio.

Join Aprio’s Information Technology team and you will help clients maximize their opportunities. Aprio is a progressive, fast-growing firm looking for a Senior Cybersecurity Engineer to join their dynamic team.

Aprio’s Cybersecurity Engineering team builds and operates the controls that make the firm defensible: identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Senior Cybersecurity Engineer is the senior individual contributor on that team — the engineer who takes a control domain from “documented” to “running cleanly in production,” sets the standard for how it’s done, and pulls the Mid and Associate engineers up with them. This is a hands-on engineering role that also leads cross-team initiatives.

This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws.

What You’ll Do:

  • You will own the operational health of one or two engineering domains, lead cross-team initiatives that touch multiple control areas, and design the patterns the rest of the team executes against.
  • You’re the engineer who can take a tool from “purchased” to “deployed, tuned, and instrumented,” the partner Cloud Ops and Identity call when they need a security pattern that actually works, and the senior who makes the Mid and Associate engineers better through pairing, code review, and clear standards.
  • You’ll also be a senior voice in architecture and decision conversations alongside the Principal Engineer and the Manager.

Key Responsibilities:

  • Domain ownership: Own the operational health of one or two engineering domains (identity, network/segmentation, cloud security baselines, monitoring/logging, encryption/key management, endpoint, vulnerability management, configuration management). Keep them measurably healthy and improving.
  • Cross-team initiatives: Lead initiatives that span Security, IT, Identity, Cloud Operations, and delivery teams — controlled rollouts, control set hardening, tool migrations. Land them without breaking production.
  • Architecture and standards: Design new control patterns and reference architectures. Write the decision records, runbooks, and standards the team executes against and the auditors review.
  • Controlled rollouts: Lead the end-to-end deployment of new control sets (e.g., bringing a new EDR online, hardening a new cloud account, standing up new logging pipelines) — pilot, measure, expand, document.
  • Mentorship: Pair with Mid and Associate engineers, run design reviews, give substantive code/config review, and grow the next tier. Quality of output from less senior engineers is part of your scope.
  • Operational partnership: Be the senior partner Cloud Ops, Identity, IT Service Management, GRC, and the SOC call when they need security engineering input. Solve problems with them, not at them.
  • Detection/response engineering support: Partner with Detection Engineering and the SOC on logging coverage, telemetry quality, and the engineering pieces of response (privileged access tooling, isolation capabilities, evidence capture).
  • Evidence and audit readiness: Produce control evidence and architecture documentation that holds up under audit and peer review. Keep your domains’ evidence map current.
  • Automation: Push toward repeatable, codified controls (IaC, policy-as-code, automated evidence collection) instead of one-off manual work.

What Success Looks Like:

First 30–60 days: You can operate your priority domains safely on Aprio’s tooling, you’ve assessed current control posture, and you’ve published a prioritized remediation backlog for at least one domain.

By 90 days: You’re leading at least one cross-team initiative, you’ve published or substantially revised at least one architecture pattern or decision record, and you’re an active mentor to the Mid and Associate engineers.

By 6–12 months: Your domains have measurably improved control health (less drift, cleaner evidence, faster remediation, fewer escalations). At least one controlled rollout has landed cleanly. Less senior engineers on the team are visibly better because of how you work with them.

Required Qualifications:

  • 5+ years in security engineering, with hands-on responsibility for implementing controls across identity, network, cloud, endpoint, and/or monitoring.
  • Strong fundamentals in IAM, network segmentation, encryption / key management, and centralized logging / monitoring.
  • Experience with at least one major cloud platform (Azure, AWS, GCP) in a security-engineering capacity.
  • Ability to produce clear architecture documentation, runbooks, and decision records that hold up under audit and peer review.
  • Excellent written and verbal communication; able to explain tradeoffs across Security, IT, and delivery audiences in plain language.
  • Comfortable mentoring less senior engineers and owning quality-of-output for one or more domains.

Preferred Qualifications

  • Regulated-environment experience (CMMC, NIST 800-171, NIST 800-53, FedRAMP-aligned, SOC 2, ISO 27001, HIPAA, PCI).
  • Infrastructure-as-code experience (Terraform, Bicep, Pulumi) and policy-as-code (Sentinel, OPA).
  • Security tooling integration experience (SIEM, EDR, vulnerability scanning, IAM, secrets management).
  • Industry certifications (one or more): CISSP, CCSP, GIAC (e.g., GCED, GPEN, GCWN), AZ-500, AWS Security Specialty.
  • Experience supporting a SOC’s detection/response engineering needs.
  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience

$100,000 - $125,000 a year

The salary range for this opportunity is stated above. As such, an actual salary may fall closer to one or the other end of the range, and in certain circumstances, may wind up being outside of the listed salary range.

The application window is anticipated to close on July 27th and may be extended as needed.

Why work for Aprio:

Whether you are just starting out, looking to advance into management or searching for your next leadership role, Aprio offers an opportunity to grow with a future-focused, innovative firm.

Perks/Benefits we offer for full-time team members:

- Medical, Dental, and Vision Insurance on the first day of employment

- Flexible Spending Account and Dependent Care Account

- 401k with Profit Sharing

- 9+ holidays and discretionary time off structure

- Parental Leave – coverage for both primary and secondary caregivers

- Tuition Assistance Program and CPA support program with cash incentive upon completion

- Discretionary incentive compensation based on firm, group and individual performance

- Incentive compensation related to origination of new client sales

- Top rated wellness program

- Flexible working environment including remote and hybrid options

What’s in it for you:

- Working with an industry leader: Be part of a high-growth firm that is passionate for what’s next.

- An awesome culture: Thirty-one fundamental behaviors guide our culture every day ensuring we always deliver an exceptional team-member and client experience.  We call it the Aprio Way.  This shared mindset creates lasting relationships between team members and with clients.

- A great team: Work with a high-energy, passionate, caring and ambitious team of professionals in a collaborative culture.

- Entrepreneurship: Have the freedom to innovate and bring your ideas to help us grow to become the CPA firm of choice nationally.

- Growth opportunities: Grow professionally in an environment that fosters continuous learning and advancement.

- Competitive compensation: You will be rewarded with competitive compensation, industry-leading benefits and a flexible work environment to enjoy work/life balance.

EQUAL OPPORTUNITY EMPLOYER

Aprio is an Equal Opportunity Employer encouraging diversity in the workplace. All qualified applicants will receive consideration for employment without regard to race; color; religion; national origin; sex; pregnancy; sexual orientation; gender identity and/or expression; age; disability; genetic information, citizenship status; military service obligations or any other category protected by applicable federal, state, or local law.

Aprio, LLP and Aprio Advisory Group, LLC, operate in an alternative business structure, with Aprio Advisory Group, LLC providing non-attest tax and consulting services, and Aprio, LLP providing CPA firm services.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Read the full description