Source Job

US Unlimited PTO 18w maternity 12w paternity

  • Build the Git/GitHub backbone for our controls, assets, and risk scenarios.
  • Stand up a trust data lake (likely in Google BigQuery) and the pipelines that feed it.
  • Automate control evidence collection and other “governance as code” workflows.

Git GitHub Python SQL BigQuery

20 jobs similar to Security Engineer, Governance and Trust

Jobs ranked by similarity.

$101,405–$140,400/yr
US Unlimited PTO

  • Analyze security vulnerabilities and drive remediations.
  • Integrate security at every stage of the SDLC.
  • Deploy and manage security tooling.

Modern Health is a mental health benefits platform for employers, offering access to various resources for emotional, professional, social, financial, and physical well-being. They are the fastest entirely female-founded company in the U.S. to reach Unicorn status, with a unique culture centered around high empathy and accountability.

Europe Unlimited PTO 13w maternity 9w paternity

  • Collaborate with cross-functional teams to translate product requirements into technical solutions.
  • Develop and maintain core services for Chainguard.
  • Practice continuous improvement by iterating on how services are deployed, configured, monitored, and maintained on our platform.

Chainguard provides a secure foundation for software development and deployment by offering guarded open source software that is built from source and continuously updated. Founded by industry experts, they aim to be the safe source for open source and have built the largest library of open source software that is secure by default.

$62,594–$84,769/yr
Europe 5w PTO 6w maternity

  • Own security issue intake and coordination by triaging reports and coordinating fixes with maintainers.
  • Drive timely remediation by tracking SLAs, communicating status, and coordinating releases and backports when required.
  • Harden our CI/CD and release workflows by improving build pipeline security, secrets management, artifact integrity, and access controls.

The Open Home Foundation is a non-profit organization based in Switzerland, fighting for privacy, choice, and sustainability in smart homes by supporting open-source projects and open standards. They focus on open-source projects like Home Assistant and collaborate with others to promote privacy, choice, and sustainability.

US

  • Assist in designing and maintaining secure infrastructure on EKS in our multi-cloud environment (AWS) using Infrastructure as Code (Terraform).
  • Write code (Python, Go, or Bash) to automate manual tasks, threat detection, and vulnerability management processes.
  • Integrate security tools (SAST, DAST, SCA) into our CI/CD pipelines, ensuring developers receive fast, actionable feedback on their code.

Smartsheet helps people and teams achieve anything with seamless work management and scalable solutions. They empower teams to automate the manual, uncover insights, and scale smarter, creating space for impactful work. The company values diverse perspectives and supports employee growth.

Mexico

  • Focused on Python-driven automation, building systems integrations between HRIS, Identity Provider, SaaS, and Finance Platform.
  • Transforming operational data into actionable insights and dashboards.
  • You’ll own high-impact projects end-to-end, mentor teammates, and raise the bar on reliability, security, and employee experience.

EarnIn is building products that deliver real-time financial flexibility for those with the unique needs of living paycheck to paycheck. They are growing fast and are excited to continue bringing world-class talent onboard to help shape the next chapter of their growth journey.

Remote

Minimal
US Canada 3w PTO

  • Comfort with ambiguity, able to take loosely defined problems and figure out what needs to happen.
  • A dynamic team player who seeks to make valuable contributions wherever it is most-needed.
  • Follows through, communicates proactively, and cares about the outcome.

Minimal is building a secure, reproducible foundation for software that makes building, maintaining, and releasing software predictable and effortless. They are carefully growing their team with people that are excited about building a workflow that feels lightyears ahead of everything else.

US

  • Design, build, and maintain scalable and secure CI/CD pipelines in GitLab.
  • Implement and manage GitOps workflows for continuous delivery to RKE2 clusters using ArgoCD.
  • Develop and maintain automation scripts and tools to streamline the software development lifecycle.

DecisionPoint delivers technology solutions and services. They focus on supporting federal government clients with IT modernization and digital transformation initiatives. They are an Equal Employment Opportunity and Affirmative Action employer.

$125,000–$175,000/yr
US

  • Lead architecture interviews with stakeholders.
  • Develop architecture briefing documents.
  • Support Continuous Monitoring activities.

Smartsheet helps people and teams achieve their goals with work management and scalable solutions. They empower teams to automate tasks, uncover insights, and scale smarter, with a focus on creating space for innovation and meaningful work.

Global

  • Manage and optimize GitHub Enterprise environments.
  • Design, implement, and maintain GitHub Actions CI/CD pipelines.
  • Enable and manage GitHub Advanced Security.

Beyondsoft is a mid-sized business IT and consulting company. They combine modern technologies and methodologies to tailor solutions. They have a diversely talented team that thrives on innovation and pushing the bounds of technology.

$164,000–$289,000/yr
US Canada

  • Harden login and registration flows using risk-based controls.
  • Partner closely with Security and Engineering teams to identify and remediate abuse.
  • Develop internal Trust & Safety tooling that centralizes risk signals.

Webflow is building the world’s leading AI-native Digital Experience Platform as a remote-first company. They empower teams to design, launch, and optimize for the web without barriers, believing the future of the web, and work, is more open, more creative, and more equitable.

$30–$36/hr
US Unlimited PTO

  • Learn about our users, systems, and security posture, and how security enables our product and business goals.
  • Support security assessments of code and infrastructure changes with guidance from Security Engineers, helping ensure alignment with SOC 2, PCI-DSS, and internal policies.
  • Assist with automating recurring security and compliance activities such as vulnerability scanning, risk assessments, third-party risk reviews, and control validation.

ezCater is the leading food for work technology company in the US, connecting anyone who needs food for their workplace to over 100,000 restaurants nationwide. They provide flexible and scalable solutions and are backed by top investors.

US

  • Serve as a primary architect of our CI/CD vision, ensuring delivery speed and compliance posture accelerate together as Aledade scales.
  • Lead the evolution of a "Universal Pipeline" by building automation and guardrails to ensure every deployment is HIPAA-compliant by default.
  • Foster a high-velocity engineering culture where security, compliance, and audit evidence are seamless side-effects of a delivery lifecycle.

Aledade partners with independent practices, health centers, and clinics to build and lead Accountable Care Organizations (ACOs) anchored in primary care. I don't have enough information to comment on the company size or culture.

US Unlimited PTO

  • Deliver GitLab Professional Services engagements, including installation, migration, training, and advisory services across GitLab capabilities.
  • Lead migrations from multiple source systems to GitLab SaaS or self-managed GitLab, helping customers adopt secure, reliable workflows.
  • Serve as a trusted technical advisor for customers, translating goals and constraints into practical implementation plans and clear next steps.

GitLab is the intelligent orchestration platform for DevSecOps. They enable organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. The company has more than 50 million registered users and a high-performance culture.

$140,000–$150,000/yr
US Global

  • Partner with engineering teams to conduct threat modeling.
  • Build and maintain automated scanning, penetration testing frameworks, and monitoring tools within our AWS CI/CD pipelines.
  • Champion a "security-first" mindset and host workshops that empower developers to write secure code.

Panopto is a customer-centric learning technology company and the leader in visual and audio-based learning. They empower organizations to share knowledge effortlessly. Panopto has been adopted by more than 1,600 companies and universities worldwide with over 11 million end users.

  • Shaping the Python language ecosystem with a strong product and platform mindset.
  • Architecting, building and delivering high-impact solutions that uplift the Python developer experience.
  • Developing internal observability tooling and metrics that give the team actionable insights.

Canva is a design platform that enables users to create a variety of visual content. They have campuses in Sydney and Melbourne and co-working spaces in Brisbane, Perth and Adelaide; they value work-life balance by providing their teams with the choice in where and how they work.

Europe

  • Participate in the monitoring, maintenance, and evolution of the system infrastructure supporting the TuoTempo web application.
  • Design, create, and support system distribution; test and monitor application code.
  • Support our internal development teams in the effective use of our organizational systems.

TuoTempo, part of the Docplanner group, develops a CRM solution for hospitals, medical centers, and health insurance providers, managing the patient journey and centralizing communications. They operate in Italy, Spain, Mexico, Colombia, Brazil, and Chile, aiming to revolutionize healthcare interactions and improve efficiency.

US

  • Design, build, and maintain our build and deployment systems across a multi-repo, multi-language codebase.
  • Add efficiency, robustness, and security to our release processes by standing up automated tools or processes as necessary.
  • Integrate security and compliance workflows, including tools like Grype and SBOM generation for ATO/IATT processes.

TurbineOne is a fast-moving and high-performance startup with a mission to strengthen situational awareness for all Americans serving at our nation’s frontlines. They are backed by DefenseTech venture capitalists and their Frontline Perception System is an edge-first software platform.

$106,500–$202,500/yr
US

  • Implementing and maintaining Application Security Testing (AST) tools to identify code and dependency vulnerabilities during the software development lifecycle.
  • Implementing and maintaining Application Security Posture Management (ASPM) tools to centralize findings from multiple solutions and integrate into software development processes.
  • Acting as the first line of support for users by helping resolve false positives, providing guidance on finding remediation, and evaluating security exception requests.

AbbVie discovers and delivers innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. They strive to have a remarkable impact on people's lives across several key therapeutic areas and products and services in their Allergan Aesthetics portfolio.

$84,481–$105,775/yr
Europe

  • Understand, reproduce and resolve complicated technical issues that our customers have raised.
  • Own each customer question from initial creation to resolution.
  • Manage support tickets to ensure issues are recorded, tracked, resolved, and follow-ups are done in a timely manner.

Semgrep empowers invention without friction by providing code security for builders. They are backed by Menlo Ventures, Felicis Ventures, Lightspeed Venture Partners, Redpoint Ventures, and Sequoia Capital and recognized by Gartner in Application Security Testing.

Canada

  • Help scale NerdWallet’s application security program through automation, tooling, and developer enablement.
  • Partner with engineering and product teams to identify and remediate security gaps across multiple systems while balancing business priorities.
  • Build tools, processes, and automation that improve security posture visibility for engineers and leadership.

NerdWallet aims to bring clarity to life's financial decisions with a team of exceptional Nerds. They foster an inclusive, flexible, and candid culture where employees are empowered to grow and take risks, supporting well-being and development whether working remotely or in-office.