Jobiba hiring network

Senior Security Risk Management Framework Engineer Jobs

7,292 active opportunities · Updated for October 2026

Fresh results

15 shown

Explore current senior security risk management framework engineer jobs. Use filters to narrow by work mode, employment type, experience and date posted.

L
LTS
📍 United States - Remote• Remote
10 days ago

Location: Remote (U.S.) Clearance: U.S. Citizen or Permanent Resident Required with the ability to obtain a Public Trust Salary Range: 110K – 125K LTS is seeking a Senior Security RMF Engineer to join a cybersecurity transformation surge team supporting the VA.gov Platform. This role will serve as the bridge between VA security/RMF requirements and the engineers responsible for implementing those requirements across VA.gov. The Senior Security / RMF Engineer must understand how security controls are implemented in modern cloud infrastructure and software delivery environments and be able to translate control deficiencies, authorization requirements, and security risks into actionable engineering work.This is not intended to be a documentation-only compliance role. This individual will work closely with DevSecOps engineers and the existing VA.gov Platform ATO/security team to assess the current security posture, address gaps in VA.gov's Critical Controls, support ATO/cATO readiness, improve authorization artifacts, and automate evidence and control assessment wherever possible. The PWS specifically describes the desired model as one in which ATO/RMF documentation confirms security rather than defines it, with success measured through risk reduction and security outcomes rather than paperwork completeness. What You’ll Do: Assess VA.gov Platform compliance with the 18 Critical Controls identified by VA and help establish a baseline of current implementation and remaining gaps. Perform security reviews, gap analyses, and risk assessments across VA.gov Platform infrastructure, pipelines, applications, and component systems. Support ongoing ATO and cATO readiness for the VA.gov Platform authorization boundary. Develop, update, and maintain RMF and authorization artifacts, including System Security Plans (SSPs), control narratives, POA&Ms, Business Impact Analyses (BIAs), Privacy Threshold Analyses (PTAs), and supporting evidence. Evaluate identified

REMOTEawskubernetes
View job →
A
Asana
📍 San Francisco• Full-time• From $194K/yr
1mo ago

At Asana, security is foundational to our mission of helping teams work together effortlessly. Our security team protects Asana's employees, users, and customers by proactively addressing threats, ensuring compliance, and fostering a culture of security throughout our product and operations. As the Security Risk Manager, you will own Asana's internal security risk management program end-to-end. This is a senior role for someone who goes beyond frameworks and checklists — you will engineer the quantitative and automated foundations that let Asana continuously measure and make confident decisions about security risk. You'll build the systems and processes that make risk scalable, not just the policies that describe it, and serve as a trusted advisor to senior leadership. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements What you'll achieve Own Asana's security risk management program: Design and continuously mature a quantitative risk framework — including risk scoring methodologies, likelihood and impact modeling, and risk appetite thresholds — that enables consistent, data-driven risk decisions across the organization. Build and maintain a living risk register: Own Asana's central security risk register, developing KRIs, tracking trends over time, and driving accountability for risk treatment and remediation with business and technical owners. Automate risk identification and monitoring: Design and implement automated data pipelines and integrations that continuously surface security risks — pulling signals from vulnerability scanners, cloud security tooling, SIEMs, and third-party risk sources — so Asana's

restaigo
View job →
P
7 days ago

ABOUT THE ROLE Peloton is seeking an experienced, collaborative leader to join the Legal team as Legal Director, Privacy. This role will be responsible for implementing, managing, and evolving Peloton's global privacy program, playing a pivotal role in our mission to be the most trusted brand in connected fitness. As a senior leader on our Legal team, you will act as a primary privacy advisor to the business. You will partner closely with leaders across Information Security, Data Analytics, Product, Engineering, Marketing, and other business units to ensure that our commitment to Member trust is embedded in every product we build and every interaction we have. This role requires a strategic thinker with deep subject matter expertise who can translate complex global regulations into a practical, scalable, and business-enabling privacy framework. YOUR DAILY IMPACT AT PELOTON Lead and refine Peloton's global privacy program, including our policies, procedures, and data governance standards, to ensure compliance with international law Partner closely with cross-functional teams to embed privacy by design in our core processes for collecting, maintaining, using and sharing personal data Develop and manage our privacy risk management framework, including conducting Data Protection Impact Assessments (DPIAs), managing data subject rights requests, and overseeing privacy incident responses Serve as the subject matter expert on global privacy, cybersecurity, and data protection laws. Advise the business on the impact of evolving regulations and continually refine Peloton’s privacy program to reflect best practices Develop and deliver engaging privacy training and awareness programs to educate Peloton employees and key stakeholders on their data protection responsibilities Serve as the primary legal point of contact for data protection authorities. Prepare and present regular reports on the privacy program's status and risk posture to leadership YOU BRING TO PELOT

airecruitment
View job →
O
Okta
📍 San Francisco• Full-time• From $264K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. Position Overview: We are seeking a visionary Senior Director, Governance, Risk and Compliance (GRC) to lead and scale our world-class GRC Security organization. We don't view Governance, Risk, and Compliance (GRC) as a passive reporting function or an administrative checklist—we build engineering-forward, automated, and AI-driven GRC programs capable of operating in an evolving AI world. Reporting directly to Security Executive leadership, you will operate as a partner to the Senior Executives across Okta’s workforce, taking direct responsibility for cyber risk, data governance, security compliance and product certifications to enable Okta to ship world class, secure products. You will blend deep domain expertise across enterprise cyber risk, audit, and global compliance with a forward-thinking engineering mindset—pioneering continuous control monitoring, compliance-as-code, and robust AI governance for generative and agentic architectures. This is not just a leadership role. This is a builder’s role. Key Responsibilities: Drive AI-first Transformation: Execute a vision to integrate AI and agentic tools into daily GRC operations (automated evidence collection, automated risk scoring, intelligent policy mapping, and continuous audit readiness). Enterprise Risk & Governance: Operationalize Okta’s AI risk and governance framework—addressing training data protection, model risk management, responsible AI principles, and alignment with emerging

awsrestmachine learning
View job →

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. Senior Backend Engineer - Database Change Management An overview of this role As a Senior Backend Engineer, Database Upgrades, you'll help replace GitLab's sequential database migration system with a dependency graph model that makes upgrades faster and safer for GitLab.com and self-managed customers. You'll lead the design and delivery of a migration validation and test framework, including versioned fixture data across about 1,000 tables, a continuous integration (CI)-integrated test runner, and required correctness checks. You'll also serve as the senior technical anchor for our India-based engineering group, using clear writt

sqlpostgresqlgit
View job →
R
Reolink
📍 Singapore• Full-time
15 days ago

Reolink , a leader in intelligent visual technology for homes and businesses, was founded in 2009 by a group of engineers with a strong commitment to and passion for smarter security solutions. Our products are now trusted by millions of users across more than 110 countries and regions worldwide. Building on this trust, we continue expanding our presence and bringing our innovations to more markets around the globe. Reolink remains committed to delivering advanced, reliable, and user‑centric solutions that empower people to protect what matters most. Responsibilities:​ Global Compliance and Strategic Management:​ Develop, lead, and oversee the company’s global legal compliance strategies and framework to ensure all operations across regions fully comply with local laws, regulations, and international standards. Legal System Development and Contract Management:​ Establish, refine, and optimize the company’s global contract management system and standardized legal documents; lead or review major, complex commercial contracts, agreements, and investment-related legal documents; build a comprehensive global legal risk prevention and management system. Dispute Resolution and Business Support:​ Represent the company in handling significant and complex litigation, arbitration, and other legal disputes; provide on-site legal leadership and support in key business negotiations, M&A, financing, and other strategic matters to safeguard the company’s core interests. Legal Advisory and Risk Control:​ Provide authoritative and forward-looking legal advice and solutions to senior management and various business departments; identify, assess, and alert legal and compliance risks in global business operations. Team Leadership and External Resource Management:​ Lead and manage the global legal team (including legal professionals in Singapore and overseas locations); efficiently manage and coordinate external lawyers and legal advisors to ensure quality and cost-effectiveness in h

awsrestai
View job →
O
Okta
📍 Bellevue• From $189K/yr
1mo ago

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role As Senior Product Manager, Policies, you own product strategy and execution for Okta's authentication policy roadmap. The Policies team owns how Okta evaluates risk and context to decide when, how, and whether a user, machine, or agentic identity is allowed to authenticate and stay authenticated. This includes Application Sign-On Policy, Global Session Policy, Okta Account Management Policy (OAMP), and Device Signal Collection Policy as well as the underlying Policy Framework, Policy API, and Auth Pipeline that power them. Policies is foundational to the entire Okta product portfolio as it's the decision layer that sits between every authentication event and the security experience a customer wants for their end users. You'll work closely with engineering, design, other product teams, and cross-functional stakeholders across Okta's platform to ensure policy capabilities evolve strategically, including how policy changes are rolled out and managed at scale (change management / identity operations). What You'll Do Own roadmap and prioritization for your product area, balancing customer requests, platform needs, and market/strategic differentiation Collaborate with design and engineering to define, scope, and ship policies that have best-in-class user experience while meeting the security needs of Okta customers Drive product direction for the Policy Framework, Policy API, and Auth Pipeline that underpin every policy evaluation acros

machine learningartificial intelligenceai
View job →

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day. Smartsheet's customers in Europe, the Middle East, and Africa expect our Customer Trust team to understand their compliance challenges, speak their language, and respond quickly to security assessments. We're looking for a Sr. Security Engineer I to lead Customer Trust operations across EMEA—responding to security questionnaires, managing vendor risk assessments, and building trusted relationships with enterprise customers in these regions. You will be responsible for questionnaire triage, completion, and queue management for EMEA customers. You'll work closely with EMEA sales teams, understand regional compliance requirements (GDPR, EU data protection, sector-specific frameworks), and ensure Smartsheet maintains a strong reputation for responsiveness and technical credibility in these high-value markets. You will work remotely from the UK and report to our Sr. Director, GRC Engineering, based in the US You Have 5+ years of experience in customer trust, vendor risk management, security assessment, or customer-facing security roles at SaaS or cloud platform companies. Proven experience completing and responding to customer security questionnaires, vendor assessments, and RFIs. Strong understanding of GDPR, EU data protection, and regional compliance requirements: Familiarity with data residency, data processing agreements, DPIAs, and how cloud services operate within EU regulatory frameworks. Knowledge of GRC frameworks: Working knowledge of SOC 2, ISO 27001, and compliance standards commonly referenced in EMEA asse

REMOTEawsaigo
View job →
A
Asana
📍 San Francisco• Full-time• $202K – $230K/yr
1mo ago

We are dedicated to ensuring proactive elimination of entire classes of security risk by engineering the core libraries, platforms and frameworks that provide secure guardrails for all Asanas. We are looking for a Senior Software Engineer to join our new Security Development team. This team is focused on building durable, secure-by-default solutions to protect Asana's infrastructure and product. Instead of acting as gatekeepers, we build guardrails that empower engineering teams to move quickly and safely. You will be responsible for engineering preventative controls at scale, focusing on building platforms and frameworks that eradicate systemic risks. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements. What you’ll achieve: Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities. Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems. Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently. Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure. Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents) Influence engineering initiatives through design reviews, communicating security principles, and helping teams make sound security trad

awsrestai
View job →
A
Asana
📍 San Francisco• Full-time• $202K – $230K/yr
1mo ago

We are dedicated to ensuring proactive elimination of entire classes of security risk by engineering the core libraries, platforms and frameworks that provide secure guardrails for all Asanas. We are looking for a Senior Software Engineer to join our new Security Development team. This team is focused on building durable, secure-by-default solutions to protect Asana's infrastructure and product. Instead of acting as gatekeepers, we build guardrails that empower engineering teams to move quickly and safely. You will be responsible for engineering preventative controls at scale, focusing on building platforms and frameworks that eradicate systemic risks. This role is based in our San Francisco office with an office-centric hybrid schedule. The standard in-office days are Monday, Tuesday, and Thursday. Most Asanas have the option to work from home on Wednesdays. Working from home on Fridays depends on the type of work you do and the teams with which you partner. If you're interviewing for this role, your recruiter will share more about the in-office requirements. What you’ll achieve: Design, build, and maintain secure-by-default frameworks, libraries, and platforms to eliminate entire classes of vulnerabilities. Engineer and improve core security services, including our access control frameworks, secrets management infrastructure, and AWS permissions systems. Develop and own the platform for vulnerability remediation, creating tooling that empowers engineering teams to address risks efficiently. Partner with product and infrastructure teams to architect and implement foundational security controls for Asana including cloud networking, and compute infrastructure. Partner with product teams to effectively offer recommendations for how to secure projects at all phases of implementation (design, development, launch, and/or incidents) Influence engineering initiatives through design reviews, communicating security principles, and helping teams make sound security trad

awsrestai
View job →
C
Clearwater
📍 India• Full-time• $30K – $35K/yr
15 days ago

SPECIFIC JOB RESPONSIBILITIES Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP). Multi-Tenancy & MSSP Architecture: Architect a scalable, multi-tenant environment that ensures strict data isolation between clients while allowing for unified " ClickOps " and Terraform-driven automation. AI & Innovation: Explore and implement Now Assist (GenAI) and AI-heavy workflows to automate security reporting and incident summarization. Defensive Operations (SecOps): Design and automate the Security Incident Response (SIR) and Vulnerability Response (VR) lifecycles. Build playbooks in Flow Designer to automate threat containment and remediation. Offensive Operations: Develop custom scoped applications to track penetration testing results, manage red-team engagement lifecycles, and automate the ingestion of reconnaissance data. Compliance & GRC: Configure and customize Integrated Risk Management (IRM) modules to map technical controls to frameworks like SOC2, ISO 27001, HIPAA, and FedRAMP. Integrations & Orchestration: Build robust, secure integrations (REST/SOAP, IntegrationHub , MID Servers) with our XDR, SIEM (Splunk/Sentinel), and cloud-native services (AWS/Azure/GCP)

awsazuregcp
View job →
R
1mo ago

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te

javascripttypescriptpython
View job →
CH
Cohere Health
📍 Hyderabad• Full-time
15 days ago

Opportunity Overview: We are seeking a Senior Data Engineer to contribute to the design and delivery of our cloud-native healthcare data platform. You will implement scalable data solutions built on AWS, Apache Iceberg, Lake Formation, Glue Catalog, Athena, dbt, and modern orchestration frameworks. This role combines strong hands-on engineering with collaboration across platform, analytics, and business teams. What You'll Do Data Engineering Delivery Deliver complex data engineering projects in collaboration with cross-functional teams Drive technical execution from design through production deployment Implement scalable data patterns and reusable frameworks Design and implement batch and near-real-time pipelines Build reusable ingestion, transformation, validation, and publishing frameworks Support modernization of legacy workloads Contribute to Apache Iceberg implementation and optimization Apply standards for schema evolution, partitioning, compaction, and metadata management Ensure efficient storage and query performance Implement data quality frameworks and validation layers Support observability and monitoring practices Contribute to operational excellence and reliability improvements Participate in architecture and design discussions Conduct and participate in code reviews Mentor junior engineers and share best practices ISMS roles and responsibilities Good knowledge of Information security Oversee specific business processes within the ISMS. Responsible to manage the ISMS documentation, conduct risk assessments, and implement risk treatment plans. Risk Owners are responsible for identifying, assessing, and managing risks within their areas of responsibility. They are also responsible for implementing risk treatment plans. Conduct the BCP and other test related to information security continuity along with CISO Responsible for monitoring and reporting on the performance of the ISMS. Responsible for implementation of security policies and procedures and report

pythonsqlaws
View job →
P
Pagerduty
📍 Atlanta• $180K – $303.6K/yr
10 days ago

PagerDuty, Inc. (NYSE: PD) is the global leader in AI-first digital operations. By automatically detecting, diagnosing, and remediating issues, the PagerDuty Platform orchestrates AI agents and automated workflows with context from over 750 integrations. Trusted by approximately two-thirds of the Fortune 100 and nearly half of the Fortune 500, PagerDuty is the industry standard for organizations scaling resilient, autonomous operations. Notable customers include Chipotle, Cloudflare, Docusign, Fox, Nvidia, Salesforce, Spotify, Zoom and more. We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform. About the Role PagerDuty is seeking a Principal Product Manager, Platform Security to own the strategy and execution of how we secure, harden, and defend our Operations Cloud platform. This role sits within our Product Development organization and reports to the Sr Director of Product, Platform & Partners. This is a senior individual contributor role. You'll bring the same rigor to security that a great PM brings to a product: deep customer empathy, structured threat modeling, clear risk tiering frameworks, and a bias toward measurable outcomes. You'll also be the connective tissue between Product, Engineering, IT, and Legal, ensuring security strategy translates into engineering execution and customer trust. This role owns the full lifecycle from recommendation to implementation to operations. You'll be the decision-maker on risk acceptance, control exceptions, and incident escalation in real-time. The ideal candidate has operated at the intersection of product management and security engineering in a later-stage B2B SaaS environment. You've owned security architecture decisions end-to-end, built security infrastructure, and have the credibility to influence both product roadmaps and engineering practices without formal authority. What You'l

aisalesforce
View job →
CH
Cohere Health
📍 Hyderabad• Full-time
15 days ago

Opportunity Overview: We’re looking for a senior-level automation engineer who will help raise the bar on release quality, environment reliability, and change safety across Cohere’s platform. You’ll partner closely with Product, Engineering, Platform, and SRE to build scalable automation, guardrails, and validation systems that reduce production risk while increasing delivery velocity. This is not a “test scripts only” role. You’ll shape automation strategy, embed quality into the SDLC, and help define how changes move safely from dev → staging → UAT → prod in a fast-moving healthcare platform. You’ll help define how quality scales as Cohere grows. This role has real influence over release safety, platform reliability, and how engineering teams ship software in a regulated, high-impact domain. You won’t just test features — you’ll shape how Cohere delivers them safely to production. What you’ll do: Own and evolve Cohere’s end-to-end test automation strategy across UI, API, config changes, and critical workflows Design and maintain scalable E2E automation frameworks for multi-tenant, payer-specific workflows Build automated validation for deployment guardrails, release readiness, and production change safety Partner with Platform/DevOps to integrate automation into CI/CD pipelines and deployment workflows Create automated coverage for high-risk paths (authorization flows, partner integrations, file pipelines, feature flags, config changes) Drive test reliability, flake reduction, and actionable failure signals Define and enforce quality gates for prod releases, blue/green and canary deployments, and config changes Collaborate with Product and Engineering to ensure business outcomes are testable, measurable, and observable Improve test data management and environment stability to enable reliable automation at scale Mentor engineers on testability, automation best practices, and quality-first development Partner with SRE and Security to ensure production readines

typescriptawsci/cd
View job →
🔔

Get new senior security risk management framework engineer jobs by email

Daily job updates · Unsubscribe anytime