Most recent job postings at Help Net Security
via Glassdoor posted_at: 9 days agoschedule_type: Full-timework_from_home: 1
Overview: The Security Best Practices team at CIS is looking for an QA Engineer to ensure the health and progress of our state of the art security policy authoring website. As a QA engineer, you will be designing and implementing tests, debugging and troubleshooting issues discovered, and making corrective actions within a fast-paced Agile development environment... You will play a vital role in the development process. You will be responsible for Overview:

The Security Best Practices team at CIS is looking for an QA Engineer to ensure the health and progress of our state of the art security policy authoring website. As a QA engineer, you will be designing and implementing tests, debugging and troubleshooting issues discovered, and making corrective actions within a fast-paced Agile development environment...

You will play a vital role in the development process. You will be responsible for working with software engineers to test cybersecurity products throughout their development and providing feedback to ensure that the products are free from errors and reliable.

Individuals with application and web development experience are encouraged to apply.

The Center for Internet Security (CIS) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit responsible for industry leading best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats.

What You'll Do:
• Participate in functional requirements and technical design discussions to plan for test development and provide meaningful feedback
• Develop functional test cases that represent business challenges and issues
• Perform all types of testing as needed, including functional, regression, performance, and security
• Identify, record, document and track bugs as needed. Validate bug fixes
• Identify and collect quality metrics that support SDLC Improvement
• Continually evaluate testing approaches, tools, and stacks
• Other tasks and responsibilities as assigned

What You'll Need:
• Bachelor's degree in Computer Science or related field*
• 4+ years of relevant QA experience, to include but not limited to Information Technology, Information Security, or Cyber Security
• Experience in testing automation using tools like Laravel Dusk, Selenium or similar
• Strong attention to detail
• Ability to communicate effectively with a remote team
• Must be team-oriented and able to contribute ideas to improve efficiency and productivity
• Demonstrable drive towards continual professional growth and improvement
• Must be authorized to work in the United States

It's a plus if you have:
• 2+ years of operational experience in a DevOps team
• Hands-on expertise with Laravel/PHP/JavaScript
• Experience with PHP Unit testing
• Experience with load testing tools
• Experience with continuous integration/continuous delivery tools
• Experience in AWS (operation + API), and other cloud infrastructures
• Experience using Git
• Fundamental understanding of agile principles and corresponding methodologies
• Solid foundation in SDLC and working experience in the Agile process framework (e.g., Scrum) and Atlassian stack (JIRA, Confluence)
• Additional years of relevant experience or a combination of an Associate’s degree or equivalent and relevant experience may be substituted for the Bachelor’s degree.

At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place
Show more details...
via Dice posted_at: 5 days agoschedule_type: Full-timework_from_home: 1
Piper Companies is hiring a Security Research Engineer for a large technology company located in RTP, NC. The Security Research Engineer will be supporting the security research of the companies products. The preference for the Security Research Engineer is to live in RTP, NC, Knoxville, TN, Austin, TX but can be fully remote for the right candidate. Responsibilities for the Security Research... Engineer: • Evaluate global products and services Piper Companies is hiring a Security Research Engineer for a large technology company located in RTP, NC. The Security Research Engineer will be supporting the security research of the companies products. The preference for the Security Research Engineer is to live in RTP, NC, Knoxville, TN, Austin, TX but can be fully remote for the right candidate.

Responsibilities for the Security Research... Engineer:
• Evaluate global products and services to identify security vulnerabilities and improvements
• Use tools, techniques and processes to mock real world adversaries
• Work with researchers to develop evolving ethical hacking skills and networking product knowledge

Requirements for the Security Research Engineer:
• 6+ years of experience in Security Penetration testing (web applications, APIs, embedded devices, user interfaces)
• 6+ years of experience of software engineering or reverse engineering (preferably C, C++ or python/ruby)
• Experience in a leadership position within security assessments
• 0 day vulnerability experience is preferred

Compensation for the Security Research Engineer: $130,000-$190,000 DOE, plus bonus and RSUs
Show more details...
via Upwork posted_at: 15 days agoschedule_type: Contractorsalary: 25–49 an hourwork_from_home: 1
We are looking for an expert in secure coding on .Net applications to work through a set of recommendations on an existing application and advise on the best way to generically resolve the points. We are looking for an expert in secure coding on .Net applications to work through a set of recommendations on an existing application and advise on the best way to generically resolve the points. Show more details...
via Indeed schedule_type: Internshipwork_from_home: 1
Overview: The primary purpose of this Stakeholder Engagement position is to gain experience while providing support to essential EI-ISAC functions. This position will provide exceptional service to all customers; ensuring ongoing satisfaction and retention, while representing CIS and the EI-ISAC in a professional and courteous manner. This position is also designed to gain experience and... exposure to cybersecurity and elections through administrative Overview:

The primary purpose of this Stakeholder Engagement position is to gain experience while providing support to essential EI-ISAC functions. This position will provide exceptional service to all customers; ensuring ongoing satisfaction and retention, while representing CIS and the EI-ISAC in a professional and courteous manner. This position is also designed to gain experience and... exposure to cybersecurity and elections through administrative and operational assistance. This is a paid internship opportunity.

The Center for Internet Security (CIS) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit responsible for industry leading best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats.

What You'll Do:
• Support the development and execution of the EI-ISAC strategy and mission.
• Membership onboarding, outreach, research, and reporting.
• Assist with data cleanup, reporting, and any ongoing projects.
• Customer service outreach via emails/phone calls.
• Develop and/or document procedure and workflows.
• Update metrics in EI-ISAC reports and presentation slides.
• Other tasks and responsibilities as assigned.

What You'll Need:
• 2 years of study in Elections, Communications, Business, Cybersecurity, or related field.
• Ability to cultivate and maintain supportive relationships.
• Strong online research skills and proficiency in Microsoft Office applications.
• Self-motivated with strong attention to detail and accuracy with grammar and spelling.
• Strong interpersonal skills and professional demeanor.
• Strong communication, problem solving, collaboration, and analytical skills.
• Ambition to learn and share ideas openly.
• The position is open to U.S. citizens and requires a favorably adjudicated DHS Fitness Review for Public Trust Positions**.

It's a Plus if you have:
• Associate’s Degree in related field
• *Factors that may cause a negative Fitness Review decision include:
• Criminal Conduct
• Dishonest Conduct
• Employment Misconduct
• Alcohol Abuse
• Drug Use (illegal drug use or use of a legal drug in a manner that deviates from approved medical direction) Additionally, illegal drug use includes the use of drugs that are illegal for federal purposes despite being legal in select states and countries, such as marijuana.)
• False Statements
• Financial Issues
• Have not resided in the US for three (3) of the past five (5) years

At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place
Show more details...
via Indeed schedule_type: Internshipwork_from_home: 1
Overview: Reporting to the Member Programs (MP) Manager, the intern will partner with other cybersecurity team members within Member Programs and Stakeholder Engagement to support our mission. The primary purpose of this position is to gain experience and exposure while providing administrative and operational support to the MP team. The Intern will assist the team with the federally funded... Nationwide Cybersecurity Review (NCSR) initiative, assisting Overview:

Reporting to the Member Programs (MP) Manager, the intern will partner with other cybersecurity team members within Member Programs and Stakeholder Engagement to support our mission. The primary purpose of this position is to gain experience and exposure while providing administrative and operational support to the MP team. The Intern will assist the team with the federally funded... Nationwide Cybersecurity Review (NCSR) initiative, assisting with reporting and data analytics, and various other administrative duties in the office.

The Center for Internet Security (CIS) makes the connected world a safer place for people, businesses, and governments through our core competencies of collaboration and innovation. We are a community-driven nonprofit responsible for industry leading best practices for securing IT systems and data. We lead a global community of IT professionals to continuously evolve these standards and provide products and services to proactively safeguard against emerging threats.

What You'll Do:
• Assist with NCSR user registration, customer service, troubleshooting and account management
• Update and create standard operating procedures
• Maintain and update team communications on company intranet
• Ad hoc reporting for internal and external NCSR stakeholders
• Vetting and acceptance of program applicants
• Assisting in the research, editing, and writing of newsletters, articles, reports, guides, whitepapers, and other educational materials on cyber security related topics
• Assisting with data related processes such as data imports and exports
• Other tasks and responsibilities as assigned

What You'll Need:
• 2 years of study in Cybersecurity, Business, or a related field
• Applicable coursework or related work experience
• Strong administrative skills including proficiency in Microsoft Office Applications (Word, Excel, PowerPoint)
• Ability to handle confidential employee information
• Excellent analytical skills
• Excellent interpersonal and written communication skills
• Excellent customer service skills
• Strong attention to detail and time management
• Must be authorized to work in the United States
• The position is open to U.S. citizens and requires a favorably adjudicated DHS Fitness Review for Public Trust Positions**

It's a Plus if You Have:
• Experience using WebEx software is a plus
• Experience working in customer relationship management or similar databases
• *Factors that may cause a negative Fitness Review decision include:
• Criminal Conduct
• Dishonest Conduct
• Employment Misconduct
• Alcohol Abuse
• Drug Use (illegal drug use or use of a legal drug in a manner that deviates from approved medical direction) Additionally, illegal drug use includes the use of drugs that are illegal for federal purposes despite being legal in select states and countries, such as marijuana.
• False Statements
• Financial Issues
• Have not resided in the US for three (3) of the past five (5) years

At CIS, we are committed to providing an inclusive environment in which the diverse backgrounds, experiences, and views of our employees, members, and customers are valued and respected. It is through this commitment that we are able to work together towards our common mission: to make the connected world a safer place
Show more details...
via Jobs By Workable posted_at: 7 days agoschedule_type: Full-timework_from_home: 1
Keeper Security is hiring an experienced Senior Full Stack Developer to join the KeeperChat team. This can be a 100% remote or hybrid position. Keeper Security’s applications have millions of users around the world and thousands of Enterprise customers. Join one of the fastest-growing Cybersecurity companies and work within the KeeperChat team under the guidance of an engineering team lead. This... person must be a detail and process oriented, Keeper Security is hiring an experienced Senior Full Stack Developer to join the KeeperChat team. This can be a 100% remote or hybrid position.

Keeper Security’s applications have millions of users around the world and thousands of Enterprise customers. Join one of the fastest-growing Cybersecurity companies and work within the KeeperChat team under the guidance of an engineering team lead. This... person must be a detail and process oriented, independent, self-motivated individual with a proven track record of experience in C#, .Net Development. This person will be working on the KeeperChat team specifically.

About Keeper Security

Keeper Security, Inc. ("Keeper") is transforming the way organizations and individuals protect their credentials, secrets, connections and sensitive digital assets to significantly reduce the risks of identity security-related cyberattacks, while gaining visibility and control. Keeper is the leading provider of zero-trust and zero-knowledge security cloud services trusted by millions of people and thousands of organizations for password management, secrets management, privileged access, secure remote infrastructure access and encrypted messaging.

Keeper's products are the highest-rated in the industry across G2, Trustpilot, PCMag and U.S. News & World Report. For the last several years, Keeper has received several InfoSec Awards from Cyber Defense Magazine for its cybersecurity enterprise software. Keeper is SOC 2 and ISO 27001 certified, FIPS 140-2 validated and FedRAMP Authorized. Keeper is backed by Insight Partners, a leading venture capital and private equity firm with $90b AUM.

Responsibilities
• Develop front-end and back-end client application features
• Participate in the SDLC in an Agile environment, following SCRUM principles
• Collaborate with the product team in defining requirements
• Collaborate with the development team to review peers' code
• Develop software that delivers features and fixes bugs
• Mentor junior developers
• Communicate with stakeholders to identify issues and deliver progress status
• Communicate with other teams to identify the role of shared applications in solving the problem at hand
• Conduct thorough testing of new code before handing it off to QA
• Assist QA as needed in their testing
• Excellent communication skills
• Ability to pick up new technologies quickly and with passion
• BS in Computer Science or equivalent experience
• Extensive full stack development experience
• Extensive experience in mobile development C#/Xamarin
• Extensive experience in test driven development
• Extensive experience with GitHub and CD/CI pipelines

Preferred Requirements:
• Java experience is a strong plus
• Experience with MySQL and Redshift
• Medical, Dental & Vision (Inclusive of domestic partnerships)
• Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life
• Voluntary Short/Long Term Disability Insurance
• 401k (Roth/Traditional)
• A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty, etc)
• Above market annual bonuses

Keeper Security, Inc. is an equal opportunity employer and participant in the U.S. Federal E-Verify program. We celebrate diversity and are committed to creating an inclusive environment for all employees.

Classification: Exempt
Show more details...
via Glassdoor posted_at: 8 days agoschedule_type: Full-timesalary: 140K a yearwork_from_home: 1
Posted: September 29, 2022 Start Date: January 2023... Position Status: Open Location: Remote within US Compensation: $140k USD, 100% 401k Match, Excellent Insurance We’re making HTTPS easier for developers to use, we’re doing it at scale, and we need your help. We’re a first-of-our-kind Certificate Authority (CA). We make certificates available to anyone, for free, and we offer an API to do it. This means more people can enable HTTPS on Posted: September 29, 2022

Start Date: January 2023...

Position Status: Open

Location: Remote within US

Compensation: $140k USD, 100% 401k Match, Excellent Insurance

We’re making HTTPS easier for developers to use, we’re doing it at scale, and we need your help. We’re a first-of-our-kind Certificate Authority (CA). We make certificates available to anyone, for free, and we offer an API to do it. This means more people can enable HTTPS on their websites, with less work. That protects everyone’s web traffic from snoops, and makes us all safer.

We’re looking for an additional software engineer for our Site Reliability Engineering (SRE) team. Maybe that’s you! Here's what our SRE team does:
• We develop software that improves automation and security in our infrastructure.
• We contribute code to ISRG's core applications. (e.g. Let's Encrypt).
• We maintain and evolve both the logical and the physical operational infrastructure.
• We contribute to open source projects we depend on.
• We help design policies and procedures for both the certificate authority and the organization.
• We participate in an on call rotation. We value protecting our teammates from burnout and accommodate people's schedules as needed.
• We are committed to improving ourselves and the services we provide. We teach each other and learn from our mistakes, often through blameless post-mortems.
• We help run a community forum where developers and end users find solutions to problems they might have with our services. We moderate comments to ensure everything stays on-track. We are happy to say ours is the friendliest and most supportive HTTPS-related forum around.
• We help research potential new projects that ISRG may operate.

Position Must Haves:
• 2+ years work experience programming in a compiled language with consistent attention paid to high quality tests.
• 2+ years working professionally with Linux.
• Attention to detail and a willingness to take time to think things through.
• Ability to prioritize and maintain cognizanse of your priorities in your work.
• Excellent written, verbal, and collaborative communication skills.
• Reliable time and task management.

Position Nice to Haves (if you don't know these already, we will help you learn on the job):
• Competency writing software in Go and Python.
• Systems and network administration experience. For example, managing firewalls and routers, working with automation tools like SaltStack, and managing virtual machines on both physical and cloud infrastructure.
• Domain-specific knowledge: PKI and some cryptography.

Location and Benefits

Our team has always been entirely remote (U.S. and Canada) and our processes and infrastructure are built around that. We will help you get your home office in good shape, including reimbursing internet and phone expenses. Other benefits include excellent health insurance, a 100% match for 401k contributions, and flexible time off and parental leave policies.

Applying

To apply, please submit your resume to: careers@letsencrypt.org

Not sure if you actually meet some of our requirements? Studies have shown that female-identifying folks and people of color are less likely to be confident that they meet requirements. At ISRG we are dedicated to building a diverse, inclusive, and authentic workplace, so if you’re excited about this role but you’re not sure if your past experience aligns with the requirements in the job description, we encourage you to ask.

ISRG is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex, gender, orientation, national origin, age, disability, or any other characteristic. We celebrate diversity and strive to create an inclusive workplace for everyone
Show more details...
via Built In posted_at: 7 days agoschedule_type: Full-timework_from_home: 1
Bitwarden promotes better internet security and safety with the leading open source password management solution for individuals, teams, and business organizations. Our philosophy about security is that “we are all in this together” – and so we continue to offer a full-featured free version of Bitwarden so that everyone can be protected with strong password management. At the same time, we... provide enterprise-grade solutions to some of the Bitwarden promotes better internet security and safety with the leading open source password management solution for individuals, teams, and business organizations. Our philosophy about security is that “we are all in this together” – and so we continue to offer a full-featured free version of Bitwarden so that everyone can be protected with strong password management. At the same time, we... provide enterprise-grade solutions to some of the largest companies in the world, and will continue to innovate in the identity and authentication market as the world starts to grow beyond passwords. Read more on the Bitwarden blog.

As a Back-End Software Engineer at Bitwarden, you will be responsible for building new features and maintaining our Password Manager back-end codebase, which includes our APIs, serverless functions, and databases. We’re looking for someone who will thrive in a growing organization with a strong collaborative focus. You will have the opportunity to take ownership over key areas of our product, providing direction for future changes and scoping out work to bring exciting new features to our users while maintaining overall code quality and maintainability.

This is an all-remote team and we need someone who can have some overlap with the US Eastern time zone.

Responsibilities
• Become an expert and authority on the Password Manager server codebase, including our APIs, serverless functions, and database
• Participate in hands-on development of the Bitwarden Password Manager product
• Participate in code reviews, learning and spreading technical knowledge
• Independently plan, estimate and deliver new feature work and bug fixes
• Occasionally contribute bug fixes submitted by the user community

What you bring to Bitwarden
• Expertise in developing and maintaining .NET Core services and libraries in C#
• Experience with maintaining, modifying, and optimizing SQL databases for enterprise-level solutions
• Understanding of authentication concepts, including OpenIDConnect, SAML, OAuth, and SSO flows
• Collaborative and adaptable mindset
• Openness and authenticity combined with excellent communication skills
• Excitement and enthusiasm for open source and for better internet security
• Excellent problem-solving skills – you might not know all the answers, but you know how to find and communicate the solution
• Familiarity with modern front-end frameworks (specifically Angular) is a plus for cross-collaboration with teammates

What to expect in the interview process

Selected candidates will be invited to schedule an introduction call and potentially progress through the following stages:
• Interview with hiring manager
• Panel interview with other engineers
• Reference calls
• Interview with CEO

Successful candidates will be asked to authorize and complete a background check. We do not discriminate based on having a criminal record, and we encourage candidates to be open with us about anything that may come up on the report, so we can discuss in advance and determine impact on the role and company.

A few reasons to work with us
• Our user community loves us and we love them. Come to work each day with a sense of purpose as we bring a more secure internet experience to everyone from our friends and family to the world’s largest organizations.
• Become an expert. You’ll get immersed in the prominent technology markets of security and open source software.
• We are dedicated to building a diverse and talented team. Work remotely with motivated and supportive team members across the world and take part in productive and fun meetups.
• Learn and grow. Take on new challenges with the support of your team, and join our #growth-club to continue personal and professional development.

We recognize and understand that people come with a wealth of experience and talent beyond just the technical requirements of a job. If you don’t meet 100% of the qualifications for the position, you should still consider applying. Diversity of experience and skills combined with passion is a key to innovation and excellence; therefore, we encourage people from all backgrounds to apply. Please let us know if you require accommodations during the interview process
Show more details...