
Camunda · Remote
Camunda is the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex, end-to-end bus...
Camunda is the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems
across complex, end-to-end business processes. With built-in governance, auditability, and human oversight, Camunda gives
enterprises the control they need to move AI from pilots to production — safely and at scale. Trusted by over 700 organizations
worldwide, including 9 of top 10 US banks, Camunda helps enterprises boost operational efficiency, accelerate time-to-value, and
deliver better customer experiences.
Fully remote and global, we are in the middle of something bigger: transforming into an AI-first organisation, built on our own
platform. We use Agentic AI to automate, orchestrate intelligent processes, and elevate human contribution across every team.
Named GP Bullhound’s Top 100 Next Unicorn list, 2025 Great Place to Work certified. Visionary in 2025 Gartner® Magic Quadrant™ for
Business Orchestration and Automation Technologies. ranked 3rd in Flexa's 2026 Most Flexible Companies, We’re growing fast and
looking for top talent to join our team. If you want meaningful work, visible impact and put something genuinely rare on your CV,
keep reading.
As a Senior Information Security Engineer (AppSec) at Camunda, you’ll join a small, senior, and highly collaborative InfoSec team
that lives our FAITH values – Focus, Ambition, Integrity, Talent and Humor – every day. You’ll work hand-in-hand with our product
and engineering teams across the entire SDLC to make sure our platform is designed, built, and shipped securely as we continue to
grow. This is a technical, hands-on, developer-centric, developer-centric role where you’ll shape how we build secure Java
services in a modern CI/CD, SaaS environment, strengthen our AppSec tooling and practices, and directly influence how customers
trust and adopt Camunda. You can be based anywhere that allows you to collaborate effectively within CET to Eastern Time working
hours.
testing, to deployment – to embed security by design in our products.
scanning into CI/CD pipelines, and making sure findings are actionable for developers.
with teams on fix/mitigate/accept decisions, and ensuring we continuously improve our security posture.
helping teams understand security trade-offs and make sound, risk-based decisions.
and other stakeholders to investigate, contain, and learn from issues.
(Java) services, working in CI/CD environments, and shipping SaaS or other cloud-based applications securely.
distributed/API/microservices systems, and performing risk assessments on product changes or new features.
container/image scanning, evaluating and triaging findings (including false positives), and driving fix/mitigate/accept
decisions with engineering teams.
stakeholders while explaining complex security issues and trade-offs in a clear, pragmatic way to both technical and
non-technical audiences.
escalations, you see yourself as an enabler (not a gatekeeper), and you influence teams toward risk-based, practical security
improvements.
This role is an existing vacancy
#LI-SG1 #LI-Remote #C1
Compensation
We offer competitive, fair, and transparent compensation. Salary ranges are location-based, with Standard and Major markets
(global tech hubs) reflecting local competition.
The Annual Total Target Cash (base salary + 100% variable target, where applicable) shown below spans from the minimum in a
Standard market to the maximum in a Major market. Final offers depend on skills, experience, and location, and we typically hire
If you’re based elsewhere, you’ll be hired via Remote.com (our global employer partner), and your Talent Acquisition Partner will
provide a personalized Total Rewards Calculator after your first interview.
Equity: We also offer equity (where applicable) through our Virtual Stock Option Plan (VSOP).
Benefits & Perks
We invest in your wellbeing, growth, and ability to connect, along with perks that support you no matter where you’re based. Our
benefits are globally designed and locally delivered where applicable.
time off to recharge when you need it.
offsites, and Camundi Connection Budgets, including contributing to meetups while travelling,, and local gatherings with fellow
Camundi.
Spending Account (LSA), a flexible, global benefit that puts you in control of your whole life, not just work, from: staying
active, to caring for family, exploring personal passions, meaningful experiences, and investing in your financial wellbeing.
The Live Well program launches in 2026 and scales to €1,000 annually from 2027.
relevant.
”Everyone is welcome at Camunda” — it’s a celebrated component of our culture. We strive to create an inclusive environment that
empowers our people. At Camunda, we honour diverse cultures and backgrounds and are proud to be an equal opportunity employer. All
qualified applicants will receive consideration without regard to gender, race, ethnicity, religion, belief, sexual orientation,
age, disability or any other protected characteristics under applicable law. We are looking forward to your application!
Come join us and be part of Camunda’s incredible journey: Make an impact at a pivotal moment in our story!
AI in our hiring process: Camunda may use AI tools to aid the screening of applications and during the interview process. You can
learn more here
ABOUT US Parity is one of the world’s most experienced companies building the core infrastructure behind blockchain — the system that allows information and value to be shared securely without needing an intermediary. We’re laying the foundation for a better web which respects the freedom and data of individuals, and empowers developers to build better, more trustworthy online services. Our remote-first, global team develop open-source software that anyone can use or improve. This includes Polkadot, Polkadot SDK, and Kusama — key parts of the Web3 tech stack, the next generation of the internet. Our mission is to make Polkadot the most active and innovative community in blockchain, powering a new era of connected and decentralised applications. ABOUT THE TEAM Parity’s Security Engineering team is at the forefront of protecting the Polkadot ecosystem by designing and implementing secure software, auditing code for vulnerabilities, and building cutting-edge ML tools to automate security analysis. We work closely with development teams to embed security best practices across our open-source stack, ensuring that our blockchain infrastructure is robust, resilient, and secure by design. ABOUT THE ROLE As a security-focused software engineer, you will go beyond traditional application security - you’ll audit and ideally write secure Rust code where needed, conduct deep manual and automated code audits, and leverage machine learning to enhance security across our ecosystem. This is an opportunity to shape the security landscape of the next generation of decentralized applications and protocols. * Assist in developing Secure Software – Write and optimise Rust code to build security-critical components and tools. * Code Auditing & Vulnerability Analysis – Perform deep manual and automated code reviews to identify and mitigate security vulnerabilities. * ML-Powered Security – Design and implement machine learning models for automated security analysis, anomaly detection, and threat mitigation. * Bug Bounty & Vulnerability Management – Manage bug bounty submissions, triage security reports, and collaborate with ethical hackers to resolve issues. * Secure Development Best Practices – Work with engineering teams to integrate security best practices into the software development lifecycle. * Threat Modeling & Risk Assessment – Identify and assess security risks in our blockchain infrastructure, smart contracts, and core software. * Stay Cutting-Edge – Research and implement the latest advancements in secure coding, ML-driven security, and blockchain security. WHAT WE'RE LOOKING FOR * Experience with secure coding practices and memory safety concepts. * Background in code auditing, vulnerability analysis, or exploit development. * Experience triaging and resolving bug bounty reports. * Knowledge of machine learning techniques applied to security (e.g., anomaly detection, fuzzing, automated threat detection). * Familiarity with cryptographic principles, blockchain security, or decentralized systems. * Strong problem-solving skills and an offensive security mindset. If you're excited about writing secure software, auditing code, and pioneering ML-driven security solutions for Web3, we’d love to hear from you! ABOUT WORKING WITH US Joining Parity means joining team mates who are genuinely excited about the impact their projects are having, and the opportunity to grow alongside some of the brightest minds in the Web3 space! You’ll work remotely and flexibly, while still getting to meet your team mates throughout the year at team and company-wide retreats. Upon receiving an offer, all candidates undergo a background check through Zinc, our trusted third-party provider. Team members will be taken on as a contractor via our UK entity. View our Applicant Notice to see how we use your data. Parity is an Equal Opportunity Employer. We welcome diversity in our global team and care about everyone in our collective feeling included and welcome. Is this position not quite your match? Browse our other open roles.
THUMBTACK HELPS MILLIONS OF PEOPLE CONFIDENTLY CARE FOR THEIR HOMES. Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance and bigger improvements. We help homeowners know which projects to do, when to do them and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we’ll build together. ABOUT THE CYBER SECURITY TEAM The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start. We partner closely with teams across the organization to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust. THE CHALLENGE AI is reshaping how work gets done at Thumbtack. Employees leverage AI assistants in their daily work and teams are building autonomous agents that act on their behalf - reading data, calling APIs, and making changes across enterprise systems. This introduces changes in the risk landscape. Identities now belong to agents and services as often as to people. Protocols like MCP are opening new pathways between AI and enterprise data. And the pipelines feeding AI systems cross more services, vendors, and trust boundaries than they have previously. The challenge is to evolve security controls to address these shifts in the technology and risk landscape driven by AI-adoption: hardening IAM for non-human and delegated identities, defining safe defaults for MCP servers and autonomous agents, and securing the data pipelines that feed AI systems. We package these controls as secure defaults, paved paths, and reusable patterns so teams can adopt them with confidence. The goal is straightforward — keep Thumbtack moving fast on AI while keeping customer and employee data protected. WHAT YOU’LL DO * This role focuses on improving AI-adjacent security at Thumbtack, including the agents, identities, integrations, and data pipelines that modern AI systems depend on. It also covers broader security engineering work across the enterprise platforms and services that support them. * Deliver high-quality security assessments and threat models for first-party and third-party AI tools, agents, and AI-integrated systems, ensuring they adhere to enterprise security principles and approved patterns, with sound authentication, authorization, data access, and observability by design. * Design and validate technical guardrails and reusable patterns that keep AI usage safe at Thumbtack. This spans AI behavior (safe defaults for agent actions, tool and permission scoping, human-in-the-loop boundaries for sensitive access, input and output controls, audit and observability) and AI connectivity (MCP servers, integrations, trust boundaries, and the data pipelines that feed first- and third-party AI systems). Contribute to the frameworks and tooling that support secure AI development and use across Thumbtack. * Harden IAM across the enterprise, with particular focus on the non-human and delegated identities behind AI systems (service accounts, agent credentials, SaaS-to-SaaS OAuth, and SCIM federation). Bring least-privilege and lifecycle hygiene to identities that increasingly act at machine speed. * Provide broader security engineering support across Thumbtack's enterprise platforms and services, including SaaS security and posture management, third-party and integration security, data governance, endpoint security, and identity-centric controls. Build paved paths, shared tooling, and automation that scale these controls. * Lead cross-functional security initiatives end-to-end. Partner with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to surface risk early, set clear requirements, and support scalable adoption of secure patterns. Conduct security design and architecture reviews for enterprise applications, SaaS platforms, and internally developed systems. * Mentor engineers and partner-team members, raising the overall security bar through guidance and example. * Support security incident response and drive learning through post-incident analysis. IN ORDER TO BE SUCCESSFUL, YOU MUST BRING * 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field. * Experience developing threat models and proposing technical guardrails for AI tooling and agentic systems, including non-human identities, tool/permission scoping, and safe defaults for agent behavior. * Deep expertise in modern enterprise security disciplines: authentication and authorization (SSO, OAuth/OIDC, SAML, federation, SCIM), API security and token handling, secrets management, least-privilege design, SaaS security and posture management. * Strong experience evaluating risk and conducting security design and architecture reviews across enterprise applications, SaaS platforms, integrations, and internally developed systems, including evaluating data flows, third-party integrations, trust boundaries, automation platforms, AI-connected workflows, and emerging integration patterns such as MCP. * Strong experience securing modern, cloud-native systems (AWS and/or GCP) and familiarity with core control domains such as audit logging, encryption, access control, data retention, and incident response. * Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive measurable improvements in enterprise security. * Excellent written and verbal communication skills, with the ability to influence without authority and translate technical risk into clear requirements and actionable guidance for both technical and non-technical audiences. EXPECTED SALARY RANGES * For candidates living in Ontario and British Columbia, the expected salary range for the role is currently $180,200.00 - $233,200.00. Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role. Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law. Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact: recruitingops@thumbtack.com. For information about how Thumbtack collects, uses, and shares personal information about job applicants, please see our Job Applicant Privacy Policy. We put as much craftsmanship into candidate safety as we do into the hiring experience itself. While scammers may try to impersonate our team, we’ll never ask you for money, banking info, or SSNs during hiring. Check out our blueprint on how to spot the fakes.
THUMBTACK HELPS MILLIONS OF PEOPLE CONFIDENTLY CARE FOR THEIR HOMES. Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance and bigger improvements. We help homeowners know which projects to do, when to do them and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we’ll build together. ABOUT THE CYBER SECURITY TEAM The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start. We partner closely with teams across the organization to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust. THE CHALLENGE AI is reshaping how work gets done at Thumbtack. Employees leverage AI assistants in their daily work and teams are building autonomous agents that act on their behalf - reading data, calling APIs, and making changes across enterprise systems. This introduces changes in the risk landscape. Identities now belong to agents and services as often as to people. Protocols like MCP are opening new pathways between AI and enterprise data. And the pipelines feeding AI systems cross more services, vendors, and trust boundaries than they have previously. The challenge is to evolve security controls to address these shifts in the technology and risk landscape driven by AI-adoption: hardening IAM for non-human and delegated identities, defining safe defaults for MCP servers and autonomous agents, and securing the data pipelines that feed AI systems. We package these controls as secure defaults, paved paths, and reusable patterns so teams can adopt them with confidence. The goal is straightforward — keep Thumbtack moving fast on AI while keeping customer and employee data protected. WHAT YOU’LL DO * This role focuses on improving AI-adjacent security at Thumbtack, including the agents, identities, integrations, and data pipelines that modern AI systems depend on. It also covers broader security engineering work across the enterprise platforms and services that support them. * Deliver high-quality security assessments and threat models for first-party and third-party AI tools, agents, and AI-integrated systems, ensuring they adhere to enterprise security principles and approved patterns, with sound authentication, authorization, data access, and observability by design. * Design and validate technical guardrails and reusable patterns that keep AI usage safe at Thumbtack. This spans AI behavior (safe defaults for agent actions, tool and permission scoping, human-in-the-loop boundaries for sensitive access, input and output controls, audit and observability) and AI connectivity (MCP servers, integrations, trust boundaries, and the data pipelines that feed first- and third-party AI systems). Contribute to the frameworks and tooling that support secure AI development and use across Thumbtack. * Harden IAM across the enterprise, with particular focus on the non-human and delegated identities behind AI systems (service accounts, agent credentials, SaaS-to-SaaS OAuth, and SCIM federation). Bring least-privilege and lifecycle hygiene to identities that increasingly act at machine speed. * Provide broader security engineering support across Thumbtack's enterprise platforms and services, including SaaS security and posture management, third-party and integration security, data governance, endpoint security, and identity-centric controls. Build paved paths, shared tooling, and automation that scale these controls. * Lead cross-functional security initiatives end-to-end. Partner with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to surface risk early, set clear requirements, and support scalable adoption of secure patterns. Conduct security design and architecture reviews for enterprise applications, SaaS platforms, and internally developed systems. * Mentor engineers and partner-team members, raising the overall security bar through guidance and example. * Support security incident response and drive learning through post-incident analysis. IN ORDER TO BE SUCCESSFUL, YOU MUST BRING * 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field. * Experience developing threat models and proposing technical guardrails for AI tooling and agentic systems, including non-human identities, tool/permission scoping, and safe defaults for agent behavior. * Deep expertise in modern enterprise security disciplines: authentication and authorization (SSO, OAuth/OIDC, SAML, federation, SCIM), API security and token handling, secrets management, least-privilege design, SaaS security and posture management. * Strong experience evaluating risk and conducting security design and architecture reviews across enterprise applications, SaaS platforms, integrations, and internally developed systems, including evaluating data flows, third-party integrations, trust boundaries, automation platforms, AI-connected workflows, and emerging integration patterns such as MCP. * Strong experience securing modern, cloud-native systems (AWS and/or GCP) and familiarity with core control domains such as audit logging, encryption, access control, data retention, and incident response. * Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive measurable improvements in enterprise security. * Excellent written and verbal communication skills, with the ability to influence without authority and translate technical risk into clear requirements and actionable guidance for both technical and non-technical audiences. EXPECTED SALARY RANGES * For candidates living in San Francisco / Bay Area, San Jose, New York City, or Seattle metros, the expected salary range for the role is currently $210,800.00 - $272,800.00. * For candidates living in Austin, TX or Washington DC metros or in California, Massachusetts, New Jersey, or Washington states, the expected salary range for the role is currently $189,600.00 - $245,300.00. * For candidates living in all other US locations, the expected salary range for this role is currently $179,400.00 - $232,100.00. Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role. Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law. Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact: recruitingops@thumbtack.com. For information about how Thumbtack collects, uses, and shares personal information about job applicants, please see our Job Applicant Privacy Policy. We put as much craftsmanship into candidate safety as we do into the hiring experience itself. While scammers may try to impersonate our team, we’ll never ask you for money, banking info, or SSNs during hiring. Check out our blueprint on how to spot the fakes.