Careers
-
Location: Remote (Austin, TX area preferred)
Experience Level: 7+ Years
Job Type: Full-Time
We’re looking for a Network Penetration Tester to break what others build. In this role, you’ll probe enterprise networks, cloud environments, and infrastructure to uncover vulnerabilities before attackers do. You’ll emulate real-world adversaries, exploit weaknesses, and deliver sharp insights that help strengthen our defenses. If you thrive on uncovering hidden paths, privilege escalation tricks, and cracking hardened perimeters, we want you on our team. Learn more…
-
Location: Fully Remote
Experience Level: 8+ Years
Job Type: Full-Time
We are seeking an experienced Application Penetration Tester to conduct in-depth security assessments of web, mobile, and cloud-based applications. You will play a key role in identifying vulnerabilities, simulating real-world attacks, and providing actionable remediation guidance to improve security posture. Learn more…
-
Location: Fully Remote
Experience Level: 8+ Years
Job Type: Full-Time
We are seeking an experienced Senior Security Consultant - GRC to help organizations design, implement, and optimize security programs that align with business goals and regulatory requirements. This role requires expertise in governance, risk, and compliance (GRC), as well as the ability to translate security frameworks into technical controls. You will work closely with clients to assess security posture, develop strategic roadmaps, and ensure compliance with industry standards. Learn more…
-
Location: Fully Remote (but local to Austin, TX highly preferred)
Experience Level: 5+ Years
Job Type: Full-Time
Join our innovative team as a Mid-Level Full-Stack Developer and dive into the exciting world of secure application development with Node and React. You'll be at the forefront of enhancing our cutting-edge security and GRC platform, collaborating with passionate product and services teams to deliver top-notch solutions that make a real difference for our clients. Learn more…
-
Location: Fully Remote
Experience Level: 5+ Years
Job Type: Full-Time
We are seeking a Cybersecurity Services Project Manager to oversee and manage penetration testing projects, security assessments, and cybersecurity engagements. This role requires a strong understanding of security testing processes, exceptional project management skills, and the ability to track milestones while ensuring customer satisfaction. The ideal candidate is highly organized, technically fluent, and skilled at coordinating cross-functional teams to deliver successful cybersecurity engagements. Learn more...
-
Location: Hybrid Remote/On-Site in Austin, TX
Experience Level: 5+ Years
Job Type: Full-Time
We are seeking a highly skilled Security Engineer / Administrator to augment our client’s IT team. This critical role merges advanced system administration with cutting-edge security engineering expertise to deliver robust, secure, and high-performing IT infrastructure. The ideal candidate will thrive in both on-premises and cloud-based environments, proactively driving operational excellence and fortifying cybersecurity defenses against evolving threats. This position offers a unique opportunity to impact mission-critical systems, collaborate with diverse teams, and implement innovative solutions that ensure system reliability, scalability, and security. Learn more…
-
Location: Hybrid Remote/On-Site in Austin, TX (Set days in-office weekly required)
Experience Level: Mid to Senior Level
Job Type: Contract / Fractional (Full time)
Certifications: GRC or security certifications (CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP) a bonus
Crux Security is looking for a self-directed Supply Chain Analyst to stand up a Supply Chain Risk Management (SCRM) program for a client engagement, working under the direction of an experienced Supply Chain lead who will provide subject-matter direction and quality review. This is a force-multiplier role: you will take a defined scope of work and drive it to audit-ready completion with minimal day-to-day oversight, escalating judgment calls rather than routine execution questions.
You will build a supplier register from scratch, design and apply a vendor risk tiering methodology, review and update security contract clauses alongside Legal, stand up a SOC 2 / ISO 27001 certification review process for critical vendors, and design a SaaS procurement security checklist. The end state is an ISO 27001:2022-aligned evidence package (mapped to A.5.19–A.5.23) that is audit-ready, along with documented procedures and a formal transition plan handing long-term ownership to the client. Learn more…