Design, implement, and maintain security controls for Box's enterprise applications and cloud services.
Partner with IT and business owners to securely deploy and operate enterprise platforms, SaaS apps, and integrations.
Perform security assessments, build monitoring and automation, and support vulnerability management and incident response.
Box is a leader in intelligent content management, providing a platform for collaboration, content lifecycle management, and secure workflows with enterprise AI. Founded in 2005, Box serves leading global organizations and has offices across the US, Europe, and Asia.
Lead the development and implementation of security strategies, policies, and procedures.
Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.
Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.
Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.
Lead secure code reviews, threat modeling, and secure design assessments to translate findings into actionable guidance.
Design and integrate application security controls across CI/CD platforms and developer workflows.
Define secure coding standards, reference architectures, and automated security capabilities scalable to engineering teams.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities, ensuring rapid and fair application reviews. They focus on leveraging technology to streamline hiring processes and are committed to data privacy and professional growth.
Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
Build offensive tooling, develop exploits, and support incident response and security education.
Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.
Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.
Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.
Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.
Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.
Lead a team of Security Engineers, providing decision-making support and enabling them to deliver security consulting to the wider business.
Work directly with Product & Technology teams to assist in how our platform is built and how applications behave, supporting everything from user security to internet connectivity.
Have significant impact on security of systems used by thousands of firefighters, paramedics, and hospitals worldwide.
ESO is a data, technology, and research company passionate about improving community health and safety through the power of data. We serve thousands of customers out of our offices across the US, Canada and Northern Ireland, and we are small enough to be nimble and fun but big enough to be a great place to work.
Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.
Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.
Lead product security engineering across key verticals, engaging with engineering leadership and technical teams.
Build and automate security design reviews, threat modeling, vulnerability management, and AI-assisted tools.
Serve as a subject matter expert for mobile, API, and cloud security, mentoring engineers and collaborating cross-functionally.
Xplor Technologies powers the experiences at the heart of everyday life through modern vertical software, embedded payments, and AI-powered capabilities. With over 130,000 businesses in 72+ countries and processing over $47 billion annually, we foster a culture of innovation, collaboration, and empathy, guided by core values like 'Find a better way' and 'Win together'.
Build and deliver technical solutions with national security partners.
Deliver world-class demos and training experiences to partners.
Speak at conferences and communicate technical concepts with excellence.
Wiz is a cloud security company that enables teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single context. As one of the fastest-growing startups ever, it is trusted by over 65% of the Fortune 100, powered by Google, and values world-class talent in a culture of innovation and fun.
You will own end-to-end data protection: architecting security infrastructure, managing PCI/SOC2 programs, and setting the security roadmap.
You will integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and harden containerized and cloud-native environments.
You will configure IAM and SSO platforms, manage EDR/DLP/SIEM tooling, and run security awareness training.
Campminder builds software for summer camps, enabling meaningful experiences for kids. With over 100 employees, they are stable, profitable, and have a values-led culture committed to work/life balance.
Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.
The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.
Own the full lifecycle of security findings and recommendations through triage, remediation, verification, and closure.
Secure and govern modern authentication flows like OIDC, OAuth 2.0 with PKCE, JWT, and mTLS.
Build and enforce guardrails using Azure Policy and Terraform, and operate Microsoft Defender for Cloud.
Valce Talent Solutions helps clients enhance talent attraction capacities, especially in technological profiles. Founded in 2016 with 24 employees, we offer consulting services to technology companies in IT, software development, cybersecurity, and project management.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.