Own the vulnerability management program, prioritizing and driving a culture of ownership across business units.
Drive metrics and program review to transparently communicate performance and accountability.
Provide expert leadership to highly visible, multi-faceted projects while coordinating across teams and geographies.
We empower organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity of our customers and trusted alliance of elite hackers with our patented data and AI-powered Security Knowledge Platform. We are based in San Francisco and New Hampshire, supported by General Catalyst and others, and we foster a diverse and inclusive culture.
Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
Perform vulnerability triage, validation, and proof-of-concept testing to determine real-world security impact.
Collaborate with engineering teams to communicate risks and drive remediation efforts.
This company provides a large-scale software platform for AI and data science solutions, serving organizations with demanding compliance and risk requirements. It fosters a culture of innovation, transparency, and collaboration, with a growing security function and an inclusive workplace.
Lead end-to-end technical onboarding and configuration of bug bounty, vulnerability disclosure, and pentest programs for customers.
Serve as technical point of contact during launches, providing guidance on vulnerability triage and integration best practices.
Manage program timelines and dependencies, proactively communicating with stakeholders to ensure on-time delivery.
Bugcrowd is a crowdsourced security platform that empowers organizations to stay ahead of threat actors by uniting hackers and AI-powered technology. The company, backed by General Catalyst and others, fosters a diverse and inclusive culture where employees from all backgrounds feel like family.
Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.
Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.
Identify and remediate high-impact security risks across applications, infrastructure, and production systems.
Integrate security practices into CI/CD pipelines and infrastructure-as-code workflows.
Collaborate with engineering teams to embed security into development and delivery workflows.
The company develops software and AI-powered solutions to support critical business workflows. It is a remote-first, fast-moving organization with a culture focused on ownership, transparency, and continuous improvement.
Assess and validate web application vulnerabilities across targets, confirming exploitability and scope.
Reproduce findings hands-on using tools like Burp Suite and rate severity with CVSS/OWASP.
Write clear, accurate customer-facing finding descriptions and remediation guidance.
RunSybil builds Sybil, an AI-driven pentester that automates hacker intuition to discover vulnerabilities before exploitation. Founded in 2023, the company is backed by strong investor support and includes experts from OpenAI, Meta, Mandiant, Palantir, Cruise, Trail of Bits, and Aptiv.
Define and execute comprehensive testing strategies across complex technology solutions.
Collaborate closely with product and development teams to validate requirements and improve delivery processes.
Apply automation, security, and performance testing expertise to ensure software quality and reliability.
Jobgether uses AI-powered matching to connect candidates with job opportunities. The company works with various hiring employers and values diversity, collaboration, and innovation.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.
Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.
Lead and grow a team of engineers specializing in web application discovery and attack surface enumeration.
Set technical direction, methodology standards, and quality expectations for the team's deliverables.
Partner with Product and software engineering teams to translate discovery gaps into prioritized roadmap input.
Horizon3 is a fast-growing, remote cybersecurity company dedicated to autonomous pentesting through its NodeZero platform. They are a team of former Special Operations cyber operators, engineers, and security practitioners committed to a culture of collaboration and ownership.
Develop and enhance ServiceNow solutions to improve digital workflows and automation.
Collaborate with agile teams to design, test, and implement platform improvements.
Serve as a technical reference, ensuring solutions meet security and quality standards.
The company specializes in delivering innovative ServiceNow solutions to improve digital workflows and enterprise service management. It fosters an agile, collaborative culture with a focus on professional growth and technical excellence.
Protect applications trusted by millions of users in the Web3 ecosystem.
Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
Embed security throughout the software development lifecycle to build resilient products.
This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.
Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Develop and maintain backend features for GitLab's vulnerability management workflows, primarily using Ruby on Rails.
Collaborate with frontend engineers and contribute across the stack when needed, focusing on performance and reliability.
Participate in on-call rotations to assist with troubleshooting product operations and security issues.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and reduce security risk. With over 50 million registered users and more than 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Diagnose and resolve customer-reported issues quickly, from investigation through durable fix.
Deliver high-quality engineering work that improves platform reliability and directly addresses customer needs.
Partner closely with Customer Success to align on technical solutions and maintain backend systems, APIs, and data pipelines.
VulnCheck is The Exploit Intelligence Company, delivering structured exploit intelligence for exploitation prevention. Founded in 2021, the company has a transparent, collaborative, and supportive culture with a team of cybersecurity experts.
Conduct thorough security assessments and penetration testing to identify vulnerabilities in web and mobile applications.
Collaborate with development teams to integrate security best practices and design secure application architectures.
Lead incident response and ensure compliance with security standards and regulations.
Moniepoint Inc. is an all-in-one African financial platform serving 20 million businesses with payments, banking, and tools. As Nigeria's largest merchant acquirer, it processes over $250 billion annually and fosters a culture of innovation and teamwork.