Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.
Turquoise Health is a Series C price transparency platform building a more open, efficient healthcare marketplace for finance leaders. They're a remote-first US team backed by top investors, powering transparency for 300+ enterprise organizations.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
Review cloud application architectures, build automation for security controls, and participate in incident response.
Communicate security risks to technical and non-technical audiences and champion improvements to security processes.
Atlassian provides collaboration software solutions designed to help teams work better together. The company has a global, inclusive culture where the unique contributions of all employees create success.
Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.
Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.
RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.
Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.
GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, profitable, privately-held value added reseller focused exclusively on information security.
Lead the Application Security program across all products, embedding security throughout the SDLC.
Integrate AppSec findings into centralized vulnerability workflows, correlating them with asset and exploit intelligence.
Automate security testing pipelines and mentor engineers on secure coding and threat modeling.
ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter with its AI platform. The company is building an AI-native culture where technology and talent are unstoppable together.
Collaborate with DevOps and engineering teams to embed security throughout the software development lifecycle.
Implement automated security testing, including SAST, DAST, SCA, and container security, and strengthen cloud-native security controls.
Support compliance with PCI-DSS, GDPR, CCPA, and SOC 2, and evaluate secure adoption of AI-assisted coding tools.
Our partner is a technology company in the travel and hospitality industry. They have a collaborative remote culture and value employee development and diversity.
Conduct code and container vulnerability assessments using DoD scanning tools, DISA STIGs, and SRGs.
Apply SAST and DAST methodologies and integrate security controls into CI/CD pipelines.
Serve as GitLab security reviewer and coordinate remediation of security findings across teams.
This partner company supports cybersecurity and secure software delivery within U.S. Department of Defense and Navy environments. The organization offers a fully remote, mission-focused culture with opportunities to collaborate across engineering and program teams.
Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.
Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.
Design, build, and maintain production features with a strong product security focus.
Own vulnerability response from initial triage through coordinated disclosure and patched releases.
Conduct threat modeling and security-sensitive design reviews to help engineers make informed security decisions.
This company builds cloud-native infrastructure software with a strong focus on Kubernetes security. They operate as a remote-first, globally distributed team that values engineering ownership and autonomous work.