Own and improve the secure software development lifecycle, perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features.
Drive vulnerability management across internal reviews, bug bounty, pentests, and other research signals, ensuring findings are validated, prioritized, and tracked through remediation.
Configure and improve AppSec tooling and integrations, and use AI to automate and scale security processes while validating outputs with strong engineering judgment.
Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion.
Partner with Product and Engineering teams to integrate security into application design and development, leading threat modeling and secure code reviews.
Develop and implement automated security guardrails across the SDLC, investigate and prioritize application security findings.
Promote secure coding practices through training and coaching, and create security standards and procedures that scale across teams.
Quanata is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions and builds a full-stack, flexible, digital & increasingly AI-native insurance platform. We are a remote-first company wholly owned and funded by State Farm, with a culture that prioritizes inclusivity and positive collaboration.
Lead security architecture reviews for new and existing applications.
Develop, enforce, and continuously refine secure coding standards across engineering teams.
Continuously improve threat modeling frameworks across application components.
Lumin Digital is a trailblazer in digital banking solutions, driven by a unique approach to technology, service, and people. They empower credit unions and banks by creating cutting-edge digital experiences. At Lumin, their culture is built on trust in expertise and decisions, respect for diverse perspectives and talents, and boldness in pursuing new ideas.
Lead AppSec program assessments to evaluate current state and help clients prioritize remediation efforts based on risk, resources, and organizational readiness.
Design pragmatic security workflows, processes, and tooling integrations that engineering teams will actually adopt.
Deliver polished client work including clear assessments, actionable roadmaps, and executive communications that drive decision-making.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. The company has grown to over 1,200 employees and serves as a trusted advisor to more than 6,200 customers.
Play a key role in protecting and strengthening large-scale cloud-native applications that power next-generation AI infrastructure.
Work at the intersection of software engineering and cybersecurity, ensuring security is embedded throughout the software development lifecycle.
Collaborate cross-functionally to identify and remediate vulnerabilities in complex distributed systems.
Our partner is a company building large-scale cloud-native applications that power next-generation AI infrastructure. They have a high-impact security engineering environment with a collaborative and innovative culture focused on trust, learning, and impact.
Conduct threat modelling reviews of Technical Design Documents (TDDs) and provide actionable security recommendations early in the design process.
Perform application security assessments, including penetration testing, vulnerability assessments, and proof-of-concept development.
Investigate, triage, and respond to Bug Bounty program submissions, validating findings and driving timely remediation with engineering teams.
MoonPay is a unified payments platform for digital currency. Trusted by over 30 million customers and over 500 ecosystem partners, the company is committed to building a fairer, more open financial system with a culture of accountability and inclusivity.
Deliver Application Security services including threat modeling, architecture reviews, and program assessments.
Author comprehensive reports tailored to technical and managerial audiences with remediation strategies.
Contribute to practice development and mentor team members while embracing emerging technologies.
GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations minimize risk. With over 1,200 employees, the company fosters a collaborative culture focused on mentorship and knowledge sharing.
Enable software engineering teams to continuously improve the security posture of products and SaaS environments through AppSec and DevSecOps expertise.
Serve as the go-to AppSec expert, mentoring engineers on secure design patterns and coding practices while collaborating on threat models and design reviews.
Lead automation of vulnerability management tooling across CI/CD pipelines, perform security code reviews, and contribute to compliance strategies.
Hypori is a high-growth cybersecurity SaaS company transforming how organizations think about secure mobility. Backed by $55M in funding from investors including UBS and AE Industrial Partners, the company is expanding into new commercial and regulated markets.
Champion and implement security best practices and automated tooling across Spotify's infrastructure and platforms.
Partner closely with teams to integrate security throughout the software development lifecycle from design to deployment.
Conduct threat modeling, security reviews, and risk assessments for both AI and non-AI systems.
Spotify is the world's most popular audio streaming subscription service, unlocking the potential of human creativity by giving artists the opportunity to live off their art. With over 700 million users, the company values curiosity, collaboration, and a willingness to both teach and learn from others.
Perform penetration testing and design reviews to identify vulnerabilities and insecure designs.
Maintain and build internal tools to automate security efforts, including SAST and DAST testing.
Identify vulnerabilities, demonstrate business impact, and articulate risk to drive prioritization.
Brex is the intelligent finance platform that enables companies to spend smarter and move faster in over 200 markets. With tens of thousands of customers including DoorDash, Coinbase, and Zoom, Brex fosters a diverse and inclusive team culture where collaboration with some of the brightest minds in the industry is key.
Serve as the technical expert for Zero Trust Architecture in cloud environments (AWS, Azure, GCP).
Collaborate with sales and engineering teams to influence the product roadmap and customer strategies.
Drive customer Proof-of-Value engagements, demonstrating Zscaler's unique value proposition.
Zscaler accelerates digital transformation by securing users, devices, and applications through its cloud-native Zero Trust Exchange platform. As an AI-forward enterprise leveraging the world's largest security data lake, Zscaler fosters a culture of execution, transparency, and high-impact collaboration.
Design and build the AI security control plane to enable safe adoption of AI across the enterprise.
Partner with engineering and security teams to modernize the SDLC for an AI-enabled world.
Drive technical leadership by translating emerging AI risks into actionable engineering strategies.
Granicus provides cloud-based solutions for government communications, website design, meeting management, and digital services. With over 5,500 government agency clients, 300 million citizen subscribers, and a remote-first culture, it has been consistently recognized on the GovTech 100 list.
Own the managed AI platform posture end-to-end, anticipating changes and governing usage across the organization.
Build financial visibility with token tracking dashboards, anomaly detection, and ROI reporting for leadership.
Harden AI security posture by mitigating prompt injection risks and ensuring no sensitive data flows into AI prompts.
Chainguard is the trusted source for open source, delivering hardened, secure builds of open source software and AI agents. They are venture-backed by leading investors and count Fortune 500 enterprises like Anduril, Canva, and OpenAI as customers.
Partner with engineering teams to design, build, and operate secure-by-default cloud infrastructure across AWS and Google Cloud.
Build reusable Terraform modules and policy-as-code guardrails to make secure implementation easier for engineering teams.
Operate CSPM/CNAPP tooling and drive remediation of cloud vulnerabilities and misconfigurations.
Fullscript is a health technology company that provides a platform for practitioners to access clinical insights, lab interpretations, and high-quality supplements, serving over 125,000 practitioners and 10 million patients. The company has a remote-first culture, emphasizes work-life balance, and values inclusivity and continuous learning.
Design and operationalize AI security architecture, guardrails, and secure-by-design patterns across the enterprise.
Engineer security controls for AI-enabled applications, internal AI agents, model hosting, RAG architectures, and training pipelines.
Implement data security controls with Microsoft Purview, focusing on AI-driven data access, classification, and protection.
J.S. Held is a global consulting firm that combines technical, scientific, financial, and strategic expertise to advise clients on value realization and risk mitigation. The firm provides a comprehensive suite of services and has a high-energy, collaborative environment that rewards hard work.
Act as the main cybersecurity partner to Customer Support and Integrity teams, establishing the dedicated security function and building vision, strategy, and execution.
Lead technical direction, design security controls, and operationalize solutions to reduce risk for support agents and tooling across global teams.
Drive alignment, build measurable metrics, and perform security testing to proactively manage security risks at scale.
DoorDash is a technology and logistics company that enables door-to-door delivery, connecting consumers, merchants, and Dashers. They are a large, rapidly growing company committed to supporting employee happiness and health with comprehensive benefits and perks.
Own and manage bug bounty intake processes, including triaging reports, validating vulnerabilities, and reproducing proof of concepts.
Collaborate with developers and product teams to design and implement effective remediation strategies for identified security issues.
Contribute directly to codebases by reviewing and submitting pull requests to fix security vulnerabilities.
Jobgether is a company using AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. They have a collaborative, feedback-driven culture that encourages innovation and ownership.
Lead integration of security across the SDLC, embedding automated testing into CI/CD pipelines.
Secure cloud-native AWS architectures and enforce least privilege access and runtime protections.
Perform threat modeling, automate compliance, and innovate with AI security standards.
TrueML is a mission-driven financial software company that uses machine learning to improve customer experiences for distressed borrowers. The team includes data scientists, financial services experts, and customer experience fanatics building inclusive financial technology.
Define, implement, and maintain the AI security strategy across Deel's infrastructure and product ecosystem.
Lead security assessments and threat modeling for AI/ML models, LLM integrations, and agentic AI systems.
Evaluate and deploy AI Security Posture Management (AISPM) and AI Detection & Response (AIDR) solutions.
Deel is the all-in-one payroll and HR platform for global teams with a vision to unlock global opportunity. They are among the largest globally distributed companies with a team of 7,000 spanning more than 100 countries with a connected and dynamic culture.
Own the operational health of one or two engineering domains (identity, network, cloud, endpoint, monitoring) and lead cross-team security initiatives.
Design security patterns, reference architectures, and standards that the team executes against, ensuring audit-ready documentation.
Mentor mid and associate engineers through pairing, code review, and clear standards to elevate team capability.
Aprio is a Top 20 CPA and advisory firm with over 40 U.S. office locations, international offices, and more than 3,200 team members speaking 60+ languages. They provide expertise and strategic foresight for fast-growing industries, fostering a progressive and innovative culture.