Contribute to secure-by-design practices and maturing SAST, SCA, and DAST programs.
Develop Secure AI Development Lifecycle and AI-assisted threat modeling framework.
Mentor engineers on secure coding and foster cross-functional collaboration.
Spring Health is a global mental health company using an AI-native platform to deliver personalized mental health support. The company reaches over 170 million people worldwide and fosters a culture of innovation, collaboration, and commitment to eliminating barriers to mental health.
Lead security assessments of AI/ML models, data pipelines, and AI-enabled applications, identifying vulnerabilities such as prompt injection, model inversion, data poisoning, and adversarial inputs.
Partner with Data & Analytics and Engineering to embed security requirements and threat modeling into the AI development lifecycle, from data collection through model deployment.
Build and maintain guardrails, monitoring, and detection controls for AI systems in production, flagging anomalous model behavior and unauthorized data access.
Interra Health is a healthcare technology company that helps providers and patients navigate the prescription journey. It is a fast-growing, mission-driven team of about 100 employees, formed through the merger of DoseSpot, Arrive Health, and pVerify, and focused on reducing friction and improving access to medications.
Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.
GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, profitable, privately-held value added reseller focused exclusively on information security.
Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.
Fast-growing B2B SaaS company serving the life sciences and pharma space. A small, high-impact security team with an engineering-first mindset, building AI-native features.
Deliver accurate security assessments of software, code, and firmware, evaluating resilience against AI-driven attacks.
Build and pressure-test novel AI-enabled security tooling and workflows, then drive adoption across the security org.
Partner cross-functionally to define and drive Samsara's medium- and long-term AI security strategy.
Samsara provides a Connected Operations Cloud platform that helps organizations improve safety, efficiency, and sustainability of physical operations. As a publicly traded company, they foster a culture of rapid career development and hyper growth, with a high-caliber team.
Lead threat modeling and security architecture for AI-enabled systems, including LLM applications and cloud-native platforms.
Define and implement secure engineering patterns and guardrails across AWS infrastructure, CI/CD pipelines, and third-party integrations.
Partner with engineering and security teams to embed security throughout the AI product lifecycle and drive cross-functional security initiatives.
Quanata is an insurance technology innovation company that engineers advanced risk prediction and prevention solutions for State Farm and HiRoad. We are a wholly owned subsidiary of State Farm with a remote-first culture that values inclusion and positive team dynamics.
Secure BJAK's AI-enabled products and agent workflows using third-party models.
Assess customer data shared with model vendors and design least-privilege controls for AI agents.
Threat model prompt injection and support SC TRM/BNM RMiT compliance for AI risks.
BJAK is a mobile-first insurance platform that makes insurance accessible online and is the leading insurtech in Southeast Asia. With over 20 nationalities working from offices and remotely worldwide, the company values passionate builders who love creating next-generation financial products.
Lead security reviews of architecture, code, and security-sensitive changes.
Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
Threat model new capabilities and build scalable guardrails that reduce recurring risks.
Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.
Shape the Cogent product at the frontier of AI and cybersecurity, working hand-in-hand with ML engineers.
Build the world's first AI-native cybersecurity organization, extending security posture and incident response.
Educate the market and elevate the industry through thought leadership and customer partnerships.
Cogent is an applied AI lab building next-generation AI agents for cybersecurity. The company is a rapidly growing startup backed by Greylock, with a team of experts from top universities and companies, fostering a culture of cutting-edge research and real-world execution.
Conduct hands-on application security reviews threat modeling and code audits across the entire stack (backend frontend APIs infrastructure).
Build and improve security automation for vulnerability management including SAST DAST container scanning and secrets detection.
Drive remediation of findings from bug bounty scanners and audits partnering with engineering teams to prioritize and fix.
Close builds a communication-first AI-powered CRM that helps sales teams sell more and faster. With a 120-person 100% remote team they are bootstrapped profitable and focused on eliminating manual data entry for scaling businesses.
Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Design and maintain secure architectures across AWS, Azure, and GCP with infrastructure-as-code and policy-as-code enforcement.
Secure AI/ML pipelines and LLM applications, addressing OWASP Top 10 for LLMs and implementing guardrails and content-filtering controls.
Drive security operations, including SIEM monitoring, incident response, and supporting HIPAA/HITRUST/SOC 2 compliance.
Reveleer delivers a unified platform for risk adjustment, quality improvement, clinical intelligence, and member management for health plans and provider organizations in value-based care. Trusted by 80+ customer organizations nationwide, the company fosters a collaborative, compliance-focused culture with transparent, human-in-the-loop AI at its core.
Own vulnerability management across code, dependencies, images, and cloud config, automating triage and remediation.
Build and expand security gates in CI/CD pipelines, define secure cloud baselines, and drive least privilege identity.
Partner with DevOps on paved roads for secure-by-default development and lead incident response.
Aegis AI is a startup founded by ex-Google engineers who built Safe Browsing and reCAPTCHA, focused on stopping adversarial AI attacks. The team is flat, flexible, and fast, with engineers owning decisions and clear KPIs.
Design and build secure enterprise applications with React, TypeScript, Python, and API services.
Build agentic workflows and MCP integrations that connect AI applications to enterprise data and tools.
Mentor other engineers and help guide technical direction across teams.
Nortal shapes digital transformation for global enterprises and public sector organizations, helping them turn data into real business value. We champion autonomy, open communication, and respect for diversity, with a close-knit remote community and strong People Care support.
Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.
Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.
Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.
Turquoise Health is a Series C price transparency platform building a more open, efficient healthcare marketplace for finance leaders. They're a remote-first US team backed by top investors, powering transparency for 300+ enterprise organizations.
Design and build CI/CD workflow integrations that bring application security into software delivery pipelines and developer environments.
Run discovery sessions and architecture workshops with enterprise customers to align the Snyk platform to their requirements.
Build trusted relationships with technical stakeholders and support implementations from pre-sales through post-sales.
Snyk builds a security platform where AI agents work alongside engineers to find and fix risk at the speed software is built. The company fosters an inclusive culture with global benefits and employee resource groups, aiming to make the digital world safer.
Lead Affirm's enterprise AI security review process, evaluating architecture, data flows, and design of AI tools and agentic systems.
Threat model AI/LLM systems for risks like prompt injection, insecure output handling, and data poisoning, and drive remediation.
Build security guardrails, tooling, and policy-as-code to automate AI security and support cross-functional initiatives.
Affirm is a financial technology company that offers clear, predictable point-of-sale installment loans with no hidden fees. The company is remote-first and values transparency, care, and flexibility, with a focus on building a diverse and inclusive team.
Add security tooling and checks to CI/CD pipelines with Python automation.
Perform offensive testing, triage findings, and patch straightforward vulnerabilities.
Collaborate with engineers, DevOps, and Fraud while leveraging AI for security work.
Super.com is a high-growth tech company helping people save, earn, and get more out of life. They are a remote-first, collaborative team that has hosted over 100 engineering internships and values career progression.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.