Own and lead building out the Insider Trust Team’s infrastructure to engineer and automate end-to-end detection and investigation workflows.
Develop, measure, and tune detection rules in Sigma to ensure effective and sustainable operations.
Drive projects with a focus on Insider Risks, ranging from access abuse and intellectual property theft, to novel risks emerging within the blockchain/Web3 space.
Serve as Incident Commander for SIRN security cases, owning coordination from detection to resolution.
Lead incident triage, rapidly assessing scope, severity, and impact to drive prioritization.
Develop, tune, and triage telemetry signals for on-chain and infrastructure detection.
Asymmetric Research is a boutique security venture specializing in deep partnerships with L1/L2 blockchains and DeFi protocols. Their fully remote team brings decades of security-first experience from top tech companies, valuing autonomy and professionalism.
Lead complex end-to-end blockchain investigations to trace ransomware proceeds and identify threat actor infrastructure.
Produce actionable finished intelligence including actor profiles, attribution assessments, and operational reporting.
Mentor peers and refine investigative methodologies to elevate team tradecraft.
TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. It is a Series C company with $220M in total funding, operating as a distributed-first team with a culture of high ownership, adaptability, and collaboration.
Lead detection engineering innovation by reimagining how unlimited AI capacity transforms SOC workflows.
Partner with engineering teams to encode expert detection knowledge into product, designing scoring rubrics for AI-generated content.
Stay current on emerging threats and conduct original research to develop novel AI-assisted detection approaches.
Dropzone's mission is to scale cybersecurity beyond human limits by augmenting security engineers with AI specialists. We are an award-winning, venture-backed company disrupting the $200B+ cybersecurity market with a team experienced in cybersecurity, AI/ML, and SaaS.
Monitor security events and provide technical analysis on alerts.
Lead information security incidents and employee insider investigations.
Coordinate building of services and technologies to support security operations.
Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. A recently public company, it fosters a collaborative and growth-minded culture focused on safety, efficiency, and sustainability.
Monitor security events and provide technical analysis on alerts.
Lead information security incidents and employee investigations, developing response strategies.
Deliver security guidance and coordinate building services to support security operations.
Samsara is the pioneer of the Connected Operations Cloud, helping organizations that depend on physical operations harness IoT data to improve safety, efficiency, and sustainability. As a recently public company with a culture that encourages rapid career development, they support a flexible, employee-led remote model.
Monitor logs, alerts, and telemetry to detect threats across infrastructure and cloud environments.
Perform in-depth security analysis and investigations to assess risk and identify root causes.
Coordinate and execute incident response efforts including containment, mitigation, and recovery.
Binance.US is a licensed and regulated U.S. crypto platform providing secure access to over 190 cryptocurrencies. As a remote-first team, we innovate to bridge traditional finance and Web3, helping bring financial freedom within reach for all.
Build into the product by writing investigation flows, building integrations with security tools, and fixing bugs.
Evolve the investigation logic and pipelines to handle new classes of security alerts, balancing accuracy, performance, and maintainability.
Contribute directly to the Python codebase while influencing architectural decisions and long-term product strategy.
Dropzone AI scales cybersecurity beyond human limits by augmenting security engineers with AI specialists. The venture-backed company is disrupting the $200B+ cybersecurity market and has a team with deep experience in cybersecurity, AI/ML, and SaaS.
Perform investigations of security incidents using digital forensics and data analytics.
Build automation and detection models to identify anomalous activity and mitigate threats at scale.
Partner with engineering teams to develop advanced detection solutions and complex investigations.
This is a leading global travel technology marketplace that connects users with travel services worldwide. The company culture emphasizes collaboration, mentorship, and calm problem-solving in high-stakes security operations.
Respond to security incidents as part of a distributed 24x7 on-call schedule, triaging and containing events.
Conduct security investigations and forensics across data sources to determine event timelines and impact.
Build automations leveraging AI and agentic platforms to expedite incident response and scale team impact.
Databricks is the data and AI company, providing a unified platform for data, analytics, and AI. More than 10,000 organizations worldwide, including over 50% of the Fortune 500, rely on Databricks, which fosters a diverse and inclusive culture.
Conduct end-to-end investigations into sanctions-related alerts, CTF suspicions, and high-risk activity on Binance's platform.
Perform blockchain tracing and on-chain analysis to identify fund flows and links to sanctioned entities or terrorist financing networks.
Manage caseloads within SLAs, prepare detailed investigation reports, and support client off-boarding processes.
Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange by trading volume and registered users. Trusted by over 300 million people in 100+ countries, they offer a fast-paced, innovative environment with a flat structure and a diverse workforce.
Design and automate controls, detection mechanisms, and tooling to improve Information Security of Algolia's infrastructure and products.
Partner with engineering and product teams to integrate Information Security into new features, systems, and development pipelines.
Conduct Information Security risk assessments and threat models of core systems, services, and third-party vendors.
Algolia is a pioneer and market leader in AI Search, empowering 17,000+ businesses with blazing-fast, predictive search experiences. The company raised $150M in Series D funding, quadrupling its valuation to $2.25B, and has a global team with offices in Paris, NYC, London, Sydney, and Bucharest.
Monitor enterprise AI usage end to end to detect unauthorized AI tools and rogue agent activity.
Investigate alerts related to autonomous agents and AI-powered workflows, including data exfiltration and credential misuse.
Partner with security, legal, and engineering teams to align findings with incident response processes and support ISO 42001 audits.
AlphaSense provides AI-driven market intelligence and search to help companies make informed decisions. With over 2,000 employees across the globe, the company fosters a collaborative and innovative culture.
Lead the development, rollout, and operations of security operations tools and services such as SIEM, EDR, NDR, email, and cloud, building detection rules, automated playbooks, and integrations.
Apply a detections-as-code approach with version-controlled, peer-reviewed detection rules tuned against alert quality metrics.
Architect and implement security engineering capabilities including endpoint security, data loss prevention, email security, network security, SIEM enhancements, detection engineering, and security automation.
Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization, empowering organizations to govern interactions across the modern enterprise. It is a global team with a culture of innovation, respect, and fairness, backed by strategic investment from TPG.
Design, test, and optimize detection workflows including sourcing queries, collection methods, enrichment logic across data sources.
Partner with Product and Engineering to communicate customer feedback and emerging threat patterns.
Analyze recurring trends across alerts and customer environments to inform scalable platform improvements.
Doppel is building the future of social engineering defense using an AI-native platform to protect against phishing, impersonation, and fraud. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with deep cybersecurity expertise and a culture of clarity and collaboration.
Investigate security alerts using tools such as CrowdStrike Falcon Suite and Microsoft Sentinel to determine scope and impact.
Support incident response activities, including containment, remediation, and post-incident documentation.
Collaborate with cross-functional teams to improve detection quality, workflows, and response readiness.
Commvault is the gold standard in cyber resilience, empowering customers to uncover, take action, and rapidly recover from cyberattacks. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks and improve governance.
Perform investigations into detected threats using EDR, Network, and Identity telemetry to analyze, contain, and remediate threats in customer environments
Identify, scope, and manage ongoing customer incidents, developing remediation plans and providing thorough reports
Collaborate with Detection Engineering, Intelligence, Research, and Product Management teams to develop new approaches to threat remediation
Zscaler provides a cloud-native Zero Trust Exchange platform that secures users, devices, and applications from cyberattacks and data loss. They foster a culture of transparency, collaboration, and customer obsession with a focus on impact and accountability.
Own attribution for the most complex parts of the crypto ecosystem and set the analytic standard.
Design and lead AI/automation to scale attribution across the team.
Mentor analysts and shape collection strategy to feed products and customers.
Chainalysis is a blockchain data platform that helps organizations investigate illicit activity and manage risk. They have a globally distributed team with a culture of high standards, collaboration, and innovation.
Build the Security Telemetry and Risk Fabric to design layered control implementations and shift from reactive monitoring to self-healing security.
Architect Universal Identity and Access Automation, including provisioning connectors and secret discovery to eliminate manual workflows.
Partner across Security, Engineering, and Product to build custom automation for compliance with various audit frameworks.
ClickHouse is a fast-growing private cloud company recognized on the 2025 Forbes Cloud 100 list, leading the market in real-time analytics, data warehousing, observability, and AI workloads with over 3,000 customers. The company has grown ARR over 250% year over year, recently raised a $400M Series D, and counts Meta, Sony, and Tesla among its customers.
Monitor the threat landscape and deliver actionable intelligence through Flash Reports.
Administer the Threat Intelligence Platform and automate intelligence collection with Python.
Support incident response and collaborate on Purple Team exercises to improve defenses.
GitLab provides an intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and improve security. With over 50 million users and more than 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Own security technical controls including SIEM, vulnerability management, cloud hardening, and secrets management.
Manage security-critical IT operations including endpoint hardening and SaaS app security.
Drive security program and compliance by automating evidence collection and implementing technical controls.
CollegeVine deploys powerful AI agents in complex, regulated industries, starting with higher education to automate administrative workflows. The company is a venture-backed, fully remote startup with a diverse team based primarily in the US and worldwide.