Own cybersecurity compliance for connected hardware products, including RED, EN 18031, and CRA.
Perform threat modeling, security validation, and manage vulnerability risks across firmware, cloud, and devices.
Collaborate with engineering teams to integrate security early and translate technical findings into compliance evidence.
Nabu Casa builds cloud services and hardware for the open-source Home Assistant smart home platform. It is a profitable, fully remote company with no external investors, funded by users, and supports several open-source projects.
Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
Own application security, threat modeling, and vulnerability disclosure from design review to production.
Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.
Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Own end-to-end architecture of hardware safety and power management systems, designing safe-state strategies and power sequencing across multiple cores and PMICs.
Implement low-level drivers and firmware for safety-critical integrated circuits directly from datasheets, ensuring bug-free and testable code on bare metal and FreeRTOS.
Lead development of hardware-software safety diagnostic frameworks, integrating TI Safety Diagnostic Library to map diagnostic coverage to ISO 26262 hardware fault metrics.
Latitude AI develops L3 automated driving technology for Ford vehicles. It is a Ford subsidiary with engineering centers in Pittsburgh, Dearborn, and Palo Alto.
Design, develop, and optimize firmware for embedded systems, ensuring reliability and efficiency.
Collaborate with hardware teams to implement firmware solutions for wireless embedded designs and communication interfaces like Bluetooth, LoRa, or LTE.
Conduct debugging, testing, and firmware updates in rugged, mission-critical environments to meet defense-grade standards.
LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed. The company serves defense, space, healthcare, and energy sectors, with a focus on agility and collaboration.
Build and harden secure CI/CD pipelines with security gates to catch issues before production.
Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS.
Harden container images, Kubernetes configurations, and cloud IAM to minimize attack surface.
Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises, with a culture that values customer obsession, intentional action, and trust.
Own the end-to-end hardware architecture for Outpost kiosks and site technology systems, from design to deployment and fleet management.
Develop reference designs covering edge compute, networking, power, cameras, and access systems, ensuring reliability and recoverability.
Partner with cross-functional teams to validate designs, troubleshoot failures, and establish standards for a growing distributed deployment.
Outpost is building the backbone of freight by reinventing supply chain infrastructure with carrier agnostic truck terminals. They are a vertically integrated real estate, operations, and technology company backed by $1B, with a small, high-conviction team.
Develop firmware for millions of IoT devices, including battery-powered sensors, Linux gateways, and dashcams.
Own peripheral drivers, secure bootloaders, and device firmware updates for field-deployed hardware.
Collaborate with electrical engineers on hardware bring-up and optimize power consumption for extended device life.
Samsara is the pioneer of the Connected Operations Cloud, enabling organizations to harness IoT data for actionable insights. As a public company with a global team, Samsara fosters a high-caliber, hyper-growth culture focused on safety, efficiency, and sustainability.
Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
FirstPrinciples is a research company building AI for scientific discovery. We're a fast-growing, remote-first team of builders, researchers, engineers, and thinkers working across Canada, the US, the UK, and expanding globally.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Develop and maintain embedded firmware supporting secure communications and cryptographic functionality.
Integrate and optimize use of the nRF54L Series AES-256 hardware accelerator within embedded firmware.
Design, implement, and validate secure key management capabilities for embedded devices.
LMI is a digital solutions provider accelerating government impact with innovation and speed. Headquartered in Tysons, Virginia, the company serves defense, space, healthcare, and energy sectors with a focus on agility and collaboration.
Lead a team of Security Engineers, providing decision-making support and enabling them to deliver security consulting to the wider business.
Work directly with Product & Technology teams to assist in how our platform is built and how applications behave, supporting everything from user security to internet connectivity.
Have significant impact on security of systems used by thousands of firefighters, paramedics, and hospitals worldwide.
ESO is a data, technology, and research company passionate about improving community health and safety through the power of data. We serve thousands of customers out of our offices across the US, Canada and Northern Ireland, and we are small enough to be nimble and fun but big enough to be a great place to work.
You will own KPA's enterprise security platforms and lead technical security initiatives.
You will manage vulnerability remediation, endpoint security, identity security, and incident response.
You will secure cloud environments across Azure, AWS, and Microsoft 365, integrating security into CI/CD pipelines.
KPA provides compliance and risk management software for the automotive and equipment industries. The company values trust, innovation, excellence, and results, fostering a collaborative culture with a team of security and IT professionals.
Lead security architecture across AWS and colocation, defining secure patterns and controls.
Partner with engineering teams to threat model, review designs, and promote secure-by-design.
Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.
NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.
Extend Airwall onto new devices and hardware targets, owning embedded software on constrained platforms like OpenWRT and ARM.
Work deep in the secure data path: identity-based overlay networking, IPsec, IKE, tunnel encapsulation, and PKI.
Diagnose hard networking failures in live customer environments with packet-level analysis and mentor engineers across the team.
Johnson Controls is a global leader in thermal management, mission-critical building systems, and decarbonization, serving industries like data centers and healthcare. With over 140 years of history, the company employs a large field organization and emphasizes innovation and sustainability.
Act as certification expert for security (SESIP, FIPS 140-3, PSA) and safety (ISO 26262, IEC 62443) standards.
Optimize PQShield's certification strategy and manage the entire certification process with test labs and stakeholders.
Interact with architects and product security teams to advise on requirements and prototype soft IP into certifiable products.
PQShield is a deep tech startup developing post-quantum cryptography and secure semiconductor IP. They work with founders and inventors to bring advanced RISC-V based security solutions to market, with a collaborative team environment.