Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.
Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.
Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.
Lead secure design reviews, threat modeling, and risk assessments for AI-driven products and APIs.
Embed security practices throughout the software and AI development lifecycle.
Architect and enforce security controls for AI/ML systems and cloud-native infrastructure.
AlphaSense provides AI-driven market intelligence and search platform trusted by over 6,000 enterprise customers. Founded in 2011, the company has more than 2,000 employees globally with offices in multiple countries.
Lead Application Security initiatives across HighLevel's products and engineering teams.
Conduct architecture reviews, threat modeling, and security assessments for web, mobile, and API applications.
Drive DevSecOps practices by automating security in CI/CD pipelines and managing security tooling.
HighLevel is an AI-powered, all-in-one white-label sales and marketing platform that empowers agencies and businesses to grow their digital presence. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment with a culture rooted in creativity, collaboration, and impact.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.
Lead product security engineering across key verticals, engaging with engineering leadership and technical teams.
Build and automate security design reviews, threat modeling, vulnerability management, and AI-assisted tools.
Serve as a subject matter expert for mobile, API, and cloud security, mentoring engineers and collaborating cross-functionally.
Xplor Technologies powers the experiences at the heart of everyday life through modern vertical software, embedded payments, and AI-powered capabilities. With over 130,000 businesses in 72+ countries and processing over $47 billion annually, we foster a culture of innovation, collaboration, and empathy, guided by core values like 'Find a better way' and 'Win together'.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.
Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.
Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.
Build and lead Attio's Product Security function, securing their AI-native SaaS platform and sensitive customer data.
Work with Engineering Leadership to ensure security by design, mitigating unique risks from AI-driven features and AI-assisted development.
Lead production security incident response, recruiting and retaining a world-class team of Security Engineers and SecOps practitioners.
Attio is the CRM for agentic revenue, designed for ambitious go-to-market teams to understand every customer and automate at scale. They have raised $116M from top investors and hire builders who thrive on complex technical challenges, holding themselves to a high bar and delighting users.
Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.
Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.
Lead a team of Security Engineers, providing decision-making support and enabling them to deliver security consulting to the wider business.
Work directly with Product & Technology teams to assist in how our platform is built and how applications behave, supporting everything from user security to internet connectivity.
Have significant impact on security of systems used by thousands of firefighters, paramedics, and hospitals worldwide.
ESO is a data, technology, and research company passionate about improving community health and safety through the power of data. We serve thousands of customers out of our offices across the US, Canada and Northern Ireland, and we are small enough to be nimble and fun but big enough to be a great place to work.
Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
Lead AI security initiatives including threat modeling and auditing third-party models and APIs.
Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.
Lead security architecture reviews and threat modeling exercises for applications and platforms.
Partner with engineering and product teams to identify risks and recommend mitigation strategies.
Develop security standards, automation, and developer enablement materials to promote secure-by-design practices.
Our partner company is dedicated to building secure digital products through innovative security practices. They offer a collaborative, remote-friendly culture with opportunities for professional growth.
Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
Own application security, threat modeling, and vulnerability disclosure from design review to production.
Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.
Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Act as the primary security partner for the Walrus team, providing architectural guidance and embedding security practices throughout the development lifecycle.
Lead security assessments for new features and contribute to ecosystem-wide security initiatives, identifying systemic risks and actionable remediation plans.
Drive a security-by-design culture, leveraging AI and automation to focus on high-impact, complex security research and mentor engineers.
Mysten Labs builds foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies. They are a well-funded, remote-first team with over $300M in Series B funding from top venture firms, fostering a culture of innovation and growth.