Embed security expertise within software engineering teams to influence product design and development.
Combine software engineering with proactive security practices like threat modeling, static analysis, and fuzzing.
Work extensively with Linux and open source technologies, contributing to upstream projects and strengthening security.
They are a leading open source software company behind Ubuntu, providing secure and scalable solutions. They operate with a globally distributed team, emphasizing collaboration and continuous learning.
Develop and maintain backend features for GitLab's vulnerability management workflows, primarily using Ruby on Rails.
Collaborate with frontend engineers and contribute across the stack when needed, focusing on performance and reliability.
Participate in on-call rotations to assist with troubleshooting product operations and security issues.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and reduce security risk. With over 50 million registered users and more than 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Partner with product and engineering teams to identify application security risks and frame them as clear business risks, launch options, and recommended next steps.
Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The company is remote-first with a people-first culture, offering competitive benefits and equity rewards.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
You cover a broad range of security work including hands-on coding, incident response, and threat hunting.
You review and triage security submissions and bug bounties, and help improve incident response processes.
You communicate security requirements to non-technical teams and support access governance and permission management.
Eneba builds an open, safe, and sustainable marketplace for gamers. They support over 20 million active users and foster a culture of ownership, growth, and collaboration.
United States
Unlimited PTO
18w maternity
12w paternity
Manage a novel vulnerabilities pipeline, owning measurement, disclosure, and reporting of thousands of vulnerabilities weekly.
Coordinate across the industry with bodies like the Linux Foundation and CISA, and represent Chainguard externally.
Guide industry direction and work with AI model vendors to evolve software supply chain security.
Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises and global industry leaders.
Lead architecture and delivery of Linux kernel engineering initiatives across performance, security, and reliability.
Drive technical engagements with silicon and cloud partners to deliver optimized solutions.
Coach and guide engineers while coordinating complex initiatives across teams.
Our partner is a leading technology company focused on developing and maintaining the Ubuntu operating system and Linux kernel. They operate with a globally distributed team and emphasize open-source engineering, autonomy, and collaboration.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Manage vulnerability assessments across operating systems, containers, dependencies, and application environments.
Perform vulnerability triage, validation, and proof-of-concept testing to determine real-world security impact.
Collaborate with engineering teams to communicate risks and drive remediation efforts.
This company provides a large-scale software platform for AI and data science solutions, serving organizations with demanding compliance and risk requirements. It fosters a culture of innovation, transparency, and collaboration, with a growing security function and an inclusive workplace.
Perform hands-on coding and security implementation, incident response, and threat hunting.
Review and triage security submissions, bug bounty reports, and follow up on remediation.
Write and maintain security policies, communicate risks to non-technical teams, and monitor logs for anomalies.
Eneba is building an open, safe and sustainable marketplace for gamers. The company supports close to 20 million active users and fosters a culture of ownership, growth, and collaboration.
Develop, test, and release improvements to the Ubuntu Pro client, a command-line tool managing specialist services on Ubuntu.
Collaborate with distributed teams, write high-quality Python code, debug issues, and review code from other engineers.
Work remotely with global travel 2-4 weeks per year for internal and external events.
Canonical is a leading provider of open source software and operating systems, publishing Ubuntu, a platform for AI, IoT, and cloud. With 1200+ colleagues in 75+ countries, the company is founder-led, profitable, and growing with a pioneering distributed work culture.
Protect applications trusted by millions of users in the Web3 ecosystem.
Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
Embed security throughout the software development lifecycle to build resilient products.
This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.
Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Break things on purpose by threat-modeling and reviewing Solidity contracts, Rust blockchain state transition functions, and other critical systems.
Own protocol components from design review through production, ensuring secure architecture and implementation.
Track the adversary, follow industry hacks and exploits, and convert lessons into concrete improvements.
Matter Labs builds private settlement infrastructure using zero-knowledge cryptography for regulated institutions. They are a fully remote team of about 70, backed by a16z and Union Square Ventures, with eight years of production zero-knowledge infrastructure.
Own major product components and engineering workstreams from discovery to production.
Design scalable architectures and build production-grade software with focus on reliability and security.
Use AI-assisted development tools to improve engineering efficiency.
They develop Linux security products and automation systems. They are a remote-first team emphasizing professional development and challenging technical projects.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Lead threat modeling and secure design reviews across C++, Go, and Rust
Build and tune application security testing (SAST, SCA, secret scanning, DAST) and fuzzing harnesses
Operate PSIRT and build security champions program to raise the security bar
Redpanda is a unified platform for agent-data interaction, combining streaming, SQL analytics, and intelligent connectivity with governance for enterprise AI agents. It is a fast-moving, people-first organization with a small, high-trust security team and team members across the globe.