Conduct third-party security assessments and evaluate vendor security controls to manage risk.
Build and maintain automation using Python and agentic coding tools to replace manual GRC workflows.
Partner with cross-functional teams including Procurement, Legal, Engineering, and Compliance on risk-informed decisions.
Affirm is a financial technology company that reinvents credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees. It is a remote-first company with a culture focused on innovation and engineering-driven security.
Build and maintain automation using Python and agentic coding tools to reduce manual GRC workflows.
Partner with Procurement, Legal, Engineering, and other teams on risk reviews and risk-informed decisions.
Affirm is a financial technology company that offers buy now, pay later services. The company values security as critical to its success and has a culture focused on engineering-driven risk management.
Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
Answer customer security questionnaires and ensure compliance documents are accurate.
Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.
Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.
Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.
Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.
EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.
Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
Engineer GRC workflows with internal systems to support compliance by design.
Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.
Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.
Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.
Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.
Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.
A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.
Own CI/CD and infrastructure design across application teams, using agentic AI to build and validate pipelines.
Implement security, testing, and observability as designed-in requirements across all shipped products.
Collaborate with DevSecOps peers to build shared standards and coach engineers on AI-driven development practices.
ComPsych is the worldwide leader in organizational mental health, well-being, and absence management. Their solutions touch more than 160 million lives across 200 countries, and 40% of the Fortune 500 choose them.
Monarch is an all-in-one personal finance platform that simplifies finances. Since 2021, they have become the top-recommended app, with a fully remote, AI-driven team focused on building a product people love.
Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.
Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.
Add security tooling and checks to CI/CD pipelines with Python automation.
Perform offensive testing, triage findings, and patch straightforward vulnerabilities.
Collaborate with engineers, DevOps, and Fraud while leveraging AI for security work.
Super.com is a high-growth tech company helping people save, earn, and get more out of life. They are a remote-first, collaborative team that has hosted over 100 engineering internships and values career progression.
Design, implement, and maintain security controls across AWS environments, including IAM, VPC, encryption, and logging.
Integrate security checks into CI/CD pipelines and harden Kubernetes/EKS workloads using Terraform and policy-as-code.
Automate vulnerability management, security monitoring, and incident response to reduce cloud and application risk.
Electric Power Engineers provides consulting expertise and energy intelligence software solutions for power and energy clients, focusing on modern, secure, and resilient grid challenges. They are leaders in the renewables space and emphasize collaboration, innovation, and making an impact on communities and the environment.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Build agent-driven workflows for cloud security platforms like FedRAMP High Cloud-Native SIEM and Tier 1 Agentic SOC.
Develop autonomous AI tools including triage, investigation, and reporting agents using agentic AI frameworks.
Translate complex systems requirements into production-ready AI solutions following AWS Well-Architected and NIST security controls.
First Due provides transformative, end-to-end software solutions for fire and EMS agencies to improve safety and effectiveness. The company offers a comprehensive benefits package and promotes a fully remote, inclusive work environment.
Assist customers with application security testing tool configurations and triage support.
Lead AppSec Program maturity assessments using frameworks like BSIMM and SSDF.
Develop Strategic Roadmaps and deliver presentations to executive leadership.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. It is a recognized pioneer in application security, providing SAST, SCA, and DAST solutions.
Own the security boundary of Percy, including vault enclave and sandbox isolation for AI agents processing live PII.
Assess and harden encryption, key management, access control, and the append-only audit ledger across AWS Nitro Enclaves.
Drive product-security controls for SOC 2, PCI DSS, and GDPR audits, and run technical pentests.
Footprint builds Percy, an AI agent that automates financial crime investigations for banks and fintechs. Backed by QED, Index, and Box Group, the company is small, senior, and ships fast, having 5x'd revenue last year.