Lead security and IT for Cardlytics, overseeing security engineering, IT operations, and compliance for a fully remote team.
Manage SOX/SOC 2 compliance, identity and access management, and cloud security across AWS environment.
Drive AI adoption company-wide while partnering with executives and the board to align security priorities with business strategy.
Cardlytics is a purchase intelligence and incentives platform that helps businesses attract and incentivize consumers through digital reward programs. As a public company (NASDAQ: CDLX) with a lean, high-trust team, they prioritize integrity and growth.
Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
Strengthen security monitoring, detection, incident response, and integrate security into CI/CD pipelines.
Support compliance efforts including SOC 2 and ISO audits, and lead customer security reviews.
AlertMedia helps organizations protect their people, operations, and brand with a modern Risk Intelligence and Response platform. It is a high-growth, PE-backed SaaS company with more than 4,000 clients and a 10-year award-winning culture.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.
Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.
Threat-model and adversarially test multi-tenant isolation, identity/access, and application security for a patent intelligence platform.
Drive SOC 2 Type II readiness by mapping controls and coordinating evidence collection via Drata.
Build incident-response plans, coordinate third-party pen tests, and hand over a prioritized remediation backlog.
Labrynth builds AI-powered platforms to navigate complex regulations, serving clients in energy, compliance, and government. The company operates as a small, high-velocity engineering organization with forward-deployed teams.
Own cloud and platform security end to end across AWS and Azure, including architecture, detection, and response.
Build self-serve security tooling and guardrails to replace manual processes and reduce risk.
Partner with engineering teams to embed security into CI/CD pipelines and product development.
Ada is an AI customer service platform that enables enterprise companies to deliver instant, proactive, and personalized customer experiences. Established in 2016, the Canadian company has powered over 5.5 billion interactions for brands like Square and YETI, backed by over $250M in funding from top-tier investors.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity.
Lead security architecture across AWS and colocation, defining secure patterns and controls.
Partner with engineering teams to threat model, review designs, and promote secure-by-design.
Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.
NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Design and enforce least-privilege IAM architectures, network segmentation, and cloud security controls across multiple AWS accounts.
Build automated detection and response pipelines using AI tools for fast, actionable remediation.
Own vulnerability management, HIPAA compliance, and lead cross-functional security initiatives.
Chamber Cardio is rebuilding the cardiology system to focus on outcomes, partnering with independent cardiologists with technology, data, and operational tools. They are a mission-driven team combining clinical expertise, design, and a modern operating platform, with a culture of low ego, empathy, courage, ownership, and grit.
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Write code for automations that support security requirements like threat detection and incident containment.
Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.
You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
You will run the vulnerability management program and remediate security findings across AWS.
You will support security incident response, fraud investigations, and third-party risk assessments.
We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Lead secure design reviews, threat modeling, and risk assessments for AI-driven products and APIs.
Embed security practices throughout the software and AI development lifecycle.
Architect and enforce security controls for AI/ML systems and cloud-native infrastructure.
AlphaSense provides AI-driven market intelligence and search platform trusted by over 6,000 enterprise customers. Founded in 2011, the company has more than 2,000 employees globally with offices in multiple countries.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.
Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.
Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.
Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.
Operate and sustain Chainguard’s technology platforms (cloud, IAM, and AI) and help implement access controls and identity policies.
Support the hardening and monitoring of cloud infrastructure, assist in securing AI/ML pipelines, and troubleshoot systems.
Document processes, contribute to runbooks, and adapt to shifting priorities while learning security best practices.
Chainguard delivers hardened, secure, and production-ready builds of open source software. It is a venture-backed late-stage startup with Fortune 500 customers including Anduril, Canva, and OpenAI.