Conduct third-party security assessments and evaluate vendor security controls to manage risk.
Build and maintain automation using Python and agentic coding tools to replace manual GRC workflows.
Partner with cross-functional teams including Procurement, Legal, Engineering, and Compliance on risk-informed decisions.
Affirm is a financial technology company that reinvents credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without hidden fees. It is a remote-first company with a culture focused on innovation and engineering-driven security.
Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
Build security tooling and automation, contributing to development of internal applications and scripts.
Execute incident response efforts by identifying, investigating, and remediating security incidents.
BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.
Review vendor SOC 2 reports, security questionnaires, and penetration-testing evidence.
Identify risks and inconsistencies to improve AI-generated security assessments.
Develop evaluation rubrics and golden responses for security evaluations.
Jobgether is a job platform that uses AI-powered matching to connect candidates with opportunities. They emphasize efficiency and fairness in the hiring process, partnering with companies to manage applications.
Partner with product and engineering teams to identify application security risks and recommend mitigations.
Read application code, configuration, and pull requests to understand security risks and suggest improvements.
Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.
Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Write code for automations that support security requirements like threat detection and incident containment.
Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.
Lead the GRC strategy, shifting from bureaucratic to strategic enabler focused on real business risk.
Manage cyber risk quantification, third-party risk, and continuous compliance programs.
Oversee information security governance, AI governance, and IAM governance, reporting to the CISO.
Grupo QuintoAndar is the largest real estate ecosystem in Latin America, covering all phases of the housing journey. The company is valued at over USD 5.1 billion, with a culture of innovation, collaboration, and high performance working with top professionals.
Act as a trusted advisor to business leaders, bridging security risks and business priorities.
Lead security assessments, risk reviews, and remediation planning for new products and enterprise changes.
Maintain clear visibility of security risk, control health, metrics, and dashboards, escalating when needed.
Experian is a global data and technology company, powering opportunities for people and businesses around the world. With a team of 25,200 people in 32 countries, they foster an inclusive, purpose-driven culture and have been recognized as a World's Best Workplace in 2025.
Monitor and investigate security alerts across cloud, identity, endpoint, and network environments.
Write scripts to automate repetitive security tasks and support incident response.
Work with internal teams to identify risks and support remediation, compliance, and audit activities.
Cision is a global leader in PR, marketing and social media management technology and intelligence, helping brands connect with customers and stakeholders. They have offices in 24 countries and a network of over 1.1 billion influencers, committed to diversity and inclusion with a "Top Diversity Employer" designation.
Monitor security events and provide technical analysis on alerts
Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives
Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.
Run day-to-day third-party risk reviews, collecting vendor security documentation and drafting assessment summaries.
Manage vendor follow-up communications and support procurement requests, including migrating workflows to a new system.
Use AI tools to assist with daily tasks and document AI-assisted processes to enhance security and compliance operations.
Branch is on a mission to make insurance more accessible by using data, tech, and automation to simplify the insurance process. The company is remote-first with a collaborative culture, offering flexible time off and stock options.
Automate governance, risk, and compliance frameworks including ISO 27001, PCI-DSS, DORA, and UK Cyber Essentials.
Engineer GRC workflows with internal systems to support compliance by design.
Translate compliance requirements into technical specifications for engineering teams and non-technical stakeholders.
Pleo builds spend solutions that make managing money seamless for finance teams and employees. They are a driven, progressive team of 850+ people from over 100 nationalities, committed to delivering the future of business spending.
Lead the Trust Risk Program to drive risk-based decisions across security, privacy, trusted AI, and resilience.
Guide product and engineering teams in proactive risk management and develop AI-enabled modernization strategies.
Establish enterprise mechanisms for mitigation accountability and communicate program health to executives.
Autodesk creates software that powers the design and making of everything from buildings to movies. The company fosters a culture of belonging and innovation, with a global team dedicated to transforming how things are made.
Lead security architecture across AWS and colocation, defining secure patterns and controls.
Partner with engineering teams to threat model, review designs, and promote secure-by-design.
Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.
NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.
Own the security program day-to-day, pursuing ISO 27001 certification and FedRAMP readiness.
Manage GRC tool (Vanta), maintain SOC 2 Type II, and run vendor security reviews.
Answer customer security questionnaires and ensure compliance documents are accurate.
Massed Compute is building a modern GPU cloud platform for AI and high-performance compute workloads. We are a lean, ambitious team operating in one of the most important technology markets in the world.
Take ownership of the information security program, lead the IT team, and collaborate with engineering on deep technical work.
Own SOC 2, Vanta, governance, IT/TechOps, vendor diligence, SIEM, vulnerability management, and cloud security.
Partner with the CTO and AI Labs to build security capabilities and automate with AI tooling.
We are a Forbes Fintech 50, SHRM-backed company tackling employer talent retention and the student debt crisis. We are a Series B startup with a strong technical team, enterprise customers, and a high security bar.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
Own the full technology and security remit, including enterprise infrastructure, security, identity, applications, and workplace technology.
Lead and grow three functions: IT & Security Operations, Cloud Platform Engineering, and GRC.
Mature security operations with automation and serve as customer zero for the company's own platform.
UpGuard builds a Cyber Risk Posture Management platform that integrates security ratings, threat intel, and agentic AI to help organizations manage cyber risk. They are a certified Great Place to Work with a lean, high-growth culture and a global remote team.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.
Lead secure design reviews, threat modeling, and risk assessments for AI-driven products and APIs.
Embed security practices throughout the software and AI development lifecycle.
Architect and enforce security controls for AI/ML systems and cloud-native infrastructure.
AlphaSense provides AI-driven market intelligence and search platform trusted by over 6,000 enterprise customers. Founded in 2011, the company has more than 2,000 employees globally with offices in multiple countries.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.