Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.
Fast-growing B2B SaaS company serving the life sciences and pharma space. A small, high-impact security team with an engineering-first mindset, building AI-native features.
Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.
The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.
Protect cloud infrastructure, applications, and customer data across a modern technology environment.
Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.
Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.
Lead the technical vision for platform hardening across AWS and GCP, including tier-0 access and secrets services.
Own the hardening roadmap for critical cloud infrastructure and drive operational excellence with rigorous on-call practices.
Mentor a global team of engineers and partner cross-functionally to build secure-by-default controls.
DoorDash is a technology and logistics company building the most reliable delivery network for consumers, merchants, and dashers. The company is growing rapidly and fosters a culture of learning, customer obsession, and inclusive leadership.
Conduct AWS security reviews and validate best practices across the cloud environment.
Implement security improvements and fix custom-built security tools with the Lead Security Architect.
Participate in on-call rotation to ensure 24/7 system availability for customers.
Mapbox is the leading real-time location platform powering location-aware businesses with maps, navigation, and location data tools. With over 4 million registered developers and a globally distributed team, Mapbox fosters a culture of flexibility, security, privacy, and inclusion.
Design and implement backend services for licensing, entitlements, feature access, and usage limits across NodeZero's product and APIs.
Build and evolve provisioning, admin experience, MSP/MSSP capabilities, and audit logging for a multi-tenant SaaS platform.
Operate production services with monitoring, incident response, and a high bar for design quality and test coverage.
Horizon3 is a fast-growing, remote cybersecurity company that helps organizations proactively find, fix, and verify exploitable attack vectors through its NodeZero autonomous pentesting platform. The team is a fusion of former special operations cyber operators and startup engineers, fostering a culture of respect, collaboration, ownership, and results.
Own cloud and product security across AWS and GCP, setting baselines for IAM, networking, data protection, and workload configuration.
Partner with platform, SRE, and product teams to embed practical security controls into developer workflows and automate guardrails in delivery pipelines.
Perform security architecture reviews, threat modeling, and incident response, and drive systemic improvements with meaningful security metrics.
We create intelligent software development tools used by more than 15 million users and 300,000 companies, including 88 of the Fortune Global Top 100. Our mission is to make development teams more productive and AI adoptable at scale, and we foster an open and inclusive workplace.
Design, prototype, and deploy technical controls to close high-impact abuse vectors.
Translate empirical attacker evidence into precise technical requirements and control specifications.
Collaborate with cross-functional teams to run experiments and build regression testing suites.
Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments and grow revenue. It is a large company with a mission-driven culture focused on increasing the GDP of the internet.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.
Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.
Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
Build offensive tooling, develop exploits, and support incident response and security education.
Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.
Develop playbooks and address security-related tasks in AWS serverless environments.
Drive improvements in security posture, including application, endpoint, and access management.
Collaborate with product engineering teams to raise the bar for security in CI/CD, dependency management, and secure design reviews.
Stedi is building a new healthcare clearinghouse and RCM engine, accessible via API. With $142 million in funding and a lean, passionate team, they ship products weekly and prioritize automation and eliminating toil.
Lead the development, implementation, and ongoing maintenance of comprehensive security strategies and solutions.
Design and deploy advanced security controls to protect the business across disciplines.
Mentor and galvanize engineers to uphold security process standards.
Aledade PBC empowers independent primary care practices, helping them deliver better care and thrive in value-based care. Founded in 2014, Aledade has become the largest network of independent primary care in the US, with a collaborative, remote-first culture.
Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.
Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.
Build and operate backend systems that support accurate customer outcomes after financial transactions.
Collaborate with cross-functional teams including product, design, analytics, and compliance.
Contribute to system reliability, monitoring, and on-call responsibilities.
The company builds high-scale backend systems for accurate financial transaction processing. They have a remote-first, collaborative engineering culture with a focus on reliability and operational excellence.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Own and improve the organization's SIEM, including threat detection, alert tuning, and incident response.
Conduct security architecture reviews, code reviews, and infrastructure assessments to identify and remediate risks.
Build scalable security processes and integrate security practices into development workflows across cloud and container environments.
This company is a fast-moving technology organization focused on building secure and scalable software systems. It fosters a high-ownership, remote-first culture where experienced professionals collaborate with high-caliber engineering teams.
Implement and maintain AWS security configurations across development, staging, and production environments.
Operate SAST, DAST, and SCA tools integrated into CI/CD pipelines to remediate vulnerabilities.
Support compliance efforts such as SOC 2 Type II and ISO 27001 audits and improve security processes.
Pacvue is a leading software suite for eCommerce advertising, sales, and intelligence, helping brands grow on Amazon, Walmart, Instacart, and other marketplaces. The team is energetic, passionate, and focused on innovation, with a mission to help brands and sellers succeed.
Design, build, and maintain production features with a strong product security focus.
Own vulnerability response from initial triage through coordinated disclosure and patched releases.
Conduct threat modeling and security-sensitive design reviews to help engineers make informed security decisions.
This company builds cloud-native infrastructure software with a strong focus on Kubernetes security. They operate as a remote-first, globally distributed team that values engineering ownership and autonomous work.
Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
Perform security assessments, vulnerability remediation, and lead key security programs.
Automate security processes and integrate DevSec practices into the software development lifecycle.
Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.
Lead and grow a team of security engineers focused on protecting cloud-native environments and CI/CD pipelines.
Drive technical strategy, threat modeling, and security automation across multi-cloud infrastructure.
Partner with engineering and DevOps teams to embed secure-by-design principles and manage vulnerability and supply chain security.
Wiz is a cybersecurity company that provides a cloud security platform connecting code, cloud, and runtime to secure cloud and AI applications. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, and now powered by Google, with a culture that values world-class talent.