Source Job

Canada

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Application Security Threat Modeling Vulnerability Management CrowdStrike

20 jobs similar to Lead Incident Security Responder

Jobs ranked by similarity.

US

  • Provide strong leadership as a security thought leader across Delinea's product offerings.
  • Perform end-to-end security architecture reviews and threat modeling.
  • Maintain and mature Product Security tooling such as SAST, SCA, DAST, ASPM.

Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization. They are a global team of passionate problem-solvers, with a culture of innovation, respect, and fairness.

Canada

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
  • Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
  • Contribute to security architecture reviews and support bug bounty programs and incident response.

Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.

$130,000–$170,000/yr
US

  • Partner with product and engineering teams to identify risks early and build security into new features.
  • Lead threat modeling and secure design reviews for new products and architecture changes.
  • Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.

Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

US 5w PTO

  • Own key security domains such as vulnerability management, application security, API security, and supply chain security.
  • Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
  • Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.

NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.

  • Establish secure by design standards and target state security architecture across product development, covering threat modeling, secure design review, and vulnerability management.
  • Build a formal vulnerability management program encompassing traditional and AI-specific threats like prompt injection, model manipulation, and data exfiltration.
  • Provide senior technical leadership and build trusted partnerships across Product, Engineering, and Security teams.

Semperis is a cybersecurity company on a mission to be a Force for Good, protecting identity and data. We are one of America's fastest-growing cybersecurity companies and have been recognized as a top workplace.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

US 16w maternity 16w paternity

  • Participate in team exercises to identify potential security risks, including threat modeling and tabletop scenarios.
  • Plan projects to address prioritized risks and coordinate with cross-functional stakeholders to execute them.
  • Partner with engineering teams to architect secure software and build a strong security culture.

Vanta's mission is to help businesses earn and prove trust by enabling continuous security monitoring and verification. The company has a kind and talented team, and many have been successful without prior security experience.

Australia 14w maternity 6w paternity

  • Design and implement security controls across Mable's platform, applications, and infrastructure
  • Embed security into the software development lifecycle through design reviews, threat modeling, and code reviews
  • Lead vulnerability assessments and coordinate remediation efforts across engineering teams

Mable is one of Australia's leading healthtech platforms connecting people with disability and older Australians with independent support workers. With over 25 million hours of support facilitated since 2014, they have been recognized on AFR's Top 100 and Deloitte Tech Fast 50, fostering a purpose-driven and dynamic team environment.

Canada

  • Design and ship scalable security solutions to bridge the gap between security and engineering teams.
  • Build cooperative partnerships with product and engineering teams to integrate robust security capabilities at scale.
  • Drive security risk reduction through technical leadership, security reviews, and mentorship across engineering teams.

Twilio is a communications platform that delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide to craft personalized customer experiences. The company has a remote-first work culture with a strong focus on connection, global inclusion, and diverse experiences, making a global impact each day.

$129,280–$161,600/yr
US

  • Lead, coach, and develop a team of Security Consultants while driving operational excellence and process improvements.
  • Serve as a subject matter expert in application security, incident response, and vulnerability assessment, and handle complex escalations.
  • Build strong cross-functional partnerships and stay current on security industry standards to continuously improve team capabilities.

Bugcrowd is a crowdsourced security platform that empowers organizations to stay ahead of threat actors by uniting the ingenuity of elite hackers with our patented data and AI-powered Security Knowledge Platform. Based in San Francisco and New Hampshire, Bugcrowd is supported by General Catalyst and Rally Ventures, and we foster a diverse, inclusive culture where we value perspectives from all backgrounds.

EMEA

  • You'll lead the VIPR & VMDR function, integrating vulnerability intelligence, detection, and response for customers across APJ/APAC.
  • You'll operate and tune vulnerability detection tools like Tenable, Qualys, and Rapid7, and automate pipelines using Python and REST APIs.
  • You'll build risk dashboards and executive briefings, and collaborate with Customer Success and Security Engineering to improve remediation metrics.

ServiceNow is the AI control tower for business reinvention, bringing together AI, data, and workflows to help 85% of the Fortune 500 work smarter. The company fosters an AI-native culture where technology and talent are unstoppable together.

US

  • Manage the vulnerability management program end-to-end, including scanning and remediation.
  • Collaborate with developers on secure architecture, threat modeling, and code dependency reviews.
  • Oversee bug bounty programs, security tools, incident response, and compliance frameworks.

RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.

$125,000–$152,000/yr
US

  • Bridge the gap between traditional infrastructure security and modern DevSecOps, defining secure-by-design frameworks and implementing high-impact DevSecOps pipelines across multi-cloud environments.
  • Lead critical security reviews for emerging technologies, including artificial intelligence, and act as a collaborative partner to internal teams fostering proactive security and cyber vigilance.
  • Manage security lifecycles within multi-cloud environments, own the end-to-end vulnerability management program, and leverage SIEM platforms for real-time threat intelligence.

NPR is a thriving, mission-driven multimedia organization that produces award-winning news, information, and music programming in partnership with hundreds of independent public radio stations across the nation. They are innovators and leaders in diverse fields, from journalism and digital media to IT and development, committed to building an inclusive workplace where collaboration is essential and diverse voices are heard.

Canada

  • Deliver compelling technical presentations and live demonstrations of Tenable Enterprise products, focusing on the Tenable One Platform.
  • Manage enterprise software trials and Proof of Concept evaluations, driving successful outcomes aligned with customer business objectives.
  • Answer technical questions and provide consultative guidance on security best practices, compliance frameworks, and risk management.

Tenable is the Exposure Management company, helping over 40,000 organizations globally understand and reduce cyber risk. Their global employees support 65 percent of the Fortune 500, 50 percent of the Global 2000, and large government agencies, fostering a culture of belonging, respect, and excellence.

$145,000–$175,000/yr
United States

  • Strengthen company-wide security posture through hands-on engineering, collaboration, and pragmatic standards, focusing on application security, cloud and infrastructure security, and secure development practices.
  • Define and implement scalable security standards supporting SOC 2 readiness through practical, automated, and auditable solutions, partnering with Engineering, Infrastructure, IT, Product, Legal, and other teams.
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, and operational visibility.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns by combining real creator relationships, trusted intelligence, and expert guidance. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns deliver results.

UK

  • Lead and support the response to all security events and incidents across Twilio's global infrastructure, services, and applications.
  • Work cross-collaboratively to solve challenges related to a broad spectrum of threat actors and improve security posture.
  • Own the security incident lifecycle, participate in on-call rotation, and conduct post-incident betterments.

Twilio shapes the future of communications with innovative solutions for hundreds of thousands of businesses, empowering millions of developers worldwide. The company embraces a remote-first work culture and a strong culture of connection and global inclusion, fostering a vibrant and diverse team.

US

  • Lead implementation and optimization of AppSec tools such as SAST, DAST, and SCA across client environments.
  • Conduct manual application and API security assessments, identifying vulnerabilities and recommending remediation strategies.
  • Advise clients on secure SDLC practices and integrate security tools into CI/CD pipelines.

The company is a cybersecurity consulting firm that helps organizations design and operationalize application security programs. It operates with a remote-first culture and a collaborative, client-facing team.

US Unlimited PTO

  • Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
  • Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
  • Build, maintain, and improve application security tooling and participate in incident response activities.

The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.