Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.
Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Research and remediate prioritized security vulnerabilities in PHP code, including injection, authentication, and deserialization defects.
Perform AWS-side remediation and deployment, including configuration hardening, IAM adjustments, and secret rotation.
Validate fixes with automated tests and document closure evidence for the client's risk program.
CI&T helps large enterprises transform the potential of AI into real business impact with AI deployment, AI-native execution, and tech-integrated business solutions. With 30 years of experience and 8,000 employees across more than 25 countries, the company fosters a collaborative culture focused on building secure, resilient software.
Develop and maintain tools to empower communities to identify and mitigate abuse across Wikimedia projects.
Design privacy-conscious systems to detect abusive behavioral patterns while respecting user anonymity.
Collaborate cross-functionally to create holistic, human-centered solutions that balance safety and freedom.
The Wikimedia Foundation is the nonprofit organization that operates Wikipedia and the other Wikimedia free knowledge projects. It is a remote-first organization with staff in over 40 countries, dedicated to providing free access to knowledge for all.
Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.
Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.
Own threat modeling and secure code reviews for new products and features.
Maintain and tune AppSec tooling, and run the bug bounty program.
Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.
Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.
Build production-grade security applications and services using Python.
Develop internal security platforms and tooling from scratch.
Design and enforce secure cloud architectures (AWS) and implement policy enforcement for IAM least-privilege models.
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. They are trusted by 300+ million people in 100+ countries and have a diverse workforce.
Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
Build security tooling and automation, contributing to development of internal applications and scripts.
Execute incident response efforts by identifying, investigating, and remediating security incidents.
BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Lead threat modeling and secure design reviews across C++, Go, and Rust
Build and tune application security testing (SAST, SCA, secret scanning, DAST) and fuzzing harnesses
Operate PSIRT and build security champions program to raise the security bar
Redpanda is a unified platform for agent-data interaction, combining streaming, SQL analytics, and intelligent connectivity with governance for enterprise AI agents. It is a fast-moving, people-first organization with a small, high-trust security team and team members across the globe.
Build and harden secure CI/CD pipelines with security gates to catch issues before production.
Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS.
Harden container images, Kubernetes configurations, and cloud IAM to minimize attack surface.
Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises, with a culture that values customer obsession, intentional action, and trust.
Lead end-to-end response to product security incidents, from discovery to disclosure.
Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
Drive coordinated vulnerability disclosure and partner with external security researchers.
1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.
Partner with product and engineering teams to identify application security risks and recommend mitigations.
Read application code, configuration, and pull requests to understand security risks and suggest improvements.
Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.
Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.
Build fraud detection and risk decisioning systems, rule engines, and scoring pipelines.
Create investigation tooling for the Trust & Safety ops team to triage and resolve cases.
Mentor team members in Trust & Safety domain expertise and code reviews.
Givebutter is the most-loved nonprofit fundraising and CRM platform, empowering changemakers to raise more, pay less, and give better. It has been certified as a Great Place to Work since 2021 and is the #1 rated nonprofit software company on G2.
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Write code for automations that support security requirements like threat detection and incident containment.
Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.
Design, build, and maintain services for user controls, identity, and security.
Build secure content sharing and internal analytics tooling.
Contribute to Dgraph internals and collaborate with platform teams.
Istari Digital develops a data platform for identity, security, and content sharing. The company fosters an outcomes-driven culture with a flat hierarchy and mutual respect.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
Contribute to security architecture reviews and support bug bounty programs and incident response.
Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.
Analyze complex Web3 security cases to extract recurring attack patterns and build comprehensive SOPs.
Proactively identify operational gaps and propose systematic improvements to enhance team efficiency.
Partner with AI agents to crystallize security insights into a high-quality knowledge base for faster response.
Binance is a leading global blockchain ecosystem behind the world’s largest cryptocurrency exchange by trading volume and registered users. Trusted by over 300 million people across 100+ countries, we are a fast-paced, user-centric organization with a flat structure and a focus on innovation.
Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.
Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.