Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Information SecurityApplication SecurityISO 27001KubernetesCloud Security
Lead the development and implementation of security strategies, policies, and procedures.
Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.
Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.
Design, implement, and maintain security controls across AWS environments, including IAM, VPC, encryption, and logging.
Integrate security checks into CI/CD pipelines and harden Kubernetes/EKS workloads using Terraform and policy-as-code.
Automate vulnerability management, security monitoring, and incident response to reduce cloud and application risk.
Electric Power Engineers provides consulting expertise and energy intelligence software solutions for power and energy clients, focusing on modern, secure, and resilient grid challenges. They are leaders in the renewables space and emphasize collaboration, innovation, and making an impact on communities and the environment.
You will own end-to-end data protection: architecting security infrastructure, managing PCI/SOC2 programs, and setting the security roadmap.
You will integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and harden containerized and cloud-native environments.
You will configure IAM and SSO platforms, manage EDR/DLP/SIEM tooling, and run security awareness training.
Campminder builds software for summer camps, enabling meaningful experiences for kids. With over 100 employees, they are stable, profitable, and have a values-led culture committed to work/life balance.
Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.
EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.
Own the full technology and security remit, including enterprise infrastructure, security, identity, applications, and workplace technology.
Lead and grow three functions: IT & Security Operations, Cloud Platform Engineering, and GRC.
Mature security operations with automation and serve as customer zero for the company's own platform.
UpGuard builds a Cyber Risk Posture Management platform that integrates security ratings, threat intel, and agentic AI to help organizations manage cyber risk. They are a certified Great Place to Work with a lean, high-growth culture and a global remote team.
Take ownership of information security governance, including policies, risk registers, and control documentation.
Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
Lead incident response, compliance support, and serve as primary counterpart to the vCISO.
Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.
Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.
Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.
Improve security design and controls within GCP and Kubernetes.
Champion secure development by integrating security best practices early into the software development lifecycle.
Build and automate security tooling for vulnerability detection, remediation, and compliance verification.
Virta Health is a healthcare company that reverses type 2 diabetes and obesity through individualized nutrition and clinical support. They have raised over $350 million from top-tier investors and partner with major health plans, employers, and government organizations.
Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
Monitor and respond to security incidents, tuning WAF policies and security rulesets.
Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.
EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.
Lead and scale the product security program, defining strategy, roadmap, and metrics in alignment with company objectives.
Build and mentor a high-performing product security team, fostering technical excellence and sustainable execution.
Partner with engineering and product leaders to embed security throughout the software development lifecycle, leveraging AI and automation.
Tines provides an intelligent workflow platform that applies AI, automation, and integration to drive business results. Founded in 2018 with co-headquarters in Dublin and Boston, the company serves a diverse range of customers and fosters a culture of Simplicity, Speed, and Soundness.
Design and build secure CI/CD pipelines with integrated security tooling to accelerate product delivery.
Harden cloud infrastructure on AWS and Azure using infrastructure-as-code and enforce policy with OPA or Sentinel.
Lead threat modeling, incident response, and mentor engineers on secure coding and operational security.
PAR Technology provides software and hardware solutions for over 100,000 restaurants in 110+ countries. A publicly traded company with a focus on innovation and collaboration, it fosters a culture of continuous improvement.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.
Support day-to-day information security operations and maintain strong operational security posture across the platform.
Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.
The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.
Lead coordination and implementation of a comprehensive information security program, including policies, processes, and technical controls.
Assess security threats, evaluate emerging technologies, and develop countermeasures to protect sensitive systems and data.
Collaborate across teams to translate risks into practical strategies and ensure compliance with security regulations and privacy laws.
This organization protects critical technology and information systems across internal IT, e-commerce, web, and cloud environments in the healthcare sector. It fosters a mission-driven, inclusive culture with employee resource groups and career development programs.
Define and implement the data security framework for the lakehouse, including RBAC, ABAC, and column/row-level security.
Lead compliance programs for applicable regulations: GDPR, CCPA, HIPAA, SOC 2, PCI-DSS.
Conduct data risk assessments and threat modeling for platform components and data pipelines.
Dynata is the world's largest first-party data and insights platform, serving nearly 6,000 customers globally. The company fosters a collaborative, inclusive culture focused on inspiration, excellence, and employee growth.
Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.
The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.
Own and build Flodesk's security program end to end, including policies, controls, and governance.
Lead SOC 2, ISO 27001, and CCPA readiness while partnering with engineering on secure development.
Manage IT operations, vendor vetting, and security tooling to scale the program.
Flodesk is a fast-growing email marketing company that helps creators and small businesses design emails and monetize their email lists. It is a remote-first company with a globally distributed team and offices in San Francisco, Menlo Park, and Da Nang.
Develop and execute enterprise cybersecurity strategy and multi-year security roadmap.
Lead cybersecurity risk management, security operations, and incident response programs.
Ensure compliance with HIPAA, HITRUST, NIST, and other regulatory frameworks.
Mom's Meals provides home-delivered meal solutions for individuals with health needs. The company values its team members and offers a generous benefits package.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.