Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.
Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.
Define security requirements and design application architectures following a secure-by-default approach.
Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.
Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.
Identify and remediate vulnerabilities across the product ecosystem using code reviews and automation.
Integrate security tools and practices into CI/CD pipelines to ensure secure development.
Collaborate with engineering teams to apply threat modeling and secure-by-design principles.
They are a partner company specializing in digital product security. The team size is not specified, but the culture emphasizes trust, collaboration, and remote work.
Conduct technical research on new blockchain and DeFi projects to identify architecture risks and security gaps.
Deconstruct attack logic and exploit techniques to develop actionable detection rules and security strategies.
Collaborate with the wallet team to implement security measures balancing robust protection with user experience.
Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange by trading volume and registered users. They are trusted by over 300 million people in 100+ countries and offer a diverse, inclusive work environment with a flat structure.
Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.
RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.
Develop and maintain a multi-platform implant in Rust for Windows, Linux, and macOS.
Build C2 infrastructure, post-exploitation modules, and AV/EDR evasion techniques.
Design network pivoting and tunneling capabilities, and write integration tests.
Horizon3 is a cybersecurity company that provides the NodeZero autonomous pentesting platform to help organizations find and fix exploitable attack vectors. They are a remote team of former U.S. Special Operations cyber operators and engineers, committed to a culture of respect, collaboration, and ownership.
Take ownership of protecting product, users, and collaborators as a Security Engineer on a fast-growing AI dating platform.
Perform weekly code reviews, coordinate security audits, and maintain risk register to ensure safety of AI-generated content.
Monitor emerging AI security threats, manage IT access and device security, and run phishing simulations company-wide.
EverAI builds the world's largest AI companionship platform, redefining relationships for millions with a proprietary moderation system, EverGuard. With 50 million users in two years, the team of about 100 is enthusiastic, passionate, and hardworking, led by experienced entrepreneurs.
Perform hands-on security testing and code review across web applications and APIs.
Conduct threat modeling and embed secure development practices into the SDLC.
Build and tune security tooling, including SAST, DAST, and CI/CD automation.
Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.
Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.
Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.
Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.
Conduct security reviews and penetration tests across Brave products including the browser and search engine.
Triaging and fixing security reports, and designing secure code in C++ and other languages.
Work asynchronously with a geographically-distributed team to secure AWS infrastructure and web security models.
Brave builds a privacy-focused web browser that blocks trackers and ads, a private search engine, a crypto wallet, and an opt-in private ad network. With over 110 million monthly active users and a small, distributed team, Brave is dedicated to protecting user privacy and challenging Big Tech.
Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.
Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.
Own the architectural integrity of the product and stand behind every shipment.
Take responsibility for code quality, security, and scalability across AI-generated code.
Build hands-on with AI development tooling, moving at pilot pace and hardening for scale.
Instructure creates intuitive products that simplify learning and personal development. They are a public company with a culture focused on empowering smart, creative people to innovate.
Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.
Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.