Perform hands-on coding and security implementation, incident response, and threat hunting.
Review and triage security submissions, bug bounty reports, and follow up on remediation.
Write and maintain security policies, communicate risks to non-technical teams, and monitor logs for anomalies.
Eneba is building an open, safe and sustainable marketplace for gamers. The company supports close to 20 million active users and fosters a culture of ownership, growth, and collaboration.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.
Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
Build security tooling and automation, contributing to development of internal applications and scripts.
Execute incident response efforts by identifying, investigating, and remediating security incidents.
BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.
Lead end-to-end response to product security incidents, from discovery to disclosure.
Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
Drive coordinated vulnerability disclosure and partner with external security researchers.
1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.
Monitor security events and provide technical analysis on alerts
Lead information security incidents as Incident Commander, developing response strategies and coordinating across teams
Champion Samsara's cultural principles while delivering security guidance for incident response and insider threat initiatives
Samsara (NYSE: IOT) is the pioneer of the Connected Operations™ Cloud, a platform that enables organizations to harness IoT data for actionable insights and improved operations. They are a recently public company with a culture that encourages rapid career development and a focus on digitizing large sectors of the global economy.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Write code for automations that support security requirements like threat detection and incident containment.
Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.
Partner with product and engineering teams to identify application security risks and recommend mitigations.
Read application code, configuration, and pull requests to understand security risks and suggest improvements.
Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.
Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.
Design, develop, and maintain security automation and SOC tooling, including integrations with SIEM, EDR, cloud services, and internal security platforms.
Participate in security detection engineering, including log parsing, data normalization, and detection logic implementation.
Assist in security incident response, including triage, investigation, containment, eradication, and post-incident analysis.
Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange by trading volume and registered users. We are trusted by 300+ million users in 100+ countries with a focus on security and innovation.
Own end-to-end security incident response, from triage to recovery, and drive post-incident learnings.
Build and improve detection coverage across cloud, endpoint, identity, and SaaS systems.
Develop security automation and workflows to reduce manual toil and improve response speed.
Front is the customer operations platform for B2B complexity, keeping teams, tools, and conversations in sync. Over 9,000 companies rely on Front, and it's backed by Sequoia Capital and Salesforce Ventures, with a highly recognized workplace culture.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Design, implement, and maintain Cloudflare Zero Trust architecture including Access, Gateway, Tunnel, and One Client.
Harden endpoints, run vulnerability management, and build security monitoring with SIEM detections.
Enforce network segmentation, coordinate penetration tests, and lead incident response for infrastructure security incidents.
Social Discovery Group (SDG) is a group of social discovery companies that solve problems of loneliness and isolation by transforming virtual intimacy into the new normal. They have an international remote team and are a two-time 'Great Place to Work' winner (USA & Japan, 2024-2025).
Develop and maintain backend features for GitLab's vulnerability management workflows, primarily using Ruby on Rails.
Collaborate with frontend engineers and contribute across the stack when needed, focusing on performance and reliability.
Participate in on-call rotations to assist with troubleshooting product operations and security issues.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and reduce security risk. With over 50 million registered users and more than 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Diagnose and resolve customer-reported issues quickly, from investigation through durable fix.
Deliver high-quality engineering work that improves platform reliability and directly addresses customer needs.
Partner closely with Customer Success to align on technical solutions and maintain backend systems, APIs, and data pipelines.
VulnCheck is The Exploit Intelligence Company, delivering structured exploit intelligence for exploitation prevention. Founded in 2021, the company has a transparent, collaborative, and supportive culture with a team of cybersecurity experts.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.
Collaborate with engineering and product teams to improve security posture through threat modeling, assurance, and secure implementation.
Identify security gaps and vulnerabilities in ClickHouse Cloud and OSS, triaging vulnerabilities from bug bounty and responsible disclosure.
Drive adoption of security tools and develop automation to scale security processes.
ClickHouse provides a leading real-time analytics platform for data warehousing, observability, and AI workloads. With over 3,000 customers and rapid growth, the company fosters a remote-friendly, innovative culture.