Protect cloud infrastructure, applications, and customer data across a modern technology environment.
Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.
Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.
Own the configuration, tuning, and management of our SIEM solution to diagnose unusual threats.
Perform architecture reviews, code reviews, and penetration testing on web and mobile apps.
Build and maintain vulnerability management CI/CD pipeline and collaborate with engineering teams.
Engine is the AI-native platform for intelligent travel, serving over 38,000 customers and nearly 2 million travelers. Recognized as one of Fast Company's Best Workplaces for Innovators (2025) and Built In's Best Places to Work (2020–2026), we have a culture of exponential growth and high-caliber colleagues.
Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.
Fast-growing B2B SaaS company serving the life sciences and pharma space. A small, high-impact security team with an engineering-first mindset, building AI-native features.
Own and mature Cleo's SSDLC, including threat modeling, design reviews, and automated security scanning.
Run risk-based triage for product vulnerabilities, penetration testing, and the CVE lifecycle.
Own product security posture, customer-facing advisories, and secure-by-default configurations.
Cleo provides secure data integration and managed file transfer solutions for enterprise businesses. With over 4,000 clients and a 99% retention rate, the company promotes a supportive, life-work balanced culture.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.
The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.
Build and maintain secure CI/CD pipelines, embedding security testing and controls into software development and deployment.
Strengthen application and cloud-native security across Kubernetes and containerized environments, identifying risks and implementing practical controls.
Manage CVE and vulnerability lifecycles, supporting prioritization and working with application teams on mitigation and remediation.
Redcare Pharmacy is Europe's leading online pharmacy, driven by dedicated teams and cutting-edge innovation. The company fosters an enjoyable and collaborative working environment where every employee feels comfortable and motivated to contribute to the vision: 'Until every human has their health.'
Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.
Turquoise Health is a Series C price transparency platform building a more open, efficient healthcare marketplace for finance leaders. They're a remote-first US team backed by top investors, powering transparency for 300+ enterprise organizations.
Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.
Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.
Design, deploy, and maintain Microsoft cloud security technologies including Purview, Defender for Cloud, and Entra ID.
Apply a red-team mindset to identify weaknesses and improve security posture.
Act as a trusted security advisor to internal teams and customers on governance and data protection.
Patch My PC provides an enterprise solution for automating and managing third-party updates in Microsoft ConfigMgr, Intune, and WSUS. The fully remote crew of 150 GIF-loving humans supports over 10,000 customers and more than 32 million devices.
Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
Build offensive tooling, develop exploits, and support incident response and security education.
Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.
Integrate security controls into CI/CD pipelines, including SAST, SCA, and container scanning.
Lead vulnerability management and governance with risk-based prioritization and remediation.
Design and implement security controls across GCP infrastructure using IaC practices.
The company is a technology firm specializing in cloud-native security solutions. It operates with a globally distributed team and emphasizes a flexible, autonomous working culture.
Conduct code and container vulnerability assessments using DoD scanning tools, DISA STIGs, and SRGs.
Apply SAST and DAST methodologies and integrate security controls into CI/CD pipelines.
Serve as GitLab security reviewer and coordinate remediation of security findings across teams.
This partner company supports cybersecurity and secure software delivery within U.S. Department of Defense and Navy environments. The organization offers a fully remote, mission-focused culture with opportunities to collaborate across engineering and program teams.
Lead and grow a team of security engineers focused on protecting cloud-native environments and CI/CD pipelines.
Drive technical strategy, threat modeling, and security automation across multi-cloud infrastructure.
Partner with engineering and DevOps teams to embed secure-by-design principles and manage vulnerability and supply chain security.
Wiz is a cybersecurity company that provides a cloud security platform connecting code, cloud, and runtime to secure cloud and AI applications. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, and now powered by Google, with a culture that values world-class talent.
Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
Perform security assessments, vulnerability remediation, and lead key security programs.
Automate security processes and integrate DevSec practices into the software development lifecycle.
Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.
Design, build, and maintain production features with a strong product security focus.
Own vulnerability response from initial triage through coordinated disclosure and patched releases.
Conduct threat modeling and security-sensitive design reviews to help engineers make informed security decisions.
This company builds cloud-native infrastructure software with a strong focus on Kubernetes security. They operate as a remote-first, globally distributed team that values engineering ownership and autonomous work.
Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.
The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.
Establish and employ continuous integration and delivery (CI/CD) patterns for successful software solutions.
Design secure, operationally sound solutions across AWS, Azure, OpenShift, and IBM Cloud.
Implement observability stacks, manage Kubernetes clusters, and automate infrastructure with Terraform.
Conga unifies commercial operations by aligning pricing, quoting, contracting, rebates, and communications so companies run as connected, smarter businesses. With more than 10,000 customers worldwide, including over 50% of the Fortune 100, Conga fosters a collaborative culture where every voice is heard.
Design and build authentication flows, OAuth integrations, and authorization platforms across Motive's products.
Develop BYOK capabilities and security controls for customers with advanced data-protection requirements.
Drive security projects from technical design to implementation, including threat modeling, vulnerability remediation, and security automation.
Motive empowers the people who run physical operations with tools to make their work safer, more productive, and more profitable. The company serves nearly 100,000 customers, from Fortune 500 enterprises to small businesses, across a wide range of industries.