Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
Own application security, threat modeling, and vulnerability disclosure from design review to production.
Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.
Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.
Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.
Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Lead security architecture across AWS and colocation, defining secure patterns and controls.
Partner with engineering teams to threat model, review designs, and promote secure-by-design.
Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.
NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.
Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Lead secure design reviews, threat modeling, and risk assessments for AI-driven products and APIs.
Embed security practices throughout the software and AI development lifecycle.
Architect and enforce security controls for AI/ML systems and cloud-native infrastructure.
AlphaSense provides AI-driven market intelligence and search platform trusted by over 6,000 enterprise customers. Founded in 2011, the company has more than 2,000 employees globally with offices in multiple countries.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Review system designs and implementations to identify security issues and align with best practices.
Develop cloud security architecture and implement automated security testing tools.
Promote DevSecOps principles through CI pipeline integration and Infrastructure as Code scanning.
Iterable is the leading AI-powered customer engagement platform that helps brands like Redfin and SeatGeek create dynamic experiences. With nearly 1,200 clients globally and a diverse workforce, we foster a culture of innovation and inclusion, recognized as one of Inc's Best Workplaces.
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Write code for automations that support security requirements like threat detection and incident containment.
Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.
Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.
Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.
Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
Lead AI security initiatives including threat modeling and auditing third-party models and APIs.
Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.
Lead the security design, implementation, and controls for Jasper’s AI infrastructure and AI-powered internal workflows.
Own threat modeling for AI-specific risks and design controls for validating, logging, and auditing AI outputs.
Build security tooling and automated checks to let internal teams adopt AI capabilities without slowing down.
Jasper is the marketing agents platform that helps enterprises orchestrate AI agents for marketing execution. Founded in 2021, Jasper has team members across the U.S., Australia, and France, and is trusted by hundreds of enterprises including nearly 20% of the Fortune 500.
Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.
Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.
Build and operate Lumin's security fabric engineered for reliability and scale across hundreds of environments.
Design and maintain agentic AI workflows using tools like Claude Code and MCP integrations to automate security platform engineering.
Write production-quality Python applications and tooling supporting platform operations and AI-assisted workflows.
Lumin Digital is a trailblazer in digital banking solutions, providing cloud-native digital experiences for credit unions and banks. We foster a culture of curiosity, innovation, trust, and respect, with a focus on collaboration and continuous improvement.
Lead the development and implementation of security strategies, policies, and procedures.
Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.
Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.