Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.
Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.
Lead security reviews of architecture, code, and security-sensitive changes.
Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
Threat model new capabilities and build scalable guardrails that reduce recurring risks.
Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.
United StatesCanadaDominican Republic
Unlimited PTO
Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.
Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.
Partner with product and engineering teams to identify application security risks and frame them as clear business risks, launch options, and recommended next steps.
Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The company is remote-first with a people-first culture, offering competitive benefits and equity rewards.
Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.
RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.
Add security tooling and checks to CI/CD pipelines with Python automation.
Perform offensive testing, triage findings, and patch straightforward vulnerabilities.
Collaborate with engineers, DevOps, and Fraud while leveraging AI for security work.
Super.com is a high-growth tech company helping people save, earn, and get more out of life. They are a remote-first, collaborative team that has hosted over 100 engineering internships and values career progression.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.
Perform high quality penetration testing on software, platforms, and services.
Conduct manual code review and vulnerability hunting to find security flaws.
Collaborate with engineering teams to strengthen security controls and mentor other security practitioners.
Atlassian develops software products that help teams collaborate and unleash their potential. With a distributed-first culture, they value diversity and inclusion, and employ thousands worldwide.
Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.
EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.
Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.
Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.
Penetration test web applications, APIs, and mobile applications for clients across various industries.
Work with technical and non-technical stakeholders to identify vulnerabilities and recommend remediations.
Collaborate closely with developers and teams to strengthen application security and drive continuous improvement.
Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing. They are a small team with big plans, recently securing Series A funding.
Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.
Jobgether is a company that uses AI-powered matching to streamline job applications. It is a technology platform connecting candidates with hiring companies, with a focus on efficient and objective candidate review.