Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Lead secure design reviews, threat modeling, and risk assessments for AI-driven products and APIs.
Embed security practices throughout the software and AI development lifecycle.
Architect and enforce security controls for AI/ML systems and cloud-native infrastructure.
AlphaSense provides AI-driven market intelligence and search platform trusted by over 6,000 enterprise customers. Founded in 2011, the company has more than 2,000 employees globally with offices in multiple countries.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.
Lead Application Security initiatives across HighLevel's products and engineering teams.
Conduct architecture reviews, threat modeling, and security assessments for web, mobile, and API applications.
Drive DevSecOps practices by automating security in CI/CD pipelines and managing security tooling.
HighLevel is an AI-powered, all-in-one white-label sales and marketing platform that empowers agencies and businesses to grow their digital presence. With over 1,500 team members across 15+ countries, we operate in a global, remote-first environment with a culture rooted in creativity, collaboration, and impact.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.
Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.
Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.
Lead and scale the product security program, defining strategy, roadmap, and metrics in alignment with company objectives.
Build and mentor a high-performing product security team, fostering technical excellence and sustainable execution.
Partner with engineering and product leaders to embed security throughout the software development lifecycle, leveraging AI and automation.
Tines provides an intelligent workflow platform that applies AI, automation, and integration to drive business results. Founded in 2018 with co-headquarters in Dublin and Boston, the company serves a diverse range of customers and fosters a culture of Simplicity, Speed, and Soundness.
Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.
Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.
Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.
Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.
Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
Lead AI security initiatives including threat modeling and auditing third-party models and APIs.
Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.
Lead threat modeling and secure design reviews across C++, Go, and Rust
Build and tune application security testing (SAST, SCA, secret scanning, DAST) and fuzzing harnesses
Operate PSIRT and build security champions program to raise the security bar
Redpanda is a unified platform for agent-data interaction, combining streaming, SQL analytics, and intelligent connectivity with governance for enterprise AI agents. It is a fast-moving, people-first organization with a small, high-trust security team and team members across the globe.
Own threat modeling and secure code reviews for new products and features.
Maintain and tune AppSec tooling, and run the bug bounty program.
Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.
Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.
Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
Own application security, threat modeling, and vulnerability disclosure from design review to production.
Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.
Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.