Own threat modeling and secure code reviews for new products and features.
Maintain and tune AppSec tooling, and run the bug bounty program.
Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.
Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.
Protect applications trusted by millions of users in the Web3 ecosystem.
Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
Embed security throughout the software development lifecycle to build resilient products.
This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
Build security tooling and automation, contributing to development of internal applications and scripts.
Execute incident response efforts by identifying, investigating, and remediating security incidents.
BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.
Partner with product and engineering teams to identify application security risks and recommend mitigations.
Read application code, configuration, and pull requests to understand security risks and suggest improvements.
Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.
Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Act as the primary security partner for the Walrus team, providing architectural guidance and embedding security practices throughout the development lifecycle.
Lead security assessments for new features and contribute to ecosystem-wide security initiatives, identifying systemic risks and actionable remediation plans.
Drive a security-by-design culture, leveraging AI and automation to focus on high-impact, complex security research and mentor engineers.
Mysten Labs builds foundational infrastructure to accelerate the adoption of decentralized protocols based on blockchain technologies. They are a well-funded, remote-first team with over $300M in Series B funding from top venture firms, fostering a culture of innovation and growth.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
Own application security, threat modeling, and vulnerability disclosure from design review to production.
Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.
Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.
Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Operate and sustain Chainguard’s technology platforms (cloud, IAM, and AI) and help implement access controls and identity policies.
Support the hardening and monitoring of cloud infrastructure, assist in securing AI/ML pipelines, and troubleshoot systems.
Document processes, contribute to runbooks, and adapt to shifting priorities while learning security best practices.
Chainguard delivers hardened, secure, and production-ready builds of open source software. It is a venture-backed late-stage startup with Fortune 500 customers including Anduril, Canva, and OpenAI.
Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.
Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Lead threat modeling and secure design reviews across C++, Go, and Rust
Build and tune application security testing (SAST, SCA, secret scanning, DAST) and fuzzing harnesses
Operate PSIRT and build security champions program to raise the security bar
Redpanda is a unified platform for agent-data interaction, combining streaming, SQL analytics, and intelligent connectivity with governance for enterprise AI agents. It is a fast-moving, people-first organization with a small, high-trust security team and team members across the globe.
Lead security architecture across AWS and colocation, defining secure patterns and controls.
Partner with engineering teams to threat model, review designs, and promote secure-by-design.
Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.
NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.
Take ownership of protecting product, users, and collaborators as a Security Engineer on a fast-growing AI dating platform.
Perform weekly code reviews, coordinate security audits, and maintain risk register to ensure safety of AI-generated content.
Monitor emerging AI security threats, manage IT access and device security, and run phishing simulations company-wide.
EverAI builds the world's largest AI companionship platform, redefining relationships for millions with a proprietary moderation system, EverGuard. With 50 million users in two years, the team of about 100 is enthusiastic, passionate, and hardworking, led by experienced entrepreneurs.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.