Contribute to secure-by-design practices and advance the S-SDLC program.
Mentor engineers on secure coding and career growth.
Evaluate and recommend AI-assisted security tooling.
Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.
Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.
Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.
Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
Partner with engineering teams to validate fixes and implement long-term security improvements.
Define and maintain secure SDLC processes, including security reviews and threat modeling.
The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.
United StatesCanadaDominican Republic
Unlimited PTO
Lead application and product security across Forward-built, third-party, and AI-built software.
Evolve the pentest program and proactively build AI solutions within the appsec function.
Own remediation workflows and partner with teams to build controls for external exposure.
Forward Financing is a financial technology company that unlocks capital for small businesses across America. They are a recognized Best Place to Work with a remote-first culture and team members across the US, Canada, and Dominican Republic.
Own key security domains such as vulnerability management, application security, API security, and supply chain security.
Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.
NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.
Partner with product and engineering teams to identify risks early and build security into new features.
Lead threat modeling and secure design reviews for new products and architecture changes.
Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.
Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.
Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
Build, maintain, and improve application security tooling and participate in incident response activities.
The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.
Lead application and product security across Forward-built, third-party, and AI-built software.
Evolve the pentest program to aggressively test and remediate vulnerabilities in existing and new software.
Build and integrate AI solutions within the appsec function.
Forward Financing is a financial technology company that unlocks capital for small businesses across America. Recognized as a Best Place to Work, it invests in employees, technology, and customer experience with a long-term focus.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.
Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.
Provide strong leadership as a security thought leader across Delinea's product offerings.
Perform end-to-end security architecture reviews and threat modeling.
Maintain and mature Product Security tooling such as SAST, SCA, DAST, ASPM.
Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization. They are a global team of passionate problem-solvers, with a culture of innovation, respect, and fairness.
Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.
ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.
Define security requirements and design application architectures following a secure-by-default approach.
Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.
Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.
Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.
Perform hands-on security testing and code review across web applications and APIs.
Conduct threat modeling and embed secure development practices into the SDLC.
Build and tune security tooling, including SAST, DAST, and CI/CD automation.
Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.
Define and enforce security requirements for software products, features, and components.
Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.
symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.
Establish secure by design standards and target state security architecture across product development, covering threat modeling, secure design review, and vulnerability management.
Build a formal vulnerability management program encompassing traditional and AI-specific threats like prompt injection, model manipulation, and data exfiltration.
Provide senior technical leadership and build trusted partnerships across Product, Engineering, and Security teams.
Semperis is a cybersecurity company on a mission to be a Force for Good, protecting identity and data. We are one of America's fastest-growing cybersecurity companies and have been recognized as a top workplace.
Define and drive AI-forward product strategy for SpyCloud's investigations capabilities, enabling security teams to uncover, understand, and act on cybercriminal activity using intelligent, automated workflows.
Partner closely with Engineering, Design, Data Science, and Go-to-Market teams to deliver innovative AI-driven features that help customers investigate threats faster and reduce manual effort.
Own the product vision, strategy, and roadmap for the AI-powered Investigations product portfolio, balancing long-term vision with customer needs and business priorities.
SpyCloud transforms recaptured darknet data to disrupt cybercrime, offering automated identity threat protection solutions that use advanced analytics and AI to accelerate investigations and protect identities. Headquartered in Austin, TX, SpyCloud employs over 250 cybersecurity experts focused on protecting businesses and consumers from stolen identity data.
Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.
Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.
Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
Contribute to security architecture reviews and support bug bounty programs and incident response.
Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.