Investigate emerging vulnerabilities across the Ubuntu ecosystem, helping identify, assess, remediate, and document security issues.
Collaborate with internal engineering teams, upstream developers, and the broader open source community to deliver robust security fixes.
Contribute to security initiatives across the broader open source ecosystem and engage with industry communities.
They are a globally distributed security engineering team dedicated to protecting users and strengthening the security of open source software. The environment is highly technical, collaborative, and international, with opportunities to share knowledge through open source contributions and industry events.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Design, configure, and support ServiceNow Vulnerability Response (VR) to manage the end-to-end vulnerability lifecycle.
Build and maintain remediation workflows, vulnerability groups, assignment rules, and calculators using Flow Designer and other ServiceNow technologies.
Configure and manage vulnerability scanning and security tool integrations via APIs including Qualys, Tenable, Rapid7, Microsoft Defender, and CrowdStrike.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations minimize risk and make better decisions. Since 2011, the company has grown to over 1,300 employees and serves as a trusted advisor to more than 6,200 customers, with a culture driven by core values and collaboration.
Triage incoming bug bounty reports and vulnerabilities, assess impact, and coordinate with development teams.
Communicate professionally with security researchers and support CVE assignment processes.
Maintain accurate records, monitor metrics, and improve runbooks for vulnerability handling.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and reduce security risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, which fosters a high-performance culture driven by values and continuous knowledge exchange.
Lead the Application Security program across all products, embedding security throughout the SDLC.
Integrate AppSec findings into centralized vulnerability workflows, correlating them with asset and exploit intelligence.
Automate security testing pipelines and mentor engineers on secure coding and threat modeling.
ServiceNow is the AI control tower for business reinvention, helping 85% of the Fortune 500 work smarter with its AI platform. The company is building an AI-native culture where technology and talent are unstoppable together.
Design, prototype, and deploy technical controls to close high-impact abuse vectors.
Translate empirical attacker evidence into precise technical requirements and control specifications.
Collaborate with cross-functional teams to run experiments and build regression testing suites.
Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments and grow revenue. It is a large company with a mission-driven culture focused on increasing the GDP of the internet.
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.
RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.
Own problems end-to-end across Matomo Core, from customer insight to shipped improvements.
Work across PHP, MySQL, JavaScript, Vue.js, and TypeScript to build a widely used analytics platform.
Use AI-assisted development to move faster while maintaining high standards for security and privacy.
Matomo builds privacy-friendly, open-source web analytics that gives organizations full ownership of their data. They are an independent, profitable company with a small, collaborative team that values transparency and product quality.
Lead security reviews of architecture, code, and security-sensitive changes.
Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
Threat model new capabilities and build scalable guardrails that reduce recurring risks.
Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.
Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.
Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.
Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.
Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.
Lead the engineering strategy and technical vision for Turnkey's Product Engineering organization, including key management, APIs, and signing systems.
Build, manage, and grow a high-performing engineering org, hiring and developing engineering managers and senior ICs.
Partner with Product and Design leadership to translate customer needs into a clear technical roadmap.
Turnkey builds programmable guardrails for autonomous economic systems, founded by the team that scaled Coinbase Custody to $100M+ in ARR. The team is low-ego, high-agency, and deeply technical, consisting of experts in cryptography, security, and systems.
Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.
Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.
Define and own the strategy and roadmap for the unified remote workspace, spanning collaboration, identity, and zero-trust access.
Lead the enterprise collaboration and productivity platform, securely embedding AI features like summarization and transcription.
Manage a global zero-trust access platform, oversee offensive security, vulnerability management, and incident response.
Binance is a leading global blockchain ecosystem behind the world's largest cryptocurrency exchange. We serve 300+ million people in 100+ countries with secure, transparent digital-asset products and a culture focused on advancing financial freedom.
Walk through your approach to integrating security into CI/CD pipelines during feature development.
Describe how you handle vulnerability verification in production environments.
React to technical scenarios involving application security threats and balancing feature velocity.
Terac is building the world's largest pool of vetted human experts for AI. Researchers, AI labs, and product teams use Terac to recruit, screen, and pay study participants across industries, languages, and skill sets.
Design, build, and maintain payment processing systems handling billions in annual ACH and wire transfers.
Implement fraud prevention, transaction verification, and anomaly detection controls.
Own architectural decisions and partner with compliance, risk, and accounting stakeholders.
Qualia is a leading B2B real estate technology company that transforms the home buying and selling experience into a simple, secure process. The company is remote-first, growing quickly, and mission-driven with a focus on trust and transparency.
Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Participate in code reviews of ERC-20, ERC-721, and other token smart contracts to identify security risks.
Explore and apply AI/LLM and Agent technologies to automate smart contract vulnerability detection.
Combine manual analysis with AI to analyze Web3 attack causes and impacts for audit process optimization.
Bybit is a leading cryptocurrency exchange and digital financial platform founded in 2018, serving over 80 million users across 200+ countries. Backed by a global team of ambitious builders and innovators, we foster a high-performance environment where talent drives real impact.
Lead end-to-end planning and execution of enterprise security programs including vulnerability management, incident response, and cloud security.
Drive cross-functional coordination between engineering, product, and legal to implement security controls on schedule.
Manage program risks, report to executive and board audiences, and foster a culture of transparency and trust.
Backblaze is the object storage leader in the open cloud, helping customers break free from legacy solutions. Founded in 2007, they scaled with minimal funding and now generate over $100m in revenue, serving 500K+ customers globally.
Run continuous vulnerability scanning in Tenable and CrowdStrike Falcon to ensure full coverage of cloud assets.
Prioritize findings by real-world risk using exploitability, threat intelligence, and asset context, and validate high-priority findings hands-on.
Automate scan-to-ticket workflows with Python, push validated fixes through Jira, and help define vulnerability management standards and SLAs.
Revinate is the hotel data activation platform that connects and cleans guest data from every system into Rich Guest Profile data, powered by an AI intelligence layer trained on 17 years of hospitality data. Revinate powers 1.1 billion data points across 12,500+ hotels, driving over $24 billion in direct revenue, and is proud to be a Great Place To Work Certified company.