Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.
Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.
Set and execute the technical vision for the Security Engineering Platform team, spanning AWS and GCP hardening and tier-0 services.
Own the hardening roadmap for tier-0 cloud infrastructure and access services, backed by rigorous, follow-the-sun on-call.
Coach and mentor highly skilled tech leads and engineers as a player-coach, leaning in on cloud hardening, identity, and secrets management problems.
DoorDash is a technology and logistics company that started by enabling door-to-door delivery and now builds the industry's most scalable and reliable delivery network. The company is growing rapidly with a global team committed to empowering local economies and supporting employees' well-being through comprehensive benefits.
Own security of the software build and release pipeline, cloud environments, and AWS identity and access.
Operationalize a 15-domain cloud security framework and CrowdStrike CSPM across all AWS estates.
Mentor a junior cloud security engineer and build paved-road patterns for engineering teams.
Vermont Information Processing is a leading beverage industry technology provider trusted by over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security with executive sponsorship and a funded roadmap.
Develop playbooks and address security-related tasks in AWS serverless environments.
Drive improvements in security posture, including application, endpoint, and access management.
Collaborate with product engineering teams to raise the bar for security in CI/CD, dependency management, and secure design reviews.
Stedi is building a new healthcare clearinghouse and RCM engine, accessible via API. With $142 million in funding and a lean, passionate team, they ship products weekly and prioritize automation and eliminating toil.
Lead and grow a small security team while owning Canary's security and compliance program end-to-end.
Serve as the primary security voice to customers, partners, and auditors, translating security posture for varied audiences.
Set technical direction for security tooling and stay hands-on in architecture and threat-model reviews.
Canary Technologies is a leading agentic AI platform for hotel and guest management, powering digital infrastructure for over 20,000 hotels in 125+ countries. With nearly $200M raised, they are a top-funded hotel tech company, recognized for growth and workplace excellence.
Manage identity, access, and lifecycle across Google Workspace and SaaS tools.
Implement endpoint management and protection across the macOS fleet.
Build internal security tooling, alerts, and access reviews with the CSTO.
SpotMe is a B2B event platform helping enterprises run impactful in-person, virtual, and hybrid events. It powers Onomi for life sciences, with over 500,000 healthcare professionals engaging monthly.
Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.
The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.
Own and execute application, cloud, and API security across the platform.
Build detection, response, and hardening for a high-scale SaaS environment.
Collaborate with engineers to embed security into the SDLC and enterprise client requirements.
YGO.ai is a VC-funded AI tourism platform that provides AI search and recommendation engines for major travel enterprises. As a VC-funded startup, we maintain a hands-on, engineering-driven culture where security is integral from the start.
Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.
Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.
Own identity and endpoint security, including access management, device standards, and risk assessments.
Administer SSO, enforce MFA, manage MDM/EDR, and automate security workflows.
Act as a first responder for incidents, conduct vendor reviews, and build scalable security processes.
Squads is a financial technology company building products and APIs for the stablecoin economy. More than 450 teams use Squads Multisig to secure over $10 billion in value.
Own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments.
Translate broad security objectives into concrete technical requirements, controls, tooling, and implementation plans.
Partner across Engineering, Platforms, Product, and business teams to continuously strengthen security posture as we scale.
Backstory is the leading AI answers platform for sales teams, helping modern sales teams ask questions and get the right answer in real time. Backed by top investors like Andreessen Horowitz and ICONIQ Capital, Backstory is based in San Francisco and has been recognized by Gartner, Forrester, and the Forbes AI 50.
Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.
Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.
Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.
The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.
Protect clients' digital assets by designing and implementing security solutions across multi-cloud environments.
Work closely with senior leadership and mentor junior team members while contributing across cybersecurity engineering, GRC, and security strategy.
Take ownership of client relationships and bring people along, adapting between engineering, strategy, and compliance conversations.
Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership. The firm serves startups, mid-market companies, and PE-backed portfolios with a collaborative and entrepreneurial culture.
Design and build security for future infrastructure, partnering with engineering and compliance teams.
Lead AI-native security initiatives, designing autonomous agents for threat detection and incident response.
Devise defense-in-depth frameworks, research threats, and maintain KPIs for a healthy cloud security program.
WeightWatchers is a global digital health company that blends science and community to help millions build sustainable healthy habits. The engineering team drives transformative change through technology, with a culture that thrives on urgency, collaboration, and passion for impactful work.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
You will own end-to-end data protection: architecting security infrastructure, managing PCI/SOC2 programs, and setting the security roadmap.
You will integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and harden containerized and cloud-native environments.
You will configure IAM and SSO platforms, manage EDR/DLP/SIEM tooling, and run security awareness training.
Campminder builds software for summer camps, enabling meaningful experiences for kids. With over 100 employees, they are stable, profitable, and have a values-led culture committed to work/life balance.
Own the design, resilience, and health of infrastructure across AWS and hybrid on-prem/Azure/GCP environments.
Execute disaster recovery, patching, and security/compliance controls across a large, multi-account, multi-platform estate.
Build CI/CD pipelines, automate to reduce toil, and serve as L2 escalation for infrastructure incidents.
HealthEdge offers AI-powered operational infrastructure for health insurance companies, guaranteeing an enduring financial edge in an increasingly competitive market. We're experiencing strong market momentum with a growing number of health plans choosing HealthEdge to modernize their operations and competing effectively, making this a pivotal moment to join and shape the future of healthcare technology.
Support cloud security consulting engagements, including assessments and architecture reviews.
Assist with AWS security configurations and documentation under senior guidance.
Participate in client meetings and contribute to deliverable preparation.
GuidePoint Security provides trusted cybersecurity expertise, solutions and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, privately-held company known for its collaborative culture and mentorship.