Conduct and support static and dynamic application-security testing using tools like Fortify, X-Ray, and OWASP ZAP.
Work with software engineers to understand root causes, resolve vulnerabilities, and integrate security testing into CI/CD workflows.
Strengthen software supply-chain security and apply secure development practices in environments using GitLab, OpenShift, and Kubernetes.
Rackner builds secure software supporting high-impact Department of Defense planning and decision-support missions. The company has delivered more than $30 million in recent federal awards and fosters a collaborative, mission-focused culture.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.
Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.
Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.
Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.
Assist with source code review and secure coding improvements.
Use SAST, DAST, and SCA tools to identify and validate vulnerabilities.
Collaborate with teams to integrate security into CI/CD and SDLC processes.
This company is a technology-driven healthcare organization integrating security into software development. It fosters a collaborative remote culture and supports professional growth in cybersecurity.
Act as an Application Security SME, partnering with Engineering and Product teams to embed security throughout the SDLC.
Lead application security reviews, threat modeling, code reviews, and penetration testing to identify and mitigate risks.
Design and automate security controls across CI/CD pipelines, including SAST, SCA, and other AppSec tooling.
Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America, backed by leading investors, and places millions of workers.
Define security requirements and design application architectures following a secure-by-default approach.
Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.
Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.
Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
Partner with engineering teams to validate fixes and implement long-term security improvements.
Define and maintain secure SDLC processes, including security reviews and threat modeling.
The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.
Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.
RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.
RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.
Identify and remediate vulnerabilities across the product ecosystem using code reviews and automation.
Integrate security tools and practices into CI/CD pipelines to ensure secure development.
Collaborate with engineering teams to apply threat modeling and secure-by-design principles.
They are a partner company specializing in digital product security. The team size is not specified, but the culture emphasizes trust, collaboration, and remote work.
Design, implement, and maintain enterprise security solutions to strengthen cybersecurity posture and advance Zero Trust maturity.
Operate security tools like EDR, SIEM, and vulnerability scanners, integrating security into CI/CD pipelines.
Build dashboards to measure security performance and Zero Trust maturity metrics.
Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. Named one of the fastest-growing privately held companies, they pride themselves on an employee-centric culture and great benefits.
Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
Build, maintain, and improve application security tooling and participate in incident response activities.
The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.
Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.
Contribute to secure-by-design practices and advance the S-SDLC program.
Mentor engineers on secure coding and career growth.
Evaluate and recommend AI-assisted security tooling.
Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.
Perform hands-on security testing and code review across web applications and APIs.
Conduct threat modeling and embed secure development practices into the SDLC.
Build and tune security tooling, including SAST, DAST, and CI/CD automation.
Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.
Partner with product and engineering teams to identify risks early and build security into new features.
Lead threat modeling and secure design reviews for new products and architecture changes.
Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.
Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.