Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.
Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.
RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.
Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.
Define and enforce security requirements for software products, features, and components.
Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.
symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.
Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
Improve secure development practices through code reviews, threat modeling, and security design reviews.
Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.
Analyze, assess, reproduce, and triage incoming security vulnerability reports from the bug bounty program.
Communicate clearly with security researchers and drive the lifecycle of submissions through to resolution.
Understand root causes of vulnerabilities and advise on mitigation strategies to improve security posture.
Stripe is a financial infrastructure platform for businesses, enabling millions of companies to accept payments, grow revenue, and accelerate new business opportunities. As a large, mission-driven company, Stripe fosters a culture of passion, grit, and integrity with diverse perspectives.
Lead end-to-end vulnerability management and cloud security posture management lifecycle.
Administer and optimize security tooling, including configuration, automation, and reporting.
Monitor AWS cloud infrastructure to detect misconfigurations and compliance drift.
US Security & IT is a partner company focused on security and IT services. The company fosters an inclusive and collaborative work environment centered on security innovation and impact.
Bolster Auctane's global engineering and operations within the Information Security Group, reporting to the CISO.
Lead security programs defining technology and processes for cybersecurity, focusing on Enterprise and Cloud Infrastructures.
Manage core security operations, incident response, and vulnerability management while promoting security by design.
Auctane provides mailing and shipping software products that enable businesses of all sizes to send billions of items annually, worth over $200 billion, to recipients worldwide. The company, with a family of brands including ShipStation and Stamps.com, values a flat and open engineering culture and emphasizes teamwork, customer delight, and delivering great outcomes.
Own key security domains such as vulnerability management, application security, API security, and supply chain security.
Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.
NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.
Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.
Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.
Design and ship scalable security solutions to bridge the gap between security and engineering teams.
Build cooperative partnerships with product and engineering teams to integrate robust security capabilities at scale.
Drive security risk reduction through technical leadership, security reviews, and mentorship across engineering teams.
Twilio is a communications platform that delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide to craft personalized customer experiences. The company has a remote-first work culture with a strong focus on connection, global inclusion, and diverse experiences, making a global impact each day.
Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.
ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.
Lead the security research function by defining methodologies and best practices for identifying cloud and application security threats.
Conduct advanced vulnerability research and collaborate with engineering teams to translate findings into product features.
Publish high-quality technical content and establish thought leadership in the cybersecurity community.
The company is a cybersecurity vendor that develops AI-powered security solutions. It is a fast-growing, remote-first organization with a collaborative culture emphasizing technical excellence and continuous learning.
Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.
The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.
Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
Contribute to security architecture reviews and support bug bounty programs and incident response.
Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.
Lead security strategy and develop scalable practices to protect systems, products, and customers.
Partner with engineering teams to improve resilience, reduce risk, and embed security into development.
Manage security incidents, evaluate emerging technologies, and build a high-performing security team.
The company is a fast-growing technology firm focused on innovation and engineering excellence. It operates with a distributed international team and emphasizes trust, autonomy, and ownership.
Strengthen platform defenses and safeguard customer data against emerging threats.
Lead vulnerability management and incident response for product security events.
Promote secure development practices and manage Security Champions programs.
Jobgether uses AI-powered matching to connect candidates with hiring companies. They process applications and share shortlists with employers, who manage next steps.
Lead and support the response to all security events and incidents across Twilio's global infrastructure, services, and applications.
Work cross-collaboratively to solve challenges related to a broad spectrum of threat actors and improve security posture.
Own the security incident lifecycle, participate in on-call rotation, and conduct post-incident betterments.
Twilio shapes the future of communications with innovative solutions for hundreds of thousands of businesses, empowering millions of developers worldwide. The company embraces a remote-first work culture and a strong culture of connection and global inclusion, fostering a vibrant and diverse team.
Lead threat modeling, architecture reviews, and code reviews for web applications, APIs, and microservices.
Actively develop and commit code to fix security flaws in Python, Go, or JavaScript/TypeScript codebases.
Implement and manage security testing tools within CI/CD pipelines to catch vulnerabilities early in the SDLC.
RunPod is the AI Developer Cloud, providing a platform for developers to experiment, train, fine-tune, deploy, and scale AI. We are a small, remote-first team that has processed over 20 billion inference requests and closed a $100M Series A in June 2026.