Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Shape the Cogent product at the frontier of AI and cybersecurity, working hand-in-hand with ML engineers.
Build the world's first AI-native cybersecurity organization, extending security posture and incident response.
Educate the market and elevate the industry through thought leadership and customer partnerships.
Cogent is an applied AI lab building next-generation AI agents for cybersecurity. The company is a rapidly growing startup backed by Greylock, with a team of experts from top universities and companies, fostering a culture of cutting-edge research and real-world execution.
Design adversarial prompts to test AI models for offensive security capabilities.
Evaluate model-generated code for functional correctness and real-world exploitability.
Test model behavior across cybersecurity categories like malware, exploitation, and social engineering.
Handshake is a career platform that helps everyone find a path to a great career. They support 25 million job seekers, over 1 million employers, and 1,600 educational institutions.
Add security tooling and checks to CI/CD pipelines with Python automation.
Perform offensive testing, triage findings, and patch straightforward vulnerabilities.
Collaborate with engineers, DevOps, and Fraud while leveraging AI for security work.
Super.com is a high-growth tech company helping people save, earn, and get more out of life. They are a remote-first, collaborative team that has hosted over 100 engineering internships and values career progression.
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.
RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Lead and mentor a global engineering team to build an AI-driven offensive security platform.
Own the technical vision and architecture, ensuring scalability, stability, and resiliency.
Drive adoption of engineering best practices, including AI-assisted development and agile methodologies.
Cobalt provides a SaaS platform for offensive security testing, leveraging a community of vetted testers. The company is fully remote, diverse, and committed to inclusion, with over 500 skilled testers in its core team.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
Design and implement AI-enabled workflows to scale security testing and threat related operations.
Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.
Integrate security controls into CI/CD pipelines while explaining tools and processes.
Identify and verify application vulnerabilities throughout feature development and deployment.
Share practical examples from recent projects to illustrate secure deployment approaches.
The company is conducting paid technical interviews to research cybersecurity practices in CI/CD pipelines. The organization size and culture are not specified, but the engagement is fully remote.
Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
Build offensive tooling, develop exploits, and support incident response and security education.
Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.
Lead security reviews of architecture, code, and security-sensitive changes.
Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
Threat model new capabilities and build scalable guardrails that reduce recurring risks.
Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.
Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Be a technical contributor on a global software engineering team in Product Security, building robust and scalable systems.
Design and implement software and automation tools for security use cases like software supply chain security and AI-powered vulnerability discovery.
Own SRE excellence, CI/CD, and datastore operations for mission-critical security services, ensuring flawless performance.
CrowdStrike is a global leader in cybersecurity, protecting organizations with an AI-native platform to stop breaches. Founded in 2011, the company fosters a culture of flexibility, autonomy, and responsible AI adoption, with a large-scale distributed system processing trillions of events daily.
United StatesCanadaDominican Republic
Unlimited PTO
Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.
Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.
Assess software engineering tasks for technical accuracy, realism, and reproducibility.
Provide actionable feedback on codebase integration issues and logic errors.
Ensure AI training workflows are rigorous and practically applicable.
Project World Wide sources experienced technical specialists for AI training task auditing. This freelance contract opportunity focuses on ensuring technical rigor and accuracy in AI workflows.
Triage and validate incoming security vulnerability submissions for Bugcrowd managed programs.
Communicate directly with clients and researchers to clarify submission details and escalate critical bugs.
Maintain strong knowledge of OWASP Top Ten vulnerabilities and use interception proxies like Burp Suite.
We empower organizations to stay ahead of threat actors by uniting customers and elite hackers with our AI-powered Security Knowledge Platform. We are backed by General Catalyst and other investors, and our team is diverse and inclusive.
Configure, monitor, and maintain cloud and network environments including AWS, Azure, and GCP.
Troubleshoot complex infrastructure and connectivity issues while applying cybersecurity best practices.
Collaborate with cross-functional teams to ensure reliability, security, and operational efficiency.
Our partner is a technology company that provides secure, reliable infrastructure solutions. They operate as a fully remote team with a collaborative culture.
Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.
GuidePoint Security provides trusted cybersecurity expertise, solutions, and services to help organizations make better decisions and minimize risk. With over 1,300 employees, it is a rapidly growing, profitable, privately-held value added reseller focused exclusively on information security.
Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.