Own internal IT, security, and compliance strategy across the organization.
Lead the migration from MSP to an in-house IT function and manage a SecOps team.
Drive enterprise incident response, business continuity, and disaster recovery planning.
Karbon is the global leader in AI-powered practice management software for accounting firms. The company is well-funded, ranked #1 on G2, and has a people-first culture recognized with Great Place To Work certification and on Fortune's Best Small Workplaces list.
Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security.
Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first.
Treat incident response as core, not afterthought.
Tremendous is a global platform for businesses to send payouts like gift cards and money to anyone, anywhere, instantly. Trusted by 20,000+ organizations, they are profitable and fully remote with a high-documentation, low-meeting culture and an employee NPS in the high 80s.
Lead Playlab's security engineering, compliance, and privacy programs with end-to-end ownership of risk and customer assurance.
Drive security automation, incident response, and SOC 2/SIEM implementations to safeguard educational data globally.
Collaborate cross-functionally to build partnerships and promote thoughtful decision-making in a fast-growing organization.
Playlab is a tech non-profit dedicated to helping educators and students become critical consumers and creators of AI through open-source, community-driven tools. With over 60,000 educators using the platform, the team is mission-driven, small, and passionate about equity, creativity, and joyful learning.
Own the technical operations domain covering IT, security, DevOps, and infrastructure for an AWS-native platform.
Build and lead a lean team, leveraging AI agents and tooling to automate DevOps, security, and compliance tasks.
Partner with engineering leadership to ensure reliability, scalability, and HIPAA/CMS compliance in a regulated environment.
Spark Advisors builds healthcare technology for Medicare advisors, helping seniors navigate complex coverage. They are a fast-growing platform backed by Primary Ventures and Viewpoint Ventures, recognized as one of Inc. Magazine's Best Workplaces of 2025.
Partner with Engineering to design, implement, and improve security controls across software, application architecture, and AWS infrastructure.
Strengthen security monitoring, detection, incident response, and integrate security into CI/CD pipelines.
Support compliance efforts including SOC 2 and ISO audits, and lead customer security reviews.
AlertMedia helps organizations protect their people, operations, and brand with a modern Risk Intelligence and Response platform. It is a high-growth, PE-backed SaaS company with more than 4,000 clients and a 10-year award-winning culture.
Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.
Ada is an AI customer service company that helps enterprises automate customer conversations with AI agents. Founded in 2016, we've powered over 5.5 billion interactions and raised over $250M from top investors.
Lead security architecture across AWS and colocation, defining secure patterns and controls.
Partner with engineering teams to threat model, review designs, and promote secure-by-design.
Develop automated security tooling and guardrails using infrastructure-as-code and AI-assisted workflows.
NMI enables partners with choice, challenging the one-size-fits-all approach to payments. We're a global company with a remote-first culture, fostering diversity and inclusion through initiatives like affinity groups and DEI action teams.
Design and enforce least-privilege IAM architectures, network segmentation, and cloud security controls across multiple AWS accounts.
Build automated detection and response pipelines using AI tools for fast, actionable remediation.
Own vulnerability management, HIPAA compliance, and lead cross-functional security initiatives.
Chamber Cardio is rebuilding the cardiology system to focus on outcomes, partnering with independent cardiologists with technology, data, and operational tools. They are a mission-driven team combining clinical expertise, design, and a modern operating platform, with a culture of low ego, empathy, courage, ownership, and grit.
Own security technical controls including SIEM, vulnerability management, cloud hardening, and secrets management.
Manage security-critical IT operations including endpoint hardening and SaaS app security.
Drive security program and compliance by automating evidence collection and implementing technical controls.
CollegeVine deploys powerful AI agents in complex, regulated industries, starting with higher education to automate administrative workflows. The company is a venture-backed, fully remote startup with a diverse team based primarily in the US and worldwide.
Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
Own SOC 2 Type II program management and the customer-facing trust portal.
Author security policies and manage AI compliance frameworks.
Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.
Operate and sustain Chainguard’s technology platforms (cloud, IAM, and AI) and help implement access controls and identity policies.
Support the hardening and monitoring of cloud infrastructure, assist in securing AI/ML pipelines, and troubleshoot systems.
Document processes, contribute to runbooks, and adapt to shifting priorities while learning security best practices.
Chainguard delivers hardened, secure, and production-ready builds of open source software. It is a venture-backed late-stage startup with Fortune 500 customers including Anduril, Canva, and OpenAI.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.
Own cloud and platform security end to end across AWS and Azure, including architecture, detection, and response.
Build self-serve security tooling and guardrails to replace manual processes and reduce risk.
Partner with engineering teams to embed security into CI/CD pipelines and product development.
Ada is an AI customer service platform that enables enterprise companies to deliver instant, proactive, and personalized customer experiences. Established in 2016, the Canadian company has powered over 5.5 billion interactions for brands like Square and YETI, backed by over $250M in funding from top-tier investors.
United States
Unlimited PTO
12w maternity
12w paternity
Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of AI/ML workloads.
Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources.
Act as the senior security resource across cloud security and security reviews, mentoring teammates.
SmarterDx is a clinical AI platform that helps health systems capture revenue and improve quality metrics using clinically-validated EHR data. The company is a remote-first team with a small, collaborative engineering culture focused on making healthcare more accurate and effective.
You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
You will run the vulnerability management program and remediate security findings across AWS.
You will support security incident response, fraud investigations, and third-party risk assessments.
We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Use your knowledge of security architecture to help engineers build and securely operate products and services from the ground up.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials. Trusted by more than 100,000 businesses and millions of users worldwide, LastPass blends strong security with everyday simplicity.
Improve and maintain AWS security configurations including IAM, GuardDuty, and CloudTrail.
Manage security tooling across the organization including EDR, MDM, DLP, and respond to SOC alerts.
Lead vulnerability management activities, coordinate patching, and support compliance assessments.
This company is a fully remote, international technology firm specializing in cloud and operational security. It has a diverse team of over 40 nationalities and a culture that values curiosity, ownership, and continuous improvement.
Write, tune, and maintain detections in a modern SIEM across cloud, container, and SaaS log sources.
Run cloud security operations in AWS, triage alerts, and help execute incident-response playbooks.
Build and extend security-automation tooling with code fluency in Python or TypeScript.
SmarterDx uses clinical AI to help health systems capture the full value of patient care. They are a remote-first team with a mission to make healthcare more accurate and sustainable.
Own and mature the enterprise security program across identity, endpoint, and SaaS security.
Implement access control, vulnerability management, and secure configuration of cloud and developer infrastructure.
Collaborate with the CISO and operations teams to deliver security approaches that protect critical assets in a web3 environment.
Solana Foundation is a non-profit based in Zug, Switzerland, dedicated to the adoption, decentralization, and security of the Solana network. They are a global team looking for talented individuals who are willing to jump right in and use their expertise to help the ecosystem build.
Partner with engineering teams to review cloud and compute architecture design changes.
Establish threat models for cloud and compute paved roads to identify security risks.
Write code for automations that support security requirements like threat detection and incident containment.
Quora operates two platforms: a global knowledge sharing platform with over 300 million monthly unique visitors, and Poe, a platform for AI language models. The company is remote-first with a culture rooted in transparency, idea-sharing, and experimentation.