Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
FirstPrinciples is a research company building AI for scientific discovery. We're a fast-growing, remote-first team of builders, researchers, engineers, and thinkers working across Canada, the US, the UK, and expanding globally.
Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Shape AI security at the edge by turning new threats into protections customers can use.
Think like an attacker to find new ways AI systems can be exploited and stop them.
Build for real time, catching threats without slowing down the applications we protect.
bunny.net is a content delivery network and edge computing company that accelerates the internet. Founded in 2015, the company has 95+ employees and fosters a culture of ownership, improvement, and challenging what's possible.
Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.
Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.
Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.
Lead the security design, implementation, and controls for Jasper’s AI infrastructure and AI-powered internal workflows.
Own threat modeling for AI-specific risks and design controls for validating, logging, and auditing AI outputs.
Build security tooling and automated checks to let internal teams adopt AI capabilities without slowing down.
Jasper is the marketing agents platform that helps enterprises orchestrate AI agents for marketing execution. Founded in 2021, Jasper has team members across the U.S., Australia, and France, and is trusted by hundreds of enterprises including nearly 20% of the Fortune 500.
Adversarially test our AI and LLM-backed features.
Build and operate production security services.
Threat model from product designs.
GoodLeap is a technology company that provides financing and software products for sustainable solutions like solar panels and energy-efficient HVAC. With over $30 billion in financing since 2018, the company supports a collaborative culture and backs the nonprofit GivePower.
Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.
Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.
Lead and scale the product security program, defining strategy, roadmap, and metrics in alignment with company objectives.
Build and mentor a high-performing product security team, fostering technical excellence and sustainable execution.
Partner with engineering and product leaders to embed security throughout the software development lifecycle, leveraging AI and automation.
Tines provides an intelligent workflow platform that applies AI, automation, and integration to drive business results. Founded in 2018 with co-headquarters in Dublin and Boston, the company serves a diverse range of customers and fosters a culture of Simplicity, Speed, and Soundness.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Shape the Cogent product at the frontier of AI and cybersecurity, working hand-in-hand with ML engineers.
Build the world's first AI-native cybersecurity organization, extending security posture and incident response.
Educate the market and elevate the industry through thought leadership and customer partnerships.
Cogent is an applied AI lab building next-generation AI agents for cybersecurity. The company is a rapidly growing startup backed by Greylock, with a team of experts from top universities and companies, fostering a culture of cutting-edge research and real-world execution.
Partner with product and engineering teams to identify application security risks and frame them as clear business risks, launch options, and recommended next steps.
Read application code, configuration, pull requests, logs, and documentation to understand how systems work and where security risks may exist.
Contribute small code changes, scripts, detections, tests, secure defaults, or automation that improve AppSec workflows and reduce recurring issues.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest. The company is remote-first with a people-first culture, offering competitive benefits and equity rewards.
Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.
Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.
Architect internal AI security strategy for ServiceNow's adoption of agentic tools, LLMs, and copilots.
Drive execution excellence by pushing architecture through to production-grade outcomes across security domains.
Lead AI threat modeling and partner with product AI security research to apply frontier research internally.
ServiceNow is the AI control tower for business reinvention, empowering 85% of the Fortune 500 with its AI platform. Founded on the idea of freeing people from busywork, it fosters an AI-native culture where technology and talent are unstoppable.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
United StatesCanadaDominican Republic
Unlimited PTO
Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.
Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.
Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.
Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.