Own cloud and product security across AWS and GCP, setting baselines for IAM, networking, data protection, and workload configuration.
Partner with platform, SRE, and product teams to embed practical security controls into developer workflows and automate guardrails in delivery pipelines.
Perform security architecture reviews, threat modeling, and incident response, and drive systemic improvements with meaningful security metrics.
Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.
Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.
Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.
Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
Review cloud application architectures, build automation for security controls, and participate in incident response.
Communicate security risks to technical and non-technical audiences and champion improvements to security processes.
Atlassian provides collaboration software solutions designed to help teams work better together. The company has a global, inclusive culture where the unique contributions of all employees create success.
Own identity, SSO, and device management across Google Workspace and macOS, automating joiner and leaver flows from day one.
Secure cloud and SaaS environments by managing IAM, cloud guardrails, and vulnerability management end to end.
Bring a security perspective to incidents and audits, using AI-assisted workflows to reduce manual work.
Maze is a user research platform that helps product teams build the right products faster by making user insights accessible. With less than 150 team members and a global remote workforce, Maze fosters a culture of transparency and inclusion.
Design and enforce cloud security controls and IAM policies across multi-account AWS environments.
Embed automated security tools into CI/CD pipelines to catch vulnerabilities pre-deployment.
Develop automated detection and remediation workflows using Python, Bash, or Go and IaC tools.
The Tripadvisor Group connects people to experiences worth sharing, aiming to be the world's most trusted source for travel and experiences. It is a publicly traded company with a global portfolio of travel brands, fostering a culture of collaboration, agility, and traveler-first mindset.
Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.
The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.
Implement and maintain AWS security configurations across development, staging, and production environments.
Operate SAST, DAST, and SCA tools integrated into CI/CD pipelines to remediate vulnerabilities.
Support compliance efforts such as SOC 2 Type II and ISO 27001 audits and improve security processes.
Pacvue is a leading software suite for eCommerce advertising, sales, and intelligence, helping brands grow on Amazon, Walmart, Instacart, and other marketplaces. The team is energetic, passionate, and focused on innovation, with a mission to help brands and sellers succeed.
Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
Perform security assessments, vulnerability remediation, and lead key security programs.
Automate security processes and integrate DevSec practices into the software development lifecycle.
Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.
Own security of the software build and release pipeline, cloud environments, and AWS identity and access.
Operationalize a 15-domain cloud security framework and CrowdStrike CSPM across all AWS estates.
Mentor a junior cloud security engineer and build paved-road patterns for engineering teams.
Vermont Information Processing is a leading beverage industry technology provider trusted by over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security with executive sponsorship and a funded roadmap.
Own and execute application, cloud, and API security across the platform.
Build detection, response, and hardening for a high-scale SaaS environment.
Collaborate with engineers to embed security into the SDLC and enterprise client requirements.
YGO.ai is a VC-funded AI tourism platform that provides AI search and recommendation engines for major travel enterprises. As a VC-funded startup, we maintain a hands-on, engineering-driven culture where security is integral from the start.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Lead the technical vision for platform hardening across AWS and GCP, including tier-0 access and secrets services.
Own the hardening roadmap for critical cloud infrastructure and drive operational excellence with rigorous on-call practices.
Mentor a global team of engineers and partner cross-functionally to build secure-by-default controls.
DoorDash is a technology and logistics company building the most reliable delivery network for consumers, merchants, and dashers. The company is growing rapidly and fosters a culture of learning, customer obsession, and inclusive leadership.
Develop playbooks and address security-related tasks in AWS serverless environments.
Drive improvements in security posture, including application, endpoint, and access management.
Collaborate with product engineering teams to raise the bar for security in CI/CD, dependency management, and secure design reviews.
Stedi is building a new healthcare clearinghouse and RCM engine, accessible via API. With $142 million in funding and a lean, passionate team, they ship products weekly and prioritize automation and eliminating toil.
Integrate AppSec tools into CI/CD pipelines and manage application security vulnerabilities.
Monitor and respond to security incidents, tuning WAF policies and security rulesets.
Collaborate with IT partners to perform security reviews and remediate findings across cloud platforms.
EMCOR Group, Inc. is a Fortune 500 leader in mechanical and electrical construction, industrial and energy infrastructure, and building services. As a large company with a diverse portfolio, it emphasizes a culture of security and collaboration.
Protect clients' digital assets by designing and implementing security solutions across multi-cloud environments.
Work closely with senior leadership and mentor junior team members while contributing across cybersecurity engineering, GRC, and security strategy.
Take ownership of client relationships and bring people along, adapting between engineering, strategy, and compliance conversations.
Riveron helps organizations implement leading governance, risk and compliance practices by combining deep expertise with pragmatic partnership. The firm serves startups, mid-market companies, and PE-backed portfolios with a collaborative and entrepreneurial culture.
Protect cloud infrastructure, applications, and customer data across a modern technology environment.
Identify and remediate vulnerabilities directly in application repositories and infrastructure code.
Build and tune SIEM detections, strengthen AWS security controls, and lead incident response.
Cloudbeds is a hospitality technology company providing cloud-based management solutions for lodging businesses. It operates as a remote-first organization with a globally distributed team across 40+ countries and a small, senior security team.
Establish and enforce a unified security posture across GCP and OCI, including guardrails, IAM policies, and centralized monitoring.
Validate cloud deployments meet FedRAMP High, FISMA, and NIST 800-53 requirements, working with governance and audit teams.
Identify vulnerabilities, policy deviations, and architectural risks, and drive remediation.
Latitude is a growing Service-Disabled Veteran Owned company within the Federal Sector, working with various federal clients across multiple agencies. They foster a remote work-from-home culture, invest in employee growth, and strive for innovation to break through technology and government barriers.
Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.
Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.
Fix vulnerabilities across the stack by writing pull requests in application repositories and Terraform.
Build and tune SIEM detections, mapping coverage to MITRE ATT&CK and reducing false positives.
Lead incident response, harden AWS estate, and automate security workflows with code.
Cloudbeds is a hospitality management platform powering hotels across 150 countries, processing billions in bookings annually. The company is a remote-first team of 650+ across 40+ countries, recognized for innovation and an inclusive culture.