Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Lead security reviews of architecture, code, and security-sensitive changes.
Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
Threat model new capabilities and build scalable guardrails that reduce recurring risks.
Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.
Contribute production-quality code to the application (Node.js and Python), shipping security fixes end-to-end.
Build AI-powered automation and manage a bug bounty program, evaluating and reproducing submissions.
Define secure-by-design patterns and drive security standards across the architecture, including AI-integrated features.
Fast-growing B2B SaaS company serving the life sciences and pharma space. A small, high-impact security team with an engineering-first mindset, building AI-native features.
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.
RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.
Build and tune the application security scanning program (SAST, DAST, SCA, container and IaC) to surface real risk.
Triage scan, penetration test, and bug bounty findings, prioritizing by risk and tracking remediation to closure.
Partner with engineering on threat modeling, secure-coding standards, and hands-on fixes.
Turquoise Health is a Series C price transparency platform building a more open, efficient healthcare marketplace for finance leaders. They're a remote-first US team backed by top investors, powering transparency for 300+ enterprise organizations.
Work with engineering teams to run security assessments and threat models for cloud-native and SaaS products.
Review cloud application architectures, build automation for security controls, and participate in incident response.
Communicate security risks to technical and non-technical audiences and champion improvements to security processes.
Atlassian provides collaboration software solutions designed to help teams work better together. The company has a global, inclusive culture where the unique contributions of all employees create success.
Get hands-on with our Go codebase, AWS and Kubernetes environment, SIEM, and security services, contributing security feedback to design docs and shipping your first fix or detection.
Own a security domain end to end, such as cloud hardening or detection engineering, and ship reusable Go security middleware adopted by service teams.
Drive multi-quarter initiatives like default-deny networking, expand Kubernetes security, and automate compliance evidence for audits.
Bastion provides regulated infrastructure for businesses to hold, move, and issue stablecoins, combining custodial wallets, payment orchestration, and issuance. As a 40-person startup, we operate through our own regulated entities with built-in compliance and risk controls.
Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.
Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.
Build automated triage and validation systems for bug bounty findings at scale.
Use LLM/agent-based reasoning to validate complex vulnerabilities and drive root cause.
Develop customer-facing security testing capabilities on the Vercel platform.
Vercel is the agentic infrastructure company that helps builders ship software with speed, security, and exceptional developer experience. Trusted by OpenAI, PayPal, Ramp, Supreme, and millions of developers worldwide, Vercel is an open, innovative workplace.
Partner with engineering teams on architecture reviews, threat modeling, and secure design to translate risks into practical recommendations.
Improve security tooling, strengthen SDLC and CI/CD controls, and serve as a GCP security subject matter expert.
Drive vulnerability management, coordinate penetration testing, and enable engineers through documentation and mentorship.
Doppel builds an AI-native platform for social engineering defense, protecting executives, employees, customers, and brands from phishing, impersonation, and fraud across digital channels. Backed by Andreessen Horowitz and Bessemer Venture Partners, it is a rapidly growing Series C startup with a team focused on cybersecurity expertise and startup velocity.
Develop playbooks and address security-related tasks in AWS serverless environments.
Drive improvements in security posture, including application, endpoint, and access management.
Collaborate with product engineering teams to raise the bar for security in CI/CD, dependency management, and secure design reviews.
Stedi is building a new healthcare clearinghouse and RCM engine, accessible via API. With $142 million in funding and a lean, passionate team, they ship products weekly and prioritize automation and eliminating toil.
Bridge security and platform engineering to make infrastructure secure by design and provable at audit.
Own infrastructure vulnerability management and automate security guardrails on Azure and Kubernetes.
Build detection as code, widen SIEM coverage, and eliminate long-lived credentials.
360Learning is a collaborative learning platform for turning internal experts into champions for employee, customer, and partner growth. Founded in 2013, it has 400+ employees across North America and EMEA with an inclusive Convexity culture.
Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
Build offensive tooling, develop exploits, and support incident response and security education.
Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.
Design, build, and operate services powering the Exposure Management platform across the full production lifecycle.
Work with large volumes of security data to improve scanning, asset discovery, and vulnerability prioritization.
Collaborate with product, threat research, and client-facing teams to turn security requirements into production-ready features.
They build an external attack-surface and Exposure Management platform that helps organizations discover internet-facing assets and prioritize vulnerabilities. They foster a collaborative, curious engineering culture with an AI-first approach to security and scale.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling that enables development teams to 'shift left' and integrate end-to-end security into their workflows.
Drive vulnerability management and remediation efforts, prioritizing issues, implementing mitigations, and designing strategic preventative controls in software supply chains from development through production.
Wiz is redefining security for the AI era, enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. As one of the fastest-growing startups ever, we are trusted by over 65% of the Fortune 100 and scan over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.
Apply your cybersecurity expertise to train next-generation AI systems with real-world input.
Analyze, debug, and resolve software bugs and vulnerabilities across diverse codebases.
Perform security audits, penetration testing, and contribute to backend development.
Our client is a venture-backed AI company developing intelligent systems via human expertise and machine learning. They are rapidly growing with over $40 million in funding and a global network of experts.
Own vulnerability management across code, dependencies, images, and cloud config, automating triage and remediation.
Build and expand security gates in CI/CD pipelines, define secure cloud baselines, and drive least privilege identity.
Partner with DevOps on paved roads for secure-by-default development and lead incident response.
Aegis AI is a startup founded by ex-Google engineers who built Safe Browsing and reCAPTCHA, focused on stopping adversarial AI attacks. The team is flat, flexible, and fast, with engineers owning decisions and clear KPIs.
Conduct AWS security reviews and validate best practices across the cloud environment.
Implement security improvements and fix custom-built security tools with the Lead Security Architect.
Participate in on-call rotation to ensure 24/7 system availability for customers.
Mapbox is the leading real-time location platform powering location-aware businesses with maps, navigation, and location data tools. With over 4 million registered developers and a globally distributed team, Mapbox fosters a culture of flexibility, security, privacy, and inclusion.
Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.
Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.