Deliver Application Security services including assessments, threat modeling, and source code reviews for web, mobile, AI, and thick client applications.
Perform AI/LLM and agentic security assessments, including prompt injection, model bypass, and tool-calling exploitation, mapped to OWASP Top 10 for LLM and Agentic Applications.
Build and extend AI-driven tooling and automation harnesses to improve testing coverage, consistency, and efficiency.
United StatesCanadaDominican Republic
Unlimited PTO
Conduct manual penetration tests against core systems and AI systems, and build AI-assisted tooling to extend testing coverage.
Help define how we pentest AI, including LLM applications, agents, and agent-generated code.
Triage findings from SAST tools, fix vulnerabilities, and tune rules to reduce false positives.
Forward Financing is a fintech company that unlocks capital for small businesses across America. Since 2012, they have provided over $4.8 billion in funding to more than 92,000 small businesses and are recognized as a Best Place to Work.
Perform weekly code reviews to catch security vulnerabilities before they ship.
Coordinate external security audits and penetration tests, and track remediation.
Manage GRC documentation, run phishing simulations, and oversee security monitoring with weekend coverage.
EverAI builds the world's largest AI companionship platform, redefining relationships with AI. With a team of approximately 100 people, we are fully remote, fast-moving, and led by founders with a track record of scaling companies from zero to IPO.
Strengthen application security across modern software environments, including AI-enabled applications and services.
Embed security throughout the development lifecycle through code reviews, automated testing, and secure design practices.
Partner with engineering, product, DevOps, compliance, and incident response teams to identify and reduce risk.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. It operates as a remote-first organization with a focus on integrity, collaboration, and continuous learning.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.
Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.
Lead Affirm's enterprise AI security review process, evaluating architecture, data flows, and design of AI tools and agentic systems.
Threat model AI/LLM systems for risks like prompt injection, insecure output handling, and data poisoning, and drive remediation.
Build security guardrails, tooling, and policy-as-code to automate AI security and support cross-functional initiatives.
Affirm is a financial technology company that offers clear, predictable point-of-sale installment loans with no hidden fees. The company is remote-first and values transparency, care, and flexibility, with a focus on building a diverse and inclusive team.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.
Assess and validate web application vulnerabilities across targets, confirming exploitability and scope.
Reproduce findings hands-on using tools like Burp Suite and rate severity with CVSS/OWASP.
Write clear, accurate customer-facing finding descriptions and remediation guidance.
RunSybil builds Sybil, an AI-driven pentester that automates hacker intuition to discover vulnerabilities before exploitation. Founded in 2023, the company is backed by strong investor support and includes experts from OpenAI, Meta, Mandiant, Palantir, Cruise, Trail of Bits, and Aptiv.
Triage and validate incoming security vulnerability submissions for Bugcrowd managed programs.
Communicate directly with clients and researchers to clarify submission details and escalate critical bugs.
Maintain strong knowledge of OWASP Top Ten vulnerabilities and use interception proxies like Burp Suite.
We empower organizations to stay ahead of threat actors by uniting customers and elite hackers with our AI-powered Security Knowledge Platform. We are backed by General Catalyst and other investors, and our team is diverse and inclusive.
Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.
Jobgether is a company that uses AI-powered matching to streamline job applications. It is a technology platform connecting candidates with hiring companies, with a focus on efficient and objective candidate review.
Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
Design and implement AI-enabled workflows to scale security testing and threat related operations.
Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.
Perform security reviews of source code, smart contracts, and protocol changes across RootstockLabs projects.
Triage and validate bug bounty reports, assess severity, and coordinate remediation with engineering.
Build and operate security automation including AI-assisted code review, scanning, and findings-triage pipelines.
RootstockLabs builds Bitcoin-secured DeFi infrastructure enabling companies and financial institutions to offer borrowing, lending, investment, and payment solutions at global scale. They operate at the intersection of crypto and institutional finance with a global, diverse team.
Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.
Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.
Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.
Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.
Lead the security design, implementation, and controls for Jasper’s AI infrastructure and AI-powered internal workflows.
Own threat modeling for AI-specific risks and design controls for validating, logging, and auditing AI outputs.
Build security tooling and automated checks to let internal teams adopt AI capabilities without slowing down.
Jasper is the marketing agents platform that helps enterprises orchestrate AI agents for marketing execution. Founded in 2021, Jasper has team members across the U.S., Australia, and France, and is trusted by hundreds of enterprises including nearly 20% of the Fortune 500.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Penetration test web applications, APIs, and mobile applications for clients across various industries.
Work with technical and non-technical stakeholders to identify vulnerabilities and recommend remediations.
Collaborate closely with developers and teams to strengthen application security and drive continuous improvement.
Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing. They are a small team with big plans, recently securing Series A funding.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.