Conduct comprehensive penetration tests across applications, APIs, cloud environments, and infrastructure to identify vulnerabilities.
Assess security controls in multi-cloud environments (AWS, GCP) and review Infrastructure as Code configurations.
Collaborate with engineering teams to improve security practices and create high-quality technical documentation.
The company develops and secures products in a multi-cloud environment, focusing on cybersecurity. It fosters a collaborative and inclusive culture that encourages innovation and technical excellence.
Penetration test web applications, APIs, and mobile applications for clients across various industries.
Work with technical and non-technical stakeholders to identify vulnerabilities and recommend remediations.
Collaborate closely with developers and teams to strengthen application security and drive continuous improvement.
Cytix is a platform that threat models development tickets and creates security testing plans that include both manual and automated testing. They are a small team with big plans, recently securing Series A funding.
Lead end-to-end penetration testing and red team engagements for customer environments including internal networks, web applications, and cloud infrastructure.
Perform in-depth testing with manual techniques to find business-logic flaws and high-impact attack chains that automated tools miss.
Deliver high-quality client-ready reports with clear risk ratings, business impact, and practical remediation guidance.
Horizon3 is a fast-growing cybersecurity company whose NodeZero platform delivers autonomous pentests and assessment operations for organizations of all sizes. The team is a fusion of former U.S. Special Operations cyber operators, startup engineers, and cybersecurity practitioners, committed to a culture of respect, collaboration, ownership, and results.
Lead the maturation of Delinea's Offensive Security program, including penetration testing and red teaming operations.
Manage a team of penetration test engineers, set performance objectives, and provide mentorship.
Collaborate with Product Development, DevOps, IT, and SecOps to test security controls and report findings to technical and executive audiences.
Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization, empowering organizations to govern interactions across the modern enterprise. The company is a global, passionate team backed by TPG, valuing diversity, innovation, and a culture of respect and fairness.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Conduct advanced vulnerability research and security assessments across modern application and cloud stacks.
Develop proof-of-concept exploits and collaborate with cross-functional teams to strengthen customer security.
Provide mentorship to junior researchers and represent Cobalt in the security research community.
Cobalt provides offensive security testing via a SaaS platform and a community of over 400 vetted testers. The company is fully remote and values diversity and inclusion.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Identify and validate realistic attack paths across applications and infrastructure.
Develop safe proof-of-concept exploits to demonstrate security risks.
Partner with engineering teams to validate fixes and improve security posture.
A fast-growing technology environment focused on product security, protecting products used by millions of consumers. The culture emphasizes collaboration, proactive security practices, and leveraging AI to improve efficiency.
Champion a secure by default culture, building defense in depth into frameworks and processes.
Develop security requirements and work directly with teams to build them into new applications.
Run security risk assessments, hands-on penetration testing, and threat modeling.
Grow Therapy is a three-sided marketplace that empowers therapists and patients by providing technology and insurance support. The company has raised over $328M in funding, employs roughly 145 engineers, and values a mission-driven culture.
Conduct thorough security assessments and penetration testing to identify vulnerabilities in web and mobile applications.
Collaborate with development teams to integrate security best practices and design secure application architectures.
Lead incident response and ensure compliance with security standards and regulations.
Moniepoint Inc. is an all-in-one African financial platform serving 20 million businesses with payments, banking, and tools. As Nigeria's largest merchant acquirer, it processes over $250 billion annually and fosters a culture of innovation and teamwork.
Conduct sophisticated security assessments across client environments, identifying vulnerabilities missed by conventional approaches.
Develop targeted attack plans based on bespoke hypotheses and client-specific objectives.
Produce actionable, threat-based reports that translate technical discoveries into meaningful security improvements.
Jobgether uses AI-powered matching to connect candidates with roles. It is a platform focused on efficient, objective hiring, with a culture emphasizing technical excellence, radical candor, and collaboration.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Review system designs and implementations to identify security issues and align with best practices.
Develop cloud security architecture and implement automated security testing tools.
Promote DevSecOps principles through CI pipeline integration and Infrastructure as Code scanning.
Iterable is the leading AI-powered customer engagement platform that helps brands like Redfin and SeatGeek create dynamic experiences. With nearly 1,200 clients globally and a diverse workforce, we foster a culture of innovation and inclusion, recognized as one of Inc's Best Workplaces.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.
Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.
Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.
Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.
Build and harden secure CI/CD pipelines with security gates to catch issues before production.
Lead security architecture reviews and threat models for Kubernetes-based workloads on GCP and AWS.
Harden container images, Kubernetes configurations, and cloud IAM to minimize attack surface.
Chainguard is the trusted source for open source, delivering hardened, secure, and production-ready builds of open source software. The company is venture-backed by leading investors and serves Fortune 500 enterprises, with a culture that values customer obsession, intentional action, and trust.