Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.
YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Proactively identify and drive security improvements across the product and platform.
Partner with engineering teams to threat model new features and review designs early in development.
Build and improve security tooling, libraries, and workflows to make secure development the default path.
Fellow is an AI meeting assistant that helps teams record, transcribe, summarise, and act on their meetings. We are a Series A company backed by major venture firms, with a remote-first culture and a growing team.
Threat model new product features and integrations, hardening systems with effective controls.
Operate and evolve the application security toolchain, keeping it high-signal for developers.
Own day-to-day security operations across the detection stack, triaging and resolving incidents.
Gauntlet builds the financial systems of the future, operating across the entire onchain finance stack to offer vault products for institutional clients. They serve over $1.5B in client TVL and combine traditional finance with crypto-native expertise.
Develop processes, tooling and automation to scale incident management response and mitigate risks.
Collaborate with security, engineering, product, support, and business operations to identify detection use cases.
Maintain security logging platform and stay updated on threats to improve detection mechanisms.
ClickHouse is a leading real-time analytics, data warehousing, observability, and AI workloads company with over 4,000 customers and rapid growth, validated by a $400M Series D funding round. The company values innovation and collaboration, offering a remote-friendly culture with a global team.
Build secure-by-default infrastructure and automation to eliminate entire vulnerability classes across money-moving systems.
Own application security, threat modeling, and vulnerability disclosure from design review to production.
Partner with engineering to set security standards, make risk-based decisions, and ship fast without compromising safety.
Flex is building the AI-native private bank for business owners, re-architecting the entire financial system for entrepreneurs. Since launching in 2023, Flex has scaled to nine-figure annualized revenue, raised $100M+ in equity and $300M+ in debt, and operates with a high-bar, low-ego culture focused on speed and execution.
Own threat modeling and secure code reviews for new products and features.
Maintain and tune AppSec tooling, and run the bug bounty program.
Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.
Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
You cover a broad range of security work including hands-on coding, incident response, and threat hunting.
You review and triage security submissions and bug bounties, and help improve incident response processes.
You communicate security requirements to non-technical teams and support access governance and permission management.
Eneba builds an open, safe, and sustainable marketplace for gamers. They support over 20 million active users and foster a culture of ownership, growth, and collaboration.
Champion a secure by default culture, building defense in depth into frameworks and processes.
Develop security requirements and work directly with teams to build them into new applications.
Run security risk assessments, hands-on penetration testing, and threat modeling.
Grow Therapy is a three-sided marketplace that empowers therapists and patients by providing technology and insurance support. The company has raised over $328M in funding, employs roughly 145 engineers, and values a mission-driven culture.
Champion secure-by-default culture by embedding defense-in-depth principles into engineering frameworks and development practices.
Conduct hands-on source code reviews, threat modeling, and security assessments across microservice architectures.
Build automation and frameworks to eliminate repetitive security work and create scalable security capabilities.
Jobgether is a company that uses AI-powered matching to streamline job applications. It is a technology platform connecting candidates with hiring companies, with a focus on efficient and objective candidate review.
Design and implement security controls across applications, cloud infrastructure, and development environments.
Conduct architecture reviews, threat modeling, and security assessments for new products.
Identify, prioritize, and remediate vulnerabilities across the technology stack.
SignalFire partners with top early-stage startups that are shaping the future of technology. They have a portfolio of over 200 innovative companies across AI, cybersecurity, healthtech, fintech, developer tools, and enterprise SaaS.
United States
Unlimited PTO
16w maternity
16w paternity
Lead the technical direction for Security Product Engineering at DoorDash globally.
Set and execute the vision for Proactive Security, Bug Bounty, and Vulnerability Management teams.
Partner cross-functionally to build proactive security controls that enable secure by design practices.
DoorDash is a technology and logistics company that built a scalable delivery network for consumers, merchants, and Dashers. They are growing rapidly and committed to diversity and inclusion.
Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.
Lead the Security Posture Management team to secure GitLab's own software factory and drive comprehensive rollouts of security capabilities.
Serve as Customer Zero for GitLab security features, capturing adoption friction and feeding insights to Product and Engineering.
Establish proactive software supply chain security, including third-party governance, trusted dependency controls, and SBOM requirements.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity and reduce security risk. With over 50 million registered users and more than 50% of the Fortune 100 trusting them, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.
Serve as the security subject matter expert on customer calls, owning responses to security questionnaires and due diligence requests.
Operate and tune security tools including CrowdStrike EDR, Entra ID identity controls, and vulnerability management.
Drive the SOC 2 Type 2 compliance program using Vanta, maintaining controls, policies, and vendor risk reviews.
AssetWatch is a remote-first industrial condition monitoring company that helps manufacturers predict equipment failure before it happens. The team includes world-renowned engineers and distinguished business leaders, united by a goal to build the future of predictive maintenance.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Own the vulnerability management lifecycle across Glean's technology stack, from discovery through remediation and reporting.
Harden base OS images and secure open-source dependencies and the broader software supply chain.
Integrate SAST, DAST, dependency scanning, and automated security validation into CI/CD pipelines.
Glean is the Work AI platform that helps everyone work smarter with AI. With over 1,000 employees across more than 25 countries, we foster a diverse, inclusive workplace and are recognized as one of the world's most innovative companies.
FirstPrinciples is a research company building AI for scientific discovery. We're a fast-growing, remote-first team of builders, researchers, engineers, and thinkers working across Canada, the US, the UK, and expanding globally.