Drive and conduct security testing and penetration tests across applications, infrastructure, and networks to identify exploitable vulnerabilities.
Manage and implement security testing tools and frameworks to simulate real-world attacks and validate security controls.
Design and implement AI-enabled workflows to scale security testing and threat related operations.
Valon is building the AI-native operating system for regulated finance, starting with mortgage servicing. They are a Series C company backed by a16z, managing over $110 billion in loans, with a culture that values security and innovation.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Lead the long-term technical strategy for offensive security, including red teaming and adversary simulations.
Conduct deep-dive vulnerability research and partner with DevOps to build automated security guardrails.
Mentor senior and mid-level engineers to foster a security-minded development culture.
Greenlight is a family technology company that helps families raise financially smart kids through its suite of products including the Greenlight app, debit card, and safety features. With over 6.5 million family members, Greenlight fosters a culture of innovation and collaboration to make family life easier.
Perform high quality penetration testing on software, platforms, and services.
Conduct manual code review and vulnerability hunting to find security flaws.
Collaborate with engineering teams to strengthen security controls and mentor other security practitioners.
Atlassian develops software products that help teams collaborate and unleash their potential. With a distributed-first culture, they value diversity and inclusion, and employ thousands worldwide.
Plan and execute red team operations, adversary simulations, and targeted security assessments focused on cloud environments.
Evaluate the security of cloud infrastructure, identity architectures, CI/CD pipelines, and containerized workloads.
Identify and validate attack paths involving IAM misconfigurations, overprivileged roles, and secrets exposure.
We empower the people who run physical operations with tools to make their work safer, more productive, and more profitable. We serve nearly 100,000 customers across industries, from Fortune 500 enterprises to small businesses, fostering a diverse and inclusive workplace.
Own production security across a multi-cloud footprint (AWS, GCP, Azure, Vercel) and secure multi-tenant SaaS, dedicated VPC, and air-gapped deployments.
Secure the Hermes Agent platform with sandboxing, kernel-level isolation, and agent identity controls, and lead SOC 2 compliance.
Harden identity management, vulnerability management, incident response, and secure software development lifecycle practices.
Nous Research builds open-source AI language models and agents, including Hermes Agent, used by consumers and Fortune 500 enterprises across various deployment environments. The company is a fast-growing startup with a high-velocity, open-source-native engineering culture that values security and pragmatism.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.
Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.
Serve as the senior technical authority for penetration testing and red-team delivery across federal programs.
Define and improve assessment standards, rules of engagement, and technical methodologies.
Guide technical teams, mentor staff, and communicate findings to government customers.
The company provides offensive security assessments and red-team services for sensitive federal cyber environments. The team is remote and focuses on high-impact national cybersecurity missions.
Own and execute application, cloud, and API security across the platform.
Build detection, response, and hardening for a high-scale SaaS environment.
Collaborate with engineers to embed security into the SDLC and enterprise client requirements.
YGO.ai is a VC-funded AI tourism platform that provides AI search and recommendation engines for major travel enterprises. As a VC-funded startup, we maintain a hands-on, engineering-driven culture where security is integral from the start.
Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.
Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Improve security design and controls within GCP and Kubernetes.
Champion secure development by integrating security best practices early into the software development lifecycle.
Build and automate security tooling for vulnerability detection, remediation, and compliance verification.
Virta Health is a healthcare company that reverses type 2 diabetes and obesity through individualized nutrition and clinical support. They have raised over $350 million from top-tier investors and partner with major health plans, employers, and government organizations.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Secure cloud infrastructure, applications, APIs, and AI-driven workflows.
Partner with engineering to embed security controls into production.
Lead vulnerability management and incident response activities.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. The company is a high-growth startup with a remote-first culture, emphasizing transparency, autonomy, and technical craftsmanship.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.
Lead the security design, implementation, and controls for Jasper’s AI infrastructure and AI-powered internal workflows.
Own threat modeling for AI-specific risks and design controls for validating, logging, and auditing AI outputs.
Build security tooling and automated checks to let internal teams adopt AI capabilities without slowing down.
Jasper is the marketing agents platform that helps enterprises orchestrate AI agents for marketing execution. Founded in 2021, Jasper has team members across the U.S., Australia, and France, and is trusted by hundreds of enterprises including nearly 20% of the Fortune 500.
Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Conduct threat modelling sessions using STRIDE with product and engineering teams, focusing on clinical safety, abuse, and business-logic threats.
Own and evolve the Secure by Design process, including self-evaluation screening, secure design review, and automated tooling against technical artefacts.
Perform automated application and API penetration testing against web, mobile backends, cloud-native services, and AI features, and lead third-party penetration engagements.
Numan is a digital health platform founded in 2018 that integrates diagnostics, medication, supplements, digital programmes, and doctor consultations to empower people to take control of their health. They are a 300+ person team distributed globally, guided by values of patient focus, learning, quality, collaboration, and care.
Translate security policy into practical, deployable solutions across applications, data environments, and AI systems.
Design, build, and deploy security controls for web applications, data pipelines, APIs, and Agentic AI systems.
Implement secure-by-design practices throughout the software development lifecycle, including code-level remediations and configuration hardening.
EnableComp provides Specialty Revenue Cycle Management solutions for healthcare organizations, leveraging over 24 years of industry-leading expertise. A multi-year recipient of the Top Workplaces award, they have been recognized as Black Book's #1 Specialty RCM Solution provider in 2024 and are among the top one percent of the Inc. 5000 fastest-growing private companies in the US for eleven years.