Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.
Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.
Design and ship scalable security solutions to bridge the gap between security and engineering teams.
Build cooperative partnerships with product and engineering teams to integrate robust security capabilities at scale.
Drive security risk reduction through technical leadership, security reviews, and mentorship across engineering teams.
Twilio is a communications platform that delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide to craft personalized customer experiences. The company has a remote-first work culture with a strong focus on connection, global inclusion, and diverse experiences, making a global impact each day.
Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.
Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.
Own key security domains such as vulnerability management, application security, API security, and supply chain security.
Partner with engineering teams to integrate security into design reviews, threat modeling, CI/CD pipelines, and developer workflows.
Develop and improve security tooling and automation to reduce manual effort and leverage AI for triage and detection.
NinjaTrader is an industry-leading trading platform and futures broker that empowers traders with award-winning software and brokerage services. Since 2003, the company has grown to over 2 million users and is the number one rated futures brokerage worldwide, fostering a dynamic culture focused on social connection, professional development, and employee recognition.
Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.
Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.
Strengthen company-wide security posture through hands-on engineering, collaboration, and pragmatic standards, focusing on application security, cloud and infrastructure security, and secure development practices.
Define and implement scalable security standards supporting SOC 2 readiness through practical, automated, and auditable solutions, partnering with Engineering, Infrastructure, IT, Product, Legal, and other teams.
Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, and operational visibility.
Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns by combining real creator relationships, trusted intelligence, and expert guidance. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns deliver results.
Design and implement security controls across Mable's platform, applications, and infrastructure
Embed security into the software development lifecycle through design reviews, threat modeling, and code reviews
Lead vulnerability assessments and coordinate remediation efforts across engineering teams
Mable is one of Australia's leading healthtech platforms connecting people with disability and older Australians with independent support workers. With over 25 million hours of support facilitated since 2014, they have been recognized on AFR's Top 100 and Deloitte Tech Fast 50, fostering a purpose-driven and dynamic team environment.
Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement.
Lead triage and technical validation of incoming reports across multiple intake channels, driving end-to-end vulnerability remediation.
Collaborate with the Security Incident Response Team on active incidents and perform targeted code reviews.
Mozilla Corporation is a non-profit-backed technology company that has shaped the internet for the better over the last 25 years. With over 225 million people using our products monthly, we are a mission-driven organization focused on privacy, open-source software, and reclaiming the internet for people.
Define security requirements and design application architectures following a secure-by-default approach.
Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.
Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.
Lead implementation and optimization of AppSec tools such as SAST, DAST, and SCA across client environments.
Conduct manual application and API security assessments, identifying vulnerabilities and recommending remediation strategies.
Advise clients on secure SDLC practices and integrate security tools into CI/CD pipelines.
The company is a cybersecurity consulting firm that helps organizations design and operationalize application security programs. It operates with a remote-first culture and a collaborative, client-facing team.
Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.
Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.
Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.
ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.
Set and own strategic roadmaps for assigned security partner pod and work directly with product, engineering and security leaders to ship product security outcomes.
Prioritize customer experience, ergonomics and thoughtful security design to prevent adverse impact from security flaws.
Go deep and become an expert in the Dasher Logistics engineering vertical, focusing on resolving classes of security vulnerabilities.
DoorDash is a technology and logistics company that empowers local economies by enabling door-to-door delivery. The company is growing rapidly and is committed to diversity and inclusion, offering comprehensive benefits and a focus on employee well-being.
Provide strong leadership as a security thought leader across Delinea's product offerings.
Perform end-to-end security architecture reviews and threat modeling.
Maintain and mature Product Security tooling such as SAST, SCA, DAST, ASPM.
Delinea is a pioneer in securing human and machine identities through intelligent, centralized authorization. They are a global team of passionate problem-solvers, with a culture of innovation, respect, and fairness.
Partner with product and engineering teams to identify risks early and build security into new features.
Lead threat modeling and secure design reviews for new products and architecture changes.
Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.
Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.
Perform hands-on security testing and code review across web applications and APIs.
Conduct threat modeling and embed secure development practices into the SDLC.
Build and tune security tooling, including SAST, DAST, and CI/CD automation.
Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.
Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
Improve secure development practices through code reviews, threat modeling, and security design reviews.
Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.
Define and enforce security requirements for software products, features, and components.
Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.
symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.
Lead security discovery workshops and translate high-level architectural requirements into actionable security roadmaps.
Design end-to-end cloud security frameworks and document controls for SOC 2 and HITRUST compliance.
Establish governance and security processes for AI and manage vulnerability remediation with development teams.
Ollion is a global technology partner that helps organizations solve their toughest business challenges in AI, data, and cloud. They are a remote-first, globally distributed team focused on making a world of difference through innovation and collaboration.
Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.
The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.