Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.
Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.
Own and manage the application vulnerability remediation program, prioritizing findings and guiding developers.
Partner with engineering teams to validate fixes and implement long-term security improvements.
Define and maintain secure SDLC processes, including security reviews and threat modeling.
The company develops internet-facing financial software, APIs, and cloud-based solutions. It operates with a remote-first culture and emphasizes security and compliance.
Partner with product and engineering teams to identify security risks and implement secure solutions throughout the product lifecycle.
Lead threat modeling activities, secure design reviews, and security-focused code reviews to improve development practices.
Build, maintain, and improve application security tooling and participate in incident response activities.
The partner company is a fast-moving engineering organization focused on protecting modern software products and the sensitive data they manage. The team values innovation, inclusion, and continuous improvement, and offers a collaborative culture with high ownership.
Partner with product and engineering teams to identify risks early and build security into new features.
Lead threat modeling and secure design reviews for new products and architecture changes.
Perform security-focused code reviews and maintain application security tooling integrated into CI/CD.
Jump builds AI-powered tools that help financial advisors automate meeting prep, notes, and follow-up. It is a small startup with a culture that prioritizes security and trust, and security is core to the product.
Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.
Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features and APIs.
Develop and maintain scalable security tools and automation pipelines for vulnerability detection across the SDLC.
Contribute to security architecture reviews and support bug bounty programs and incident response.
Lime is a global leader in micromobility on a mission to make transportation shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered over a billion rides in 30 countries and is a fast-paced, lean, remote-first team.
Hunt for and close security vulnerabilities across Counterpart Assistant using custom tooling and AI-driven frameworks.
Harden systems, services, and endpoints while establishing strong security monitoring and safeguarding PHI.
Raise the security bar by reviewing critical pull requests, running training, and mentoring engineers on secure coding practices.
Counterpart Health, a subsidiary of Clover Health, builds an AI-enabled primary care tool called Counterpart Assistant that helps physicians diagnose and manage chronic conditions earlier. The company employs a remote-first culture with a diverse and inclusive team focused on transforming healthcare at scale.
Lead threat modeling and security architecture reviews with engineering teams by translating security risks into concrete development actions.
Architect, build, and maintain security tooling and integrations that make secure development the default in our CI/CD pipelines.
Design and deploy automated security testing to identify vulnerabilities early in the development process.
Abnormal Security protects the humans behind the world's most critical organizations from AI-powered cybercrime. More than 4,500 enterprises trust its behavioral AI platform.
Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
Serve as a product security point of contact for incidents, contributing to investigation, root-cause analysis, and post-incident improvement.
Lime is a global leader in micromobility, on a mission to build a future where transportation is shared, affordable, and carbon-free. A Time Magazine 100 Most Influential Company, Lime has powered more than one billion rides across 30 countries and is a fast-paced, lean, remote-first company.
Assist with source code review and secure coding improvements.
Use SAST, DAST, and SCA tools to identify and validate vulnerabilities.
Collaborate with teams to integrate security into CI/CD and SDLC processes.
This company is a technology-driven healthcare organization integrating security into software development. It fosters a collaborative remote culture and supports professional growth in cybersecurity.
Protect applications trusted by millions of users in the Web3 ecosystem.
Combine hands-on security engineering with threat modeling, code reviews, and developer enablement.
Embed security throughout the software development lifecycle to build resilient products.
This company builds products and infrastructure for the Web3 ecosystem, focusing on digital assets, identities, and blockchain technology. It is a globally distributed, remote-first team with a culture of security, autonomy, and innovation.
Perform hands-on security testing and code review across web applications and APIs.
Conduct threat modeling and embed secure development practices into the SDLC.
Build and tune security tooling, including SAST, DAST, and CI/CD automation.
Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.
Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
RainFocus provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, rapidly growing, and fosters a culture of innovation, teamwork, and fun.
Plan and execute application security testing across the software development lifecycle to identify vulnerabilities.
Communicate findings and risks to stakeholders and collaborate with teams to drive secure design practices.
Lead AI security initiatives including threat modeling and auditing third-party models and APIs.
Clear Capital is a national real estate analytics and valuation technology company that builds confidence in real estate decisions. Established in 2001, the company values integrity, empathy, and excellence in its team.
Partner with product and engineering teams to identify application security risks and recommend mitigations.
Read application code, configuration, and pull requests to understand security risks and suggest improvements.
Contribute to vulnerability management, automation, and security tooling to scale AppSec efforts.
Affirm is reinventing credit to make it more honest and friendly, providing consumers the flexibility to buy now and pay later without hidden fees. We are a remote-first company with a culture centered on people, transparency, and offering competitive benefits including health coverage and flexible spending.
Drive application security initiatives across the SDLC, partnering with engineering teams to promote secure coding and security-by-design.
Integrate security testing tools into CI/CD pipelines and automate security processes using modern AppSec and DevSecOps tools.
Perform vulnerability analysis, source code review, and support threat modeling and secure design reviews.
Devoteam Cyber Trust is the cybersecurity arm of the Devoteam Group, offering end-to-end cyber resilience and managed security services. With 800+ experts across EMEA, they are ISO 27001 certified and serve clients in over 20 countries.
Lead end-to-end response to product security incidents, from discovery to disclosure.
Own and evolve 1Password's PSIRT function, including severity frameworks and playbooks.
Drive coordinated vulnerability disclosure and partner with external security researchers.
1Password is a cybersecurity company providing enterprise password management and Unified Access Management, trusted by over 180,000 businesses. With $400M ARR and a remote-first culture, it values collaboration, transparency, and innovation.