Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.
Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.
Conduct application security reviews including threat modeling, code review, and risk assessment for new features.
Perform and improve SAST/DAST operations, triage, validation, and remediation tracking in CI/CD pipelines.
Apply and improve AI security review processes for LLM-integrated features and agentic attack surfaces.
Monarch is a powerful, all-in-one personal finance platform designed to simplify money management. They are a fully remote team of do-ers led by experienced entrepreneurs, passionate about building a product people love.
Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.
The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.
Perform hands-on security testing and code review across web applications and APIs.
Conduct threat modeling and embed secure development practices into the SDLC.
Build and tune security tooling, including SAST, DAST, and CI/CD automation.
Prolific builds human data infrastructure for AI development, connecting researchers with a global participant pool to collect high-quality, ethically sourced behavioral data. They are a mission-driven company trusted by world-leading research institutions and AI labs, with a remote-first culture.
Review and threat model AI-powered product features, LLM integrations, and agentic workflows before launch.
Build reusable AI security primitives like guardrails, scanners, and policy checks to secure AI development.
Design security tooling to detect and prevent prompt injection, jailbreaks, and data leakage in AI systems.
Reddit is a community of communities built on shared interests, passion, and trust, hosting open conversations. With over 100,000 active communities and 126 million daily active users, it is one of the largest sources of information online.
Perform penetration tests of IT infrastructures, web applications, and web services.
Conduct security assessments in Active Directory, cloud environments (Azure, AWS), and mobile applications.
Analyze AI-powered applications and LLM integrations for vulnerabilities and misconfigurations.
SITS Deutschland GmbH is part of the SITS Group, a leading IT security provider offering holistic security solutions. The company has over 700 employees and fosters a culture of appreciation, team spirit, and work-life blending.
Design and ship security workflows combining deterministic analysis with LLM reasoning to find real vulnerabilities across languages and frameworks.
Engineer agentic pipelines and prompts that are precise, cost-aware, and trustworthy for security-critical work.
Push on hard problems in automated triage and validation to close the gap between finding and actionable fix.
Semgrep is a code security platform that helps teams catch and fix vulnerabilities before they ship. They are a venture-backed startup with a transparent culture that values respect and honesty.
Own the architectural integrity of the product and stand behind every shipment.
Take responsibility for code quality, security, and scalability across AI-generated code.
Build hands-on with AI development tooling, moving at pilot pace and hardening for scale.
Instructure creates intuitive products that simplify learning and personal development. They are a public company with a culture focused on empowering smart, creative people to innovate.
Define security requirements and design application architectures following a secure-by-default approach.
Conduct threat modeling, code reviews, and penetration testing on cloud-based web and mobile apps.
Implement, manage, and automate SAST/DAST/SCA security controls and WAF rules to enforce protection at scale.
Prima is a motor insurance company that uses data and technology to provide a great experience for drivers. They are trusted by over 5 million drivers and have over 350 engineers in their Engineering department, fostering a culture of curiosity and collaboration.
Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.
Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.
United StatesCanadaDominican Republic
Unlimited PTO
Lead application and product security across Forward-built, third-party, and AI-built software.
Evolve the pentest program and proactively build AI solutions within the appsec function.
Own remediation workflows and partner with teams to build controls for external exposure.
Forward Financing is a financial technology company that unlocks capital for small businesses across America. They are a recognized Best Place to Work with a remote-first culture and team members across the US, Canada, and Dominican Republic.
Oversee cybersecurity and technology risk management for assigned products, including strategy implementation and compliance.
Automate manual cybersecurity controls using AI-based tools and automation solutions.
Assess and evaluate cybersecurity risks for projects, third parties, systems, and information.
Talan is an international consulting group specializing in innovation and business transformation through technology. With over 7,200 consultants in 21 countries and a turnover of €850M, the company is committed to delivering impactful, future-ready solutions.
Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
Improve secure development practices through code reviews, threat modeling, and security design reviews.
Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.
Conduct security risk assessments of third parties, evaluating overall maturity and mapping data flows to assess supplier security risks.
Build security tooling and automation, contributing to development of internal applications and scripts.
Execute incident response efforts by identifying, investigating, and remediating security incidents.
BetterHelp is on a mission to make mental health care accessible to everyone by providing affordable online therapy. Founded in 2013, it is now the world's largest online therapy service with a network of over 30,000 licensed therapists, and it deeply invests in its team's well-being and professional development.
Contribute to secure-by-design practices and advance the S-SDLC program.
Mentor engineers on secure coding and career growth.
Evaluate and recommend AI-assisted security tooling.
Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.
Lead a specialized team of security engineers focused on application, cloud, and AI system security.
Champion shift-left security practices including threat modeling, secure code review, and developer training.
Define cloud security standards and enforce security for AI systems including LLM-based agents.
Acquia empowers ambitious brands to create digital customer experiences using open source Drupal. Headquartered in Boston, MA, it is a Great Place to Work-Certified company and among the world's top software companies.
Lead application security reviews, threat modeling, and secure code review for new features and significant product changes.
Operate and improve SAST, DAST, and SCA tooling, triage findings, and partner with engineering teams to harden the codebase.
Plan and execute internal penetration tests against web applications, APIs, and mobile clients, and own the vulnerability management lifecycle.
ButterflyMX empowers people to automate property access, operations, and security from a single platform, serving over 20,000 properties worldwide. As a distributed, primarily remote workforce, they seek intelligent, passionate, and collaborative individuals driven by a shared commitment to excellence and innovation.
Define security guardrails and perform risk assessments and red-team exercises for AI technologies.
Collaborate with Security, Architecture, Engineering, and Compliance teams throughout the AI solution lifecycle.
Advise on secure implementation and contribute to AI security awareness initiatives.
Inetum Polska is part of the global Inetum Group, driving digital transformation for businesses and public institutions. With over 28,000 professionals across 19 countries, the company fosters a diverse and inclusive work environment and actively supports employee development.