Integrate security into the SDLC through automation, testing, and continuous improvement.
Identify, investigate, and remediate application and infrastructure vulnerabilities.
Develop tools and automation in Python, Go, or Terraform to improve security and developer productivity.
Corbalt is a technology company that partners with federal agencies to modernize and operate complex technology ecosystems, building shared platforms and reusable services. They are a remote-first team that values curiosity, kindness, ownership, and continuous learning, with roots in the Healthcare.gov recovery effort.
Design, implement, and maintain security controls across AWS environments, including IAM, VPC, encryption, and logging.
Integrate security checks into CI/CD pipelines and harden Kubernetes/EKS workloads using Terraform and policy-as-code.
Automate vulnerability management, security monitoring, and incident response to reduce cloud and application risk.
Electric Power Engineers provides consulting expertise and energy intelligence software solutions for power and energy clients, focusing on modern, secure, and resilient grid challenges. They are leaders in the renewables space and emphasize collaboration, innovation, and making an impact on communities and the environment.
You will own end-to-end data protection: architecting security infrastructure, managing PCI/SOC2 programs, and setting the security roadmap.
You will integrate security scanning (SAST, DAST, SCA) into CI/CD pipelines and harden containerized and cloud-native environments.
You will configure IAM and SSO platforms, manage EDR/DLP/SIEM tooling, and run security awareness training.
Campminder builds software for summer camps, enabling meaningful experiences for kids. With over 100 employees, they are stable, profitable, and have a values-led culture committed to work/life balance.
Lead and evolve the company's application security strategy, roadmap, and day-to-day operations.
Manage and optimize AppSec tooling including GitHub Advanced Security, Invicti, Hadrian, and Cloudflare WAF.
Build secure development standards, conduct security reviews, and partner with engineering teams on design and code review.
Beyond Finance helps everyday Americans escape debt and achieve financial freedom through compassionate, individualized care and customized solutions. The company is rapidly growing, has helped over 1 million clients, and fosters a forward-thinking culture focused on compliance and ethics.
Assist customers with application security testing tool configurations and triage support.
Lead AppSec Program maturity assessments using frameworks like BSIMM and SSDF.
Develop Strategic Roadmaps and deliver presentations to executive leadership.
Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. It is a recognized pioneer in application security, providing SAST, SCA, and DAST solutions.
Improve security design and controls within GCP and Kubernetes.
Champion secure development by integrating security best practices early into the software development lifecycle.
Build and automate security tooling for vulnerability detection, remediation, and compliance verification.
Virta Health is a healthcare company that reverses type 2 diabetes and obesity through individualized nutrition and clinical support. They have raised over $350 million from top-tier investors and partner with major health plans, employers, and government organizations.
Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.
Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.
Design, build, and scale application security capabilities to support secure software development across the enterprise.
Develop security patterns and guardrails for AI-assisted development and agentic workflows.
Integrate security tools with developer platforms to improve vulnerability management and automate remediation.
NBCUniversal is a leading media and entertainment company creating world-class content for film, television, streaming, and theme parks. As a subsidiary of Comcast, it fosters an inclusive culture and community engagement across a diverse global workforce of thousands.
Lead the development and implementation of security strategies, policies, and procedures.
Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.
Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.
Own CI/CD and infrastructure design across application teams, using agentic AI to build and validate pipelines.
Implement security, testing, and observability as designed-in requirements across all shipped products.
Collaborate with DevSecOps peers to build shared standards and coach engineers on AI-driven development practices.
ComPsych is the worldwide leader in organizational mental health, well-being, and absence management. Their solutions touch more than 160 million lives across 200 countries, and 40% of the Fortune 500 choose them.
Design and build secure CI/CD pipelines with integrated security tooling to accelerate product delivery.
Harden cloud infrastructure on AWS and Azure using infrastructure-as-code and enforce policy with OPA or Sentinel.
Lead threat modeling, incident response, and mentor engineers on secure coding and operational security.
PAR Technology provides software and hardware solutions for over 100,000 restaurants in 110+ countries. A publicly traded company with a focus on innovation and collaboration, it fosters a culture of continuous improvement.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Embed security into every phase of the SDLC and champion secure design for Gen AI and agentic AI tools.
Perform secure code reviews, threat modeling, and establish secure API patterns across engineering teams.
Operate the application vulnerability management lifecycle and communicate risk to engineering and business leaders.
GameChanger builds a platform for youth sports, helping families elevate the next generation through community and technology. They are a remote-first, dynamic tech company based in New York City, solving major challenges in youth sports.
Act as a strategic security leader by defining and driving cloud security principles, standards, and reference architectures across the organization.
Partner with DevOps and CI/CD engineers to embed shift-left security practices throughout the software development lifecycle.
Assess, design, and implement security processes and controls to meet security, compliance, and audit requirements.
LastPass delivers Secure Access Essentials, helping individuals and organizations manage and protect access to AI, applications, and credentials straight from the browser. Trusted by more than 100,000 businesses and millions of users worldwide, they blend strong security with everyday simplicity in a remote-first, collaborative culture.
Perform application security testing and vulnerability assessments on web applications, APIs, and CI/CD pipelines.
Support DevSecOps tool integration and automation, including security scanning and policy enforcement.
Develop proof-of-concept secure reference implementations and utility applications to demonstrate best practices.
Ardent supports the federal government's most critical national security and defense priorities. They offer competitive pay, comprehensive benefits, and a culture that values dedication and flexibility.
Build and maintain security infrastructure across AWS and Kubernetes, including telemetry pipelines, cryptographic material lifecycle, and compliance automation.
Engineer agentic AI workflows using tools like Claude Code and MCP integrations to automate security tasks such as code review and drift detection.
Develop threat models and embed security controls into deployment pipelines to prevent vulnerabilities at build time.
Lumin Digital provides cloud-native digital banking solutions for credit unions and banks. The company fosters a culture of trust, respect, and boldness, encouraging innovation and collaboration in a fully remote, async-first environment.
Lead threat modeling and security reviews across Wiz's products and cloud infrastructure, identifying attack surfaces and developing scalable mitigation strategies.
Build automation, policy-as-code, and security tooling to enable development teams to shift left and integrate security into workflows.
Design and implement secure baselines for cloud resources and Kubernetes-based infrastructure, and drive vulnerability management efforts.
Wiz is a cloud security company enabling teams to secure cloud and AI applications by connecting code, cloud, and runtime. As one of the fastest-growing startups, trusted by over 65% of the Fortune 100, Wiz values world-class talent and creativity.
Build and operate Lumin's security fabric engineered for reliability and scale across hundreds of environments.
Design and maintain agentic AI workflows using tools like Claude Code and MCP integrations to automate security platform engineering.
Write production-quality Python applications and tooling supporting platform operations and AI-assisted workflows.
Lumin Digital is a trailblazer in digital banking solutions, providing cloud-native digital experiences for credit unions and banks. We foster a culture of curiosity, innovation, trust, and respect, with a focus on collaboration and continuous improvement.
Own application and product security: threat modeling, secure design review, and secure code review for a member-facing healthcare app.
Build and secure the AI-native agentic SDLC with security gates and controls for AI-generated code.
Manage security architecture across AWS environment, identity and access management, and third-party vendor integrations.
Oshi Health is on a mission to eliminate the impact of digestive health conditions through innovative GI care, operating a virtual-first platform. As a fully remote, SaaS- and cloud-native healthcare company, they foster a culture that thrives on diversity, with monthly DEIB discussions, and emphasize core values like owning the outcome and doing the right thing.
Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.
Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.