Author and execute functional test cases across the governance rule library to ensure correct PERMIT/DENY/ESCALATE outcomes.
Build negative and edge-case test coverage focused on actions the platform is designed to stop.
Maintain a traceable mapping between test cases, rules, and requirements while logging defects with clear reproduction steps.
Ubiminds connects Latin American tech professionals with software companies in the US and Canada. With 9 years in the market and GPTW-certified, it supports hundreds of professionals in data, design, product, and engineering, providing full back-office support and career guidance.
Add security tooling and checks to CI/CD pipelines with Python automation.
Perform offensive testing, triage findings, and patch straightforward vulnerabilities.
Collaborate with engineers, DevOps, and Fraud while leveraging AI for security work.
Super.com is a high-growth tech company helping people save, earn, and get more out of life. They are a remote-first, collaborative team that has hosted over 100 engineering internships and values career progression.
Conduct cutting-edge security research on GitLab's AI-powered DevSecOps capabilities, including the Duo Agent Platform and GitLab Duo Chat, to identify and validate vulnerabilities before they impact the platform or customers.
Develop novel testing methodologies and perform hands-on penetration testing, translating emerging threats into actionable security improvements for the next generation of AI-powered DevSecOps tools.
Collaborate with engineering teams to define security requirements, build tooling and automation for scalable security research, and mentor other team members in security best practices.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. With more than 50 million registered users and over 50% of the Fortune 100 as customers, GitLab fosters a high-performance culture driven by values and continuous knowledge exchange.
Drive offensive security through pen tests, red-team engagements, and threat modeling across Docker products and infrastructure.
Partner with engineering to implement secure architecture, automated reviews, and vulnerability management.
Build offensive tooling, develop exploits, and support incident response and security education.
Docker builds tools for developers to build, share, and run applications, including Docker Desktop, Docker Hub, and Docker Scout. It is a globally distributed, remote-first team trusted by 20M+ monthly users, focused on secure container development.
Build and maintain automation using Python and agentic coding tools to reduce manual GRC workflows.
Partner with Procurement, Legal, Engineering, and other teams on risk reviews and risk-informed decisions.
Affirm is a financial technology company that offers buy now, pay later services. The company values security as critical to its success and has a culture focused on engineering-driven risk management.
Author and execute functional test cases for core user journeys, including account creation, call/challenge/pool flow, and outcome resolution.
Test against the SECURITY DEFINER RPC layer, support settlement-path and money-movement testing, and exercise age-gating and identity-verification flows.
Log defects with clear repro steps in the shared tracker and re-test after fixes.
Ubiminds connects Latin American tech professionals with software companies in the US and Canada. With 9 years in the market and GPTW-certified, the company has supported hundreds of professionals in data, design, product, and engineering to grow in North American teams.
Help shape technical direction of security tooling and AppSec practices. - Lead secure design across major engineering projects, from threat modeling through architecture. - Perform advanced offensive security work, chaining vulnerabilities and proving business impact.
Super.com is a fast-paced, high-growth tech company that maximizes lives for customers and employees. It offers a remote-first culture, invests in career progression, and provides generous benefits including unlimited PTO and parental leave.
Lead end-to-end technical onboarding and configuration of bug bounty, vulnerability disclosure, and pentest programs for customers.
Serve as technical point of contact during launches, providing guidance on vulnerability triage and integration best practices.
Manage program timelines and dependencies, proactively communicating with stakeholders to ensure on-time delivery.
Bugcrowd is a crowdsourced security platform that empowers organizations to stay ahead of threat actors by uniting hackers and AI-powered technology. The company, backed by General Catalyst and others, fosters a diverse and inclusive culture where employees from all backgrounds feel like family.
Design, implement, and maintain internal tooling for acquiring and parsing recaptured underground data.
Build and deploy cloud infrastructure using Infrastructure as Code technologies.
Collaborate with the research team to support targeting and collection of new data sources.
SpyCloud transforms recaptured darknet data to disrupt cybercrime. They have over 250 cybersecurity experts and foster a collaborative, innovative culture.
Support and improve existing test automation for a CCaaS backend.
Identify and troubleshoot defects, and validate new features.
Ensure system stability, scalability, and compatibility with evolving product functionality.
Miratech is a global IT services and consulting company that brings together enterprise and start-up innovation, supporting digital transformation for some of the world's largest enterprises. They retain nearly 1000 full-time professionals, have a 99% project success rate, and a culture of Relentless Performance.
Perform high quality penetration testing on software, platforms, and services.
Conduct manual code review and vulnerability hunting to find security flaws.
Collaborate with engineering teams to strengthen security controls and mentor other security practitioners.
Atlassian develops software products that help teams collaborate and unleash their potential. With a distributed-first culture, they value diversity and inclusion, and employ thousands worldwide.
Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.
AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.