Remote Cyber security Jobs · Product Security

Job listings

  • Own threat modeling and secure code reviews for new products and features.
  • Maintain and tune AppSec tooling, and run the bug bounty program.
  • Design and evolve the secure SDLC, and partner with engineering teams to implement secure-by-default patterns.

Ondo Finance is building institutional-grade financial infrastructure for tokenized real-world assets. The company operates at the intersection of traditional finance and on-chain systems, with a focus on security and innovation.

$250,000–$330,000/yr

  • Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security.
  • Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first.
  • Treat incident response as core, not afterthought.

Tremendous is a global platform for businesses to send payouts like gift cards and money to anyone, anywhere, instantly. Trusted by 20,000+ organizations, they are profitable and fully remote with a high-documentation, low-meeting culture and an employee NPS in the high 80s.

  • Leads product security work across Black Duck's portfolio, including architecture reviews, threat models, vulnerability triage, and customer-facing security inquiries.
  • Maintains detection content in CrowdStrike NG-SIEM and Sumo Logic, contributes to SOAR automations, and coordinates vulnerability fixes with engineering teams.
  • Acts as an informal technical resource for less experienced team members, explains complex security topics to diverse stakeholders, and documents runbooks and SOPs.

Black Duck Software, Inc. helps organizations build secure, high-quality software, minimizing risks while maximizing speed and productivity. A recognized pioneer in application security with industry-leading tools and services, they partner with teams to maximize security and quality in DevSecOps.

  • Establish secure by design standards and target state security architecture across product development, covering threat modeling, secure design review, and vulnerability management.
  • Build a formal vulnerability management program encompassing traditional and AI-specific threats like prompt injection, model manipulation, and data exfiltration.
  • Provide senior technical leadership and build trusted partnerships across Product, Engineering, and Security teams.

Semperis is a cybersecurity company on a mission to be a Force for Good, protecting identity and data. We are one of America's fastest-growing cybersecurity companies and have been recognized as a top workplace.