Remote Cyber security Jobs · Threat Modeling

Job listings

Unlimited PTO

  • Assess ServiceNow instance configurations against security baselines and identify misconfigurations.
  • Triage and validate customer-reported security findings related to instance configuration.
  • Partner with cross-functional teams to resolve complex security issues and drive systemic improvements.

ServiceNow is the AI control tower for business reinvention, enabling AI-powered workflows for enterprises. The company serves 85% of the Fortune 500 and fosters an AI-native culture focused on innovation and talent.

  • Identify and reduce security risk across AWS, Kubernetes, containerized workloads, and platform infrastructure.
  • Conduct threat modeling, architecture reviews, and technical risk assessments for platform and infrastructure systems.
  • Partner with infrastructure, platform, and SRE teams to design practical controls and secure-by-default patterns.

Supabase is the Postgres development platform, providing a complete backend solution including Database, Auth, Storage, Edge Functions, Realtime, and Vector Search. With over 540,000 community members and having raised over $1B, our globally distributed team of ~400 people operates across 60+ countries with deep open-source values.

  • Embed security into the software development lifecycle through threat modeling, secure design reviews, and secure-coding guidance that engineers actually adopt.
  • Own application security testing (code review, SAST/DAST, and triage) and drive issues to remediation, not just filing them.
  • Harden the software supply chain, build and automate security tooling, and serve as the internal security SME on product and workflow decisions.

Cogent is an Applied AI Lab building the next generation of AI agents for cybersecurity, using AI to assess petabytes of enterprise data and remediate critical breaches. We're backed by Greylock, have experienced rapid growth, and our team includes top minds from Stanford, Deepmind, and leading tech companies.

$103,886–$130,429/yr
5w PTO

  • Own cybersecurity compliance for connected hardware products, including threat modeling and security validation.
  • Translate security findings into technical documentation and risk assessments for regulatory frameworks like RED and CRA.
  • Collaborate with engineering teams to embed security early in the development lifecycle.

Nabu Casa develops the Home Assistant open-source smart home platform, focused on privacy and local control. The company is a distributed team with a culture of autonomy, ownership, and sustainability.

$139,000–$258,000/yr
US Canada Unlimited PTO

  • Design and implement layered AI guardrails and sandboxing to constrain AI behavior and secure enterprise workflows.
  • Partner with users to bake secure-by-default patterns into AI-assisted workflows and maintain an inventory of AI-to-service connections.
  • Continuously test guardrails through red-teaming and evaluate new AI tools to find secure ways to enable adoption.

Waabi, founded by AI visionary Raquel Urtasun, is the leader in Physical AI, developing autonomous transportation technology for commercial trucks and robotaxis. Backed by world leaders in AI and automotive, the company has offices in Toronto, San Francisco, Dallas, and Pittsburgh and is growing quickly with a diverse, innovative team.

$250,000–$275,000/yr

  • Lead and scale the product security program, defining strategy, roadmap, and metrics in alignment with company objectives.
  • Build and mentor a high-performing product security team, fostering technical excellence and sustainable execution.
  • Partner with engineering and product leaders to embed security throughout the software development lifecycle, leveraging AI and automation.

Tines provides an intelligent workflow platform that applies AI, automation, and integration to drive business results. Founded in 2018 with co-headquarters in Dublin and Boston, the company serves a diverse range of customers and fosters a culture of Simplicity, Speed, and Soundness.

  • Define the security architecture for Theo.
  • Secure agent identity and authority.
  • Lead threat modelling and secure design.

FirstPrinciples is a research company building AI for scientific discovery. We're a fast-growing, remote-first team of builders, researchers, engineers, and thinkers working across Canada, the US, the UK, and expanding globally.

Global 5w PTO

  • Own cybersecurity compliance for connected hardware products, including RED, EN 18031, and CRA.
  • Perform threat modeling, security validation, and manage vulnerability risks across firmware, cloud, and devices.
  • Collaborate with engineering teams to integrate security early and translate technical findings into compliance evidence.

Nabu Casa builds cloud services and hardware for the open-source Home Assistant smart home platform. It is a profitable, fully remote company with no external investors, funded by users, and supports several open-source projects.

$180,000–$180,000/yr
US Unlimited PTO

  • Get involved early in new products and features, using threat modeling and security design reviews to find problems before they reach production.
  • Dig into application architecture, APIs, authentication, authorization, data flows, cloud services, and third-party integrations to understand how systems could be attacked.
  • Own and improve security tooling across the development lifecycle, including SAST, DAST, dependency scanning, and secret scanning.

YipitData is a leading market research and analytics firm for the disruptive economy, raising $475M from The Carlyle Group at a valuation over $1B. They operate globally with offices in the US, APAC, and India, and have been recognized by Inc. as a Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.

  • Break things on purpose by threat-modeling and reviewing Solidity contracts, Rust blockchain state transition functions, and other critical systems.
  • Own protocol components from design review through production, ensuring secure architecture and implementation.
  • Track the adversary, follow industry hacks and exploits, and convert lessons into concrete improvements.

Matter Labs builds private settlement infrastructure using zero-knowledge cryptography for regulated institutions. They are a fully remote team of about 70, backed by a16z and Union Square Ventures, with eight years of production zero-knowledge infrastructure.