Lead Affirm's enterprise AI security review process, evaluating architecture, data flows, and design of AI tools and agentic systems.
Threat model AI/LLM systems for risks like prompt injection, insecure output handling, and data poisoning, and drive remediation.
Build security guardrails, tooling, and policy-as-code to automate AI security and support cross-functional initiatives.
Affirm is a financial technology company that offers clear, predictable point-of-sale installment loans with no hidden fees. The company is remote-first and values transparency, care, and flexibility, with a focus on building a diverse and inclusive team.
Perform security design reviews and threat modeling for new products and features, including AI-enabled services.
Conduct manual penetration testing of web, API, mobile, and cloud-native applications, and validate third-party findings.
Drive adoption of secure coding practices and improve security automation in CI/CD pipelines.
Iru is an AI-powered security & IT platform that unifies identity and access, endpoint security, and compliance automation for fast-growing companies. Backed by top investors and valued at $850 million, it serves customers like Cursor and Vercel, and is recognized for employee engagement.
Design and strengthen security features across Pigment's product and infrastructure, threat modeling new services and making architectural decisions.
Lead security investigations and incident response, manage vulnerability detection and remediation, and build detection engineering capabilities.
Drive the security roadmap end-to-end, working hands-on with code and infrastructure to balance risk and business benefit.
Pigment is an AI-powered business planning and performance management platform. Founded in 2019, the company has over 600 employees and has raised nearly $400M, recognized as a Gartner Visionary.
Lead security reviews of architecture, code, and security-sensitive changes.
Secure AI-powered products against prompt injection, unsafe tool use, and tenant isolation risks.
Threat model new capabilities and build scalable guardrails that reduce recurring risks.
Cohere is a security-first enterprise AI company building foundation models and products for business. It is a global team of researchers, engineers, and designers headquartered in Toronto with offices worldwide.
Conduct application and cloud security assessments to identify risks and vulnerabilities.
Collaborate with development teams to integrate security best practices into the SDLC.
Support vulnerability management, incident response, and security awareness education.
Business Wire is a leading global news release distribution service. The company is a large organization with a remote-first culture and offers competitive benefits.
Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
Perform security assessments, vulnerability remediation, and lead key security programs.
Automate security processes and integrate DevSec practices into the software development lifecycle.
Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.
Lead and scale Product Security and Security Operations teams to embed security throughout the software development lifecycle.
Define strategy, operating plans, metrics, and resource priorities aligned with the company’s highest risks.
Build strong partnerships with product and engineering teams to align on risk, response, and remediation.
Calendly takes the work out of scheduling, giving customers more time to focus on what truly matters. As a fast-growing company trusted by millions worldwide, we foster a strong security and engineering culture that attracts self-starters who thrive in dynamic environments.
Act as the bridge between architectural intent and operational reality, mediating conflicts between security requirements and feasible implementation.
Implement preventive, default-on security controls across cloud and enterprise environments, codified as policy- and infrastructure-as-code.
Define and enforce security requirements for AI-powered features, including model access controls, prompt-injection mitigations, and output validation.
Rithum is the world's most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. More than 40,000 companies trust Rithum to grow their business across hundreds of channels, representing over $50 billion in annual GMV.
Embed security expertise within software engineering teams to influence product design and development.
Combine software engineering with proactive security practices like threat modeling, static analysis, and fuzzing.
Work extensively with Linux and open source technologies, contributing to upstream projects and strengthening security.
They are a leading open source software company behind Ubuntu, providing secure and scalable solutions. They operate with a globally distributed team, emphasizing collaboration and continuous learning.
Own and execute application, cloud, and API security across the platform.
Build detection, response, and hardening for a high-scale SaaS environment.
Collaborate with engineers to embed security into the SDLC and enterprise client requirements.
YGO.ai is a VC-funded AI tourism platform that provides AI search and recommendation engines for major travel enterprises. As a VC-funded startup, we maintain a hands-on, engineering-driven culture where security is integral from the start.