F5NASDAQ: FFIV: Provides application delivery networking and multi-cloud security solutions.
20+ YOE20+ years in software/security architecture with 10+ years in application-layer security (WAAP, DDoS, API security, bot protection); deep protocol, TLS, identity, zero-trust, and cloud-native expertise.
Washington Health Benefit Exchange: Operates Washington state's health insurance enrollment marketplace.
7+ YOE7+ years in information security with application security, secure SDLC, DevSecOps, cloud/Azure experience; experience with code reviews, threat modeling, vulnerability management, and tools like Nessus, Rapid7, Nmap, and Burp Suite.
Washington State Department of Ecology: Provides environmental regulation and conservation services for Washington state.
7+ YOE7+ years information security experience in application security, vulnerability management, penetration testing or related areas; strong secure SDLC, cloud/DevSecOps, threat modeling, code review, and remediation skills; familiarity with NIST/OWASP and regulatory requirements.
Microsoft Azure, Nessus, Rapid7, Nmap, Burp Suite, SAST, DAST, SCA, STRIDE, MITRE ATT&CK, Security Information and Event Management (SIEM), Endpoint Detection & Response (EDR)
Seattle or Los Angeles or San Francisco or California or Colorado or Connecticut or Delaware or Hawaii or Illinois or Maine or Maryland or Massachusetts or Minnesota or Nevada or New Jersey or New York or Rhode Island or Virginia or Washington or Washington DC or United States
$141k-$259k/yrOnsiteFull Time
Nordstrom: Operates luxury department stores and off-price retail outlets.
4+ YOE4+ years in application security or related field; experience shipping security tooling and automation; expert threat modeling, security design review, and manual code review; fluent reading/writing code in Java, Kotlin, C#, or Python; cloud-native and LLM/AI security knowledge.
United States or Canada or San Francisco or New York City or Seattle
$190k-$273k/yrRemoteFull Time
Apollo.io: AI-powered platform for B2B sales intelligence and outreach automation.
5+ YOE5+ years software engineering or application security experience; strong coding skills (Ruby, Python), Linux and GCP familiarity, deep AppSec/vulnerability management, pen-testing and SAST experience, AI security, and strong communication.
Rocket CompaniesNYSE: RKT: Provides digital mortgage, real estate, and personal finance services.
5+ YOE10+ years in information security or 5+ with relevant degree; experience in threat modeling, secure coding, AppSec tooling, cloud/container security, and mentoring engineers.
Anthropic: Developing safe and reliable artificial intelligence systems.
Hands-on application and infrastructure security experience, production-quality coding in Python/Go/Rust/TypeScript, threat-modeling, vulnerability ID, clear communication, and ability to assess unfamiliar codebases under time pressure.
Birmingham or Bentonville or Phoenix or Tempe or Irvine or Los Angeles or Sacramento or San Diego or San Francisco or Santa Clara or Boulder or Denver or Hartford or Stamford or Washington or Fort Lauderdale or Jacksonville or Miami or Orlando or Tallahassee or Tampa or Atlanta or Des Moines or Boise or Chicago or Indianapolis or Louisville or Baton Rouge or New Orleans or Shreveport or Boston or Baltimore or Detroit or Minneapolis or Kansas City or St Louis or Jackson or Charlotte or Raleigh or Winston-Salem or Lincoln or Omaha or Montvale or Short Hills or Albuquerque or Las Vegas or Albany or Buffalo or Melville or New York or Rochester or Cincinnati or Cleveland or Columbus or Oklahoma City or Portland or Harrisburg or Philadelphia or Pittsburgh or Providence or Greenville or Knoxville or Memphis or Nashville or Austin or Dallas or Fort Worth or Houston or San Antonio or Salt Lake City or Ashburn or McLean or Richmond or Seattle or Milwaukee or Virginia Beach or El Segundo
$90k-$168k/yrOnsiteFull Time
KPMG: Global professional services network providing audit, tax, and advisory.
4+ YOE4+ years application security/DevSecOps experience, familiarity with CI/CD, SAST/DAST, cloud (preferably Azure), programming in Java/C#/JavaScript/Python/SQL, strong threat modeling and risk assessment skills, and U.S. work authorization without sponsorship.
Metropolis: Computer vision technology for checkout-free parking and retail payments.
Experience in application and product security, DevSecOps/secure SDLC, cloud-native system security, CI/CD security tooling, strong scripting/software engineering skills, and ability to partner with engineering teams.
Anduril Industries: Defense technology building autonomous military hardware and software.
5+ YOE5+ years building production software, strong Go and Python skills, experience with distributed systems and AWS, ability to interpret security tool output, and eligible to obtain U.S. Secret clearance.
Airtable: No-code platform for building collaborative apps and business workflows.
4+ YOE4+ years in product/application security; strong CS background; proficient in JavaScript/TypeScript, Node.js; experience securing LLM integrations; strong communication of security risks; thrives in fast-paced environments.
JavaScript, TypeScript, Node.js, Web Frameworks, Security tooling
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOE5+ years identifying security issues and developing mitigations, 4+ years troubleshooting and scripting, experience with application security, threat modeling, code review, and mentoring; strong communication skills.
Sift: Provides AI-based fraud detection and digital trust software services.
5+ YOE5+ years in security/infrastructure/application security; hands-on with AWS or GCP; proficiency in Python/Go/Java; experience with SAST/DAST and SIEM; knowledge of secure system design, incident response, and AI/LLM security risks.
5+ YOEBachelor's degree or equivalent experience,5+ years security engineering and distributed cloud experience,3+ years with containerization/GKE,BLS? (not applicable) EMR? (not applicable),strong communication and critical thinking.
Google Kubernetes Engine (GKE), Kubernetes, Google Cloud Platform (GCP)
The Trade DeskNASDAQ: TTD: Cloud-based programmatic advertising platform for data-driven media buying.
2+ MgmtLeadership experience building security engineering teams; deep application and platform/cloud security expertise; experience with security program maturity, vulnerability management, and secure SDLC practices.
SAST, DAST, SCA, CSPM, MITRE ATT&CK, NIST, ISO 27001, ISO 27002, OWASP, CWE, AWS, GCP, Azure
Headway: Builds technology that helps therapists accept insurance and run their practice to increase access to mental health care.
5+ YOE5+ years security or software engineering experience, strong application and product security skills, experience with cloud and modern stacks, security reviews, incident response, and AI-native tooling.
San Francisco or New York City or Seattle or Austin
$151k-$280k/yrOnsiteFull Time
Rippling: Unified platform managing workforce HR, IT, and finance operations
5+ YOE5+ years product security experience, deep web application security, fluency in Python, React, Django Rest Framework, experience with code review, CI/CD application security, and mentoring engineering teams.