Theori: Private cybersecurity firm providing offensive security consulting, AI-powered security testing, AI red teaming, and training to organizations.
Experience in security engineering, vulnerability research or penetration testing; CTF or bug bounty experience preferred; proficiency auditing code; ability to triage AI-generated static analysis reports and write proof-of-concept exploits.
Austin or Chicago or Denver or Los Angeles or San Diego or San Francisco or United States or Australia or New Zealand or Canada or United Kingdom or Philippines
$131k-$169k/yrHybridFull Time
Karbon: Cloud practice-management software that helps accounting firms manage workflows, clients, communications, and billing.
4+ YOE4+ years security/development experience embedding AppSec in SDLC, cloud (Azure/AWS/GCP), SAST/SCA/DAST configuration, CI/CD security, code review, Python/PowerShell/Bash, and strong communication skills.
SentinelOneNYSE: S: AI-native cybersecurity platform for autonomous threat protection.
7+ YOERequires 7+ years in application or product security, expert proficiency in at least two of Go, Java, and C#, SAST rule authoring, threat modeling, secure SDLC, Git, CI/CD, and executive communication.
Harness: Private software providing AI software delivery and DevOps automation to engineering teams.
Pre-sales experience supporting DevSecOps or cybersecurity SaaS, hands-on knowledge of application/API/AI security practices and tools, strong presentation and communication skills, willingness to travel occasionally.
Fabric Health: Public-benefit helping busy families access healthcare and public benefits through community-based services.
5+ YOE5+ years in application security, including penetration testing and secure code review; AI security expertise; programming proficiency; SAST/DAST, CI/CD, OWASP, AWS, and regulated healthcare security experience.
Ruby on Rails, Python, React, Node.js, SAST, DAST, CI/CD, AWS, OWASP Top 10, FHIR, HL7, Epic, Cerner, Google Meet, Zoom, Skype, WhatsApp, LinkedIn, Google Forms
AmazonNASDAQ: AMZN: Multinational technology focused on e-commerce and cloud computing.
Bachelor's degree in engineering, computer science, or related field; security engineering experience; web security knowledge; coding or scripting ability; and experience with application security, testing, or incident response.
New York Life Insurance: Mutual life insurance providing insurance and investment solutions.
5+ YOEBachelor's degree or equivalent and 5+ years in application or cloud security. Requires Python, AI platform security, CI/CD, infrastructure-as-code, cloud IAM, secure API design, and AI threat-model knowledge.
Google Cloud Vertex AI, Amazon SageMaker, Azure Machine Learning, Python, LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI, MITRE ATLAS, OWASP Top 10 for LLM Applications, NIST AI RMF, Google Secure AI Framework (SAIF), OPA/Rego, Cloud Custodian, Sentinel, Lakera, Protect AI, NeMo Guardrails, Llama Guard, Vertex AI Safety Filters, CI/CD, SLSA, SBOMs
New York Life Insurance: Mutual life insurance providing insurance and investment solutions.
5+ YOEBachelor's degree or equivalent practical experience, 5+ years in application or cloud security, production AI platform security, CI/CD and infrastructure-as-code controls, cloud IAM, application security, and Python automation.
Google Cloud Vertex AI, Amazon SageMaker, Azure Machine Learning, Python, LangChain, LangGraph, Vertex AI Agent Builder, ADK, CrewAI, MITRE ATLAS, NIST AI RMF, OPA/Rego, Cloud Custodian, Sentinel, Lakera, Protect AI, NeMo Guardrails, Llama Guard, Vertex AI Safety Filters, CI/CD, SLSA, SBOMs, IAM
LENS: AI traffic-safety serving public-safety agencies and transportation departments with real-time highway hazard detection.
Design, implement, and operate end-to-end security for cloud-native platforms; lead FedRAMP/GovRAMP compliance; perform threat modeling, appsec, and incident response; partner with engineering teams.
Web Application Security Engineer (AppSec / DevSecOps)
Washington, District of Columbia, United States
HybridFull Time
Essnova Solutions: Minority-owned Alabama small-business government contractor delivering IT, professional, geospatial, healthcare, and environmental services to public and commercial clients.
Experience in application security, secure SDLC, vulnerability assessment, WAF, CI/CD/DevSecOps integration, and familiarity with federal frameworks (NIST, FedRAMP); Public Trust clearance or ability to obtain.
SAST, DAST, Software Composition Analysis (SCA), Web Application Firewall (WAF), CI/CD, DevSecOps, AWS, Microsoft Azure, OWASP Top 10, NIST, FedRAMP
Mach7 Technologies, Inc.: A provider of enterprise imaging solutions that consolidates medical images and supports secure, accessible patient care.
5+ YOE5+ years security engineering with strong AppSec focus; threat modeling, secure code review, SAST/DAST/SCA, SBOM and supply-chain experience; ability to read code and communicate risk to engineers and executives.
Boston or New York City or Los Angeles or San Francisco
$275k-$395k/yrOnsiteFull Time
Suno: Private AI music platform that helps people create complete songs from text prompts.
10+ YOE10+ years security engineering experience with deep expertise in AppSec, cloud/infrastructure security, or incident response; experience building security capabilities, mentoring teams, and participating in on-call incident response.
5+ YOERequires 5+ years of information security engineering experience, AppSec expertise, tooling integration, CI/CD knowledge, leadership, regulated-environment experience, and strong written, verbal, and presentation skills.
Boston or Chicago or Los Angeles or New York or San Francisco or Toronto or Vancouver or Vancouver
$145k-$175k/yrRemoteFull Time
Later: Private influencer marketing and social media management serving brands, agencies, and creators.
5+ YOE5+ years security engineering experience; strong application, cloud, and infrastructure security; SOC 2 and compliance experience; vulnerability management, IaC and CI/CD security; strong communication and software engineering skills.
OWASP, NIST, CIS Controls, SOC 2, ISO 27001, AWS Security Hub, Azure Security Center, GCP Security Command Center, SIEM, SOAR, Terraform, CloudFormation, C#, CI/CD
Merge: B2B software integration platform serving SaaS companies, Fortune 500 organizations, and AI agents.
3+ YOE3+ years security engineering with product/application focus; familiarity with OWASP, threat modeling, secure code review, SAST/DAST/SCA and CI/CD integration; able to read/write code; SaaS/API experience.