San Francisco or New York City or Seattle or Austin
$151k-$280k/yrOnsiteFull Time
Rippling: Unified platform managing workforce HR, IT, and finance operations
5+ YOE5+ years product security experience, deep web application security, fluency in Python, React, Django Rest Framework, experience with code review, CI/CD application security, and mentoring engineering teams.
MongoDBNASDAQ: MDB: Cloud-based document database platform for software application development.
3+ YOE3+ years in application/software/product security, strong C++ experience, scripting ability, threat modeling and security assessment experience, strong communication and ownership.
Candid Health: Automates medical billing and revenue cycle management for healthcare providers.
5+ YOE5+ years in software or security engineering focusing on product security; strong cloud and web security knowledge; collaboration and problem solving.
Cogent Security: Autonomous AI agents for enterprise vulnerability remediation.
5+ years security engineering experience in application/product security, secure SDLC, threat modeling, code scanning, supply-chain security, strong software engineering skills, and familiarity with modern AI security concerns.
Headway: Builds technology that helps therapists accept insurance and run their practice to increase access to mental health care.
5+ YOE5+ years security or software engineering experience, strong application and product security skills, experience with cloud and modern stacks, security reviews, incident response, and AI-native tooling.
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
4+ YOEMid-level software security engineer with 4-6 years of experience, strong Python/JavaScript, AI/ML security, cloud and container deployments, and secure SDLC knowledge.
CLEARNYSE: YOU: Secure biometric identity platform for travel and venue access
6+ YOE6+ years security engineering/product security experience; hands-on with vulnerability management stacks; understanding of VM workflows, cloud (AWS) patterns, strong communication, and audit/regulatory experience.
United States or Raleigh or New York City or Brussels or Wrocław
$168k-$210k/yrRemoteFull Time
Collibra: Provides a data intelligence platform for governance and discovery.
5+ YOE5+ years application/product security experience, 2+ years securing Java/Python/JavaScript apps, proficient with SAST/SCA/IAST/DAST and CI/CD, cloud and container experience, AI security knowledge; US citizenship required.
5+ YOE5+ years security engineering and coding experience, security assessments or threat modeling, vulnerability management, bachelor\u0002s or equivalent, strong communication and collaboration skills.
Oscar HealthNYSE: OSCR: Provides tech-enabled health insurance plans and telemedicine services.
4+ YOE4+ years in technology and security engineering; experience securing SDLC, vulnerability management (SAST/DAST), code review, risk assessment, and AI integration; strong communication and mentorship skills.
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
5+ YOE5+ years building and scaling production services; experience with vulnerability management, distributed systems, cloud infrastructure security; strong engineering and communication skills.
The Better Money Company: A New York City startup building stablecoin-backed payments and a clearinghouse to improve money movement.
5+ YOE5+ years security engineering with payments or regulated financial experience; experience with GCP and Terraform; knowledge of application and operational security; ability to write production code and build security programs; familiarity with SOC 2 and PCI-DSS.
Cleveland or Kansas City or Phoenix or Tampa or Nashville or Hartford or New Haven
HybridFull Time
CBIZNYSE: CBZ: Provides financial, tax, and business advisory services to organizations.
8+ YOECollege degree or equivalent, 8+ years related experience, expert technical knowledge in application and AI security, ability to lead teams, travel and on-call availability, strong verbal and written communication.
Semgrep, CodeQL, SonarQube, Checkmarx, Veracode, Burp Suite, OWASP ZAP, Snyk, Black Duck, GitHub Actions, GitLab CI, Azure DevOps, Jenkins, Microsoft Azure, AWS, Kubernetes, OWASP Top 10, CWE Top 25, MITRE ATT&CK, CVSS, MITRE ATLAS, NIST AI RMF, ISO/IEC 42001, OAuth 2.0, OIDC, SAML
Merge: Unified API platform for connecting B2B software integrations.
3+ YOE3+ years security engineering with product/application focus; familiarity with OWASP, threat modeling, secure code review, SAST/DAST/SCA and CI/CD integration; able to read/write code; SaaS/API experience.
Nuvo: Platform for automating B2B commerce and trade credit management.
5+ YOE5+ years security engineering experience with deep application/product security expertise; experience across cloud, infrastructure, detection; threat modeling, secure design, code review, and building a security program.