AppleNASDAQ: AAPL: Designs and sells consumer electronics, software, and online services.
Conduct offensive security research to find and fix vulnerabilities across Apple products to protect users; work as part of a security engineering and research team.
HUMAN: Provides cybersecurity solutions to protect against automated bot attacks.
Deep knowledge of internet protocols, javascript signal collection, and adversarial techniques; proven scripting experience with Python and JavaScript; experience researching fraud/abuse in Ad Tech or cybersecurity; strong analytic and communication skills.
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
7+ YOERequires 7+ years in vulnerability research, protocol analysis, or reverse engineering; 5G/4G and 3GPP expertise; Linux or RTOS knowledge; binary analysis tools; US citizenship; and ability to obtain a security clearance.
MicrosoftNASDAQ: MSFT: Develops software, services, devices, and cloud computing solutions.
1+ YOEMaster's (1+ yr) or Bachelor's (2+ yrs) in a relevant field or equivalent; ability to pass Microsoft security screening; research experience with LLMs, CodeLLM or AI IDE preferred; experience publishing and running large-scale ML experiments.
GitHub Copilot, Microsoft VS Code, Microsoft Visual Studio, Copilot CLI, Copilot Code Review, LLM, CodeLLM, RAG, Code agent, AI IDE
CACINYSE: CACI: Provides information technology and professional services to government clients.
7+ YOERequires 7+ years in vulnerability research, exploitation, or low-level engineering; Kubernetes, Linux internals, cloud security, Python, binary analysis, fuzzing, and US citizenship. Clearance eligibility required.
Wiz: Cloud security platform providing agentless visibility and risk mitigation
6+ YOE6+ years security/threat research experience; deep OS internals knowledge; cloud and Kubernetes familiarity; Python proficiency; strong communication and independent research skills.
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
10+ YOEBachelor's degree in information systems, software engineering, computer science, or related field plus 10 years of relevant experience and expertise in financial modeling, trading systems, mortgage-backed securities, and programming.
Python, C#, CVS, GitHub, Microsoft Excel VBA, Intex Deal Maker, C++, YieldBook API, Bloomberg API
Pensar: AI-powered continuous adversarial security testing for developers.
5+ YOE5+ years in offensive security or vulnerability research; strong programming in Python, Go, JavaScript, C/C++; experience running end-to-end pentests, customer-facing communication, and open source contributions; Bachelor's degree or equivalent.
Security Engineer, Product Security - Global Security Organization
Singapore or Los Angeles or New York City or London or Dublin or Paris or Berlin or Dubai or Jakarta or Seoul or Tokyo
OnsiteFull Time
TikTok: Global short-form video hosting and social media platform.
3+ YOERequires 3+ years in product security or cybersecurity, AI and automation experience, vulnerability analysis, incident response, and security researcher collaboration. Programming and Unix-based systems experience preferred.
5+ YOEBachelor's or equivalent experience,5+ years security engineering and assessments,5+ years coding experience,1 year technical leadership,experience with security reviews,threat modeling,and vulnerability research.
Albert Einstein College of Medicine: Academic medical school focused on education and biomedical research.
10+ MgmtBachelor's degree required, advanced degree preferred; minimum 10 years of progressive security leadership; experience in higher education or research institutions preferred; CPP and PSP certifications preferred; expertise in emergency preparedness, behavioral threat assessment, and security program management.
Albert Einstein College of Medicine: Private medical school and research institution in the Bronx.
10+ YOEBachelor's degree required, 10+ years progressive security leadership, experience in higher education or research environments preferred, CPP/PSP certifications preferred, strong crisis leadership and emergency management, contract and budget oversight.
Security Engineer 1, Application Security - Remote US
United States or New York City
$100k-$160k/yrRemoteFull Time
Trail of Bits: Provides high-end security research and software auditing services.
0+ YOEDemonstrated vulnerability research and code-analysis ability, coding proficiency in at least two languages (e.g., Rust, Go, C, C++, Python, JavaScript, TypeScript), memory-safety and systems knowledge, autonomous problem-solving, and clear technical communication.
Stony Brook University: Provides public higher education, medical research, and healthcare services.
5+ YOEBachelor's (or equivalent experience) and 5+ years cybersecurity experience in research or large-scale distributed systems; expertise with NIST 800-171, HIPAA, IAM, Linux, high-performance networking/storage, and translating regulatory requirements into technical controls.
Security Software Engineer, Open Source Frameworks
San Francisco or New York City or London or Berlin
$208k-$312k/yrHybridFull Time
Vercel: Frontend cloud platform for building and hosting web applications.
4+ YOE4+ years security engineering with hands-on open source contributions; deep JavaScript/TypeScript and Node framework knowledge; vulnerability research, coordinated disclosure, and CVE experience; strong communication.
Principal Application Security Engineer - Threat Research
New York City, New York, United States
$144k-$288k/yrHybridFull Time
CVS HealthNYSE: CVS: Provides retail pharmacy, health insurance, and pharmacy benefit management services.
10+ YOE3+ Mgmt10+ years securing and deploying security technologies; deep experience with cloud, containerization, WAF, vulnerability analysis, and leading security initiatives.
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
PhD or equivalent research experience; expertise in SAT/SMT/theorem proving/program analysis; strong programming and research skills; professional software development experience preferred.
CloudflareNYSE: NET: Provides security and performance services for internet properties.
4+ YOERequires 4+ years in offensive or application security, AI/LLM and agentic security expertise, penetration testing or exploit development, cloud security, MITRE ATT&CK, BAS tools, and strong communication skills.
LLMs, MITRE ATT&CK, AWS, GCP, Bare Metal, Automated Breach and Attack Simulation (BAS), WAF, EDR, SIEM
Senior Manager - Blockchain Security & Digital Asset Infrastructure
New York or Charlotte or Chicago or St. Louis or Boston
$150k-$344k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
8+ YOEBachelor's in a technical field and 8+ years in cybersecurity, systems engineering, blockchain security or cryptographic research; hands-on custody and key-management experience; expertise in blockchain protocols, cryptography, incident response, and AI-enabled threat analysis.