Jobs in United States

Security Threat Hunting Specialist in United States

1,152 active opportunities · Updated October 2026

Explore current security threat hunting specialist jobs across United States. Filter by work mode, employment type, experience, department, date posted and distance.

R
📍 Foster City, California, United States· Full-time
✓ Quality checkedCompany trend -85.9%

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. About the Role We are seeking a mid-level AppSec Vulnerability Management Engineer with a strong software development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify application vulnerabilities, maintain software supply chain security, and drive tracking to satisfy strict regulatory compliance frameworks. You will also serve as a technical responder during security incidents, deploying real-time countermeasures to protect our software ecosystem. What You'll Do Core Responsibilities Vulnerability Scanning & Triage: Perform periodic application security scanning activities. Review results and prioritize flaws based on CVSS scores, real-world exploitability, and system exposure. Compliance-Driven Tracking: Track, document, and manage vulnerabilities according to strict compliance SLAs (e.g., SOC 2, ISO 27001, PCI-DSS). Maintain audit-ready evidence of remediation timelines and exception approvals. Executive Reporting & Alerting: Escalate and report critical exposures directly to the CISO and senior leadership. Maintain dashboards and alerting mechanisms that visualize vulnerability status, risk trends, and compliance posture. Software Supply Chain Security: Ownership of the organization's Software Bill of Materials (SBOM). Continually update SBOM inventories to ensure compliance with modern regulatory requirements and dependency tracking. Help Replit mature through various SLSA levels for supply chain security. Remediation Collaboration: Partner with development teams to provide clear mitigation paths. Review, write, and patch code directly when necessary to resolve security flaws. Tooling Integration: Configure and tune automated security te

JavaScriptTypeScriptPythonJava
P
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -72.3%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners. We own Plaid’s security compliance frameworks, run our audits and risk programs, and partner across the company to keep Plaid’s platform secure, resilient, and aligned with industry and regulatory expectations. GRC Engineering is how we make all of that scale — turning compliance into code, evidence into telemetry, and audits into a continuous, automated capability. The Role: You will own GRC Engineering at Plaid — a foundational, high-ownership role defining an emerging discipline from the ground up. Today most of our compliance work is manual and point-in-time; you will turn it into an engineered system that is continuous, data-driven, and scalable, and set the technical direction for the field. You will: Define the discipline and the architecture — how GRC Engineering works at Plaid, not just execute with

PythonSQLAWSCI/CD
P
📍 New York, New York, United States· Full-time
✓ Quality checkedCompany trend -72.3%

We believe that the way people interact with their finances will drastically improve in the next few years. We’re dedicated to empowering this transformation by building the tools and experiences that thousands of developers use to create their own products. Plaid powers the tools millions of people rely on to live a healthier financial life. We work with thousands of companies like Venmo, SoFi, several of the Fortune 500, and many of the largest banks to make it easy for people to connect their financial accounts to the apps and services they want to use. Plaid’s network covers 12,000 financial institutions across the US, Canada, UK and Europe. Founded in 2013, the company is headquartered in San Francisco with offices in New York, Washington D.C., London and Amsterdam. Team: The Security Governance, Risk, and Compliance (GRC) team is part of Plaid’s security organization, focused on enabling the business by proactively managing information security risks and maintaining effective controls. Our mission is to reduce the likelihood and impact of security risks while operating a robust assurance program that builds trust with our customers, consumers, and data partners.We partner closely across the company to ensure Plaid’s platform remains secure, resilient, and aligned with industry and regulatory expectations. Third-party ecosystem risk is a core part of how we keep Plaid safe—we vet the security of both the vendors we rely on and the customers and partners who connect to our platform, so trust runs in both directions. Role: You will run security risk assessments for Plaid’s third parties end-to-end—from intake and questionnaire through risk rating, findings, and tracked exceptions. You will assess the security posture of customers and partners onboarding to the platform with the same rigor we apply to vendors. You will keep the third-party risk lifecycle moving—risk tiering, reassessment cadence, remediation follow-through, and a clean, current risk register. You

AWSAIGoRust
G
📍 United Kingdom; Remote, United States· Full-time· Remote
✓ High-confidence listingCompany trend -97.9%

From $139.2K/yr

Quick readStrong listing-quality and freshness signals

GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. * Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. An overview of this role You will engineer security improvements to the GitLab product as well as building and maintaining the tools we use to detect and prevent abuse on our SaaS platforms. A strong software engineering background with experience in large Ruby/Rails codebases is required. As a senior engineer on the Trust and Safety team, you will predictively identify abuse patterns and trends and build anomaly detection and prevention systems to mitigate abusive users and their activities. This role is an ideal fit for candidates with software engineering backgrounds interested in moving into security engineering. Formal

AWSGCPGitRest
D
📍 New York, New York, United States· Full-time
✓ High-confidence listingCompany trend -84.7%

From $187K/yr

Quick readStrong listing-quality and freshness signals

As a Cloud Security Engineer you will partner with different stakeholders across the organization to secure our cloud infrastructure. As part of the Platform Security organization we secure the building blocks of Datadog’s applications and infrastructure. We do this by building solutions to solve systemic risks and combine an approach of making the secure path easier and the insecure path harder to secure and accelerate the business. We regularly partner with the most bleeding edge internal products and are working to solve and build solutions to enable our safe usage of AI. We also develop AI based solutions to enable security at scale. We are looking for a Service Mesh and Kubernetes focused security specialist to help round out an incredibly strong infrastructure security focused group. You will rotate through a variety of internal projects and gain deep exposure to Datadog’s infrastructure. At Datadog, we place value in our office culture - the relationships that it builds, the creativity it brings to the table, and the collaboration of being together. We operate as a hybrid workplace to ensure our employees can create a work-life harmony that best fits them. What You’ll Do: Solve our most challenging cloud infrastructure security problems starting with our core building blocks and golden paths. Enable our engineers to build and ship secure solutions quickly. Build and extend Datadog’s Platform Security solutions. Leverage and influence the direction of Datadog’s products to secure our infrastructure, and provide internal feedback that enables our teams to improve the products for ourselves and our customers. Who You Are: You have a BS/MS/PhD in a Computer Science, Engineering or related scientific field or equivalent professional experience. Passionate about advocating for and implementing solutions to complex problems, at-scale, in a large multi-cloud environment. You don’t want to just provide security recommendations, you want to help imple

PythonAWSAzureGCP
M
📍 United States· Full-time
✓ High-confidence listingCompany trend -93.7%

From $151K/yr

Quick readStrong listing-quality and freshness signals

MongoDB’s Security Product Management team is seeking a Staff Product Manager to own security, compliance, and public sector product strategy within Atlas for Government (A4G). In this role, you will be a key member of the security product management team, helping make data security a market differentiator that enables MongoDB to win in enterprise and regulated industries. You will lead product strategy and execution for capabilities and programs that support federal compliance requirements and broader regulated-industry needs. You will work across Engineering, Compliance, Legal, Security, and Go-to-Market teams to translate complex regulatory and customer requirements into clear product investments, roadmaps, and outcomes. This role is suited for a candidate who can orchestrate multiple interlinked product areas, own cross-team product and architectural trade-offs, and align senior stakeholders around multi-year bets. You will be expected to identify opportunities and dependencies that cut across team boundaries, bring clarity to ambiguous problem spaces, and establish reusable ways of working that help MongoDB deliver secure, compliant platform capabilities for public sector and other regulated markets. You will partner closely with senior engineering and business leaders to evaluate trade-offs, sequence investments, and bring clarity to decisions that balance customer impact, execution risk, and long-term business value. This role can be based out of of our offices or remotely in the United States. The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services. Our FedRAMP program requires that anyone who is accessing customer data or metadata inside the Authorization Boundary be a US Person on US Soil. Responsibilities Security and Compliance Product Strategy Own the public sector compliance roadm

MongoDBAWSAzureGCP
M
📍 United States· Full-time
✓ High-confidence listingCompany trend -93.7%

From $151K/yr

Quick readStrong listing-quality and freshness signals

The Role MongoDB is seeking a Staff Product Manager to lead strategic initiatives across Identity and Security. In this role, you will serve as the senior product leader shaping the next generation of authentication, authorization, and access control across MongoDB Atlas, the core database engine, and emerging developer platforms. You will lead the strategy for non-human identity—spanning workload identity federation, zero-trust passwordless access, Model Context Protocol (MCP) integrations, and autonomous AI agentic identity. You will partner closely with engineering, UX, product marketing, and enterprise customers to build identity experiences that are enterprise-grade, seamless for developers, and secure by default. Responsibilities Set and champion a multi-year product strategy across interrelated identity areas, aligning dependencies and investments to MongoDB’s broader objectives Identify cross-cutting customer and market opportunities, build business cases for investment, and bring a clear point of view to senior stakeholders Lead workload identity federation and programmatic access initiatives across cloud and enterprise identity environments Define secure authorization approaches for AI agents and MCP clients, including delegation, identity lifecycle, policy, and administrative controls Drive developer-first access management, ensuring security controls enhance rather than obstruct developer velocity Partner with engineering, design, GTM, and cross-functional leadership to validate enterprise requirements, prioritize initiatives, and measure feature adoption Stay ahead of evolving cloud security paradigms, emerging standards (e.g., SPIFFE/SPIRE, O4AA), and AI access patterns to guide executive decision-making Represent MongoDB’s security and identity vision at industry events, customer advisory boards, and executive briefings Demonstrate creativity, an innovative spirit, and a bias towards action Requirements 8+ years (or equivalent experience) in Pro

MongoDBAWSAzureGCP
T
📍 San Francisco, California, United States· Full-time
✓ High-confidence listingCompany trend -50%

$155K – $207K/yr

Quick readStrong listing-quality and freshness signals

About Taskrabbit: Taskrabbit is a marketplace platform that conveniently connects people with Taskers to handle everyday home to-do’s, such as furniture assembly, handyman work, moving help, and much more. At Taskrabbit, we want to transform lives one task at a time. As a company we celebrate innovation, inclusion and hard work. Our culture is collaborative, pragmatic, and fast-paced. We’re looking for talented, entrepreneurially minded and data-driven people who also have a passion for helping people do what they love. Together with IKEA, we’re creating more opportunities for people to earn a consistent, meaningful income on their own terms by building lasting relationships with clients in communities around the world. Taskrabbit is a hybrid company with employees distributed across the US and EU and a Built In — Best Places to Work (2022, 2023, 2024, 2025) continually ranked across multiple national and regional categories. Join us at Taskrabbit, where your work will be meaningful, your ideas valued, and your potential unleashed! This role operates on a hybrid schedule requiring two days of in-office collaboration per week. About the Role Reporting to the Infrastructure Director of Engineering, you are a pragmatic security leader who acts as a business enabler rather than a gatekeeper. You thrive in a high-velocity, non-regulated environment where you must define "what good looks like" from scratch and drive security progress with a blend of strong planning skills and strong cross-functional partnerships. You are a technical player-coach who manages the "how" behind engineering initiatives, providing direct guidance to a lean team which needs to navigate trade-offs between quality, depth, and delivery volume. You are just as comfortable planning core initiatives as you are writing a proposal for security program improvements. You have a proven track record of leading a team to achieve compliance with a security framework from scratch (e.g., CIS, SOC2, P

AgileMachine LearningAIGo
O
📍 United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role Trusted Computing and Cryptography is a core security team at OpenAI focused on deploying high-performance cryptography at scale, secure key management, and trusted hardware enclaves—from boot measurements to GPU confidential computation. As a Hardware Platform Security Architect, you’ll own hardware platform security at OpenAI. In this role, you will: Co-Architect Secure Silicon: Collaborate with cross-functional silicon teams (Silicon Design, DV, FW) and silicon partners (silicon test facilities, foundries) to develop secure silicon that meets the end-to-end system requirements. Co-Architect Secure Hardware: Collaborate with hardware vendors and cross-functional teams (kernel, compiler, infra) to design secure hardware that meets performance and security needs. Co-Architect Secure Systems: Architect and deploy systems using TPM2, Secure Boot, Nitro Enclaves, Intel SGX, AMD-SEV, and other secure hardware technologies. Drive Innovation: Engage with internal and external partners to align hardware innovations with OpenAI’s trusted computing and cryptographic requirements. You might thrive in this role if you have: 10+ years of industry experience in hardware security or hardware–software co-design. Proven expertise in deploying secure hardware systems at scale and integrating secure hardware primitives. Strong coding skills in Rust and/or C/C++, with proficiency in Python. Proven ability to collaborate across teams, architect solutions,

PythonAWSRestAI
O
📍 United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team OpenAI’s Cyber team works to make frontier AI safe, trusted, and transformative for developers and enterprises. This team is building the security foundation for Codex: the native controls that govern what Codex can access and do, and the interfaces that allow customers and security partners to inspect, constrain, approve, and respond to Codex activity. Our goal is to make Codex secure by default, governable by enterprises, and interoperable with the security products customers already trust . This extends the existing product direction around tenant-scoped tools, guarded actions, approval systems, and scalable partner interfaces. About the Role We are looking for a deeply technical Product Manager to help build Codex security controls and the partner ecosystem around them. This role focuses on securing Codex itself : how identity, permissions, tools, MCP servers, repositories, secrets, networks, and high-impact actions are governed across Codex products. You will also help define standard interfaces through which authorized customer and partner systems can provide security context, inspect activity, return policy decisions, receive telemetry, and initiate bounded responses. You will work closely with Codex product and engineering, OpenAI Security and Safety, enterprise customers, and partners across application security, identity, cloud security, data security, infrastructure, and security operations. In this Role you Will Build native security controls for Codex Partner with engineering, design, security, and safety teams to develop controls for: Identity, roles, permissions, and tenant isolation. Access to repositories, files, tools, MCP servers, secrets, networks, and infrastructure. Read, write, execute, and deployment authority. Human and policy-based approvals. Prompt-injection and untrusted-content defenses. Audit trails, provenance, stop conditions, revocation, and rollback. Help establish a graduated authority model in which local, read-only

AWSCI/CDRestAI
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team The Infrastructure Engineering function sits within IT and is responsible for reliably building, deploying, and operating critical on prem and hybrid environments that power internal services and critical R&D environments. This is an early, high-leverage technical role focused on applying strong Site Reliability Engineering discipline to environments where uptime, safety, recoverability, and security are non-negotiable. This person helps replace bespoke, one-off infrastructure with standardized infrastructure-as-code building blocks that compound reliability and operational leverage as OpenAI scales. About the Role We are looking for an experienced Site Reliability Engineer working on security infrastructure to design, build, and operate reliable, secure, and scalable infrastructure that underpins identity, access, endpoint, and shared platform services across the company. In this role, you will be a senior technical owner for infrastructure and identity systems end to end, from architecture and implementation through policy enforcement, upgrades, recovery, and day-two operations. You will build durable, production-grade platforms that remove operational friction, enforce security by default, and enable teams to move faster with confidence. This role is well suited for a hands-on senior engineer who thrives in ambiguity, enjoys owning complex systems end to end, and raises the reliability and security bar by replacing fragile implementations with standardized, repeatable infrastructure. This role is based in our San Francisco HQ and requires in-office presence. In this role, you will: Design, build, and operate reliable infrastructure across on-prem, hybrid, shared, and product adjacent environments. Establish standardized infrastructure patterns that replace bespoke implementations with repeatable, auditable, secure-by-default systems. Own the lifecycle of critical infrastructure platforms, including provisioning, deployment, upgrades, patching,

AWSAzureRestAgile
O
📍 San Francisco, California, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role We are seeking a Software Engineer, Security Observability to join our Security team. In this role, you will be responsible for building secure, scalable systems that enhance our security observability infrastructure. Leveraging your strong engineering skills, you will collaborate with cross-functional teams to develop, deploy, and maintain robust software solutions that support our security and detection capabilities. This role is open to remote employees, or relocation assistance is available to one of our OpenAI offices in San Francisco, Seattle, or New York City. Due to requirements associated with work this role may support, applicants for this position must be U.S. citizens. In this role, you will: Design and develop scalable software systems that facilitate security observability across our infrastructure. Build and maintain data pipelines that centralize and store security-relevant data from diverse sources. Proactively improve the resilience and reliability of data systems to ensure high platform availability Collaborate closely with Detection & Response (D&R) and other security teams to reduce the company’s security risk. Contribute to data engineering in support of forensic investigations and compliance efforts. You might thrive in this role if you have: Strong software engineering experience, with proficiency in programming languages such as Python, Golang, or similar. A background in infrastructure as code, with exp

PythonAWSAzureRest
O
📍 Washington, District of Columbia, United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role Our technologies support some of the most important and impactful work in the world, including our strategic and high-impact customers in the public sector. As a Forward Deployed Security Engineer (FDSecE) you will be responsible for securing these novel applications of OpenAI’s technology. We’re looking for motivated, tenacious, and curious people who will work closely with engineering teams to ensure our infrastructure deployments are highly secure against our adversaries. As an FDSecE, you will embed directly throughout the lifecycle, working on-site and being hands-on to ensure the overall security of these deployments from design to production and through ongoing operations. This role is preferred to be based in Washington DC but may consider remote work. We use a hybrid work model of 3 days in the office per week and offer relocation assistance to new employees. Travel to and working from customer sites is required for this role. In this role, you will: Deeply embed with our most strategic public sector customers to implement and maintain robust security controls. Be a design and technical thought partner by leveraging security expertise on protective controls including access controls, authentication, encryption, network, and system security. Collaborate closely with teammates, cross-functional teams, customers, and service providers to achieve security and compliance goals. Ensure continuity of critical security and monitoring c

PythonAWSAzureKubernetes
O
📍 United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but are operational in how we do our work, and are committed to supporting all products and research at OpenAI. Our Security team tenets include: prioritizing for impact, enabling researchers, preparing for future transformative technologies, and engaging a robust security culture. About the Role We’re seeking an exceptional Principal-level Offensive Security Engineer focused on deep, hands-on penetration testing of OpenAI’s agent-powered products, infrastructure, and model-integrated application surfaces. You’ll assess complex systems end to end, identify realistic vulnerabilities, validate exploitability and impact, and partner closely with engineering teams to drive durable fixes. This role will be primarily focused on continuously testing our agent-powered products like Codex and Operator. These systems are uniquely valuable targets because they’re rapidly evolving, can perform sensitive actions on behalf of users, and have large, diverse attack surfaces. You will play a crucial role in securing our agents by finding vulnerabilities that emerge from the interactions between the applications, infrastructure, tools, and models that power them. You’ll have the chance to not only find vulnerabilities, but actively drive their resolution, build reusable testing approaches, automate offensive security workflows with cutting-edge technologies, and use your attacker perspective to improve the security of OpenAI’s products. In this role you will: Conduct deep penetration tests of OpenAI’s agent-powered products, including web applications, APIs, cloud services, identity and authorization flows, CI/CD systems, and model-integrated product surfaces. Continuously hunt for exploitable vulnerabilities in the interactions between the appli

PythonReactAWSAzure
O
📍 United States· Full-time
✓ Quality checkedCompany trend -80.2%

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but operational in how we execute, and we support every product and research effort at OpenAI. Our tenets include prioritizing for impact, enabling researchers and developers, preparing for future transformative technologies, and fostering a strong, collaborative security culture. About the Role OpenAI is seeking a Security Software Engineer to join the Infrastructure Security (InfraSec) team. InfraSec safeguards the core of OpenAI’s research and production environments—GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter spans everything from bare-metal hardware and firmware to Kubernetes clusters, service meshes, and the data pathways that carry highly sensitive model weights and user data. As a Security Software Engineer, you will design and build critical foundational services, such as authentication systems, egress/ingress proxies, access brokers, and key management platforms, that demand high standards of reliability, scalability, and software craftsmanship. These systems form the security backbone of OpenAI’s supercomputing environment and must remain robust under intense scale and adversarial pressure. In this role, you will: Architect and implement production-grade security services (e.g., auth services, access brokers, secure proxies, key-management infrastructure) that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD. Partner with infrastructure and research engineers to embed security into high-performance compute clusters, enabling rapid model training and deployment without compromising protection. Develop automation and detection tooling to continuously identif

PythonAWSAzureGCP
🔔

Get new security threat hunting specialist jobs in United States by email

Daily job updates · Unsubscribe anytime