
501 - 1000 employees
Founded 2020
🏗️ Construction
🏥 Healthcare
đź’¸ Finance
Construction • Healthcare • Finance
GoodLeap is a tech company delivering best-in-class financing and software products for sustainable solutions. It supports homeowners and businesses nationwide by providing solar loans, energy efficiency loans, and other financing solutions to promote green energy adoption. GoodLeap is committed to a sustainable future, having facilitated $58B in cumulative financing and offsetted 14M metric tons of CO2. The company offers solutions like solar and storage systems, energy-efficient upgrades, and smart home technologies, primarily catering to the green energy sector. Their partnerships and initiatives aim to expand access to clean energy and support environmental sustainability.
🔥 14 hours ago
🇺🇸 United States – Remote
đź’µ $146k - $185k / year
⏰ Full Time
đźź Senior
👮‍♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
đź‘» Ghost score 1%
Improve your chances of getting an interview by checking your resume score before you apply.

501 - 1000 employees
Founded 2020
🏗️ Construction
🏥 Healthcare
đź’¸ Finance
Construction • Healthcare • Finance
GoodLeap is a tech company delivering best-in-class financing and software products for sustainable solutions. It supports homeowners and businesses nationwide by providing solar loans, energy efficiency loans, and other financing solutions to promote green energy adoption. GoodLeap is committed to a sustainable future, having facilitated $58B in cumulative financing and offsetted 14M metric tons of CO2. The company offers solutions like solar and storage systems, energy-efficient upgrades, and smart home technologies, primarily catering to the green energy sector. Their partnerships and initiatives aim to expand access to clean energy and support environmental sustainability.
• Adversarially test AI- and LLM-backed features, including prompt injection, jailbreaks, tool abuse, and data exfiltration • Build and operate production security services and internal tooling using TypeScript, Node.js, .NET, or Python • Identify opportunities to automate manual security work and prototype improved solutions • Review and triage pull-request vulnerability findings, investigate authentication paths and high-risk changes, and improve security tooling • Threat model product requirements and technical designs by identifying trust boundaries, data flows, and security questions • Manually test web applications and APIs, assess exploitability, retest fixes, and support bug bounty and penetration-testing programs • Operate and improve AppSec tooling, including SAST/dependency scanning, finding triage and routing, SSO, and access management • Secure tooling infrastructure through least-privilege IAM, secrets management, container/network lifecycle management, infrastructure as code, and drift checks • Create practical security training and documentation for engineers • Evaluate security products through structured bake-offs and help define AI/agent production standards • Support investigations, threat hunting, incident response, vulnerability management, and security analytics
• Strong backend engineering in at least one modern language • At least one production service built that others depend on • Familiarity with async patterns, HTTP APIs, and streaming transports • Ability to read code across more than one language and stack • Knowledge of identity and authorization failures, including token exchange, scope handling, session lifetime and revocation, request signing, OAuth pitfalls, SSRF, and DNS rebinding • Practical knowledge of REST and GraphQL, OpenAPI, schema contracts, input validation, rate limiting, gateway-level authentication, and webhook/service-to-service verification • Hands-on manual testing of web applications and APIs • Threat modeling from written product and technical designs • Working AWS and infrastructure-as-code competence, including IAM, secrets management, containers/compute, network egress control, and drift checks • Practical exposure to AI/LLM security through work, CTF, published research, or a personal lab • Ability to write and speak clearly for engineers, product managers, executives, and Legal • Preferred: AppSec tooling ownership, vendor evaluations, security policy or AI standards, security training, cryptography and key management, detection engineering, incident response, threat hunting, SaaS product development understanding, or product/engineering management experience
• Salary bonus eligibility • Reasonable accommodations for known disabilities as required by law
Apply Now🔥 14 hours ago
Senior Security Assurance Engineer automating AWS security controls, evidence, and AI-native GRC workflows at 6sense. Improving continuous monitoring, audit readiness, and risk remediation.
🇺🇸 United States – Remote
đź’µ $141.2k - $180.1k / year
đź’° $200M Series E on 2022-01
⏰ Full Time
đźź Senior
👮‍♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🔥 14 hours ago
Physical security systems designer engineering access control, CCTV, and intrusion systems for Vultr’s global cloud data centers. Coordinating designs, integrations, commissioning, and ongoing technical support.
🇺🇸 United States – Remote
đź’µ $90k - $10k / year
đź’° $329M Debt Financing - Vultr on 2025-06
⏰ Full Time
🟡 Mid-level
đźź Senior
👮‍♂️ Cybersecurity / Security Engineer
🔥 14 hours ago
Physical Security Evaluator assessing data-center security for Vultr, a global cloud infrastructure provider. Identifying vulnerabilities, driving mitigations, and guiding physical security strategy.
🇺🇸 United States – Remote
đź’µ $80k - $100k / year
đź’° $329M Debt Financing - Vultr on 2025-06
⏰ Full Time
🟡 Mid-level
đźź Senior
👮‍♂️ Cybersecurity / Security Engineer
🔥 15 hours ago
Information System Security Officer supporting Zeiders’ cloud-hosted federal digital services platforms. Managing cybersecurity controls, compliance, authorization, and secure system operations.
🔥 15 hours ago
Cybersecurity Engineer securing Zeiders’ cloud-hosted digital services platform. Implementing controls, vulnerability remediation, monitoring, and DevSecOps security practices for military and family support programs.