Help secure the AI era — and prove it.
We are building the platform that maps, tests and constrains AI agents, code and cloud. Ten roles are open across security analysis, security engineering and sales.
What working on this looks like.
Analysts who decide what is true.
Security Analyst, AI Application SecuritySecurity analysis · Full-time · Remote
Validate and triage findings from autonomous AI-application scans, and turn them into fixes an engineer can act on.
About the role
Our agents attack chatbots, agents and RAG endpoints and report only what they can prove. You are the human who checks that proof, decides what it means for the customer, and tells the engineering team where the agents are wrong.
What you will do
- Reproduce proofs of concept and confirm severity, reachability and business impact before a finding reaches a customer.
- Write remediation guidance developers can follow, referencing OWASP LLM Top 10, MITRE ATLAS, CWE and CVSS.
- Review draft pull requests our platform opens and judge whether the fix is complete and safe.
- Feed false-positive and missed-finding patterns back to the agent and detection engineers.
What you bring
- 2+ years in application security, penetration testing, or a SOC / vulnerability-management role.
- Solid web and API security fundamentals; comfortable with Burp, curl and reading traces.
- Clear written communication — your reports are the product.
Nice to have
- Hands-on LLM or agent security experience (prompt injection, tool abuse, RAG poisoning).
- CREST, OSCP, or equivalent.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Senior Security Analyst, Findings Assurance & ReportingSecurity analysis · Full-time · Remote
Own the quality bar for attestation letters and technical reports, and the mapping from findings to compliance frameworks.
About the role
Customers hand our reports to auditors and to their own customers. You make sure every claim in them is supported, correctly labelled, and no stronger than the evidence.
What you will do
- Review reports before release: evidence labels (observed, reported, proven), severity, and wording.
- Maintain the mapping of findings to SOC 2, ISO 27001, ISO 42001, PCI DSS, HIPAA, NIST AI RMF and the EU AI Act — and keep it honest about what is evidence versus certification.
- Perform certified human reviews of scans where a customer asks for them.
- Work with customers' auditors and GRC teams on the machine-readable report exports.
What you bring
- 4+ years in security assurance, audit, GRC, or penetration-test reporting.
- Working knowledge of at least SOC 2 and ISO 27001 control language.
- An instinct for over-claiming, and the discipline to remove it.
Nice to have
- Experience with Vanta, Drata or Secureframe.
- Familiarity with AI governance frameworks.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Threat Intelligence Analyst, Agentic & MCP EcosystemSecurity analysis · Full-time · Remote
Track how AI agents and third-party MCP servers are attacked, and turn it into scoring, detections and public research.
About the role
Third-party MCP servers are installed by agents with almost no vetting, and nobody owns that risk. You will study the ecosystem — registries, packages, publishers — and help us score servers and warn the people who install them.
What you will do
- Monitor registries, repositories and advisories for malicious or risky MCP servers and agent tooling.
- Analyse packages for supply-chain signals: unpinned content, long-lived static secrets, over-broad permissions, suspicious egress.
- Maintain the scoring model behind our trust badges, and investigate disputes from publishers.
- Write up findings for customers and for public release.
What you bring
- 3+ years in threat intelligence, malware analysis, or software supply-chain security.
- Comfortable reading Python, JavaScript and container images to see what they really do.
- Sound judgement about disclosure — what to publish, when, and to whom.
Nice to have
- Experience with MCP, agent frameworks or package-registry abuse.
- Track record of published research.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Engineers who build the attack, the sensor and the trust.
Offensive Security Engineer, AI Red TeamSecurity engineering · Full-time · Remote
Build the attack modules our autonomous pentest agents use against LLM applications, agents and RAG systems.
About the role
You teach the agents to attack. That means turning the newest prompt-injection, indirect-injection and tool-abuse techniques into reliable, safe, replayable tests — and measuring whether they actually find real bugs.
What you will do
- Design and implement attack strategies across the OWASP LLM Top 10, including multi-step chains and excessive-agency tests.
- Build and maintain intentionally vulnerable benchmark applications and score the agents against them.
- Keep the testing sandbox safe: bounded budgets, no unintended egress, no damage to the target.
- Make every successful attack replayable so a customer can reproduce it.
What you bring
- 3+ years in offensive security, red teaming, or vulnerability research.
- Strong Python; comfortable building tooling, not only running it.
- Practical understanding of how LLM applications, tool calling and retrieval pipelines fail.
Nice to have
- Published CVEs or LLM-security research.
- Experience building or evaluating agentic systems.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Cloud Security Engineer, Posture & Attack PathsSecurity engineering · Full-time · Remote
Extend our agentless AWS, Azure and GCP collectors and the attack-path analysis built on them.
About the role
Connecting a cloud must install nothing and hold no write access. You will make the collectors accurate and cheap to run, and make the graph of identities, workloads and data stores answer the question customers care about: what can actually be reached?
What you will do
- Build and harden agentless collectors for AWS, Azure and GCP and the least-privilege onboarding for each.
- Model IAM, network and data-store relationships into the estate graph, including paths that cross clouds.
- Add posture and data-security (DSPM) checks, and keep the false-positive rate low.
- Make coverage explicit: every run states what it did and did not see.
What you bring
- 3+ years in cloud security or cloud platform engineering on at least two major clouds.
- Deep IAM knowledge — policy evaluation, role assumption, federation.
- Python or Go; experience with Terraform or equivalent infrastructure-as-code.
Nice to have
- Graph modelling or attack-path analysis experience.
- Kubernetes security background.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Detection & Runtime Security EngineerSecurity engineering · Full-time · Remote
Own our optional eBPF runtime sensor and the detections and telemetry built on it.
About the role
The runtime sensor is detection-only and off unless a customer turns it on. You will make it trustworthy: low overhead, safe by design, and precise enough that its alerts are worth reading.
What you will do
- Develop and maintain the eBPF-based sensor and its Kubernetes deployment.
- Write detections and map them to MITRE ATT&CK; measure and reduce noise.
- Keep ingestion bounded — per-post and per-hour limits, with drops counted rather than silent.
- Work on the integration with third-party prevention engines, which is where any blocking action lives.
What you bring
- 3+ years in detection engineering, endpoint or runtime security, or Linux kernel-adjacent work.
- Experience with eBPF, Falco, Tetragon or similar.
- Discipline about performance and failure modes on customers' production hosts.
Nice to have
- Kubernetes operator or DaemonSet experience.
- Windows or macOS endpoint telemetry background.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Security Software Engineer, Agent Identity & TrustSecurity engineering · Full-time · Remote
Build the cryptographic identity, signed policy and inline gateway behind Agent Trust Fabric.
About the role
Agent Trust Fabric gives agents verifiable identities and produces signed, time-limited trust signals a third party can check offline. ATF Enforce adds an inline gateway that can stop out-of-scope requests — gated behind a review of real traffic. You will build across all of it.
What you will do
- Extend the identity, signed-event and policy-bundle services (SPIFFE-style identities, Ed25519 signatures, receipts).
- Work on the inline gateway and its decision engine — allow, deny, or pause — and keep it fail-closed.
- Design the review and burn-in flows that decide when an identity may move from shadow to enforce.
- Write the tests and the verification tooling third parties will rely on.
What you bring
- 4+ years of backend engineering, ideally in security, identity or infrastructure products.
- Strong Python and a working grasp of applied cryptography (signing, key rotation, replay resistance).
- Care about correctness where the failure mode is silent.
Nice to have
- Experience with SPIFFE/SPIRE, OAuth/OIDC or service-mesh policy.
- Proxy or gateway internals (mitmproxy, Envoy).
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
The people who put it in customers' hands.
Enterprise Account Executive, SecuritySales · Full-time · Remote
Sell an AI-native security platform to CISOs and platform-security teams at mid-market and enterprise companies.
About the role
Buyers are asking a new question — how do we control what our AI agents can reach? — and have no established vendor for it. You will own the full cycle from first conversation to signed Enterprise agreement.
What you will do
- Run complex, multi-stakeholder sales cycles with security, platform and compliance buyers.
- Build pipeline through your own prospecting, partner introductions and inbound interest.
- Qualify rigorously and forecast honestly; keep the CRM true.
- Bring customer language back to product and marketing.
What you bring
- 4+ years closing B2B cybersecurity or developer-security software, including six-figure deals.
- Comfort selling to technical buyers and running a proof of value.
- A record of hitting quota, with a story about a deal you lost and what you learned.
Nice to have
- Experience selling cloud security, AppSec or GRC products.
- Existing relationships with security leaders or MSSPs.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Solutions EngineerSales · Full-time · Remote
Be the technical voice in the sale: demos, proofs of value, security questionnaires and integration design.
About the role
Our product is best understood by watching it find something real. You will run those moments, and make sure what we promise in a sale is what the platform does.
What you will do
- Lead technical discovery and tailored demos, including live scans against a customer's staging application.
- Scope and run proofs of value; write up results customers can share internally.
- Answer security and architecture questionnaires accurately — no claim without evidence.
- Design integrations with CI/CD, GRC tools, SSO and cloud accounts.
What you bring
- 3+ years as a solutions engineer, sales engineer, or security consultant.
- Working knowledge of web and API security, cloud, and CI/CD.
- Ability to explain a technical finding to a CISO and to the engineer who has to fix it.
Nice to have
- Hands-on AppSec or pentest background.
- Experience with LLM applications or agent frameworks.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Partnerships & Channel ManagerSales · Full-time · Remote
Build and run the partner program with pentest firms, MSSPs, technology vendors and registries.
About the role
Partners extend our reach: services firms that deliver our platform to their clients, vendors whose products complement ours, and registries and gateways where the install decision for third-party agent tooling is made.
What you will do
- Recruit, onboard and enable services partners, and support them through their first engagements.
- Develop technology and registry integrations with partner product and engineering teams.
- Own partner pipeline and the joint plans that produce it.
- Keep the program's terms and pricing simple and consistent.
What you bring
- 4+ years in channel, alliances or partnerships at a security or developer-tools company.
- Understanding of how MSSPs and pentest firms make money.
- Comfortable working with engineers on integration scope.
Nice to have
- Existing relationships with MSSPs, pentest firms or GRC vendors.
- Experience with marketplace or registry programs.
Send a short note and your CV or a link to your work. Tell us about the hardest thing you have built or broken, and why this role.
Do not see your role?
If you work on AI security, cloud security or security sales and think you belong here, write to us anyway.