We build frontier cybersecurity agents and the infrastructure to run them. Our platform, SDK, and API let security teams assemble agents into workflows that investigate vulnerabilities, prepare fixes, and verify deployed changes.
Our customers are insurance companies and financial services firms with hardened web applications. Our human security experts run black-box penetration tests against their systems.
We’re looking for experienced web application penetration testers who can leverage our internal tooling and AI agents to drive pentests and write professional reports. You’ll work directly with our founding team: Abdullah (Google Search) and Saad (Tesla Autopilot, Essential AI).
What you’ll do
- Perform black-box web application penetration testing against insurance and financial services platforms: customer portals, claims systems, payment flows, internal dashboards
- Operate our internal AI pen testing agent, supervise its runs, take over when it hits walls, and manually exploit what it identifies
- Test complex authentication flows (SSO, OAuth, SAML, JWT, multi-tenant access control) and find the business logic flaws that scanners miss
- Write clear technical reports with actionable remediation guidance and executive summaries for non-technical stakeholders
- Run multiple concurrent engagements across different customer environments
Requirements
- 4 to 5 years of full-time web application penetration testing as your primary job responsibility
- At least one of: OSCP, OSCE, CREST, or PCI-certified
- Burp Suite Professional: proxy, repeater, intruder, extensions
- OWASP Top 10: you can find and exploit these manually, not just flag them with a scanner
- SQL injection, XSS (reflected, stored, DOM-based), CSRF, SSRF, XXE, insecure deserialization, API testing
- Business logic testing: IDOR, privilege escalation, access control flaws, things automated tools miss
- Python, JavaScript, or Bash for custom scripts and exploit PoCs
- Professional report writing: you’ve delivered findings to clients or stakeholders before