
11 - 50 employees
Founded 2024
đ Cybersecurity
đ¤ Artificial Intelligence
âď¸ SaaS
Cybersecurity ⢠Artificial Intelligence ⢠SaaS
XBOW is an AI-powered penetration testing platform that delivers human-level security testing at machine speed. It utilizes hundreds of specialized AI agents that collaborate to discover, validate, and exploit vulnerabilities autonomously, allowing companies to test their applications rapidly. With a focus on comprehensive coverage and efficiency, XBOW enables continuous security validation for applications, ensuring they remain secure against emerging threats. Its capabilities include testing every endpoint and attack vector, making it a crucial tool for organizations looking to maintain security without the traditional bottlenecks of manual pentesting.
đĽ 1 minute ago
đ United States, Canada, +1 more countries â Remote
â° Full Time
đĄ Mid-level
đ Senior
đŽââď¸ Cybersecurity / Security Engineer
đť Ghost score 13%
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
Founded 2024
đ Cybersecurity
đ¤ Artificial Intelligence
âď¸ SaaS
Cybersecurity ⢠Artificial Intelligence ⢠SaaS
XBOW is an AI-powered penetration testing platform that delivers human-level security testing at machine speed. It utilizes hundreds of specialized AI agents that collaborate to discover, validate, and exploit vulnerabilities autonomously, allowing companies to test their applications rapidly. With a focus on comprehensive coverage and efficiency, XBOW enables continuous security validation for applications, ensuring they remain secure against emerging threats. Its capabilities include testing every endpoint and attack vector, making it a crucial tool for organizations looking to maintain security without the traditional bottlenecks of manual pentesting.
⢠Design and implement security controls across cloud, infrastructure, and internal platforms ⢠Partner with engineering to harden cloud architecture, IAM, and infrastructure ⢠Own product security reviews for new features, services, and major architecture changes ⢠Drive threat modeling and secure design decisions early in the SDLC ⢠Operate and improve AppSec workflows (SAST, SCA, secrets scanning, IaC scanning) ⢠Triage vulnerabilities across application, container, and cloud findings, and drive remediation with risk-based SLAs ⢠Define and run the vulnerability management lifecycle: intake, prioritization, exception handling, validation, and reporting ⢠Improve CNAPP coverage and finding quality across cloud accounts and workloads ⢠Improve Kubernetes and container security posture ⢠Monitor, investigate, and respond to security events and incidents ⢠Build automation to improve security operations, access workflows, and incident response ⢠Support wider teams by providing timezone coverage for the fully remote organization
⢠5+ years of experience in security engineering, product security, cloud/platform security, or closely related roles ⢠Strong hands-on experience securing cloud environments (AWS, Azure and GCP) ⢠Comfortable owning technical security problems end-to-end in fast-moving environments ⢠Hands-on experience with product/application security in engineering environments (secure design reviews, threat modeling, code-level risk discussions) ⢠Experience operating AppSec tooling and processes at scale (SAST, SCA, secrets, IaC scanning) ⢠Strong vulnerability triage and remediation management experience, including risk-based prioritization and SLAs ⢠Experience with CNAPP (or equivalent cloud security platforms) and tuning findings for engineering actionability ⢠Working knowledge of Kubernetes/container security in production systems ⢠Ability to partner with developers and platform teams to ship secure defaults without blocking delivery ⢠Comfortable writing scripts and automations to improve security reliability and scale ⢠Experience in incident response, investigation, and post-incident hardening in cloud-native environments ⢠Security-minded, detail-oriented, and a proactive communicator in remote-first teams ⢠Multi-cloud experience beyond AWS (e.g., Azure/GCP/OCI) advantageous ⢠Offensive security/pentesting background advantageous ⢠Experience scaling security at a startup from early stage to audit-ready maturity advantageous ⢠Relevant security certifications advantageous (e.g., OSCP, OSCE, AWS Security Specialty, Kubernetes security certs)
⢠Meaningful stock options ⢠Comprehensive benefits ⢠401k plan ⢠Opportunity to learn from and collaborate with top security and AI experts ⢠Regular opportunities to meet in person ⢠Support to travel to collaborate with colleagues in person
Apply NowđĽ 24 minutes ago
Senior Director leading Clarivateâs enterprise cybersecurity strategy and security operations. Protecting regulated healthcare and life sciences systems, products, data, and customers.
đĽ 25 minutes ago
Senior Director leading Clarivateâs enterprise cybersecurity strategy and operations. Protecting regulated healthcare and life sciences systems, products, data, and customers.
đĽ 1 hour ago
Senior Red Team Engineer leading adversary emulation, penetration testing, and cyber defense for KeyBank. Driving offensive security strategy, cloud assessments, CTEM validation, and executive risk reporting.
đĽ 4 hours ago
Lead IT Security Engineer designing and managing cybersecurity solutions for Make-A-Wish America. Protecting enterprise infrastructure through IAM, endpoint security, cloud security, threat hunting, and incident response.
đşđ¸ United States â Remote
đľ $69.5k - $84.1k / year
â° Full Time
đ Senior
đŽââď¸ Cybersecurity / Security Engineer
đĽ 6 hours ago
Cloud Security Architect conducting CSPM-based security assessments for Ankura clients. Delivering prioritized remediation roadmaps across Azure, Microsoft 365, AWS, and related cloud environments.
đşđ¸ United States â Remote
đľ $140k - $190k / year
đ° Private Equity Round on 2021-11
â° Full Time
đ Senior
đ´ Lead
đŽââď¸ Cybersecurity / Security Engineer
đŚ H1B Visa Sponsor