SECTION I · THE BRIEF
Brief #08089Updated 22 AUG 2026SAN FRANCISCO, CAYcY COMBINATOR
Employbl Company Profile

Member of Security Staff

Hex Security is a cybersecurity company that offers autonomous AI agents for penetration testing in web apps and APIs.

Location
San Francisco, CA
Company size
1–10
Posted
1mo ago
Via
Yc
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Member of Security Staff

Parameter· San Francisco, CA, USView company profile


Job title
Member of Security Staff
Job location
San Francisco, CA, US
Job description
We're looking for an Offensive Security Engineer who can bridge the gap between manual penetration testing and our autonomous AI agents. You'll conduct hands-on security assessments across web applications, APIs, and cloud infrastructure while also working to improve the agents that scale that work. You'll review and validate agent findings, develop custom exploits and tooling, and contribute directly to the platform as an engineer. **What you'll do:** Execute penetration tests across web applications, APIs, and cloud environments. Review, validate, and enhance findings generated by our autonomous agents. Develop custom exploits, tools, and methodologies for complex vulnerabilities. Contribute production code to improve agent capabilities and coverage. Produce actionable security assessment reports with clear remediation guidance. Work with customer engineering teams to walk through findings and fixes. **What we're looking for:** 3+ years of professional penetration testing or offensive security experience with a track record of identifying critical vulnerabilities. Strong software engineering skills in Python and/or TypeScript. Deep understanding of web application security, including injection flaws, broken access control, authentication bypasses, and SSRF. Experience with common offensive tooling (Burp Suite, Nuclei, custom scripts) and comfort building your own. Familiarity with cloud security across at least one major provider (AWS, GCP, Azure). **Nice to have:** Experience with AI/LLM security, including prompt injection and agent manipulation. Bug bounty track record or published CVEs. Familiarity with OAuth/OIDC and SCIM attack surfaces. Relevant certifications (OSCP, OSWE, OSEP), though we care more about what you can do.
View job listing ↗
The Saturday Briefing

Get the Saturday tech briefing

New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

Where this role is based

San Francisco, CA

Loading map…

Parameter headquarters

San Francisco, CA

Company size

1–10 employees

Founded

2026

Total raised

$500,000

View company profile ↗

Funding rounds