
Casco
Autonomous security testing for web apps, APIs, cloud, and AI systems
What Casco does
Casco performs autonomous security testing for your web apps, APIs, infrastructure, and AI systems. Human supervision optionally available. Use Casco for year-round security and get a penetration test report for your SOC2 and ISO27001 compliance certifications. Trusted by 100+ companies from enterprises to fast-moving startups, such as Gusto, CrewAI, Novig, and Accrual. Hack yourself at: https://casco.com --- We already secure software deployed in 60% of Fortune 500 companies and are default alive. [1] [1] http://www.paulgraham.com/aord.html
4 open roles
What the role involves
About the Role We're seeking an exceptional Offensive Security Engineer to join our fast-growing startup and help shape the future of security testing. This role uniquely combines traditional penetration testing excellence with cutting-edge AI/LLM security expertise. You'll conduct sophisticated manual penetration tests while also working alongside our automated agentic red teaming systems, bridging the gap between human expertise and AI-driven security assessment. What You’ll Do Core Responsibilities Execute comprehensive, white-glove manual penetration tests across web applications, APIs, cloud infrastructure, and network environments Review, validate, and enhance findings generated by our agentic red teaming platform Develop custom exploits, tools, and methodologies to identify complex security vulnerabilities Contribute to the development of security-focused software and tooling within our engineering team Collaborate with our engineering team to improve and refine our automated security testing capabilities Produce detailed, actionable security assessment reports with clear remediation guidance Partner with customer engineering teams to ensure security findings are properly understood and addressed Research emerging attack vectors, particularly those involving AI/LLM systems and applications Technical Leadership Drive innovation in offensive security methodologies, especially at the intersection of traditional pentesting and AI-assisted security assessment Mentor team members on advanced penetration testing techniques Contribute to the company's security strategy and roadmap Participate in the continuous improvement of our security testing frameworks and processes What We’re Looking For Required Qualifications 3+ years of professional penetration testing or offensive security experience with a proven track record of identifying critical vulnerabilities Hands-on experience with AI/LLM security, including prompt injection, model manipulation, data poisoning, or other AI-specific attack vectors Strong software engineering skills with proficiency in at least two programming languages, including TypeScript. Deep understanding of OWASP Top 10, MITRE ATT&CK framework, and modern attack methodologies Experience with common penetration testing tools (Burp Suite, Metasploit, Cobalt Strike, custom tooling) Expertise in at least two of the following domains: Web application security Cloud security (AWS, Azure, GCP) Network penetration testing API security testing Preferred Qualifications Experience building or contributing to security tools and frameworks Knowledge of machine learning security, adversarial ML, or AI red teaming Relevant certifications (OSCP, OSWE, OSEP, GPEN, or equivalent) Experience with container security and Kubernetes environments Background in vulnerability research or exploit development Contributions to open-source security projects Experience working in fast-paced startup environments Skills & Attributes Hacker mindset: Creative, persistent, and always thinking outside the box Technical depth: Ability to dive deep into complex systems and understand their security implications Communication excellence: Can translate technical findings into business risk for various stakeholders Self-directed: Thrives in a startup environment with minimal supervision Continuous learner: Passionate about staying current with evolving threats and technologies Collaborative spirit: Works effectively with cross-functional teams including engineers, product managers, and leadership What We Offer Remote-first culture: Work from anywhere within the United States Competitive compensation: Base salary: $200,000 Equity package with high growth potential Cutting-edge work: Be at the forefront of AI-assisted security testing Growth opportunities: Shape the security posture of a rapidly scaling startup Learning budget: Annual allocation for training, certifications, and conferences Modern tech stack: Access to the latest
What the role involves
We're looking for a Technical Account Executive to help turn founder-led sales momentum into a repeatable motion. You'll sell to AppSec leaders and CISOs who know traditional pentesting is too slow to be the way they actually measure security. Software is shipping faster, exploit timelines are collapsing, and a point-in-time assessment cannot tell a team whether their product is secure this week. Casco exists for that new reality: continuous, autonomous security testing that keeps pace with how modern software gets built and attacked. What You'll Actually Do Run the full sales cycle from first touch to close across AppSec leaders and CISOs Build outbound lists, write the emails, make the calls, and create pipeline without waiting for perfect enablement Work founder-led deals side by side with the team, then turn what works into a repeatable sales motion Attend security events, work the room, follow up quickly, and turn conversations into real opportunities Run discovery with enough security context to understand why a customer pentests today, what is broken about it, and who needs to believe in a new approach Pitch Casco in a way that makes autonomous security testing feel concrete, credible, and urgent Bring field feedback back to founders, engineering, and security so we sharpen the product and the story together Keep the pipeline honest: clear next steps, real close plans, and no fantasy forecasting What We're Looking For Must-Haves Experience closing technical B2B software deals, ideally in security, developer tools, infrastructure, or AI Comfort selling to AppSec leaders and CISOs, including buyers who are skeptical of new categories Strong outbound instincts. You know how to find the right accounts, craft a sharp message, and follow through Good discovery. You can map how security work actually gets bought, who blocks it, and what pain is urgent enough to change behavior Technical fluency around application security, APIs, cloud environments, vulnerabilities, SDLC workflows, and remediation Clear writing. Your follow-ups make next steps obvious and your customer notes are useful to the rest of the team A willingness to do the unglamorous work: events, follow-ups, CRM hygiene, cold outbound, and messy early sales motion building Nice-to-Have Experience selling application security, pentesting, vulnerability management, cloud security, or developer security products Experience selling into mid-market security organizations A track record of building outbound motions from scratch Hands-on familiarity with AI tools, security testing workflows, or developer platforms Existing relationships with AppSec, security engineering, or CISO communities What This Role Is Not This is not a demo-only AE role where marketing hands you a calendar full of qualified meetings This is not a polished enterprise sales org with a finished playbook, mature enablement, and every objection already documented This is not a job for someone who wants to sell an obvious category. You'll need to make a new kind of security testing feel inevitable What We Offer San Francisco based: Work from our SF office Competitive Compensation: OTE: $350,000 Equity package with high growth potential A real chance to shape the sales motion for an emergent security category Direct access to founders, engineering, and security experts who can move quickly on what you learn in the field A product that is getting real customer momentum because security teams want pentesting to be faster, deeper, and more continuous A team of ex-AWS engineers and security experts who care deeply about the customer and the craft
What the role involves
We are looking for a Growth Engineer to design, build, and scale our growth engine. You will treat growth like a video game, constantly experimenting to get the highest score. You have the technical chops to wire together agents and APIs, the marketing instincts to convert a deeply skeptical security audience, and the AppSec maturity to communicate with credibility. What You'll Do Own the Growth Engine: Architect and wire the automation layer (APIs, webhooks, LLM agents) that turns product triggers, like a completed pentest, into programmatic upsells. Do Things That Don't Scale: Hustle manually to validate new channels and tactics first. Once a playbook proves it drives high-quality traffic, write the code to automate and scale it indefinitely. High-Tempo Experimentation: Rapidly ship, measure, and iterate on campaigns across HackerNews, Reddit, and LinkedIn to compound user acquisition. Technical Chops + Marketing Instincts: Write the scripts necessary to stitch our systems together, and the copy required to convert security engineers. AppSec Maturity: Move fast and break things in the automation layer, but possess the industry context to never compromise user trust, privacy, or brand reputation. What We're Looking For Must-Haves Excellent communicator: Strong writing, researching, and communication skills. You can craft copy that resonates with a technical audience Development experience: Not necessarily in a formal engineering role, but enough to vibecode your own growth automations and stitch systems together Technical audience expertise: Experience targeting security and development teams as customers, or writing for deeply technical audiences Campaign experience: Hands-on experience running email campaigns, GTM campaigns, and sales enablement programs What This Role IS NOT Death by PowerPoint: You won't be building pitch decks to get committee approval for minor experiments. We bias toward action. Brand Bikeshedding: You won't spend weeks debating font weights or logo placements. Vanity Metrics: We don't celebrate "impressions." We care about pipeline, product usage, and revenue. Vendor Management Hell: You won't spend your days evaluating bloated enterprise marketing software. You'll build leaner, faster systems yourself. What We Offer San Francisco based: Work from our SF office. Competitive Compensation: Base salary: $180,000 Equity package with high growth potential Actual Impact: Your work directly shapes how we acquire and grow our user base. Learning Opportunities: We support your growth with a budget for conferences, books, and tools. Smart Colleagues: Work with a team of ex-AWS engineers and security experts who are genuinely excited about what they build.
What the role involves
About the Role We're looking for a Software Engineer who gets excited about building AI agents that break into systems (legally). You'll be crafting the core of our agentic red teaming platform, think autonomous systems that discover vulnerabilities while you sleep. This isn't your typical engineering role where you're handed specs and told what to build. You'll make critical technical decisions, ship fast, and directly shape how AI transforms security testing. What You'll Actually Do Build agent systems: Design and implement autonomous agents that conduct security assessments. If you've built agents before, you know how wild this space can be Ship with autonomy: Own features from conception to production without someone looking over your shoulder Make smart tradeoffs: Balance speed and scalability in a startup environment where perfect is the enemy of shipped Collaborate cross-functionally: Work directly with security engineers and customers to turn ambitious ideas into reality Write TypeScript without any: Build robust, maintainable systems that can handle the chaos of autonomous security testing Learn security on the fly: You don't need to be a security expert, but you should be pumped about learning how hackers think Communicate clearly: Explain complex technical decisions to teammates and write documentation that actually helps What We're Looking For Must-Haves Strong TypeScript experience: You know the language deeply and can architect complex systems with it Agent building experience: You've built autonomous systems, agents, or similar "smart" software that makes decisions independently Cloud native experience: You've built on cloud services and know distributed systems Security-minded: You have basic understanding of cybersecurity concepts (or genuine excitement to learn them) Self-directed execution: You see problems and fix them without waiting for permission or detailed instructions Collaborative mindset: You actively seek input from others and make the team better Excellent communication: You write clearly, explain complex ideas simply, and aren't afraid to overcommunicate Startup-ready: You thrive in ambiguity, make decisions with incomplete information, and adapt quickly AI optimism: You believe AI will fundamentally change software and want to be part of making that happen Nice-to-Have Track record of shipping products in fast-paced environments Open source contributions or side projects showing your passion What We Offer Remote-first: Work from anywhere in the US Compensation: Base salary: $200,000 Meaningful equity (we're early enough that it actually matters) Actual impact: Your code will directly shape how companies approach security Learning opportunities: Conference budget, books, courses, whatever helps you grow Modern stack: TypeScript, cutting-edge AI tools, and whatever else gets the job done Smart colleagues: Work with people who are genuinely excited about this space. 80% of us are ex-AWS and have shipped products for millions of developers. Our Mission We're making all software effortlessly secure by building AI agents that think like attackers. This isn't incremental improvement – it's a fundamental shift in how security testing works. If you're excited about building autonomous systems that can outsmart traditional security tools, we should talk. Interview Process Quick chat with a founder (30 minutes) - We'll talk about your experience with agents and what excites you about this space Technical discussion (45 minutes) - Show us something you've built and walk us through your decisions Paid work trial (1 week) - Work on a real problem with the team and see if we're a mutual fit
Roles are as last read from the company’s own listings. Openings close without notice — check the date on the listing before you spend an evening on the application.
Check the company’s own careers page — linked at the top — before a job board. A role appears there first, sometimes weeks before it is syndicated anywhere else.
Questions and experiences
Nobody has asked anything about Casco yet. If you have interviewed here, what you know is worth more to the next person than anything on the rest of this page.
Company facts compiled from public sources and last refreshed 9 September 2026. Details change; treat the company’s own site as the authority.