
What Hex Security does
Hex Security builds AI agents that run continuous penetration tests against your apps and infrastructure. Instead of a once-a-year penetration test, Hex Security's agents works 24/7 to find and verify critical vulnerabilities so you can prevent them before attackers.
2 open roles
What the role involves
We're looking for an Offensive Security Engineer who can bridge the gap between manual penetration testing and our autonomous AI agents. You'll conduct hands-on security assessments across web applications, APIs, and cloud infrastructure while also working to improve the agents that scale that work. You'll review and validate agent findings, develop custom exploits and tooling, and contribute directly to the platform as an engineer. What you'll do: Execute penetration tests across web applications, APIs, and cloud environments. Review, validate, and enhance findings generated by our autonomous agents. Develop custom exploits, tools, and methodologies for complex vulnerabilities. Contribute production code to improve agent capabilities and coverage. Produce actionable security assessment reports with clear remediation guidance. Work with customer engineering teams to walk through findings and fixes. What we're looking for: 3+ years of professional penetration testing or offensive security experience with a track record of identifying critical vulnerabilities. Strong software engineering skills in Python and/or TypeScript. Deep understanding of web application security, including injection flaws, broken access control, authentication bypasses, and SSRF. Experience with common offensive tooling (Burp Suite, Nuclei, custom scripts) and comfort building your own. Familiarity with cloud security across at least one major provider (AWS, GCP, Azure). Nice to have: Experience with AI/LLM security, including prompt injection and agent manipulation. Bug bounty track record or published CVEs. Familiarity with OAuth/OIDC and SCIM attack surfaces. Relevant certifications (OSCP, OSWE, OSEP), though we care more about what you can do.
What the role involves
We're building autonomous AI agents that find and verify real security vulnerabilities the kind that used to require a senior pentester and a week of work. We're a YC W26 company with ~$1M ARR in a few weeks, top-tier investors, and top customers. We need engineers who are cracked at AI, infrastructure security, and TypeScript. You'll be shipping systems that orchestrate agents across sandboxed environments, process untrusted code at scale, and deliver verified findings that security teams actually trust. What you'll do: Design and build the core platform. Agent orchestration, verification pipelines, and the infrastructure that ties it all together. Ship production features end-to-end: you own it from architecture to deployment. Work across our stack: Temporal workflows, Kubernetes, Nomad Clusters, sandboxed execution environments. Solve hard distributed systems problems like scheduling, isolation, fault tolerance, encryption. Collaborate directly with founders and customers to shape what we build next. What we're looking for: An overall cracked individual. Strong in TypeScript and/or Python, you write clean code and you ship fast. Comfort with cloud infrastructure (GCP/AWS) and containerized environments. You've debugged something at 2am that wasn't your fault and fixed it anyway. You default to ownership. If something's broken, you fix it. If something's missing, you build it. Your entire life has to be this company. Nice to have: Experience with AI/LLM agent systems, tool-use patterns, or multi-step orchestration. Background in security, offensive tooling, or working with untrusted inputs. Familiarity with Temporal, Kubernetes, or sandbox technologies (E2B, gVisor, bubblewrap). You've built something from zero that people actually use.
Roles are as last read from the company’s own listings. Openings close without notice — check the date on the listing before you spend an evening on the application.
Check the company’s own careers page — linked at the top — before a job board. A role appears there first, sometimes weeks before it is syndicated anywhere else.
Questions and experiences
Nobody has asked anything about Hex Security yet. If you have interviewed here, what you know is worth more to the next person than anything on the rest of this page.
Company facts compiled from public sources and last refreshed 9 September 2026. Details change; treat the company’s own site as the authority.