Member of Technical Staff

at Hex Security — Agentic Offensive Security at Scale

San Francisco, CA, USFull-timeAny (new grads ok)$130K - $250KYC-W26

What the role involves

We're building autonomous AI agents that find and verify real security vulnerabilities the kind that used to require a senior pentester and a week of work. We're a YC W26 company with ~$1M ARR in a few weeks, top-tier investors, and top customers.

We need engineers who are cracked at AI, infrastructure security, and TypeScript. You'll be shipping systems that orchestrate agents across sandboxed environments, process untrusted code at scale, and deliver verified findings that security teams actually trust.

What you'll do

Design and build the core platform. Agent orchestration, verification pipelines, and the infrastructure that ties it all together. Ship production features end-to-end: you own it from architecture to deployment. Work across our stack: Temporal workflows, Kubernetes, Nomad Clusters, sandboxed execution environments. Solve hard distributed systems problems like scheduling, isolation, fault tolerance, encryption. Collaborate directly with founders and customers to shape what we build next.

What we're looking for

An overall cracked individual. Strong in TypeScript and/or Python, you write clean code and you ship fast. Comfort with cloud infrastructure (GCP/AWS) and containerized environments. You've debugged something at 2am that wasn't your fault and fixed it anyway. You default to ownership. If something's broken, you fix it. If something's missing, you build it. Your entire life has to be this company.

Nice to have

Experience with AI/LLM agent systems, tool-use patterns, or multi-step orchestration. Background in security, offensive tooling, or working with untrusted inputs. Familiarity with Temporal, Kubernetes, or sandbox technologies (E2B, gVisor, bubblewrap). You've built something from zero that people actually use.

About Hex Security

Hex Security builds AI agents that run continuous penetration tests against your apps and infrastructure. Instead of a once-a-year penetration test, Hex Security's agents works 24/7 to find and verify critical vulnerabilities so you can prevent them before attackers.

Full Hex Security profile

Other roles at Hex Security

Similar Engineering, Full stack elsewhere

jobo is a browser extension. Open this on a computer to install it.