
Oneleet
YC's most popular security compliance platform (SOC 2, ISO 27001,…
What Oneleet does
Oneleet helps companies become secure and compliant through an all-in-one solution that combines automated tools and human expertise. Oneleet has built the second generation of security compliance automation software, providing tools that go beyond what is classically provided for just compliance alone. Tools like a code security scanner, attack-surface management, access reviews and trust portal are all built in. As the most popular, highest rated and most frequently used platform in the YC community, Oneleet has quickly established itself as the preferred and superior alternative to other incumbents. The founder behind Oneleet has spent the past 10+ years helping companies become more secure by performing penetration tests.
14 open roles
What the role involves
About Oneleet Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners. Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry. The Role You will be the architect of the community and event experience that makes Oneleet the most connected name in cybersecurity and compliance. From intimate customer dinners and executive roundtables to industry conferences and digital community spaces, you will build the programs that turn customers, prospects, and practitioners into a genuine Oneleet community. This is a founding role. There is no inherited event calendar or existing community platform to manage- you will define the strategy, build the infrastructure, and create the moments that matter. You will work hand-in-hand with Sales, Marketing, and Customer Success to ensure every event and community touchpoint is purposeful, on-brand, and driving real relationships that translate into pipeline and retention. You will thrive here if you believe that community is a growth strategy, not a feel-good initiative- and if you have the operational discipline to execute flawlessly while never losing sight of the human experience you are trying to create. What You Will Do Community Strategy & Program Building Own and build Oneleet's community strategy from the ground up- defining the audience, the value proposition, the platforms, and the programming that will make practitioners and buyers want to be part of it Launch and manage Oneleet's owned community channels (Slack, Discord, LinkedIn, or similar) with clear onboarding journeys, engagement rituals, and moderation standards Develop a content and programming calendar for the community: AMAs with security experts, compliance Q&A sessions, peer networking threads, and product feedback loops Build a champion and ambassador program that turns Oneleet's most enthusiastic customers into active community voices Event Strategy & Execution Own the full Oneleet events calendar- from intimate executive dinners and customer roundtables to hosted meetups, webinars, and presence at major industry conferences Design event experiences that feel distinctly Oneleet: thoughtful, high-quality, and anything but generic Manage end-to-end event logistics: venue sourcing, vendor management, invitations, run-of-show, on-site execution, and post-event follow-through Build a repeatable playbook for flagship event formats so the program can scale without losing quality Executive & Customer Engagement Programs Design and run exclusive programs for senior stakeholders- CISO roundtables, CTO advisory dinners, customer advisory boards- that deepen relationships and generate strategic insights Partner with Sales and Customer Success to identify the right attendees for the right events and ensure every invitation feels personal and intentional Create closed, peer-led forums where security and compliance leaders can connect, share challenges, and see Oneleet as the trusted platform at the center of those conversations Conference & Industry Presence Own Oneleet's strategy and presence at key industry events and other relevant conferences Coordinate booth experiences, sponsored sessions, side events, and executive meetings that maximize Oneleet's impact at each conference Scout and evaluate new conference and sponsorship opportunities that align with where Oneleet's buyers spend their time Measurement & Growth Def
What the role involves
About Oneleet: Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity management program. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Who we’re looking for: At Oneleet we value individuals who are passionate and motivated to make a large impact in the cybersecurity ecosystem. We are looking for rebels with a growth mindset who love to take ownership, who exhibit excellent communication skills, and who have a "can-do" attitude towards technical challenges and innovation. A rebel’s mindset — we’re frustrated with the state of the cybersecurity industry, and believe that a rebel mindset is key to changing it. Opinionated (but not obstinate) — we believe that having an opinion is better than having no opinion, and helps us move quicker. We're building Oneleet's customer support function from the ground up, and this is one of the first hires. As a Customer Support Specialist, you'll be the first point of contact for our customers — a mix of technical and non-technical stakeholders navigating compliance for the first time. You'll work primarily through Slack shared channels and email, with a high bar for response time. Our standard is a first response within 15 minutes — because our customers can't afford to wait. This is a foundational role with real room to grow. You'll help shape how support works at Oneleet, contribute to the knowledge base, and have direct visibility into how the product is experienced day-to-day. Key Responsibilities Monitor and respond to customer questions across Slack shared channels and the support ticket queue Resolve platform navigation, onboarding, billing, and pentest scheduling inquiries Triage incoming requests and route escalations to the right internal team with full context documented Send timely holding responses on escalations so customers always know what's happening Log and tag all interactions accurately in our ticketing system (Pylon) Identify recurring issues and contribute answers to the internal knowledge base Collaborate with Security Program Managers, CS, and Engineering to resolve customer issues efficiently What to Expect Fast-paced environment — we're growing 2x and the support function is being built in real time High ownership — you won't be handed a fully built playbook. You'll help write it. Direct impact — your work directly affects whether our customers hit their compliance goals on time Collaborative team — you'll work closely with Security Program Managers, CS, and Engineering, not in a silo Requirements 2+ years in a customer-facing support or success role at a SaaS company Exceptional written communication — clear, concise, and warm under pressure Comfortable managing high volume across multiple channels simultaneously Strong organizational instincts — nothing falls through the cracks on your watch Self-directed and able to work autonomously in a fully remote environment Nice to have: Familiarity with compliance frameworks (SOC 2, ISO 27001) or willingness to learn quickly Experience with Pylon, HubSpot, or Slack-based support workflows Prior experience at an early-stage or high-growth startup Why Oneleet At Oneleet, you'll join a tight-knit crew of cybersecurity rebels on a mission to reshape the industry. We move fast, take ownership, and aren't afraid to disrupt stagnant business models to make security effortless for companies. Our "work hard, play hard" culture means we hold ourselves to high standards, then celebrate wins. Our leading-edge tech st
What the role involves
About Oneleet Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry. We are making cybersecurity and compliance effective, easy, and painless. We do this by providing a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners. Oneleet just raised a Series A of $33 million and is rapidly growing in customers and employees. The team has several decades of experience in security and compliance. Be a part of our team of opinionated rebels and help us create a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry. The Role We are looking for a Growth Content and Community Manager who wants to build a cult following around the best security and compliance platform on the planet, someone who thrives where speed, ownership, and impact matter. We are looking for someone who will have an outsized impact on a startup that already has a rocket ship trajectory. You will own our entire content and community presence from scratch. Your job is to make Oneleet impossible to ignore. You will pick fights with the status quo, challenge how the industry thinks about compliance, and build a tribe of people who believe Oneleet is the best thing since sliced bread, because we are. You will go against the grain, press buttons, and say the things nobody else has the guts to say, backed by real arguments because being right is the whole point. This is not a "schedule posts and report on impressions" role. You create content that provokes. You show up where our buyers hang out and become the voice they actually want to hear. You build a cult following from nothing. You will thrive here if you have already built your own audience that you grew yourself because you could not stop creating, and measured the growth. You have made people angry, made people think, and made people follow you because they could not look away. What You Will Do Own community presence across every channel where our buyers hang out--Reddit, Hacker News, Indie Hackers, Product Hunt, Twitter/X, etc.--where CTOs and founders talk about picking security vendors. You'll show up as the person everyone actually wants to hear from. Write and publish high-volume content for technical and business audiences that makes Oneleet the sharpest voice in security and compliance. Not louder for the sake of it, louder because we are right. You'll develop a brand voice so distinct people know it's us before they see the logo. Turn internal knowledge into content that hits different. The kind people screenshot and send to their group chats. Thought leadership that makes people stop scrolling, and start associating Oneleet with clarity in a space full of noise. Brand awareness and pipeline--your work will be measured by how it builds recognition among founders, CTOs, and security leaders, and how that recognition converts to leads and revenue conversations. Ghostwrite for founders and experts. Take their raw ideas and make them go viral. Challenge industry narratives. Call out the broken way things have been done. Say what everyone is thinking but nobody is saying. Run experiments constantly. Kill what does not work, double down on what does. Who We Are Looking For 3-6 years of experience in content, community, or growth marketing, where you've earned attention from technically sophisticated audiences, but we care more about what you have built than how long you have been at it. Exceptional writing skills with a portfolio that proves it. We will ask to see your work, and it better make us stop scrolling. You're community-native. You understand Reddit karma dynamics, how to add value in Hacker News, and why a well-placed comment in the right forum thread can outperform a month of blog posts. You set targets before you launch, trac
What the role involves
About Oneleet: Oneleet is a cybersecurity startup with a mission to revolutionize the industry. We make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps them build, manage, and monitor their cybersecurity management program. Backed by top-tier venture capital firms including Y Combinator, our founding team brings over 10 years of penetration testing and cybersecurity experience. Join our team of opinionated rebels and help us create a category-defining company reshaping the broken and fragmented cybersecurity industry. The Role: The Internal Security Compliance Auditor plays a critical role in ensuring the quality and completeness of client evidence before they undergo formal external compliance audits. Working behind the scenes as part of our internal quality assurance team, you'll partner with our Security Program Managers to review controls documentation, validate evidence quality, and perform final pre-audit quality assurance checks across multiple compliance frameworks including SOC2, ISO27001, PCI, HIPAA, and GDPR. Your expertise will strengthen our clients' compliance posture and prepare them thoroughly for their audit processes, while maintaining the high standards that differentiate Oneleet in the marketplace. This position requires deep technical knowledge of compliance frameworks combined with meticulous attention to detail. Key Responsibilities: Perform thorough internal reviews of client-uploaded evidence for compliance frameworks including SOC2, ISO27001, PCI, HIPAA, and GDPR Conduct detailed quality assurance checks on individual controls to verify completeness, accuracy, and sufficiency prior to their audits with third-party auditing firms. Execute comprehensive final QA reviews prior to clients engaging with an external auditor. Identify gaps or weaknesses in evidence documentation and recommend improvements Develop and maintain internal QA standards and review methodologies Create guidance documents to help clients improve evidence quality Collaborate with Security Program Engineers to address compliance gaps Stay current on evolving compliance requirements across multiple frameworks to ensure our pre-audit preparation meets industry standards Track audit readiness metrics and identify opportunities for process improvement Provide expert feedback to our product team for compliance platform enhancements to better support pre-audit readiness Requirements: Deep understanding of SOC2, ISO27001, PCI, HIPAA, and GDPR requirements Strong technical knowledge of security controls and their implementation Experience reviewing and evaluating evidence for compliance audits, particularly in preparing organizations for external audit processes Excellent attention to detail and quality control mindset Strong written communication skills for documenting findings Ability to work independently while supporting multiple client engagements Familiarity with compliance automation platforms and tools Experience in pre-audit preparation and internal quality assurance, preferably with multiple frameworks Certification in relevant frameworks (e.g., CISA, ISO 27001 Lead Auditor) preferred Why Oneleet: At Oneleet, you'll join a tight-knit crew of cybersecurity rebels on a mission to reshape the industry. We move fast, take ownership, and aren't afraid to disrupt stagnant business models to make security effortless for companies. Our "work hard, play hard" culture means we hold ourselves to high standards, then celebrate wins. Our leading-edge tech stack keeps things exciting for any geek. And our experienced team ensures you're always sharpening your skills. Bottom line, you'll have a blast doing deeply meaningful work. Expect hard problems, lots of autonomy, and plenty of growth. If you want your work to drive real change, this is the place to make your impact. Oh, and we offer all the usual startup perks too: Comprehensive benefits packages designed to support your health an
What the role involves
About Oneleet: Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity management program. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Who we’re looking for: At Oneleet we value individuals who are passionate and motivated to make a large impact in the cybersecurity ecosystem. We are looking for rebels with a growth mindset who love to take ownership, who exhibit excellent communication skills, and who have a "can-do" attitude towards technical challenges and innovation. A rebel’s mindset - we’re frustrated with the state of the cybersecurity industry, and believe that a rebel mindset is key to changing it. Opinionated (but not obstinate) - we believe that having an opinion is better than having no opinion, and helps us move quicker. We’re looking for a tech-savvy relationship builder to lead our customers through every stage of their penetration testing journey with us. In this role, you’ll own pentest engagements from start to finish- running scoping calls, coordinating test execution, and acting as the trusted point of contact for clients. You’ll translate complex security work into clear guidance, answer questions along the way, and ensure every deliverable lands smoothly and on time. This role is a great fit for a junior pentester who’s eager to grow and gain exposure to the business side of security. You’ll sharpen your technical skills while also building client relationships, learning how engagements are scoped, managed, and delivered, and seeing firsthand how security work drives real business outcomes. If you enjoy collaborating with people, explaining technical concepts in a clear way, and want a well-rounded path to advance your career, this position offers hands-on experience and meaningful growth opportunities. Key Responsibilities Lead scoping calls with clients to understand requirements, timelines, and target environments Serve as primary point of contact for clients throughout the engagement lifecycle Manage project schedules and ensure deliverables are completed on time Answer client questions regarding testing approach, findings, and remediation guidance Coordinate internal resources and communicate project status to stakeholders Facilitate kickoff meetings, status updates, and closeout discussions Handle engagement logistics including access provisioning, scheduling, and documentation Gather and organize pre-engagement information (IP ranges, credentials, rules of engagement) Ensure client satisfaction and address concerns promptly and professionally Support quality assurance processes to ensure consistent deliverable standards Assist pentesters on complex engagements and act as the point contact for escalated technical issues as needed Stay current on emerging threats, vulnerabilities, and testing methodologies Requirements 1-3 years of experience in penetration testing, security assessments, or related cybersecurity role Previous client-facing or customer service experience preferred Understanding of networking fundamentals Familiarity with operating systems and command line interfaces Basic knowledge of web application technologies and common attack vectors Ability to read and understand basic code Strong written and verbal communication skills with ability to explain technical concepts to non-technical audiences Professional demeanor with excellent client interaction abilities Strong organizational skills with ability to manage multiple engagements simultaneously Detail-oriented with exc
What the role involves
About Oneleet Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners. Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry. The Role You will be the single owner of the content and collateral that moves buyers from curious to convinced. White papers, competitive comparison tables, custom sales decks, ROI frameworks, battlecards- you will build the arsenal that gives our Sales and Customer Success teams an unfair advantage in every deal. This is a founding role within product marketing. There is no inherited content library to maintain- you will build it from scratch with sharp opinions about what actually influences B2B buying decisions in the security and compliance space. You will sit at the intersection of product, sales, and marketing, translating deeply technical capabilities into clear, compelling narratives that resonate with the CTOs, CISOs, heads of engineering, and compliance leads who buy Oneleet. You will thrive here if you believe that great product marketing is equal parts research and craft- that you cannot write a compelling comparison table without genuinely understanding how a buyer thinks, and that a well-built sales deck can be as strategically important as a feature launch. What You Will Do Sales Enablement & Deal Support Build and maintain the full library of sales collateral: one-pagers, battlecards, competitive comparison tables, objection-handling guides, and ROI/TCO frameworks Create custom presentations and tailored pitch materials for mid-market prospects and strategic accounts- working directly with Account Executives to craft decks that speak to a specific buyer's context, industry, and pain points Develop mid-funnel content that accelerates deals: case studies, proof-of-concept summaries, security posture assessments, and compliance outcome narratives Partner with Sales to identify recurring objections and gaps in the current collateral library, and close those gaps faster than anyone expects Thought Leadership & Long-Form Content Own the white paper and research content program- from topic ideation and outline through interviews, drafting, design briefing, and distribution Write authoritative, deeply credible long-form content on topics including SOC 2, ISO 27001, compliance automation, security program maturity, and the cost of legacy approaches Develop point-of-view content that positions Oneleet as the category-defining platform in the compliance and cybersecurity space Work with subject matter experts on the engineering and security team to extract insights that no generalist writer could produce Competitive Intelligence & Positioning Own Oneleet's competitive intelligence program- continuously monitoring the landscape, updating battlecards, and synthesizing win/loss patterns into actionable positioning guidance Build and maintain comparison frameworks (feature tables, methodology comparisons, pricing narratives) that hold up to scrutiny in a sales conversation Translate competitive insights into crisp, confident messaging that arms Sales to win against specific alternatives without sounding defensive Product Launches & Messaging Partner with Product to develop launch messaging, positioning, and collateral for new features and capabilities Ensure that product updates are translated into customer-facing language that emphasizes outcomes, not features Maintain a living messag
What the role involves
About Oneleet: Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity management program. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Who we’re looking for: At Oneleet we value individuals who are passionate and motivated to make a large impact in the cybersecurity ecosystem. We are looking for rebels with a growth mindset who love to take ownership, who exhibit excellent communication skills, and who have a "can-do" attitude towards technical challenges and innovation. A rebel’s mindset — we’re frustrated with the state of the cybersecurity industry, and believe that a rebel mindset is key to changing it. Opinionated (but not obstinate) — we believe that having an opinion is better than having no opinion, and helps us move quicker. The Security Program Manager is part vCISO & part account manager. You will work with our customers from the start to asses their current security/compliance framework, provide guidance and recommendations for improvements, and work with clients to implement recommendations. You're passionate about security, and enjoy sharing your knowledge with not only our customers but your colleagues. Key Responsibilities Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives. Provide guidance and recommendations for improving client security posture Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs. Collaborate with clients to customize and refine the security program to match their specific use cases. Communicate with clients and stakeholders to ensure smooth and efficient security program creation Liaise with auditors to ensure clients' security programs align with auditors' expectations Maintain expertise across a range of security frameworks, control types, and technologies including GDPR, NIST, ISO27001, SOC2, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more. Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs. Be highly technical, learn new technologies quickly, and translate security concepts into implementations. Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations. Requirements 3+ years in an information security role Must be located in the EU or UK Broad knowledge of security best practices, frameworks, control types, and relevant technologies. Ability to understand client infrastructure and map security controls to meet compliance goals. Strong analytical skills to evaluate environments and determine appropriate safeguards. Excellent verbal and written communication skills. Self-driven with the ability to work independently and move fast in a startup environment. Willingness to go the extra mile to meet tight deadlines and deliver results. Why Oneleet: At Oneleet, you'll join a tight-knit crew of cybersecurity rebels on a mission to reshape the industry. We move fast, take ownership, and aren't afraid to disrupt stagnant business models to make security effortless for companies. Our "work hard, play hard" culture means we hold ourselves to high standards, then celebrate wins. Our leading-edge tech stack keeps things exciting for any geek. And our experienced team ensures you're a
What the role involves
About Oneleet Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry — making cybersecurity and compliance effective, easy, and painless. We do this by providing a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners. Oneleet just raised a Series A of $33 million and is rapidly growing in customers and employees. The team has several decades of experience in security and compliance. Be a part of our team of opinionated rebels and help us create a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry. Who we’re looking for: We value passionate self-starters with a growth mindset and a bias for action and personal accountability. If you love solving hard problems, thrive in ambiguity, and want to make a real impact, you’ll fit right in. We’re especially drawn to: Rebels with a cause — frustrated with the status quo and eager to disrupt it. Opinionated (but not obstinate) builders — decisive yet collaborative, who help us move fast. Clear communicators — who own their ideas and follow through. Our mission is simple: make effective cybersecurity painless. We believe cybersecurity should empower, not burden. This belief unites our team and drives every decision we make. If you’re ready to challenge the status quo and help shape the future of cybersecurity, we’d love to meet you. The Role Design at Oneleet isn't a support function, it's a competitive weapon. Our customers are security and engineering teams who deal with clunky, outdated tooling every day. We are the product they actually enjoy using. As our Product Designer, you'll join one other designer and together own the design of our product end-to-end: from the first pixel of a new feature to how it feels in production. You'll also shape our visual identity, making sure Oneleet looks and feels like the category leader it is. You will work side-by-side with engineers (our stack includes React, Tailwind CSS, Radix), shipping fast and iterating faster, and you will spend real time talking to customers to understand what they need before you open Figma. This is a fully remote, high-autonomy role based in EU or US timezones. There's occasional travel (team offsites, customer visits), but your default is async, and you own your schedule. What You Will Do Own the UX of our core product, from complex compliance workflows to onboarding flows and dashboards — making hard things feel simple Define and evolve Oneleet's visual identity and design language across the product and brand Work directly with engineers in tight feedback loops — handing off specs, reviewing implementations, and pushing for visual polish Get in front of customers regularly: run discovery calls, usability tests, and interviews to ground your design decisions in reality, not assumptions Leverage product analytics and user behavior data to inform your decisions — find out what's broken and what's working before anyone tells you Contribute to and maintain a scalable design system that keeps the product consistent as we grow Help raise the design bar constantly Who You Are 5–8 years of product design experience at a B2B SaaS company with a strong design culture An excellent portfolio showing complex product UX — not just polished UI, but evidence of hard problem-solving, research, and iteration You move fast and ship. You don't wait for perfect conditions — you get things in front of users and learn Genuinely curious about what customers are experiencing — you reach out, ask, listen, and translate what you learn into better design You use data and analytics tools as a core part of your workflow, not an afterthought Fluent in Figma with strong opinions on how to build and maintain lean design systems that balance consistency and velocity A high vi
What the role involves
About Oneleet Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity management program. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Role Description Want the chance to join one of the fastest growing cybersecurity companies in YC history? This is a career defining role for the right person who wants to be able to come in and have an outsized impact on a startup that already has a rocket ship trajectory. TLDR - we need you to provide demos & close all of our inbound leads, helping startups achieve real-world security & obtain a SOC2 attestation. You’ll be selling quite literally the best product on the market, against other competing offers that have a larger brand name, but fall short on providing the real-world security that’s required to enable enterprise deals + partnerships. We need a human who authentically loves security & is ALSO an A+ sales rep or account executive. 90% of the sales process is talking about our product and explaining the SOC2 process, but you’ll often be selling into highly technical founders. Oneleet is a company that deeply cares about security & we are building a sales team that cares about authentic real-world security more than simply closing a deal. If you have a passion for both security AND sales, we would love to talk to you. Job Requirements Authentic passion for both security AND sales Technical background in either Computer Science or CyberSecurity Experience as a high preforming sales rep (top 1% of your org) Extremely strong communication skills, written + verbal Compensation is $60k - $100k base plus commission, OTE is $100k - $150k in year 1, with possibility for more going into year 2 factoring in renewals. Base varies depending on location, experience, and background.
What the role involves
About Oneleet Oneleet is one of the fastest-growing security and compliance platforms in history. We are on a mission to change the compliance and security industry by making cybersecurity and compliance effective, easy, and painless. We provide a platform that helps companies build, manage, and monitor their cybersecurity programs and achieve compliance standards such as SOC 2 and ISO 27001 efficiently, without cutting corners. Having just raised a $33 million Series A, we are rapidly growing in customers and employees. Our team has decades of experience in security and compliance. Join our team of opinionated rebels and help us build a category-defining company reshaping the broken and fragmented compliance and cybersecurity industry. The Role You will be the single owner of our entire go-to-market tech stack, data infrastructure, and attribution model. This is a founding role where you will architect how data flows between every system that touches our revenue motion from the first ad click to closed-won deal. You will build the connective tissue between Clay, HubSpot, DreamData, Google Tag Manager, Google Ads, Looker Studio, CrazyEgg, and whatever tools come next. This is not a tool administrator role. You are equal parts builder and strategist designing experiments, connecting platforms via APIs, setting up attribution models, and translating messy data into clear insights that help our sales team close deals and our executives understand where revenue comes from. You will thrive here if you light up when you see disconnected systems and immediately start thinking about how to wire them together. If you have ever built a Clay workflow that enriched leads, synced them to HubSpot, triggered a routing automation, and then measured attribution in a BI tool this is your role, but with full ownership and strategic influence. Key Responsibilities Tech Stack Ownership & Systems Architecture • Own every tool in the GTM stack as the architect who decides how they connect, what data flows where, and why • Evaluate, implement, configure, and maintain platforms including Clay, HubSpot (CRM, Marketing Hub, Operations Hub), DreamData, Google Tag Manager, Google Ads, Looker Studio, and CrazyEgg • Build integrations using APIs, webhooks, middleware, or custom code when native connections do not exist • Design the master data model that ensures a single source of truth across all systems • Create documentation so the infrastructure scales beyond you Data, Attribution & Analytics Infrastructure • Design and implement the entire UTM strategy and multi-touch attribution model from scratch • Configure DreamData for B2B revenue attribution and set up Google Tag Manager with proper event tracking and data layer implementation • Build Looker Studio dashboards that show executives exactly where pipeline and revenue originate • Create tracking infrastructure (CrazyEgg heatmaps, GA4 events, conversion tracking) that captures every meaningful interaction • Own data quality, enrichment workflows, lead scoring models, and the entire journey from anonymous visitor to closed deal Experimentation & Growth Enablement • Design and run experiments across the funnel A/B tests on landing pages, outbound sequence variations, lead routing optimizations, and scoring model adjustments • Build the infrastructure that makes experimentation possible: proper tracking, clean control groups, and statistically valid measurement • Use Clay to build enrichment and prospecting workflows, test new data sources, and scale what works into production automations Stakeholder Support & Revenue Intelligence • Deliver enriched lead data, buying signals, and account intelligence that makes every sales conversation more informed • Build dashboards and reports for executives that clearly show which channels, campaigns, and motions drive pipeline and revenue • Sit in revenue meetings, explain what the data shows, and recommend where to invest next Requir
What the role involves
Note: Even though the job posting only mentions US, we are looking for candidates from all NATO countries. Please only apply directly to this job posting. Messages sent outside of this platform will not be considered. About Oneleet Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity program. We’re essentially building an all-in-one security platform that will allow companies to have everything they need under one roof to build a secure company. We have already built our own ASM (Attack-Surface Monitoring), CSPM (Cloud-Security Posture Management), MDM (Mobile-Device Management) and Vulnerability Management modules, and have many more on the roadmap. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Who we’re looking for At Oneleet we value individuals who are passionate and motivated to make a large impact in the cybersecurity ecosystem. We are looking for rebels with a growth mindset who love to take ownership, who exhibit excellent communication skills, and who have a "can-do" attitude towards technical challenges and innovation. A rebel’s mindset — we’re frustrated with the state of the cybersecurity industry, and believe that a rebel mindset is key to changing it. Opinionated (but not obstinate) — we believe that having an opinion is better than having no opinion, and helps us move more quickly. You’re excited about a role that requires hands-on coding, enabling you to address challenges and play a substantial role in shaping the trajectory of the Oneleet platform. Expert time management; we work with clients all over the world as well as have a team that is spread throughout multiple continents. We don’t expect anyone to be working or available 24/7- but we are looking for someone comfortable operating outside of the 9-5 mentality. Our core hours are 9am-1pm EST and expect that you can schedule your day effectively outside of that, while being flexible. Job Description: As an Engineer on the Oneleet Agent team, you'll be responsible for developing and maintaining our cross-platform endpoint security agent that monitors, configures, and protects employee devices. You'll work on everything from low-level system configuration automation to high-level API design that enables seamless communication between endpoints and our cloud platform. You'll architect solutions that collect security telemetry, enforce compliance policies, and monitor for vulnerabilities across Windows, macOS, and Linux environments. This role requires deep technical expertise in system programming, security best practices, and the ability to build software that operates reliably in diverse enterprise environments. As a seed stage startup, you'll collaborate directly with the founding team and have significant influence over the technical direction of our endpoint security capabilities. Key Responsibilities: Design and implement cross-platform agent functionality for Windows, macOS, and Linux using Go and JavaScript Build low-level configuration automation and system monitoring capabilities that interact with OS-specific APIs and security frameworks Develop secure communication protocols between agents and our cloud platform using gRPC or REST APIs Implement real-time threat detection and response capabilities at the endpoint level Create robust update and deployment mechanisms that ensure agents remain current without disrupting user workflows Build telemetry collection systems that provide visibility into device security posture while respecti
What the role involves
Please only apply directly to this job posting. Messages sent outside of this platform will not be considered. The why behind this position: At Oneleet we provide a platform that makes it easy for our clients to become secure and compliant. Our Cloud Security Posture Management (CSPM) product is a critical component of our all-in-one security platform, continuously monitoring cloud environments to identify misconfigurations, compliance violations, and security risks before they become vulnerabilities. As our client base is rapidly expanding, we need to strengthen our CSPM engineering team. While integrations with cloud providers and security tools remain a huge part of CSPM, we need engineers who can work across the entire product - from building and maintaining cloud integrations to developing security policies, improving detection logic, and ensuring our monitoring systems are robust and reliable. One of the most common complaints we get from clients relates to reliability and coverage gaps in our CSPM product, so bringing on someone with experience building scalable, robust cloud security solutions is very important for us at this time. Job Description: As a security platform for startups, our CSPM product monitors cloud environments across AWS, GCP, and Azure to ensure customers are configured securely. For example, we detect exposed storage buckets, verify encryption standards, identify overly permissive IAM policies, and track compliance with security frameworks. You will extend and improve Oneleet's CSPM capabilities, working on everything from cloud provider integrations to security policy development. You'll contribute to the design and implementation of cloud security monitoring features, build detection rules for new attack vectors, and ensure our CSPM product scales reliably as customers' cloud footprints grow. You'll work with various security solutions including vulnerability assessments, compliance scanning, configuration monitoring, and risk scoring systems. As a seed stage startup, you'll have the opportunity to collaborate with the founding team to understand business/customer needs and contribute to building the core technology that powers the Oneleet platform. Key Responsibilities: Build and maintain cloud provider integrations to discover resources, monitor configurations, and detect security risks across multi-cloud environments Develop security policies and detection rules to identify misconfigurations, compliance violations, and emerging threats Design systems that structure and validate diverse cloud data sources, handling inconsistent APIs and evolving cloud services Create comprehensive documentation for CSPM features, security findings, and remediation guidance Ensure reliable monitoring and alerting for both customer environments and our own CSPM infrastructure Contribute to risk scoring algorithms and prioritization logic to help customers focus on critical issues Improve engineering standards, tooling, and processes Qualifications: Experience with strongly typed compiled languages like Go, Java, C#, C++, or Rust. We strongly prefer Go experience. 3+ years of development experience, ideally with a focus on backend APIs, integrations, or networking Experience with SQL Experience building, architecting, or maintaining SaaS platforms Experience integrating with REST APIs, implementing solutions based on documentation, or parsing data from sources like spreadsheets Bonus: Experience in the information security field Bonus: Knowledge of authentication methods like OAuth 2.0, OIDC, SAML and API security best practices Bonus: Experience with integration testing and debugging tools Bonus: Bachelor's or Master's degree in Computer Science or related field You should apply if any of the following excite you: Making the world a more secure, privacy focused, and trusted place. Automating processes that have a huge impact and save time for many companies at once including a large part of t
What the role involves
About Oneleet: Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity management program. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Who we’re looking for: At Oneleet we value individuals who are passionate and motivated to make a large impact in the cybersecurity ecosystem. We are looking for rebels with a growth mindset who love to take ownership, who exhibit excellent communication skills, and who have a "can-do" attitude towards technical challenges and innovation. A rebel’s mindset — we’re frustrated with the state of the cybersecurity industry, and believe that a rebel mindset is key to changing it. Opinionated (but not obstinate) — we believe that having an opinion is better than having no opinion, and helps us move quicker. The Security Program Manager is part vCISO & part account manager. You will work with our customers from the start to asses their current security/compliance framework, provide guidance and recommendations for improvements, and work with clients to implement recommendations. You're passionate about security, and enjoy sharing your knowledge with not only our customers but your colleagues. Key Responsibilities Conduct initial consultation calls with new clients to assess their current security posture, infrastructure stack, compliance requirements and overall objectives. Provide guidance and recommendations for improving client security posture Develop high-level security programs consisting of technical, operational and administrative controls based on industry frameworks and client needs. Collaborate with clients to customize and refine the security program to match their specific use cases. Communicate with clients and stakeholders to ensure smooth and efficient security program creation Liaise with auditors to ensure clients' security programs align with auditors' expectations Maintain expertise across a range of security frameworks, control types, and technologies including NIST, SOC2, ISO27001, CMMC, AWS, Azure, GCP, Kubernetes, Docker, Terraform, and more. Provide feedback to Oneleet's engineering team to inform development of integrations, solutions, and products that deliver on client needs. Be highly technical, learn new technologies quickly, and translate security concepts into implementations. Partner with internal teams to translate security programs into implementations consisting of policies, procedures, configurations and software integrations. Requirements 3+ years in an information security role Broad knowledge of security best practices, frameworks, control types, and relevant technologies. Ability to understand client infrastructure and map security controls to meet compliance goals. Strong analytical skills to evaluate environments and determine appropriate safeguards. Excellent verbal and written communication skills. Self-driven with the ability to work independently and move fast in a startup environment. Willingness to go the extra mile to meet tight deadlines and deliver results. Why Oneleet: At Oneleet, you'll join a tight-knit crew of cybersecurity rebels on a mission to reshape the industry. We move fast, take ownership, and aren't afraid to disrupt stagnant business models to make security effortless for companies. Our "work hard, play hard" culture means we hold ourselves to high standards, then celebrate wins. Our leading-edge tech stack keeps things exciting for any geek. And our experienced team ensures you're always sharpening your skills. Bottom l
What the role involves
Note: Even though the job posting only mentions US, we are looking for candidates from all NATO countries. About Oneleet Oneleet is a cybersecurity startup with a mission to revolutionize the industry. It aims to make effective cybersecurity easy and painless for companies by providing a comprehensive platform that helps companies build, manage, and monitor their cybersecurity program. We’re essentially building an all-in-one security platform that will allow companies to have everything they need under one roof to build a secure company. We have already built our own ASM (Attack-Surface Monitoring), CSPM (Cloud-Security Posture Management), MDM (Mobile-Device Management) and Vulnerability Management modules, and have many more on the roadmap. Oneleet is backed by top-tier venture capital firms including Y Combinator, and is part of their S22 cohort. The founding team has over 10 years of penetration testing and cybersecurity experience. Be a part of our team of opinionated rebels and help us create a category-defining company on a mission to reshape the broken and fragmented cybersecurity industry. Who we’re looking for At Oneleet we value individuals who are passionate and motivated to make a large impact in the cybersecurity ecosystem. We are looking for rebels with a growth mindset who love to take ownership, who exhibit excellent communication skills, and who have a "can-do" attitude towards technical challenges and innovation. A rebel’s mindset — we’re frustrated with the state of the cybersecurity industry, and believe that a rebel mindset is key to changing it. Opinionated (but not obstinate) — we believe that having an opinion is better than having no opinion, and helps us move more quickly. You’re excited about a role that requires hands-on coding, enabling you to address challenges and play a substantial role in shaping the trajectory of the Oneleet platform. Expert time management; we work with clients all over the world as well as have a team that is spread throughout multiple continents. We don’t expect anyone to be working or available 24/7- but we are looking for someone comfortable operating outside of the 9-5 mentality. Our core hours are 9am-1pm EST and expect that you can schedule your day effectively outside of that, while being flexible. About the job The Software Engineer (Backend) is a crucial contributor to Oneleet's success, providing technical expertise and innovative solutions in our cybersecurity platform. As a seed-stage startup, this role offers unique opportunities for close collaboration with the founding team and cross-functional departments. You'll be instrumental in building and optimizing our backend infrastructure, working with latest technologies like Go, TypeScript, and PostgreSQL. Key Responsibilities Develop and maintain backend services and APIs written in Go Implement and improve metrics and distributed tracing across our services Optimize PostgreSQL database performance and queries Collaborate with the Engineering team on improving the overall Developer Experience Implement security best practices Collaborate with frontend and the overall engineering team Qualifications 6+ years of experience with Go and designing REST APIs Experience writing optimized PostgreSQL queries Scrappy; prior startup experience and not afraid to get their hands dirty Pragmatic; knows how to build things fast without unnecessarily complicating things Expert time management; we work with clients all over the world. We don’t expect anyone to be working 24/7- but we are looking for someone comfortable operating outside of the 9-5 mentality. Comfortable wearing many hats and eagerly adjusts to shifting priorities Experience in (and thrives in) a fast-moving, start-up engineering environment Excellent communication skills across all levels of technical proficiency Experience with architecting, building and maintaining SaaS platform backends Bonus: Experience with gRPC or similar tool Bonus: Experience with Ty
Roles are as last read from the company’s own listings. Openings close without notice — check the date on the listing before you spend an evening on the application.
Check the company’s own careers page — linked at the top — before a job board. A role appears there first, sometimes weeks before it is syndicated anywhere else.
Questions and experiences
Nobody has asked anything about Oneleet yet. If you have interviewed here, what you know is worth more to the next person than anything on the rest of this page.
Company facts compiled from public sources and last refreshed 9 September 2026. Details change; treat the company’s own site as the authority.