Are you looking to build tools that engineers actually keep in their workflow? Do you get excited about AI agents that fix real vulnerabilities instead of writing confident nonsense about them? Are you willing to tolerate ridiculous bird puns? If you said yes to at least two of those, keep reading.
\nStackHawk builds the security layer for AI-assisted engineering. Our platform finds exploitable vulnerabilities in running applications and APIs, then hands the proof and the fix path directly to the coding agent already sitting in the developer's editor. Claude Code, Cursor, Copilot, Codex. Scan, fix, verify, in a loop, without a human copying findings between tabs.
That product is real and shipping. It is also early, which means the architecture decisions that matter most have not been made yet.
We are looking for a senior engineer to own that loop. You will spend most of your time on agentic systems: the tool surfaces our agents call, the context they get, the loop that decides when a fix is actually verified, and the evals that tell us whether any of it got better this week. You will also work in the core platform, because the loop is only as good as the scan engine and APIs underneath it. This is not a research role. Everything you build goes to customers.
The team is small. Your work will be visible in the product within days, and in customer conversations within weeks.
Want to see what we mean before you apply? Our agent skills are open source at github.com/stackhawk/agent-skills. Read them. If you look at that and immediately have ideas, apply.
This role is onsite in Denver. We know that narrows the pool and we are doing it on purpose. The hard part of this work is not writing the code. It is the whiteboard argument about why the loop stopped early, the shoulder tap when an eval result looks wrong, and the twenty minutes after a customer call that turns into a design change. That happens in a room with our small team.
We move fast and this list is not exhaustive.
If your agentic experience is one weekend project and a course certificate, this is not the right role yet. If it is a system you shipped, maintained, and had to debug at 11pm, we want to talk.
AppSec depth is a strong plus, not a requirement. If you already know your vulnerability classes cold, that will accelerate everything. If you do not, we will teach you, and you will learn faster here than anywhere else. What we do require is curiosity about how software breaks and the discipline to care about correctness. An agent that reports a fix it did not verify is worse than no agent at all.
No trivia and no take home that eats your weekend. Expect a working session where we look at a real agent loop problem together, talk through where it fails and how you would measure it, and dig into something you have actually built. Use whatever language you are strongest in. We are not screening for Kotlin syntax. Bring the messy version. We are more interested in how you debugged it than how it looks in the README.
StackHawk is proud to be an equal opportunity employer. We are committed to equal opportunity regardless of race, color, ancestry, religion, gender, gender identity, genetic information, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, disability, or Veteran status.
StackHawk provides a Dynamic Application Security Testing (DAST) platform designed to integrate security testing into the software development lifecycle. Its tools enable developers to identify and address security vulnerabilities in APIs and web applications before deployment. The platform supports various API types, including REST, GraphQL, SOAP, and gRPC, and integrates with development tools such as GitHub, GitLab, Azure Repos, and Bitbucket. StackHawk's API Discovery feature leverages AI to automatically identify APIs and microservices, offering real-time visibility into potential security risks. By incorporating security testing into Continuous Integration and Continuous Delivery (CI/CD) workflows, StackHawk facilitates early detection and remediation of vulnerabilities, aligning with modern DevOps practices. The platform also provides detailed vulnerability insights, including request/response evidence and mitigation documentation, to assist development teams in prioritizing and resolving security issues efficiently.
Salary
$150,000 - $200,000
Location
Denver, CO
Total raised
$47.3M
Last stage
Series C
Investors
No applications, no recruiter spam. Just the intro.
A few questions to make sure this role is the right shape for you. Two minutes.
I write the intro, send it to the founder, and handle the back-and-forth.
If they’re a yes, I book the chat. You show up — that’s the whole job-hunt.