Member of Security Staff

San Francisco, CA
Full-time
Visa Sponsorship

About the role

We're looking for an Offensive Security Engineer who can bridge the gap between manual penetration testing and our autonomous AI agents. You'll conduct hands-on security assessments across web applications, APIs, and cloud infrastructure while also working to improve the agents that scale that work. You'll review and validate agent findings, develop custom exploits and tooling, and contribute directly to the platform as an engineer.

What you'll do:

Execute penetration tests across web applications, APIs, and cloud environments. Review, validate, and enhance findings generated by our autonomous agents. Develop custom exploits, tools, and methodologies for complex vulnerabilities. Contribute production code to improve agent capabilities and coverage. Produce actionable security assessment reports with clear remediation guidance. Work with customer engineering teams to walk through findings and fixes.

What we're looking for:

3+ years of professional penetration testing or offensive security experience with a track record of identifying critical vulnerabilities. Strong software engineering skills in Python and/or TypeScript. Deep understanding of web application security, including injection flaws, broken access control, authentication bypasses, and SSRF. Experience with common offensive tooling (Burp Suite, Nuclei, custom scripts) and comfort building your own. Familiarity with cloud security across at least one major provider (AWS, GCP, Azure).

Nice to have:

Experience with AI/LLM security, including prompt injection and agent manipulation. Bug bounty track record or published CVEs. Familiarity with OAuth/OIDC and SCIM attack surfaces. Relevant certifications (OSCP, OSWE, OSEP), though we care more about what you can do.

About Hex Security

Hex Security (now rebranded as Parameter) is an agentic offensive security company that builds AI agents to autonomously run continuous penetration tests against web applications, APIs, and infrastructure. Instead of traditional once-a-year pentests, their agents operate 24/7 to find, chain, and validate critical vulnerabilities with reproduction steps and remediation guidance. The company is a Y Combinator W26 batch member based in San Francisco.

Other roles at Hex Security

Interested?

Let me introduce you to the founders.

Skip the process

Job details

Salary

$130,000 - $180,000

Location

San Francisco, CA

Experience

0+ years

Company

NameHex Security
IndustryCybersecurity
Team Size10

Funding

Last stage

Pre-seed

Investors

Y Combinator

Founders

Ahmad Khan

Ahmad Khan

Co-Founder

LinkedIn
Prama Yudhistira

Prama Yudhistira

Co-Founder

LinkedIn
Huzaifa Ahmad

Huzaifa Ahmad

Co-Founder

LinkedIn

What happens next.

No applications, no recruiter spam. Just the intro.

01

Confirm the fit

A few questions to make sure this role is the right shape for you. Two minutes.

02

I pitch you to the company

I write the intro, send it to the founder, and handle the back-and-forth.

03

A meeting lands on your calendar

If they’re a yes, I book the chat. You show up — that’s the whole job-hunt.