--- title: 'AppSec Engineer at Theori' canonical: 'https://feeny.ai/job/appsec-engineer-theori-united-states-qw04q9qs65t6' type: 'job' last_seen: '2026-09-10' --- # AppSec Engineer at Theori - **Company:** Theori - **Location:** United States - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-06-05 - **Last confirmed live:** 2026-09-10 - **Apply:** https://jobs.ashbyhq.com/theori/bc072f72-2e83-4bbe-9962-1276055415b9 ## Job description We're looking for a hands-on Cyber Security Engineer to sit at the intersection of AI-driven tooling and real-world security research. In this role, you'll own the end-to-end triage and validation lifecycle for vulnerability reports generated by our AI-powered static analysis platform, separating true positives from noise, writing proof-of-concept exploits, and reporting vulnerabilities upstream to the appropriate vendor. This is a deeply technical role built for someone who thinks like an attacker, thrives in ambiguous environments, and has a track record of finding and exploiting vulnerabilities. ## What You'll Do - Triage and validate vulnerability reports produced by our AI static analysis tool, verifying severity, exploitability, and business impact - Write proof-of-concept exploits for critical vulnerabilities to confirm true positives - Analyze false positives to identify patterns and provide structured feedback to engineering - Author detailed vulnerability reports that will be submitted to upstream vendors and open source projects ## What We're Looking For - Experience in a security engineering, vulnerability research, or penetration testing role - Demonstrated CTF experience through participation in competitive CTFs (e.g. DEFCON, PlaidCTF) with writeups - Hands-on real-world vulnerability research and exploitation experience is preferred - Proficiency reading and auditing code across multiple programming languages - Prior bug bounty participation is preferred - Based in US or Canada ## About Theori ## Company Overview - **One-liner**: Theori is an offensive cybersecurity company that uses AI-powered solutions and elite hacker expertise to secure AI systems, applications, and networks for global clients. - **Entity Type**: Private (Seed stage) - **Headquarters**: Austin, Texas, United States (US office); Seoul, South Korea (Korea office) - **Founded**: 2016 - **Founders**: Not publicly listed (company built by elite hackers with multiple DEF CON wins) ## Core Business - **Primary industry/industries**: Cybersecurity (offensive security, AI security, application security, blockchain security, security training) - **Target customers**: Enterprises (B2B) – including Microsoft, Google, Okta, POSCO DX; also government and defense organizations - **Mission or purpose statement**: “Raising the standard of security at every turn” – Theori tackles the most difficult cybersecurity challenges from an attacker’s perspective and trains the next generation of security leaders. ## Products & Services - **Xint**: AI-powered application security testing (AST) solution that identifies vulnerabilities with human-level expertise, speed, and cost efficiency. Includes Xint Code for real-time code scanning. - **αprism**: LLM security monitoring and guard model that continuously monitors prompts and model responses to protect AI interactions. - **Dreamhack / Dreamhack Enterprise**: Cybersecurity training platform offering interactive, self-paced learning and customizable curricula for enterprises. Includes a paid subscription service and in-house competition management. - **PatchDay**: Bug bounty platform launched in 2024. - **ChainLight / ChainLight DART**: Blockchain security audit and risk management services. - **Fermium-252**: Threat intelligence database. - **AI Red Teaming**: Expert-led audits covering all angles of AI systems to identify vulnerabilities before exploitation. - **Relic Protocol**: Chain data attestation protocol (launched 2018). - **Upside Academy**: Cyber training program (now in its 3rd edition). ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric**: Total Funding – **$15.5 million** (seed round led by K2G Fund, reported in 2025); prior investment from NAVER (2020). - **Notable Investors/Partners**: K2G Fund (lead), NAVER, POSCO DX (strategic partnership), Okta (strategic cybersecurity partnership). - **Growth Signals**: - Won #1 in DARPA AI Cyber Challenge (AIxCC) Semifinals (2024) - 9 DEF CON competition wins - Over 50 international hacking competition wins - Beta launch of αprism in April 2025 - Launch of PatchDay bug bounty platform (August 2024) - Partnership with POSCO DX for AI-driven security framework (May 2025) - Received Presidential Commendation from the President of South Korea (2022) - Opened US office in Austin, TX ## Competitive Advantages - **Elite Hacker Team**: Built by top offensive security experts with proven track records in global hacking competitions (DEF CON, AIxCC). - **AI-Native Security**: Products like Xint and αprism are purpose-built for the AI era, monitoring and securing LLMs and codebases proactively. - **Offensive Security Approach**: Tests systems from an attacker’s perspective, identifying vulnerabilities before malicious actors can exploit them. - **Trusted by Industry Leaders**: Microsoft, Google, and Okta rely on Theori’s research and solutions. - **Dual Headquarters (US + Korea)**: Allows access to both American and Asian markets and talent pools. ## Strategic Focus - **AI Security Leadership**: Expanding AI-powered security solutions (Xint, αprism) and AI red teaming services to address emerging threats. - **Training the Next Generation**: Growing Dreamhack enterprise offerings and Upside Academy programs to build a skilled cybersecurity workforce. - **Continuous Innovation**: Annual independent research period for employees and ongoing product launches (PatchDay, ChainLight, Fermium-252). - **Global Expansion**: Building US presence from Austin office while maintaining strong Korea operations. ## Why Work Here - **Culture Highlights**: “Built by elite hackers” – the company emphasizes hands-on hacking, continuous learning, and ethical transparency. Annual independent research period and support for CTF competitions. - **Remote/Hybrid/Office Policy**: Hybrid workspace with two offices (Austin, TX and Seoul, Korea). Remote positions available (e.g., AppSec Engineer, Backend Software Engineer). - **Notable Perks**: - Unlimited leave system - 1-month sabbatical leave for every 3.5 years - Learning stipend and education/personal development stipend - Technology stipend - Meal allowance, free snacks and drinks - Monthly Culture Day - Seasonal corporate gifts - Annual health screenings (Korea) - Support for workplace social clubs - Mentoring program for new recruits - Military service exemption business (Korea) ## Sources 1. [theori.io](https://theori.io/) 2. [theori.io/about](https://theori.io/about) 3. [theori.io/career/culture](https://theori.io/career/culture) 4. [jobs.ashbyhq.com/theori](https://jobs.ashbyhq.com/theori) 5. [builtin.com](https://builtin.com/company/theori-inc) ## Other roles at Theori - [Backend Software Engineer](https://feeny.ai/job/backend-software-engineer-theori-united-states-g0n0j5rwvavp) — United States - [AppSec Engineer](https://feeny.ai/job/appsec-engineer-karbon-austin-tx-qsrg2ddf436g) — Austin TX, United States / Chicago IL, United States / Denver CO, United States / Los Angeles CA, United States / San Diego CA, United States / San Francisco CA, United States