--- title: 'Founding Member of Technical Staff (Security) at hacktron.ai' canonical: 'https://feeny.ai/job/founding-member-of-technical-staff-security-hacktron-ai-san-francisco-hmqpbfx96rr4' type: 'job' last_seen: '2026-09-08' --- # Founding Member of Technical Staff (Security) at hacktron.ai - **Company:** hacktron.ai - **Location:** San Francisco, CA - **Compensation:** $100k–$150k - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-01-18 - **Last confirmed live:** 2026-09-08 - **Apply:** https://jobs.gem.com/hacktron/am9icG9zdDq9yW6Nj6UyXVgzg60zef3A ## Job description We're looking for a founding security researcher to join us to build the future of security. Apply only if you’re deeply motivated by building in a small team, high ownership, high impact environment where your code will directly define the product and the company’s trajectory. Hacktron is building security products that empower teams building the software of tomorrow. We joined Project Europe's first cohort in July, raised our Seed round in January, and are continuing the grow, fast. ## What you'll do Your work will be central to our security research efforts and play a key role in testing LLM capabilities on real-world software. You will: - Work closely with one of the founders to scale our vulnerability research on open-source software, building on the work we've published in our [blog](https://www.hacktron.ai/blog). - Create benchmarks to evaluate agent performance on real-world scenarios. - Work closely with the engineering team to improve the efficacy of our agents by observing their performance on real systems. - Review and test our product and internal systems for security vulnerabilities. ## What we're looking for This is not an exhaustive list, nor are they strict requirements. If you meet at least 2 of the following criteria, please apply. We believe that frameworks can be learnt and are therefore framework-agnostic when evaluating past experience. - You have a strong understanding of reachability analysis / taint tracking. - You have a good understanding of web application vulnerabilities, and have demonstrated this through CTF competitions or being credited for the discovery of CVEs. - You have presented technical security research at conferences. - You have experience working with both traditional and LLM tools to aid your security research. ## How we work We're a hybrid team because we believe that the best talent can come from anywhere. We use Deel for payroll, allowing us to hire both employees and contractors in any country in the world. We give you a WeWork All Access Pass which covers desk bookings at any WeWork office around the world. You can use it to work in-person with other team members in the same city, but it is not mandatory - just get work done. You can participate in our Project Europe offsites which happen about once every 2 months. ## About hacktron.ai ## Company Overview - **One-liner**: Hacktron AI builds autonomous AI security agents that automatically identify, validate, and explain software vulnerabilities by reviewing every pull request and proving impact with working exploits. - **Entity Type**: Private (Seed stage) - **Headquarters**: Singapore, Singapore (with offices in San Francisco, Hyderabad, and London) - **Founded**: 2025 - **Founders**: Zayne Zhang (CEO), Mohan Pedhapati (CTO), Harsh Jaiswal (Chief Research Officer), Fabian Faessler (Head of Agent Engineering) ## Core Business - **Primary Industry**: Cybersecurity / AI-powered Application Security (AppSec) - **Target Customers**: B2B — engineering teams, security teams, and penetration testers at enterprises and high-growth technology companies - **Mission Statement**: "Find and fix security issues before they ship." ## Products & Services - **Hacktron AI Code Review Agent**: An autonomous agent that reviews every pull request on GitHub, GitLab, or Bitbucket. It traces code changes like an attacker would, finds exploitable vulnerabilities, and delivers a working proof-of-concept exploit directly in the PR thread. Includes AI-driven remediation suggestions. - **Full White-Box Pentests**: On-demand, full-scope security assessments that run in minutes. Includes threat modeling, taint tracing, dynamic exploit validation, and an audit-ready report for SOC 2 or ISO 27001 compliance. - **Vulnerability Disclosure & Research**: The team has publicly disclosed critical CVEs in major platforms including BeyondTrust, Metabase, OpenAM, OAuth2 Proxy, Next.js, WSO2, and Palo Alto Networks. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed - **Key Metric**: 15 total employees (as of 2025); the company is in its earliest stages - **Notable Investors/Partners**: Not publicly disclosed - **Growth Signals**: The founding team consists of elite, globally recognized security researchers and competitive hackers (DEF CON CTF finalists, BlackHat/DEF CON speakers, top bug bounty hunters). The company has already disclosed critical CVEs in major enterprise software, signaling immediate credibility and demand. The platform integrates with GitHub, GitLab, Bitbucket, Slack, Jira, Linear, and MCP/REST APIs — indicating a broad go-to-market strategy. ## Competitive Advantages - **Elite Founding Team**: Founders include a former Cure53 senior researcher, a top-ranked bug bounty hunter featured in Forbes for hacking Apple, a DEF CON CTF runner-up, and a security educator with 1M+ YouTube followers. This is a genuine "rockstar team" in the security world. - **Proof-of-Exploit, Not Just Alerts**: Hacktron differentiates by proving every finding with a working exploit. If they can't demonstrate impact, they don't alert. This eliminates false positives and gives developers immediate, actionable context. - **Agentic & Learning**: The system learns from each triage decision (accept, dismiss, downgrade) and gets smarter over time. It supports project rules that version with code and can auto-remediate findings. - **Pentest-as-a-Service at Machine Speed**: Full white-box assessments in hours, not weeks, with audit-ready compliance reports. ## Strategic Focus - **Automating the "Post-Finding" Workflow**: The platform is designed to automatically verify, fix, and test vulnerabilities, then notify the team — closing the loop from detection to remediation. - **Building for the AI-Native Security Era**: The company explicitly positions itself against attackers who are leveraging AI to find vulnerabilities faster. Hacktron aims to give defenders the same or greater speed advantage. - **Scaling the Team**: With only 15 employees and open roles for founding members of technical staff, the company is in a hyper-growth hiring phase. ## Why Work Here - **Culture**: Described as a small team of "world-class engineers and researchers." The company values solving the hardest problems in security and software engineering. The team has a competitive hacking background (DEF CON, bug bounties), suggesting a high-ownership, low-bureaucracy, meritocratic environment. - **Remote/Hybrid Policy**: Hybrid workspace. Offices in San Francisco, Singapore, Hyderabad, and London. Typical time on-site is not specified, but the company is open to hybrid arrangements. - **Notable Perks & Engineering Culture**: Opportunity to work alongside some of the most respected names in offensive security. The role is a "Founding Member of Technical Staff" — meaning high equity, high impact, and the chance to shape the product and company from near-day one. The tech stack likely involves AI/LLMs, static analysis, and cloud infrastructure. Internships are also available. - **For Job Seekers**: This is an extremely early-stage, high-risk/high-reward opportunity. The team's pedigree is exceptional, and the product has clear product-market fit signals. Ideal for engineers who want to work on cutting-edge AI security and are comfortable with a fast-paced, unstructured startup environment. ## Sources 1. [hacktron.ai](https://www.hacktron.ai/) 2. [hacktron.ai/team](https://www.hacktron.ai/team) 3. [LinkedIn](https://www.linkedin.com/company/hacktron) 4. [Built In](https://builtin.com/company/hacktron-ai-inc) 5. [Gem Careers](https://jobs.gem.com/hacktron) ## Other roles at hacktron.ai - [Founding Member of Technical Staff (Engineering)](https://feeny.ai/job/founding-member-of-technical-staff-engineering-hacktron-ai-san-francisco-8rhsjwqt9f6v) — San Francisco, CA - [Member of Technical Staff Intern](https://feeny.ai/job/member-of-technical-staff-intern-hacktron-ai-san-francisco-5hgmjvp60kgw) — San Francisco, CA