--- title: 'Security Product Engineer at DepthFirst' canonical: 'https://feeny.ai/job/security-product-engineer-depthfirst-san-francisco-73fe5368zeje' type: 'job' last_seen: '2026-09-11' --- # Security Product Engineer at DepthFirst - **Company:** DepthFirst - **Location:** San Francisco, CA - **Employment:** full-time - **Work type:** onsite - **Posted:** 2026-04-16 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/depthfirst/f0b11e7a-d1e8-43cf-a0e9-991f0cd1a4d8 ## Job description ## About depthfirst We believe that software is the foundation of modern civilization. Yet vulnerabilities threaten its integrity, security, and resilience. We are on a mission to secure the world's software. depthfirst is building intelligence to detect and remediate critical software vulnerabilities. We are training and scaling security AI agents to discover zero-days vulnerabilities across large customer codebases and popular open source software. Our founding team includes deep expertise in data, infrastructure, security and LLMs with technical leaders from DeepMind, Databricks, Square, and Faire. We are looking for strong technical people who are interested in working at the intersection of AI, Security, and Infrastructure. ## About This Role We're looking for a Security Product Engineer to work directly with customers to deploy and operationalize depthfirst's security AI agents in their environments. You'll be the technical bridge between our product and enterprise security infrastructure, ensuring our AI successfully detects vulnerabilities at scale. You'll embed with customers to understand their security challenges, build custom integrations on top of depthfirst's platform, and partner closely with our product team to generalize solutions. This role combines hands-on engineering with deep customer collaboration—you'll shape both how customers use depthfirst and how our product evolves. You're excited about this role because you will… - Embed with enterprise customers to deploy depthfirst's security AI agents into production environments - Build deep relationships with security teams, becoming a trusted advisor who understands their challenges - Translate customer problems into solutions: build custom integrations, data pipelines, and workflows that connect depthfirst with existing security tools - Bridge the gap between customers and product—identify patterns across deployments and collaborate with product to turn one-off solutions into platform capabilities - Communicate clearly with diverse stakeholders, from security engineers to CISOs - Own end-to-end technical delivery: from scoping to implementation and optimization - Travel to customer sites as needed to drive successful outcomes ## Qualifications - 3+ years of software engineering experience or relevant expertise - Excellent communication skills and genuine interest in working closely with customers to solve their problems - Experience in application security, penetration testing, or security research - Experience bridging customer needs and product capabilities, with a track record of collaborating with product teams to generalize solutions - Experience with security tooling, vulnerability management, or security-focused engineering - Proficiency in Python and experience building integrations, APIs, and data pipelines - Strong problem-solving skills with a bias toward action - Excitement about AI and security - Based in or willing to relocate to San Francisco Bonus Points For - Experience with LLMs, AI agents, or AI platforms - Familiarity with enterprise security infrastructure (SIEM, SOAR, vulnerability management platforms) - Prior experience as a solutions engineer, security engineer, or forward deployed engineer - Open source contributions or experience with large codebases ## What We Offer - Competitive salary with meaningful equity - Health, vision, and dental insurance - Office lunch and dinner (when working from our SF office) - Direct impact on customer success and product direction - The opportunity to work at the cutting edge of AI and security depthfirst is an equal opportunity employer and does not discriminate on the basis of race, gender, sexual orientation, gender identity/expression, national origin, disability, age, genetic information, veteran status, marital status, pregnancy or related condition, or any other basis protected by law. To all recruitment agencies: depthfirst does not accept agency resumes. Please do not forward resumes to depthfirst employees. depthfirst is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with the Company. ## About DepthFirst ## Company Overview - **One-liner**: Autonomous security platform that uses AI to continuously find, validate, and fix exploitable vulnerabilities across code, infrastructure, dependencies, and runtime environments. - **Entity Type**: Private (Series B, $80M total funding) - **Headquarters**: San Francisco, California, United States - **Founded**: Not publicly available - **Founders**: Qasim Mithani, Daniele Perito, Andrea Michi ## Core Business - **Primary industry**: Cybersecurity (AI-native autonomous security) - **Target customers**: B2B, Enterprise (developers, security teams, CISOs) - **Mission or purpose statement**: "Secure the world’s most important software." ## Products & Services - **Agentic Pentesting**: Autonomous penetration testing that runs dynamic exploits against running applications to confirm real attack paths. - **Supply Chain Security**: Traces risk through full dependency trees and surfaces only vulnerabilities with a real execution path. - **Secrets & Sensitive Data**: Detects and validates credentials across codebase, CI/CD pipelines, and runtime environments. - **Code Security**: Finds vulnerabilities by tracing business logic, data flows, and cross-service interactions across the codebase. - **Dependency Firewall**: Detects and blocks malicious behavior before it spreads in the environment. - **Fix & Verify**: Generates merge-ready pull requests for every confirmed vulnerability, then replays the attack post-fix to ensure the vulnerability is truly resolved. ## Market Standing - **Valuation**: Not disclosed (private company) - **Key Metric**: Total funding $80M (Series B announced March 2026, led by Meritech Capital Partners; Series A with 12 investors) - **Notable Investors/Partners**: Meritech Capital Partners (lead Series B), plus 12 Series A investors. Backed by leading investors in AI, security, and software. - **Growth Signals**: 33 employees (366.7% YoY growth); 11 active job postings; claims 8x more true positives and 95% fewer false positives vs. leading tools; 90% of fixes accepted by developers; $5M in platform credits offered to open source maintainers via the Open Defense Initiative. ## Competitive Advantages - **AI-native context-aware reasoning** – The platform understands code, business logic, and infrastructure to find complex vulnerabilities (including business logic flaws and chained exploits) that siloed tools miss. - **Extremely low false positives and high fix acceptance** – 95% false positive reduction and 90% developer-accepted fixes create trust and productivity. - **Founding team** – Built security at Cash App/Faire, infrastructure at AWS/Databricks, and AI research at Google DeepMind (contributions to Gemini, AlphaDev, Nature publications). - **Continuous autonomous verification** – After each fix, the same attack is replayed in the running application; vulnerabilities are only closed when exploitation fails, not when code changes. ## Strategic Focus - Advancing AI agents for security through reinforcement learning (training vulnerability discovery agents, e.g., dfs-mini1 model). - Scaling enterprise adoption and expanding the Open Defense Initiative to secure widely deployed open source projects. - Building a research-driven applied AI lab focused on software security. ## Why Work Here - **Culture**: Positioned as an "applied AI lab" at the frontier of security and AI research. Team members come from top companies like Databricks, Meta, Google DeepMind, Faire, and Notion. - **Work policy**: On-site in San Francisco (multiple offices, including 250 Montgomery St and 1 Sutter St). - **Open roles**: 11 positions across Engineering (Backend, Product, Security, Research), Sales (Account Executive, SDR, Solutions Engineer), Product Design, and Business Operations. - **Notable perks**: Not explicitly detailed but typical for well-funded Series B startups; equity, competitive compensation, and the chance to work on cutting-edge autonomous security in a rapidly growing team. ## Sources 1. [depthfirst.com](https://depthfirst.com/) 2. [jobs.ashbyhq.com/depthfirst](https://jobs.ashbyhq.com/depthfirst) 3. [depthfirst.com/about](https://depthfirst.com/about) 4. [linkedin.com/company/depthfirst](https://www.linkedin.com/company/depthfirst) 5. [builtin.com/company/depthfirst](https://builtin.com/company/depthfirst) ## Other roles at DepthFirst - [Recruiting Coordinator](https://feeny.ai/job/recruiting-coordinator-depthfirst-san-francisco-5cyt00c1955d) — San Francisco, CA - [Technical Account Manager](https://feeny.ai/job/technical-account-manager-depthfirst-san-francisco-q9z1adhzcasb) — San Francisco, CA - [Analytics & GTM Operations Lead](https://feeny.ai/job/analytics-gtm-operations-lead-depthfirst-san-francisco-m2bpyhgeyqyh) — San Francisco, CA - [Recruiter](https://feeny.ai/job/recruiter-depthfirst-san-francisco-nctmw46zw084) — San Francisco, CA - [Product Marketing Lead](https://feeny.ai/job/product-marketing-lead-depthfirst-san-francisco-hyzqtxyagt3g) — San Francisco, CA - [Chief of Staff, CEO](https://feeny.ai/job/chief-of-staff-ceo-depthfirst-san-francisco-mvtyx5wjnqtx) — San Francisco, CA - [Product Manager](https://feeny.ai/job/product-manager-depthfirst-san-francisco-mhm9q7m349mm) — San Francisco, CA - [Sales Development Representative](https://feeny.ai/job/sales-development-representative-depthfirst-san-francisco-2bmyvnhjc5t1) — San Francisco, CA - [Solutions Engineer](https://feeny.ai/job/solutions-engineer-depthfirst-san-francisco-67h8ve7dk5qx) — San Francisco, CA - [Forward-Deployed Security Engineer](https://feeny.ai/job/forward-deployed-security-engineer-depthfirst-san-francisco-byz7vsnkc69t) — San Francisco, CA