--- title: 'Senior Security Engineer at CYBRET AI' canonical: 'https://feeny.ai/job/senior-security-engineer-cybret-ai-oslo-tht3wh9s03rr' type: 'job' last_seen: '2026-09-11' --- # Senior Security Engineer at CYBRET AI - **Company:** CYBRET AI - **Location:** Oslo, Norway - **Employment:** full-time - **Work type:** remote - **Posted:** 2026-01-12 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/cybret/df989dbc-687f-418e-95b1-63573c909d47 ## Job description Senior Security Engineer ## CYBRET AI Remote Norway and Europe preferred Full-time Early hire with equity ## About CYBRET AI CYBRET AI is building Autonomous Security Infrastructure for modern organizations operating in complex, distributed, cloud-native environments. Our ambition is to move cybersecurity away from reactive, human-dependent workflows and toward continuous, intelligent, autonomous security. We design systems that combine human judgment where it matters with fully autonomous decision-making where speed, scale, and precision are required. We make a strict distinction between automation and autonomy. CYBRET AI does not rely on static rules or predefined playbooks. Our systems understand context, reason over attack surfaces and exposure, assess real-world consequences, and take risk-based decisions. Humans are involved only when escalation is necessary. Our primary focus is Exposure and Vulnerability Management as a decision system, not a reporting layer. Instead of listing CVEs or producing noisy scan results, our platform understands real attack surfaces, realistic attack paths, business criticality, identity relationships, trust boundaries, and how modern attackers chain exposures in practice. CYBRET AI answers questions such as: - What can actually be exploited right now - What creates real risk for the organization - What actions reduce risk most effectively We are building toward Azure, AWS, and Google Cloud Marketplace launches, with cloud-agnostic design as a core principle. ## About the Role This is a senior security role with deep technical responsibility and real ownership. You will help define how exposure, risk, and exploitability are modeled, analyzed, and acted upon inside autonomous security systems. Your work directly shapes how CYBRET AI reasons about security decisions. You will work across cloud security, identity, network security, detection engineering, and security architecture, closely influencing both product logic and technical direction. ## Responsibilities Exposure and Attack Surface Analysis Design and improve how CYBRET AI models attack surfaces across cloud, identity, network, and application layers Identify real-world attack paths and exploit chains rather than theoretical vulnerabilities Vulnerability and Risk Engineering Develop risk scoring and prioritization beyond CVSS Incorporate exploitability, exposure, identity context, and business impact into decision-making Cloud and Identity Security Design and evaluate security controls across Azure, AWS, and GCP Work deeply with identity systems, permissions, service principals, and trust boundaries Define secure patterns for cloud-native and hybrid environments Detection and Security Logic Contribute to detection logic, correlation, and multi-signal reasoning Distinguish noise from real risk to support autonomous decision-making Network and Zero Trust Architecture Design and assess secure network architectures including private networking, segmentation, and zero-trust principles Evaluate exposure through public services, APIs, and infrastructure Security Research and Threat Modeling Track attacker techniques, emerging threats, and exploitation patterns Perform threat modeling and security analysis to improve product logic and coverage ## How We Work CYBRET AI operates fully remote. The team is currently based in Norway, but we hire internationally. We recruit based on merit, excellence, and intelligence. We value deep focus, curiosity, and strong ownership. You are expected to work independently and make sound decisions in both low-effort, high-impact situations and high-effort, high-impact situations. A strong shipping mindset is essential. Security work at CYBRET AI must lead to real product improvements, not just analysis. Interest in security research and state-of-the-art techniques is strongly preferred. Writing technical blogs or research content is optional but highly valued. This is an early-stage startup. The pace is high, structure evolves continuously, and impact is real. Culture and Benefits Monthly social gatherings such as weekend trips, cabin stays, and team events are covered by CYBRET AI Dedicated budget for learning, courses, and professional development Small, highly skilled, talent-dense team Ambition to scale without sacrificing quality or depth English is the primary working language The company is Norwegian, with potential future transition to a US INC structure Fully remote role with home office agreement Laptop of your choice up to 20,000 NOK Optional home office equipment Mobile subscription and home internet fully reimbursed Strict confidentiality and correct handling of sensitive information is mandatory Ability to pass background checks and applicable security clearance is required Standard insurance coverage is provided Equity and Ownership CYBRET AI offers a highly competitive and generous Employee Stock Option Program. Early hires are viewed as owners, not employees. This role includes meaningful equity and long-term upside. Investors CYBRET AI is backed by leading Nordic and European investors. Venture capital partners include Skyfall Ventures, Inception Fund, Visionaries Club, FR8 Ventures, and Wave Ventures. Angel investors include leaders associated with Silo AI, WithSecure, HoxHunt, Google Cloud, and more. ## About CYBRET AI ## Company Overview - **One-liner**: CYBRET AI builds an autonomous security platform that uses a unified knowledge graph and neurosymbolic reasoning to continuously discover, validate, and respond to real attack paths across code, cloud, identity, and APIs. - **Entity Type**: Private (early-stage, no disclosed funding rounds) - **Headquarters**: Global (remote-first; team distributed across EU and US) - **Founded**: 2025 - **Founders**: Not publicly disclosed (described as a deliberately small group of security researchers, AI engineers, and former operators) ## Core Business - **Primary industry**: Cybersecurity (autonomous application security, exposure management, runtime detection and response) - **Target customers**: Enterprise AppSec teams, CISOs, and security operations (B2B) - **Mission/purpose**: Replace noise and manual effort with continuous, evidence-based validation and machine-speed defense — “no noise, no guesswork, only proven exposures.” ## Products & Services - **Exposure Intelligence** (SaaS): Unified knowledge graph across 30+ sources (code, cloud, identity, SIEM, ITSM) to surface exploitable attack paths and rank by real-world risk. Deduplicates thousands of findings into a handful of real paths. - **Validation** (SaaS): Continuous autonomous re-attack of every deploy and config change to earn or revoke “critical” status with signed proof-of-exploit capsules (trace, privilege graph, screenshot, rollback). Compliance-grade evidence for SOC 2, PCI, HITRUST, DORA. - **Runtime Detection** (SaaS): Graph-native anomaly detection fused with UEBA and rule engines. Correlates runtime signals with known exploitable paths; agents author and execute reversible responses (contain, rotate, revert, validate) and synthesize runbooks. - **Pricing tiers**: Free (one repo, full Exposure Intelligence, community support), Pro ($990/month, up to 25 apps, attack path analysis, Slack+Jira routing), Enterprise (custom, with all three products and priority support). ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Early stage — no public revenue or funding round announced; team size under 25 people - **Notable Investors/Partners**: Not publicly listed; described as a “private research lab” with founder-led sales and early design partners - **Growth Signals**: Active hiring for seven roles across engineering, research, security, and go-to-market; live platform at app.cybret.ai; processing 1.2 million events per second; expanding into US market (SF expansion planned) ## Competitive Advantages - **Neurosymbolic reasoning engine** that traverses code, identity, cloud, and APIs the way an attacker would, rather than relying on CVSS scoring or scanner noise. - **Autonomous agent orchestration** with full reversibility and auditability — every agent action is scoped and reversible, enabling machine-speed response without risk. - **Unified knowledge graph** that correlates findings across 30+ connectors, deduplicating thousands of alerts into a handful of real, exploitable paths. - **Continuous validation** that runs on every deploy or config change, not just periodic pen tests. ## Strategic Focus - **Build a category-defining autonomous security platform** by expanding the knowledge graph, improving agent reasoning, and proving the model with enterprise design partners. - **Scale go-to-market** in both EMEA and North America with a founder-led, proof-driven sales motion. - **Maintain a small, high-leverage team** (<25 people) that owns unreasonable amounts of the product end-to-end, with deep focus and no ghost managers. ## Why Work Here - **Remote-first, async culture** with global team (EU and US); co-location when it matters, remote when it doesn’t. - **Flat structure** where each person owns a surface of the product top-to-bottom — no layers, no busywork, deep focus by default. - **Transparent compensation** (salary or OTE shared on the first call), meaningful equity, home-office stipend, and real PTO. - **Hiring process** is under two weeks from first call to offer, no whiteboard leetcode, no unpaid projects; five-step process adapted to the role. - **Work on genuinely hard problems**: neurosymbolic reasoning, agent orchestration, machine-speed defense — with a live platform and early customers already putting it to work. ## Sources 1. [cybret.ai](https://www.cybret.ai/) 2. [cybret.ai/about](https://www.cybret.ai/about) 3. [cybret.ai/careers](https://www.cybret.ai/careers) 4. [jobs.ashbyhq.com/cybret](https://jobs.ashbyhq.com/cybret) 5. [linkedin.com/company/cybret](https://se.linkedin.com/company/cybret) ## Other roles at CYBRET AI - [Founding Account Excecutive (USA)](https://feeny.ai/job/founding-account-excecutive-usa-cybret-ai-san-francisco-145sj4m9hm7x) — San Francisco, CA - [Head of Engineering](https://feeny.ai/job/head-of-engineering-cybret-ai-oslo-znvrehbgrrdx) — Oslo, Norway - [Senior Full Stack Developer](https://feeny.ai/job/senior-full-stack-developer-cybret-ai-oslo-7n458f5ypya8) — Oslo, Norway - [Senior Backend Engineer](https://feeny.ai/job/senior-backend-engineer-cybret-ai-oslo-4ahnt0nhespx) — Oslo, Norway - [Product Engineer](https://feeny.ai/job/product-engineer-cybret-ai-oslo-sdacx09z39qj) — Oslo, Norway - [Senior Cloud / Security Engineer](https://feeny.ai/job/senior-cloud-security-engineer-cybret-ai-oslo-3kre6we81tga) — Oslo, Norway - [Senior Software Engineer](https://feeny.ai/job/senior-software-engineer-cybret-ai-oslo-0eedq9evtgzv) — Oslo, Norway - [Senior AI Engineer](https://feeny.ai/job/senior-ai-engineer-cybret-ai-oslo-mazzfbhh0fec) — Oslo, Norway - [Founding Account Excecutive](https://feeny.ai/job/founding-account-excecutive-cybret-ai-oslo-myw8btf3fnzn) — Oslo, Norway - [Head of Design](https://feeny.ai/job/head-of-design-cybret-ai-oslo-j7cre6e6eafv) — Oslo, Norway