
XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first product that passes 75% of web security benchmarks with zero human intervention.

XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first product that passes 75% of web security benchmarks with zero human intervention.
What they do: AI-powered autonomous offensive security platform that finds, exploits, and validates web-app vulnerabilities
HQ: Seattle, Washington
Employees: 34
Funding: $117M total (including $75M Series B)
Founded: 2024 (public product announcements in 2024)
| Company |
|---|
Web application security / offensive security / automated penetration testing
2024
Computer and Network Security
$20M
$75M
Series B increased total funding to $117M according to company blog
“Investors include Sequoia Capital, Altimeter Capital, and angel/co-investor Nat Friedman”
About XBOW At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.
AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead.
What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats—we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn’t just a tool; it’s a transformative force in the secure development lifecycle.
Backed by Sequoia Capital and a team that includes the creators of GitHub Copilot and GitHub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.
We’re building something that must be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.
Your Role: Information Security Analyst, GRC We’re looking for a detail-oriented, Governance, Risk & Compliance Analyst to help scale our security and trust function as we grow. In this role, you’ll play a key part in supporting customer and prospect security reviews, assessing third-party vendor risk, and continuously improving how we identify and manage risk across the business.
This is an individual contributor role with no initial people-management responsibilities. However, as the risk and compliance function matures, there is a clear opportunity for this role to grow in scope and responsibility.
You’ll work closely with Security, Engineering, Legal, Sales, and Customer teams, acting as a trusted partner in communicating our security posture and ensuring we meet customer and regulatory expectations.
What You'll Do
Who You Are
Bonus Points
What We Offer
What Else You Should Know
Location: Remote US East Coast preferred (all team members are remote but we meet regularly and you’re supported to travel to collaborate with colleagues in person)
Contract: Full-time.
We’re a security company that builds with AI at the core - so you’ll be protecting a team that moves fast, iterates aggressively, and lives in the command line. If that sounds like your kind of environment, let’s talk.
Hiring Process:
Talent Introduction
HM Interview
Security Knowledge Interview
We’d provide you some information live, and then ask you to analyze the information and provide a response from a security lens.
Final Interview as needed