
XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first…

XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first…
What they do: AI-powered autonomous offensive security platform that finds, exploits, and validates web-app vulnerabilities
HQ: Seattle, Washington
Employees: 34
Funding: $117M total (including $75M Series B)
Founded: 2024 (public product announcements in 2024)
Web application security / offensive security / automated penetration testing
2024
Computer and Network Security
$20M
$75M
Series B increased total funding to $117M according to company blog
“Investors include Sequoia Capital, Altimeter Capital, and angel/co-investor Nat Friedman”
| Company |
|---|
About XBOW Build the future of offensive security with XBOW. Attackers are already using AI to move faster than defenders can react—we’re creating the platform that puts security ahead in the arms race. Our AI-powered system autonomously discovers, validates, and even exploits vulnerabilities, giving organizations proof-backed results in hours instead of weeks.
Founded by Oege de Moor, creator of GitHub Copilot, and backed by Sequoia, Altimeter, and other leading investors, XBOW is applying cutting-edge AI to one of the world’s most urgent problems. In just over a year, our AI, built by a world-class AI team and legendary security researchers — has uncovered thousands of real-world zero-days across the software billions rely on, and achieved the #1 ranking on HackerOne’s global leaderboard.
We’re a team of builders, hackers, and researchers who thrive on solving problems others think are impossible. If you want to push the boundaries of AI, reshape how security is done, and join the group defining this new era of defense — we’d love to talk.
Your Role: Site Reliability Engineer (SRE), Automation, and Incident Response In this role, daily work centers on keeping XBOW’s production systems stable, observable, and resilient as the product scales. You’d be building and maintaining automated reliability tooling, covering monitoring, alerting, and self healing; while defining and tracking service level goals for both production and development environments.
The role involves close collaboration with infrastructure and feature teams to manage cloud systems through IaC, review architectural changes for reliability and capacity impact, and respond to incidents during local working hours as part of a “follow the sun model.”
When issues occur, you’d lead or contribute to root-cause investigations, analyze incident trends across the organization, and turn those insights into improvements that reduce future risk. You’d also help maintain internal and customer-facing status dashboards that clearly communicate system health and uptime.
What You Will Do
Essential Skills and qualifications
Advantageous
What We Offer
What Else You Should Know
We aren't focused on seniority titles at XBOW—so if you’re worried about “leveling,” don’t be. We care a lot more about mission fit, capability, and impact than what’s on your LinkedIn headline.
We believe in people who are driven by curiosity and a willingness to learn. Even if you don't check every box, we encourage you to apply if you're excited about the role and our mission.
Your next opportunity is in here somewhere. Sign up to explore 52,000+ startups and their open roles. No spam. No gamification. Just jobs.
52,000+
Startups
58,000+
Open Roles
2,300+
New This Week
Automation of site reliability infrastructure, monitoring, and self-healing systems.
Definition and ownership of Service Level Objectives for production and development deployments.
Infrastructure-as-code for production and development systems, in collaboration with the infrastructure engineering team.
Incident response:
Responding to in-hours alerts (we run a follow-the-sun model to avoid out-of-hours paging)
Conducting RCAs in collaboration with the feature teams
Building resilience to prevent future outages.
Incident analysis: Organization-wide analysis of incident cause, frequency, and severity, to guide prioritization of future changes.
Design reviews for architectural changes: reviewing for scalability, reliability, and capacity planning.
Public and internal status and uptime dashboards.