
XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first…

XBOW brings AI to offensive security, augmenting the work of bug hunters and security researchers. It autonomously finds, exploits and reports vulnerabilities in web applications. It is the first…
What they do: Autonomous AI penetration testing platform that discovers, validates, exploits, and reports web-app vulnerabilities
Traction: Claims 1,092+ autonomously discovered real vulnerabilities and passed 75% of web security benchmarks with zero human intervention
Team: Founded by Oege de Moor with engineers from GitHub Copilot/Advanced Security and security leaders
Employees: 34
Recent funding: Series C with a $35M extension reported in 2026 (Series C reported at $120M prior to extension)
Offensive application security / penetration testing for web applications
Computer and Network Security
$75M
Reported Series B announced in June 2025
$120M
Reported Series C prior to an extension
$35M
Extension led by strategic investors including Accenture Ventures, DNX Ventures, Liberty Global Tech Ventures, NVentures, Samsung Ventures, and SentinelOne Ventures
“Includes strategic corporate investors (Accenture Ventures, Samsung Ventures, SentinelOne Ventures, NVentures) alongside traditional VCs (Sequoia Capital, DFJ Growth, Northzone)”
| Company |
|---|
About XBOW Build the future of offensive security with XBOW. Attackers are already using AI to move faster than defenders can react—we’re creating the platform that puts security ahead in the arms race. Our AI-powered system autonomously discovers, validates, and even exploits vulnerabilities, giving organizations proof-backed results in hours instead of weeks.
Founded by Oege de Moor, creator of GitHub Copilot, and backed by Sequoia, Altimeter, and other leading investors, XBOW is applying cutting-edge AI to one of the world’s most urgent problems. In just over a year, our AI, built by a world-class AI team and legendary security researchers — has uncovered thousands of real-world zero-days across the software billions rely on, and achieved the #1 ranking on HackerOne’s global leaderboard.
We’re a team of builders, hackers, and researchers who thrive on solving problems others think are impossible. If you want to push the boundaries of AI, reshape how security is done, and join the group defining this new era of defense — we’d love to talk.
Your Role: Site Reliability Engineer (SRE), Automation, and Incident Response In this role, daily work centers on keeping XBOW’s production systems stable, observable, and resilient as the product scales. You’d be building and maintaining automated reliability tooling, covering monitoring, alerting, and self healing; while defining and tracking service level goals for both production and development environments.
The role involves close collaboration with infrastructure and feature teams to manage cloud systems through IaC, review architectural changes for reliability and capacity impact, and respond to incidents during local working hours as part of a “follow the sun model.”
When issues occur, you’d lead or contribute to root-cause investigations, analyze incident trends across the organization, and turn those insights into improvements that reduce future risk. You’d also help maintain internal and customer-facing status dashboards that clearly communicate system health and uptime.
What You Will Do
Essential Skills and qualifications
Advantageous
What We Offer
What Else You Should Know
We aren't focused on seniority titles at XBOW—so if you’re worried about “leveling,” don’t be. We care a lot more about mission fit, capability, and impact than what’s on your LinkedIn headline.
We believe in people who are driven by curiosity and a willingness to learn. Even if you don't check every box, we encourage you to apply if you're excited about the role and our mission.
Your next opportunity is in here somewhere. Sign up to explore 70,000+ startups and their open roles. No spam. No gamification. Just jobs.
70,000+
Startups
82,000+
Open Roles
4,700+
New This Week
Automation of site reliability infrastructure, monitoring, and self-healing systems.
Definition and ownership of Service Level Objectives for production and development deployments.
Infrastructure-as-code for production and development systems, in collaboration with the infrastructure engineering team.
Incident response:
Responding to in-hours alerts (we run a follow-the-sun model to avoid out-of-hours paging)
Conducting RCAs in collaboration with the feature teams
Building resilience to prevent future outages.
Incident analysis: Organization-wide analysis of incident cause, frequency, and severity, to guide prioritization of future changes.
Design reviews for architectural changes: reviewing for scalability, reliability, and capacity planning.
Public and internal status and uptime dashboards.