Startups

Founding Engineer

SubImage · San Francisco, CA, US · On-site

← All jobs
About SubImage

The Open-Core Security Graph. Backed by Y Combinator.

About the role

We are a seed stage company (a mighty team of 4!) but are growing rapidly - our customers are companies and organizations that your parents have heard of. We need engineering help to meet the demand! This is your chance to get in on the ground floor of something big. Or at least, figure out very quickly that this won’t work (it’s startup life; just being honest about it). We’re seeking the holy grail in multiple security challenges.

What they're looking for

  • 3+ years experience at high growth companies. We are looking for fast trajectory. You are curious and hungry
  • Strong experience in distributed systems and cloud tech
  • You are based in the SF Bay Area and want to work in-person, in-office 5 days a week
  • Strong sense of ownership. You care deeply about delivering a solution end-to-end
  • You demonstrate strong first-principles, systems thinking
  • You aren’t afraid of implementing gnarly business logic to make the lives of jaded security engineers easier. Ideally you can do this in a maintainable and elegant way
More about this role

SubImage maps infrastructure the way an attacker does so security teams at scale-ups and enterprises can find and fix problems. We’re built on Cartography , the open source tool our founders helped create at Lyft that’s now a CNCF project, adopted at over 70 companies.

We are a seed stage company (a mighty team of 4!) but are growing rapidly - our customers are companies and organizations that your parents have heard of. We need engineering help to meet the demand! This is your chance to get in on the ground floor of something big. Or at least, figure out very quickly that this won’t work (it’s startup life; just being honest about it).

We’re seeking the holy grail in multiple security challenges.

  • Can we triage and contextualize security vulnerabilities? This problem goes deep:

Are the vulns on internet-facing assets? Via which active services? What is the full path?

  • Are the vulnerable functions truly reachable from a code perspective?
  • Are there any compensating controls at play that make the vuln invalid?
  • Once exploited, does the vuln grant access to sensitive data? Via what providers, and via how many hops?
  • Any agent can generate code now. How can we prove that the...

Read the full posting on SubImage's site ↗

Engineering

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.