An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Parameter builds AI agents that perform autonomous security testing on production apps and cloud environments. The role is generalist, moving between agent capability, the web app, and the reporting pipeline to ship features quickly.
You will own the web application surface, from findings dashboard to remediation workflows, and build interfaces for replayable attack traces and evidence chains. Onsite in San Francisco.
Parameter builds AI agents that do offensive security work. Our agents run autonomous penetration tests against production applications and cloud environments, finding IDORs, broken access control, XSS, and infrastructure misconfigurations that scanners miss and that human pentest firms only look for once or twice a year.
We are not a theoretical security company. Our team has responsibly disclosed real, high-severity vulnerabilities to well-known technology companies, and our findings are the front door to most of our customer relationships.
This is the generalist version of the job. There is no work stream attached to it: you go where the gap is. Some weeks that's agent capability, some weeks it's the web application our customers read findings in, some weeks it's the unglamorous pipeline between a finished run and a report that lands in someone's inbox.
We hire this role because the constraint on a small team is rarely a specialist. It's someone who will pick up whatever is between us and a shipped thing and not need to be told twice.
What you'll do
What we're looking for
Interview process
Stack
TypeScript, React, Next.js, Tailwind, GCP, Linear, Graphite
We move quickly. Our target is an offer within two weeks of first contact. Small team, high trust, extremely fast. If you want to see your work in front of customers within days, this is that.
This role is onsite in San Francisco. You must be authorized to work in the US; we are not able to sponsor visas at this time.