Stand out for this role — generate a tailored resume and cover letter in about a minute.
Parameter ai is hiring for a full-time offensive security specialist in San Francisco, CA. You will perform hands-on testing against customer web apps, APIs, and cloud infrastructure, and translate findings into autonomous agent capabilities.
You’ll work across product, agent systems, and client engagements in a fast-moving, small team. The role emphasizes practical exploit development, responsible disclosure, and delivering clear, actionable reports to executives and engineers.
Full time • San Francisco, CA • $180K – $250K
Parameter builds AI agents that do offensive security work. Our agents run autonomous penetration tests against production applications and cloud environments, finding IDORs, broken access control, XSS, and infrastructure misconfigurations that scanners miss and that human pentest firms only look for once or twice a year.
We are not a theoretical security company. Our team has responsibly disclosed real, high-severity vulnerabilities to well-known technology companies, and our findings are the front door to most of our customer relationships.
You are the person whose expertise gets encoded into the product. You'll do real offensive work against customer environments, then turn your methodology into agent capability.
The title points at where you'll spend most of your time. Expect the rest of the week to go wherever the work is: agent systems one day, the product the next, a customer call or a report that has to go out after that. We are small enough that everyone works across every product, and we hire people who want that.
Run manual penetration tests against customer web applications, APIs, and cloud infrastructure
Translate your methodology into agent capabilities: new attack modules, detection logic, and verification steps
Validate and triage agent findings before they reach customers. You are the quality bar
Lead the technical side of customer engagements, including scoping calls and findings walkthroughs
Contribute to our vulnerability research and responsible disclosure work, which is a core part of how we go to market
3+ years of hands-on offensive security: web application pentesting, red teaming, or serious bug bounty work
Deep knowledge of web application vulnerability classes, particularly access control, authentication, and business logic flaws
Cloud security experience across AWS or GCP: IAM, misconfiguration, privilege escalation paths
You write code and build your own tooling rather than only running other people's. We're a TypeScript shop, but we care more that you build than what you've built in
Ability to write clearly for both engineers and executives. Findings that nobody understands do not get fixed
Bonus: OSCP, OSWE, published CVEs, bug bounty leaderboard placement, or conference talks
Intro call with a founder (30 minutes)
Technical deep dive on your past work (60 minutes)
Paid work trial or take-home, scoped to roughly one day
Onsite in San Francisco with the team
References and offer
We move quickly. Our target is an offer within two weeks of first contact. Small team, high trust, extremely fast. If you want to see your work in front of customers within days, this is that.
This role is onsite in San Francisco. You must be authorized to work in the US; we are not able to sponsor visas at this time.