Get more replies from employers
Send a job-specific resume in minutes.
StepSecurity is hiring for a backend-focused role building Golang services that power our security platform. You will design and implement scalable systems used across the software development lifecycle.
Join a fast-moving, early-stage startup where you own problems end to end, collaborate with cloud teams, and shape the robust backend that protects OSS and CI/CD pipelines.
StepSecurity prevents, detects, and responds to software supply chain attacks by analyzing behavior across the full software development lifecycle for both developers and AI coding agents. We are building a vertical AI agent for supply chain security across three pillars: securing AI agents on developer machines, OSS package security, and CI/CD security, covering the entire agentic pipeline from dev environment to cloud.
Founded by Varun Sharma (ex-Microsoft, 21 years, led supply chain security for Azure) and Ashish Kurmi (ex-Uber, Microsoft, Plaid, 17 years), we are a 16-person team working on hard problems at the intersection of security, AI, and open source.
We are at the forefront of supply chain security research and product development. We were the first to detect several major supply chain attacks in 2025 and 2026, including the axios npm compromise and tj-actions. https://www.stepsecurity.io/newsroom
Our research is regularly cited by Bloomberg, TechCrunch, Hacker News, and Dark Reading. The US Cybersecurity and Infrastructure Security Agency (CISA) has published advisories citing StepSecurity. https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem
Beyond our enterprise customers, StepSecurity has been adopted by more than 15,000 open-source projects, including projects from Microsoft, Google, Amazon, and Datadog.
You will work on high-impact, zero-to-one problems with meaningful early-stage equity upside.