Build the future of offensive security with XBOW. Attackers are already using AI to move faster than defenders can react—we’re creating the platform that puts security ahead in the arms race. Our AI-powered system autonomously discovers, validates, and even exploits vulnerabilities, giving organizations proof-backed results in hours instead of weeks.
Founded by Oege de Moor, creator of GitHub Copilot, and backed by Sequoia, Altimeter, and other leading investors, XBOW is applying cutting-edge AI to one of the world’s most urgent problems. In just over a year, our AI, built by a world-class AI team and legendary security researchers — has uncovered thousands of real-world zero-days across the software billions rely on, and achieved the #1 ranking on HackerOne’s global leaderboard.
We’re a team of builders, hackers, and researchers who thrive on solving problems others think are impossible. If you want to push the boundaries of AI, reshape how security is done, and join the group defining this new era of defense — we’d love to talk.
Your Role: Research Engineer (backend)We’re looking for a Backend Research Engineer who’s passionate about building scalable systems and solving hard problems in ambiguous environments. In this role, you’ll design and implement the distributed infrastructure that powers our core engine. You’ll work across services written in TypeScript, Kotlin and Go (no worries if you haven’t used these languages—we care more about your fundamentals and your willingness to learn), and deploy everything on AWS.
You’ll be joining a small team of superstars that’s shipping quickly and operating with high trust. This is a role for someone who loves to own open-ended problems and figure things out—whether that’s designing fault-tolerant systems, scaling distributed architectures, or debugging hairy production issues. If you like being at the intersection of deep tech and real-world impact, you’ll feel right at home.
What you will doDesign and build distributed backend systems that scale reliably and securely
Work in TypeScript, Kotlin and Go (and pick them up quickly if you haven’t used them before)
Deploy and operate services in AWS and other cloud providers.
Own problems end-to-end—from design through deployment to production support
Navigate ambiguity and help define how we build as much as what we build
Collaborate closely with teammates across the stack, including AI researchers, Security researchers and frontend engineers
Essential:
Experience building and operating scalable, distributed systems
Comfort working in a fast-moving, early-stage environment
Strong problem-solving skills and the ability to work with incomplete information
Familiarity with AWS or similar cloud platforms
You’re comfortable working with infrastructure as code (e.g., Terraform or CDK) and see infra as part of the engineering system—not something separate from it.
Eager to learn new tools, languages, and technologies as needed
A thoughtful communicator who values clarity and simplicity
Comfort working in a fast-paced, early-stage startup environment
Advantageous:
Experience with event-driven architectures, message queues, or async workflows
Experience designing and optimizing relational databases (we use Postgres), and you know how to structure data for both performance and clarity.
Background in systems programming, networking, or performance tuning
Experience with hybrid deployments (cloud + on-prem) and know how to build resilient systems that handle the complexity of mixed environments.
Experience working in an early stage startup
Prior experience building security products or products for technical users
Compensation & Equity: Competitive salary and a generous equity package, making you a true owner of the company.
Career Growth: Shape your role, lead the function, and grow with the company as we redefine cybersecurity.
Meaningful Work: You will tackle technically complex challenges and play a pivotal role in the growth of our business, working alongside an amazing team and some of the world’s experts to shape how AI transforms cybersecurity.
Location: Remote (all team members are remote but we meet regularly and you’re supported to travel to collaborate with colleagues in person)
Contract: Full-time.
Hiring Process:
45-min introductory chat with our Head of Talent, Zac Wallis.
45 minutes with our Head of Engineering, Andy Rice.
2-3 hour technical deep dive around relevant case study.
30-min final meeting with our CEO and founder, Oege de Moor.
We aren't focused on seniority titles at XBOW—so if you’re worried about “leveling,” don’t be. We care a lot more about mission fit, capability, and impact than what’s on your LinkedIn headline.
We believe in people who are driven by curiosity and a willingness to learn. Even if you don't check every box, we encourage you to apply if you're excited about the role and our mission.