11 Sep
|
StackHawk
|
Quinte West
11 Sep
StackHawk
Quinte West
Are you looking to build tools that engineers actually keep in their workflow? Do you get excited about AI agents that fix real vulnerabilities instead of writing confident nonsense about them? StackHawk builds the security layer for AI-assisted engineering.
Our platform finds exploitable vulnerabilities in running applications and APIs, then hands the proof and the fix path directly to the coding agent already sitting in the developer’s editor. Scan, fix, verify, in a loop, without a human copying findings between tabs. That product is real and shipping.
We are looking for a senior engineer to own that loop.
You will spend most of your time on agentic systems: the tool surfaces our agents call, the context they get, the loop that decides when a fix is actually verified, and the evals that tell us whether any of it got better this week. Everything you build goes to customers. Your work will be visible in the product within days, and in customer conversations within weeks.
The hard part of this work is not writing the code. It is the whiteboard argument about why the loop stopped early, the shoulder tap when an eval result looks wrong, and the twenty minutes after a customer call that turns into a design change. Design and build the find, fix, and verify loop that powers our agentic security workflows Build and own the tool layer coding agents use to reach our platform.
Do the context engineering work that makes the difference between a helpful agent and a plausible one. Build core product features and supporting services in a microservices architecture using Kotlin, Java, Rust, gRPC, Postgres, Docker, Kubernetes, and Gradle Design and build APIs for both our UI and our customers Integrate with the platforms engineers already live in: GitHub, GitLab, CI systems, IDEs,
and agent runtimes We are small enough that you will hear customer feedback firsthand and ship against it Learn more about vulnerability classes than you expected to, and get very good at explaining Remote OS Command Injection at parties 6+ years building and shipping production SaaS software ~ Deep in at least one statically typed language. Python, TypeScript, Go, or Rust experience is where our agent tooling and CLI live, so that helps immediately ~ Our core platform is Kotlin and Java.
Solid API design instincts and the tooling that goes with it ~ Obsessive about automation and automated testing You have done real context engineering.
Bonus: you have built or published MCP servers, agent skills, or custom agent integrations If your agentic experience is one weekend project and a course certificate, this is not the right role yet. If it is a system you shipped, maintained, and had to debug at 11pm, we want to talk. What we do require is curiosity about how software breaks and the discipline to care about correctness.
When something you shipped breaks, you are already looking at it You bring people to your position with logic and data, not volume You know security is a supporting function of a business, and you know the difference between binary security and security at scale No trivia and no take home that eats your weekend. Use whatever language you are strongest in. We are not screening for Kotlin syntax.
Salary plus a real equity stake in what we are building Solid benefits . Health, dental, and vision 100% covered for employees and dependents. Life insurance, AD&D;, and 401k Take what you need, plus ten paid holidays Home office equipment, good tools, and a team that is fun to build with StackHawk is seven years old with real customers and real revenue.
We are committed to equal opportunity regardless of race, color, ancestry, religion, gender, gender identity, genetic information, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, disability, or Veteran status. #
📌 Software Systems Engineering (Quinte West)
🏢 StackHawk
📍 Quinte West