SubImage (YC W25) 正在旧金山招聘创始工程师
SubImage (YC W25) Is Hiring a Founding Engineer in SF

原始链接: https://www.ycombinator.com/companies/subimage/jobs/NCTFgKK-founding-engineer

SubImage 是一家获得 YC 支持的种子轮网络安全初创公司。我们利用图论技术绘制基础设施,帮助企业识别并修复漏洞。我们的平台基于 CNCF 开源项目 *Cartography* 构建,目前已获得超过 70 家机构的信赖,用于可视化复杂的云环境。 我们的团队由四人组成,处于高速增长阶段。创始成员均来自 Lyft、Anthropic 和美国国家安全局(NSA)。我们正在攻克安全领域的“圣杯”难题,包括 AI 驱动的漏洞语境化分析、近乎实时的攻击路径分析,以及自动化安全修复。我们的技术栈包括 Neo4j、Python (FastAPI)、Svelte 和定制的 WebGL 图形渲染器,并通过 MCP 服务器与 AI 智能体集成。 我们正在寻找渴望成长且具备主人翁精神的工程师,要求拥有 3 年以上分布式系统和云技术经验。申请人必须常驻旧金山湾区,并愿意每周五天在办公室工作。如果你热衷于解决棘手的系统问题,并希望从零开始构建一个基础性的安全平台,欢迎加入我们。我们提供具有竞争力的福利待遇,包括 401k 匹配、全面的医疗保险,以及以快速执行和深远影响力为核心的企业文化。

Hacker News 最新 | 过往 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 SubImage (YC W25) 正在旧金山招聘创始工程师 (ycombinator.com) 29 分钟前 | 隐藏 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请 YC | 联系 搜索:
相关文章

原文

SubImage maps infrastructure the way an attacker does so security teams at scale-ups and enterprises can find and fix problems. We’re built on Cartography, the open source tool our founders helped create at Lyft that’s now a CNCF project, adopted at over 70 companies.

We are a seed stage company (a mighty team of 4!) but are growing rapidly - our customers are companies and organizations that your parents have heard of. We need engineering help to meet the demand! This is your chance to get in on the ground floor of something big. Or at least, figure out very quickly that this won’t work (it’s startup life; just being honest about it).

Novel engineering problems you’ll work on

We’re seeking the holy grail in multiple security challenges.

  • Can we triage and contextualize security vulnerabilities? This problem goes deep:
    • Are the vulns on internet-facing assets? Via which active services? What is the full path?
    • Are the vulnerable functions truly reachable from a code perspective?
    • Are there any compensating controls at play that make the vuln invalid?
    • Once exploited, does the vuln grant access to sensitive data? Via what providers, and via how many hops?
  • Any agent can generate code now. How can we prove that the security fixes our agent proposes will not break anything?
  • How do we build a near-real time, self-updating map of our environment so that we can see and stop attacks as they happen?
  • How do we teach an agent to answer questions about our graph very quickly, while making sure that it has just the context that it needs, without making mistakes?
  • How do we correctly determine the owner of a given resource based on environment heuristics like actions, tags, logs, files?
  • How do we reliably and sustainably track and manage the state of compliance processes like vulnerability management?
  • How might we implement “time travel” in our knowledge graph so that we can replay an attack as it happened?

If these sorts of challenges sound inspiring, this is our life’s work, and this is the job for you.

Who we’re looking for

  • 3+ years experience at high growth companies. We are looking for fast trajectory. You are curious and hungry. 
  • Strong experience in distributed systems and cloud tech.
  • You are based in the SF Bay Area and want to work in-person, in-office 5 days a week.
  • Strong sense of ownership. You care deeply about delivering a solution end-to-end.
  • You demonstrate strong first-principles, systems thinking.
  • You aren’t afraid of implementing gnarly business logic to make the lives of jaded security engineers easier. Ideally you can do this in a maintainable and elegant way.

Nice to have

  • Knowledge of cloud-native infra e.g. Kubernetes.
  • Information security knowledge and interest.

Our stack

  • Cartography does the ingestion. You’ll be shipping code that runs at over 70 companies, not just ours.
  • Neo4j holds the graph.
  • Python backend with FastAPI.
  • Svelte frontend with a custom homegrown cool-as-hell WebGL graph renderer.
  • An MCP server that exposes the graph and everything in our platform to AI agents.
  • IaC with Terraform.

Benefits

  • Health + Vision + Dental
  • 401k match (what STARTUP does this?)

Perks

  • Gym membership
  • Lunches with team
  • Unlimited PTO

Hi! We're SubImage, a YC-backed cybersecurity startup. We use graph theory to map out customer environments, helping them find and fix vulnerabilities before they get hacked.

Our tech is built around an open source tool called Cartography that we created at Lyft and donated to the Linux Foundation. It’s used by over 70 companies - including 7 in the Fortune 100 - to make sense of complex infra across AWS, Okta, GitHub, and more.

We're a small, fast-moving team passionate about security, infra, and AI. Before starting SubImage, we've worked at places like Lyft, Anthropic, and the NSA.

联系我们 contact @ memedata.com