Careers
Work on the browser security problem
There are over 300,000 extensions we keep track of. Most organisations have no visibility into what they are running. We are the team fixing that.
We analyse extensions at scale - real-time network behaviour monitoring, and continuous supply chain scanning across a database of hundreds of thousands of Chrome Web Store extensions. Our analysis pipeline runs advanced agentic AI workflows with human expert verification to produce findings that are accurate enough to act on.
Our research roots go deep - the founding team includes published academic security researchers and engineers who have spent years finding vulnerabilities in browser extensions. That depth shows in the product.
The stack
Everything runs at the edge. No traditional servers, no cold starts, no infrastructure to babysit. The analysis pipeline runs separately from the customer-facing product and is designed to scale horizontally as the extension database grows.
What the engineering looks like
The discovery pipeline picks up extension updates and version changes in near real-time and feeds them into analysis automatically. The analysis runs agentic AI workflows that reason about extension behaviour across versions - detecting meaningful changes, not just permission diffs.
The fleet monitoring product gives enterprise security teams a live view of every extension across their managed devices, with configurable policy enforcement that pushes through their existing MDM. The API is public and documented, and customers build on top of it for SIEM ingestion and custom alerting workflows.
There is interesting unsolved work in detection accuracy, pipeline latency, and the scoring methodology. If that kind of problem interests you, there is plenty of it here.
Open roles
No formal listings right now. We are interested in people who are exceptional at any of the following.
Security research / threat analysis
You have found vulnerabilities in real software. You understand what malicious JavaScript looks like at the AST level, how obfuscation techniques work, and what makes a finding actionable vs. noise.
Full-stack engineering (TypeScript)
You care about performance, type safety, and clean API boundaries. You have shipped production SaaS and you are comfortable owning a feature from database schema to UI.
Security-focused sales / GTM
You understand the enterprise security buying cycle. You can run a technical proof of concept, navigate procurement, and talk credibly to both CISOs and the engineers who report to them.
Interested?
Send us a note about what you have built and what you are looking for. No recruiters, no cover letters.
Get in touch