OUR PEOPLE
People who never say "it should be fine"
In security work, guessing becomes an incident. We hire for the habit of checking.
What we actually look at
-
You make findings reproducible
Finding a vulnerability is easier than writing it up so someone else can reproduce it. We ask about reproduction steps from your past work.
-
You say when you don't know
Pretending to cover something outside scope gives a client false confidence. Stating the boundary precisely is a skill.
-
You think through the fix
A report that ends at "this is risky" changes nothing. You need a remediation that survives the operational constraints.
-
You write things down
Without a record of why a structure was chosen, the same argument repeats in six months. Decision records are engineering, not paperwork.
Hiring process
Application review, a 90-minute technical interview, a take-home exercise or case review, a team interview, then offer discussion. The whole process usually completes within three weeks.
The technical interview is not a quiz. We pick one project you actually delivered and go deep on the judgement calls inside it: why you sequenced the assessment that way, what you gave up, what you would change.
The take-home exercise is your choice of assessing a deliberately vulnerable sample application or designing a small API. It is scoped to four hours, is used only for hiring, and is destroyed when the process closes.
Currently open
If nothing fits, tell us what you are interested in and we will reach out when a role opens.