Founding Engineer
Summary
Founding engineer at SubImage, a seed-stage cybersecurity startup that maps cloud infrastructure like an attacker to help security teams find and fix vulnerabilities. You'll work on graph-based security tooling end-to-end: a Python/FastAPI backend, Neo4j knowledge graph, Svelte/WebGL frontend, Terraform IaC, and AI agent integrations via an MCP server.
SubImage maps infrastructure the way an attacker does so security teams at scale-ups and enterprises can find and fix problems. We’re built on Cartography, the open source tool our founders helped create at Lyft that’s now a CNCF project, adopted at over 70 companies.
We are a seed stage company (a mighty team of 4!) but are growing rapidly - our customers are companies and organizations that your parents have heard of. We need engineering help to meet the demand! This is your chance to get in on the ground floor of something big. Or at least, figure out very quickly that this won’t work (it’s startup life; just being honest about it).
Novel engineering problems you’ll work on
We’re seeking the holy grail in multiple security challenges.
- Can we triage and contextualize security vulnerabilities? This problem goes deep:
- Are the vulns on internet-facing assets? Via which active services? What is the full path?
- Are the vulnerable functions truly reachable from a code perspective?
- Are there any compensating controls at play that make the vuln invalid?
- Once exploited, does the vuln grant access to sensitive data? Via what providers, and via how many hops?
- Any agent can generate code now. How can we prove that the security fixes our agent proposes will not break anything?
- How do we build a near-real time, self-updating map of our environment so that we can see and stop attacks as they happen?
- How do we teach an agent to answer questions about our graph very quickly, while making sure that it has just the context that it needs, without making mistakes?
- How do we correctly determine the owner of a given resource based on environment heuristics like actions, tags, logs, files?
- How do we reliably and sustainably track and manage the state of compliance processes like vulnerability management?
- How might we implement “time travel” in our knowledge graph so that we can replay an attack as it happened?
If these sorts of challenges sound inspiring, this is our life’s work, and this is the job for you.
Who we’re looking for
- 3+ years experience at high growth companies. We are looking for fast trajectory. You are curious and hungry.
- Strong experience in distributed systems and cloud tech.
- You are based in the SF Bay Area and want to work in-person, in-office 5 days a week.
- Strong sense of ownership. You care deeply about delivering a solution end-to-end.
- You demonstrate strong first-principles, systems thinking.
- You aren’t afraid of implementing gnarly business logic to make the lives of jaded security engineers easier. Ideally you can do this in a maintainable and elegant way.
Nice to have
- Knowledge of cloud-native infra e.g. Kubernetes.
- Information security knowledge and interest.
Our stack
- Cartography does the ingestion. You’ll be shipping code that runs at over 70 companies, not just ours.
- Neo4j holds the graph.
- Python backend with FastAPI.
- Svelte frontend with a custom homegrown cool-as-hell WebGL graph renderer.
- An MCP server that exposes the graph and everything in our platform to AI agents.
- IaC with Terraform.
Benefits
- Health + Vision + Dental
- 401k match (what STARTUP does this?)
Perks
- Gym membership
- Lunches with team
- Unlimited PTO
