Full-Time

Software Engineer 1

RunSybil

RunSybil

11-50 employees

AI-native autonomous penetration testing platform

Compensation Overview

$135k - $165k/yr

+ Equity

New York, NY, USA

Hybrid

Hybrid work in New York City.

Category
Software Engineering (1)
Required Skills
LLM
Python
React.js
Data Structures & Algorithms
TypeScript

Get referred to RunSybil

See people who can refer or advise you

Requirements
  • Strong Python fundamentals and real comfort with data structures are required; the candidate should write clean, working code and explain every line.
  • Evidence of shipping software in any setting, including internships, team or class projects, research, or personal projects, is required.
  • Hands-on experience coding with large language models and judgment about when to use them, how to validate their output, and when to write the code directly are required.
  • Initiative in taking on work beyond the assignment, fixing unowned problems, or independently learning what the work requires is expected.
  • Fast, honest communication about what is known, unknown, and blocked is required.
  • Coachability, including taking a hint, acting on it, and carrying the lesson forward, is required.
Responsibilities
  • Ship customer-facing features end to end, from the first commit through production, with close review and support from senior engineers.
  • Build and extend the agentic systems behind Sybil, working primarily in Python with TypeScript and React across the stack.
  • Use large language models as a core part of the workflow by prompting, evaluating generated code, and building tooling that makes the team faster.
  • Own small projects, including scoping the problem, proposing the approach, and seeing the work through to completion.
  • Debug real issues in a production system that customers rely on and learn how long-running agentic workloads behave in production.
  • Contribute to technical design discussions and code reviews and raise better approaches when identified.
  • Learn offensive security on the job from the team.
Desired Qualifications
  • Familiarity with modern JavaScript and React is a plus.

RunSybil builds AI-native security tooling that continuously tests live systems. Its flagship product, the Sybil AI agent, performs autonomous black-box penetration testing against applications and infrastructure by interacting with real interfaces rather than relying on static code analysis. Sybil reasons like a hacker, chaining small weaknesses to uncover privilege escalations or cross-tenant data access, and it automatically documents findings for fast remediation. Unlike traditional scanners, it operates without human input and provides security feedback on every pull request, helping teams reduce false positives and move away from infrequent bug bounty programs. The company targets a subscription-based model for startups and large enterprises, including names like Cursor, Notion, and Turbopuffer, and raised funding to scale R&D and go-to-market efforts. Its goal is to automate hacker-like intuition to continuously improve an organization’s security posture.

Company Size

11-50

Company Stage

Early VC

Total Funding

$40M

Headquarters

San Francisco, California

Founded

2023

Get referred to RunSybil

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • RunSybil raised $40 million in March 2026 from Khosla, Anthology Fund, and Menlo.
  • Customers include Cursor, Notion, Turbopuffer, Baseten, and Thinking Machines Lab.
  • RunSybil says early customers cut false positives over 90% and found critical vulnerabilities.

What critics are saying

  • Palo Alto Networks, Microsoft, and scanner vendors bundle similar testing into existing platforms.
  • A public customer list with only five startups leaves enterprise revenue concentration fragile.
  • Code-review agents from Anthropic and OpenAI seize category ownership by 2027.

What makes RunSybil unique

  • Sybil performs black-box, autonomous penetration testing on live systems without source-code access.
  • Founders Ari Herbert-Voss and Vlad Ionescu combine OpenAI and Meta offensive-security pedigree.
  • RunSybil chains vulnerabilities across APIs, cloud, and infrastructure, catching commit-time issues scanners miss.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Remote Work Options

Hybrid Work Options

Growth & Insights and Company News

Headcount

6 month growth

4%

1 year growth

0%

2 year growth

-24%
SiliconANGLE Media
Mar 19th, 2026
RunSybil raises $40M to automate offensive security with AI agents

RunSybil raises $40M to automate offensive security with AI agents - SiliconANGLE

RootData
Mar 18th, 2026
AI cybersecurity startup RunSybil raises $40M led by Khosla Ventures

AI cybersecurity startup RunSybil has raised $40 million in a funding round led by Khosla Ventures, with participation from S32, Anthropic's Anthology Fund, Menlo Ventures, Conviction and Elad Gil. Angel investors include Nikesh Arora, Amit Agarwal, Jeff Dean and executives from OpenAI, Palo Alto Networks, Stripe and Google. Founded in 2023 by Ari Herbert-Voss, OpenAI's first security researcher, and Vlad Ionescu, former head of offensive security red team at Meta, RunSybil has developed Sybil, an AI agent that continuously performs automated penetration testing on live applications. The system discovers, exploits and documents security vulnerabilities without human intervention. RunSybil's clients include Cursor, Turbopuffer, Notion, Baseten and Thinking Machines Lab, alongside several large enterprises.

Fortune
Mar 18th, 2026
Exclusive: AI cybersecurity startup RunSybil, founded by OpenAI's first security hire, raises $40 million led by Khosla Ventures.

Exclusive: AI cybersecurity startup RunSybil, founded by OpenAI's first security hire, raises $40 million led by Khosla Ventures. RunSybil, an AI cybersecurity startup that uses AI agents to automatically hack company software to find security weaknesses, has secured $40 million in venture capital funding. The round was led by Khosla Ventures, with participation from S32, the Anthology Fund from Anthropic and Menlo Ventures, Conviction and Elad Gil, along with angel investors including Nikesh Arora, Amit Agarwal, Jeff Dean, and other founders and leaders from companies including OpenAI, Palo Alto Networks, Stripe and Google. The company did not disclose the valuation it achieved in the new funding round. The company's AI agent, Sybil, conducts continuous autonomous penetration tests against live applications - finding, exploiting and documenting real security vulnerabilities without humans in the loop. That's different from other security tools currently making headlines, such as Claude Code Security, which analyzes source code in applications for known vulnerabilities before it is deployed. RunSybil instead tests software that is already running, probing live systems the way a hacker would - by exploring systems, chaining vulnerabilities together and testing authentication boundaries to find paths to sensitive data. Automating 'ethical hacking' Companies have long relied on a mix of penetration tests - where outside security experts, or "ethical hackers," try to break into their systems; bug bounty programs that reward independent hackers for reporting flaws; and internal "red teams" that simulate real cyberattacks. RunSybil says its AI system can automate much of that work, continuously probing applications for vulnerabilities as new code is deployed. RunSybil argues this kind of automation is becoming necessary as AI reshapes how companies operate. Procurement, legal, finance, engineering and operations are all being rebuilt with AI - including the growing use of AI agents. Yet security testing is still often treated as a discrete, scheduled event managed by a separate team on its own timeline. That mismatch can be especially challenging for highly regulated industries such as finance, insurance and health care, which face strict legal and audit requirements around cybersecurity. RunSybil was co-founded in 2023 by Ari Herbert-Voss, who joined OpenAI as its first security research hire in 2019, and Vlad Ionescu, who previously led offensive security red teams at Meta. Together, they say they represent a rare intersection: people who understand how to build frontier AI systems and how to hack into complex software. "We check every box that needs to be checked - for auditors, regulators and compliance teams," Herbert-Voss said. But the real work, he said is transforming where, when and how customers discover and fix security issues: "Not as a project, but as a permanent capability embedded in how they build." 'On the edge' of the AI security frontier. Vinod Khosla, who made an early bet on OpenAI in 2019 and often invests in companies he considers to be on the technological frontier, told Fortune that "what it takes to add security and penetration testing to the AI world is definitely frontier - RunSybil is on the edge." There is currently little competition in this part of the offensive security market, he said, though security incumbents such as Palo Alto Networks may eventually move into the space. Paid Content For now, "nobody's really knowledgeable about it except individuals like [Herbert-Voss]," he said, adding that he has long been concerned about AI's cyber capabilities falling into the hands of adversaries such as China. "We invest in founders who tackle large, unsolved problems with technically ambitious solutions," he added. "[Herbert-Voss and Ionescu] are building exactly the kind of platform security teams will need as software complexity and AI-driven development accelerate." Herbert-Voss has long been steeped in both hacking and AI. Growing up in a mostly Mormon community in Utah, he said he was drawn to the online hacker scene in middle and high school but pivoted away after friends "started getting arrested." While pursuing a Ph.D. at Harvard University studying machine learning and ways to make algorithms more efficient, he first heard about OpenAI. He dropped out of Harvard, he said, after becoming convinced that the rapid scaling of AI models - training larger systems with more data and computing power - would unlock powerful new capabilities. Evolving cyber capabilities with LLMs. "Once OpenAI dropped GPT-2, I said wow, this changes everything about the economics of what it would take to run a cyber campaign," he explained. He sent a couple of hacker demos to OpenAI CEO Sam Altman and Jack Clark, then-head of policy at OpenAI who went on to co-found Anthropic. Both of them expressed their concerns about the potential misuse of LLMs and asked Herbert-Voss to come on to do security research. But by 2022, Herbert-Voss said he also began to see how quickly offensive cyber capabilities could evolve once powerful language models became widely available, including to malicious actors. Those same advances, he said, could dramatically expand cyber threats. That led to Herbert-Voss's decision to leave OpenAI and start RunSybil as a research project. RunSybil currently works with startups including Cursor, Turbopuffer, Notion, Baseten, and Thinking Machines Lab. The company says it also works with several major financial institutions and Fortune 500 companies, though it declined to name those customers. Herbert-Voss said that customers have already reported finding critical vulnerabilities that had gone undetected using traditional methods.