Full-Time

Founding Engineer

Early Careers

Tracebit

Tracebit

11-50 employees

Cloud intrusion detection via canary decoys

Compensation Overview

£50k - £70k/yr

London, UK

In Person

Five days per week in the Central London office.

Bachelor's, Master's

Category
Software Engineering (1)
Required Skills
Claude
Infrastructure as Code (IaC)
Cybersecurity
C#
Terraform
DevOps

Get referred to Tracebit

See people who can refer or advise you

Requirements
  • An undergraduate or master's degree, ideally in a STEM subject such as computer science, engineering, mathematics, or physics, with demonstrated academic excellence.
  • Strong engineering fundamentals and the ability to write clean, correct code in a known programming language.
  • A genuine interest in technology and cybersecurity and an eagerness to build a career in the field.
  • Experience building side projects, contributing to open source, or participating in hackathons.
Responsibilities
  • Work face to face with both founders, the engineering team, customers, and prospects to build a product that solves real problems.
  • Work across the stack, primarily in C# on .NET Core 10, while also using Terraform and building the frontend in HTMX.
  • Apply continuous delivery, infrastructure as code, and simple, scalable, powerful architecture practices.
  • Ship product changes daily for demanding customers in a small team with limited bureaucracy.
  • Use AI-assisted development tools such as Claude and Codex.
  • Participate in daily standups, customer feedback, analysis, and planning for longer-term product work.
  • Work primarily from the Central London office five days per week, with occasional flexibility on a case-by-case basis.

Tracebit provides cloud security by offering a Software-as-a-Service intrusion detection platform. It creates and manages canary resources—decoy components placed within a client’s cloud infrastructure—that attract and trap attackers, delivering early warnings of unauthorized activity. The service operates as a SaaS, handling the deployment and ongoing management of these decoys and analyzing signals from them to detect breaches in real time. Unlike traditional security tools that rely on monitoring existing assets, Tracebit’s approach uses active decoys to improve visibility into attacker techniques and quickly alert security teams. The company's goal is to help organizations strengthen their cloud security posture by providing proactive threat detection and faster breach awareness.

Company Size

11-50

Company Stage

Series A

Total Funding

$25M

Headquarters

London, United Kingdom

Founded

2022

Get referred to Tracebit

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Tracebit raised $20 million on March 17, 2026, totaling $25 million.
  • July 2026 context bombing cut admin escalation from 57 percent to 5 percent.
  • New York expansion and Community Edition widen distribution while lowering enterprise adoption friction.

What critics are saying

  • Thinkst Canary, Acalvio, and Microsoft Defender compress Tracebit into feature competition.
  • Context bombing depends on AI attackers reading decoys; non-LLM intruders ignore it entirely.
  • If AWS, Microsoft, or Google ship native deception, Tracebit's standalone SaaS loses urgency.

What makes Tracebit unique

  • Tracebit turns cloud decoys into automated detection across AWS, Azure, GCP, Kubernetes, and CI/CD.
  • March 2026 Series A launched Perimeter Canaries, Deceptive Artifacts, and GCP support.
  • Tracebit claims millions of canaries deployed for Riot Games, Snyk, Docker, and Synthesia.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Relocation Assistance

Growth & Insights and Company News

Headcount

6 month growth

7%

1 year growth

-4%

2 year growth

-6%
NOW LET US
Jul 18th, 2026
Prompt injection attacks are thwarting AI hacking agents.

Prompt injection attacks are thwarting AI hacking agents. Defenders are turning the tables on AI hacking agents by using prompt injection as a defense mechanism. Dubbed "context bombing," the technique plants forbidden commands in decoy data to trigger safety guardrails and shut down attacking LLMs. Prompt injections, the malicious commands attackers embed into content to entice large language models to follow them, have been attackers' go-to tool for turning AI platforms against their users. A well-phrased command sneaked into an email or calendar invitation is often all it takes to cause the LLM to exfiltrate sensitive data or follow other harmful actions. Machine Learning & Artificial Intelligence Now, defenders are embracing the prompt injection, too. Researchers from Tracebit on Monday said they found that placing prompt injections alongside passwords, cryptographic keys, and other secrets stored on Amazon Web Services was often all that was needed to shut down attacks from AI hacking agents. The prompts direct the attacking LLM to perform an action forbidden by its guardrails, the safety barriers AI developers erect to prevent it from taking harmful actions. The LLM responds by shutting down. Examples are a prompt that orders the LLM to provide steps for developing inhalable Anthrax spores, or, in the case of LLMs from Chinese developers, make references to the iconic Tank Man from the 1989 Tiananmen Square massacre. Once the LLM encounters these forbidden commands, it no longer follows its existing commands. The researchers have named the technique context bombing. "Ultimately we're triggering a refusal mechanism in the context," said Andy Smith, cofounder and CEO of Tracebit, when explaining the name choice. "What we're trying to capture is the fact that this does have a strong, sharp effect and one that can be difficult for the agents to come back from. Once they get that into their context they are going to keep refusing." Tracebit says initial testing suggests context bombing has great potential. They tested Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6 by giving them instructions to perform routine developer tasks that led the models to enumerate resources and stumble onto the planted strings. They ran the models inside a simulated AWS environment. "Across five leading models and 152 attack runs, planting one of these strings in a decoy secret cut the rate at which agents seized full account admin from 57 percent to 5 percent, and complete compromise (where they also left themselves a persistent foothold) from 36 percent to 1 percent," Monday's post reported. "The most capable agent in our tests, Opus 4.8, went from achieving admin access in 93 percent of runs to failing every single time when confronted with a context bomb." Averaged across the five models and the 152 runs, the results included: * Admin privilege escalation fell from 57 percent to 5 percent * Admin escalation with a persistent foothold fell from 36 percent to 1 percent * Runs achieving any attack path fell from 91 percent to 15 percent * On average, a run went from completing 1.53 paths successfully to just 0.16 * No runs were able to complete an attack path without at least triggering a canary detection The research builds on findings from May, when Tracebit introduced a method for defenders to receive warnings when their infrastructure is under attack from AI agentic adversaries. It comes in the form of AWS resources that look like ones serving a legitimate purpose but, in fact, aren't used at all. They sit alongside the resources that are used. When they are probed by agentic AI, defenders receive an alert. Like "canaries" taken into coal mines, these resources allow defenders to detect a threat before it has fatal consequences. The Tracebit Canariens, on average, alerted the start of an attack within eight minutes. The motivation for developing context bombing came out of the need for something that stopped attacks, rather than simply warning of them. In the experiments, the agentic models needed, on average, 14 minutes to escalate to administrative control. The six-minute heads-up was cutting things uncomfortably close. Attackers have already been using prompt injections to close down AI defenses inside networks. Researchers from security firm Socket, for instance, last month unearthed an LLM agent that directed target LLMs to provide instructions for building a nuclear bomb or biological weapons. The injections were designed to shut down AI-assisted malware analysis. Researchers from Check Point discovered a similar malware prototype. Context bombing appears to be the first known case where defenders turned the tables. "I've not seen anyone else use this technique as a defense, to the best of my knowledge," Earlence Fernandes, a UC San Diego professor specializing in AI security, said in an interview. He said he had been toying with a similar approach, although in a slightly different context. "I wanted to be the first here, but I guess these guys beat me to the punch!" Machine Learning & Artificial Intelligence To date, there is no known way to solve the root cause of prompt injections. That has left developers with no option other than to construct elaborate guardrails that prevent injected prompts from forcing LLMs to go off the rails. Defenders may now find a way to use this intractable problem in their favor. Ad slot ready: 5887729102 Discover more Management Customer Relationship Management (CRM) Business Operations

London Daily News
Jul 1st, 2026
Tapestry VC launches $80m Fund III to continue backing Europe's $2 trillion Repeat Founder boom.

Tapestry VC launches $80m Fund III to continue backing Europe's $2 trillion Repeat Founder boom. Fresh off the back of being named the best VC in Europe for spotting exceptional founders first, Tapestry VC is today launching its $80 million Fund III to double its scale and deepen its focus on backing Repeat Founders across Europe and North America. At almost three times the size of the firm's previous funds, the $80M Fund III is co-anchored by a $40 million commitment from new sovereign investor British Business Bank, alongside returning institutional co-anchors Railpen - a £35B pension plan - and Molten Ventures - a £1B fund-of-fund. Notable tech leaders, such as OpenAI CFO Sarah Friar, are also joining the new fund. Tripling down on Europe. It's clear today to see the impact Europe's Repeat Founder flywheel has had on innovation, job creation and growth: European tech has minted 477 unicorns over the past eight years, of which 60% have been started by a repeat founder. Yet in 2018, when Tapestry was founded, this ecosystem was still taking shape and Tapestry was among the first to spot and lead the trend. It was the first and only institutional European fund to invest in Nothing's Seed round in 2020, before the hardware manufacturer became the unicorn it is today with $1B in revenue. Tapestry backed Hopin at Seed, before it rocketed to a $7.75B valuation; while another of its early bets, Fin AI, was acquired in June by Salesforce for $3.6B - one of the largest acquisitions of a European startup. Compounding conviction. Now, Dealroom data analysed by Tapestry shows just how impactful this conviction was. Companies built by second and third-time European founders are today worth $2.2T in combined enterprise value. These companies employ more than 2M people across 23,000 companies and globally - up an astonishing 7x from just 300,000 employees in 2018 (see figure). Across the board, repeat founders in Europe outperform - raising 45% more capital compared to first-time teams, and 23% more than the baseline. Today, 75% of startups worth over $50B globally were founded by serial entrepreneurs. With the launch of Fund III, the opening of Tapestry VC's flagship London office, and with founder Patrick Murphy relocating from San Francisco to London after a decade of investing on both sides of the Atlantic, Tapestry is sending a direct message to the ecosystem: it's poised to support the next cycle of repeat founders due to come from the rising AI company exits. Global from day one. Tapestry VC's sector-agnostic portfolio spans software, AI, cybersecurity, fintech, autonomy and deep technology at Seed and Pre-Seed. It specialises in working with founders before there's even a company or formal process in place, supporting product direction, hiring, fundraising and more. Yet while many European VCs prioritise keeping their portfolio companies rooted in Europe, Tapestry VC's partners take a deliberately transatlantic approach - backing founders with the ambition to build global companies from day one and helping them access the customers, talent and capital they need to do it. Just recently: Irish drone delivery startup Manna Air announced it will expand operations internationally into the UK and USA; UK cybersecurity leader Tracebit opened a New York office; and Nothing is opening stores in New York and San Francisco, adding to locations in India and UK. This approach recently saw Tapestry ranked the number one VC in Europe, and third in the world, for backing Seed and Pre-Seed companies before they go on to raise exceptional Series A rounds from top-tier US firms. Notably, all of the firm's recent serial founder bets at Seed and Pre-Seed in Europe have raised Series A rounds in the $100Ms or fielded acquisition offers, including Sunrise Robotics, Maze AI, Tracebit and Requesty AI, contributing to the fund's 100% 'graduation' rate. Repeat founders. Nothing's Carl Pei exemplifies Tapestry VC's Repeat founder ethos. In the six years since Tapestry VC's seed investment, Nothing has become one of Europe's fastest-growing companies; on track for $1B in sales this year, having recently hit unicorn status following a $200M funding round in 2025 led by Tiger Global. Tapestry also backed Fin AI when Eoghan McCabe and Des Traynor re-founded the company (formerly Intercom) in 2023 around AI. Fin was the first AI customer support platform, and Tapestry VC has supported it from zero to over $100M in revenue. "Expensive experience" Patrick's background as an engineer and operator means he can engage with founders on the hardest product and technical decisions; whilst partner Audrey Miller founded her own startup before switching her vocation to the other side of the table. Together, they bring the instincts that can only come from having been "in the room" with founders through thick and thin. Patrick Murphy, founder at Tapestry VC, said: "I've spent a decade investing on both sides of the Atlantic and the opportunity in Europe has never been clearer. There's an entire generation of founders returning to build again with sharper instincts, deeper networks and who share our global-from-day-one ambition." Audrey Miller, Partner at Tapestry VC said: "Today's repeat founders represent a generation shaped by expensive experience. They've already navigated the realities of building, scaling and exiting technology companies and, second time around, they want partners who have felt the same pressures. This is what Tapestry VC brings."

FinTech Global
Mar 18th, 2026
Security canary firm Tracebit bags $25m Series A.

Security canary firm Tracebit bags $25m Series A. March 18, 2026 Tracebit, a cybersecurity company that deploys security canaries to help enterprises detect intruders, has closed a Series A funding round, bringing its total investment to $25m. The round was led by FirstMark and joined by Accel, MMC Ventures, Tapestry VC and CCL, with continued backing from existing angel investors. The raise follows an initial seed round secured in 2024, which enabled the company to significantly expand the capabilities of its platform beyond its original AWS environment to include Azure, Kubernetes, CI/CD pipelines, developer workstations and identity providers. A Community Edition was also introduced during this period to make the platform more accessible. Tracebit has built an enterprise platform that simplifies the deployment and management of security canaries - digital decoys embedded across a company's infrastructure that expose attackers the moment they gain access. The approach is grounded in the "assume breach" philosophy, which treats a security infiltration as an inevitability and focuses instead on rapid detection. The company argues that when it comes to intrusion detection, the gap between identifying a threat in seconds versus months is not marginal - it is the difference between containment and catastrophe. Since its founding, Tracebit has deployed millions of canaries at companies including Riot Games, Snyk, Docker and Synthesia, thwarted red team attacks, and detected intruders across a growing number of enterprise customers. The new capital will be used to accelerate product development and strengthen customer support across both the UK and the US, where the company has opened a new office near Union Square in New York. Tracebit is also expanding its engineering and commercial teams in London and New York. Alongside the funding announcement, the company has launched several new products: Perimeter Canaries, Deceptive Artifacts and GCP Support. The raise comes as the cybersecurity landscape grows increasingly complex. Writing in March 2026, Tracebit's co-founders noted that while defenders have gained access to powerful new tooling, AI-assisted threat actors are making the years ahead among the most volatile the industry has seen - reinforcing the case for canary-based detection as a core element of the enterprise security stack. Kai, an AI-driven cybersecurity company focused on autonomous threat defence, has emerged from stealth with up to $125m in funding. Investors. The following investor(s) were tagged in this article.

SecurityWeek
Mar 17th, 2026
Tracebit raises $20M for cloud-native deception technology.

Tracebit raises $20M for cloud-native deception technology. The company plans to scale its products, expand to new markets, and grow its marketing and engineering teams. | March 17, 2026 (7:52 AM ET) Cybersecurity startup Tracebit on Tuesday announced raising $20 million in a Series A funding round that brings the total raised by the company to $25 million. The investment round was led by FirstMark, with additional support from Accel, MMC Ventures, Tapestry VC, and CCL. Founded in 2023, London, UK-based Tracebit has built cloud-native threat deception technology that uses tailored canaries to detect threats everywhere on a system. The canaries, which are described as fake honeypots, are deployed across the entire environment to attract threats and help organizations prevent cyberattacks and respond to incidents faster, employing an 'assume breach' approach. These decoy assets bait attackers into revealing their location, enabling responders to identify compromised accounts and prevent lateral movement. According to Tracebit, its cloud-native technology has been built for the modern tech stack to identify and prevent evolving threats. Its canaries can be deployed by identity providers, on workstations, in AWS, Azure, Kubernetes, and CI/CD pipelines. The startup's portfolio was recently expanded with Perimeter Canaries, new decoys meant to be deployed at the edge of SaaS and cloud for faster detection of AI-powered and agentic attacks. Tracebit also launched Deceptive Artefacts and GCP Support and plans to use the new funding to support the rollout of all its new products. It will also invest in expanding across the US, in customer support, and in growing its go-to-market and engineering teams. "Tracebit is building the cloud-native deception and detection layer for the AI era, giving security teams the highest signal proof of compromise. We believe 'assume breach' will become the default posture for modern enterprises, and Tracebit is leading that shift," said FirstMark partner David Waltcher. Ionut Arghire is an international correspondent for SecurityWeek.

FinSMEs
Mar 17th, 2026
Tracebit raises $20M in Series A funding.

Tracebit raises $20M in Series A funding. March 17, 2026 Tracebit, a London, UK-based provider of a cloud-native cybersecurity platform, raised $20m in Series A funding. The round was led by FirstMark, with participation from Accel, MMC Ventures, Tapestry VC, and CCL. This follows a $5M seed round in 2024, bringing the company's total funding to $25m. The company intends to use the funds to accelerate its U.S. expansion, grow its go-to-market and engineering teams in its new New York office, and support the rollout of advanced deception products, including support for Google Cloud Platform (GCP). Led by co-founders Andy Smith (CEO) and Sam Cox (CTO), Tracebit provides a "cloud-native deception" platform that automates the deployment of canaries - decoy assets designed to bait attackers. Unlike traditional hardware-based honeytokens, Its software-defined approach scales across AWS, Azure, Kubernetes, and CI/CD pipelines, monitoring over 5 billion events weekly for customers like Riot Games, Snyk, and Docker. In conjunction with the funding, the company is launching Perimeter Canaries and Deceptive Artefacts, which are designed to counter AI-powered "agentic" attackers that scan cloud sprawl for vulnerabilities, moving detection from "months to minutes" by placing decoys at the very edge of SaaS environments. 17/03/2026