Full-Time

Senior Software Engineer

HackerOne

HackerOne

5,001-10,000 employees

Crowdsourced vulnerability hunting via ethical hackers

Compensation Overview

₹3.7M - ₹4.8M/yr

+ Equity stock options

Pune, Maharashtra, India

In Person

UK-shift working hours required.

Category
Software Engineering (1)
Required Skills
LLM
Python
JavaScript
Distributed Systems
React.js
Ruby
Ruby on Rails
Postgres
RDBMS
GraphQL
RAG
Version Control
Vulnerability Analysis
AWS
Observability

Get referred to HackerOne

See people who can refer or advise you

Requirements
  • At least 8 years of professional software engineering experience in modern software-as-a-service environments.
  • Hands-on experience building production artificial-intelligence-assisted features, large-language-model-powered workflows, or agentic systems at scale, including taking at least one non-trivial large language model or agent system from prototype to production and operating it.
  • Strong working knowledge of agentic architectures, including tool use and function calling, workflow orchestration, retrieval and retrieval-augmented generation, and human-in-the-loop patterns.
  • Strong working knowledge of large language model evaluation and experimentation, including golden sets, offline and online evaluations, regression detection, and prompt and version discipline.
  • Strong proficiency in at least one dynamically typed, object-oriented programming language such as Ruby, JavaScript, or Python, along with experience building scalable backend systems.
  • Experience with relational databases such as PostgreSQL and cloud platforms such as Amazon Web Services to design and operate distributed systems.
  • Proven experience delivering end-to-end technical projects, including defining scope, managing trade-offs, and driving execution with cross-functional partners.
  • Ability to explain how artificial intelligence systems are evaluated and operated in production, including quality metrics, evaluations, rollout strategy, observability, and failure modes.
Responsibilities
  • Lead production artificial intelligence delivery by designing and shipping agentic workflows that integrate tool use, orchestration, retrieval, and human-in-the-loop patterns, owning these systems from architecture through rollout and post-launch operations.
  • Define and implement evaluation frameworks, including golden sets, offline and online evaluations, experimentation pipelines, and prompt and version discipline, and embed these practices across squads.
  • Apply first-principles problem solving to break down ambiguous artificial intelligence problems, define clear solutions, and deliver scalable, maintainable systems that combine artificial intelligence with secure, reliable product experiences.
  • Design workflows incorporating large language models, tooling, retrieval, and human-in-the-loop patterns to improve product outcomes and engineering velocity.
  • Define success metrics and quality and latency trade-offs, and use data to guide experimentation and continuous improvement in artificial intelligence systems.
  • Adapt to changes in model capabilities, artificial intelligence tooling, and priorities, re-scope work effectively, and keep cross-functional stakeholders aligned.
  • Lead execution of complex, cross-functional projects that bring artificial intelligence capabilities into core product features across backend, frontend, and platform layers.
  • Design, build, and maintain highly available, performant, and durable platform features, contributing to artificial intelligence product innovation and system reliability.
  • Collaborate across engineering, product, and design to align priorities, clarify requirements, and deliver solutions that drive measurable customer impact.
  • Identify and address technical debt and system inefficiencies in artificial intelligence and non-artificial-intelligence code paths, improving code quality, scalability, and developer experience within the team and across shared systems.
  • Mentor and grow engineers, especially on applied artificial intelligence patterns, evaluation discipline, and production readiness for large-language-model-based systems, and contribute to a culture of learning and continuous improvement.
Desired Qualifications
  • Experience with vector stores, embeddings, hybrid retrieval, and building observability for large language model and agent systems, such as tracing, cost and latency dashboards, and reasoning logs.
  • Experience implementing evaluation and experimentation frameworks at team or organizational scale, including feedback loops that close onto product and model improvements.
  • Experience improving engineering practices, workflows, or system design through reusable patterns or shared solutions, particularly for artificial intelligence engineering.
  • Experience with Ruby on Rails.
  • Experience with React JavaScript.
  • Experience with PostgreSQL.
  • Experience with GraphQL.
  • Experience with Amazon Web Services.
  • Exposure to security domains such as vulnerability management, application security, or threat intelligence.

HackerOne runs a cybersecurity platform that helps organizations improve digital security by leveraging a global community of ethical hackers. It supports attack surface management, continuous asset testing, and security coverage validation, enabling clients to import asset data, have ethical hackers assess and rank risk, and adjust the scope of testing on demand. The platform provides 24/7 security coverage and scalable cost management, charging clients for platform access and the hackers’ services. This is complemented by proven penetration tests that reveal significant findings and demonstrate the value of a bug bounty program as part of a proactive security strategy. Compared with competitors, HackerOne combines a large, active community of researchers with flexible scope control and continuous asset monitoring to deliver ongoing risk reduction rather than one-off assessments.

Company Size

5,001-10,000

Company Stage

Series E

Total Funding

$159.4M

Headquarters

San Francisco, California

Founded

2012

Get referred to HackerOne

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Vulnerability submissions rose 76% year-over-year in March 2026, expanding demand.
  • May 13, 2026 Wiz integration embeds HackerOne findings into cloud security workflows.
  • July 30, 2026 H1 Remediation sends code-level fix plans into Jira, GitHub, ServiceNow, and MCP.

What critics are saying

  • February 18, 2026 researchers accused HackerOne of using submissions to train AI.
  • Community backlash can cut researcher supply, weaken report quality, and break the marketplace.
  • If H1 automation commoditizes validation, HackerOne loses its moat to Wiz and AI pentesters.

What makes HackerOne unique

  • June 2, 2026 H1 Platform unifies discovery, validation, prioritization, and remediation.
  • HackerOne pairs Hai AI with 1,300 organizations and 20% of Fortune 500.
  • It validates exploitable risk using researchers, pentesters, and continuous testing, not theoretical scans.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Unlimited Paid Time Off

Paid Vacation

Paid Sick Leave

Paid Holidays

Parental Leave

Employee Assistance Program

Digital First Stipend

Equity Stock Options

Retirement Plans

Leaves of Absence

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
AgentLensHQ
Aug 10th, 2026
The decline of HackerOne: from hacker-centric community to corporate AI engine.

The decline of HackerOne: from hacker-centric community to corporate AI engine. August 10, 2026 · gemma-4-31b-it HackerOne's shift from community to corporate sales. HackerOne has transitioned from a platform designed by hackers for hackers into a corporate-centric entity focused on B2B sales and predictable revenue. This shift, which accelerated around 2020-2021, saw the company move away from its original mission of providing a safe, mutual space for ethical researchers and companies to connect, instead prioritizing capacity-based fee structures, multi-year contracts, and aggressive sales growth. The erosion of the "golden age" Between 2017 and 2020, HackerOne focused on high-impact community building, most notably through Live Hacking Events (LHEs). These exclusive gatherings brought top researchers together to find critical vulnerabilities in concentrated bursts, fostering a unique infosec community and providing immense value to participating programs. However, this era ended as the company shifted focus toward corporate growth. The decline was marked by: * Reduced Event Quality: Custom-designed event materials were replaced by low-effort prints, and experienced event organizers were laid off. * Stagnating Product: The core platform UI and performance remained largely unchanged for years, while engineering focus shifted away from researcher-requested features. * The Rise of Sales: The company replaced its founding CEO with a corporate executive and pivoted toward a sales-heavy model, rewarding sales teams with lavish trips while the technical product floundered. The Hacker Success Program (HSP) and inequality. To mitigate the dissatisfaction of top researchers, HackerOne introduced the Hacker Success Program (HSP). While providing dedicated Hacker Success Managers (HSMs) to help elite hackers navigate disputes and payouts, the program created a tiered system. New researchers often find themselves without advocacy or support, effectively creating a lopsided playing field where the "rich get richer" and entry-level hackers have little recourse for platform issues. The AI controversy: training vs. Contextual learning. In 2026, HackerOne faced significant backlash over allegations that researcher submissions were being used to train AI models. This conflict centers on the technical distinction between "training/fine-tuning" and "contextual learning/memory." The tos dispute. In February 2026, updates to the Terms of Service (ToS) suggested that reports could be used to train AI models. Following a surge of researcher departures and public outcry, co-founder Alex Rice and CEO Kara Sprague denied that researcher data was used to train, fine-tune, or improve generative AI models, including the "Hai" AI assistant. The "H1 Intake" Revelation. Shortly after these denials, it was revealed that HackerOne uses an AI system for "H1 Intake" to automate the preliminary review of all reports. This system determines whether a report goes to a human validation team or is handled automatically. Crucially, the system "learns from behavior," meaning it uses the outcomes of past reports to influence future recommendations. While HackerOne argues that storing "learnings" in a database to augment reasoning is fundamentally different from training model weights (fine-tuning), researchers argue this is a distinction without a meaningful difference. In practice, the system uses researcher data to improve its automated behavior, effectively automating the triage process using the intellectual property of the researchers. Market impact and community perspectives. The transition of HackerOne has led to a perceived decline in quality for all stakeholders involved in the bug bounty ecosystem. Impact on stakeholders. * For Researchers: Triage quality has declined, and the platform is flooded with low-quality programs and "AI slop" submissions. * For Customers: Some corporate users report that the quality of reports has decreased, and high-profile events like LHEs have become less actionable, often yielding redundant findings. * For Triagers: High workloads and low pay led to the burnout and departure of the best triage talent, many of whom were hackers themselves. Counterpoints and Industry context. Community discussion provides additional nuance to the decline: * Payment Infrastructure: Some argue that HackerOne's primary remaining value is its universal payment system, which handles the complex legal and financial burden of paying international researchers - a problem that simple software tokens cannot solve. * The Role of COVID-19: Industry veterans suggest that the pandemic played a significant role in killing the budget and appetite for the expensive travel required for Live Hacking Events, accelerating the shift toward virtual, less impactful alternatives. * Economic Pressures: Analysts note that bug bounty margins are thin and triage is expensive, necessitating product diversification into "Continuous Threat Exposure Management" (CTEM) to compete with AI-driven pentesting firms. "The system also learns from behaviour so, if a recommendation is rejected [...] it will take these into account with its recommendations as well." - HackerOne Product Manager regarding AI triage.

UK Tech News
Jul 30th, 2026
HackerOne tackles growing remediation gap with H1 Remediation.

HackerOne tackles growing remediation gap with H1 Remediation. Global leader in Continuous Threat Exposure Management (CTEM), HackerOne, has launched H1 Remediation, a new capability that delivers developer-ready fix plans for validated, exploitable findings. Each plan is grounded in the customer's own source code, enriched with business context, and delivered directly into the issue tracking tools and AI coding agents engineering teams already use via Model Context Protocol (MCP). Root cause is traced to specific lines of code, so engineers can act immediately without follow-up from security. This helps reduce exposure debt faster. H1 Remediation addresses a gap that has widened as AI accelerates discovery faster than security and engineering teams can validate and fix what's found. With AI enabling faster discovery, the resolution rate for critical-severity findings has fallen significantly over the last year, even as critical-finding mean time to remediate improved by more than 50%. The result is that the backlog of unresolved critical issues has grown 29x over that same timeframe, according to H1 Platform data. The bottleneck is not effort. It is friction: security lacks the data to make a compelling prioritisation case, engineering is sceptical of severity ratings it cannot verify, and both sides operate from different risk frameworks with no shared ground truth. H1 Remediation removes that friction at the source. Fix plans are generated only for findings with validated exploitability, traced to the actual lines of vulnerable code in the codebase. Engineers get the specificity they need to act fast, without waiting for security to verify the work. "Boards no longer want to hear how many vulnerabilities were found. They need to know the magnitude of the exposure debt you're carrying and what you are doing about it," said Kara Sprague, CEO at HackerOne. "H1 Remediation gives security leaders a defensible answer to both. Every finding carries a documented trail from validated exploitable vulnerability to verified fix, with exposure duration as a measurable, reportable metric. Closing that gap faster is both an operational improvement and a governance imperative." "The value for us is in speed to resolution. H1 Remediation hands our engineers clear technical steps already grounded in our own code, so they can move straight to a fix," said Connor Knabe, Application Security Architect at Veterans United Home Loans. "This results in time saved for the security and product teams. It's clear this isn't generic guidance. It's based on our actual code and fits right into how our team already works, so there's no new process, just better information showing up exactly where we need it." Unlike AI coding assistants that generate fixes without security validation, H1 Remediation works only from validated, exploitable findings. Those findings come from across the platform: security researchers identifying real-world impact through H1 Bounty, pentesters working through H1 Agentic Pentesting, and continuous exposure signals from H1 Continuous Testing. For each of these findings, Hai, HackerOne's agentic AI orchestrator, traces root cause to the actual lines of code, and generates a developer-ready fix plan informed by context from the customer's actual environment and grounded in the codebase. The result is a complete picture that gives engineering teams the confidence to act on findings they know are real. "Every customer conversation comes back to the same problem: validated findings sitting unresolved because engineering lacks the context to act on them quickly," said Nidhi Aggarwal, Chief Product Officer at HackerOne. "H1 Remediation extends the workflow from discovery to verified fix. When a fix plan starts from a validated, exploitable finding traced to the actual source code, is informed by the customer's context, and is delivered into the engineering workflows teams already use, the friction that stalls remediation disappears. Combining agentic capabilities with human ingenuity from the security research community is what gives teams the confidence that what they are fixing is real. That is what turns remediation from a backlog problem into a continuous improvement process that drives measurable risk reduction." How H1 Remediation Closes the Gap H1 Remediation is generally available through the H1 Platform. It runs automatically on incoming HackerOne-native findings, from security researchers, pentesters, and continuous testing, once exploitability and severity are validated. Key capabilities include: * Source code-informed root cause analysis that connects to customer repositories (GitHub, GitLab, Azure DevOps, Bitbucket, public and private) and traces findings to the specific lines of code where the vulnerability exists. Root cause analysis sharpens validation confidence and anchors fix guidance in the customer's actual codebase. * In-report fix plans with a remediation approach, root cause analysis detailing exactly where a risky input enters the code and where it does damage, language-specific code change suggestions, business context, and implementation guidance, added directly to the finding. * Context enrichment from connected Jira, Linear, and Confluence sources, including incident history and asset information, so fix plans reflect the customer's actual environment before delivery. * One-click delivery into issue tracking tools such as Jira, Linear, and ServiceNow as structured tickets, with status syncing back to the H1 Platform automatically. * H1 Platform MCP server integration that exposes fix plans directly to IDEs and AI coding agents, including Claude Code and Cursor, so engineers can access and act on guidance without leaving their environment. * Remediation dashboard tracking resolution rate, mean time to remediate by severity, findings flow, and exposure backlog trends, with peer benchmarking and year-over-year comparisons, giving security leaders an executive and board-level view of risk reduction over time. H1 Remediation is available today in the H1 Platform.

NOW LET US
Jun 22nd, 2026
Patch the Planet: a Daybreak initiative to support open source maintainers.

Patch the Planet: a Daybreak initiative to support open source maintainers. Nowletus is introducing Patch the Planet, a Daybreak initiative built with Trail of Bits to help maintainers strengthen the critical open-source software the world relies on. Nowletus is pairing AI-assisted security research using its most cyber-capable models with expert human review to not only identify vulnerabilities, but help patch them. AI is accelerating vulnerability discovery, but discovery alone does not protect users. Many maintainers are already being asked to sort through more reports, more quickly, with the same limited time and resources. Patch the Planet is built to reduce that burden, not add to it: security engineers review findings before they reach maintainers, work with projects to develop patches and tests, and build reusable workflows that help teams continue improving security after the first fixes land. Trail of Bits has committed their entire security research organization(opens in a new window) towards this effort for its initial surge. They are working directly with maintainers to investigate and validate vulnerabilities, develop and test patches, and coordinate disclosure of vulnerabilities. Additionally, Nowletus will be partnering with HackerOne and Calif who are helping Nowletus take its efforts further with vulnerability triage, coordinated disclosure, and additional focused vulnerability discovery efforts. Each engagement under Patch the Planet begins in consultation with the maintainer. For each collaboration, security engineers work with maintainers to understand each project's needs, preferences, and where additional security effort would be most useful: vulnerability validation, patch development, CI/CD improvements, or longer-term security engineering. Once aligned, researchers investigate potential vulnerabilities, validate meaningful issues, develop or refine patches, support testing, and coordinate disclosure through the project's established channels. Initial participants include cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python, and python.org. These projects support widely used networking, cryptography, software supply chain, and language infrastructure, where stronger security can benefit a broad range of downstream products and services. Additional projects will join in future rounds. Security researchers are equipped with its frontier models as well as Codex Security(opens in a new window) to support the analysis, patch development, testing, and documentation. Participating projects receive access to ChatGPT Pro; conditional access to Codex Security; and API credits for core open-source development, maintainer automation, and release workflows. Trail of Bits has developed AI-assisted workflows for deduplication, triage, and patching that projects can run with this support. Trail of Bits has dedicated security engineers to work full-time with Codex and GPT-5.5-Cyber across 19 open-source projects, and has already identified hundreds of security issues and merged dozens of patches, with many more still undergoing coordinated disclosure. The initial sprint also produced reusable security infrastructure: fuzzing harnesses, historical-CVE analysis pipelines, differential-testing systems, threat models, expanded test suites, and workflows for deduplication, false-positive filtering, severity correction, and patch generation. Some project-specific details will be shared later as testing, remediation, and coordinated disclosure progress. A few early examples show what the team was able to build and find: A fuzzing lab in less than a day. Trail of Bits engineers used repeated Codex /goal runs with GPT-5.5-Cyber to build an entire fuzzing lab covering dozens of entry points, variant builds, platforms, and novel test seeds. Engineers set the objectives and refined the prompts; the system then used coverage feedback to keep expanding into new surfaces, target edge cases, and filter weak or invalid candidates. Trail of Bits engineers found that, with limited guidance, GPT-5.5-Cyber made useful choices about where to expand coverage, which builds and entry points to probe, and which candidates were too weak to pursue. The completed setup took less than a day. Trail of Bits estimates that building the same lab manually would ordinarily take at least several weeks. A reusable pipeline for finding variants of known vulnerabilities. The team built an end-to-end system that ingests historical CVEs, extracts relevant vulnerability patterns, searches target codebases for related flaws, and sends candidate findings through specialized judging agents. The pipeline deduplicates results, filters likely false positives, and routes the strongest evidence to security engineers for manual confirmation. This turns years of public vulnerability history into a repeatable search strategy that can be applied across projects. Trail of Bits found the models especially effective at this kind of variant analysis, which uncovered many additional issues across the codebases under review. Differential testing in days instead of weeks or months. Different implementations of the same protocol should usually behave the same way under the same inputs. When they diverge, one may contain a bug. Applying this idea at scale is normally difficult because engineers must write custom shim and glue code connecting each implementation to a common test harness. Codex generated and iterated on that code, allowing multiple implementations to be fuzzed against one another and their behavioral differences investigated. The workflow filtered many weak or invalid results and produced a comparatively high-signal set of candidates for expert review. The team reached those results within days, compressing work that has historically taken weeks or months. Trail of Bits is continuing to expand and refine these tests before publishing project-specific details. Testing software against the behavior its specifications promise. The teams used Codex to develop threat models, attack taxonomies, invariant tests, and property-based tests grounded in project specifications and RFCs. These methods exposed notable differences between intended and actual behavior while leaving projects with broader test coverage, stronger documentation, and improvements to CI/CD and software-supply-chain tooling. Security engineers reviewed every finding before it reached a maintainer. Trail of Bits engineers manually reviewed every security issue before it was submitted to a maintainer, and the added value of this step cannot be understated. While frontier AI models are highly capable of finding vulnerabilities and patching them, they also produce a high volume of false positives that can contribute to the already overwhelming backlog maintainers are facing. Patch the Planet solves for this by having dedicated Trail of Bits researchers reproduce the evidence, check findings against project-specific documentation and threat models, remove duplicates, reassess severity, and prioritize confirmed vulnerabilities for remediation. They also develop and submit patches in accordance with maintainers preferences. Maintainers remain in control of what patches are deployed and how disclosure is handled. Patch the Planet builds on a broader body of Daybreak work showing how frontier models can help defenders find, validate, and remediate serious vulnerabilities in widely used software. Nowletus is sharing a few early highlights here, while withholding exploit mechanics and project-specific details where disclosure is still underway. As fixes land and coordinated disclosures conclude, Nowletus plan to publish deeper technical reports that walk through individual findings, research methods, validation workflows, and lessons other defenders can apply. Its findings span every layer of the software stack, with many more still in the disclosure process. **Linux Kernel:**GPT-5.5-Cyber identified security-relevant components across more than 30 million li Ad slot ready: 5887729102 Discover more Data Management

Simply Secure Group
Jun 22nd, 2026
OpenAI releases gpt5.5cyber with full automation for vulnerability detection and patching.

OpenAI releases gpt5.5cyber with full automation for vulnerability detection and patching. June 22, 2026 OpenAI has officially launched the full version of GPT-5.5-Cyber, a specialized AI model engineered for advanced vulnerability detection, patch generation, and automated remediation at machine speed. The release is part of OpenAI's broader Daybreak initiative, which aims to democratize defensive cybersecurity capabilities for trusted organizations worldwide. GPT-5.5-Cyber delivers state-of-the-art results across three major cybersecurity evaluation benchmarks: * CyberGym: 85.6% (vs. 81.8% for GPT-5.5), the highest single-model score recorded. * ExploitGym: 39.5% (vs. 25.95% for GPT-5.5), testing exploit generation from known vulnerabilities. * SEC-bench Pro: 69.8% (vs. 63.1% for GPT-5.5), evaluating long-horizon vulnerability discovery across complex software targets. The model can navigate large codebases, trace attack paths, validate exploitability, generate targeted patches, and produce remediation evidence all within a single automated workflow. Codex Security plugin updated. Alongside the model release, OpenAI has updated the Codex Security plugin, now capable of deep codebase scanning with automated patch generation. Since launching in research preview in March 2026, Codex Security has: * Scanned over 30 million commits across more than 30,000 codebases * Processed over 70,000 manually verified fixes * Automatically resolved over 500,000 findings The plugin integrates directly into developer workflows, supporting SARIF exports, CodeQL queries, and existing vulnerability management pipelines. It generates severity-rated reports with affected code locations, attack path tracing, and codebase-specific patches for human review. OpenAI launched Patch the Planet, a collaborative initiative co-founded with Trail of Bits and partnered with HackerOne and Calif, to address the critical vulnerability remediation gap in open-source software. More than 30 open-source projects have committed to participate, including: * cURL, Go, Python, Sigstore, and pyca/cryptography An initial five-day sprint across multiple projects surfaced hundreds of issues, merged dozens of patches, and built reusable fuzzing and variant-analysis workflows. Participating projects receive ChatGPT Pro, conditional Codex Security access, and API credits. GPT-5.5-Cyber is distributed exclusively through a limited release to verified, trusted defenders. It is not available for general use. OpenAI has confirmed Trusted Access for Cyber partnerships with Australia, Canada, France, Germany, Japan, South Korea, and EU institutions, including ENISA. OpenAI coordinated pre-deployment testing with the Center for AI Standards and Innovation (CAISI) and worked with the Office of the National Cyber Director (ONCD) on the implementation of the June 2026 Executive Order on AI security. For most organizations, GPT-5.5 with Trusted Access for Cyber and Codex Security remains the recommended entry point, with GPT-5.5-Cyber reserved for defenders requiring the highest capability tier with enhanced monitoring and scoped controls. OpenAI's announcement signals a fundamental shift in the cybersecurity threat model. The historical bottleneck of finding vulnerabilities has given way to a new challenge: patching them at scale. With Daybreak unifying frontier AI models, Codex Security workflows, open-source partnerships, and critical infrastructure collaboration, OpenAI is positioning AI-driven remediation, not just detection, as the next frontier in cyber defense. Follow Simply Secure Group on Google News, LinkedIn, and X to Get More Instant Updates.

Disaster Recovery Journal
Jun 2nd, 2026
HackerOne introduces H1 Platform to advance Continuous Threat Exposure Management.

HackerOne introduces H1 Platform to advance Continuous Threat Exposure Management. June 2, 2026 HackerOne has unveiled the H1 Platform, a new agentic AI-powered system built to help organizations identify, validate, prioritize, and remediate security exposures on an ongoing basis. The announcement arrives as security teams face growing pressure from a surge in both software development and vulnerability discovery driven by artificial intelligence. AI-assisted coding has become a routine part of development workflows, while security tools are uncovering vulnerabilities at an increasing rate. As a result, many organizations are struggling to keep up with validation and remediation efforts. According to HackerOne, vulnerability submissions across its platform increased by 92% over the past year. The company also reported growth in critical and high-severity findings, while remediation capacity has not expanded at the same pace. The H1 Platform is designed to address that gap through agentic AI capabilities embedded throughout the Continuous Threat Exposure Management (CTEM) process. At the center of the platform is Hai, HackerOne's AI orchestrator, which analyzes exploitability indicators, remediation guidance, and attack activity to help security teams focus on the vulnerabilities most likely to create business risk. "In a world reshaped by frontier AI models, security can't afford to be static, theoretical, or siloed. It must be continuous, validated, and tied to business impact," said Nidhi Aggarwal, Chief Product Officer at HackerOne. "As exploit windows shrink and vulnerability volume accelerates, organizations need security systems that can continuously discover and validate what matters, prioritize action, and operationalize remediation at AI scale to continuously reduce cyber risk." HackerOne Chief Executive Officer Kara Sprague said the platform reflects changing security requirements as organizations adopt more advanced AI technologies. "The AI era demands a new kind of security platform: agentic, continuous, and operating at the speed of the threat. The H1 Platform closes the discovery-remediation gap that defines this moment, built on the only foundation that could make it work: the simultaneous trust of the Fortune 500 and the world's largest community of security researchers, sustained over more than a decade," said Kara Sprague, HackerOne's Chief Executive Officer. "As enterprises move from securing code to securing AI itself, the researcher community's role on this platform will only deepen." A key component of the platform is HackerOne's global community of security researchers. While AI-driven automation can accelerate testing and analysis, researchers contribute expertise in areas that remain difficult to automate, including business logic weaknesses, novel attack techniques, and multi-step attack paths. HackerOne says this combination enables organizations to focus on vulnerabilities that have been demonstrated as exploitable rather than relying solely on theoretical risk assessments. As organizations expand their use of AI systems, HackerOne expects researcher contributions to extend beyond vulnerability discovery into broader security intelligence and risk assessment activities. Platform Capabilities The H1 Platform combines exposure discovery, validation, prioritization, and remediation within a single operational environment. Key capabilities include: * Continuous agentic testing across the attack surface with exploitability validation informed by historical program data and attack-path analysis * Vulnerability prioritization based on exploitability and business impact * Remediation workflows integrated with platforms including Jira, GitHub, ServiceNow, Azure DevOps, Linear, and other enterprise systems * Agentic exploitation workflows that generate validated findings and route them directly to development teams * Executive reporting and analytics, including Return on Mitigation (RoM) metrics intended to help organizations assess exposure reduction and remediation effectiveness Customer Adoption and Results HackerOne reports that the H1 Platform is used by approximately 1,300 organizations worldwide, including 20% of Fortune 500 companies and several leading AI-focused enterprises. Across its customer base, the company says it has helped organizations reduce more than $32 billion in exposure risk and lower mean time to remediate (MTTR) by roughly 80%. One example comes from Canadian fintech company KOHO Financial, where security teams have used the platform to improve vulnerability management processes. "We went from a set-and-forget security program to one that actually keeps pace with how fast threats move," said Scott Brown, Security Lead, KOHO Financial. "Reducing median triage time by roughly 80% has changed everything. Our team focuses on what's confirmed and exploitable, and vulnerabilities get addressed before they become real risk."