Full-Time

Technical Customer Success Manager

Founding Team

Posted on 6/3/2025

XBOW

XBOW

201-500 employees

Automated web security benchmark solver

Compensation Overview

$150k - $250k/yr

Remote in USA

Remote

Category
Sales & Account Management
Requirements
  • Experience in a technical customer-facing role at a SaaS or cybersecurity startup
  • Familiarity with application security or developer tools
  • Background in technical program management or scaled customer success
  • Ability to perform product demos and customer training sessions
  • Experience with automation, support tooling, or scaled outreach
Responsibilities
  • Serve as the primary point of contact and for a large and growing portfolio of customers
  • Own the end-to-end customer experience across hundreds of accounts; nothing falls through the cracks
  • Deliver a high-touch experience when needed by acting as a problem solver—conduct independent analysis and triage before escalating to internal teams
  • Develop and own repeatable workflows to scale self-service–led entry with product-led expansion
  • Collaborate closely with both product and sales teams to align on strategy and execution
  • Act as an external-facing technical program manager—identify process gaps, advocate for fixes, and recognize when automation is needed, even without writing code
  • Represent the voice of the customer internally to drive adoption and continuous improvement
  • Advocate for product and process changes that reduce friction, automate touchpoints, and improve outcomes
  • Navigate product questions with confidence, escalating appropriately even without deep domain knowledge

XBOW provides automated web security benchmarks using real-world scenarios with clear success criteria, such as flag capture. It works by generating Python programs that exploit specific vulnerabilities (like XML deserialization) and can deploy embedded bash scripts, while also debugging its own code and the target server environment. It stands apart by sourcing benchmarks from PortSwigger, PentesterLab, and public CTFs, focusing on practical situations rather than puzzles, and by solving challenges without needing pre-defined descriptions. The goal is to offer practical, automated web security practice and evaluation for users seeking realistic penetration testing experiences.

Company Size

201-500

Company Stage

Series C

Total Funding

$272M

Headquarters

Seattle, Washington

Founded

1995

Simplify Jobs

Simplify's Take

What believers are saying

  • XBOW raised $155M Series C, valuing unicorn at over $1B in March 2026.
  • XBOW integrates with Microsoft Security Copilot and Sentinel at RSAC 2026.
  • XBOW serves 100+ customers including Moderna, accelerating APAC expansion.

What critics are saying

  • RunSybil steals XBOW customers with cheaper, faster non-Microsoft integrations.
  • Microsoft enhances Security Copilot, obsoleting XBOW's Pentest Agents by 2027.
  • Prompt injections leak XBOW customer credentials, causing Moderna churn by August 2026.

What makes XBOW unique

  • XBOW deploys AI agent swarms topping HackerOne leaderboard in 2025.
  • XBOW validates findings via real exploitation, eliminating false positives.
  • XBOW's 104 original benchmarks test novel exploits beyond training data.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Remote Work Options

Career Growth

Growth & Insights and Company News

Headcount

6 month growth

-9%

1 year growth

-13%

2 year growth

37%
Business Wire
Mar 23rd, 2026
XBOW integrates AI penetration testing into Microsoft Security Copilot and Sentinel

XBOW, an autonomous offensive security company, has announced integration of its continuous penetration testing platform into Microsoft Security Copilot and Microsoft Sentinel data lake. The collaboration, unveiled as a public preview at RSAC 2026, enables enterprises to discover and validate vulnerabilities directly within Microsoft's security ecosystem. The integration creates a continuous feedback loop between offensive and defensive security operations. Security teams can initiate and manage XBOW assessments through Microsoft Security Copilot, with findings flowing into Sentinel data lake. The solution includes a Pentest Manager Agent, Sentinel Connector and Pentest Analysis Agent spanning the full penetration testing lifecycle. The integration addresses the gap between periodic manual penetration testing and real-time security operations, allowing teams to validate defenses and identify detection gaps without leaving Microsoft consoles.

OpenClawAI
Mar 19th, 2026
Xbow raises $120M to let AI agents hack your systems before criminals do.

Xbow raises $120M to let AI agents hack your systems before criminals do. Xbow's Series C makes it a unicorn. The former GitHub executive's company deploys swarms of AI agents that autonomously pen-test web, mobile, and native applications - reaching #1 on HackerOne and reducing testing from weeks to hours. OpenClaw Team The company that proved AI can out-hack humans just became a unicorn. Xbow raised $120M in Series C funding led by DFJ Growth and Northzone, bringing total funding to $237M and valuation above $1 billion. The Seattle-based startup, founded in 2024 by former GitHub technology incubator lead Oege de Moor, deploys swarms of AI agents that autonomously conduct penetration testing - and last year, those agents reached #1 on HackerOne, the world's largest bug bounty platform. That's not theoretical capability. That's a measured result against the same targets human hackers compete on. How it works: agent swarms, not human testers. Traditional pen testing: one human tester sequentially probes a system over weeks. Xbow: a swarm of AI agents simultaneously explore multiple attack vectors, reducing testing from weeks to hours. De Moor describes the approach: "Think of it as a swarm of agents all trying different attack types across the attack surfaces. By being able to do many of them in parallel, it can work much faster than a human pen test." The next evolution is incremental testing - instead of retesting entire systems after every change, Xbow identifies what changed and focuses only on affected endpoints. This brings testing time down from hours to minutes, making continuous testing economically viable for the first time. This matters because vibe coding is dramatically increasing the rate at which web applications are created. As de Moor notes: "AI vibe coding makes it possible for everyone to create more apps. These web apps are being created at a tremendous rate." More apps means more attack surface, which means the old model of periodic human pen tests is fundamentally broken. The $120M goes to gpus. A significant portion of the funding goes to compute infrastructure, particularly GPU resources. Autonomous hacking at scale requires massive inference capacity - every agent in the swarm is running an LLM that reasons about attack strategies, generates payloads, and evaluates responses in real time. De Moor: "We are an AI-native company that needs a lot of GPU power." The rest funds team growth (currently 190 people) and expansion beyond web applications into mobile and native environments. Native applications present harder challenges - memory corruption, system-level vulnerabilities - but also represent a larger and less-tested attack surface. Prompt injection: AI hacking AI. One of the most technically interesting areas Xbow is developing: specialized agents for detecting prompt injection vulnerabilities. This is AI systems trying to trick other AI systems into doing things they shouldn't - a fundamentally new class of vulnerability that traditional testing tools can't find. De Moor acknowledges the challenge: "The special techniques for prompt injection are not yet very well known in the training set of the models." This means Xbow has to develop novel attack patterns that weren't in any model's training data - genuine zero-day research at the intersection of AI security and AI capability. The company is also building validators to ensure findings are accurate and reproducible. False positives in offensive security waste defender time; Xbow's approach includes verification that each discovered vulnerability is genuinely exploitable. The humans-in-the-loop design. Despite the autonomous capability, Xbow maintains a human-in-the-loop design: * Security teams provide credentials, scoping instructions, and focus areas - the same briefing they'd give a human pen tester * The system maintains detailed logs of reasoning and actions for human review * When the AI identifies something suspicious but can't exploit it, humans step in to complete the analysis * Results are presented with full context so defenders can prioritize and remediate This is the right design pattern for offensive security: let AI handle the breadth and speed, let humans handle the judgment calls. The offensive AI security landscape. Xbow isn't alone. A cluster of companies is building AI-powered offensive security: | Company | Approach | Signal | | Xbow | Autonomous pen testing swarms | $120M Series C, #1 HackerOne | | Booz Allen (Vellox Striker) | AI adversary emulation | $12B defense contractor | | RunSybil | AI agents for offensive testing | $40M Series A | | Codex Security | AI vulnerability research | 14 CVEs in 30 days | | XBOW AI | First critical CVE found by AI (CVSS 9.8) | March Patch Tuesday | The pattern: AI agents are becoming both the attack surface and the primary tool for finding vulnerabilities in that surface. The companies that can build AI that thinks like an attacker are the ones best positioned to defend against AI-powered attacks. What OpenClaw users should know. Xbow's success validates something OpenClaw users should take seriously: AI agents can and will find vulnerabilities in your systems faster than you can patch them. If you're exposing OpenClaw agents to the internet - through MCP servers, API endpoints, or web interfaces - assume that AI-powered scanners are already probing them. The 30,000+ internet-exposed OpenClaw instances found without authentication earlier this year are exactly the kind of target that autonomous pen testing swarms excel at finding and exploiting. The defensive implications: * Continuous testing > periodic audits - if your attack surface changes daily, annual pen tests are meaningless * Prompt injection is a real vulnerability class - your agent's system prompts, tool descriptions, and MCP configurations are all attack surfaces * Speed matters - AI attackers don't take breaks; your defenses shouldn't either * Test your own agents - before someone else does The era of "we'll do a pen test next quarter" is over. AI-powered attackers operate continuously, and defense needs to match that cadence. Xbow's $120M Series C was announced March 19, 2026. RSAC 2026 runs March 23-26 in San Francisco. Liked this article? Try OpenClaw. Stop reading about automation - start using it. OpenClaw connects to your email, calendar, code, and smart home from WhatsApp or Telegram. More OpenClaw guides and analysis connected by topic, tags, and content overlap. Security - Mar 20, 2026 Oasis Security's Series B brings total funding to $195M for its Agentic Access Management platform. With machine identities outnumbering humans 82 to 1, the company is building least-privilege governance for AI agents at enterprise scale. Security - Mar 30, 2026 At RSAC 2026, Splunk unveiled six specialized AI agents for Enterprise Security - from detection building to malware reversing to guided response. The SOC is no longer a human-only operation. Security - Mar 28, 2026 Proofpoint CEO Sumit Dhawan argues AI agents behave like human insiders: non-deterministic, manipulable, and capable of behavioral drift. The fix isn't firewalls - it's the same behavioral monitoring enterprises already use for employee insider risk. Ready to try OpenClaw? Join the waitlist for managed hosting. OpenClaw'll notify you when your spot is ready. No credit card required. OpenClaw'll notify you when hosted service launches.

Connectweb Technologies, Inc.
Mar 18th, 2026
XBOW raises $120M to scale its autonomous hacker.

XBOW raises $120M to scale its autonomous hacker. Valued at over $1B, XBOW is Accelerating AI-powered Offensive Security to Help Defenders Outpace Modern Attackers SEATTLE-BUSINESS WIRE- XBOW, the leader in autonomous offensive security, today announced it has raised $120 million in Series C financing. The round, led by DFJ Growth and Northzone, values the company at over $1 billion. As part of DFJ Growth's investment, Ramin Sayar, Venture Partner, will join the XBOW Board of Directors. Drawing on his experience as the former CEO of Sumo Logic, he will help the company scale operations and expand in the enterprise market. The round also includes participation from new investors Sofina and Alkeon Capital, as well as existing investors Altimeter, NFDG Ventures, and Sequoia Capital. Until now, attackers were constrained by talent. Even the most sophisticated adversaries could not target every system, every version, all the time. With AI, that constraint is gone. Attackers now operate continuously and at scale, probing every release, every environment, and every exposed surface. At the same time, engineering teams are shipping faster than ever. Traditional human-led penetration testing cannot keep pace with AI-driven attackers and modern development cycles. "When I founded XBOW in January 2024, few believed AI could truly think like a hacker and operate at machine speed. We proved it. XBOW reached the top of the HackerOne leaderboard and is now deployed at some of the most security-forward companies in the world," said Oege de Moor, Founder and CEO, XBOW. "Attackers are already using AI. Defenders need to move just as fast. XBOW provides that continuous speed, and this funding enables us to bring it to the entire industry." Cybersecurity Enters the Autonomous Era Autonomous offensive security is emerging as the next evolution of security testing. Rather than relying on point-in-time manual pentests, organizations are shifting toward continuous, intelligent coverage that mirrors how modern attackers operate. XBOW applies AI reasoning and adversarial workflows modeled on real-world attack techniques to identify and validate vulnerabilities at machine speed. Its platform continuously tests applications, uncovering deep exploits often missed by manual testing, while maintaining a low false-positive rate. "XBOW was the first to demonstrate how large language models could be applied to offensive security at scale," said Barry Schuler, Co-founder and Managing Partner, DFJ Growth. "The company didn't just prove the technology, it also proved market demand. By combining AI reasoning with real-world adversarial expertise, XBOW is bringing the autonomous hacker to life." "XBOW is rapidly emerging as a category leader, with Fortune 500 and global enterprises already relying on the platform as a mission-critical layer in their security stack," said Sanjot Malhi, Partner, Northzone. "Oege and the team have built an extraordinarily capable AI-driven security platform in a remarkably short time, and we're thrilled to partner with them as they scale." Proof Achieved. Now Scaling. Over the past year, XBOW proved that autonomous systems can operate safely and effectively in live production environments. This investment will accelerate the company's expansion across enterprise markets, continued product innovation, and international growth. From day one, XBOW has paired autonomous systems with some of the world's top hackers, who help train its autonomous hacker to think like a real adversary. The company was founded by Oege de Moor, creator of GitHub Copilot and GitHub Advanced Security, and built alongside a core group of engineers from the original Copilot team. Chief Information Security Officer Nico Waisman, formerly CISO at Lyft, joined from the outset and has helped shape XBOW's approach to deploying autonomous systems safely in complex environments. Nico assembled a team of some of the best human hackers in the world to teach the XBOW system its trade. The company has further strengthened its leadership by naming Ron Gabrisko to its Board, Jonaki Egenolf as Chief Marketing Officer, Dean Breda as General Counsel, and Niro Rajadurai as Chief Revenue Officer. As part of its global expansion strategy, XBOW also appointed WonLae Lee as General Manager, South Korea, at the beginning of 2026. About XBOW XBOW is the autonomous offensive security company redefining cyber defense for the AI era. Combining AI reasoning with offensive security workflows, the XBOW platform delivers expert-level security testing at machine speed. XBOW empowers security teams to transform from reactive to proactive defense at AI scale. For XBOW customers, autonomous offense is the best defense. About DFJ Growth DFJ Growth is a prominent investor in emerging technology leaders during their scaling phase of development. Founded in 2005, DFJ Growth partners with extraordinary, mission-driven entrepreneurs disrupting the status quo with game-changing innovations that become iconic companies. Its investments include Anaplan, Anduril, Box, Cellares, Coinbase, Commonwealth Fusion Systems, Neuralink, OpenAI, Patreon, Ring (Amazon), ScaleAI, SolarCity (Tesla), SpaceX, Stripe, Tesla, Twitter, and Unity. DFJ Growth is a fearless investor and steadfast partner to founders who imagine the future and execute on their bold visions to define it. About Northzone Northzone is a global venture capital fund built on experience spanning multiple economic and disruptive technology cycles. Founded in 1996, Northzone has raised more than ten funds to date, with its most recent fundraise in excess of $1.2 billion and has invested in more than 175 companies, including category-defining businesses such as Trustpilot, Spotify, Klarna, iZettle, Kahoot!, Personio, TrueLayer, Spring Health, and Zopa. Northzone is a full-stack investor from Seed to Growth stage, with transatlantic hubs out of London, New York, Amsterdam, Berlin, Stockholm and Oslo. Contact details:

XBOW
Mar 18th, 2026
XBOW Raises $120M to Scale its Autonomous Hacker

Valued at over $1B, XBOW is Accelerating AI-powered Offensive Security to Help Defenders Outpace Modern Attackers

Bloomberg L.P.
Mar 18th, 2026
AI security startup Xbow valued at over $1B after new funding round

Xbow, a startup developing AI software to detect security vulnerabilities in applications, has raised funding at a valuation exceeding $1 billion. The deal reflects strong investor interest in applying artificial intelligence to cybersecurity challenges.

INACTIVE