Hex Security is now ParameterWe're at Black Hat USA 2026

Parameter

[ engineering ]

Member of Technical Staff, AI Engineer

Full time • San Francisco, CA • $180K – $240K • 2 openings

Parameter builds AI agents that do offensive security work. Our agents run autonomous penetration tests against production applications and cloud environments, finding IDORs, broken access control, XSS, and infrastructure misconfigurations that scanners miss and that human pentest firms only look for once or twice a year.

We are not a theoretical security company. Our team has responsibly disclosed real, high-severity vulnerabilities to well-known technology companies, and our findings are the front door to most of our customer relationships.

You'll build the agent systems that do the actual hacking. That means designing the reasoning loops, tool interfaces, and memory architecture that let an LLM behave like a competent offensive security researcher rather than a fuzzer with good manners.

The title points at where you'll spend most of your time. Expect the rest of the week to go wherever the work is: agent systems one day, the product the next, a customer call or a report that has to go out after that. We are small enough that everyone works across every product, and we hire people who want that.

What you'll do

  • Design and ship agent workflows in LangGraph and Temporal that plan, execute, and verify multi-step exploitation chains
  • Build the tool layer the agents operate through: HTTP clients, auth handling, browser control, cloud enumeration, payload generation
  • Own the eval loop. We use Braintrust and Langfuse. You'll define what “good” means for agent runs and make the number go up
  • Reduce false positives, which is the single hardest problem in this space and the thing customers care most about
  • Manage inference cost and latency at scale, including prompt caching, context strategy, and model selection across Claude and Bedrock

What we're looking for

  • 3+ years of software engineering, with at least one year building production LLM systems (not just prototypes or demos)
  • Strong TypeScript. Comfortable with async, distributed systems, and long-running workflow orchestration
  • Real intuition for context engineering, tool design, and why agents fail in the wild
  • You measure things. You've built or maintained an eval harness and know why offline metrics diverge from production behavior
  • Bonus: security background, CTF experience, bug bounty history, or a track record of breaking things you were not supposed to break

Interview process

  • Intro call with a founder (30 minutes)
  • Technical deep dive on your past work (60 minutes)
  • Paid work trial or take-home, scoped to roughly one day
  • Onsite in San Francisco with the team
  • References and offer

Stack

TypeScript, LangGraph, Temporal, GCP, AWS Bedrock, Anthropic API, Langfuse, Braintrust, GitHub Actions, Linear, Graphite

We move quickly. Our target is an offer within two weeks of first contact. Small team, high trust, extremely fast. If you want to see your work in front of customers within days, this is that.

This role is onsite in San Francisco. You must be authorized to work in the US; we are not able to sponsor visas at this time.