FlexHired LogoFlexHired
Logo of XBOW

XBOW

Application Security Consultant (founding team)

Job Summary

The role involves leveraging application security expertise to identify vulnerabilities and provide actionable insights to customers. It requires strong communication skills to translate technical findings into business impact and collaborate across technical and executive teams. The position emphasizes building customer relationships, influencing product development, and supporting security across modern web architectures. The candidate should have practical experience in security assessment, offensive techniques, and working directly with clients in a consultative capacity.

Required Skills

Communication
Collaboration
Web Technologies
Risk Management
Vulnerability Assessment
Threat Modeling
Application Security
Secure Development
Code Analysis
Offensive Security
Exploit Development
OWASP Top 10

Benefits

Remote Work
Equity
Competitive Salary
Career Growth
High-Impact Work
Mission-Driven Environment

Job Description

Application Security Consultant – founding Customer Success team

Locations: US Remote

About XBOW

At XBOW, we’re redefining the future of cybersecurity by building the world's first autonomous pentester, powered by AI. Today, the gold standard for securing software systems is human pentesters, but with the rise of artificial intelligence, we’re stepping up to scale offensive security to meet the ever-growing demand.

AI is transforming the landscape of both cybersecurity and cyberattacks. While millions of people without security expertise are creating software, bad actors are using AI to launch more effective attacks. XBOW fights back with AI-driven superpowers, enabling security teams to stay one step ahead. Our autonomous AI solves 75% of web app security benchmarks with zero human intervention—and at superhuman speed.

What makes XBOW truly unique? Like human experts, it forges creative attacks, adapts its learnings, and continuously works to find vulnerabilities faster than anyone ever could. We’re not only simulating threats—we’re also finding and responsibly disclosing real-world vulnerabilities, ensuring organizations can fix issues before they’re exploited. XBOW isn’t just a tool; it’s a transformative force in the secure development lifecycle.

Backed by Sequoia Capital and a team that includes the creators of GitHub Copilot and GitHub Advanced Security, XBOW is not just keeping up with the times—we’re shaping the future of cybersecurity. Our mission is simple: to defeat the bad actors before they strike, using AI to revolutionize how we approach offensive security.

We’re building something thatmust be built, and we’re the team to do it. Join us in shaping the next frontier of autonomous security.

Your Role: Application Security Consultant – Founding Services Team

We’re seeking a highly skilled Application Security Consultant to join our founding Services team as a key technical partner. You will work alongside Strategic Program Managers and Customer Success Managers to ensure customers realize the full value of XBOW through actionable, expert insights.

In this role, you’ll collaborate with a broad spectrum of stakeholders, including developers, AppSec engineers, and security leaders—both within customer organizations and internally.

What You’ll Do

  • Leverage your understanding of XBOW’s attack methodologies to surface meaningful insights, especially where deep security expertise empowers customers to make confident, informed decisions

  • Translate discovered exploits into business context and risk impact, guiding customers toward the most effective remediation strategies for their specific environments

  • Communicate confidently across a range of personas, from developers and AppSec engineers to CISOs—adapting your style to meet their needs and priorities

  • Influence product direction by identifying gaps between customer needs and current capabilities, working directly with our research and engineering teams to evolve how security insights are delivered at scale

  • Build lasting customer relationships through technical depth and responsiveness—earning trust, driving satisfaction, and contributing to retention and expansion, even when you're not the primary account owner

Who You Are

  • You have deep experience in application security, with a strong grasp of modern web technologies, common vulnerabilities (e.g., OWASP Top 10), and secure development practices

  • You're skilled at translating technical findings into business impact and risk narratives that resonate with both engineers and executives

  • You communicate with clarity and empathy, able to adjust your tone and depth whether you're speaking to a CISO, an AppSec lead, or a front-end developer

  • You’re customer-obsessed: responsive, pragmatic, and always thinking about how to deliver maximum value

  • You thrive in ambiguity and enjoy building from the ground up, whether that’s a new process, a customer engagement model, or feedback loop with Product

  • You’re a team player who enjoys cross-functional collaboration and knows how to earn trust quickly

  • You’re comfortable digging into a codebase, analyzing attack paths, and making confident recommendations without needing a detailed script

Requirements:

  • Hands on experience in application security, offensive security, or a related technical security role

  • Strong understanding of modern web architectures, authentication/authorization models, and common vulnerability classes (e.g., OWASP Top 10, business logic flaws)

  • Proven ability to interpret and contextualize security findings, prioritizing based on real-world risk and business impact

  • Hands-on experience collaborating with engineering and security teams to drive remediation and improve application posture

  • Excellent communication skills, with the ability to tailor technical depth and tone to suit developers, security engineers, and executive stakeholders

  • Comfortable analyzing source code, reviewing logs, and investigating exploitability without relying on prescriptive checklists

  • Experience working directly with customers or clients in a consultative, advisory, or customer success capacity

  • Ability to thrive in a fast-paced, ambiguous environment and contribute to early-stage team building and process development

  • Prior red teaming, pentesting, bug bounty, or exploit development experience is a strong bonus

What We Offer

  • Compensation & Equity: Competitive salary and a meaningful equity package—you’ll be a true owner in what we’re building

  • Customer Impact: Help hundreds of customers succeed with AI-driven security at scale

  • Career Growth: Shape how we deliver customer success in a high-volume, high-leverage environment.

  • Mission-Driven Team: Join a company that’s not just following the AI wave—we’re defining what the future of security looks like

What Else You Should Know

Location: Remote in the US (all team members are remote but we meet regularly and you’re supported to travel to collaborate with colleagues in person)

Contract: Full-time.

Hiring Process:

  • 30-min introductory chat.

  • Interview with our Head of Product & Customer Success (~60mins)

  • Interview with our Head of Security

  • Take home working session relevant to the role

  • Presentation of working session artifacts

  • Final conversation with our CEO and founder, Oege de Moor

We’re looking for someone who brings empathy, urgency, and clarity to the self-serve customer journey. If you’re excited to support our mission and help shape the future of scaled customer success at XBOW, we’d love to talk.

Even if you don’t meet every requirement, we encourage you to apply. We value curiosity, resilience, and people who are excited to build the future of security with us.

Interested in this job?

Application deadline: Open until filled

Logo of XBOW

XBOW

Boosting offensive security with AI

See more jobs
Date PostedMay 28th, 2025
Job TypeFull Time
LocationUS remote
Salary$150,000 - $250,000
Exciting remote opportunity (requires residency in United States) for a Application Security Consultant (founding team) at XBOW. Offering $150,000 - $250,000 (full time). Explore more remote jobs on FlexHired!

Safe Remote Job Search Tips

Verify Employer Thoroughly

Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.

Never Pay to Get a Job

Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.

Safeguard Your Personal Information

Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.

Scrutinize Communication & Interviews

Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.

Beware of Unrealistic Offers

If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.

Insist on a Formal Contract

Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.

Related Jobs

Full Time
$175,000 - $275,000
US remote
Full Time
$150,000 - $250,000
US remote
Full Time
$244,500 - $275,600
US Remote

Subscribe Newsletter

Never miss a remote job opportunity. Subscribe to our newsletter today and receive exclusive job alerts, career advice, and industry insights delivered straight to your inbox.