Kybernao keeps missions running when the cloud is gone. We are a small team of security researchers, systems engineers, and hardware builders working on problems where the consequence is physical.
GuardianContainment plan opened · ready for review
Sentinel3/3 write vectors observed at OT boundary
FedSpaceLink restored · 3 findings synced at 9.6 kbps
NodeNODE-X thermal qualification passed · 55 °C
CommandRetest scheduled 21:00 · attaching log to finding
6 events4 engines0 cloud calls
0%remote-firstEngineers across four time zones. We meet in person a few times a year.
0node form factorsOne team ships hardware, graph, adversary emulation, and console.
0open rolesResearch, engineering, hardware, and go-to-market.
<0 wkstypical hiring loopFour steps. You always know where you stand.
Why this work matters
Most security tools assume a connection, a cloud, and a human on the other end. Our customers cannot assume any of those.
Real constraints
Denied, degraded, intermittent, and limited connectivity is the default. Every design decision is tested against a link that will not be there.
Physical consequence
A path through identity, cloud, and OT ends at a generator, a pump, or a radio. We measure success by whether the site keeps running, not by alert counts.
Whole-stack ownership
Node hardware, the terrain graph, adversary emulation, detection, and the operator console are one system built by one team.
How we work
Principles we hire for
These are the habits that show up in our best engineers. If they sound like you, we want to talk.
A finding is a working path, validated in a twin, with evidence attached. We hold ourselves to the same standard we hold the product to.
02
Assume the link is down
Design for the node alone first. Federation is a bonus, never a dependency.
03
Safety is a feature
Offensive capability against live processes ships with execution levels, operator control, and a way to stop. Always.
04
Write it down
Decisions, runbooks, and postmortems live in the open. Remote teams run on clear writing.
A week here
Deep work, real sites, and a written record
No stand-up theatre. Long focus blocks, one customer touchpoint a week for most engineers, and everything that matters written down.
MonDesign review
One written proposal, discussed for an hour, decided by the owner.
TueTwin run
Red replays this week's paths against the site twin. Sentinel measures.
WedRoute walkthrough
A mission engineer walks a customer through a path in Command.
ThuRetest window
Fixes shipped this week get re-attacked. Evidence goes on the finding.
FriWriting day
Postmortems, runbooks, and the changelog. No meetings after noon.
Open roles
Every role is remote-first. Some defense-facing roles require eligibility to work on US government programs.
About the role
Kybernao Red is the offensive engine of the platform. It proves attack paths through identity, cloud, and OT, first in a site twin and then, under explicit operator control, against live systems. You will design the techniques, the safety rails, and the evidence Red produces so an operator can trust every finding.
What you will do
Design and implement attack techniques across identity providers, cloud control planes, and lateral movement into OT networks.
Build the execution-level model (Observe, Twin, Live) and the controls that keep live validation non-destructive.
Turn every reproduced path into evidence a mission engineer can hand to a customer.
Pair with Sentinel and Guardian engineers so detections and containment close the loop on what Red finds.
What we look for
Six or more years in offensive security, red teaming, or adversary emulation.
Hands-on depth with at least two of: Entra ID or Okta, AWS or Azure control planes, Active Directory, Kubernetes.
A record of writing tooling, not just running it.
Comfort working where a mistake has physical consequence, and the judgement that comes with it.
Nice to have
OT or ICS experience (Modbus, DNP3, OPC UA, PLC engineering software).
Published research, CVEs, or conference talks.
Eligibility to work on US government programs.
Remote · US · Full-time · Research. Compensation includes salary and meaningful equity.
Atlas is the terrain graph: every asset, trust relationship, and physical dependency on a site. You will make sure the OT half of that graph is real. That means understanding controllers, protocols, and processes well enough to model what an attacker can reach, and what happens when they do.
What you will do
Model industrial assets, protocols, and physical processes so paths in Atlas end at real consequences.
Build passive discovery for OT networks that never sends a packet a plant engineer would not approve.
Design safe validation in the twin for paths that touch controllers, and define what "Live" may never do.
Work with customers on substations, plants, and facilities to ground the model in real sites.
What we look for
Deep familiarity with PLCs, HMIs, historians, and at least two industrial protocols.
Experience assessing or defending OT environments, ideally in energy or process industries.
Ability to read a P&ID or a one-line diagram and explain the consequence of a write.
Strong writing. Your findings are read by plant engineers, not just security teams.
Nice to have
Vendor engineering tool experience (TIA Portal, Studio 5000, or similar).
Safety instrumented systems knowledge.
Prior research publications in the ICS space.
Remote · Full-time · Research. Compensation includes salary and meaningful equity.
FedSpace is how sovereign Kybernao nodes share selected state when a link happens to exist. It has to work when the link is a few kilobits over SATCOM for ten minutes a day, and it can never make a node depend on it. You will own the design.
What you will do
Design the replication model: what state is shared, how conflicts resolve, and how trust between nodes is established and revoked.
Build bandwidth-aware sync that prioritises findings and containment state over bulk telemetry.
Define the security boundary so a compromised node cannot poison the federation.
Set the engineering bar for the team through design reviews and clear written decisions.
What we look for
Ten or more years building distributed systems in production, including at least one system with intermittent connectivity or partition tolerance as a core requirement.
Fluency in Rust or Go and a strong opinion about where each belongs.
Experience with CRDTs, log replication, or similar convergence models.
A habit of writing design documents before code.
Nice to have
Experience with tactical networks, SATCOM, or mesh radio.
Cryptographic protocol design.
Prior staff-level or principal role.
Remote · Full-time · Engineering. Compensation includes salary and meaningful equity.
Sentinel is detection that runs entirely on the node. Because Red has already proven the exact paths that matter on a site, Sentinel does not guess. You will turn those paths into detections, measure whether they fire, and feed the misses back to the team.
What you will do
Write detections for identity, cloud, network, and OT telemetry that execute locally with no reach-back.
Build the measurement loop: when Red replays a path, did Sentinel see it, and how fast?
Design the telemetry pipeline for constrained hardware, from NODE-S to NODE-R.
Tune for the environments our customers run: plants, substations, and vehicles, not office networks.
What we look for
Four or more years in detection engineering, threat hunting, or SOC engineering.
Comfort with Sigma, KQL, or equivalent, and with the raw logs beneath them.
Working knowledge of attacker tradecraft across identity and cloud.
Software engineering habits: tests, reviews, and version control for detections.
Nice to have
OT protocol telemetry experience.
Zeek, Suricata, or eBPF work.
Experience shipping on resource-constrained hardware.
Remote · Full-time · Engineering. Compensation includes salary and meaningful equity.
Command is the surface operators, defenders, and mission owners work in. It shows a route through the mission and the consequence at the end of it, and it has to be clear at 3 a.m. in a control room. You will own the console end to end, from the terrain graph to the retest log.
What you will do
Build and refine the findings board, containment plan review, retest logs, and the interactive terrain graph.
Design for operators under pressure: dense information, no ambiguity, keyboard-first.
Own performance on the node, including rendering large graphs on modest hardware.
Work directly with mission engineers and customers to see the console in use.
What we look for
Six or more years shipping production web applications, with deep TypeScript and modern front-end experience.
A portfolio that shows clarity under complexity, not just visual polish.
Experience with data visualisation or graph rendering at scale.
Care for accessibility and keyboard interaction as first-class requirements.
Nice to have
Security or operations tooling background.
Design skills strong enough to work without a mockup.
SVG, Canvas, or WebGL rendering experience.
Remote · Full-time · Engineering. Compensation includes salary and meaningful equity.
Kybernao Node carries the whole platform into a rack, a DIN rail, a backpack, or a vehicle. You will own the layer between the hardware and the platform: boot, trust, capture, and the power and thermal constraints that decide what the node can run.
What you will do
Own secure boot, measured boot, and hardware root of trust across the four form factors.
Build passive network capture that is provably passive on OT segments.
Characterise power and thermal envelopes and work with the platform team on what runs where.
Qualify hardware for rugged and industrial deployment, including environmental and EMC testing.
What we look for
Five or more years in embedded Linux or firmware engineering on shipping products.
Experience with TPM or secure element integration, U-Boot or UEFI, and kernel-level work.
Comfort with hardware bring-up, schematics, and lab equipment.
Understanding of network capture at the driver or NIC level.
Nice to have
Rugged or MIL-spec hardware experience.
Experience with Yocto or Buildroot.
Eligibility to work on US government programs.
Remote · US · Full-time · Hardware. Compensation includes salary and meaningful equity.
Each deployment is assigned a named mission engineer. You are the person inside Command with them: reviewing findings before they land, walking teams through paths, and designing how nodes deploy across their sites. This role is the product's reputation.
What you will do
Review every finding for your customers before it reaches them, so nothing false or unclear ships.
Run office hours and walk operators through paths, consequences, and containment plans.
Design site and edge deployments, from node placement to federation policy.
Feed what you learn back to product and research every week.
What we look for
Four or more years in security engineering, incident response, or solutions engineering with a technical depth customers trust.
Ability to read an attack path end to end and explain it to an operator and to an executive.
Strong writing and a calm presence in difficult conversations.
Willingness to travel to sites, roughly one week a month.
Nice to have
OT or defense customer experience.
Prior consulting or professional services background.
Eligibility to work on US government programs.
Remote · travel · Full-time · Go-to-market. Compensation includes salary and meaningful equity.
Kybernao Edge exists for missions that run disconnected. You will build the government side of the business: the relationships with mission owners, the path through acquisition, and the programs that take a pilot to production.
What you will do
Own the government pipeline from first conversation through pilot, contract, and program of record.
Work with mission owners to define deployments and success criteria that matter to them.
Navigate acquisition vehicles, compliance, and the partners needed to deliver.
Represent the customer inside the company and shape the roadmap for Edge.
What we look for
Eight or more years in defense or public-sector business development, program management, or a uniformed role with acquisition exposure.
A track record of taking a capability from pilot to program.
Working knowledge of relevant acquisition pathways and compliance regimes.
Credibility with technical and operational audiences alike.
Nice to have
Cyber or C2 domain experience.
Existing relationships in the communities we serve.
An active or recent clearance.
Remote · US · Full-time · Go-to-market. Compensation includes salary and meaningful equity.