07 Aug
|
rootline labs
|
Hyderabad
07 Aug
rootline labs
Hyderabad
We're building autonomous AI agents that break web applications before real attackers do—and we need our Founding Engineer.
Most security tools throw a wall of theoretical, static false positives at developers. We’re building Haven (rootline labs): a self-hosted AI penetration testing platform where coordinated agents run persistent recon, write working Proof-of-Concept (PoC) exploits, and chain minor flaws into full exploit paths.
The role This isn't a slice of a larger engineering org you'd be building the core of the product itself. You'll own the multi-agent layer: coordinating specialized agents (recon, exploitation, post-exploitation) so they hand off findings to each other and escalate a chain of small issues into a real exploit path, and pushing that toward an always-on model persistent parallel agents running continuously, not one-off scans kicked off by a CLI command.
What you'll do Design and build a multi-target, persistent agent orchestration layer
Design how agents coordinate — shared state, findings handoff, escalation logic
Build enterprise features: SSO, audit logging, compliance-ready reporting
Own the security logic itself — payload design,
exploit validation, false-positive reduction — not just the infrastructure around it
Ship rapid and alone, with minimal process
You probably have Python at a real engineering level — services and tools shipped to users, not scripts
Hands-on experience building agents: tool/function calling, multi-agent state sharing, context management (via LangGraph, CrewAI, AutoGen, or a custom framework)
Real offensive security depth: OWASP Top 10 fluency, hands-on exploitation experience, comfort with Burp Suite, Nuclei, sqlmap, nmap
Docker-based sandboxing and CI/CD (GitHub Actions is fine)
Mindset High agency — no one's writing tickets for you, you decide and build
Genuinely into both halves of this role (AI agents and offensive security) — one without the other won't work here
Comfortable being the only engineer, with real ambiguity, for a while
Nice to have Basic exposure to SSO, audit logging, or RBAC — it's on the roadmap
Prior work on an autonomous security or AI-agent product, open source or commercial
📌 Founding Engineer Hyderabad
🏢 rootline labs
📍 Hyderabad