apPosture is a self-hosted ASPM platform that does not just find security gaps - it proves them, with a captured request, response and exploit evidence. If that bar excites you, you will fit in here.
We ship findings only when the engine can prove exploitation. That bar shapes how we hire, review and build - no theatre, no vanity metrics.
A compact team of specialists who own real surface area. You will not be one voice in fifty - your work is in the product within the week.
Everything runs self-hosted and air-gapped. We build for finance, government and critical infrastructure, where data cannot leave the building.
Based in Baku, open to remote across compatible time zones. We optimise for deep focused work, not seat-time.
Competitive salary and meaningful ownership in an early, technical company.
Conferences, courses, CVE research time and the hardware to do it. Staying at the frontier is part of the job.
You pick up whole capabilities, not tickets. What you build ships and gets used against real targets.
Medical cover and a genuine respect for rest - a security tool must never be built by burned-out people.
Deep-work friendly. We care that the engine gets sharper, not when you were online.
Autonomous exploitation, taint analysis, reachability, LLM-assisted triage. The hard, unsolved parts of AppSec.
We hire slowly and deliberately. If you want to teach a machine to think like an attacker, start here.
apPosture will never ask for payment or financial details during hiring, and every official message comes from an @apposture.com address. If in doubt, write to careers@apposture.com.