SubImage maps infrastructure the way an attacker does so security teams at scale-ups and enterprises can find and fix problems. We’re built on Cartography, the open source tool our founders helped create at Lyft that’s now a CNCF project, adopted at over 70 companies.
We are a seed stage company (a mighty team of 4!) but are growing rapidly - our customers are companies and organizations that your parents have heard of. We need engineering help to meet the demand! This is your chance to get in on the ground floor of something big. Or at least, figure out very quickly that this won’t work (it’s startup life; just being honest about it).
Novel engineering problems you’ll work on
We’re seeking the holy grail in multiple security challenges.
Can we triage and contextualize security vulnerabilities? This problem goes deep: Are the vulns on internet-facing assets? Via which active services? What is the full path? Are the vulnerable functions truly reachable from a code perspective? Are there any compensating controls at play that make the vuln invalid? Once exploited, does the vuln grant access to sensitive data? Via what providers, and via how many hops?
Any agent can generate code now. How can we prove that the security fixes our agent proposes will not break anything?
How do we build a near-real time, self-updating map of our environment so that we can see and stop attacks as they happen?
How do we teach an agent to answer questions about our graph very quickly, while making sure that it has just the context that it needs, without making mistakes?
How do we correctly determine the owner of a given resource based on environment heuristics like actions, tags, logs, files?
How do we reliably and sustainably track and manage the state of compliance processes like vulnerability management?
... continue reading