Who gets hired, and where they land
Oneleet, a Y Combinator-backed compliance automation platform that raised a $33 million Series A in October 2025, TechCrunch reported, has grown to roughly 75 people serving more than 750 customers, including two-thirds of the YC portfolio. The company was founded in 2022 by Bryan Onel, his wife Ora, and college friend Erik Vogelzang. Onel's thesis emerged from his penetration-testing career: compliance platforms had become compliance theater — evidence-collection tools that spit out certificates while leaving actual security gaps unaddressed. His clients kept asking for a better way. The workforce is remote-first, globally distributed, and organized around a product that bundles automation, penetration testing, audit support, and continuous monitoring into a single platform.
Engineering makes up the largest share of headcount, split across several specialized tracks. The endpoint security team builds a cross-platform agent (Windows, macOS, Linux) in Go and JavaScript that runs on customer devices and feeds telemetry back to the platform. A separate AI implementation track integrates large language models into the compliance workflow: gathering contextual security data, calling and optimizing AI services, and mapping responses into actionable UI built with React. Integrations engineers connect the platform to the dozens of tools customers already use (cloud providers, identity systems, CI/CD pipelines) while application security engineers harden the product itself. The board's own listings show these roles clustering in a $110,000–$180,000 base range, with application security engineering reaching $160,000–$220,000, Zero G Talent's board data shows.
Product and design sit adjacent to engineering but carry distinct mandates. The product manager for the code security suite owns direction across SAST, SCA, DAST, IaC scanning, secrets detection, and container scanning, essentially the entire static and dynamic analysis surface. A senior product designer, listed at $120,000–$190,000, shapes the experience for security teams and auditors alike, translating complex control mappings into interfaces that don't require a compliance background to navigate.
Security and compliance expertise lives in its own function. Framework engineers research and map regulatory frameworks (SOC 2, ISO 27001, HIPAA, GDPR, PCI) to the company's internal control library, maintaining automations that reduce what Onel calls security theatre. Security program managers operate as part-vCISO, part-account manager: they assess client posture, design custom security programs, liaise with external auditors, and guide implementation. This role demands hands-on compliance experience and the ability to translate between auditor language and engineering reality.
Go-to-market talent is lean but technical. A GTM AI engineer owns the data infrastructure layer (HubSpot, Dreamdata, advertising platforms, PostHog, website analytics) feeding a BigQuery warehouse that powers attribution and pipeline analysis. The role signals that Oneleet treats its own growth engine with the same engineering rigor it applies to the product.
Across functions, the company signals a consistent profile: engineers who have felt the pain of fragmented security tooling, compliance practitioners who have watched checklist-driven audits miss real risk, and builders frustrated by the status quo. The job descriptions name it explicitly: "rebels with a cause," "opinionated but not obstinate," "clear communicators who own their ideas and follow through." The through-line is domain fluency: you don't just write code or run processes; you understand why a control exists, how an auditor evaluates it, and where an attacker exploits the gap between the two.
The pay picture
Oneleet compensates like a Series A cybersecurity company that raised $33 million and targets engineers who want enterprise-grade security work without legacy-vendor bureaucracy. The company's job board shows a salary band running roughly $77,000 to $187,000 with a median of $180,000. That median sits above the typical early-stage startup range but below the $200,000–$350,000 senior engineers command at mature enterprise security firms, per Scoutify's market analysis.
| Role (location) | Salary range (USD/year) |
|---|---|
| Application Security Engineer (US / GB / NL / Remote) | $160,000 – $220,000 |
| Senior Product Designer (Remote US) | $120,000 – $190,000 |
| Fullstack Engineer (Remote US) | $120,000 – $180,000 |
| Application Software Engineer, Endpoint Security (Remote US) | $110,000 – $180,000 |
| Software Engineer, Integrations (Remote US) | $110,000 – $180,000 |
| Fullstack Engineer, AI Implementation (Remote US) | $110,000 – $180,000 |
The board data aligns with spreads posted on Y Combinator's Work at a Startup platform, which list bands from $70,000–$100,000 for junior roles up to $160,000–$220,000 for senior security positions. A European listing shows €70,000–€90,000 for Amsterdam-based roles, confirming geographic adjustment rather than a flat global rate.
Equity appears in the YC postings as 0.01%–0.05% for engineering roles. Oneleet's careers page describes the package as "competitive compensation & equity" without publishing a cap table or strike-price detail.
Benefits include health and wellness coverage, 20 days PTO plus eight floating holidays, and a remote-first culture backed by team off-sites in locations such as Amsterdam and Italy. The company frames these as often better than startups or big tech and highlights predictable schedules — a deliberate contrast to the chaos of earlier-stage ventures and the process-heavy calendars of incumbent compliance vendors.
For candidates comparing offers, the takeaway is clear: Oneleet pays at the upper end of the Series A security tier, reserves its widest bands for specialized security and AI-implementation talent, and couples cash with a standard venture equity structure and a benefits suite built for retention rather than recruitment flash.
Inside the interview loop
Oneleet's interview pipeline reflects its identity as a security-first, compliance-focused platform: structured, transparent, and weighted toward demonstrated technical depth over pedigree. Publicly documented stages cluster into four phases (automated screening, recruiter qualification, technical evaluation, and final human review), though the company does not publish a single canonical flowchart and candidate reports vary by role.
Automated screening and the referral multiplier
Every application passes through AI-assisted tooling that analyzes application data and identity signals to support, but not replace, human hiring decisions, as stated in the company's LinkedIn job postings. The system flags fraudulent submissions and scores qualifications against the role's hard requirements (years of Go/JavaScript experience, production API work, compliance-framework fluency) before a recruiter sees the file. All final hiring decisions remain with a human reviewer, and candidates can request accommodation or bias-audit results by emailing [email protected].
A single data point quantifies the referral advantage: LinkedIn listings for the Framework Engineer role note that referrals double your chances of interviewing at Oneleet. In a team of roughly 75, that multiplier is meaningful — internal referrals likely account for a disproportionate share of the 15 open roles listed on Work at a Startup as of September 2026.
Recruiter screen: mission alignment and "rebels with a cause"
The first human conversation tests two things: whether the candidate's technical baseline matches the posted requirements, and whether their motivation aligns with Oneleet's stated ethos. Job descriptions repeatedly call for "passionate self-starters with a growth mindset and a bias for action and personal accountability," "rebels with a cause, frustrated with the status quo and eager to disrupt it," and "opinionated (but not obstinate) builders, decisive yet collaborative." Candidates who frame their background around frustration with the current compliance space and how much security theatre there is (language lifted verbatim from the Framework Engineer posting) signal the mission alignment recruiters are trained to detect.
Technical evaluation: LeetCode, bug hunts, and system design
Glassdoor reports from Full Stack Developer candidates describe a consistent technical bar: one LeetCode easy-medium, a rundown of your thought process as well as any optimization you can provide, and identifying bugs in a few code statements. The emphasis on explaining optimizations and spotting planted bugs mirrors the day-to-day work of securing production APIs and integrating third-party services — core responsibilities for the Fullstack Engineer, AI Implementation role (5+ years Go/JavaScript, REST/gRPC, React).
Senior and specialized tracks (Application Security Engineer, Senior Product Designer) add architecture discussions and portfolio reviews. The board's first-party salary bands (Application Security Engineer at $160,000–$220,000, Senior Product Designer at $120,000–$190,000, according to Zero G Talent) imply a technical bar commensurate with mid-to-senior IC expectations at venture-backed enterprise SaaS companies.
Behavioral questions reported by candidates skew unconventional: "toughest subjects and favourite year in campus" appears in one Glassdoor account, suggesting interviewers probe intellectual honesty and learning trajectory more than rehearsed STAR stories. Scoutify's interview-prep material coaches STAR responses, but the company's own postings stress the aforementioned qualities over polished storytelling.
Final review and offer timeline
After the technical panel, a hiring committee reviews the packet. New York City candidates receive a statutory 10-business-day decision window per local law; other geographies move on a rolling basis. The company's geographic pay bands ("we hire globally and compensate competitively within each market") mean offer numbers adjust by location, but the equity component stays consistent with the Series A capitalization.
What distinguishes successful candidates
Three traits recur across role specifications, recruiter-facing language, and candidate debriefs:
Compliance fluency as engineering craft — not checkbox awareness. Framework Engineer candidates need strong working knowledge of major compliance frameworks paired with automation instincts (JSON, scripting). AI Implementation engineers must ensure AI features integrate smoothly with existing platform workflows and don't disrupt current user patterns — a security engineer's constraint mindset applied to LLM integration.
Bias for action in ambiguity: "thrive in ambiguity, and enjoys building processes from scratch" appears in both Framework and AI Implementation postings. With 75 people shipping a platform that handles those frameworks simultaneously, the organization rewards engineers who define the spec before writing the code.
Mission-coded frustration — the strongest signal is a documented history of hating compliance theater. Candidates who can cite a specific program they built, a framework they implemented, or a vendor they fired because the security posture was performative move faster through the pipeline. Oneleet's marketing positions the company as YC's most popular security compliance platform ending compliance theater; the interview process selects for people who have already fought that war.
The process is not fast — enterprise sales cycles and compliance audits set a deliberate cadence, but it is legible. Candidates who treat the application as a security review (evidence-based, scoped, automated where possible) tend to pass the same gates they'll later help customers clear.
Where the work gets done
Oneleet operates from two physical hubs (its legal headquarters in Wilmington, Delaware, and a European office in Amsterdam, Netherlands) while running a remote-first model that spans the United States, United Kingdom, and the Netherlands. The Wilmington address listed on LinkedIn (1111b S Governors Ave STE 6771, Dover, Delaware 19904) serves as the company's registered base; Crunchbase and Highperformr both confirm Wilmington as the headquarters location. Highperformr also notes the Amsterdam presence, and LinkedIn's company page lists both cities under "Primary" locations. Founded in 2022, the company grew from 25 employees in Highperformr's April 2025 snapshot to roughly 75 by the Series A close six months later.
The remote-first posture isn't aspirational — it's baked into every open role. Zero G Talent's board listings for Oneleet show consistent location tags: Application Security Engineer lists "US / GB / NL / Remote (US; GB; NL)"; Senior Product Designer, Fullstack Engineer, Application Software Engineer (Endpoint Security), Software Engineer (Integrations), and Fullstack Engineer (AI Implementation) all list "Remote (US)." This pattern signals that the engineering, product, and security teams are distributed across North America and Western Europe, with the Amsterdam office providing a European time-zone anchor for compliance work that often involves EU frameworks (GDPR, DORA, ISO 27001) and regional auditors.
That geographic spread maps directly to the product. Oneleet's platform automates evidence collection, risk assessments, penetration testing, and AI-driven questionnaire responses for frameworks spanning the core frameworks and PCI DSS, NIST 800-171, and FedRAMP. Building and testing those features (especially the AI modules that map controls across frameworks, review evidence against requirements, and draft security-questionnaire answers) requires engineers who can simulate multi-region cloud environments, integrate with identity providers and code repositories used by global customers, and validate penetration-test findings against production-like infrastructure.
The Amsterdam office plays a specific operational role. Several customer testimonials on LinkedIn reference EU-focused engagements (ISO 27001 certifications, DORA readiness, GDPR evidence reviews) and the company's marketing emphasizes localized support and expertise for European clients. Oneleet manages third-party auditor interactions directly. The Wilmington hub, meanwhile, aligns with the U.S. SaaS startup cohort that drives the bulk of SOC 2 and HIPAA demand; the company's Y Combinator S22 roots and Series A funding keep investor and partner networks concentrated on the East Coast.
Remote employees aren't second-class contributors. The board's salary bands (the aforementioned Application Security Engineer band, Fullstack Engineer (AI Implementation) at $110,000–$180,000) apply across locations, and the benefits structure (equity, health) extends to all salaried roles. The interview process evaluates candidates on the same technical depth and mission alignment whether they sit in Dover, Amsterdam, or a home office in Manchester. Synchronous design reviews cluster around overlapping hours, while async workflows (PR reviews, evidence audits, AI model evaluation) run continuously across the three time zones.
This setup also supports the company's penetration-testing practice. OSCE/OSWE-certified testers operate remotely, and Oneleet maintains the 24/7 protection monitoring it advertises — continuous attack-surface discovery and agent-based device policy enforcement that must run across customer fleets distributed globally.
In short, Oneleet's physical footprint is minimal by design: two small offices that anchor legal entity presence and auditor relationships, wrapped in a remote-first engineering culture that mirrors the compliance complexity its product solves.
Who stays and grows
The people who stay and grow at Oneleet share a recognizable profile: they treat security as an engineering discipline, not a paperwork exercise, and they operate with the urgency of a team that ships code used in production by companies closing enterprise deals. Customer reviews, founder statements, and the company's own hiring patterns converge on a handful of traits that correlate with long‑term success.
Security‑first, compliance‑second mindset. Every reviewer who mentions the compliance theater problem does so to contrast it with Oneleet's approach. The founder, Bryan Onel, frames the mission explicitly: companies pass audits while remaining easy to break into. Engineers and security practitioners who find that framing motivating (who would rather harden an endpoint than polish a policy document) self‑select into the organization. The board's open roles reinforce this: Application Security Engineer, Application Software Engineer for Endpoint Security, and Fullstack Engineer for AI Implementation all sit at the intersection of product engineering and offensive security. Candidates who view penetration testing and continuous monitoring as core product features, not afterthoughts, match the roadmap funded by the Series A.
Ownership that extends past the ticket. "We move fast, take ownership, and aren't afraid to disrupt stagnant business models" appears in the company's public culture statement, and customer reviews echo it. Multiple buyers describe the assigned security program manager joining sales calls, managing third‑party auditors end‑to‑end, and responding on Slack during weekends when emergencies hit. That pattern (a single point of accountability who can navigate both technical depth and commercial pressure) shows up in the hiring bar. The Senior Product Designer role (at the aforementioned range) and the Integrations Engineer role ($110,000–$180,000) both require shipping customer‑visible outcomes, not just internal tooling. People who treat "done" as "the customer's audit passed and the deal closed" thrive; people who treat "done" as "my PR merged" do not.
Direct, evidence‑based communication. Reviewers repeatedly call out direct and firm feedback, well reasoned answers, and the absence of a black box feeling. The platform explains both the fix and the reasoning behind each control; the vCISO pushes back on auditors when the finding is noise. Internally, that translates to a culture where disagreement is expected to be specific and grounded. The interview process screens for this: candidates who can walk through a real security finding, estimate remediation effort, and defend the priority against a product deadline signal the communication style the team relies on.
Comfort with ambiguity in integrations and domains. Oneleet's automation covers AWS, GitHub, Google Workspace, Cloudflare, and a growing list of SaaS tools — but customers still report missing integrations (Xero, HubSpot) and edge‑case breakage in irregular AWS setups. The Integrations Engineer and AI Implementation Engineer roles exist because the product must adapt to each customer's stack, not the other way around. Engineers who enjoy reverse‑engineering a weird API, designing a fallback when the webhook fails, and then codifying the pattern for the next tenant will find a steady stream of that work. Those who need a stable, fully‑specified contract before writing code will struggle.
Pragmatic prioritization over perfection. The tailored compliance program setup strips out irrelevant controls from the start so teams move faster without getting bogged down in requirements that don't reflect how their business actually operates. That philosophy (build the minimum viable security program that satisfies the auditor and actually protects the data) runs through product decisions. The platform pairs each finding with effort estimates so engineering leads can plan sprints. People who instinctively ask "what's the risk if we don't fix this?" and can articulate the trade‑off to a non‑technical founder fit the rhythm; people who default to "best practice says we must" create friction.
Remote‑first discipline with high‑bandwidth collaboration. The board lists every current role as remote across the US, UK, and Netherlands. Yet the customer experience depends on real‑time Slack support, joint sales calls, and weekend incident response. That duality (asynchronous autonomy by default, synchronous intensity when the customer needs it) selects for engineers who structure their own week but drop context fast when a P0 lands. The "work hard, play hard" line in the culture note is not a slogan; it describes a cadence of sustained sprinting toward audit deadlines followed by visible celebration when the report lands.
Mission alignment that survives the grind. Reddit threads in the research are blunt: the hard part about SOC 2 isn't the automation of collecting evidence; the hard part is actually being secure. Oneleet sells the hard part. Employees who join for the Series A momentum but leave when the integration backlog piles up are the ones who missed that the product is the grind — and that the grind is the differentiator. The ones who stay treat each customer's weird AWS configuration, each missing HubSpot connector, each auditor pushback as the actual work, not a distraction from it.
Onel still describes the company the same way he did in the YC batch: a penetration tester building the tool that would have made his job obsolete. The engineers who stay are the ones who want that tool to exist.
Working in frontier tech? Zero G Talent tracks the openings: see every open Oneleet role, browse frontier tech jobs, the companies hiring, and the people building the field.