Casco's Mission and the Rise of AI-Specific Threats
The security playbook that protected software for two decades has a blind spot the size of a large language model. Enterprises are deploying AI agents into production, including customer-facing chatbots, autonomous coding assistants, and decision-making pipelines, while the tools and teams meant to secure them are still calibrated for static code and known vulnerability classes. The gap isn't theoretical. It's showing up in incident logs, insurance claims, and board-level risk registers faster than most security organizations can hire for it.
Casco was founded in 2025 by Rene Brandel and Ian Saultz, who met building the Generative AI team at AWS. Brandel served as Lead Engineer and Security; Saultz was Head of Product. From that vantage they watched enterprises adopt AI agents faster than their security stacks could adapt. Traditional scanners, built for deterministic code paths, returned noisy, low-signal findings against probabilistic models. Manual red-teaming, thorough but expensive, couldn't scale to the velocity of new model releases and prompt-injection variants. The founders concluded that the only way to close the gap was to automate the attacker. They built AI agents that red-team other AI agents, and supervise those agents with human expertise forged at AWS, Microsoft, and government programs. Their mission: empower builders to innovate confidently, knowing their AI systems are secure.
Gartner's 2024 AI Security Survey found that 73 percent of enterprises experienced at least one AI-related security incident in the prior 12 months, with an average cost of $4.8 million per breach. IBM's 2024 reporting put the breach rate at 13 percent of organizations, with another 8 percent unsure whether they had been compromised. Detection and remediation take 40 percent longer for AI incidents than for conventional ones, according to the same Gartner data. Sixty percent of known AI incidents led to compromised data; 31 percent caused operational disruption.
Existing tooling fails on three fronts. Automated scans produce low-quality, noisy findings that drown security teams in false positives. Thorough human-led evaluations are cost-prohibitive for all but the largest enterprises. New attack vectors, including prompt injection, model extraction, data poisoning, and agent hijacking, are emerging faster than signature-based defenses can be updated. Casco's response is supervised, agentic red-teaming. Autonomous attack simulation mimics expert human red-teamers, devising and executing multi-step attacks against AI agents and applications, with findings validated by a team that has built and secured AI systems at hyperscale. The output is compliance-ready reporting mapped to SOC 2, NIST AI RMF, EU AI Act, and ISO 27001. The company already secures AI systems deployed in 60 percent of the Fortune 500 and counts Gusto, CrewAI, Novig, and Accrual among its 100-plus customers.
That traction, and the incident data behind it, is why Casco is hiring now. The technical bar for its five open roles is set accordingly.
Inside Casco's Open Roles: What They're Actually Building
Casco's hiring push centers on a single, well-documented engineering role. The Software Engineer position is detailed with two additional roles named in public listings: Customer Success Engineer and Offensive Security Engineer. The company's careers page and Y Combinator posting detail the Software Engineer role at $200,000 base salary with 0.1–1% equity, a reflection of its P25 YC batch status and a ten-person team where 80 percent are ex-AWS veterans who have shipped products for millions of developers. The role is remote-first with a preference for San Francisco or Seattle candidates; Seattle teammates work remotely and meet regularly.
The work itself is not abstract. The Software Engineer owns features from conception to production on an agentic red teaming platform that conducts autonomous security assessments across web apps, APIs, cloud infrastructure, and AI systems. The job description is explicit: "Design and implement autonomous agents that conduct security assessments. If you've built agents before, you know how wild this space can be." Candidates need deep TypeScript expertise, plus cloud-native distributed systems experience and a track record of shipping in fast-paced environments. Security domain knowledge is not required upfront, but the posting demands genuine excitement to learn how hackers think, because the agents must replicate attacker logic end to end.
That logic was validated in a real-world campaign against Hugging Face, where an autonomous agent breached a Kubernetes cluster, harvested credentials, and persisted for four and a half days while generating 17,600 detection events. Noise that buried the signal. Casco's platform aims to run those same campaigns continuously and legally, giving enterprises visibility before adversaries do. The EU AI Act's August 2026 deadlines, which mandate adversarial testing of AI controls, add regulatory urgency to the technical challenge.
The interview process mirrors the work: a 30-minute founder chat on agent experience, a 45-minute technical walkthrough of something the candidate has built, and a paid one-week work trial on a real problem with the team. The company frames it as mutual fit, but the trial also functions as a live evaluation of autonomous decision-making under ambiguity, the same trait the agents must exhibit.
The two named companion roles signal where the product edges meet customers and deeper offensive expertise. A Customer Success Engineer translates agent findings into remediation guides for engineering teams; an Offensive Security Engineer likely shapes the attack logic the agents execute. Neither role's specifications appear in the current research, so their exact scopes remain undefined here. What is defined is the through-line: every hire extends a platform that turns red teaming from a periodic human exercise into a continuous, agent-driven capability. The screen filters for engineers who have already built autonomous systems, understand the chaos of cloud environments, and can ship TypeScript that survives contact with production. Because the agents they build will operate without supervision, and the vulnerabilities they find are real.
What Gets You Past Casco's Screen: Skills That Matter
Casco's job descriptions read like a taxonomy of the modern attack surface. The screening process filters for engineers who have already mapped it. The company is explicit: candidates need proven depth in at least two traditional offensive domains. The listed pillars are web application security, cloud security across AWS, Azure, and GCP, network penetration testing, and API security testing. A resume showing only one of those four gets deprioritized. The bar isn't familiarity; it's the ability to execute comprehensive, white-glove manual penetration tests across those environments and produce detailed, actionable reports with clear remediation guidance.
That traditional foundation is table stakes. The differentiator is adversarial machine learning. The adversarial ML engineer role demands strong experience in AI security research and hands-on work with LLM-based systems spanning OpenAI, Anthropic, and open-source models. The description lists specific attack vectors candidates must understand: prompt injection techniques, model jailbreak methodologies, AI system exploitation vectors, guardrail bypasses, agent and tool-chain misuse, dangerous-capability evaluation, API abuse, data poisoning, model inversion, and membership inference. These aren't academic categories. The role requires performing hands-on adversarial testing across models, applications, agentic layers, and data pipelines.
Python fluency is non-negotiable. Both the offensive security engineer and adversarial ML engineer postings call for strong Python skills and experience building custom attack tooling or experimentation frameworks. Casco's engineers don't just run scanners; they develop custom exploits, tools, and methodologies to identify complex vulnerabilities. The offensive security engineer description emphasizes contributing to security-focused software and tooling within the engineering team and collaborating to improve and refine automated security testing capabilities. The software engineer role frames it more bluntly: "You'll be crafting the core of our agentic red teaming platform, think autonomous systems that discover vulnerabilities while you sleep."
The screening also weighs how candidates bridge human expertise and AI-driven assessment. Casco's model pairs expert security engineers with an autonomous pentesting agent that can perform hundreds of security tests in parallel. The offensive security engineer role explicitly requires reviewing, validating, and enhancing findings generated by the agentic red teaming platform. That means candidates must understand how to audit autonomous output, not just produce their own. Research instinct matters too — the job descriptions single out researching emerging attack vectors, particularly those involving AI/LLM systems and applications, and driving innovation in offensive security methodologies at the intersection of traditional pentesting and AI-assisted assessment.
Communication appears as a hard requirement, not a soft skill. Both roles call for partnering with customer engineering teams to ensure security findings are properly understood and addressed. The offensive security engineer must produce detailed, actionable security assessment reports with clear remediation guidance. In a consulting-heavy model where Casco Supervised delivers year-round protection and penetration test reports for SOC2 and ISO27001 compliance, the ability to translate technical findings into executive-ready artifacts is part of the job.
The composite profile Casco is hiring for doesn't exist in most security teams. It's a pentester who has already crossed into AI red teaming, writes production-grade Python tooling, and can validate autonomous agent output. The five open roles all orbit that intersection. Candidates who clear the screen typically show a portfolio of custom exploits, published research on LLM vulnerabilities, or open-source tooling they've built for AI safety testing. Generic certifications and checklist pentesting experience don't move the needle.
Why Casco's Approach Is Gaining Traction in Enterprise AI
Traditional security tools were built for a world where code is trusted and data is not. That model breaks down the moment an AI agent starts retrieving documents, calling APIs, and acting on instructions that arrive as indistinguishable tokens. Web application firewalls, data loss prevention suites, and runtime monitoring stacks operate at layers that never existed for these systems. They validate input the way a human would, but an agent cannot tell the difference between a legitimate command and a prompt injection buried in a retrieved document. The result is a security gap that grows wider with every autonomous action the agent takes.
What enterprises are discovering is that the attack surface of an agentic AI system is not a single perimeter but a constellation of trust boundaries. Each tool an agent can invoke, each memory store it consults, each API it calls represents a distinct point of compromise. A poisoned document in a RAG pipeline can redirect behavior without the attacker ever touching the model directly. A malicious tool description can expand the agent's capabilities beyond what its developers intended. And because agents compress the kill chain, turning what used to be a multi-day intrusion into a single autonomous interaction, the window for detection closes fast.
Casco's response is to treat agentic red teaming as a continuous, adversarial exercise rather than a point-in-time audit. The company's platform simulates sophisticated attacks across what it describes as 320-plus attack vectors, probing each component of an agent's workflow to find the paths by which an attacker can make the system act against its owner's intent. This is not about patching a static vulnerability; it is about mapping the dynamic interplay between planning, tool use, memory, and execution that defines an agent's behavior.
The urgency behind this approach comes from real-world deployment patterns. As of mid-2025, 65 percent of enterprises were deploying or piloting AI agents, yet fewer than 30 percent had systematic AI security testing in place. The mismatch is stark: agents are being given standing credentials far beyond what any individual task requires, they trust the content they retrieve by default, and they lack enforced boundaries between planning and acting. Casco's model pushes back against all three weaknesses by running multi-step attack simulations that mirror the same autonomy the agents themselves possess.
This is where the offensive and defensive sides of AI security converge. The same autonomy that makes agents risky also makes them useful as red team operators, capable of running continuous adversarial testing that re-runs as the target evolves. But Casco's framework keeps human expertise at the center: agents widen coverage and run continuously, humans design the campaign, verify the findings, and own the result. The company's research has found that a simple, scalable black-box attack achieved an 89 percent success rate against GPT-4o and 78 percent against Claude 3.5, working across text, vision, and audio modalities. Those numbers do not come from theoretical analysis — they come from running the attacks and watching them succeed.
For enterprises, the alternative to proactive simulation is reactive incident response. A prompt injection that manipulates an agent into exposing customer PII means the CISO gets the 2 AM call. A hallucinated financial recommendation that costs a customer money brings legal into the conversation. Compliance auditors asking for six months of runtime safety logs that were never collected turns into a regulatory problem. Casco's approach tries to surface those failures before they happen, by finding the unauthorized actions an agent can be induced to take using credentials the enterprise does grant, against systems the enterprise does control.
The gap between AI adoption and AI security is widening, and early movers who get this right are already positioning themselves ahead of the next wave of incidents. Those who wait for a public breach will pay a much higher price, not just in remediation costs, but in the trust that took years to build.
The Broader Signal: AI Security Hiring as a Market Leading Indicator
Casco's five open roles are not an isolated bet. They sit inside a capital shift that started showing up in budget forecasts before it appeared on job boards. Kings Research puts the global AI-powered threat detection and response market at USD 5.59 billion in 2024, projecting USD 23.52 billion by 2032, a 20 percent compound annual growth rate. EY reports that as AI-linked cyber incidents rise, the share of cybersecurity budgets allocated to AI solutions is expected to increase significantly. Leaders surveyed expect agentic AI to become more central in cyber defense over the next two years, with AI governance emerging as a key driver of cyber resilience.
The SANS AI Cybersecurity Careers Guide, published in May 2026, states plainly: "The cybersecurity career landscape looks different than it did a year ago, and AI is why. New roles are emerging, existing roles are evolving, and the skills that matter most are shifting fast." That guide maps six new certification paths: SEC536 for adversarial AI penetration testing, GAIPT for AI penetration testers, SEC546 for securing agentic AI, SEC411 for AI security principles, SEC545 for GenAI and LLM application security, and GAIPS for AI platform security. Certification programs do not launch for roles that do not exist.
Deloitte's mid-decade aerospace and defense outlook identifies the same convergence: digital transformation, supply chain volatility, talent constraints, and geopolitical events are meeting new catalysts including agentic AI and autonomous systems. Defense contractors are not waiting for standards bodies to finish their work. They are hiring red-team engineers who can probe multi-agent systems, multilingual targets, and multimodal inputs, the same scope Casco's roles demand.
The technical validation layer is hardening in parallel. NIST's large-scale red-teaming competition across 30 LLM challenges drew 1,674 participants and 214,271 attack attempts. Automated approaches achieved a 69.5 percent success rate versus 47.6 percent for manual efforts. Dawson et al. 2025 introduced AIRTBench, 70 black-box challenges measuring autonomous AI red-teaming capabilities, finding frontier models solve up to 61 percent of challenges with efficiency advantages exceeding 5,000× over human operators on difficult tasks. The catalog of known adversarial techniques now exceeds several dozen distinct strategies, each with its own parameterization, strengths, and failure modes.
Open-source tooling is commoditizing the baseline. PyRIT, Garak, Promptfoo, Garrick, PromptBench, and Microsoft's Pyit can run systematic vulnerability scans in deployment pipelines. The Dreadnode SDK agent creates workflows grounded in 45-plus adversarial attacks, 450-plus transforms, and 130-plus scorers, compressing weeks of manual workflow assembly to hours. But tooling raises the floor, not the ceiling. As one practitioner noted, red teaming is not a one-time event; it is continuous, especially as systems evolve and adversarial techniques improve.
Interviewers at top companies are starting to probe candidates on threat modeling, adversarial testing, and layered defense. Engineers who can speak to those domains stand out in any senior AI interview. Infosecwriteups calls agentic AI red teaming "not only the hottest cybersecurity role of 2026 — it may be one of the most important security jobs of the next decade."
Casco's hiring window reflects that trajectory. The company is not staffing for a pilot; it is staffing for a product line that enterprises will buy repeatedly as their agent fleets expand. The five roles span agent architecture, adversarial ML, evaluation infrastructure, and platform engineering, mapping directly to the capabilities the market is pricing at a premium. When certification paths, budget forecasts, defense procurement signals, and competitive benchmarks all point the same direction, a five-role hire is a lagging indicator, not a leading one. The lead happened last year.
Working in frontier tech? Zero G Talent tracks the openings: see every open ASML role, browse frontier tech jobs, openings at Stripe, and the people building the field.