AI is collapsing the cost of offense. What used to require a skilled exploit developer can increasingly be automated, and defenders are still working from tooling that was designed two decades ago: tools that produce endless lists of findings without telling anyone what actually matters or what to do about it.
Hinoki is building the AI-native platform that fixes this. We continuously map an enterprise's real exposure, figure out what is genuinely dangerous in the customer's specific environment, and drive the remediation through to verified resolution. Old scanners produce lists. We produce fixes.
We're backed by Andreessen Horowitz and led by a second-time security founder, most recently from Google. The platform is already in production at Fortune 500 enterprises.
This is a critical engineering hire to own our frontend end-to-end. You'll be responsible for the product surface our customers interact with every day. That includes the verification flows where analysts confirm our agents' work, investigative features where security engineers confirm vulnerabilities on remote assets using AI agents, and the reporting surfaces where investigations turn into reports.
We are looking for someone who treats frontend as a specialty and pushes the boundary of frontend performance. If optimizing React and diving into the latest RSC innovations excite you, then you would find this role very fun.
What we're looking forThree to six years of engineering experience, plus:
Deep React expertise. You should be the person other engineers come to when they hit a wall in React. Reasoning about the rendering model and hook internals shouldn't require a trip to the docs, and you've spent enough time in DevTools to know what a bad render trace looks like at a glance. Bonus if you've been following the RSC work closely or have strong opinions on Suspense boundaries.
A point of view on performance. Tell us what you measure and why, and walk us through a piece of performance work you're proud of.
Product sense. Show us something you shipped where the small details actually show. Things like empty states that don't feel like an afterthought, tiny shortcuts that users naturally discover, motion that helps comprehension instead of decorating.
AI-native workflow. Claude Code, Codex, or Cursor is in your daily loop. You can articulate where these tools help and where they don't.
High agency. You read a plan doc and ship. You don't wait for design tickets. You fix what's broken regardless of whose code it is.
Taste for small, reversible changes. You know when to extract a component and when to keep markup inline. You don't ship 800-line refactors when 30 lines would do.
We work in TypeScript and C++ but care more about engineering depth than specific languages. No security background required. We'll teach you the domain.
Skills Required
- Three to six years of engineering experience
- Deep React expertise (render model, hooks, rendering optimization)
- Point of view on performance and experience executing performance work
- Strong product sense with attention to UX details
- Daily use of AI coding tools (Claude Code, Codex, or Cursor)
- High agency and ability to ship from plan docs without handholding
- Taste for small, reversible changes and pragmatic refactoring
- Experience with TypeScript
- Experience with C++
- Familiarity with React Server Components (RSC) and Suspense boundaries
What We Do
Hinoki Security is building an AI-native platform to combat the collapsing cost of cyber-offense. The company continuously maps an enterprise's real exposure, determines what is genuinely dangerous within a customer's specific environment, and drives remediation through to verified resolution, replacing old scanners that only produce lists of findings with a system that produces actual fixes.
.png)





