Infisical (YC W23) Is Hiring Engineers to Build the Modern OSS Security Stack

YC startup wants US devs to “secure the AI era” — commenters roast and rally

TLDR: Infisical is hiring US-based engineers to build open-source tools for managing passwords and keys, touting speed and AI. Commenters split: some cheer a fresh alternative and open code, while others bash the US-only rule, AI-in-secrets hype, and “move fast” rhetoric in security. This matters because trust is everything.

Infisical, a Y Combinator–backed open-source security startup, posted a US-only role for a JavaScript whiz to help build tools that manage secrets (think passwords, certificates, and keys) plus new toys like PKI (public key infrastructure), SSH (secure shell), and KMS (key management service). The pitch: “generational company,” “high standards,” “bias toward action,” and maybe a dash of AI sprinkled on your secrets. The comments? Absolute fireworks.

The loudest camp scoffed at the AI angle: “AI handling my passwords? Hard pass,” with memes of chatbots “accidentally” tweeting private keys. Another hot thread torched the “move fast” vibe in security: folks warned that speed plus incomplete info equals leaks, not locks. Meanwhile, devs outside the US dragged the “remote, but US-based” requirement, calling it open-source hypocrisy. Others countered that enterprise customers and compliance sometimes force US-only hiring. Cue the popcorn.

A third faction defended Infisical as a rising alternative after license drama at competitors, praising open-source transparency and linking to their GitHub and careers page. Skeptics questioned “JavaScript for security,” while pragmatists noted JS for the app and Go for heavy lifting. Jokes flew: “Move fast and encrypt things,” “SSH = Surely Someone Hacks,” and “PKI stands for Pain Keeps Intensifying.” Somehow, lunch stipends became a meme too: “Free sandwiches won’t fix 2am cert rotations.” Delicious discourse.

Key Points

  • Infisical is hiring a US-based Full Stack Engineer to build and expand open source security products for secrets, PKI, SSH, and KMS.
  • Role responsibilities include working with the CTO, communicating with enterprise customers, and exploring AI applications in security infrastructure.
  • Required skills: React.js, Node.js, TypeScript; bonuses include Go, devops/tooling knowledge, startup/founder and open source experience, and strong communication.
  • Infisical operates remotely with a San Francisco office, offers salary and equity plus benefits like a lunch stipend and work setup budget.
  • Infisical manages over 1.5B secrets monthly, has customers such as Hugging Face, Lucid, and LG, and has raised $19M (plus a prior $3M) from YC, Google/Gradient Ventures, and notable angels.

Hottest takes

“AI touching my secrets? That’s a nope from me” — keysmashking
“Open source but US-only… pick a lane” — eurodev_404
“Security isn’t where you ‘bias toward action’” — cautious_cat
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.