Work on the scanner that refuses to bluff.

Most security tools are confident about everything. Webcuris publishes how sure it is about every single finding — and which tests it deliberately refuses to run, because the conclusive version would be the attack itself. That one decision shapes the whole product, and everyone who works on it.
What you would be working on

46 checks, across websites, repositories and the AI systems teams have started shipping without anyone reading the code. Certificates, headers, exposed secrets, vulnerable dependencies, cloud buckets somebody left open, prompt-injection surfaces that did not exist two years ago.

The interesting part is not the number. It is that every finding says how sure the engine is, and that the checks it will not run are written down with the reason — because the conclusive test for a whole class of vulnerability is the attack itself, and running it against somebody's live business is not a feature.

That restraint is the product. It is why a finding here can be taken to an engineer without being re-verified first, and it is what you would be representing.

Assets plotted, swept continuously

Why people take a role here

The product earns the meeting

You do not talk anyone into a demo. You point the scanner at a domain the prospect already owns, and forty-six checks come back with evidence attached. The conversation starts after they have already believed you.

Decisions take hours, not quarters

There is no committee to convince, no planning cycle to wait for, and no roadmap ritual between an idea and it being live. If something should change on Tuesday, it changes on Tuesday.

You will never have to walk anything back

Every finding carries how confident the engine is. The checks it refuses to run are published, with the reason, before anyone signs up. Nothing you say in a sales call has to be quietly corrected later.

Remote, and judged on output

No core hours, no reporting lines, no office to live near. What you produce is the whole of the assessment.

Open role

Everything a role pays, and everything it does not, is on its own card before you open it. Nothing important is kept behind the click.

15% recurringUp to 12 months per customer

Sales / SaaS Growth Partner

Sell a security scanner that demos itself. You point it at the prospect's own domain or repository, and the findings do the talking.

Purely commission-based. No salary, no retainer, no expenses.

Sales / SaaS Growth Partner

Commission
15% recurring
Paid for
Up to 12 months per customer
Location
Remote, anywhere
Hours
Yours

The commission — read this part properly

15% recurring, for up to 12 months per customer, or as long as they stay subscribed — whichever is shorter.

Not 15% of the first invoice. 15% of every month they pay.

PlanCustomer paysYou keep, monthly100 × 12 months
Pro$39/mo$5.85$7,020
Business$79/mo$11.85$14,220

Close 100 accounts over a year and you don't start next month from zero — you start from a book that's already paying. No cap, no territory, no cannibalised commission.

The honest part

What this is not

Purely commission-based. No salary, no retainer, no expenses — you cover your own hardware, internet and tools.

If you need guaranteed income this month, this isn't the right role, and I'd rather say that now than waste your time.

What you get instead

No ceiling, no core hours, no reporting lines.

Real early-stage upside, with a founder who answers the same day.

Must-haves

  • English at C1 or better.
  • B2B sales experience — ideally SaaS, or something technical.
  • Comfortable generating your own pipeline. We won't hand you lists.
  • Enough technical curiosity to hold a conversation with a CTO without bluffing.
  • Your own hardware, a stable connection, and the discipline to work unsupervised.

Nice to have

  • A network in startups, dev agencies, fintech or security.
  • Familiarity with developer workflows, CI/CD or AppSec tooling.
  • Experience selling a self-serve product.

Why this is easier to sell than most security tools

Signup is free and takes a minute. You don't talk anyone into a demo — you point the scanner at their own domain or repo and let the findings talk.

Prospects arrive at the call already believing you.

How to apply

Tell me what you have sold and to whom. A scan of a domain you think is badly configured, with what you would say to its owner, is worth more than a CV.

Nothing here fits, but you think you should be working on this?

Say so. Roles here get created around the right person rather than the other way round, and a good argument does not have to survive three rounds of approval to become a job.

Write to us

Contact

Talk to us.

Questions about what the engine checks, whether it fits your estate, or what it deliberately refuses to do. A person reads every message.

  1. 01You writePlain form, no qualifying call, no obligation. The marketing checkbox is optional and unticked.
  2. 02A person reads itMessages land with the team, not a queue-bot. Nothing is auto-replied.
  3. 03You get an answerTo the address you gave — including “this product is not the right fit”, when that is the honest answer.
Reporting a vulnerability?
Read the disclosure policy first — it tells you what is in scope and what to expect.
New messagereplies go to your email

We reply to this address, so a disposable one will not reach you.

+91

0 / 4000