Skip to content

Practice 01

Verification

2 open roles

OSINT Analyst-Engineer

Build assessments from public reporting and sensor data. You'll combine imagery, flight and vessel tracking, and structured OSINT into signed work where every material claim traces to a source.

Show us
Published analysis under your name or handle: a Bellingcat-style investigation, a tracking project, a dataset with documented provenance. We care that your methods survive scrutiny in public.
Note
US-person status matters for some engagements. Tell us where you stand; it decides which engagements we can staff you on, and nothing more.

Verification Engineer

Build the signing and reproduction layer that lets a third party check our work from the source record and public key.

Show us
Cryptographic tooling in public. A signing implementation, a supply-chain security contribution (Sigstore, in-toto, the SLSA ecosystem), a CVE with your name on it.

Practice 02

Financial services testing

1 open role

Quantitative Risk Engineer

Exposure you can see before it moves. Counterparty, market and infrastructure risk traced end to end. You'll build models where every finding is signed and every backtest regenerates from a commit hash.

Show us
Published quant work: a backtesting harness, a calibration study, a paper or preprint, a Kaggle history with real methodology. We will read your validation logic before anything else. Purged cross-validation done correctly says more than any title.

Practice 03

Intelligence Log

1 open role

Security Analyst

Security analysis, published under your byline. You'll own Intelligence Log write-ups: recurring, technical, and readable by both an engineer and a risk officer. What moved, what it means, what our instruments saw.

Show us
An archive and an investigation. A Substack, a blog, a column, or a thread series with sustained readership, plus at least one piece of security analysis where the sourcing holds up. Writing samples beat pitches; an audience you built beats both.
Bonus
Enough technical literacy to read a repo and quote it correctly.

How we evaluate

No cover letters. No credential screens. Published work is the application.

  1. 01

    Links first. We open your repos and publications before anything else.

  2. 02

    Reproduce or verify. If we can run it, we will.

  3. 03

    One conversation about the work, yours and ours.

  4. 04

    Paid trial task scoped to a week, on real engagement problems, before any offer.

Apply

Pick a role, or leave the default if none fits and your links argue for a seat anyway. We read everything that arrives with a working link in it.

A paid trial task scoped to a week sits between the conversation and any offer, so the strongest thing you can send is work we can run today. All roles are remote-first and begin in Q4 2026.

Open in email app