Director, AI Product Design · reports to the CPO · top-two role score on your board, bottom-tier equity story
Phase 1 — The Moment
For supported vulnerability classes, HackerOne's agent reproduces a live security flaw against the customer's own systems in a sandboxed browser. The Director role reports straight to CPO Nidhi Aggarwal, per the posting, and no design executive appears on the leadership page. There's no design byline on the company blog, nothing on ADPList or in the conference archives. Whoever takes this sits at the top of the design function on day one, title or no title.
Real mandate, one sentence: rebuild a product design function that has had no publicly visible executive since at least 2023, while designing the authority boundaries for agents that already hold permission to act on customer infrastructure.
Window indicators, each traced:
- Aggarwal's freshest attributable public framing is 8 days old. On Full Tech Ahead, Manage Your AI Security Debt (July 24), she said flatly that "remediation has not kept pace" and that "defense has to operate at that AI offensive scale." She frames unfixed vulnerabilities as exposure debt carried on a balance sheet. That hook stays live through roughly August 7. After that it reads as homework.
- The posting date cannot be calculated. I'm not going to guess it. The earliest public trace is a June 3 syndication, 59 days back. A second aggregator marked it removed on June 8, 54 days back. The direct Ashby listing is active right now. That sequence supports a reactivated posting of unknown date rather than a stale one, and roles that go dark and come back have usually failed a first slate.
- Last priced round: January 27, 2022. $49M Series E, roughly $160M raised in total, 1,647 days ago, no disclosed valuation. HackerOne appears on Nasdaq Private Market for secondary sales, which establishes a trading channel and tells you nothing about liquidity. Since then, no tender, no acquisition, no filing.
Rubric.
| Company — 9/12 | Role — 14/15 | ||
|---|---|---|---|
| AI centrality | 3 | Total comp potential | 2 |
| Stage and equity window | 1 | Scope expandability | 3 |
| Design influence ceiling | 3 | Craft depth | 3 |
| Trajectory | 2 | AI exposure quality | 3 |
| Portfolio value | 3 |
Watch on the company. Near-ceiling on the role. I'm leaving that split unresolved on the page because the split is the decision you're actually making: a priced round from four and a half years ago with no event attached to it, weighed against the highest density of human-authority decisions anywhere on your target list.
Urgency verdict: Act Soon. Send Monday or Tuesday. Price the cash properly and model the equity as a rounding error.
Phase 2 — Portfolio Mapping
Intelligence layer check: passes, with a mutation. HackerOne surfaces machine-generated findings that humans have to trust and act on. Standard so far. The mutation is that the agent does not stop at surfacing. Agentic Validation checks program scope, flags duplicates, recommends severity, attempts reproduction. Everywhere else on your board, the worst thing a failed agent does is recommend badly, and even where agents act, at Brex or Ramp, they act inside the customer's own account. Here the action lands on a production asset belonging to someone else.
Run the gate diagnostic against their own documentation. Hai Security & Trust covers scope defined before a run, halt during a run, feature-level disabling, override on the recommendation, per-action traces. State, time, authority, system response: four for four, documented better than almost anyone shipping autonomous action right now. The fifth condition is missing. Protection from penalty. Nothing public describes what becomes of tool calls already issued when a halt fires, how quickly the halt propagates, or whether external effects get compensated. Reversibility is what makes a halt free. Without a documented undo, the operator who stops the agent owns whatever stopping it cost. They built the gate and never published the proof that the correction holds. Lead with the missing condition. It is narrower than a general trust critique, checkable against their own docs, and generous about the four things they got right, which is the only way a cold candidate opens a critique with a CPO.
Name the three-configuration problem. Customer-facing Agentic Validation is decision support: a human accepts, modifies, rejects. Hai Triage lets the agent finish intake, route, and post an acknowledgement under an agent account before any analyst looks at it. H1 Validation pushes verified findings straight into Jira and ServiceNow. Watch, Verify, and Delegate on one platform, and the customer's security lead is expected to hold all three in working memory at once.
Thermo Fisher is the second card, and not for the headline numbers. What matters is the move underneath the $20M+ in recovered margin and the 6-of-6 partner adoption. You decided in advance which single moment could not be automated, batch QA release, because the regulatory signature is irreplaceable, then designed five modules to route around it. HackerOne's open question is structurally the same one. Which action must a human authorize before an agent runs an exploit, and does that answer change by vulnerability class, asset criticality, or customer tier?
TinyFish for this buyer: current role context and technical currency, nothing more. Head of Product at TinyFish, enterprise web agent platform, Series A, shipping production agents and tracing runs in LangSmith daily to find where what the agent did diverges from what the user saw. That last clause is the sentence that lands with a security buyer. Everything else about TinyFish stays off the page.
Competitive field.
- Enterprise security design director out of Palo Alto, CrowdStrike, or Okta. Confidence: moderate as an archetype, speculative on any actual slate, but assume they are in the room. Beats you on domain vocabulary. Loses on agentic depth and 0→1.
- AI-native design leader from a frontier lab. Moderate confidence. Beats you on brand. Loses on regulated proof and function-building.
- Staff IC from a late-stage platform. Moderate confidence. Beats you on craft artifacts. Loses on the half of this mandate that is rebuilding an org.
The objection Aggarwal will raise: you have never worked in security, and adversarial systems break assumptions that hold everywhere else. That's true, and the failure mode here is asymmetric, because the agent's capability and the attacker's capability are the same capability. Answer with Thermo Fisher first. You designed inside a regime where a wrong output was a regulatory event rather than a bug. Then Carrier IQ from Agentic Labs, which demonstrates all five handoffs inside a regulated automation flow. Then commit to sixty days inside the researcher and triage analyst workflow before proposing anything, and tell her why you work that way: 32 warehouse floor interviews before you touched mySupply.
Phase 3 — The Outreach Package
Warm path: none identified. Fully cold. The 8-day-old podcast is the only thing making cold feel current. If you can't verify the quotes by Monday, open on the Hai Security & Trust documentation language instead. The hook survives that substitution. The Aug 7 deadline stops binding.
First contact message — to Nidhi Aggarwal
Subject: What happens after the agent runs the exploit
Nidhi — "remediation has not kept pace" is the line from last week's episode I keep coming back to, though from the human side of it.
Agentic Validation doesn't stop at recommending. For supported classes it reproduces against a live target. Your documentation is unusually strong on the front half of that: scope set before the run, halt during it, override on the recommendation, a trace on every action. The back half I can't find publicly. Once an agent has reproduced, routed, and opened a ticket, what does a security lead do at 2am when the finding was wrong? And does the answer shift between customer-facing Hai and managed triage, where the boundaries aren't the same?
I'm Head of Product at TinyFish, an enterprise web agent platform, building and tracing production agents daily. Before that I led design for regulated platforms where a wrong output was a compliance event, not a bug. I published the framework I use for these handoffs in June: Trust Is the New Interface.
Twenty minutes on where the human gate sits across your three agent configurations?
(180 words. No link in the body. She will look you up, and the essay is the first thing she finds.)
Resume framing note
Rebuild the summary line around authorization rather than scale: you design the moment a human authorizes, overrides, or reverses machine action in high-consequence systems. First metric on the page is Thermo Fisher's 6-of-6 partner adoption across nine sites, not Alibaba's GMV. Dollar scale reads as consumer marketplace to a security buyer, and you don't get that first impression back. Agentic Labs sits above the case studies with Carrier IQ named explicitly as regulated agentic automation. Compress Equinox+ and Allē to one line each. Cut Red Cross from the page entirely; it's a story you tell, not a bullet you list. Header reads Head of Product, TinyFish (enterprise web agent platform, Series A), with one line on three products in three months and daily agent tracing in production. Strike "design-led," "trusted AI," and "human-in-the-loop." This buyer reads all three as padding.
Cover letter hook (two sentences)
HackerOne runs three different authority boundaries on one platform, decision support in Agentic Validation, autonomous intake in Hai Triage, downstream routing in H1 Validation, and expects a customer's security lead to hold all three in working memory at once. I've spent the past year designing that arbitration in production, and the decade before it designing it in environments where a wrong output was a regulatory event rather than a bug.
Post-outreach signals — growth-stage platform tier
A long-private Series E with an enterprise sales motion and a managed-services org runs on growth-stage cadence, not AI-native startup speed. A reply inside 3–5 business days is normal. If she engages the reversibility question rather than routing you to a recruiter, that is the strongest signal available here: answer inside 24 hours and go a layer deeper on halt propagation. Silence past 7 business days means the slate is further along than the reposting implies. One follow-up on day 8 anchored to a new signal, then close the loop internally.
Ask in the first twenty minutes
- Who owned product design before this role opened, and what happened to the function after they left?
- Does the human gate differ today by vulnerability class or customer tier, and was that a decision or an accretion?
- When a halt fires mid-run, what happens to tool calls already issued, and who owns the external effect?
Disabling customer-facing Hai does not disable Hai inside HackerOne's own managed triage service. Administrators control organizational access and advanced customer-facing features, not every internal workflow where HackerOne runs the agent itself. Almost nobody in this slate will have read far enough into the docs to know that.
Warning signs, plainly
- The design leadership gap is real and it's old. Tony Corneto states on his own portfolio that he was Head of Product Design from 2022 to 2023. Mark Jenkins's portfolio places him at HackerOne immediately before WeTravel but gives no title and no dates, so that's an unresolved second layer, not a fact. Senior ICs are the only design staff publicly visible today. Whether Jenkins led the function between Corneto and now is unresolved. Treat the gap as at least two years and confirm it in conversation.
- A 12% workforce reduction in August 2023 is confirmed and stale.
- A further restructuring is unverified. A former data engineer described it in a first-person LinkedIn post roughly five months ago. Uncorroborated by the company, no headcount attached. Unverified signal, not fact.
- Glassdoor gives you themes, not findings. Currently visible reviews cluster on leadership churn, shifting priorities, and a walk-back from remote-first toward designated hubs. The accessible excerpt is too shallow to establish a multi-year pattern. Weight it as something to probe.
Read the missing design executive both ways at once: scope upside and support risk, in the same fact. Ask for the org chart before the second conversation.
Phase 4 — Window Summary
| Action | Deadline | What degrades without it |
|---|---|---|
| Send first contact to Aggarwal anchored to the July 24 episode | Fri, Aug 7, 2026 | Past 14 days the reference reads as research rather than attention, and a cold approach loses its only current-feeling opening |
| Confirm the Ashby listing is live and identify the recruiter of record | Mon, Aug 10, 2026 | It went dark once in June. A second disappearance means the search restarted, and the slate you think you're joining isn't the one that exists |
| One follow-up anchored to a new HackerOne signal, then close the loop | Mon, Aug 17, 2026 | Past this you're entering a process already at panel stage, positioned as late instead of early |
Monday, August 17, 2026.
- Read-only as a design decision: HackerOne shipped its MCP server in July 2026 with no write capability at all — connected agents can inspect reports, assets, and bounties but cannot change a single record, which is the cleanest published statement of where this company currently draws the authority line.
- Where reversibility is already a requirement: Rubrik's Director, Product Design opening names guardrails, auditability, and undoing agentic mistakes directly in the mandate — useful as a comparison point if Aggarwal asks what good looks like elsewhere in security.
- The oversight standard behind the question: NIST's AI Risk Management playbook recommends tracking overrides, exceptions, escalations, and adjudication outcomes, which gives you a non-vendor vocabulary for arguing that a halt without a record is not oversight.
- What happens when the human has responsibility but not power: Madeleine Elish's moral crumple zone research is the sharpest existing account of operators absorbing liability for automated systems they could not meaningfully control — worth reading before you argue the fifth gate condition out loud.

