Phase 1 — The Moment, Read as a Launch Trigger
On June 2, HackerOne shipped a platform that moves security agents out of assisting human review and into performing validation, prioritization, and remediation routing, with people kept for judgment rather than throughput (H1 Platform launch). The Director, AI Product Design posting surfaced one day later.
One day. That gap is the trigger. High confidence on the sequence, moderate confidence that the first thing caused the second, but the shape is legible: they shipped it, then went looking for whoever could make it defensible to a Fortune 500 security team.
The default pattern in this market is a design leadership posting trailing a new chief product officer by 30 to 90 days while the org gets rebuilt underneath them. That is not what happened here. Nidhi Aggarwal took the CPO seat on June 11, 2025, 416 days ago, and the leadership-transition window shut last September. This is a product-cycle hire, and the distinction changes your posture: nobody here needs you to stand up a function for a new executive, they need you to solve the problem their shipped product just handed them.
The real mandate, in one sentence: design the accountability layer that lets a security operator explain to an auditor, or to a customer, why an agent's judgment was trusted and where a human still owned the call.
Three signals, each with a clock:
- The launch. June 2, 60 days elapsed. Standard decay: sharpest in weeks one through three, halved by week six, functionally spent by early September. Call it 30 days of usable freshness.
- The pressure, public and quantified. 46,947 submissions in March 2026, up 76% year over year, against 19% growth in remediation throughput and a backlog the company itself called an all-time high. Intake is outrunning resolution four to one. The business case for this role was written by the company, in public. No window on it; it worsens monthly.
- No design executive. The leadership page lists no VP, Head, or Director of Design. Product and design both sit under Aggarwal. Six product designers are individually identifiable on LinkedIn, which is a floor and not a headcount.
The posting is not in HackerOne's own Ashby job board feed today. Treat this as an unresolved search rather than a 59-day-old listing, and make resolving it your first move instead of your last.
The trail, from the Ashby feed and the mirrors around it:
- Jobrapido mirror capturing the role June 3.
- Lensa mirror dated June 5.
- Archived employer text confirming the Director reports to the CPO and would "lead and scale" the design function.
- A Built In record showing removal on June 8.
- Aggregator copies still surfacing for weeks afterward.
No live employer-hosted listing anywhere. Five live days for a Director reporting to the CPO is not a fill cycle. Moderate confidence read: the search went to a retained firm, got paused, or came back relisted under different language.
Rubric.
| Dimension | Score |
|---|---|
| AI centrality | 3 |
| Design influence ceiling | 3 |
| Trajectory | 2 |
| Stage and equity window | 1 |
| Company total | 9 |
| Role total (all five dimensions at 3) | 15 |
The stage-and-equity 1 is doing all the damage. Last disclosed round was a $49M Series E in January 2022. Fifty-four months, no announced raise, no valuation mark, no revenue disclosure, no IPO signal. And the 15 of 15 on role rests on a comp band I cannot verify from archived text.
By rubric that lands on Watch, held there by one point. The flip condition is narrow and nameable: a disclosed round, a secondary sale at a stated price, a named IPO advisor, or any public ARR figure. Set alerts on all four.
Urgency verdict: Act Soon. Different axis, no contradiction. A 15/15 role mechanism, one message to verify it, and a launch window that closes in September whether or not the equity picture ever clears.
Phase 2 — Portfolio Mapping at System Altitude
Intelligence layer check: passes. Their product puts machine-generated findings in front of a human and asks for approval, edit, or override before anything consequential happens. They describe it with unusual precision themselves: the assistant presents a recommended next step with rationale, reviewers inspect each check, reviewer decisions feed downstream accuracy. So lead the intelligence layer frame and drop the agentic-products frame. Your entry point is the moment between what the agent surfaces and what the reviewer decides.
Hiring manager research. I went after Aggarwal directly: LinkedIn activity, HackerOne press mentions, conference and podcast appearances, prior-role coverage. The record is usable, not thin. Two artifacts matter. She opened HackerOne's AI Security Virtual Summit on July 15 with a session built around rising submission volume and overloaded queues, premised on the idea that discovery is no longer the constraint, exposure time is. That comes from the event description, not a transcript, so hold it as the premise of her session rather than a quote. Her June 2 LinkedIn post is directly attributable: "The discovery-remediation gap is the defining security problem of the AI era." Use that one. It's her sentence, it has seventeen days of summit reinforcement behind it, and it names the exact seam your work sits in.
Buyer-adjacent route, because the posting is missing.
- Aggarwal direct.
- Unanswered after ten days, HackerOne recruiting via the Ashby board contact.
- A warm read from the publicly visible product designers on the team, Josh Dunne or Courtney Bregar among them. They will know whether the search is alive before any public source does. Don't pitch them. Ask one question about the team's current shape.
Lead with Carrier IQ, at system altitude. Not as an interface. As a closed control loop. Every automated extraction carried its source element, the raw value, and a confidence signal derived from consistency across prior runs; a reviewer marking an error down-weighted that element, and the system produced a verification step by run five. HackerOne has built the same loop under different vocabulary: recommendation, rationale, inspectable checks, override, feedback into later accuracy. They publish 94% recommendation acceptance after five months. That number means either the loop is calibrated or the reviewers have stopped reading, and telling those two apart is a design problem, not a model problem. Say that sentence early.
Second, Thermo Fisher mySupply. Their responsible-AI operating model keeps a mandatory human gate on bounty payouts by default and compresses the policy into one line: agentic does not mean unsupervised. That is the pharmaceutical QA release gate you already designed. Five automated steps, one human authority that could not be delegated, $20M+ margin, 100% adoption across six pharma partners in twelve months. A wrong payout is as irreversible as a wrong release.
Third, American Red Cross, in reserve, for the volume conversation only. Six systems into one, $847K disbursed, national in six months. Triage under load has the same anatomy as an all-time-high backlog.
Subordinate Alibaba. Marketplace scale isn't what they're anxious about; reviewer accountability is.
TinyFish, bounded to three uses:
- Current role context. Head of Product at TinyFish, enterprise web agent platform, Series A.
- Technical currency. You review agent traces daily and work attribution, reversibility, and governance in live enterprise deployments.
- Bridge narrative. You built from zero inside an agent platform and are returning to design to point that depth at a vertical domain with real consequences.
That's a credibility signal, not a case study and not a metric.
The hardest objection this buyer raises: you have never worked in security, and their reviewers make adversarial expert judgments you cannot make yourself. It bites because in this product the reviewer's expertise is the value, so a designer who can't separate a real finding from a false positive can't design the review surface on intuition. Answer with Thermo Fisher. You designed a pharmaceutical release gate without being a regulatory specialist, by designing around what the specialist needed to see before signing their name rather than around the chemistry. Six partners, 100% adoption, twelve months. Their published vocabulary also telegraphs one question almost word for word: how do you know when a reviewer is actually reviewing? Answer with the Carrier IQ reliability model. A marked error down-weighted that source element and the system inserted a verification step by run five, which made correction rate per element the instrument. The inverse matters just as much, and say it out loud: an element that drifts while corrections go quiet is the reading you watch for, and it's why the 94% needs a second signal underneath it.
Revise your own trust ladder before a security operator does it for you. In Said vs. Shipped we treated progressive trust as a single granular autonomy dial. Too simple. Autonomy scope, meaning what an agent may touch, and intervention sensitivity, meaning how far confidence must fall before a human gets pulled in, move independently. HackerOne already separates them through allowlists, rate controls, conservative modes, and checkpointing in their agentic pentest architecture. Ask this in the first ten minutes: are you setting one dial or two, and what breaks for customers when scope and escalation move together?
Unverified this cycle: the live state of junochen.com. Before any deep dive, confirm the Carrier IQ and Thermo Fisher teasers render, and that the "What Do You Count" gate holds before HTML delivery.
Phase 3 — The Outreach Package
FIRST CONTACT MESSAGE (to Nidhi Aggarwal, CPO)
Nidhi — on June 2 you wrote that the discovery-remediation gap is the defining security problem of the AI era. The March numbers your team published make it concrete: 46,947 submissions, up 76% year over year, remediation throughput up 19%.
The number I keep returning to is in your agentic validation write-up. 94% recommendation acceptance after five months either means the loop is well calibrated or means reviewers have stopped reading. Telling those apart is a design problem, not a model problem. I've built that instrument before. In an InsurTech quote-automation system, every automated extraction carried its source element and a confidence signal derived from prior-run consistency, and a reviewer's correction changed agent behavior by the next run, which turned correction rate itself into the health metric. Before that, a pharmaceutical release workflow: five automated steps, one human gate that couldn't be delegated, adopted by all six partner organizations.
I'm Head of Product at TinyFish, an enterprise web agent platform, working traces, attribution, and governance in production every day. I want to point that depth at a vertical domain where the consequences are real.
Do you have 20 minutes in the next two weeks?
RESUME FRAMING NOTE. Open the summary on reviewer-decision surfaces for automated systems, not team size or org-building scope, because with no design executive in the building the title already assumes function-building. Put Thermo Fisher's 100% adoption across six pharma partners above Alibaba's GMV: regulated adoption reads as accountability proof, marketplace scale reads as a different job. Compress Alibaba to two lines. Keep Equinox+ and Allē off the page entirely. Cut "AI-native" from the resume and from live conversation both. It appears nowhere in the HackerOne material I reviewed this cycle. Their working vocabulary is validation, verification, audit trail, override, so mirror theirs. The bridge narrative above is my shorthand for you, not language to carry into the room. TinyFish gets one line of present-tense context. Label Thermo Fisher and Red Cross regulated and high-consequence rather than healthcare and nonprofit, which pre-empts the domain objection before anyone gets to raise it.
COVER LETTER HOOK.
Your governance policy compresses the whole problem into three words: agentic doesn't mean unsupervised. Honoring it comes down to whether a reviewer can reconstruct, six months later, why they trusted the recommendation they approved, and I've been designing that reconstruction layer since a pharmaceutical release workflow where one human gate stood behind five automated steps.
Phase 4 — Window Summary
| Action | Deadline | What degrades without it |
|---|---|---|
| Re-poll the Ashby feed, LinkedIn Jobs, Built In. Then one question to recruiting or Aggarwal: did this search move to a retained firm, and which one | Aug 8, 2026 | You prep for a role that closed in June, or miss the relist under revised language. The retained-firm question also marks you as something other than a portal applicant |
| Send the Aggarwal message regardless of posting status, anchored to her June 2 line and the 94% read | Aug 15, 2026 | Launch freshness is spent past 90 days; the hook starts reading as stale research |
| Put the equity question in conversation one: last disclosed round January 2022, nothing since, what does a grant price against | Aug 29, 2026 | The one rubric point between Watch and Act stays open through every later round |
Next verification pass: September 2, 2026.
- Autonomy and interruption diverge: Anthropic's measurement of agent autonomy found auto-approval rising from roughly 20% among newer users to over 40% among experienced ones while those same experienced users interrupted agents more often — the empirical basis for splitting autonomy scope from intervention sensitivity before your HackerOne conversation.
- Reversibility as shipped feature: Linear's agent-assisted editing visually distinguishes agent changes, preserves the agent as author, and creates restorable checkpoints, which is the closest consumer-grade reference for the recovery sequence Carrier IQ needs to show as one continuous record.
- Design systems as agent input: Altana's Head of Product Design posting describes the design system as a machine-readable language of patterns and interaction grammars that engineers and agents compose — the sharpest articulation yet of the constraint-first argument you can currently only make verbally.
- Evals as design definition of done: First Round's account of Figma's AI eval process documents one-to-four design and functionality scoring against roughly 1,000 examples with nightly model comparisons, and it is the template for the trace-to-release chain the market keeps asking you to show.

