Open source security platform with intelligent vulnerability remediation
ActiveState operates an open source security posture management platform focused on vulnerability detection and remediation. The company is building outward across language ecosystems (Python, Go, Rust, Java) while wrestling with internal scaling challenges in data pipelines and remediation velocity. A lean, engineering-forward org (3 engineers among 6 active hires) suggests product-driven growth, with go-to-market and onboarding efforts underway but not yet at sales scale.
ActiveState enables development, operations, and security teams to manage open source vulnerabilities and improve supply chain security. The platform identifies vulnerable dependencies, prioritizes fixes based on impact, and automates secure package builds and deployments—aimed at reducing time-to-remediation for breaking changes. Customers are mid-market and enterprise software orgs managing complex dependency trees. The company, founded in 1997, operates from Vancouver with 51–200 employees and continues to expand hiring in Canada and Brazil. Projects focus on dependency resolution algorithms, data modeling for vulnerability patterns, and continuous CI/CD pipeline hardening.
Primary support for Python, Go, Rust, and Java. The company lists scaling across additional languages and ecosystems as a key challenge, indicating active expansion beyond these core environments.
Yes. Engineering roles represent 3 of 6 active openings (50% of open headcount), split across manager, mid, and junior levels. Hiring velocity is accelerating.
Vancouver, BC, Canada. The company is actively hiring in Canada and Brazil, with a team of 51–200 employees.
Other companies in the same industry, closest in size