Cymulate runs a SaaS platform for validating and testing security controls across the MITRE ATT&CK framework. The tech stack—Node.js, NestJS, TypeScript, React, Kafka, Kubernetes—reflects a mature, event-driven backend built for continuous workloads rather than point-in-time assessments. Pain-point data reveals the company is pushing customers from one-time penetration tests toward ongoing control validation, a shift confirmed by active projects on continuous validation programs and SOAR/EDR platform integrations.
Cymulate provides breach-and-attack simulation and security posture validation software for mid-market and enterprise security teams. The platform deploys in under an hour and uses threat-intelligence-led scenarios to test controls across dynamic environments. Core product surfaces include red-team and purple-team automation, control effectiveness reviews, and exposure validation reporting. Sales-heavy hiring (3 of 7 open roles) alongside single engineering and product roles suggests a sales-led scaling phase. The company operates from New York and actively hires in the United States and Israel.
Node.js, NestJS, TypeScript, React, Kafka, Kubernetes, PostgreSQL, MongoDB, Redis, AWS (Lambda, SQS, SNS), Docker, Jenkins, and integrations with SOAR, EDR, and Active Directory platforms.
Active projects include continuous control validation programs, SOAR/EDR/SIEM platform integrations, advanced security features, exposure validation reporting, and product and infrastructure stack development.
Other companies in the same industry, closest in size
Cymulate's technology stack, projects, and hiring signals are inferred from public hiring and company data — career pages, public listings, and company web presence — then clustered and de-duplicated. Figures are estimates that refresh over time. Read our full methodology →
This is not an official vendor or customer list. It is a technology-adoption signal inferred from public data, intended for B2B research.