Zafran builds an AI-native exposure management platform designed to cut through vulnerability noise and automate mitigation using existing security controls. The tech stack—Python, Go, Java, Elasticsearch, Kafka, Prometheus, Datadog—reflects a mature observability and data-processing infrastructure. Hiring is heavily sales-weighted (19 of 32 roles), with 22 placements in the last 30 days, indicating a sales-led growth motion focused on enterprise pipeline expansion.
Zafran is a 51–200-person security company headquartered in New York building an AI-native exposure management platform. The product targets the manual toil in vulnerability management—noise filtering, exploitability assessment, and remediation automation—and integrates with security controls teams already operate. Active projects show a go-to-market emphasis on enterprise-scale deployment (pipeline development, outcome-based demos, onboarding & integrations) and channel partnerships (partner certification programs, MSSP/MDR service design). The team is hiring across sales and leadership seniority levels in the US and Israel.
Zafran runs Python, Go, Java, and C/C++ for core services; Elasticsearch, Kafka, ClickHouse for data pipelines; Prometheus, Grafana, Datadog for observability; and AWS, GCP, Azure for infrastructure. Salesforce, Jira, and Zendesk manage sales, engineering, and support workflows.
Core projects include enterprise pipeline development, outcome-based demos for enterprise and mid-market, onboarding & integrations, technical enablement for channel partners, and MSSP/MDR service offerings design. Internal pain points center on reducing critical vulnerability exploitation and scaling to meet sales demand.
Other companies in the same industry, closest in size
Zafran Security's technology stack, projects, and hiring signals are inferred from public hiring and company data — career pages, public listings, and company web presence — then clustered and de-duplicated. Figures are estimates that refresh over time. Read our full methodology →
This is not an official vendor or customer list. It is a technology-adoption signal inferred from public data, intended for B2B research.