Building Cycode: how we work, what we do, and who we’re looking for in Warsaw

Meet the Cycode team in Warsaw. Learn how we build security tools and what kind of engineers vibe with us.

March 7, 2025
Table of contents

Hey! Cycode team’s here.

In this piece, we want to give you an idea of what we do and how we work. Get comfortable and let’s get acquainted.

Picture this:

You’re deep in the code. Everything is on track. Feature is almost ready to ship.

And then – bam. Security alerts: a vulnerable dependency, license issues, a misconfigured setting, maybe even a hardcoded secret.

You‘re not sure how serious is all that, but it’s now your job to fix it.

Never happens, right? Until it does.

The average organization throws alerts from nearly 50 different tools at their developers. As a result, 81% of dev teams report “alert fatigue and vulnerability noise”.

Now add GenAI-generated code into the mix. The attack surface has exploded, but security tools haven’t evolved. Development velocity is up, security processes are stuck, and everyone is a bit lost on who is supposed to fix what.

And here we are. Sitting right here in Warsaw, building a tool to deal with all this. For ourselves and for other developers who’ve experienced the same mess.

Members of Cycode's team

What we do: Complete ASPM platform

We’re the R&D team behind Cycode’s Application Security Posture Management (ASPM) platform. That term describes a security platform that unifies everything, rather than piling on disconnected tools.

Understanding Cycode’s anatomy

At its core, our platform has two parts:

  1. Unified intelligence layer

Cycode connects to the security tools your company already uses, like scanners, linters, and code quality checkers.

Instead of receiving alerts from dozens of sources, you have a single interface where all notifications are collected and organized.

  1. Purpose-built native scanners

We’ve also built our own scanners from scratch. They were designed with modern development realities in mind: monorepos, ephemeral environments, GitOps workflows, containerized applications, and GenAI-generated code.

Alerts come with context, so you can know exactly what the issue is and where it is coming from.

Code context analysis

Funny thing is, we didn’t start with a big master plan to build an all-in-one platform. It grew layer by layer.

Dor Atias on LinkedIn

What will it turn into next? Nobody can say for sure, but that's the reality of startup life.

The brain: Risk Intelligence Graph

In 2024, we rolled out the Risk Intelligence GraphRIG, for short. It helps with:

  • Meaningful prioritization

Getting every theoretical vulnerability in your dependency tree is frustrating, so the AI-powered prioritization focuses attention on the small percentage of issues that could actually affect your application.

You can be sure that when an alert shows up, it’s worth your time.

  • Practical remediation
Guillaume Montard on LinkedIn

Exactly. Because RIG makes alerts actionable by providing context and prioritization, the platform can then generate ready-to-merge pull requests with the appropriate fix already applied. We moved from “here’s a problem, good luck” to “here’s a problem and here’s exactly how to fix it”.

Cycode AI

All of this fits naturally into existing workflows. Security guidance shows up in your IDE, PR reviews come with automated checks, and CI/CD pipelines run scans without slowing anything down.

Open-source ecosystem & free tools to try

To get a feel for how we think and build things, you can check out the open-source tools we maintain as part of the CyGives initiative. They’re also great if you want to secure a project of your own for free:

  • Bearer CLI

A production-grade code scanner supporting multiple languages that helps catch vulnerabilities early. Works as a CLI tool you can run locally or integrate into your CI/CD pipelines.

  • Raven

A Neo4j-powered analyzer for auditing package dependencies and GitHub Actions workflows. Loved for deep dives into supply chain security.

  • Cimon

An eBPF-powered, real-time monitor for GitHub Actions. No setup needed, just add it to your workflow and it starts catching supply chain attacks immediately.

All these tools can be found at cycode.com/cygives/.

How we build Cycode in Warsaw

In Poland, Cycode is represented by On The Spot, a company helping startups build and grow offshore R&D teams.

At the moment, we have 20+ people in Warsaw working on Cycode across nine distributed teams. "Distributed" here means our engineers in Poland work closely with product managers, team leads, designers and other developers in Israel.

Members of Cycode’s Warsaw team

Each team owns its area: integrations, the Bearer engine for code analysis, scanning features, and more. In practice, our developers in Warsaw contribute to almost the entire platform, with our frontend specialists building most of the UI.

Cycode's dashboard

The relationship between Cycode and On The Spot means that those of us working from Warsaw are as involved in the product as our teammates in Israel. We’re in tight contact, working as one engineering department across locations.

We own features end to end and have a chance to shape what gets built and how it’s done.

Artyom Fyodorov on LinkedIn

Feel our vibe

Even though we’ve picked up a couple of Gartner recognitions1,2, we’re still very much in startup mode.

We don’t know what we’ll be doing in the next quarter, let alone one, two years from now. It’s not because we are wondering what to do, it’s because we have tons of things to do… It’s a competitive industry, so we need to deliver a lot of features and do it quickly.

– Dor Atias

We look for people who are comfortable with ambiguity, take initiative, and move fast.

I always tell candidates: think of yourself like a stock. From the moment you join until the moment you leave (if you ever do), your value will have increased significantly. I see it all the time – people come in already experienced but after a few years they are much more professional, not afraid of challenges, and really know how to get the job done.

– Dor Atias

Members of Cycode’s team, with Dor Atias on the left

Because we’re still a startup, decision-making is transparent and quick.

If the pre-sales team lands a customer who needs a new feature, it will be live within a week or even a few days.

– Artyom Fyodorov

In October 2023, we moved from fully remote to hybrid. That works for us – we know each other face to face, there’s no barriers asking questions or discussing things, even if it's someone on another team. 

Small talk emerges, culture develops beyond just work. You can have a holy war over code quality and code style in person – that's a general favorite. The atmosphere is very friendly and relaxed.

– Artyom Fyodorov

Cycode’s Warsaw team playing kicker

Open positions

Right now, On The Spot is growing Cycode's R&D team in Warsaw.

We’re looking for:

We also invite you to connect with Artyom, Dor, and Guillaume on LinkedIn – get to know them better and stay connected for upcoming opportunities.

More openings, including roles at our other customers’ teams, on the Careers page.

Stay in tune
with On The Spot

Monthly digest of the latest open positions, tech events, and podcast episodes.
Thank you!

You've successfully signed up for our newsletter. Keep an eye on your inbox.

Oops! Something went wrong while submitting the form.

Discover what else is happening at On The Spot

TechSpot

Tech events in Poland and online for everyone interested in software architecture and systems design. Like-minded people, top experts from leading companies, and a big engineering community.

137 Podcast

Conversations with top engineers, CTOs, and founders about day-to-day engineering and everything that excites us about tech.

// trackers