RemoteThreat Is Building the Operating Layer for Offensive Cyber
RemoteThreat is building an operating layer for offensive cyber work at the moment artificial intelligence is making that work faster, cheaper, and harder to govern. The company's O/C/O Platform brings mission planning, command and control, implants, initial access, capability development, obfuscation, analysis, and bounded AI workflows into one environment for advanced red teams, U.S. government mission teams, and vetted defense partners.
The company was formed in 2025 by Chris Thompson and Shawn Jones, two operators with deep experience inside IBM X-Force. Thompson serves as CEO, Jones as CTO, and Rob McCall as COO. The team is betting that the next competitive advantage in offensive security will come from connecting tools, operators, evidence, authorization, and machine assistance without losing human control.
That thesis has fresh capital behind it. A February 2026 SEC filing says RemoteThreat sold $7 million of a planned $7.3 million equity offering to two investors. The filing does not name the investors or assign the round a stage, so the useful signal is not a label. It is the scale of the bet on governed offensive operations.
About RemoteThreat
RemoteThreat sits in a category that security teams have spent years assembling by hand. Red-team operators move among mission plans, command-and-control systems, payloads, infrastructure, collaboration tools, evidence stores, and reporting workflows. Each component can be capable on its own while the operation around it remains fragmented.
The O/C/O Platform is RemoteThreat's attempt to turn that toolchain into a system. RemoteThreat describes eight connected layers: Mission Operations, Command & Control, Implants, Initial Access Framework, Capabilities, Obfuscation Pipeline, Targeting, Tasking and Analysis Engines, and AI Ops Assistants. The platform is designed to support cloud, on-premises, and air-gapped deployments, with APIs and SDKs for existing tools and models.
Those are company-reported capabilities, not independently measured performance results. But the design choice is still important. RemoteThreat is not presenting AI as a substitute for the operator. It is positioning machine assistance inside a governed mission environment where rules of engagement, approvals, audit trails, and No-Strike controls travel with the work.
Why Offensive Cyber Needs an Operating Layer
AI changes the tempo of security research before it changes who carries the liability. A model can help plan a path, generate tooling, organize evidence, or execute a bounded task. It cannot own authorization, understand every downstream consequence, or answer for an operation that crossed the line.
That gap between machine speed and human responsibility is where RemoteThreat is placing its bet. The company's product thesis treats governance as part of the operational architecture, not paperwork added after a mission. For government teams and advanced red teams, that matters because capability without scope control is not leverage. It is exposure with better automation.
Thompson has made this argument publicly. In a SecurityWeek interview, he described AI as an accelerant for both attackers and expert defenders. In TechCrunch, he argued that inconsistent model guardrails can obstruct legitimate security research and push authorized practitioners toward open-weight systems. RemoteThreat's answer is not unlimited autonomy. It is bounded automation inside an operator-owned workflow.
The Operators Behind RemoteThreat
Chris Thompson previously built and led IBM's dedicated red-team and X-Force Red work. His background gives RemoteThreat direct exposure to the unglamorous parts of offensive programs: staffing expert teams, coordinating complex engagements, preserving evidence, managing scope, and explaining risk to institutions that cannot afford improvisation.
Shawn Jones, RemoteThreat's co-founder and CTO, led capability research and development and worked on IBM X-Force's Adversary Simulation team, according to the company's official biography. Rob McCall, the company's COO, led client success for IBM X-Force Adversary Services and helped Randori scale through its acquisition by IBM.
The leadership pattern is unusually coherent. The founders are not starting with a generic agent framework and looking for a cybersecurity story. They are starting with the operating constraints of offensive missions and asking where AI can increase speed without dissolving accountability.
Capital, Team Growth, and Market Timing
RemoteThreat's SEC filing records a company incorporated in 2025 that had already sold $7 million in equity by early 2026. DevCuration's funding disclosure analysis explains why the primary record supports the financing amount but not a pre-seed label. DataTribe has publicly identified RemoteThreat as a portfolio company, although the reviewed public record does not establish DataTribe as the lead in this offering or identify the second investor.
The company's LinkedIn profile places it in the 11-50 employee band. A recent, now-closed listing for a Founding AI Engineer described responsibility for models, agents, tools, memory, orchestration, evaluation, and user-facing workflows across the platform. One role is not a workforce forecast, but the shape of the role matters. It suggests RemoteThreat is investing in the orchestration and evaluation layer where offensive AI will either become operational infrastructure or another clever demo.
No current careers page or verified roster of open roles was available during this review. Builders interested in the company can follow RemoteThreat on LinkedIn and use its official site for current contact paths rather than relying on stale job listings.
What RemoteThreat Signals for Cybersecurity
Cybersecurity has spent years turning defensive operations into platforms. Data, detections, cases, automation, approvals, and evidence increasingly live in connected systems because isolated tools create gaps at machine speed. Offensive security is now confronting the same operating problem.
RemoteThreat's opportunity is to make mission context durable across the offensive lifecycle. The harder test will be whether teams can integrate existing tradecraft, measure the quality of machine-assisted work, preserve operator trust, and demonstrate that governance improves outcomes without turning every mission into a compliance ceremony.
That is why RemoteThreat is worth watching. The company is building for a world where models can produce more offensive output than institutions can safely absorb. The winning platform will not be the one that simply acts fastest. It will be the one that helps authorized teams move faster while keeping a human name attached to every consequential decision.
Cybersecurity funding, last 30 days
DevCuration's funding database tracked 7 Cybersecurity rounds totaling $335.8M in disclosed capital over the past 30 days. Recent deals we covered:
- RemoteThreat Discloses $7M for Offensive Cyber Operations$7M · Sep 29
- StrikeReady Reaches $29M for Saudi AI SOC ExpansionUndisclosed · Sep 18
- MIND Raises $72M to Rebuild DLP for the AI Agent EraSeries B · $72M · Sep 17
- Eve Security Raises $4.5M for Runtime AI GovernanceSeed Extension · $4.5M · Sep 15
- HelmGuard Raises $7.3M to Build AI Risk AssuranceSeed · $7.3M · Sep 9
Frequently Asked Questions
What does RemoteThreat do?
RemoteThreat builds the O/C/O Platform, an integrated environment for planning, executing, governing, and reviewing authorized offensive cyber operations.
Who founded RemoteThreat?
Chris Thompson and Shawn Jones co-founded RemoteThreat in 2025. Thompson serves as CEO, Jones as CTO, and Rob McCall serves as COO.
What is the RemoteThreat O/C/O Platform?
The O/C/O Platform connects mission operations, command and control, implants, initial access, capability development, obfuscation, analysis, and bounded AI workflows under shared governance.
How much funding has RemoteThreat raised?
A February 2026 SEC Form D says RemoteThreat sold $7 million of a planned $7.3 million equity offering to two investors. The filing does not name the investors, valuation, or round stage.
Is RemoteThreat hiring?
RemoteThreat recently advertised a Founding AI Engineer role, but that listing is closed and no current careers page or verified open-role roster was found. Interested candidates should check the company's official channels for current opportunities.
Where the Money Moved
The intelligence briefing of the innovation economy. Funding, M&A, debt and fund closes, read as market signal rather than deal announcements.
Subscribe to Where the Money Moved
