On September 1, a ten-person AI startup put a date on its hiring promise. Aslan had raised a $20.8 million seed round, CEO Chase Reid told Axios. It planned to nearly double its headcount by the end of October.

The company’s careers page makes that ambition more concrete. It showed six openings when I checked it on September 9: Forward Deployed Engineer, AI Engineer, Evals Lead, Head of Growth, Head of National Security, and Operations. Three sit under engineering, two under government, and one under operations. There is no visible junior opening. I use “senior” here for jobs that lead a function, request several years of experience or senior judgment, or assign independent ownership. It is an assessment of the public requirements, not a quoted Aslan job level.

Aslan sells AI agents for sensitive national-security investigations. The company says its software helps analysts connect records, plan investigative steps, and produce evidence-backed findings. Reid says people supervise the agents. He also says federal customers have piloted the product and that one investigation lasting 21 days uncovered a smuggling ring, cyber fraud, and an attempt to transfer technology to China. Those are company claims reported by Axios, not findings independently confirmed by the named agencies.

Picture the decision facing an analyst, not the demonstration facing an investor. An agent links two people and recommends another search. Before acting, the analyst needs to know which records produced the link, whether two similar names were merged, what contrary evidence was omitted, and whether the next search is authorized. A fast answer does not remove those questions. It brings them forward sooner.

The vacancies offer a firmer kind of evidence. They do not prove that anyone has been hired, that a contract has been awarded, or that an agent has been approved for an operation. They show which capabilities Aslan is trying to add and what it asks applicants to do.

Only three of the six openings sit in engineering. The rest cover government missions, budgets, and the operating chores of a growing company. Even the technical side is divided among agent behavior, testing, and work inside customer environments.

For founders, candidates, and public buyers, the list exposes the organizational work hidden by the phrase “AI agent.” Software may perform more steps. Each step still creates decisions about access, evidence, reliability, accountability, and customer use. Aslan’s six openings distribute those decisions among people.

September 1 starts a six-role hiring clock

The hiring did not begin on September 1. Axios reported that Khosla Ventures and XYZ Venture Capital led Aslan’s seed round, with participation from Silent Ventures, Haystack, SV Angel, and Valor Equity Partners. Aslan, founded in 2025 by Reid and Ansel Tessier, had ten employees at the time of the report. The money would support product development and an expansion of the technical team, including forward deployed engineers.

The six jobs were not all created after the funding announcement. Dates in Aslan’s public job-board feed show five postings from July and an Evals Lead posting from August 10. The announcement therefore starts a public measurement period, not necessarily the recruiting process itself.

Six accepted offers would lift a ten-person company to sixteen people. The math stops short of a literal doubling. “Nearly double” could include other roles, people already committed but not yet started, or a rounded description of the plan. None of those possibilities is confirmed by the job board. The clean test for late October is simple: count employees who have actually started, then compare that number with the ten-person baseline. A live vacancy proves only recruitment.

The seniority mix is concentrated at the experienced end. The two government jobs begin with “Head of.” The Evals Lead owns a function. The AI Engineer asks for roughly five or more years of experience and explicitly seeks senior judgment. The Forward Deployed Engineer asks for at least three years and expects the person to work directly with national-security customers. The operations posting describes the company’s first business-operations hire, with responsibility ranging from financial processes to office and security logistics.

Aslan’s choice is not a universal law of AI hiring. A 2026 Mercury survey of early-stage founders found that 94 percent expected to maintain or increase hiring, while 82 percent expected to keep junior hiring steady or increase it. The survey is self-reported and comes from a financial-services company serving startups, so it is a directional benchmark. Even so, small companies do not automatically stop hiring junior workers when they adopt AI.

Aslan’s current slate does. A candidate entering the field can see six ways to contribute, but none is presented as an entry route. The absence could be temporary. It could reflect the clearance, customer, and systems demands of an early national-security product. It could also indicate that the company expects experienced hires to construct the processes a later cohort will inherit. The postings alone cannot choose among those explanations.

There is a cost to waiting for that later cohort. Early systems acquire their conventions from the first people who build and deploy them. If no role owns training, documentation, or a progression path, practical knowledge can remain inside a few senior heads. A junior engineer is not automatically suitable for classified or customer-facing work, but a company can still define supervised tasks, review standards, and the experience needed to advance.

Recruiters should resist treating the six cards as one generic hunt for “AI talent.” Each has a different proof burden. The AI Engineer must show that an agent can act coherently over a long task. The Evals Lead must show when it fails. The field engineer must make it useful inside a customer’s environment. The government leaders must translate capability into mission authority and funded work. Operations must turn an improvised ten-person company into an employer and vendor that can withstand more scrutiny.

Before a single hire starts, the distribution supplies one clear signal: Aslan is hiring around the model as much as it is hiring for the model.

Six vacancies reveal the work around autonomy

An agent is the product label. The jobs describe the system around it.

Aslan describes its product as a multi-agent system for investigations. According to the company, a human gives the system an objective, agents plan and conduct parts of the inquiry, and an analyst reviews the work. Its site also says the product can connect internal and external data, preserve citations, and operate in secure environments. These descriptions explain the intended workflow. They are not independent evidence of accuracy, security, or agency deployment.

The jobs translate that workflow into six human accountabilities.

The AI Engineer handles agent orchestration, memory, model adaptation, data, and inference under constrained hardware. The Evals Lead builds datasets and tests that shape training and release decisions. The Forward Deployed Engineer works at the boundary between the software and a customer’s real process.

The Head of Growth is expected to turn a capability into a validated government requirement and then into current-year or future-year funding. The Head of National Security is expected to shape executive relationships, mission priorities, and adoption. The Operations hire owns much of the machinery required to employ people and serve institutional customers.

This division resembles a distinction drawn by Sonali Subbu Rathinam and Ronnie Kinoshita at Georgetown’s Center for Security and Emerging Technology. Their June 2026 workforce report separates people who build AI from people who adopt it and people whose existing work is exposed to it. Aslan’s list compresses the first two groups into one startup. Three engineers build and test. The field role, government roles, and operations role make adoption possible.

“Human supervised” carries weight only if a supervisor can know what the agent attempted, what information it used, where an assertion came from, which action requires approval, and how to stop or correct the run. A statement that a person remains in the loop says little unless the product and organization preserve those controls.

Aslan’s Evals Lead posting asks for provenance and data-lineage practices. Its engineering postings refer to long-horizon tasks, agent trajectories, and constrained environments. Its government postings emphasize mission context. Read together, those requirements suggest that supervision is not one review button at the end. It begins with how a task is specified, continues through data access and intermediate actions, and ends with a decision about whether an output can be used.

The careers page does not show a dedicated security leader, privacy counsel, civil-liberties specialist, product manager, recruiter, or customer-support role. That does not prove the functions are absent. A founder, contractor, investor, outside firm, or existing employee may hold them. The job board is a view of marginal hiring demand, not a complete organization chart.

The distinction matters when outsiders infer too much from vacancies. A company may post a job to learn about the market, build a candidate pipeline, or prepare for a contract that has not arrived. A role can remain open after an offer is made. It can disappear without a hire. The six postings are reliable evidence of published intent on September 9. They are weak evidence of payroll and no evidence of government authorization.

The postings show that an agentic product does not eliminate the work surrounding consequential decisions. It relocates that work into system design, evaluation, deployment, procurement, and operating control.

Engineering splits across model, field and test

The three engineering roles form a triangle. One makes the agent capable, one measures the capability, and one closes the distance between a controlled build and a customer’s environment.

The AI Engineer has the broadest technical mandate. Aslan wants experience with agent orchestration, long-horizon behavior, post-training, evaluation, and data pipelines. It also mentions models running with limited compute. In national-security settings, a system may not have uninterrupted access to a large commercial cloud or an unrestricted external API.

The posting asks for roughly five or more years of experience but leaves room for people whose work demonstrates the necessary judgment. This is not a narrow model-training position. It mixes research judgment with production responsibility. The engineer may decide when a larger model is worth the latency, what memory should persist, and how an agent recovers from a failed step. A separate decision governs how sensitive data enters a training or evaluation loop.

The Evals Lead occupies the other side of those decisions. The posting asks for someone who has shipped evaluation systems for language models or agents, created datasets used in training, and worked closely enough with agent internals to understand failure. It also calls out provenance and lineage. That makes the role more than a benchmark owner.

An investigative agent can fail while still producing fluent prose. It can retrieve the wrong person, confuse an alias, omit exculpatory context, rely on a stale record, or draw a conclusion that outruns its citations. A useful evaluation program must test the path to the answer, not only the final sentence. It needs examples drawn from the intended work, records of model and prompt versions, expected behavior under missing data, and a process for deciding whether a failure blocks release.

Average accuracy would hide the cases an analyst fears most. A wrong restaurant recommendation is recoverable. A plausible but false link between a person and a criminal network can redirect scarce investigative time or expose that person to scrutiny. Evaluations need slices for names, languages, incomplete records, conflicting sources, and allegations that cannot be corroborated. They also need a correction test: when an analyst rejects a link, can the system preserve the correction without contaminating unrelated cases?

The Evals Lead posting says datasets may inform training. That creates a governance question the job description does not answer: how will evidence from sensitive customer work be separated from material that can be reused? A data point can be valuable for improving a system and still be inappropriate to move across customers or into a general training set. Provenance is one part of the answer. Contract terms, access controls, retention rules, and review authority are others.

The Forward Deployed Engineer turns both model and evaluation choices into working software at the customer boundary. The role asks for full-stack ability, production code, work with users, travel, and eligibility for a Top Secret clearance. The person is expected to understand a workflow closely enough to configure or extend the product, yet remain enough of an engineer to carry changes back into the core system.

Field engineers learn what users actually do instead of what a product brief says they do. They can identify data mismatches, approval bottlenecks, and cases that break a laboratory test. The same feedback loop can create one-off adaptations that are hard to maintain, blur the line between product and services, or bring customer-specific assumptions into a shared codebase.

A mature deployment discipline needs records on both sides of the loop. The customer should be able to see what changed, who approved access, and which version produced an output. The product team should be able to distinguish a reusable feature from a customer exception. The evaluation owner should know when a field change invalidates an earlier test result.

The Defense Advanced Research Projects Agency made a related point when it launched AI Forge in June. DARPA said national-security AI must be reliable, predictable, understandable to operators, and secure in contested environments. That statement does not evaluate Aslan. It sets a relevant standard for the kind of work its postings describe.

Hiring one person for each corner of the triangle does not guarantee those properties. The three roles may disagree about priorities. The product engineer can favor capability, the field engineer can favor immediate customer utility, and the evaluator can block both on evidence. The company needs a release rule that decides which failures are tolerable, who can accept residual risk, and when a customer-specific result may be generalized.

Candidates should ask for that rule during interviews. Who owns a release decision? Can the Evals Lead stop one? Does a field engineer have authority to patch production at a customer site? Which data can return to the central team? What happens when a model update improves average performance but degrades a rare, severe case?

The answers reveal more than a list of tools. They show whether the startup treats evaluation as a product control or as a demonstration layer added after the agent works.

Government revenue hires before it arrives

Two of six openings face government. Aslan separates growth from national-security leadership. At a ten-person company, those functions consume a substantial share of the hiring plan.

The Head of Growth posting is operational. It asks the hire to identify mission needs, turn those needs into validated requirements, and connect them to money. The language spans current-year execution, future budgets, the Planning, Programming, Budgeting, and Execution process, and routes outside the standard Federal Acquisition Regulation process. The company is not looking only for a salesperson with agency contacts. It wants someone who understands when a need becomes spendable.

The Head of National Security role is more institutional. Aslan seeks someone with senior experience across the Defense Department, Department of Homeland Security, or intelligence community, including people who have owned doctrine, budgets, personnel, and execution. The job is to shape the company’s mission direction and build trust with senior government leaders.

One role moves an opportunity through the machinery. The other helps determine which opportunity the company should pursue and how government decision-makers interpret the company. Keeping them separate reduces the chance that every relationship is treated as a near-term sales lead. It also puts two expensive layers of experience around a product that the company says can act with some autonomy.

The need for both becomes clearer in the current federal context. On August 12, President Donald Trump signed a memorandum on transnational cyber-enabled crime that directs the Justice and Homeland Security departments to establish a program involving vetted private companies. Participating firms would operate under federal control and oversight. The memo calls for written approval of every operation, reporting, technical and personnel standards, and measures to stop or minimize activity that reaches a U.S. person or system.

It also says small businesses should be allowed to participate if they meet the standards. Depending on the implementing contracts, a firm may need a bond or escrow of at least $1 million. DOJ and DHS have 60 days from the memorandum to issue implementation guidance, placing that deadline around October 11.

This creates a plausible market for companies that can combine investigative software, cleared people, and government operating discipline. It does not establish that Aslan applied to the program, passed vetting, received a contract, or conducted an approved operation. None of those steps appears in the public sources reviewed for this article. The memorandum and Aslan’s hiring plan are adjacent facts, not evidence of a deal.

The legal and oversight burden could also slow the market. A Center for Strategic and International Studies analysis points to unresolved questions about liability, domestic law, foreign law, insurance, and operational risk for private participants. A company might qualify technically and still decide that the exposure is unacceptable.

Civil-liberties concerns extend beyond offensive cyber operations. The American Civil Liberties Union’s report on private surveillance vendors argues that private access to police data can expand surveillance while making accountability harder to trace. The report is not about Aslan, and national-security investigations are not identical to local policing. It identifies a conflict any vendor handling sensitive investigative data has to address: the same integration that makes analysis faster can also widen access and reduce practical friction around monitoring.

Aslan says it has a red line against domestic surveillance. That is a company commitment. Buyers and the public need the operational definition. Does the restriction apply to U.S. persons, domestic location, the agency’s mission, a category of data, or a category of action? Who checks it? Can a customer override it? Is a refusal logged? What happens when an investigation begins abroad and reaches a U.S. account?

These questions do not fit cleanly inside a model evaluation. They involve policy, contract language, authorization, interface design, and escalation. The Head of National Security and Head of Growth will encounter them before a field engineer configures a deployment.

The federal government’s own procurement record suggests that institutional learning is incomplete. In April, the Government Accountability Office reported that federal agencies had doubled their reported AI use from 2023 to 2024, while lessons about AI procurement and contract clauses were not being systematically collected or shared. The GAO review is government-wide, not an assessment of Aslan. It explains why a new vendor cannot assume that a buyer already has a settled template for risk, evaluation, data rights, and accountability.

For a contracting officer or program manager, the purchase is not finished when the agent performs well in a demonstration. The contract needs acceptance tests, data-use limits, incident reporting, audit access, change-control terms, and an exit plan. It should specify what the agency can retain if the vendor fails, the model changes, or a pilot ends. Without those terms, a fast deployment can turn into dependence on a result the government cannot reproduce or contest.

The two government hires therefore sit between policy and revenue. Their work is successful only when a mission need, legal authority, procurement route, technical control, and funded contract align. An introduction or pilot announcement is not the same event.

One operator catches every orphaned function

One job absorbs the organizational leftovers. The operations posting shows where the ten-person company’s informal processes may be reaching their limit.

Aslan calls it the first business-operations hire. The person would manage financial operations, vendors, contracts, insurance, registrations, compliance, internal systems, hiring pushes, office needs, and security logistics. The list reads like the work that founders and early employees have been handling between their named jobs.

Adding a dedicated operator can free technical and government leaders to focus. It can also reveal how much organizational debt the company has accumulated. Each responsibility carries a different cadence and error cost. A missed vendor renewal is not the same as a broken payroll process. A delayed office order is not the same as an incomplete security record. One person can design the system, but the company still has to decide which duties require an outside specialist, a second reviewer, or a formal control.

The job also sits inside the hiring promise. Nearly doubling headcount in two months requires scheduling, references, offers, onboarding, benefits, equipment, workplace access, and, for some roles, clearance-related coordination. The operations hire may be asked to build that process while being processed by it.

One part of the public candidate experience needs clarification. All six current postings identify the Washington, D.C. metro area, but the pages and job-board payload reviewed on September 9 did not display a salary range. The D.C. Office of the Attorney General says covered employers have had to include minimum and maximum projected compensation in job listings since June 30, 2024. The statute ties the rule to employers with at least one employee in the District.

That does not establish a violation. “D.C. metro area” does not resolve the legal worksite, employer coverage, or whether another disclosure is provided during the application flow. Aslan can remove the ambiguity by publishing a range and identifying each role’s work location. Candidates can ask before investing time in interviews.

Pay visibility matters more in a senior-only slate. Applicants must compare cash, equity, clearance demands, travel, mission risk, and the opportunity cost of leaving an established employer. Carta’s 2026 analysis of AI compensation found that small startups have increased equity grants for AI and machine-learning hires. It also recorded more departures than hires among workers with AI skills in December 2025. Those figures cover Carta’s customer data, not Aslan’s offers. They show why a title and mission statement are not enough information for a competitive process.

The operations role can turn candidate experience into a controlled process. It can establish who approves a level, how ranges are set, when equity is explained, how long interviews should take, and which security requirements must be disclosed before an offer. Those choices affect whether a six-role plan becomes six starts.

They also test the premise of lean AI organizations. A small team can automate routine work and still need someone accountable for the unautomated edges. Aslan has placed those edges in one job description. The hire’s first task should be separating them into durable systems before the list becomes an invisible second shift.

A six-role map for sensitive AI teams

A list of titles is easy to copy. The decision rights are more useful.

Founders can use Aslan’s current slate as a diagnostic, without copying its exact titles. Start with the decision each role must make, the external constraint on that decision, and the first record that would show the work occurred.

RoleDecision surfaceWhat the posting asks forExternal constraintFirst verifiable record
AI EngineerAgent architecture, memory, models, and dataLong-horizon agents, post-training, evaluation, constrained inferenceCompute limits, data rights, security boundaryVersioned release with model, data, and behavior notes
Evals LeadWhether behavior is good enough to train or releaseAgent evaluations, datasets, failure analysis, provenanceCustomer-specific data, rare severe failures, reproducibilityEvaluation report tied to an exact system version
Forward Deployed EngineerHow the product changes for a live workflowFull-stack delivery, customer work, production code, travelSite access, clearance, configuration controlCustomer-approved deployment and change record
Head of GrowthWhether mission interest becomes funded workRequirements, current-year funds, future budgets, acquisition routesAppropriations, procurement law, timingSolicitation, award, task order, or other documented vehicle
Head of National SecurityWhich missions and relationships the company should pursueSenior mission ownership, doctrine, budgets, people, executionPublic authority, agency policy, civil libertiesWritten mission scope and accountable government sponsor
OperationsWhether the company can hire and deliver consistentlyFinance, vendors, contracts, compliance, systems, hiring, facilitiesEmployment rules, insurance, security and contractual controlsCompleted onboarding and operating-control checklist

The final column prevents a common category error. A capability claim, hiring intention, and operating record are three different things.

For Aslan, the current public evidence stops at the posting stage. A more complete ledger would run through at least nine events:

  1. The job is published.
  2. The company confirms the role has an approved budget.
  3. A candidate accepts an offer.
  4. The employee starts.
  5. Required vetting or clearance work is completed.
  6. A government buyer awards an appropriate contract or authorizes a pilot.
  7. An accountable official approves a specific operation or use.
  8. The system produces a traceable output under that authority.
  9. The buyer or an independent body evaluates the result and any harm.

Aslan’s careers page confirms the first event for six roles. Axios reports the funding and the plan to grow. The sources reviewed do not publicly confirm the remaining events for these specific hires or a future private-cyber program. A founder should not tell a board that hiring is complete when applicants are entering a funnel. A government buyer should not treat a pilot claim as authorization for a new operational setting. A reporter should not turn a company-described case into an agency-verified outcome.

The same ledger helps candidates evaluate risk. Ask whether the role exists against committed capital or an anticipated award. Ask which customer work is signed, which remains a pilot, and what happens to the position if a budget slips. For an engineering role, ask whether clearance eligibility is a condition of employment, a later assignment requirement, or simply preferred. For an evaluation role, ask whether the person can access representative data and has authority to block release.

It helps a board evaluate the hiring plan as well. The board can assign a budget, accountable executive, and contingency to each opening. If the government award slips, it should know which hires still serve the product and which depend on that award. If the Evals Lead starts after deployments expand, it should ask who owns release evidence in the interim. A six-card careers page becomes a plan only when those dependencies are explicit.

The map also exposes concentration risk. At ten employees, one departure can remove a large fraction of knowledge about a model, customer, or government process. Hiring a Head of National Security does not distribute that person’s relationships. Hiring an Evals Lead does not make evaluation independent if the same executive controls deadline, scope, and release. The company needs artifacts that allow another qualified person to reconstruct a decision.

Documentation alone is insufficient. A checklist can record that a review happened while concealing weak evidence. Useful records bind a named decision-maker, an exact system version, the data and scenario tested, the applicable authority, the result, and any exception. Sensitive details may remain classified or contract-restricted, but the organization still needs an internal record and an external way to demonstrate that a control exists.

There are reasonable arguments against reading much into six vacancies. Startups often give early employees wide titles. Job descriptions mix immediate needs with future aspirations. Some functions may already be covered by founders or outside advisers. The company may remove a posting for reasons unrelated to a hire. All true.

Those limits make the job board less useful as a forecast of success. They do not erase its value as a statement of organizational design. Aslan could have posted six software-engineering roles. Instead, half the list is government or operations work, and the engineering half is split among core systems, field deployment, and evaluation. The pattern is deliberate even if the eventual headcount differs.

Another objection is that every enterprise software startup needs sales, deployment, and operations. National security is not unique in that respect. The difference is the cost of an error and the number of authorities involved. A retail recommendation can be wrong without becoming an investigative lead. A customer-service agent can be rolled back without implicating a person’s records or a cross-border operation. Sensitive work raises the standard for evidence, access, review, and refusal.

The six-role map can therefore be simplified into three controls:

  • Capability control: the AI Engineer and Evals Lead define what the system can reliably do and how that claim is tested.
  • Use control: the Forward Deployed Engineer and government leaders connect the system to an authorized mission without losing configuration or policy boundaries.
  • Company control: Operations makes hiring, contracting, security, and delivery repeatable.

No single hire can own all three. If a founder retains final authority across them, the company should make that explicit and create a review process that can challenge the founder. “Human in the loop” begins inside the vendor before it becomes a feature shown to a buyer.

October counts hires, contracts and missing evidence

October offers a test. Aslan’s headcount target should be measured with a small set of records, not a fresh round of adjectives.

First, count starts. A new biography on the company site or a role marked filled is supporting evidence, but neither is as strong as a company-confirmed employee count. A LinkedIn profile can lag, lead, or be wrong. The baseline is ten people on September 1; the claim is nearly twice that by the end of October.

Second, watch the six postings individually. A vanished card is not automatically a hire. The company could say whether the role was filled, paused, combined, or canceled. That distinction shows whether the original organization design survived contact with the candidate market.

Third, separate headcount from customer evidence. A federal contract may appear in a public award database, but some national-security work will not be fully visible. An agency can still confirm a vendor relationship at an appropriate level, describe the authority and evaluation process, or explain why details cannot be released. Absence from a public database is not proof that no work exists. It is a limit on what an outsider can verify.

Fourth, revisit the August memorandum after its implementation deadline. The DOJ and DHS guidance should clarify eligible activities, technical standards, oversight, liability, and financial requirements for private participants. If Aslan later says it participates, the relevant evidence would be admission to the program, a contract, an assigned scope, and written approval for a particular operation. The memorandum by itself supplies none of those.

Fifth, ask what changed in the product after the Evals Lead and field engineer arrived. Useful signs include a published evaluation method, a versioned system card, clearer provenance controls, a customer-specific change process, or a documented refusal path. A generic statement about improved accuracy is not enough to connect a hire with a control.

Finally, inspect the candidate experience. Do the postings gain compensation ranges? Does Aslan add an early-career route, or does the team remain built around experienced hires? Are clearance and location requirements described consistently? These details show whether the company can recruit outside a small network of already-cleared senior operators.

By November, the public record may still be incomplete. That is normal for a private company selling into sensitive government work. Incompleteness should narrow a conclusion. It should not create suspicion by default or excuse credulity.

Aslan has published the starting numbers: ten people, $20.8 million in new capital, a plan to nearly double, and six senior roles around agents that the company says remain under human supervision.

In early November, open the six job links again. A missing card will not reveal whether someone started, a role was paused, or the plan changed. Ask for the event behind the page. Apply the same discipline to the product. A contract is not written approval, and written approval is not a verified result.

The software promises to accelerate investigations. The public record should advance one hire, one authority, and one result at a time.