
How to Actually Get Hired
Who reads applications, which channel gets a reply, and what they screen for.
Don't make these mistakes
Cold outreach that does not mention the CRA by name. Any generic cybersecurity or compliance platform positioning. CRACI is specifically a CRA compliance automation product. If your outreach could apply to any compliance software company, it will not land.
What gets their attention
Lifeline Ventures is the most important signal in this round. They are the Helsinki-based fund that backed Wolt when it was a food delivery app in three Finnish cities and Supercell before Clash of Clans existed. Their investing thesis concentrates on technical founders with a category-creating product in a market that is about to be forced to care by external pressure. Juha Lindfors' quote names the thesis explicitly: "The CRA is rewriting the rules for software in Europe, and CRACI is building what this new era demands." When Lifeline makes a conviction bet at pre-seed, they expect the company to become the category default, not a niche tool. That scale ambition shapes hiring: they need a platform that works for the 99% of companies in scope, not just the ones that can afford a dedicated compliance team. Lucas Käldström as angel is the technical credibility anchor. He is a core Kubernetes ecosystem contributor (Upbound, previously Weaveworks and CNCF ambassador), a speaker who presented at the CRACI-organised Kubernetes security meetup at Founders House Helsinki, and someone who put personal money in after evaluating the technical approach from the inside. That is not a networking bet. It is a technical conviction. First Fellow Partners and Wave Ventures add the early-stage Nordic tech founder network. Wave specifically backs early-stage Finnish founders and has a track record of writing checks before anyone else is paying attention. The team is already 13 people from 4 founders, which means CRACI has been hiring since founding. The empty careers page is not absence of ambition. It is the period between "we have the money" and "we have the job descriptions written." That window is days to weeks, not months. Contact: craci.com/contact · @cracicorp on X · linkedin.com/company/craci
Why applying the normal way doesn't work
CRACI is <50 people. No recruiter, no HR. Your application goes to a founder juggling everything. Cold outreach is how you actually get seen.
Who to contact at CRACI
Founding team
Juho Niemi studied at Aalto University, which is not only Finland's most productive founder school (ranked 8th in Europe by VC-backed startup alumni 2011-2021, and responsible for a hand in every Finnish unicorn) but also the institution where CRACI's CTO did his master's thesis and where Dennis and Erika Marttinen both studied. The origin of the company is therefore a cohort effect as much as a founding decision: people who built relationships through Aalto's technical culture and then decided to solve one of the hardest unsolved problems in software supply chain security together. Juho describes the CRACI thesis on LinkedIn as solving what was "thought to be impossible" in software supply chain visibility, which is not hyperbole. Getting provably complete SBOM coverage at the transitive dependency level, continuously, across every deployed version of every product, is genuinely unsolved at production scale in most enterprises. His public operating style is visible from his LinkedIn feed: he organises Kubernetes security meetups at Founders House Helsinki (CRACI hosted the event, with Lucas Käldström and Stacklok's Juan Antonio Osorio as speakers), he travelled to New York with Dennis for the Nordic AI Night to position CRACI in the global security conversation, and he posts about supply chain attacks in real time when they happen (his npm supply chain attack post about Axios is the kind of content that lands in the feeds of the exact CISOs who are his buyers). He is not a founder who posts inspirational content. He posts when something is operationally relevant to his customers. His DMs are explicitly open for CRA conversations. The pre-seed announcement ends: "If you're shipping products with software into the EU and the CRA is on your roadmap, we'd love to compare notes on what your prep looks like today." CRACI was the first batch at Founders House Helsinki, a curated founder workspace that opened in the former Sähkötalo (Electrical House) building in central Helsinki and is described in Finnish media as an "ihmeittentekijätimonenavaruus" (roughly: a space for wonder-makers, a Finnish culture reference). Juho's co-founders are not just professional colleagues: they are part of the same Aalto technical cohort that has produced a disproportionate share of Nordic deep tech. The fact that the company hosted a Kubernetes security meetup before its own funding was public is the tell: they are building community before they are building pipeline, which is the right order.
Dennis Marttinen is the most extensively documented of the CRACI founders in public technical records, and the documentation is impressive. He completed a double-degree Master of Science in Security and Cloud Computing (SECCLO) across Aalto University in Finland and NTNU (Norwegian University of Science and Technology) in Norway, one of the most rigorous cybersecurity master's programmes in the Nordic region, which explicitly combines cloud-native security, network security, and HPC. His master's thesis, Supernetes: Establishing Synergy Between Supercomputers and Cloud Computing, was presented live on stage at KubeCon + CloudNativeCon Europe 2025 in London, one of the largest cloud-native computing conferences in the world. Supernetes is an open-source HPC-to-Kubernetes bridge that creates a 1-to-1 bidirectional mapping between Slurm-scheduled supercomputer jobs and Kubernetes Pods, and he demonstrated it live on LUMI, a global top-10 supercomputer based in Kajaani, Finland, operated by CSC. That is a KubeCon main stage talk, in a room of thousands of engineers, demonstrating software that runs on one of the most powerful computers on the planet. He was a student at the time. Before founding CRACI, his open-source contributions include Weave Ignite (a production container-to-microVM solution co-authored with the Weaveworks team, which produced Weave Scope and Flux CD and was later acquired by AWS), Racklet (a scale model datacenter rack project presented at KCD Africa 2021 that won community recognition for making distributed systems education accessible), and Supernetes (his own project, now hosted under the supernetes GitHub organisation). He is also listed as co-author of kubeadm, the standard tool for bootstrapping Kubernetes clusters, which is used by millions of engineers globally every time they set up a new cluster. His GitHub handle is @twelho and his profile bio reads: "Kubernetes, Supercomputing, Security + more." That is the accurate one-line summary of what he actually does. His SECCLO degree runs across two countries and two universities simultaneously, which is structurally unusual: students do the first year at one institution and the second year at the partner institution, producing engineers who have operated in two national technical cultures and two regulatory environments, relevant for a company building EU regulatory compliance software. Erika Marttinen (CRACI's Software Engineer, also an Aalto CS student with an exchange semester at TU Wien) shares his surname, suggesting a family connection on the founding team. His KubeCon talk was accepted on the strength of Supernetes alone, without a company affiliation: he was still a student presenting an open-source project he had built during his thesis, in a room with engineers from Google, AWS, Microsoft, and every major cloud-native company. He is now applying the same infrastructure rigour to software supply chain security.
Jaakko Sirén is the product co-founder at CRACI. His LinkedIn handle is jaakkonen, and his public profile is lower than Juho's and Dennis's. He holds a background consistent with the Aalto founder cohort and is responsible for the platform's product direction: what the SBOM graph interface looks like for a CTO or Head of Engineering who is not a compliance specialist, how vulnerability handling integrates into pull request workflows without adding friction, and how the product scales from a startup with 10 microservices to an enterprise with 500 products in production. His role title is CPO, which at a 13-person company means he is simultaneously doing product strategy, customer discovery, and UX decisions. The platform's positioning, "CRACI as your CI" and "compliance ships with every build" is clean product thinking that reflects someone who has translated a complex regulatory requirement into a single sentence that an engineer can act on. He was specifically named alongside Dennis Marttinen as the person Dennis spent "the 6 craziest months of my life" building with, in a LinkedIn post Dennis wrote about the founding period, suggesting the two had been building CRACI together from the earliest days before Juho and Petteri joined or formalised the co-founding structure. His LinkedIn is sparse but his connection to the Aalto Kubernetes and cloud-native community is confirmed through the founding team context.
Petteri Pulkkinen is the security leadership co-founder at CRACI: the person responsible for ensuring that a compliance automation platform is itself secure, and for translating what "CRA compliance" actually means in legal and technical terms into the product's design constraints. At a company selling security compliance software, the CISO co-founder is the trust anchor: the person who can sit in a customer conversation with a CISO at a Nordic industrial company and speak at the same technical and regulatory depth. Tomorrow (May 20, 2026), Petteri and Erika Marttinen are speaking together at KCD Helsinki, the regional Kubernetes Community Day, on the future of software supply chains. That is not a marketing event. KCD Helsinki draws the serious Kubernetes practitioners in the Finnish cloud-native community, and speaking there on software supply chain security the day after a funding announcement is a deliberate community signal. The CRACI team is not announcing then retreating. They are immediately embedding in the community that their product serves.
What to show them
CRACI's SBOM graph needs to ingest build outputs, track dependencies continuously, reconcile against CVE feeds, and trace exposures upward through the product graph in real time. That is a distributed systems and security engineering problem simultaneously. Dennis Marttinen's background (Kubernetes, HPC, cloud security, SECCLO) sets the technical bar. The team already has Veeti Poutsalo as Platform Engineer and Erika Marttinen as Software Engineer, but the platform workload scales with every new customer. Tomorrow (May 20) Petteri and Erika are speaking at KCD Helsinki about software supply chains, which is where the next hire will likely be in the room. Core skills: Kubernetes, cloud-native security, SBOM tooling (Syft, Grype, CycloneDX, SPDX), CI/CD pipeline integration (GitHub Actions, GitLab CI, Jenkins), Go or Rust, dependency graph modelling, CVE feed ingestion and reconciliation, container security. Proof of work: Build a minimal SBOM generation pipeline that hooks into a GitHub Actions workflow, produces a CycloneDX SBOM from a build, compares it against the OSVC CVE database, and outputs a structured vulnerability report with affected components and versions. Publish the Action. Document what your tool misses at transitive dependency depth and how you would fix it.
A cold email that works at CRACI
What CRACI screens for
Lifeline Ventures is the most important signal in this round. They are the Helsinki-based fund that backed Wolt when it was a food delivery app in three Finnish cities and Supercell before Clash of Clans existed. Their investing thesis concentrates on technical founders with a category-creating product in a market that is about to be forced to care by external pressure. Juha Lindfors' quote names the thesis explicitly: "The CRA is rewriting the rules for software in Europe, and CRACI is building what this new era demands." When Lifeline makes a conviction bet at pre-seed, they expect the company to become the category default, not a niche tool. That scale ambition shapes hiring: they need a platform that works for the 99% of companies in scope, not just the ones that can afford a dedicated compliance team. Lucas Käldström as angel is the technical credibility anchor. He is a core Kubernetes ecosystem contributor (Upbound, previously Weaveworks and CNCF ambassador), a speaker who presented at the CRACI-organised Kubernetes security meetup at Founders House Helsinki, and someone who put personal money in after evaluating the technical approach from the inside. That is not a networking bet. It is a technical conviction. First Fellow Partners and Wave Ventures add the early-stage Nordic tech founder network. Wave specifically backs early-stage Finnish founders and has a track record of writing checks before anyone else is paying attention. The team is already 13 people from 4 founders, which means CRACI has been hiring since founding. The empty careers page is not absence of ambition. It is the period between "we have the money" and "we have the job descriptions written." That window is days to weeks, not months. Contact: craci.com/contact · @cracicorp on X · linkedin.com/company/craci
Customize your CV for the CRACI role. Matching the job description language helps clear ATS filters.
Mistakes that kill applications
A recycled CV gets rejected fast at CRACI (<50 people). They notice.
Don't open with what you want. Open with what CRACI is dealing with right now — The CRA comes into force in September 2026, and what you'd do about it.
Applying and waiting = silence. Follow up at day five — it roughly doubles your odds of a reply.
Frequently asked questions
How do I apply to CRACI?
Through the roles on our CRACI jobs page, or directly to a founder or department head if you can reach them. At <50 people, direct outreach outperforms the form.
Does CRACI respond to cold emails?
Response rate data for CRACI not yet confirmed.
Who is the hiring manager at CRACI?
At this size, hiring is usually run by a founder or department head.
How competitive is it to get hired at CRACI?
Typical applicant count for AI roles (<50 people): 50-100 in two weeks. Apply fast.
Have your application sent for you
We find roles at companies like CRACI within 48 hours of them appearing, build a CV tailored to the posting, and send it while you're still applicant number ten.
Get early access →