Skip to content
CursorCursor

Software Engineer, Security

Builds secure tools and features for platform, editor, and customer protection, including AI code review, least-privilege cloud access, and safe agent environments. Requires strong software engineering with security expertise, builder-attacker mindset, and experience scaling secure systems.

About the job

Responsibilities

  • Build AI augmented code review to get involved in important systems at the right time.
  • Build a least-privilege and JIT system for cloud access that enables engineers and enforces least privileges.
  • Implement a safe environment for agents to engage with code.
  • Implement a framework for securely handling agent manipulation of user systems (e.g., MCP tool calls and command execution).
  • Implement a paved road for preventing inappropriate data from being logged.

Requirements

  • Strong software engineer first, with security as your superpower.
  • Think like both a builder and an attacker: anticipate vulnerabilities before they become issues.
  • Care about developer experience, building solutions that are secure and frictionless.
  • Comfortable moving quickly, owning problems end to end, and iterating with limited guidance.
  • Experience building or scaling secure systems in fast-moving environments.
  • Strong opinions on secure defaults, but can balance pragmatism with rigor.
  • Enjoy working on small, high-talent teams where impact is magnified.
  • Motivated by protecting developers and users, and see security as an enabler.

Skills

Cloud Infrastructure, AI, Secure Systems, Least Privilege, Jit Access, Code Review, Agent Security, Developer Tools, Vulnerability Prevention

OpenAI

OpenAI

San Francisco, CA

Software Engineer, HSM Infrastructure Security, Consumer Devices
$347k+/yrOn-site5+ YOESecurity Engineering

Design and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.

Mercor

Mercor

San Francisco, CA
Security Engineer, Application Security
$130k+/yrOn-site5+ YOESecurity Engineering

Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.

Writer

Writer

New York, NY
Security Engineer, Application Security
$132k+/yrHybrid4+ YOESecurity Engineering

Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.

Ether.Fi

Ether.Fi

New York, NY
Fraud Engineer
No salary listedHybridSecurity Engineering

Own fraud monitoring, threat hunting, detection rules, scoring logic, and mitigation systems for Ether.fi’s financial products and card program. The role requires strong analytical pattern recognition, cross-functional ownership, and familiarity with payment or crypto fraud as a plus.

Stripe

Stripe

United States

Investigator
No salary listedRemote3+ YOESecurity Engineering

Investigates and responds to complex fraud and product-abuse incidents, analyzes high-risk accounts and threat patterns, and improves detection and response at scale. Requires 3+ years of incident response and data analysis experience, strong Python and SQL skills, and expertise in security investigations.