Software Engineer, Security
Builds secure tools and features for platform, editor, and customer protection, including AI code review, least-privilege cloud access, and safe agent environments. Requires strong software engineering with security expertise, builder-attacker mindset, and experience scaling secure systems.
About the job
Responsibilities
- Build AI augmented code review to get involved in important systems at the right time.
- Build a least-privilege and JIT system for cloud access that enables engineers and enforces least privileges.
- Implement a safe environment for agents to engage with code.
- Implement a framework for securely handling agent manipulation of user systems (e.g., MCP tool calls and command execution).
- Implement a paved road for preventing inappropriate data from being logged.
Requirements
- Strong software engineer first, with security as your superpower.
- Think like both a builder and an attacker: anticipate vulnerabilities before they become issues.
- Care about developer experience, building solutions that are secure and frictionless.
- Comfortable moving quickly, owning problems end to end, and iterating with limited guidance.
- Experience building or scaling secure systems in fast-moving environments.
- Strong opinions on secure defaults, but can balance pragmatism with rigor.
- Enjoy working on small, high-talent teams where impact is magnified.
- Motivated by protecting developers and users, and see security as an enabler.
Skills
Cloud Infrastructure, AI, Secure Systems, Least Privilege, Jit Access, Code Review, Agent Security, Developer Tools, Vulnerability Prevention
Similar jobs
Security Engineering jobsDesign and ship security-critical software and firmware at the boundary between policy systems and hardware-backed cryptographic protection. The role requires 5+ years of secure embedded development and deep C, C++, or Rust experience.
Owns application security by embedding review workflows in SDLC, building SAST/DAST pipelines in CI/CD, managing vulnerability remediation, and operating bug bounty programs. Requires 5+ years experience finding/fixing vulnerabilities, strong skills in Python/TypeScript/Go, and SAST/DAST tooling.
Build and scale application security for an enterprise AI platform, including threat modeling, secure architecture, automated controls, code review, and penetration testing. Requires at least four years of application security experience, programming expertise, and knowledge of DevSecOps and security-testing practices.
Own fraud monitoring, threat hunting, detection rules, scoring logic, and mitigation systems for Ether.fi’s financial products and card program. The role requires strong analytical pattern recognition, cross-functional ownership, and familiarity with payment or crypto fraud as a plus.
Investigates and responds to complex fraud and product-abuse incidents, analyzes high-risk accounts and threat patterns, and improves detection and response at scale. Requires 3+ years of incident response and data analysis experience, strong Python and SQL skills, and expertise in security investigations.