Skip to content
CognitionCognition

Security Engineer

Security Engineer responsible for securing AI agent execution, infrastructure, and product surfaces at an applied AI lab building Devin and Windsurf. Requires deep security engineering, software engineering fundamentals, and cloud/web security expertise.

About the job

What You'll Accomplish

  • Secure the agent execution surface: Design and harden the sandboxing, isolation, and runtime controls that let Devin safely execute untrusted code and use tools across long-horizon tasks.
  • Own product and infrastructure security: Lead threat modeling, secure design reviews, and vulnerability management across Devin, Windsurf, and the underlying infrastructure they run on.
  • Build security tooling that engineers actually use: Create internal systems for secrets management, identity and access, dependency security, and detection that integrate naturally into how the team ships.
  • Lead incident response and detection: Build the detection pipeline, run incident response, and turn every event into systemic improvements.
  • Drive customer trust: Partner with go-to-market and legal teams to support compliance and customer trust initiatives. Build the controls that customers expect from a tool deeply embedded in their engineering workflow.

Exceptional Candidates Have Demonstrated

  • Deep security engineering: Hands-on experience across product security, infrastructure security, and detection and response.
  • Strong software engineering fundamentals: Security at Cognition means writing real code; proficiency in Python, Rust, Go, and comfort owning complex systems codebases.
  • Cloud security expertise: Practical experience securing Kubernetes, cloud platforms (AWS, GCP, or Azure), and multi-tenant compute environments.
  • Web security expertise: Hands-on experience hardening complex, modern web applications.
  • Threat modeling and adversarial thinking: You can look at a system and quickly identify how it breaks; you think like an attacker and design like a defender.
  • Incident response: Calm, methodical, and effective under pressure; experience leading incidents end to end and driving the fixes that follow.
  • Comfort with novel problem spaces: You are excited rather than intimidated by the security challenges unique to autonomous agents and AI-native developer tools.
  • Relevant industry experience: Prior experience at a frontier AI lab, applied AI company, or developer tools company.
  • Degree from a top-tier university: BS, MS, or equivalent in Computer Science, Mathematics, Engineering, or a related technical discipline from a highly selective program.

Compensation & Benefits

  • Base Salary: $260,000 - $300,000 + significant early-stage equity
  • Medical, Dental, Vision: Fully paid for you and your dependents
  • 401(k): Company match included
  • Perks: Private chef, cozy slippers, endless snacks, and more

Skills

Python, Rust, Go, Kubernetes, AWS, GCP, Azure, Cloud Security, Web Security, Threat Modeling, Incident Response, Sandboxing, Secrets Management, Identity And Access Management

OpenAI

OpenAI

San Francisco, CA

Cyber Operations Lead, Critical Harm Operations
$252k+/yrHybrid8+ YOESecurity Engineering

Leads cybersecurity and cyber intelligence operations for high-risk user-safety decisions, combining strategic planning, operational systems, automation, and direct people management. Requires 8+ years in cybersecurity-related work and 4+ years leading teams.

OpenAI

OpenAI

San Francisco, CA

Software Security Architect, Operating Systems | Consumer Devices
$268k+/yrOn-site7+ YOESecurity Engineering

Defines the security architecture for a next-generation operating system, spanning trust boundaries, hardware-backed protections, isolation, secure updates, and AI-agent guardrails. The role requires deep privileged-systems expertise, systems programming ability, and experience securing platforms across hardware, firmware, and software.

Anthropic

Anthropic

Washington, DC
Safeguards Enforcement Lead, Cyber Harms
$285k+/yrHybridSecurity Engineering

Leads cyber-focused AI misuse enforcement, managing analysts and contractors while developing detection and mitigation strategies for attacks, malware, and exploitation. Requires people management, cybersecurity expertise, high-volume abuse enforcement, data analysis with SQL or Python, and cross-functional risk communication.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Imprint

Imprint

San Francisco, CA
Senior Engineering Manager, Security
$220k+/yrHybrid8+ YOESecurity Engineering

Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.