Software Engineer, Security

COHERE, LLC
Toronto, United States
3 days ago
Apply on arc.dev
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$156,000.0
Working hours
Regular working hours
Job source

Tech stack

Computer-Aided Design Artificial Intelligence Amazon Web Services User Authentication Microsoft Azure Python (Programming Language) OAuth OpenID Role-Based Access Control Secure Coding Session Management Software Engineering
+6 more
Google Cloud Large Language Models Multi-Cloud Kubernetes Machine Learning Operations Devsecops

Job description

Are you passionate about secure-by-design software engineering? Do you want to be at the forefront of AI innovation and enterprise security? Cohere’s North team is seeking a Software Engineer with a focus on security to join our mission and make a significant impact. This isn’t a review-and-advise role, you’ll own and ship production security features that customers rely on every day., As a Senior Software Engineer with a security focus, you’ll play a pivotal role in building and securing North’s architecture. Your responsibilities will include:

  • Software Development: Contributing to the core development of security features such as OIDC/OAuth flows and session management, ensuring North’s AI agents are secure
  • Secure Coding: Writing secure code to handle OIDC tokens, user claims, and sensitive data, adhering to best practices for JWT validation and encryption
  • Authentication and Data Protection: Implementing authentication mechanisms including user login, token management, and authorization checks to maintain data integrity
  • Tool Integration: Pulling in new tools to enhance North’s security capabilities
  • DevSecOps: Design and implement secret management within Kubernetes clusters, including encryption and RBAC
  • Cross-functional Collaboration: Demonstrate strong soft skills to communicate security best practices to stakeholders in a clear and concise manner

Requirements

  • Have 5+ years building user-facing security features in production systems
  • Ship production Python confidently and frequently
  • Understand OIDC/OAuth 2.0, JWT validation, and token lifecycle management deeply-not just conceptually
  • Have hands-on experience with Kubernetes in both development and production environments
  • Have worked across GCP, AWS, Azure, or hybrid/multi-cloud deployments
  • Are comfortable working across the stack
  • Communicate security concepts clearly to non-security engineers and stakeholders
  • Thrive in fast-moving environments where priorities evolve
  • Experience working with AI/ML systems or LLM-based applications

Benefits & conditions

  • A weekly lunch stipend of $75/£75 or equivalent in your local currency for lunch.
  • Full health and dental benefits, including a separate budget for mental health.
  • RRSP matching, 401K, Pension Scheme.
  • 100% Parental Leave top-up for up to 6 months, for either parent.
  • Annual enrichment benefits:

Arts & culture, fitness/wellness, quality time, and a workspace improvement credit.

Education & learning stipend for conferences, courses, and coaching.

  • 6 weeks of paid vacation (30 working days!)
  • Budget for traveling to other offices if you are remote, plus an annual company offsite.

About the company

Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems.

We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that.

We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft.

We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us!, * Cohere is remote-friendly, but we also have offices in Toronto, London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul with more opening soon.

  • For those in the office: a daily lunch program, plenty of snacks, and regular community and social events.
  • For those not near an office: a co-working benefit so you can work alongside others in your city.
  • Everyone receives a $500 home office stipend to set up your workspace properly.

If any of the above doesn’t line up exactly with your experience, we still encourage you to apply.

We strive to create an inclusive work environment for all; we welcome applicants from all backgrounds and are committed to providing equal opportunities. Should you require any accommodations during the recruitment process, please submit an Accommodations Request Form, and we will work together to meet your needs.

We may use AI-enabled tools to screen and assess applicants against the criteria for this position. This helps our recruiters identify potentially qualified candidates, but it doesn’t limit the applications our recruiters may review or consider.

Beware of Scams: Cohere will never ask for payment or third-party services (e.g., CV writing) as part of our hiring process. All legitimate roles are listed on the Cohere careers page and LinkedIn only, with all communications from Cohere employees coming from an @cohere.com or @cw.cohere email alias. If jobs are viewed on other sites then please verify these through our official careers _page._Compensation Range: $180K - $325K

About Cohere

201-500 Toronto

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on arc.dev
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all