Security Engineer

Cognition LLC
San Francisco, CA, United States
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$260,000.0 - $300,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Programming Tools Python (Programming Language) Key Management Web Application Security Software Vulnerability Management Web Applications Multi-Agent Systems
+4 more
Software Security Kubernetes Information Technology Codebase

Job description

  • Secure the agent execution surface: Design and harden the sandboxing, isolation, and runtime controls that let Devin safely execute untrusted code and use tools across long-horizon tasks.
  • Own product and infrastructure security: Lead threat modeling, secure design reviews, and vulnerability management across Devin, Windsurf, and the underlying infrastructure they run on.
  • Build security tooling that engineers actually use: Create internal systems for secrets management, identity and access, dependency security, and detection that integrate naturally into how the team ships.
  • Lead incident response and detection: Build the detection pipeline, run incident response, and turn every event into systemic improvements.
  • Drive customer trust: Partner with go-to-market and legal teams to support compliance and customer trust initiatives. Build the controls that customers expect from a tool deeply embedded in their engineering workflow.

Requirements

Do you have experience in Vulnerability management?, Do you have a Bachelor’s degree?, * Deep security engineering: Hands-on experience across product security, infrastructure security, and detection and response.

  • Strong software engineering fundamentals: Security at Cognition means writing real code; proficiency in Python, Rust, Go, and comfort owning complex systems codebases.
  • Cloud security expertise: Practical experience securing Kubernetes, cloud platforms (AWS, GCP, or Azure), and multi-tenant compute environments.
  • Web security expertise: Hands-on experience hardening complex, modern web applications.
  • Threat modeling and adversarial thinking: You can look at a system and quickly identify how it breaks; you think like an attacker and design like a defender.
  • Incident response: Calm, methodical, and effective under pressure; experience leading incidents end to end and driving the fixes that follow.
  • Comfort with novel problem spaces: You are excited rather than intimidated by the security challenges unique to autonomous agents and AI-native developer tools.
  • Relevant industry experience: Prior experience at a frontier AI lab, applied AI company, or developer tools company. You know what good looks like in this category.
  • Degree from a top-tier university: BS, MS, or equivalent in Computer Science, Mathematics, Engineering, or a related technical discipline from a highly selective program.

Benefits & conditions

4.14.1 out of 5 stars San Francisco, CA $260,000 - $300,000 a year - Full-time, Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance, * Base Salary: $260,000 - $300,000 + significant early-stage equity
  • Medical, Dental, Vision: Fully paid for you and your dependents
  • 401(k): Company match included

About the company

Cognition is an applied AI lab building end-to-end software agents. We are behind Devin, the first AI software engineer, and Windsurf, an AI-native IDE. Our vision is AI that works alongside engineers as a genuine teammate, not a tool.

We are a small, talent-dense team of competitive programmers, former founders, and researchers from Scale AI, Palantir, Cursor, Google DeepMind, and others.

Role Mission

Security Engineers at Cognition own one of the most interesting security surfaces in the industry. Devin executes arbitrary code on behalf of users across millions of sandboxed sessions. Windsurf operates inside developer environments at scale. Both products handle highly sensitive customer code, credentials, and infrastructure access. You will help define what security looks like for AI-native developer tools and build the controls, systems, and culture that let Cognition ship fast without compromising on safety. This is a role for engineers who want to do hands-on, high-leverage security work at the edge of what is being figured out for the first time.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:34 min

Augmenting codebases with semantic architectures

Zaak Chalal Zaak Chalal · WWC Europe 2026

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · WWC 2022

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:32 min

Overcoming modernization challenges in aging monolithic codebases

Igor Minar Igor Minar +1 · WWC 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all