> Markdown version of [/jobs/ext/584873-security-engineer](https://www.wearedevelopers.com/jobs/ext/584873-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Cognition LLC - **Location:** San Francisco, CA, United States - **Salary:** $260,000.0 - $300,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Programming Tools, Python (Programming Language), Key Management, Web Application Security, Software Vulnerability Management, Web Applications, Multi-Agent Systems, Software Security, Kubernetes, Information Technology, Codebase - **Published:** June 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=d603a53da2aee235 ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, * Deep security engineering: Hands-on experience across product security, infrastructure security, and detection and response. * Strong software engineering fundamentals: Security at Cognition means writing real code; proficiency in Python, Rust, Go, and comfort owning complex systems codebases. * Cloud security expertise: Practical experience securing Kubernetes, cloud platforms (AWS, GCP, or Azure), and multi-tenant compute environments. * Web security expertise: Hands-on experience hardening complex, modern web applications. * Threat modeling and adversarial thinking: You can look at a system and quickly identify how it breaks; you think like an attacker and design like a defender. * Incident response: Calm, methodical, and effective under pressure; experience leading incidents end to end and driving the fixes that follow. * Comfort with novel problem spaces: You are excited rather than intimidated by the security challenges unique to autonomous agents and AI-native developer tools. * Relevant industry experience: Prior experience at a frontier AI lab, applied AI company, or developer tools company. You know what good looks like in this category. * Degree from a top-tier university: BS, MS, or equivalent in Computer Science, Mathematics, Engineering, or a related technical discipline from a highly selective program. ## Description * Secure the agent execution surface: Design and harden the sandboxing, isolation, and runtime controls that let Devin safely execute untrusted code and use tools across long-horizon tasks. * Own product and infrastructure security: Lead threat modeling, secure design reviews, and vulnerability management across Devin, Windsurf, and the underlying infrastructure they run on. * Build security tooling that engineers actually use: Create internal systems for secrets management, identity and access, dependency security, and detection that integrate naturally into how the team ships. * Lead incident response and detection: Build the detection pipeline, run incident response, and turn every event into systemic improvements. * Drive customer trust: Partner with go-to-market and legal teams to support compliance and customer trust initiatives. Build the controls that customers expect from a tool deeply embedded in their engineering workflow. ## Related Videos - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [Getting to Know Your Legacy (System) with AI-Driven Software Archeology](https://www.wearedevelopers.com/videos/1437-getting-to-know-your-legacy-system-with-ai-driven-software-archeology) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Why your codebase lies to AI?](https://www.wearedevelopers.com/videos/100281-why-your-codebase-lies-to-ai) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)