Security Engineer
Cognition San Francisco, California, United States · $260K–$300K/yr
Software Development · 51-200 employees
About the role
You will secure the agent execution surface by designing sandboxing and runtime controls for untrusted code. Additionally, you will lead threat modeling, vulnerability management, and incident response across the company's infrastructure and products.
What they look for
Requirements
Candidates must have deep experience in security engineering, software fundamentals, and cloud security, specifically with Kubernetes and major cloud platforms. A degree in a technical discipline from a highly selective program is required.
Benefits
Full description
We are an applied AI lab building end-to-end software agents.
We're the makers of Devin, the first AI software engineer.
Our team is extremely talent-dense. Among our founding team, we have world-class competitive programmers, former founders, and leaders from companies at the cutting edge of AI including Scale AI, Palantir, Cursor, Waymo, Tesla, Lunchclub, Modal, Google DeepMind, and Nuro.
Building Devin is just the first step—our hardest challenges still lie ahead. If you’re excited to solve some of the world’s biggest problems and build AI that can reason on real-world tasks, apply to join us.
About the Role
Security Engineers at Cognition own one of the most interesting security surfaces in the industry. Devin executes arbitrary code on behalf of users across millions of sandboxed sessions. Windsurf operates inside developer environments at scale. Both products handle highly sensitive customer code, credentials, and infrastructure access. You will help define what security looks like for AI-native developer tools and build the controls, systems, and culture that let Cognition ship fast without compromising on safety. This is a role for engineers who want to do hands-on, high-leverage security work at the edge of what is being figured out for the first time.
What You'll Accomplish
- Secure the agent execution surface: Design and harden the sandboxing, isolation, and runtime controls that let Devin safely execute untrusted code and use tools across long-horizon tasks.
- Own product and infrastructure security: Lead threat modeling, secure design reviews, and vulnerability management across Devin, Windsurf, and the underlying infrastructure they run on.
- Build security tooling that engineers actually use: Create internal systems for secrets management, identity and access, dependency security, and detection that integrate naturally into how the team ships.
- Lead incident response and detection: Build the detection pipeline, run incident response, and turn every event into systemic improvements.
- Drive customer trust: Partner with go-to-market and legal teams to support compliance and customer trust initiatives. Build the controls that customers expect from a tool deeply embedded in their engineering workflow.
Exceptional Candidates Have Demonstrated
- Deep security engineering: Hands-on experience across product security, infrastructure security, and detection and response.
- Strong software engineering fundamentals: Security at Cognition means writing real code; proficiency in Python, Rust, Go, and comfort owning complex systems codebases.
- Cloud security expertise: Practical experience securing Kubernetes, cloud platforms (AWS, GCP, or Azure), and multi-tenant compute environments.
- Web security expertise: Hands-on experience hardening complex, modern web applications.
- Threat modeling and adversarial thinking: You can look at a system and quickly identify how it breaks; you think like an attacker and design like a defender.
- Incident response: Calm, methodical, and effective under pressure; experience leading incidents end to end and driving the fixes that follow.
- Comfort with novel problem spaces: You are excited rather than intimidated by the security challenges unique to autonomous agents and AI-native developer tools.
- Relevant industry experience: Prior experience at a frontier AI lab, applied AI company, or developer tools company. You know what good looks like in this category.
- Degree from a top-tier university: BS, MS, or equivalent in Computer Science, Mathematics, Engineering, or a related technical discipline from a highly selective program.
Compensation & Benefits
- Base Salary: $260,000 - $300,000 + significant early-stage equity
- Medical, Dental, Vision: Fully paid for you and your dependents
- 401(k): Company match included
Perks: Private chef, cozy slippers, endless snacks, and more
Equal Opportunity
Cognition is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic under applicable law. We are committed to providing reasonable accommodations for candidates with disabilities throughout the hiring process - please let us know if you need any.
Similar roles
-
Cyber Wireless Security Engineer
General Dynamics Information Technology Hoke County, North Carolina, United States · $94K–$126K/yr
-
Cybersecurity Architecture Engineer
Leidos Huntsville, Alabama, United States · $58K–$105K/yr
-
Associate Director, AI Software Security Engineer
RTX Tewksbury, Massachusetts, United States · $157K–$299K/yr
-
Senior Cybersecurity Advisor
TC Energy Calgary, Alberta, Canada
-
AVP, Application Security
CVS Health Island, Kentucky, United States · $185K–$376K/yr
-
Cybersecurity Engineer - US Federal
Workday Reston, Virginia, United States · $118K–$210K/yr