What you'll do- Design and implement security across our entire stack (infra, app, data, and AI systems)
- Own authentication, authorization, and tenant isolation from first principles
- Build secure-by-default systems for log ingestion, storage, and querying
- Identify and mitigate risks in an AI-native product (prompt injection, data leakage, model misuse)
- Lead incident response and postmortems for security-related events
- Establish security practices without slowing down engineering velocity
- Work closely with engineering to embed security into everyday development-not bolt it on later
What we're looking for- Strong experience in application and/or infrastructure security at a modern SaaS company
- Deep understanding of common vulnerabilities (OWASP, auth flaws, data exfiltration, etc.)
- Experience securing distributed systems and APIs
- Comfort working in fast-moving, ambiguous environments without predefined processes
- Pragmatic mindset: you know when to push hard on security vs. unblock shipping
- Bonus: experience with AI/LLM security, observability systems, or developer tools
Our techOur stack is TypeScript end-to-end. We use PostgreSQL for relational data, Temporal for durable execution, and the Vercel AI SDK to orchestrate our AI agents against the latest models. At the infrastructure layer, we use Terraform, Kubernetes, and AWS.
Some of the most interesting engineering problems we grapple with are:
- AI agents at production scale
- Log processing at scale
- Multi-region data architecture
- Real-time streaming infrastructure
- Evals and reinforcement learning
- Zero-downtime deployments and fast rollbacks
What we offer- Competitive salary and equity
- Free lunches (in-office only)
- Health, dental, and vision insurance
- Unlimited paid time off
- Paid parental leave