Careers
Security Engineer
San Francisco · Full-time · In-person, 5 days/week
Own identity, scope, and incident response for agents that act on company systems.
ApplyObjective
Make agent authority explicit before execution and make containment decisive when behavior crosses that authority.
What you’ll own
- Agent identity and resource-scoped authorization
- Threat models for agent-to-tool, agent-to-agent, and agent-to-data paths
- Security review of evidence and approval posture before wider rollout
- Containment, root cause, and follow-through for agent incidents
Evidence of success
- Each privileged action is attributable to an agent identity and granted scope
- A security reviewer can reconstruct the decision and evidence behind an action
- Containment closes every known execution path during an incident
Constraints you should know
- Human approval cannot repair missing machine-enforced scope
- Audit evidence must come from the execution path, not a later reconstruction
- Security controls must remain usable under incident pressure
Working style
- Work in person with the founding team in San Francisco
- Read implementation code and own the operational response
- Turn threat models into shipped controls and regression tests
What we look for
- Shipped identity, PAM, or capability-based authorization in production
- Written threat models other teams used to ship changes
- Drove or co-led an incident response that closed a real exposure
- Read code in two of Go, Rust, Python, and TypeScript
Email a short note and something you have built to work@deixic.com.