← Careers

Careers

Security Engineer

San Francisco · Full-time · In-person, 5 days/week

Own identity, scope, and incident response for agents that act on company systems.

Apply

Objective

Make agent authority explicit before execution and make containment decisive when behavior crosses that authority.

What you’ll own

  • Agent identity and resource-scoped authorization
  • Threat models for agent-to-tool, agent-to-agent, and agent-to-data paths
  • Security review of evidence and approval posture before wider rollout
  • Containment, root cause, and follow-through for agent incidents

Evidence of success

  • Each privileged action is attributable to an agent identity and granted scope
  • A security reviewer can reconstruct the decision and evidence behind an action
  • Containment closes every known execution path during an incident

Constraints you should know

  • Human approval cannot repair missing machine-enforced scope
  • Audit evidence must come from the execution path, not a later reconstruction
  • Security controls must remain usable under incident pressure

Working style

  • Work in person with the founding team in San Francisco
  • Read implementation code and own the operational response
  • Turn threat models into shipped controls and regression tests

What we look for

  • Shipped identity, PAM, or capability-based authorization in production
  • Written threat models other teams used to ship changes
  • Drove or co-led an incident response that closed a real exposure
  • Read code in two of Go, Rust, Python, and TypeScript

Email a short note and something you have built to work@deixic.com.