Primary record

Security Engineer

Cognition Indexed employerSan Francisco
Source-hosted applyChecked 1h agoFull-Time
Apply at Cognition

Cognition receives this application through Ashby. Babu Careers does not claim delivery.

Workplace

On-site

Employment

Full-Time

Published

Aug 6, 2026

Closes

No date supplied

The role

WE ARE AN APPLIED AI LAB BUILDING END-TO-END SOFTWARE AGENTS. We're the makers of Devin, the first AI software engineer. Our team is extremely talent-dense. Among our founding team, we have world-class competitive programmers, former founders, and leaders from companies at the cutting edge of AI including Scale AI, Palantir, Cursor, Waymo, Tesla, Lunchclub, Modal, Google DeepMind, and Nuro. Building Devin is just the first step—our hardest challenges still lie ahead. If you’re excited to solve some of the world’s biggest problems and build AI that can reason on real-world tasks, apply to join us. About the Role Security Engineers at Cognition own one of the most interesting security surfaces in the industry. Devin executes arbitrary code on behalf of users across millions of sandboxed sessions. Windsurf operates inside developer environments at scale. Both products handle highly sensitive customer code, credentials, and infrastructure access. You will help define what security looks like for AI-native developer tools and build the controls, systems, and culture that let Cognition ship fast without compromising on safety. This is a role for engineers who want to do hands-on, high-leverage security work at the edge of what is being figured out for the first time. What You'll Accomplish - Secure the agent execution surface: Design and harden the sandboxing, isolation, and runtime controls that let Devin safely execute untrusted code and use tools across long-horizon tasks. - Own product and infrastructure security: Lead threat modeling, secure design reviews, and vulnerability management across Devin, Windsurf, and the underlying infrastructure they run on. - Build security tooling that engineers actually use: Create internal systems for secrets management, identity and access, dependency security, and detection that integrate naturally into how the team ships. - Lead incident response and detection: Build the detection pipeline, run incident response, and turn every e

Requirements

Department: Research & Development; Team: Core Engineering