01 · Full-time · Remote
AI Security Engineer
Defend an autonomous agent with a live browser, real credentials, and access to a human's private world.
Apply for this role →The work
This is a build-and-defend role, not a policy role. You will model threats, write controls, red-team the live agent, and harden the runtime at the same pace we ship product.
- Threat-model prompt injection, tool abuse, untrusted web content, and cross-tenant exfiltration.
- Harden Firecracker isolation, host and VM boundaries, OAuth tokens, API keys, and keyring custody.
- Build adversarial harnesses, anomaly detection, abuse controls, and permanent regression tests.
- Own incident response from detection to same-day fix, then close the whole class of failure.
- Push toward host-root-resistant privacy with encryption, crypto-shred, and honest guarantees.
You may be a fit if
- You ship security code across application, infrastructure, and host layers.
- You understand agentic threats in practice: injection, jailbreaks, tool calls, poisoning, and leakage.
- You are comfortable with Linux, networking, sandboxing, secrets, Python, and TypeScript.
- You think adversarially and prefer a real control today to a perfect slide deck next quarter.