Software Engineer, Enterprise Platform

Backend Engineer · Senior · Full Time

SF / Remote4mo ago
Apply for this role

Opens Cursor's application page

Role

What you'll do.

Cursor is seeking an Enterprise Platform Engineer to build foundational systems for large-scale engineering organizations. This IC role focuses on developing organization management, RBAC, compliance features, and administrative tooling to make Cursor enterprise-ready. The position requires deep technical expertise in multi-tenant systems, authorization frameworks, and enterprise security infrastructure.

Responsibilities

  • Organization Management System: Build and evolve multi-level organizational structures, groups, roles, and lifecycle management with SCIM provisioning for seamless admin experience
  • RBAC Implementation: Design and implement Role-Based Access Control with fine-grained permissions and resource scopes covering organizations, teams, agents, and resources
  • Enterprise Policy Framework: Extend enterprise settings and policies including org-wide defaults, security policies for models and tools, and configuration inheritance
  • Audit Infrastructure: Deepen audit logging infrastructure with comprehensive, queryable, tamper-evident trails meeting compliance requirements
  • Administrative APIs: Build admin APIs and internal tooling for enterprise admins, customer success, and sales engineering teams
  • Compliance Features: Ship end-to-end compliance features including SSO enforcement, session management, allowlisting, and security controls
  • Cross-team Collaboration: Partner with product, security, and infrastructure teams to define scalable enterprise platform abstractions
  • Technical Authority: Serve as technical authority on identity, access, and governance modeling for enterprise customers

Qualifications

What we look for.

Technical

  • Multi-tenant Systems

    Production experience building multi-tenant organization or IAM systems with deep understanding of permission models

  • Authorization Systems

    Hands-on experience shipping RBAC or ABAC systems with understanding of flexibility vs complexity tradeoffs

  • Security-First Mindset

    Deep care for correctness in authorization systems and understanding of 'fail closed' security principles

  • Full-stack Development

    Comfort shipping features end-to-end from database schema and API design to admin UI and documentation

  • Enterprise Integration

    Experience with enterprise protocols like SCIM, SAML, OAuth, and identity provider integrations

Education

  • Computer Science Degree

    Bachelor's degree in Computer Science, Software Engineering, or equivalent practical experience

Experience

  • Senior-level Experience

    5+ years of software engineering experience with focus on backend systems and enterprise infrastructure

  • IAM Systems Experience

    3+ years of hands-on experience building identity and access management systems in production environments

  • Enterprise Software

    Experience working with enterprise customers and understanding compliance, security, and scalability requirements

Skills

Required

  • Backend Engineering

    Strong backend development skills with experience in scalable system design

  • Database Design

    Expertise in designing database schemas for complex authorization and audit systems

  • API Development

    Experience building RESTful APIs and admin interfaces for enterprise customers

  • Security Engineering

    Deep understanding of security principles, authentication, and authorization patterns

  • System Architecture

    Ability to design and implement large-scale, multi-tenant enterprise systems

Preferred

  • Enterprise Protocols

    Nice to have

    Familiarity with SCIM, SAML, OAuth 2.0, and other enterprise integration standards

  • Compliance Frameworks

    Nice to have

    Knowledge of SOC 2, GDPR, HIPAA, or other compliance requirements

  • DevOps Skills

    Nice to have

    Experience with containerization, orchestration, and CI/CD pipelines

  • Frontend Development

    Nice to have

    Basic frontend skills for building admin interfaces and tooling

Tech stack

Languages

GoTypeScriptPython

Frameworks

ReactNext.js

Databases

PostgreSQLRedis

Tools

WorkOSDockerKubernetesSCIM

Other

OAuth 2.0SAMLOpenAPI

Process

Interview steps.

  1. 01

    Initial Screen

    30-minute conversation with engineering manager about background and interest in enterprise platform engineering

  2. 02

    Technical System Design

    90-minute technical interview focusing on designing multi-tenant authorization systems and enterprise infrastructure

  3. 03

    Architecture Deep Dive

    Technical discussion about past experience with IAM systems, security considerations, and scalability challenges

  4. 04

    Team Collaboration

    Behavioral interview assessing collaboration skills, problem-solving approach, and cultural fit

  5. 05

    Final Interview

    Leadership interview covering long-term vision, technical leadership, and alignment with company mission

Full posting

Original listing.

Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.

About the role

We're hiring an Enterprise Platform Engineer to build the foundational systems that make Cursor ready for the world's largest engineering organizations.

Today we have basic organizations, simple IAM primitives, early audit logs, analytics APIs, and admin APIs — but enterprise customers need much more. You will design and build the platform layer that powers organization management, access control, compliance, and administrative tooling across Cursor's product surface. This is a deeply technical IC role focused on building correct, secure, and scalable enterprise infrastructure — not gluing together vendor SDKs.

What you’ll do

  • Build and evolve our organization management system — multi-level org structures, groups, roles, lifecycle, and provisioning via SCIM, so admins can manage thousands of seats without friction.

  • Design and implement RBAC with fine-grained roles, permissions, and resource scopes that cover organizations, teams, agents, and other resources — balancing security with developer ergonomics.

  • Extend enterprise settings and policies — org-wide defaults, security policies (allowed models, MCPs, Tools, network restrictions), and configuration inheritance across different products.

  • Deepen our audit logging infrastructure — comprehensive, queryable, tamper-evident audit trails that satisfy customer-specific compliance requirements.

  • Build admin APIs and internal tooling that enterprise admins, customer success, and sales engineering depend on to manage organizations, investigate access issues, and onboard large accounts.

  • Ship compliance features end-to-end — SSO enforcement, session management, allowlisting, data analytics, and the controls that procurement and security teams require before signing.

  • Partner with product, security, and infrastructure teams to define enterprise platform abstractions that scale across the product without slowing down feature development.

  • You will own organization management, RBAC and authorization, enterprise settings and policies, audit logs, admin APIs, and compliance-related platform features. You will be a technical authority on how Cursor models identity, access, and governance for enterprise customers.

  • You will not own SSO/IdP integration at the protocol level (we use WorkOS) or billing and payments.

  • Security and correctness are part of the job, but the goal is to build systems with enough rigor and observability that enterprise operations are boring — not to manually triage every access control edge case.

You may be a fit if

  • You've built multi-tenant organization or IAM systems in production and have opinions on permission models, role inheritance, and policy evaluation.

  • You've shipped RBAC or ABAC systems and understand the tradeoffs between flexibility and complexity.

  • You deeply about correctness in authorization and understand why "fail closed" matters.

  • You can hold the tension between "ship enterprise features fast" and "do not create security gaps or break existing access patterns."

  • You feel comfortable shipping features end-to-end — from database schema and API design to admin UI and documentation.

Redirects to Cursor's application page.

Other roles

More at Cursor.

View all 36 roles