Software Engineer, Security

Security Engineer · Mid · Full Time

SF / NYUSD 150k – 250k10mo ago
Apply for this role

Opens Cursor's application page

Role

What you'll do.

Cursor is seeking a Security Software Engineer to build secure products end-to-end, covering enterprise security, cloud infrastructure, and embedded product protections. The role combines strong software engineering skills with security expertise to safeguard the AI-powered coding platform and protect customers in a fast-moving startup environment.

Responsibilities

  • Enterprise Security Architecture: Design and implement comprehensive security solutions for enterprise customers including authentication, authorization, and compliance frameworks
  • Cloud Infrastructure Security: Build and maintain secure cloud infrastructure with least-privilege access controls and just-in-time provisioning systems
  • AI Agent Security: Develop secure environments for AI agents to interact with code, implementing safe boundaries for agent manipulation of user systems
  • Security Code Review Automation: Build AI-augmented code review systems that automatically identify security vulnerabilities and enforce secure coding practices
  • Data Protection Implementation: Create frameworks and tools to prevent inappropriate data logging and ensure sensitive information is properly handled throughout the platform
  • Vulnerability Assessment: Proactively identify and remediate security vulnerabilities across the entire product stack, from frontend to backend infrastructure
  • Security Tooling Development: Build internal security tools and automation to enable developers to work securely without friction
  • Incident Response: Lead security incident response efforts and post-mortem analysis to continuously improve security posture

Qualifications

What we look for.

Technical

  • Software Engineering Expertise

    Strong foundation in software development with 3-5 years of experience building scalable systems

  • Security Engineering Experience

    Hands-on experience building or scaling secure systems in fast-moving startup environments

  • Cloud Security Knowledge

    Deep understanding of cloud security principles, AWS/GCP/Azure security services, and infrastructure as code

  • Authentication Systems

    Experience with OAuth, SAML, JWT, and other enterprise authentication protocols

  • Secure Coding Practices

    Expertise in secure software development lifecycle, threat modeling, and vulnerability assessment

Education

  • Bachelor's Degree

    Computer Science, Cybersecurity, or related technical field (or equivalent practical experience)

Experience

  • Security-First Development

    3-5 years building secure software systems with security considerations embedded from design phase

  • Startup Environment

    Experience working in fast-paced startup environments with ability to wear multiple hats and own problems end-to-end

  • Enterprise Security

    Background in enterprise security requirements, compliance frameworks (SOC2, GDPR), and B2B security needs

Skills

Required

  • Programming Languages

    Proficiency in Python, Go, or similar systems programming languages for security tooling

  • Cloud Platforms

    Deep experience with AWS, GCP, or Azure security services and infrastructure

  • Security Frameworks

    Knowledge of OWASP, NIST, and other security frameworks and best practices

  • DevSecOps

    Experience integrating security into CI/CD pipelines and development workflows

  • Threat Modeling

    Ability to analyze systems for potential security vulnerabilities and design mitigations

Preferred

  • AI/ML Security

    Nice to have

    Experience securing machine learning systems and AI-powered applications

  • Container Security

    Nice to have

    Knowledge of Docker and Kubernetes security, including image scanning and runtime protection

  • Zero Trust Architecture

    Nice to have

    Experience implementing zero trust security models and least privilege access

  • Compliance Experience

    Nice to have

    Familiarity with SOC2, ISO 27001, or other security compliance frameworks

  • Open Source Security

    Nice to have

    Experience with security in open source ecosystems and supply chain security

Tech stack

Languages

PythonGoTypeScriptRust

Frameworks

ReactNode.js

Databases

PostgreSQLRedis

Tools

DockerKubernetesAWSGitHub ActionsTerraform

Other

AI/ML SecurityOAuth/SAMLSIEM ToolsStatic Code Analysis

Compensation

Pay and benefits.

Base·USD 150,000 – 250,000

Equity·Stock options

Benefits

  • Equity Package

    Significant equity stake in a fast-growing AI startup with substantial upside potential

  • Health Insurance

    Comprehensive medical, dental, and vision coverage for employees and families

  • In-Person Culture

    Cozy offices in North Beach San Francisco and Manhattan New York with well-stocked libraries

  • Learning Resources

    Access to extensive technical libraries and resources for continuous learning

  • Small Team Impact

    Work directly with founders and have outsized impact on product direction and company growth

Process

Interview steps.

  1. 01

    Application Review

    Initial screening of application materials including resume, portfolio, and GitHub contributions

  2. 02

    Technical Phone Screen 1

    45-minute technical discussion focusing on security engineering principles and system design

  3. 03

    Technical Phone Screen 2

    60-minute coding interview with security-focused problems and vulnerability analysis

  4. 04

    Onsite Full Day

    In-person visit to SF or NY office including small project work, team meetings, and cultural fit assessment

  5. 05

    Final Decision

    Team discussion and reference checks followed by offer decision within 1-2 business days

Full posting

Original listing.

Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.

We're in-person with cozy offices in North Beach, San Francisco and Manhattan, New York, replete with well-stocked libraries.

About the Role

Security Software Engineers help us ship secure products end-to-end—covering enterprise security, cloud/infrastructure, and protections embedded directly in our products. You’ll build the tools and features that safeguard our platform and editor and protect our customers.

You may be a fit if

  • You are a strong software engineer first, with security as your superpower.

  • You think like both a builder and an attacker: you anticipate vulnerabilities before they become issues.

  • You care about developer experience, building solutions that are secure and frictionless.

  • You’re comfortable moving quickly, owning problems end to end, and iterating with limited guidance.

  • You have experience building or scaling secure systems in fast-moving environments.

  • You have strong opinions on secure defaults, but can balance pragmatism with rigor.

  • You enjoy working on small, high-talent teams where impact is magnified.

  • You’re motivated by protecting developers and users, and you see security as an enabler.

Sample projects include

  • Build AI augmented code review to get involved in important systems at the right time

  • Build a least-privilege and JIT system for cloud access that enables engineers and enforces least privileges.

  • Implement a safe environment for agents to engage with code

  • Implement a framework for securely handling agent manipulation of user systems (e.g., MCP tool calls and command execution).

  • Implement a paved road for preventing inappropriate data from being logged

Applying

If there appears to be a fit, we'll reach to schedule 2-3 short technicals. After, we'll schedule an onsite in our office, where you'll work on a small project, discuss ideas, and meet the team.

Redirects to Cursor's application page.

Other roles

More at Cursor.

View all 36 roles