We're looking for a multi-disciplinary security researcher to play a vital role in researching, planning, implementing, and maintaining security solutions for organizational adoption and usage of software in general, and AI-native software in particular, in collaboration with all product development departments.
What You'll Do
Investigating how software in general, and AI-powered tools (coding assistants, agents, LLM-integrated IDEs, etc.) are used inside organizations, and where they introduce risk: data leakage, prompt injection, supply chain exposure, malicious extensions, and so on.
Building a data-driven picture of real-world usage and adoption to prioritize what we protect against, using telemetry, surveys, and external research.
Designing detection and prevention approaches for these risks, and working with engineering, product, and data teams to ship them in our product.
Auditing implementations against the threat models you develop and iterate.
What You'll Do
Investigating how software in general, and AI-powered tools (coding assistants, agents, LLM-integrated IDEs, etc.) are used inside organizations, and where they introduce risk: data leakage, prompt injection, supply chain exposure, malicious extensions, and so on.
Building a data-driven picture of real-world usage and adoption to prioritize what we protect against, using telemetry, surveys, and external research.
Designing detection and prevention approaches for these risks, and working with engineering, product, and data teams to ship them in our product.
Auditing implementations against the threat models you develop and iterate.
Requirements:
Experience in security research, threat research, or a closely related field.
Comfortable conducting data analysis in SQL and scripting languages (Python, etc.); much of this role is finding signal in messy real-world data.
Strong written and verbal communication; you'll be explaining threat models to PMs and engineers regularly.
A track record of taking research from interesting finding to shipped capability.
The company Mindset: You take ownership, act with accountability, collaborate openly, and focus on delivering meaningful impact. You thrive in fast-moving environments, embrace ambiguity, and enjoy solving hard problems together.
Even Better If You Also Bring
Prior work on LLM/AI application security, such as prompt injection, agent security, model supply chain, securing coding assistants.
Familiarity with developer tooling ecosystems (IDE plugins, MCP, package registries).
Experience in security research, threat research, or a closely related field.
Comfortable conducting data analysis in SQL and scripting languages (Python, etc.); much of this role is finding signal in messy real-world data.
Strong written and verbal communication; you'll be explaining threat models to PMs and engineers regularly.
A track record of taking research from interesting finding to shipped capability.
The company Mindset: You take ownership, act with accountability, collaborate openly, and focus on delivering meaningful impact. You thrive in fast-moving environments, embrace ambiguity, and enjoy solving hard problems together.
Even Better If You Also Bring
Prior work on LLM/AI application security, such as prompt injection, agent security, model supply chain, securing coding assistants.
Familiarity with developer tooling ecosystems (IDE plugins, MCP, package registries).
This position is open to all candidates.
















