Security Engineer
Full-time / part-time / internship • Start ASAP • Cash + equity
We are looking for a strong security engineer to help build the runtime safety and security layer for AI agents. As agents gain the ability to read files, run code, and access systems and data on a user's behalf, they create a new class of risk — leaking sensitive data, taking unsafe or unintended actions, and drifting from their intended purpose over time. We build the systems-level layer that monitors how agents actually behave, constrains what they can do, and gives developers and enterprises real visibility and control over agent execution. As our security engineer, you'll lead how we think about agent safety and security — both the honest mistakes agents and users make (deleting the wrong files, exposing secrets, drifting off-task) and the deliberate abuse attackers attempt — modeling the risks, designing the enforcement model, and building the detection that catches what slips through. This is a high-ownership role with the chance to shape both technical architecture and product direction from an early stage.
What you'll own
- Risk-model AI agents and the systems that run them, across both safety (accidental data exposure, destructive operations, an agent going off-task) and security (credential and data exfiltration, unsafe tool use, unexpected code execution, privilege escalation)
- Design guardrails that prevent costly mistakes before they happen — destructive actions, accidental secret exposure, work outside the intended scope
- Define the enforcement and containment model: what agents are allowed to do, and how we reliably stop the rest
- Own detection engineering for risky agent behavior — deterministic rules, behavioral signatures, and anomaly detection — tuned against real usage for low false positives
- Define safe and secure defaults and data-protection guarantees — least privilege, sensitive-data redaction, privacy-by-default
- Lead safety and security reviews of product and systems changes, and translate findings into concrete mitigations
- Establish incident response practices, playbooks, and postmortem culture
- Partner with the systems team on the sensors, isolation, and pipeline your detections and policies rely on
Qualifications:
- Bachelor's degree in Computer Science or a related field, or equivalent practical experience. Master's degree or equivalent industry experience is preferred.
- 1+ years of professional security engineering experience.
- A risk mindset — you can reason about both how systems break by accident and how an attacker would abuse them, and prioritize practical mitigations
- Strong understanding of systems, OS, or endpoint security (beyond web or cloud configuration)
- Strong CS and systems fundamentals — processes, file systems, syscalls, permissions
- Experience with some mix of:
- threat / risk modeling and security design reviews
- detection engineering and behavioral detection
- OS / kernel security, sandboxing, process isolation, and access control
- secrets handling, authn / authz, and secure coding
- vulnerability analysis and incident response
- Ability to build real tools and proofs-of-concept in a systems language (C/C++, Go, Python, or Rust)
- Are strong with AI-assisted coding, but do not trust generated code blindly and can manually inspect and debug it carefully
- Communicate clearly and can work well with both teammates and users
- Enjoy ownership, ambiguity, and moving quickly
Nice to have:
- macOS or Linux security internals (macOS a strong plus)
- Experience with EDR, detection engineering, or process / behavioral monitoring
- Familiarity with SELinux, seccomp, AppArmor, eBPF, sandboxing, or untrusted code execution environments
- Applied ML for safety or security — anomaly detection or classification
- Vulnerability research or CTF experience
- Interest in AI agent safety and the emerging agent risk landscape
- Rust experience (a plus — much of our systems work is in Rust)
Why join
- Work on meaningful security problems in a modern AI infrastructure stack
- Build security into the product from an early stage
- Own real systems, not just compliance checklists
- Have direct influence on architecture and engineering practices
- Competitive compensation in cash + equity
Work authorization
Candidates must already have authorization to work in the US, or authorization to work in the country where they live. We do not sponsor H-1B visas.
Start
As soon as possible.
About GenseeAI:
GenseeAI is a research-based, quickly growing startup building the foundational infrastructure layer for the future of AI agents. Instead of building another agent, we focus on the harder and more important layer underneath: making agents execute with far better efficiency, safety, security, and privacy in real production environments.