Member of Technical Staff, Security
About Sycamore
Sycamore is building the trusted agent operating system for the enterprise. Our platform helps companies build, deploy, and orchestrate AI agents that take on real operational work, with the security and control large organizations need. We are a small, engineering-led team working directly with Fortune 500 enterprises. We have raised $65M from Coatue and Lightspeed, along with other investors and industry leaders.
About the role
You will secure the product and platform that run Sycamore's enterprise agents. The surface spans user-facing applications, APIs, agent runtimes, tools and connectors, identity and authorization, untrusted code execution, multi-tenant data, cloud infrastructure, and the software-delivery system itself. This is a hands-on engineering role: you will write production code, build controls and paved paths, review designs, model threats, test systems from an attacker's perspective, and work with engineers until durable fixes reach production.
Agent systems introduce unusual security problems. A model may consume hostile instructions from a document, invoke tools on a user's behalf, generate executable code, retain information in memory, and operate across long-running workflows. Securing that requires more than a conventional web checklist: identity must remain attributable, authority must narrow at every boundary, untrusted content must stay contained, credentials must remain outside model context, and high-impact actions must be observable and governable.
What you will do
- Lead threat modeling and security architecture for agent products, APIs, connectors, execution environments, customer applications, and platform services.
- Build production security controls for authentication, authorization, delegated agent identity, workload identity, credential brokering, tenant isolation, encryption, policy enforcement, and auditability.
- Design isolation boundaries for untrusted code and generated content, including sandboxing, network and resource controls, browser containment, and safe communication with trusted services.
- Identify and remediate vulnerabilities through design review, code review, targeted security assessment, hands-on exploitation, and adversarial testing, with clear severity, exploitability, ownership, verification, and exception handling.
- Develop reusable libraries, services, policies, test harnesses, and developer tooling that eliminate vulnerability classes rather than documenting the same mistake repeatedly.
- Participate in incident response from triage and containment through root-cause analysis, remediation, evidence preservation, and control improvement.
- Translate enterprise security requirements into defensible engineering controls and evidence, without allowing questionnaire-driven work to replace actual risk reduction.
- Raise the security capability of the engineering organization through clear design patterns, direct coaching, useful reviews, and tools engineers want to use.
The environment you will work in
Sycamore operates a cloud-native, multi-tenant platform spanning browser applications, typed backend services, agent runtimes, durable workflows, relational and vector data, containerized execution, customer-authorized integrations, infrastructure as code, and automated delivery. It includes both trusted services and deliberately untrusted workloads, and it must protect customer data and credentials while allowing agents to call tools, generate applications, execute code, retain scoped memory, and act under human-delegated authority.
Our current security controls include identity and authorization boundaries, tenant-scoped data access, workload isolation, encrypted secrets, secure delivery gates, dependency and vulnerability checks, audit trails, production telemetry, staged rollouts, and incident-response procedures. Some areas are mature; others are active engineering problems you will help define.
This is context, not a checklist. We do not require experience with every language, framework, cloud provider, scanner, or security product in our environment. We care about transferable security and software-engineering judgment and your ability to understand an unfamiliar system deeply.
What we are looking for
- 5-12 years of software or security engineering experience. We will make exceptions for exceptional people in either direction.
- Strong software-engineering fundamentals and evidence that you have built, shipped, and operated security-relevant production systems, not only assessed them.
- Strong understanding of trust boundaries, least privilege, identity, authorization, secrets, cryptography, isolation, secure software design, and common web and distributed-systems vulnerabilities.
- An attacker's curiosity paired with a builder's judgment. You can demonstrate how a system fails, but your work is not finished until the safer path works in production.
- Practical risk judgment. You distinguish plausible impact from theoretical concern, prioritize the highest-leverage work, and avoid both security theater and reckless shortcuts.
- A collaborative approach that raises engineering velocity and ownership rather than turning Security into a late-stage approval queue.
- Clear written and verbal communication. You can explain a subtle exploit to an engineer, a control gap to leadership, and an evidence-backed posture to a customer's security team.
- AI-native. You use modern AI systems and coding agents to expand your coverage while independently validating findings, exploitability, and remediation.
- Comfort with startup ambiguity, broad ownership, and occasional customer travel.
Experience securing AI or agent systems is valuable but not required. Engineers from strong product-security, platform-security, identity, cloud-security, developer-security, offensive-security, or security-focused software-engineering backgrounds can succeed here if they are excited to learn the agent-specific threat model.
Interview process
- A 30-minute introductory conversation.
- Two 60-minute technical interviews, one focused on security systems design and threat modeling and one on coding and practical problem solving.
- A take-home assignment where you analyze or build a real system and present the risks, tradeoffs, implementation, and verification using the tools you would use on the job.
Why join
- Secure agents that take consequential actions inside large enterprises.
- Work on identity, authorization, isolation, tools, connectors, generated code, multi-tenant data, supply chain, and incident response as one connected system.
- Build security foundations and paved paths rather than operating a policy or review function from the sidelines.
- Help define the security model for a category whose most important attack paths are still emerging.
- Join early enough to shape Sycamore's security architecture and engineering culture.
- Receive competitive cash compensation and meaningful equity in the company you are helping build.