Trust & Security Engineer

Trust & SecurityBengaluru / RemoteFull-time₹55–85L + meaningful equity

Our pitch is 'connect your whole working life to an agent runtime'. Nobody sane does that without proof we deserve it. You will build that proof: the permission enforcement, the audit trail, the revocation paths, and eventually the compliance program — as engineering, not paperwork.

What you will do

[01]

Own runtime permission enforcement — every tool call checked against grants, every denial logged, no prompt-level security theater.

[02]

Build the audit log into something customers actually read: complete, queryable, tamper-evident.

[03]

Make revocation instant and provable across tokens, sessions, keys, and connectors.

[04]

Run our vulnerability disclosure process and be the engineer who answers security questionnaires with real answers.

[05]

Lead us through SOC 2 Type II without letting it turn the team into a checkbox factory.

What we need

[01]

5+ years in security engineering or in backend engineering with security ownership — you have shipped authz systems, not just reviewed them.

[02]

Deep understanding of OAuth 2.0 / OIDC, token lifecycles, and the ways they go wrong.

[03]

You can threat-model a new feature in an afternoon and write it up so engineers act on it.

[04]

You have handled at least one real incident and know that honesty is the only response that scales.

[05]

You write clearly for two audiences: engineers and worried customers.

Nice to have

[01]

Experience securing LLM/agent systems — prompt injection, tool-call abuse, data exfiltration paths.

[02]

You have taken a company through SOC 2 or ISO 27001 before.

[03]

Public security writing, talks, or CVE credits.

Apply — we reply to everyone