🤫husshhussh
🤫husshhusshOnePuppy
Private information and trust · H44

Application and Agent Security Engineer

Keep documents, websites and tools from silently taking control of a person's agent. You will secure the boundaries around useful automation.

See what is open todayAll roles

Not open yet: Pilot expansion

This work starts when that stage arrives, so there is no application to submit today and we will not pretend otherwise. What is written below is what the role is for and what would make somebody right for it, published early on purpose so you can decide whether it is worth watching.

The work

What this person actually does

Review application code, connectors and tool execution for authorization failures, injection, secret leakage and unsafe external actions. Build enforceable controls outside model prompts. Work with engineers on secure defaults, egress restrictions and tests that reproduce actual failure modes.

The milestone

What it looks like when it is working

In your first 90 days, secure one complete workflow and add regression tests for its highest-risk attacks.

Evidence

What would show us you can do it

Bring practical application security and strong coding skills. Experience with agent systems is valuable, but disciplined threat modeling and remediation are essential.

Evidence, not credentials. We are describing work you can point at, in whatever form it exists.

The exercise

How we would look at it together

Review a malicious document that asks the agent to send private files elsewhere and show where enforcement must happen.

← All 72 roles in the catalog