đ Berlin / Remote
Weâre building a meeting agent that builds company-wide conversational context and eliminates busy work around meetings. Weâre a fast-moving team looking for a Cybersecurity Engineer to join our product team in Berlin (hybrid/remote possible). Youâll own the engineering that protects our customersâ conversations, from authentication and agent permissions to cloud security and incident response.
Every company runs on conversations, and most of that context disappears the moment a meeting ends. Jamie captures it, structures it, and makes it usable across the entire organisation. We work closely with our customers to build a magical product with real-world impact.
We believe in shipping fast, learning constantly, and building a product users love.
Jamie handles sensitive conversations for teams whose work depends on trust. Our product spans desktop and mobile apps, cloud services, integrations, and agents that can read information and take actions on a userâs behalf. Security needs to be built into how these systems work and how we ship them.
Youâll take ownership of technical security across the product and work directly in the codebase. Find weaknesses, understand their impact, ship fixes with the team, and build the checks that prevent them from returning. Youâll help us make good security decisions early, while keeping the team moving quickly.
Authentication & Authorization: Review and strengthen authentication, OAuth, SSO, session handling, access controls, and tenant isolation. Make the secure path easy for other engineers to use.
Product Security: Threat-model new features, review sensitive code and architecture changes, and investigate vulnerabilities across our APIs, desktop and mobile apps, and integrations. Own remediation through verified fixes.
Agent & Integration Security: Design and test permission boundaries for agents and connected tools. Address prompt injection, unsafe tool execution, sandbox isolation, and the risk of exposing customer data across users or workspaces.
Cloud & Access Security: Work with platform engineering to improve least-privilege access, secrets management, production access, audit logging, and security configuration across Cloudflare and GCP.
Continuous Security Testing: Build useful security checks into development and CI/CD, including code, dependency, and secret scanning. Run frequent agentic penetration tests, validate findings, and turn the results into engineering improvements.
Detection & Incident Response: Build actionable security signals and response playbooks. Investigate suspicious activity with the team, contain incidents, and follow through on the changes that prevent recurrence.
Security Automation: Write tools and agents that reduce repetitive security work, make risks visible, and give engineers fast feedback. Help our compliance partners obtain reliable technical evidence from the systems we actually run.
We use the best tools to build the best product, and weâre always happy to hear new ideas and perspectives that could make working better. Currently:
âď¸ Weâre thoroughly Cloudflare-pilled and run a hybrid setup on Cloudflare + GCP