🌏 Berlin / Remote

TLDR;

We’re building a meeting agent that builds company-wide conversational context and eliminates busy work around meetings. We’re a fast-moving team looking for a Cybersecurity Engineer to join our product team in Berlin (hybrid/remote possible). You’ll own the engineering that protects our customers’ conversations, from authentication and agent permissions to cloud security and incident response.

About Jamie

Every company runs on conversations, and most of that context disappears the moment a meeting ends. Jamie captures it, structures it, and makes it usable across the entire organisation. We work closely with our customers to build a magical product with real-world impact.

We believe in shipping fast, learning constantly, and building a product users love.

The Role

Jamie handles sensitive conversations for teams whose work depends on trust. Our product spans desktop and mobile apps, cloud services, integrations, and agents that can read information and take actions on a user’s behalf. Security needs to be built into how these systems work and how we ship them.

You’ll take ownership of technical security across the product and work directly in the codebase. Find weaknesses, understand their impact, ship fixes with the team, and build the checks that prevent them from returning. You’ll help us make good security decisions early, while keeping the team moving quickly.

What You Will Be Working On

Authentication & Authorization: Review and strengthen authentication, OAuth, SSO, session handling, access controls, and tenant isolation. Make the secure path easy for other engineers to use.

Product Security: Threat-model new features, review sensitive code and architecture changes, and investigate vulnerabilities across our APIs, desktop and mobile apps, and integrations. Own remediation through verified fixes.

Agent & Integration Security: Design and test permission boundaries for agents and connected tools. Address prompt injection, unsafe tool execution, sandbox isolation, and the risk of exposing customer data across users or workspaces.

Cloud & Access Security: Work with platform engineering to improve least-privilege access, secrets management, production access, audit logging, and security configuration across Cloudflare and GCP.

Continuous Security Testing: Build useful security checks into development and CI/CD, including code, dependency, and secret scanning. Run frequent agentic penetration tests, validate findings, and turn the results into engineering improvements.

Detection & Incident Response: Build actionable security signals and response playbooks. Investigate suspicious activity with the team, contain incidents, and follow through on the changes that prevent recurrence.

Security Automation: Write tools and agents that reduce repetitive security work, make risks visible, and give engineers fast feedback. Help our compliance partners obtain reliable technical evidence from the systems we actually run.

What’s our stack?

We use the best tools to build the best product, and we’re always happy to hear new ideas and perspectives that could make working better. Currently:

☁️ We’re thoroughly Cloudflare-pilled and run a hybrid setup on Cloudflare + GCP