Source description
About the role
Emergent builds autonomous coding agents that replace traditional software development by generating, testing, and deploying production applications directly from plain-language intent. Our systems run in production at global scale and are used to build millions of real applications.
Since our public launch, we've crossed $100M in ARR and grown to over 10M users across 190+ countries. We're backed by Khosla Ventures, SoftBank, Google, Lightspeed, Prosus, Together, and Y Combinator.
We're solving the hard part of AI-driven software creation: correctness, reliability, security, and scale in real production systems. The team is built by repeat founders, Olympiad medalists, IIT & IIM alumni, and leaders from Google, Amazon, and Dropbox.
We're hiring builders who want ownership, speed, and impact at global scale.
The Role: Security at Emergent isn't a checkbox, it's a core engineering discipline. With 6M+ users generating and deploying real applications every day, our attack surface is unique. We're looking for a Security Engineer who thinks like an attacker, builds like a product engineer, and operates with the urgency of a founder. You'll own security across the full stack, from AI agent pipelines and cloud infrastructure to the applications our users generate and deploy at scale.
What You'll Do
-
• Secure the AI-native stack end to end: design, implement, and continuously improve security controls across AI agent pipelines, multi-tenant cloud infrastructure, APIs, and user-generated application environments
-
• Lead threat modelling and attack surface analysis: proactively identify risks in new product features, infrastructure changes, and AI-generated code patterns. Catch vulnerabilities at design time, not after deployment
-
• Build and own vulnerability management: run automated security scans (SAST, DAST, SCA), triage findings by exploitability and impact, drive remediation, and track resolution to closure
-
• Harden AI-generated application environments: define and enforce sandboxing strategies, code execution boundaries, secret handling standards, and runtime security controls
-
• Drive security in the SDLC: embed security tooling and review gates into CI/CD pipelines, champion secure coding practices, conduct code reviews, and run internal red-teaming exercises
-
• Detect, respond, and learn: build detection coverage using cloud-native logging and SIEM tooling. Lead incident response, triage, contain, eradicate, and produce clear post-mortems
-
• Own compliance and trust: maintain and mature security posture against SOC 2, ISO 27001, and cloud security benchmarks. Serve as technical point of contact for customer security reviews
What We're Looking For
-
• 8 to 12 years of hands-on security engineering experience in a fast-moving product or cloud environment
-
• Strong application security foundation, able to read code (Python, JS/TS, SQL), identify vulnerabilities (OWASP Top 10, injection, auth flaws), and drive fixes with engineering teams
-
• Solid cloud security experience across AWS, GCP, or Azure including IAM, network security groups, secrets management, and container security (Docker, Kubernetes)
-
• Experience with SAST, DAST, SCA, secret scanning, and CSPM tooling across the development lifecycle
-
• Incident response experience with structured response from detection to post-mortem
-
• Excellent written and verbal communication, able to explain a critical vulnerability to a non-technical founder and a detailed CVE to a senior engineer
-
• High ownership mindset: you see a gap and close it
-
Good to Have:
-
• Experience securing AI/ML systems including model APIs, prompt injection risks, LLM output validation, and multi-tenant AI inference
-
• Familiarity with sandboxed code execution environments or container escape scenarios
-
• Hands-on red teaming or penetration testing experience
-
• Compliance background: SOC 2 Type II, ISO 27001, GDPR and data privacy
-
• Prior experience at a high-growth startup or infrastructure-heavy product company
-
What This Role Is Not:
-
• Not a compliance-only or checkbox security role
-
• Not removed from engineering, you'll be deep in code, PRs, and architecture discussions
-
• Not slow-moving, we ship fast and you'll need to keep pace while raising the security bar
Why Join Us
• Own the security function at one of the fastest-growing AI companies in the world, with real scope, real risk, and real impact
• Work directly with founders and engineering leads on decisions affecting millions of users
• Competitive compensation, meaningful equity, and a front-row seat to the AI-native software revolution
• Fast learning, high ownership, and a clear path to defining enterprise-grade security at the frontier of AI
Benefits and Perks
-
• Daily Meals: Lunch and Dinner provided
-
• Family Insurance: 3 Lakhs worth of coverage for you and your family
-
• Unlimited Paid Time Off: Take the time you need to recharge and come back refreshed
-
• Flexible Working Hours: Work arrangements that fit your life and commitments
-
Let's build the future of software together.
More at Emergent