远程工作雷达

工程经理, 代理与产品安全

Engineering Manager, Agent & Product Security

开发工程未标注地域
公司Cursor
薪资未公开
工作地点New York / San Francisco
地域资格未标注地域
时区要求无特别要求
用工类型FullTime
发布时间2026-07-14
数据来源Ashby
前往企业招聘页投递 →

我们的使命是自动化编码。我们旅程的第一步是打造最好的工具,供专业程序员使用,结合创新研究、设计和工程。我们的组织结构非常扁平,团队小而人才密集。我们特别喜欢追求真理、充满热情且富有创造力的人。我们享受激烈的辩论、疯狂的想法以及代码的发布。

关于职位

Cursor 的代理程序运行在世界上一些最注重安全的工程组织的代码库中——它们持有凭证、阅读不可信内容、运行工具并发布更改。目前,它们根据每个任务授权执行操作。我们未来的目标是让它们更像同事:在长时间内自主运作,承担固定职责,主动开展工作,并与人和其他代理协作。未来的需求所需的安全部署模型——自主工作者的身份和问责制、固定权限而非逐任务授权、代理间信任、随着持续自主性而扩展的监督——大多尚未存在。

作为代理与产品安全工程师经理,您将领导一个使代理软件开发值得信赖的团队。该团队负责 Cursor 产品和代理之间客户、数据、工具、仓库、工作区和代理权限之间的安全边界,并设计其背后的原始功能:代理身份、委托权限、策略执行、安全工具执行和提示注入防护。这些领域几乎没有先例,因此该团队的决策对 Cursor 以及整个行业如何解决这些问题具有特殊的重要性。

在这里,安全与产品战略紧密相连:客户会以我们使其值得信赖的速度采用代理自主性,因此你团队建立的安全边界直接决定了产品能交付什么。你将帮助确定这一方向。

你将负责

- 制定从受监督代理到可信自主代理的路径:定义使代理自主性成为可能的安全原始功能,并带领团队构建这些功能。

- 设计使 Cursor 在客户最重要的代码库中安全运行的隔离机制:针对真实对手设计的租户、工作区、密钥和数据保护。

- 构建自主代理所需的权利基础设施:身份、作用域权限、策略执行和安全工具执行,使代理能够在可验证的限制下承担真正的责任并实现完全问责。

查看英文原文

Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.

About the role

Cursor’s agents work inside the codebases of some of the most security-conscious engineering organizations in the world — holding credentials, reading untrusted content, running tools, and shipping changes. Today they act on authority delegated per task. Where we’re headed, they’ll work more like coworkers: autonomous over long horizons, holding standing responsibilities, initiating work, and collaborating with people and other agents. The security models that future needs — identity and accountability for autonomous workers, standing authority rather than per-task permission, agent-to-agent trust, oversight that scales with always-on autonomy — mostly don’t exist yet.

As Engineering Manager for Agent & Product Security, you’ll lead the team that makes agentic software development trustworthy. This team owns the security boundaries between customers, data, tools, repositories, workspaces, and agent authority across Cursor’s product and agents and designs the primitives behind them: agent identity, delegated authority, policy enforcement, secure tool execution, and prompt-injection containment. Little of this has settled precedent, so the team’s decisions carry unusual weight for Cursor and for how the industry approaches these problems.

Security here is tightly coupled to product strategy: customers adopt agent autonomy as fast as we can make it trustworthy, so the boundaries your team makes safe directly determine what the product can ship. You’ll help set that direction.

What you’ll do

- Chart the path from supervised agents to trusted autonomous ones: define the security primitives that enable agent autonomy, and lead the team that builds them.

- Engineer the isolation that makes Cursor safe to run inside customers’ most valuable codebases: tenancy, workspace, secret, and data protections designed for real adversaries.

- Build the authority infrastructure autonomous agents need: identity, scoped permissions, policy enforcement, and secure tool execution, so an agent can hold real responsibility with verifiable limits and full accountability.

- Build customer-facing security controls that are understandable, usable, and strong enough for Cursor’s most security-sensitive customers, with crisp success metrics for security outcomes.

- Hire, coach, and grow a high-performing security engineering team while staying technically close to the work: write and review code where useful, and keep execution fast and technically grounded.

You may be a fit if

- You’ve led engineering teams shipping production systems with high security, reliability, or platform stakes — and you want a problem space where much of the answer isn’t written down yet.

- You have strong product and systems judgment: you can reason from user workflows to architecture, threat models, enforcement points, and operational tradeoffs — and you see security as something that enables product capability, not only restricts it.

- You understand modern application security, authorization, tenancy, identity, secrets, data isolation, and secure-by-default platform design.

- You have good instincts about AI agents: how they use tools, where authority should come from, how prompt injection and exfiltration show up in practice, and how to build mitigations that hold up against creative adversaries.

- You’re comfortable operating in ambiguity: you can set strategy where precedent is thin, commit to a direction, and stay close enough to the implementation to know when to change it.

- You can partner well across product, infrastructure, ML, and customer-facing teams.

#LI-DNI

本页面信息整理自 Ashby,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

现场工程师

CursorRemote / New York / San FranciscoFullTime昨天
开发工程全球可投

← 返回全部职位