Design, prototype and productize the security agents that analyze real code, interpret design changes, and automate security work.
Oplane is an always-on security expert for AI-first engineering teams. Our biggest focus today is PR Analysis: every pull request reviewed against the customers' architectural threat model before it merges, with findings and code-level fixes attached rather than a report handed over. Scanners find patterns. Oplane understands the system.
That understanding is agentic. The agents that read a codebase, interpret a design change and work out what it means for security are the product, not a layer sitting on top of one. We are expanding the AI team, and this role exists to design those agents, prove they hold up on real systems, and turn the ones that do into shipped product.
What you'll own
The security agents, agentic components and workflows themselves. How they analyze real code, how they interpret a design change, and how they automate security work for teams from small companies to large enterprises.
What the job actually is
- Design, prototype and productize security agents. Agents, agentic components and workflows that perform code analysis on real-world software systems, interpret design changes and their security implications, and automate security tasks in both small companies and large enterprises. You take these from idea to production, not from ticket to merge.
- Prototype fast, then make it hold. A lot of this job is trying things quickly on open-ended problems. The other half is knowing which prototypes deserve to become robust product features, and doing the work to get them there.
- Improve reliability, cost and accuracy, in a structured way. Not by impression. You build the evaluation that tells you whether a change made the agents better, and you can say what \"better\" meant. This is the difference between an agent that demos and one enterprises depend on.
- Advance our internal AI tooling and workflows. The tooling the team builds with is your surface too, not just the tooling customers see.
- Shape the roadmap. You work directly with product, engineering and our security experts on what we build next. What is actually possible with agents right now is something only the people building them know, and that has to reach the roadmap.
- Build the agentic way, because we mean it. This is the most agent-native codebase you are likely to have worked in. Our docs are written for coding agents to read, an agent reviews our pull requests, and we build for a world where agents write most of the code. You will plan with an agent, build with one, and review with one, every day. We grow through agents rather than headcount, and if that reads as a threat to your craft rather than a multiplier of it, this is the wrong team.
Who this is for
- 5+ years in applied AI, software or AppSec R&D.
- Hands-on experience with agentic development, beyond a single prompt.
- Experience with structured testing and evaluation of AI agents in real-world scenarios, where the correct output is not a fixed value.
- A fast-moving, independent mindset. You thrive on rapid prototyping and open-ended problems, and you are comfortable deciding what to try next without being told.
- Deeper expertise in software security is a strong plus: threat modeling, penetration testing, or another security-focused area.
- Wide experience in software architecture and cloud infrastructure is a