A complete application in a minute — tailored resume and cover letter, ready to send.
HushOne, Inc. is seeking a security-focused engineer to review code, connectors and tool execution for authorization failures, injections and data leakage, and to build controls outside model prompts.
You will collaborate with engineers to implement secure defaults, egress restrictions and robust tests. In the role you will define disciplined threat modelling, fix issues end-to-end and treat external content as hostile input by default.
You keep documents, websites and tools from silently taking control of a person's agent. Prompt injection and confused-deputy problems are the defining security issue of agent systems: an agent that reads a web page has just taken instructions from a stranger, and the boundary between data and command is where this either holds or does not. This role is the one holding that line, and it is a research problem as much as an engineering one.
Review application code, connectors and tool execution for authorization failures, injection, secret leakage and unsafe external actions. Build enforceable controls outside model prompts. Work with engineers on secure defaults, egress restrictions and tests that reproduce actual failure modes.
In your first 90 days, secure one complete workflow and add regression tests for its highest-risk attacks.
Bring practical application security and strong coding skills. Experience with agent systems is valuable, but disciplined threat modeling and remediation are essential.
Review a malicious document that asks the agent to send private files elsewhere and show where enforcement must happen.
We work together in the office, five days a week, and you can be based at any of our garages: Kirkland Garage (Kirkland, WA); UAE Garage (Dubai, Dubai). We hire across the United States, India and the UAE. We are remote-friendly around family: if you need to work from home some days to look after the people you love, we arrange that with you one person at a time, and we encourage people to use it rather than tough it out.
We publish what we pay. Indicative ranges by market and level are on our compensation page, and they are realistic going market rates rather than headline numbers. Wherever we hire we pay at least the local market rate, and for full-time roles our floor is a living wage, never the statutory minimum. Compensation is reviewed every year and on promotion.
Every full-time teammate gets stock options. Four-year vesting with a one-year cliff, sized to role, level and impact, and confirmed in writing at offer. High performers earn refresh grants.
An annual performance bonus tied to clear company and personal goals, indicatively 10 to 20 percent of base for non-sales roles. Customer-facing roles carry on-target earnings, typically a 50/50 split of base and variable, with uncapped commission and accelerators above quota.
Medical, dental and vision for you and your family, plus life and disability cover. We have chosen the highest plan tier available to us rather than the cheapest one that clears the bar, because the point of this is that you never have to think about it. The specific plan numbers are confirmed in your offer letter.
A 401(k) with a company match, so the years you spend here compound into something that is yours whatever happens next. The match formula is confirmed in your offer letter.
A budget of AI tokens of your own, because a company that says you should own your AI cannot be the company that rations it. Use them on the work and on whatever you are curious about.
A gym membership, and a corporate benefits programme with its own app, where you redeem real discounts with a long list of retailers on the ordinary purchases of a life.
We are remote-friendly around your family, arranged one person at a time, and we would rather you took it than toughed it out.
Refer someone we hire full‑time who stays a year and you get $1,000 plus $10,000 in referral stock‑based equity, on top of your own package.