RefolkCandidates
Open nowEngineeringCore Engineering, Product, and Infrastructure

Software Engineer, Security

Thinking Machines Lab · San Francisco

Location
San Francisco
Level
Mid level
Posted
9 months ago

About this role

Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.

We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.

About the Role

We’re looking for a software engineer focused on making our products secure by default while supporting fast and ambitious product iteration. You’ll embed with product and research teams to bake security into design and development and to build tooling and automation that keep systems safe at scale.

Note: This is an "evergreen role" that we keep open on an on-going basis to express interest. We receive many applications, and there may not always be an immediate role that aligns perfectly with your experience and skills. Still, we encourage you to apply. We continuously review applications and reach out to applicants as new opportunities open. You are welcome to reapply if you get more experience, but please avoid applying more than once every 6 months. You may also find that we put up postings for singular roles for separate, project or team specific needs. In those cases, you're welcome to apply directly in addition to an evergreen role.

What You’ll Do

  • Partner with product and research teams to embed security into the development lifecycle: threat modeling, design reviews, and secure defaults for new features.
  • Design and implement security controls across our product stack (authentication, authorization, session management, input validation, etc.).
  • Build and maintain security tooling and automation for engineers: secure frameworks and templates, CI/CD checks, dependency management, and vulnerability detection.
  • Collaborate with researchers to identify and mitigate AI-specific product risks, such as model abuse, prompt injection, data leakage, or misuse of capabilities.
  • Improve observability and detection for security-relevant events: access anomalies, abuse patterns, and suspicious behavior in production.

Skills and Qualifications

Minimum qualifications:

  • Bachelor’s degree or equivalent experience in computer science, engineering, or similar.
  • Proficiency in at least one backend language (we use Python or Rust).
  • Strong generalist software engineering background and ability to review production code for security risks.
  • Hands-on experience securing web apps and APIs especially auth flows, access control, secrets management, input validation, and data protection.
  • Familiarity with common vulnerability classes and prevention frameworks; experience hardening prototypes into production.
  • Comfort with modern cloud infrastructure and understanding how application concerns intersect with infrastructure.
  • Comfort operating across the stack and owning projects end-to-end.
  • Thrive in a highly collaborative environment involving many, different cross-functional partners and subject matter experts.
  • A bias for action with a mindset to take initiative to work across different stacks and different teams where you spot the opportunity to make sure something ships.

Preferred qualifications - we encourage you to apply if you meet some but not all of these:

  • Experience securing AI‑powered products or working with ML/LLM APIs and their unique threat models.
  • Background in human-computer interaction, especially where security or trust plays a central role in the user experience.
  • Strong skills in rapid prototyping and iteration, with a habit of turning ad-hoc fixes into reusable patterns and tools.
  • Open‑source security work, bug bounty write‑ups, or published tooling.

Logistics

  • Location: This role is based in San Francisco, California.
  • Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $350,000 - $475,000 USD.
  • Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
  • Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.

As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.

As published by Thinking Machines Lab. Applications are handled on their site.

Skills this posting mentions

Data ProtectionAccess ControlInfrastructure

About Thinking Machines Lab

Thinking Machines Lab is an artificial intelligence research and product company. We’re building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.

All 36 openings at Thinking Machines Lab

One click, then it is written

Apply to Thinking Machines Lab with a resume written for this role.

Queue Software Engineer, Security and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Thinking Machines Lab’s form for you.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • 25 sent a week, free
  • No card
  • Nothing sent until you say so

More roles at Thinking Machines Lab

See all

Similar roles elsewhere

See more

Put this to work

Paste your career in once. Every application after that is written for you.

Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.

  1. 01Drop your resume

    A PDF or a LinkedIn URL. About a minute, once.

  2. 02I rank the openings

    Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.

  3. 03Each one is written up

    Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.

  • New matches ranked and written before you are up.
  • Every bullet stays inside what your history supports. Nothing invented.
  • Queued, submitted, interviewing, offer: one screen, not a spreadsheet.

500 free credits on sign-up. No card. Nothing is sent until you say so.

Listed from the job board Thinking Machines Lab publishes. Refolk is not the employer and does not handle their hiring. Applications go to Thinking Machines Lab directly.