hussh
Agent One
Products
PuppyTagShop
For Business
For Advisors & RIAFor BrandsFor Agent BuildersPartner with Hussh
Blog
LatestProduct UpdatesResearchFounder’s Notes
Glossary
A-ZConsent & PrivacyAgents & AIData Ownership
Company
Our StoryTeamCareersPressContact
Get Agent One
Agent One
Products
PuppyTagShop
For Business
For Advisors & RIAFor BrandsFor Agent BuildersPartner with Hussh
Blog
LatestProduct UpdatesResearchFounder’s Notes
Glossary
A-ZConsent & PrivacyAgents & AIData Ownership
Company
Our StoryTeamCareersPressContact
Private information and trust · H44

Application and Agent Security Engineer

You keep documents, websites and tools from silently taking control of a person's agent. Prompt injection and confused-deputy problems are the defining security issue of agent systems: an agent that reads a web page has just taken instructions from a stranger, and the boundary between data and command is where this either holds or does not. This role is the one holding that line, and it is a research problem as much as an engineering one.

Apply for this roleAll roles

Open for applications. Starts at: Pilot expansion.

We are taking applications for this role now and building the pipeline for it. The stage above is when the work itself is expected to begin, which is something you deserve to know before you apply rather than after. It is context, not a gate.

Where

Kirkland GarageUAE Garage

In the office together five days a week, in one of our garages, and remote-friendly around your family, arranged one person at a time. We hire across the United States 🇺🇸, India 🇮🇳 and the UAE 🇦🇪.

The work

What this person actually does

Review application code, connectors and tool execution for authorization failures, injection, secret leakage and unsafe external actions. Build enforceable controls outside model prompts. Work with engineers on secure defaults, egress restrictions and tests that reproduce actual failure modes.

The milestone

What it looks like when it is working

In your first 90 days, secure one complete workflow and add regression tests for its highest-risk attacks.

Required

What we would not hire without

  • ▸Practical application security with strong coding skills
  • ▸Disciplined threat modelling and remediation you can walk through end to end
  • ▸You treat all external content as hostile input by default
  • ▸You can fix what you find rather than only reporting it

Nice to have

What would be a bonus, not a gate

  • ▸Agent or LLM security specifically, including injection research
  • ▸Browser or sandbox security
  • ▸A track record of responsible disclosure

Evidence

What would show us you can do it

Bring practical application security and strong coding skills. Experience with agent systems is valuable, but disciplined threat modeling and remediation are essential.

Evidence, not credentials. We are describing work you can point at, in whatever form it exists.

The exercise

How we would look at it together

Review a malicious document that asks the agent to send private files elsewhere and show where enforcement must happen.

The package

What comes with the job

  • ▸Stock options for every full-time teammate, four-year vesting with a one-year cliff
  • ▸Annual performance bonus, or on-target earnings with uncapped commission for customer-facing roles
  • ▸Medical, dental and vision for you and your family, plus life and disability cover, on the highest plan tier available to us
  • ▸A 401(k) with company matching
  • ▸Pay reviewed every year and on promotion, benchmarked to your role and market
  • ▸A budget of AI tokens of your own
  • ▸Gym membership, and retailer discounts redeemed through our benefits app
  • ▸Remote-friendly around your family, arranged one person at a time
  • ▸$1,000 plus $10,000 in equity for a referral we hire who stays a year

Indicative pay ranges by market and level are on the compensation page. Plan numbers are confirmed in your offer letter.

Apply

Apply for Application and Agent Security Engineer

One short form. A person reads every application and you hear back either way. You will get your own link to check where things stand, and you can withdraw or delete your application from it at any time, without an account.

Apply for this job

* indicates a required field

Application and Agent Security Engineer

Resume *

Any one of these. If you have not got a PDF to hand, paste the text - it is not a lesser way to apply.

That is everything we need. The rest is optional, and it helps.

Where your work lives

Any of these, none of these. Paste a link and we will look.

In a hundred words or so, the piece of work you are most proud of.

You get a reference number straight away.
← All 72 roles in the catalog