Skip to content

Open nowPosted 4 days ago

Staff Software Engineer, Platform Security

Decagon148 open roles

Pay
$200,000 – $400,000 a year
Where
San Francisco
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Software Engineer, Platform SecurityDecagon · San Francisco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Decagon's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Decagon postings stay open a median of 36 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 4 days ago

Decagon median: 36 days open

The posting

About Decagon

Decagon is the leading conversational AI platform empowering every brand to deliver concierge customer experiences.

Our technology enables industry-defining enterprises like Avis Budget Group, Block’s Cash App and Square, Chime, Oura Health, and Hunter Douglas to deploy AI agents that power personalized, deeply satisfying interactions across voice, chat, email, SMS, and every other channel.

We’re building a future where customer experiences are being redefined from support tickets and hold music to faster resolutions, richer conversations, and deeper relationships. We’re proud to be backed by world-class investors who share that vision, including a16z, Accel, Bain Capital Ventures, Coatue, and Index Ventures, along with many others.

We’re an in-office company, driven by a shared commitment to excellence and velocity. Our values — Just Get It Done, Invent What Customers Want, Winner’s Mindset, and The Polymath Principle — shape how we work and grow as a team.

ABOUT THE TEAM

The Security Engineering team at Decagon protects the platform that powers the most advanced conversational AI agents for enterprise customers across voice, chat, email, and SMS. We build the security foundations that enable Decagon's AI agents to handle sensitive customer data with complete trust while defending against sophisticated, AI-enabled threats at massive scale.

This role sits at the intersection of Security and Infrastructure. Like the rest of our Infrastructure org, we believe the best security comes from paved paths, strong SLAs, and high-quality systems that other engineers can rely on by default. Our mission is to secure magical support experiences, ensuring that AI agents and human agents can collaborate safely to help users resolve their issues while maintaining the highest standards of security and privacy.

ABOUT THE ROLE

We're hiring our founding Platform Engineer, Security to design, build, and operate the security infrastructure that powers Decagon's AI platform. This is a builder's role: you'll spend your time creating durable, well-engineered systems including paved paths for secure service creation, security tooling that automatically applies secure configurations, and infrastructure-as-code that makes it easy for every engineer at Decagon to do the right thing.

As the first dedicated engineer at this intersection, you'll have outsized impact on how security infrastructure is built here, and you'll shape the technical direction of the infrastructure security program. You'll also help us invest in automation, observability, and self-service so the team operates with confidence.

The work is close to the business. Decagon serves some of the world's most security-conscious enterprises, including major financial-services institutions, and the security platform you build directly unlocks these high-value deals. This role offers a clear runway to grow your impact across security, infrastructure, and platform engineering.

IN THIS ROLE, YOU WILL

- Design and implement secure, multi-tenant infrastructure that isolates customer data while enabling efficient AI model serving across our platform

- Build "golden paths" for security including service templates, libraries, terraform policies, and automation, so new services are secure and production-ready by default

- Own infrastructure-as-code (Terraform) and GitOps best practices, including reusable modules and policy-as-code

- Expand and help operate the platforms behind alerting detection, secrets management, IAM, and automated remediation, integrating them cleanly into CI/CD and developer workflows

- Partner with Security, Infrastructure, and product engineering teams to translate enterprise and compliance requirements (SOC 2, ISO 27001, GDPR) into reliable, automated technical controls

- Participate in security on-call and continuously raise the bar on operability, runbooks, and incident learnings

YOUR BACKGROUND LOOKS SOMETHING LIKE THIS

- 8+ years building and operating production infrastructure, with meaningful exposure to security or a strong interest in moving deeper into security problems

- Deep knowledge of Google Cloud Platform and/or AWS, including compute, networking, IAM, and security services

- Proficiency with infrastructure-as-code (Terraform, Ansible, or similar) and a track record of building developer-facing tooling and automation

- Strong coding ability in at least one systems language (eg. Python, Go, TypeScript) and comfort building paved-path tooling teams actually adopt

- Experience applying AI-assisted tooling (Cursor, Claude Code, and similar) to make engineers dramatically more effective

- Experience with secure container deployment, service mesh, and Kubernetes security best practices

- Observability and incident-response tooling experience (instrumentation, alerting, dashboards), with a bias toward eliminating toil

- Clear written communication and the ability to turn ambiguous requirements into simple, reliable designs

EVEN BETTER IF YOU HAVE

- A track record of being an early or founding platform/infrastructure/security engineer at another company

- Experience building internal platforms: service templates, paved-road deployment, self-serve environments, or developer portals

- A security-minded approach to the software supply chain (provenance, secrets, least privilege) and familiarity with static analysis tooling (Semgrep, CodeQL)

- Experience with detection and response data pipelines (Kafka/Pulsar, Splunk/Panther/RunReveal, or similar)

- Knowledge of enterprise compliance requirements (SOC 2, ISO 27001, GDPR) from an infrastructure and platform perspective

Compensation

$200K – $400K + Offers Equity

Benefits

We proudly offer the following benefits for our full-time employees:

- Medical, Dental, and Vision benefits for you and your family

- Life Insurance and Disability Benefits

- Retirement Plan (e.g., 401K, pension)

- Parental Leave

- Fertility and family building benefits through Carrot

- Monthly stipend to support your wellness, lifestyle, and work-life balance

- Daily lunches and snacks in the office to keep you at your best

- Take what you need vacation policy (subject to local requirements; UK employees receive 25 days of statutory leave)

These benefits are described in more detail in Decagon’s policies, may vary by location, and can change at any time according to applicable compensation and benefits plans.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Decagon's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Decagon's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Decagon's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.