Software Engineer focusing on security features for AI systems at Cohere, contributing to production security and secure coding practices.
Responsibilities
Software Development: Contributing to the core development of security features such as OIDC/OAuth flows and session management, ensuring North's AI agents are secure
Secure Coding: Writing secure code to handle OIDC tokens, user claims, and sensitive data, adhering to best practices for JWT validation and encryption
Authentication and Data Protection: Implementing authentication mechanisms including user login, token management, and authorization checks to maintain data integrity
Tool Integration: Pulling in new tools to enhance North's security capabilities
DevSecOps: Design and implement secret management within Kubernetes clusters, including encryption and RBAC
Cross-functional Collaboration: Demonstrate strong soft skills to communicate security best practices to stakeholders in a clear and concise manner
Requirements
Have 5+ years building user-facing security features in production systems
Ship production Python confidently and frequently
Understand OIDC/OAuth 2.0, JWT validation, and token lifecycle management deeply—not just conceptually
Have hands-on experience with Kubernetes in both development and production environments
Have worked across GCP, AWS, Azure, or hybrid/multi-cloud deployments
Are comfortable working across the stack
Communicate security concepts clearly to non-security engineers and stakeholders
Thrive in fast-moving environments where priorities evolve
Experience working with AI/ML systems or LLM-based applications
Benefits
An open and inclusive culture and work environment
Work closely with a team on the cutting edge of AI research
Weekly lunch stipend, in-office lunches & snacks
Full health and dental benefits, including a separate budget to take care of your mental health
100% Parental Leave top-up for up to 6 months
Personal enrichment benefits towards arts and culture, fitness and well-being, quality time, and workspace improvement
Remote-flexible, offices in Toronto, New York, San Francisco, London and Paris, as well as a co-working stipend
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.