CipherData AI Engineer Bellevue, WA · Full time Company website

Join the team that owns CipherData AIDR’s core reasoning engine — the multi-agent layer that turns telemetry from 70+ security vendors into investigated, correlated conclusions an analyst can act on.

About CipherData

CipherData is building the AI-Native Detection and Response (AIDR) platform — a unified platform that delivers continuous risk reduction through SIEM-less detection and closed-loop autonomous response. Legacy SOC tools bolt AI copilots onto outdated architecture. AIDR redefines the entire SOC workflow, much as vibe coding is redefining the traditional SDLC: it autonomously investigates every alert within 5 minutes and delivers 24/7 coverage at the cost of a single analyst. SOC teams stop chasing alerts and start calling the shots. We are a seed-stage company headquartered in Bellevue, WA. The team is small and senior — engineers and researchers from Meta, Google DeepMind, Amazon, Microsoft, and Samsung — and AIDR is already trusted with early global enterprise customers.

Description

About the Role

You’ll join the team that owns AIDR’s core reasoning engine — the multi-agent layer that turns telemetry from 70+ security vendors into investigated, correlated conclusions an analyst can act on. You’ll design the agent architectures, run the experiments that decide which ones ship, and take them into production environments where SOC teams depend on the output. Success is measured in precision, recall, latency, and cost, not demo quality.

That standard shapes how we work:

  • Accuracy and honesty. We’re clear about what we’ve measured versus what’s still a hypothesis. We expect the same of your results — including when one doesn’t hold up.
  • Research into production. We move new research into the product quickly, then validate it against operational standards rather than demo conditions.
  • Measure, then decide. We experiment in small increments and make calls from metrics, not intuition.


In practice, you’ll spend as much time building the evaluation harnesses that tell us whether an agent is good as you will building the agent itself. If you want to work on LLM systems where “is it good?” has a number attached, this is that role.


What you’ll do

  • Build our multi-agent LLM system: Design and improve the core system where multiple LLM agents collaborate to detect, investigate, and correlate threats.
  • LLM orchestration: Build pipelines that coordinate multiple models against cost, latency, and accuracy trade-offs based on the task.
  • Evaluation & continuous improvement: Create the evaluation systems that measure agent output quality, and design the loops that feed operational data back as a learning signal.
  • Reliability: Experiment with and ship prompting, architecture, and verification strategies that reduce hallucination and improve stability and reproducibility.
  • Build what’s next: Go beyond investigation into automated response, deeper threat correlation, and new product areas that push security operations further — built from the ground up, with you.


Our Core Values

Five principles guide every decision at CipherData. We hire against them and evaluate against them:

  • Trustworthiness — be trustworthy to all people. Integrity, transparency, and dependability with colleagues, partners, and customers.
  • Growth Mindset — learn from anything, anyone, anytime. Past experience is data, not dogma. Curiosity over ego; first principles over status quo.
  • Proactive Ownership — do the right thing for the customer. Customer first, then company, then team, then self. Step beyond your role and hold yourself accountable.
  • Disagree and Commit — debate when it matters, execute with unity. Challenge high-impact decisions with data and conviction, regardless of title. Once decided, commit fully.
  • Impact-Driven Execution — ship, learn, iterate. Move fast, take calculated risks, and measure yourself by outcomes, not activity.


Minimum Qualifications

  • Hands-on experience designing and building LLM applications (agents, RAG, orchestration, etc.)
  • Strong software engineering fundamentals in Python
  • Experience building LLM workflows with various agent frameworks
  • Experience evaluating and improving LLM output quality, both qualitatively and quantitatively — a real instinct for measurement, not just implementation
  • Comfort defining ambiguous problems, experimenting quickly, and making decisions from data


Preferred Qualifications

  • Security domain knowledge (SOC / SIEM / SOAR, threat intelligence, incident response, etc.)
  • Experience designing evaluations/benchmarks, or an ML research background (publications, open source contributions, etc.)
  • Experience operating production LLM systems (monitoring, cost optimization, latency management)
  • Experience deploying production systems across cloud environments


Details

  • Position: AI Engineer
  • Experience: 2+ years
  • Employment type: Full-time
  • Location: Bellevue, WA


CipherData is an equal opportunity employer. We consider all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other protected characteristic.