Software Engineer, Enterprise Platform

Engineering · Full-time · San Francisco; Remote

Apply

Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.

About the role

We're hiring an Enterprise Platform Engineer to build the foundational systems that make Cursor ready for the world's largest engineering organizations.

Today we have basic organizations, simple IAM primitives, early audit logs, analytics APIs, and admin APIs — but enterprise customers need much more. You will design and build the platform layer that powers organization management, access control, compliance, and administrative tooling across Cursor's product surface. This is a deeply technical IC role focused on building correct, secure, and scalable enterprise infrastructure — not gluing together vendor SDKs.

What you’ll do

  • Build and evolve our organization management system — multi-level org structures, groups, roles, lifecycle, and provisioning via SCIM, so admins can manage thousands of seats without friction.

  • Design and implement RBAC with fine-grained roles, permissions, and resource scopes that cover organizations, teams, agents, and other resources — balancing security with developer ergonomics.

  • Extend enterprise settings and policies — org-wide defaults, security policies (allowed models, MCPs, Tools, network restrictions), and configuration inheritance across different products.

  • Deepen our audit logging infrastructure — comprehensive, queryable, tamper-evident audit trails that satisfy customer-specific compliance requirements.

  • Build admin APIs and internal tooling that enterprise admins, customer success, and sales engineering depend on to manage organizations, investigate access issues, and onboard large accounts.

  • Ship compliance features end-to-end — SSO enforcement, session management, allowlisting, data analytics, and the controls that procurement and security teams require before signing.

  • Partner with product, security, and infrastructure teams to define enterprise platform abstractions that scale across the product without slowing down feature development.

  • You will own organization management, RBAC and authorization, enterprise settings and policies, audit logs, admin APIs, and compliance-related platform features. You will be a technical authority on how Cursor models identity, access, and governance for enterprise customers.

  • You will not own SSO/IdP integration at the protocol level (we use WorkOS) or billing and payments.

  • Security and correctness are part of the job, but the goal is to build systems with enough rigor and observability that enterprise operations are boring — not to manually triage every access control edge case.

You may be a fit if

  • You've built multi-tenant organization or IAM systems in production and have opinions on permission models, role inheritance, and policy evaluation.

  • You've shipped RBAC or ABAC systems and understand the tradeoffs between flexibility and complexity.

  • You deeply about correctness in authorization and understand why "fail closed" matters.

  • You can hold the tension between "ship enterprise features fast" and "do not create security gaps or break existing access patterns."

  • You feel comfortable shipping features end-to-end — from database schema and API design to admin UI and documentation.

#LI-DNI


Apply for this role

U.S. EQUAL EMPLOYMENT OPPORTUNITY INFORMATION   (Completion is voluntary and will not subject you to adverse treatment)

Anysphere, Inc. provides equal employment opportunities to applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, or disability.

We invite all applicants to voluntarily self-identify their race, ethnicity, and gender. Submission of the information on this form is strictly voluntary and refusal to provide it will not subject you to any adverse treatment. Information obtained will be retained in a confidential file and separate from personnel records. This information may only be used in accordance with the provision of applicable federal laws, executive orders, and regulations. If you want more information about any of the sections, please check with a company representative.

SELF-IDENTIFICATION OF VETERAN STATUS  (Completion is voluntary and will not subject you to adverse treatment)

If you believe that you belong to any of the following categories of protected veterans, please indicate by making the appropriate selection

  • Disabled veteran – A veteran who served on active duty in the U.S. military and is entitled to disability compensation (or who but for the receipt of military retired pay would be entitled to disability compensation) under laws administered by the Secretary of Veterans Affairs, or was discharged or released from active duty because of a service-connected disability

  • Recently separated veteran – A veteran separated during the three-year period beginning on the date of the veteran's discharge or release from active duty in the U.S military, ground, naval, or air service

  • Active duty wartime or campaign badge veteran – A veteran who served on active duty in the U.S. military during a war, or in a campaign or expedition for which a campaign badge was authorized under the laws administered by the Department of Defense

  • Armed forces service medal veteran - Armed forces service medal veteran – A veteran who, while serving on active duty in the U.S. military ground, naval, or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985 (61 Fed. Reg. 1209).