企业平台软件工程师
查看雇主原标题
Software Engineer, Enterprise PlatformCursor (Anysphere) · San Francisco; Remote
职位信息来自雇主公开的招聘页面。申请前请务必在雇主官网核实详情。
为什么值得关注?
发现指数 50/100,仅依据与该职位一起存储的证据计算。
- 新的雇主官方职位
- 远程职位
分数构成
- 时效性 (随职位发布时间变化)+18
- 雇主官方来源+15
- 远程职位+8
- 稀有职位+1
- 公司来源健康度+8
该职位未包含:已披露薪资、提及签证担保、提及搬迁、未出现在监控的职位板上。
这些理由来自雇主自己的职位描述与我们核实过的来源检查结果。除了已存储的信号之外,我们不做任何推测。
职位描述
机器翻译我们的使命是实现编码自动化。我们旅程的第一步是为专业程序员打造最好的工具,结合富有创造力的研究、设计和工程。我们的组织非常扁平,团队规模小且人才密集。我们尤其喜欢求真、充满热情和富有创造力的人。我们享受激烈的辩论、疯狂的想法和交付代码。
岗位职责
我们正在招聘一名企业平台工程师,来构建让 Cursor 为全球最大的工程组织做好准备的基础系统。 今天我们已有基础的组织、简单的 IAM 原语、早期审计日志、分析 API 和管理 API——但企业客户需要更多。你将设计并构建平台层,为 Cursor 产品面上的组织管理、访问控制、合规和管理工具提供支持。这是一个深度技术型的独立贡献者角色,专注于构建正确、安全且可扩展的企业基础设施——而不是把供应商 SDK 拼凑在一起。 • 构建并演进我们的组织管理系统——多层级组织结构、组、角色、生命周期,以及通过 SCIM 进行配置,使管理员能够无摩擦地管理数千个席位。
• 设计并实现具有细粒度角色、权限和资源范围的 RBAC,覆盖组织、团队、代理和其他资源——在安全性与开发者易用性之间取得平衡。
• 扩展企业设置和策略——组织级默认值、安全策略(允许的模型、MCP、工具、网络限制),以及跨不同产品的配置继承。
• 深化我们的审计日志基础设施——全面、可查询、防篡改的审计轨迹,满足客户特定的合规要求。
• 构建管理 API 和内部工具,供企业管理员、客户成功和销售工程依赖,以管理组织、调查访问问题并完成大客户入职。
• 端到端交付合规功能——SSO 强制实施、会话管理、允许列表、数据分析,以及采购和安全团队在签约前所需的控制措施。
• 与产品、安全和基础设施团队合作,定义可在整个产品中扩展且不会拖慢功能开发的企业平台抽象。
• 你将负责组织管理、RBAC 和授权、企业设置和策略、审计日志、管理 API,以及合规相关的平台功能。你将成为 Cursor 如何为企业客户建模身份、访问和治理的技术权威。
• 你不负责协议层面的 SSO/IdP 集成(我们使用 WorkOS)或计费和支付。
• 安全和正确性是工作的一部分,但目标是构建足够严谨且具备可观测性的系统,使企业运营变得平淡无奇——而不是手动分诊每一个访问控制边缘情况。
如果你符合以下条件,你可能适合 • 你在生产环境中构建过多租户组织或 IAM 系统,并对权限模型、角色继承和策略评估有自己的见解。
• 你交付过 RBAC 或 ABAC 系统,并理解灵活性与复杂性之间的权衡。
• 你深切关注授权中的正确性,并理解为什么“失败关闭”很重要。
• 你能够承受“快速交付企业功能”与“不要制造安全漏洞或破坏现有访问模式”之间的张力。
• 你能够自如地端到端交付功能——从数据库模式和 API 设计到管理 UI 和文档。
#LI-DNI
以上内容由机器翻译自动生成,可能存在错误;投递前请以雇主原文为准。
查看雇主原文
职位描述
Our mission is to automate coding. The first step in our journey is to build the best tool for professional programmers, using a combination of inventive research, design, and engineering. Our organization is very flat, and our team is small and talent dense. We particularly like people who are truth-seeking, passionate, and creative. We enjoy spirited debate, crazy ideas, and shipping code.
岗位职责
We're hiring an Enterprise Platform Engineer to build the foundational systems that make Cursor ready for the world's largest engineering organizations. Today we have basic organizations, simple IAM primitives, early audit logs, analytics APIs, and admin APIs — but enterprise customers need much more. You will design and build the platform layer that powers organization management, access control, compliance, and administrative tooling across Cursor's product surface. This is a deeply technical IC role focused on building correct, secure, and scalable enterprise infrastructure — not gluing together vendor SDKs. • Build and evolve our organization management system — multi-level org structures, groups, roles, lifecycle, and provisioning via SCIM, so admins can manage thousands of seats without friction.
• Design and implement RBAC with fine-grained roles, permissions, and resource scopes that cover organizations, teams, agents, and other resources — balancing security with developer ergonomics.
• Extend enterprise settings and policies — org-wide defaults, security policies (allowed models, MCPs, Tools, network restrictions), and configuration inheritance across different products.
• Deepen our audit logging infrastructure — comprehensive, queryable, tamper-evident audit trails that satisfy customer-specific compliance requirements.
• Build admin APIs and internal tooling that enterprise admins, customer success, and sales engineering depend on to manage organizations, investigate access issues, and onboard large accounts.
• Ship compliance features end-to-end — SSO enforcement, session management, allowlisting, data analytics, and the controls that procurement and security teams require before signing.
• Partner with product, security, and infrastructure teams to define enterprise platform abstractions that scale across the product without slowing down feature development.
• You will own organization management, RBAC and authorization, enterprise settings and policies, audit logs, admin APIs, and compliance-related platform features. You will be a technical authority on how Cursor models identity, access, and governance for enterprise customers.
• You will not own SSO/IdP integration at the protocol level (we use WorkOS) or billing and payments.
• Security and correctness are part of the job , but the goal is to build systems with enough rigor and observability that enterprise operations are boring — not to manually triage every access control edge case.
You may be a fit if • You've built multi-tenant organization or IAM systems in production and have opinions on permission models, role inheritance, and policy evaluation.
• You've shipped RBAC or ABAC systems and understand the tradeoffs between flexibility and complexity.
• You deeply about correctness in authorization and understand why "fail closed" matters.
• You can hold the tension between "ship enterprise features fast" and "do not create security gaps or break existing access patterns."
• You feel comfortable shipping features end-to-end — from database schema and API design to admin UI and documentation.
#LI-DNI