
11 - 50 employees
Founded 2024
🤖 Artificial Intelligence
🔬 Science
☁️ SaaS
Artificial Intelligence • Science • SaaS
FirstPrinciples is a research company building AI systems for discovery in fundamental science. It develops domain-specialized models and tools (branded Theo: Theo Collaborator, Theo Conjecture, and Theo, the AI Physicist) to assist the scientific process—hypothesis generation, symbolic reasoning, tool integration, validation loops, and reproducible research objects. The company emphasizes transparency, stewardship of knowledge as a public good, and alignment with the scientific community. Technical claims include multiple fine-tuned models across physics domains, a model family with 120B+ parameters trained on a curated corpus of 3M+ scientific papers, and internal experiments in areas like quantum information.
🔥 0 minutes ago
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
Founded 2024
🤖 Artificial Intelligence
🔬 Science
☁️ SaaS
Artificial Intelligence • Science • SaaS
FirstPrinciples is a research company building AI systems for discovery in fundamental science. It develops domain-specialized models and tools (branded Theo: Theo Collaborator, Theo Conjecture, and Theo, the AI Physicist) to assist the scientific process—hypothesis generation, symbolic reasoning, tool integration, validation loops, and reproducible research objects. The company emphasizes transparency, stewardship of knowledge as a public good, and alignment with the scientific community. Technical claims include multiple fine-tuned models across physics domains, a model family with 120B+ parameters trained on a curated corpus of 3M+ scientific papers, and internal experiments in areas like quantum information.
• Define security architecture for Theo's SaaS application, APIs, cloud infrastructure, model-serving systems, agent runtimes, data platforms, research environments, and deployment pipelines • Build authentication and authorization for users, services, and AI agents, including scoped credentials, delegated permissions, least-privilege access, tenant isolation, and auditable actions • Design hardened execution environments for agent-generated and user-provided code with isolation, resource limits, filesystem and network controls, provenance, monitoring, and escape testing • Lead threat modelling and secure design across Engineering, Research, Product, and Infrastructure from architecture through production • Defend against AI- and agent-specific threats including prompt injection, unsafe tool use, confused-deputy behavior, poisoning, exfiltration, model extraction, privilege escalation, and resource abuse • Build secure-by-default services, libraries, policies, test harnesses, and platform controls for identity, secrets, encryption, policy enforcement, auditability, abuse prevention, and vulnerability management • Integrate SAST, DAST, dependency, container, infrastructure-as-code, secret, and software supply-chain scanning into development and release workflows • Establish security reviews, release controls, SBOMs, artifact provenance, and automated security regression testing • Conduct penetration tests, red-team and purple-team exercises, architecture attacks, and abuse-case testing • Assess vulnerabilities, coordinate remediation with engineers, validate fixes, and eliminate recurring weaknesses • Protect model weights, training and evaluation data, datasets, embeddings, registries, research artifacts, GPU infrastructure, and software supply chains • Define telemetry, alerting, containment, and forensic capabilities for incidents involving users, services, agents, models, and data • Translate SOC 2 and customer security requirements into technical controls and support FedRAMP and NIST SP 800-53 readiness • Automate evidence collection and control validation • Mentor engineers, establish reusable patterns, document architectural decisions, and communicate risks to technical teams and leadership • Within the first year, establish clear risk-based security architecture, explicit controls and adversarial coverage, secure-by-default workflows, integrated testing, remediation ownership, and a technical path toward FedRAMP readiness
• 7+ years of experience in product security, application security, cloud security, offensive security, or security-focused software engineering • Strong software engineering ability in at least one production language such as Python, Go, Rust, or TypeScript • Deep experience securing modern cloud and SaaS systems, including web applications, APIs, distributed services, databases, containers, Kubernetes, CI/CD, and infrastructure as code • Strong knowledge of authentication, authorization, IAM, tenant isolation, secrets management, encryption, network boundaries, logging, and secure software supply chains • Hands-on experience with threat modelling, architecture review, secure code review, vulnerability analysis, penetration testing, and remediation • Attacker-informed mindset developed through authorized red teaming, white-hat research, bug bounties, consulting, internal product-security work, or similar experience • History of delivering durable fixes through architecture changes, code contributions, shared security systems, or elimination of vulnerability classes • Judgment to balance security, product velocity, usability, and business risk • Ability to influence critical decisions across teams without formal authority • Clear written and verbal communication, intellectual honesty, high agency, and comfort with emerging threat models and architecture • Bonus: security experience with LLM applications, agentic systems, RAG, tool use, MCP integrations, code-generating systems, or multi-agent orchestration • Bonus: experience designing secure sandboxes, delegated authorization systems, machine identities, or fine-grained policy enforcement • Bonus: experience securing model training, evaluation, inference, model registries, datasets, embeddings, or GPU and Kubernetes infrastructure • Bonus: experience implementing technical controls for SOC 2 Type II, FedRAMP, or NIST SP 800-53 • Bonus: published vulnerability research, CVEs, meaningful bug-bounty findings, open-source security tools, or respected security-community participation • Bonus: deep Linux/Unix, TCP/IP, DNS, routing, firewall, proxy, VPN, AWS PrivateLink, VPC endpoint, private subnet, and controlled ingress/egress expertise • Bonus: experience establishing product security architecture in a high-growth startup, frontier technology company, or research environment • Resume and brief description of a security architecture, product-security system, or authorized offensive-security project required
• Remote-first work environment • Opportunity to shape foundational security architecture for AI scientific systems • Substantial influence over architecture, engineering practices, and security roadmap • Mentorship and capability-building opportunities • Opportunity to work with AI, scientific discovery, cloud infrastructure, and adversarial security • Global team collaboration across Canada, the US, and the UK
Apply Now🕒 August 14
Technical Counselor advising CIOs, CISOs, and technology executives across Canada. Shaping cybersecurity, AI, governance, and IT strategy through executive advisory services and research.
🕒 August 12
Staff Product Security Engineer building customer identity and authentication services for Affirm’s buy-now-pay-later platform. Designing secure, scalable CIAM backend systems and integrations.
🇨🇦 Canada – Remote
💵 $181k - $241k / year
💰 Post-IPO Equity on 2021-01
⏰ Full Time
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🕒 August 11
Staff Security Engineer advancing Mozilla’s Information Security Management System and ISO 27001/SOC 2 compliance. Supporting audits, policies, remediation, and certification readiness for an open-source technology company.
🕒 August 4
Mainframe Security Architect designing IBM Z and z/OS security for Kyndryl’s managed-services clients. Leading architecture, integration, operational readiness, and resilient security delivery.
🇨🇦 Canada – Remote
💵 $138.3k - $188.3k / year
⏰ Full Time
🟠 Senior
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🕒 July 21
Director of Cybersecurity Operations managing cybersecurity for Medavie, leading teams, and overseeing cybersecurity initiatives across the organization.