Full-Time

Design Engineer

Site

Posted on 9/7/2026

Infisical

Infisical

11-50 employees

Open-source end-to-end encrypted secrets management platform

Compensation Overview

$100k - $180k/yr

+ Equity options + Lunch stipend + Work setup budget

Remote in USA + 1 more

More locations: Remote in Canada

Remote

Must be based in the Americas or able to work Eastern Time hours.

Category
Software Engineering (1)
Required Skills
JavaScript
React.js
Node.js
HubSpot
SEO
A/B Testing
TypeScript
Next.js
Google Analytics

Get referred to Infisical

See people who can refer or advise you

Requirements
  • Deep mastery of JavaScript, React.js, Node.js, TypeScript, and frameworks such as React and Next.js.
  • Experience building high-quality frontend systems and components with strong attention to performance, accessibility, and maintainability.
  • Experience with web design and design systems.
  • Ability to make decisions, iterate quickly, and take calculated risks.
  • Based in the Americas, preferably San Francisco, or able to work Eastern Time hours.
Responsibilities
  • Design and ship pixel-perfect, reusable components and complex designs.
  • Build and maintain core website pages, including the home page, product pages, blogs, and learning/resource hubs.
  • Build microsites and maintain frontend architecture, code quality, CMS integration, and the CMS experience.
  • Implement search engine optimization best practices, run A/B tests, and optimize conversion funnels.
  • Integrate analytics, attribution, and marketing tooling, including Google Analytics, Google Tag Manager, and HubSpot.
  • Own and maintain the company's website and serve as the primary person responsible for its design and infrastructure.
Desired Qualifications
  • Technical search engine optimization fundamentals.
  • Experience with content management system platforms such as Contentful and Sanity.
  • Experience configuring website analytics and marketing platform integrations such as Google Analytics and HubSpot.
  • Experience with developer-facing products or startups.

Infisical provides an open-source platform for managing secrets and application configurations with end-to-end encryption. It helps developers store and sync sensitive data such as API keys and credentials across teams, with SDKs for multiple programming languages and easy deployment options including Kubernetes. The system uses a zero-knowledge architecture so neither Infisical nor attackers can access the stored data, and it offers features like automatic secret rotation, dynamic secrets, and continuous monitoring to prevent leaks. It differentiates itself by being open-source, offering self-hosting, and providing strong encryption and language-agnostic integrations, along with scalable deployment options for teams from small groups to large enterprises. Its goal is to help organizations secure secrets and configurations more reliably and efficiently, reducing the risk of credential leaks while supporting developer workflows and collaboration.

Company Size

11-50

Company Stage

Series A

Total Funding

$18.9M

Headquarters

San Francisco, California

Founded

2022

Get referred to Infisical

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • April 2026 Agent Vault extends Infisical into fast-growing AI infrastructure security.
  • June 2025 Series A led by Elad Gil provides capital and signal.
  • Case studies from Hugging Face and Airbyte support enterprise expansion and revenue conversion.

What critics are saying

  • Doppler, HashiCorp Vault, and OpenBao compress pricing and feature differentiation.
  • Agent Vault is still research preview, so production teams face adoption uncertainty.
  • If AI-agent security stalls, Infisical remains exposed to a crowded secrets-management market.

What makes Infisical unique

  • Agent Vault, launched April 22, 2026, targets AI-agent credential exfiltration directly.
  • Infisical combines open-source secrets management with certificates and privileged access management.
  • Named customers like Hugging Face, Airbyte, and Lucid validate enterprise adoption.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company Equity

Home Office Stipend

Phone/Internet Stipend

Remote Work Options

Growth & Insights and Company News

Headcount

6 month growth

-4%

1 year growth

-4%

2 year growth

-9%
AiThority
Apr 22nd, 2026
Infisical launches Agent Vault, letting Engineering Teams Ship AI agents to production without exposing credentials.

Infisical launches Agent Vault, letting Engineering Teams Ship AI agents to production without exposing credentials. Engineering teams building with AI agents can now ship them to production without exposing API keys and credentials to prompt injection. Agent Vault, available today on github, lets agents do their jobs without ever reading the underlying secrets, and runs on any infrastructure the team already uses. Infisical, the all-in-one secrets, certificates, and privileged access management platform, today launched Agent Vault, an open source credential security layer for AI agents. Available in research preview today at github.com/Infisical/agent-vault, Agent Vault gives engineering teams a way to move agents into production safely, with one credential security layer that works across every environment where they run agents: on-premise, in Kubernetes, and across any cloud. For the platform, DevOps, and security teams standing behind the rapid rollout of AI agents, Agent Vault closes a gap that has forced uncomfortable trade-offs between shipping quickly and controlling risk. Traditional secrets management was designed for applications that fetch a credential and use it directly, a model that breaks the moment an agent is exposed to prompt injection, because any secret an agent can read is a secret an attacker can exfiltrate. Agent Vault removes that risk at the source. Agents route their outbound requests through Agent Vault, which attaches credentials at the proxy layer, so the agent completes its work without ever seeing, storing, or logging the underlying secret. The credential brokering happens transparently: the agent is not aware that the proxy layer exists at all, which means a compromised agent has no surface to reason about, probe, or attempt to circumvent. In technical terms, Agent Vault is a TLS-intercepting, credential-injecting forward proxy purpose-built for agent workloads. "Secrets management was built for a world where applications fetched credentials and used them. That assumption no longer holds for AI agents," said Tuan (Tony) Dang, CTO and co-founder of Infisical. "The tools most teams rely on for secrets management today were designed long before prompt injection was a concern, and they are anchored to a paradigm that predates this problem. Agent Vault is purpose-built for the agentic era. It reflects how we think secrets management should work when agents, not humans, are the primary actors on the internet." Apr 22, 2026 Prev Next 1 of 42,991 What Agent Vault Delivers for Engineering Teams For the teams deploying AI agents at scale, that shift changes what the day-to-day work of shipping agents actually looks like. * Ship agents to production without the credential risk. Teams no longer need to choose between moving fast on agent development and protecting sensitive credentials. Agents keep their full ability to call APIs, query databases, and integrate with internal services, but a prompt injection attack cannot walk away with the keys. * One credential layer across every environment. Most organizations building with agents run across multiple clouds, on-premise systems, and hybrid infrastructure. Agent Vault follows the agent wherever it runs, so teams govern credential access in one place instead of stitching together environment-specific solutions. * No agent code changes required. Agent environments can be configured so that all outbound traffic routes through Agent Vault automatically. Every agent running in that environment is covered without modifying agent code, rewriting prompts, or swapping SDKs. Teams protect their entire agent fleet with a single infrastructure change Get Started With Agent Vault Engineering teams can start building with Agent Vault today. The open source project is live at github.com/Infisical/agent-vault, with full installation instructions, integration guides, and architectural overviews available at docs.agent-vault.dev. Teams evaluating credential security for agent deployments that demand production-grade reliability and enterprise support are invited to reach out to the Infisical team at infisical.com/talk-to-Aithority to discuss a commercial path. Research preview status Agent Vault is launching as a research preview. It is open source and available for developers to experiment with today, but it is not yet production-ready. Infisical is releasing Agent Vault at this stage to share its thinking openly, gather feedback from the engineering community, and iterate in public. Organizations interested in a production-grade version for enterprise use are encouraged to contact the Infisical team directly.

Fortune
Jun 6th, 2025
Infisical raises $16 million Series A led by Elad Gil to safeguard secrets

Infisical, secrets management startup, has raised a $16 million Series A, led by Elad Gil.

Fortune
Jun 6th, 2025
Infisical raises $16 million Series A led by Elad Gil to safeguard secrets

Infisical raises $16 million Series A led by Elad Gil to safeguard secrets.

TMCnet
Jun 6th, 2025
Infisical Secures $16M Series A to Redefine Enterprise Secrets, Identity, and Access Management

Infisical secures $16M series A to redefine enterprise secrets, identity, and access management.

Infisical
Jul 4th, 2023
Infisical $2.8M Seed Round

Infisical raised a $2.8M seed round led by Gradient Ventures with participation from Y Combinator and other investors.