Full-Time

Staff Software Engineer

Obsidian Security

Obsidian Security

201-500 employees

SaaS security posture management

Compensation Overview

$223k - $239k/yr

+ Equity Awards + Sales Commission + Incentive Compensation

Philadelphia, PA, USA

In Person

Category
Software Engineering (1)
Required Skills
Kubernetes
Python
SQL
Apache Kafka
Postgres
Docker
TypeScript
AWS
Go
Redis
Google Cloud Platform

Get referred to Obsidian Security

See people who can refer or advise you

Requirements
  • 8+ years of experience in a software engineering role, with a track record of increasing technical scope and impact
  • Strong proficiency in one or more modern programming languages such as Python, Go, TypeScript, or SQL
  • Demonstrated experience designing and building backend services, APIs, distributed systems, data processing workflows, or production product features at scale
  • Deep understanding of relational databases such as Postgres, including performance and scaling tradeoffs
  • Experience with cloud platforms such as AWS or GCP, including cost, reliability, and architecture tradeoffs
  • Familiarity with containerization and orchestration technologies such as Docker and Kubernetes
  • Experience with event-driven or streaming systems such as Kafka, Redis, or similar technologies
  • Strong ability to reason about system design, performance, reliability, security, and operational tradeoffs across multiple systems and teams
  • Experience setting technical direction and leading complex, cross-team technical initiatives without needing formal authority
  • Strong communication skills in code reviews, design discussions, and cross-functional planning, including with senior stakeholders
Responsibilities
  • Own features and system architecture from problem definition through production, at a scope spanning multiple teams or the broader platform
  • Design and build backend services, APIs, data processing workflows, integrations, and product-facing capabilities
  • Set technical direction and architectural standards that other engineers and teams build against
  • Work with product managers, designers, security researchers, and engineers to turn customer needs into shipped software
  • Improve the performance, reliability, scalability, and observability of existing systems, and identify systemic risks before they become incidents
  • Make practical technical decisions with organization-wide impact and explain the tradeoffs clearly to both technical and non-technical stakeholders
  • Raise engineering standards through code reviews, design discussions, mentoring senior and mid-level engineers, and documentation
  • Debug the hardest production issues and drive teams to durable fixes, not just short-term patches
  • Use AI-powered tools effectively while maintaining high standards for correctness, security, and maintainability
Desired Qualifications
  • Experience with observability and monitoring tools such as Grafana, Prometheus, or similar platforms
  • Experience with CI/CD pipelines and deployment tooling such as GitLab CI/CD
  • Deep exposure to large-scale distributed systems, high-throughput ingestion, or data pipeline architecture
  • Background or interest in security, SaaS platforms, identity, threat detection, or data protection
  • Experience working across multiple engineering teams or across geographically distributed teams
  • Experience mentoring engineers, including senior engineers, and helping teams improve technical practices
  • Experience evaluating AI-generated code and using AI tools as part of an engineering workflow
  • Leverage AI tools effectively to improve development efficiency and build AI-ready systems
  • Critically evaluate, test, and refine AI-generated outputs before they reach production
  • Understand core AI/ML concepts such as LLMs, embeddings, vector databases, inference, and evaluation
  • Experience integrating AI/ML APIs or building systems that support AI-driven product workflows
  • Ensure quality, observability, reliability, security, and performance in systems that use or support AI capabilities
  • Help establish org-wide norms and best practices for AI-assisted engineering

Obsidian Security provides a security and posture management platform for enterprise SaaS environments, offering unified visibility and control across large SaaS footprints like Microsoft 365, Salesforce, Workday, and ServiceNow. It connects to apps via APIs to collect configuration, user activity, and privilege data, then builds a Knowledge Graph to map relationships among users, permissions, and activities for threat detection such as account compromise, insider threats, and configuration drift. The platform now extends to AI governance, enabling discovery and management of shadow AI, monitoring AI agent behavior, and protection against token compromise and prompt injection. Its pricing based on organizational headcount and its enterprise-focused customer base, including Fortune 500 companies, distinguish it from competitors while the goal is to give security and IT teams a single view and control plane for SaaS and AI-enabled ecosystems.

Company Size

201-500

Company Stage

Series D

Total Funding

$204.5M

Headquarters

Newport Beach, California

Founded

2017

Get referred to Obsidian Security

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • On August 4, 2026, Obsidian raised $85 million at a $1.1 billion valuation.
  • Obsidian reported over 60 Fortune 500 customers, 100 customers above $100K, and 14 above $1 million.
  • On July 21, 2026, Claude Compliance API integration and Carl Shimel’s hire strengthened execution.

What critics are saying

  • Microsoft, Salesforce, and Anthropic can bundle native controls and squeeze Obsidian’s pricing.
  • Salesloft-Drift proved token theft happens inside integrations Obsidian depends on, not just around them.
  • If enterprises standardize on SIEM, IAM, or CNAPP platforms, Obsidian becomes a point solution.

What makes Obsidian Security unique

  • Obsidian’s knowledge graph correlates identities, permissions, and activity across SaaS applications.
  • It now governs AI agents in Copilot Studio, Agentforce, Claude, and MCP ecosystems.
  • Browser-level shadow AI detection and Integration Attestation expose SaaS abuse others miss.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Unlimited Paid Time Off

Paid Holidays

Parental Leave

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

2%

2 year growth

1%
Obsidian Security
Aug 6th, 2026
Ex-Cylance tech chief raises $9.5M for new cybersecurity startup Obsidian Security

A new cybersecurity startup called Obsidian Security has raised $9.5 million in Series A funding from Silicon Valley venture capital firm Greylock Partners. The previously unannounced company was founded by several cybersecurity industry veterans, including the former chief technology officer of Cylance. Fortune first reported the news of the startup's formation and funding round.

Yahoo Finance
Aug 4th, 2026
Obsidian Security raises $85M at $1.1B valuation amid surging demand for AI agent security

Obsidian Security has raised $85 million in Series D funding at a $1.1 billion valuation, led by Crescent Cove Advisors. The round addresses growing demand for AI agent security as businesses increasingly grant autonomous software access to sensitive enterprise data. The funding comes amid heightened concerns over AI safety. OpenAI recently disclosed that one of its models escaped testing environments, whilst Anthropic reported an experimental agent breached enterprise systems during internal testing. Chief executive Hasan Imam said nearly 70% of Obsidian's customers already allow AI agents to interact with business data. The company will use proceeds to expand its platform, which monitors AI agents across applications including Microsoft Copilot Studio and Salesforce Agentforce. Existing investors Greylock Partners and Menlo Ventures also participated.

Channel NewsAsia
Aug 4th, 2026
Obsidian Security raises funding at $1.1 billion valuation on AI security demand.

Obsidian Security raises funding at $1.1 billion valuation on AI security demand. 04 Aug 2026 08:03PM (Updated: 04 Aug 2026 08:10PM) Add CNA as a trusted source to help Google better understand and surface our content in search results. Aug 4: Obsidian Security said on Tuesday it had raised $85 million in a Series D funding round that valued the AI security startup at $1.1 billion, as businesses seek to secure a growing number of AI agents accessing sensitive enterprise data. The round, led by Crescent Cove Advisors, comes as businesses adopt autonomous software agents with access to customer records, source code, and other critical enterprise systems amid growing scrutiny of AI agent safety. OpenAI disclosed last week that one of its frontier models escaped its testing environment after exploiting a misconfiguration and accessed AI platform Hugging Face to retrieve evaluation data. Anthropic separately said one of its experimental agents breached multiple enterprise environments during internal testing after exploiting weak authentication controls. Chief Executive Hasan Imam said enterprises are rapidly giving AI agents access to third-party applications, with nearly 70 per cent of Obsidian's customers already allowing agents to interact with business data. "I think six to twelve months down the road, we are going to see a significant disruption in the agentic economy," Imam told Reuters, as cheaper proprietary and open-source models gain widespread enterprise adoption. Obsidian said it would use the proceeds to expand its platform, which monitors and governs AI agents operating across third-party applications such as Microsoft Copilot Studio, Salesforce Agentforce and Anthropic's Claude. Crescent Cove founder and chief investment officer Jun Hong Heng said falling AI costs would accelerate enterprise adoption of autonomous agents and drive demand for security software. Obsidian said the funding should support the company until it reaches positive cash flow as it aims to establish itself as a leader in AI agent security. Existing investors Greylock Partners and Menlo Ventures also participated in the round.

Obsidian Security
Aug 4th, 2026
Obsidian raises $85 million Series D to scale AI agent security growth.

Obsidian raises $85 million Series D to scale AI agent security growth. * Company valued at $1.1B with world's largest and most complex enterprises deploying agents with Obsidian's AI security platform * Trusted by 60 of the Fortune 500 companies including major financial institutions, social media networks and top telecom providers to prevent rogue agent activity in third-party applications * Series D funding, led by Crescent Cove Advisors, fuels Obsidian's R&D to secure enterprises against next-gen frontier models exploiting vulnerabilities in third-party applications PALO ALTO, Calif. - August 4, 2026 - Obsidian Security, the leading platform securing non-human identities and AI agents across third-party applications, today announced $85 million in Series D financing led by Crescent Cove Advisors, with participation from all existing investors including Greylock Partners and Menlo Ventures. The round follows accelerating customer growth with more than 100 customers now spending over $100K annually and over 14 customers spending more than $1 million today. As enterprises adopt AI agents built on next-gen models across platforms like Anthropic's Claude, OpenAI's ChatGPT, and Microsoft Copilot Studio, they are increasingly turning to Obsidian to secure how those agents operate inside the third-party applications that run their business. Obsidian has spent years preparing for this moment. Non-human identities outnumber human identities 144 to 1 inside third-party applications, and agents built on frontier models are multiplying that gap further, landing in an environment where fixing exposure already takes months. As enterprises adopt agents from multiple AI ecosystems at once, agent misbehavior is becoming more common, and security teams need one durable control point across all of them. That need has driven Obsidian's growth among the world's largest organizations across the Fortune 500 and Global 2000 and that scale is now a strength in itself. As more enterprises adopt Obsidian, its network intelligence compounds, turning patterns spotted at one company into faster protection for every customer on the platform. Obsidian will use the funding to extend that lead, bringing its platform to more of the Fortune 500 and Global 2000 as the standard for securing what AI agents can access and do. "AI is fundamentally changing how enterprises operate, creating new infrastructure challenges that legacy security models weren't designed to address," said Jun Hong Heng, Founder and Chief Investment Officer of Crescent Cove Advisors. "Obsidian recognized that shift early and is building the platform enterprises need to securely adopt AI at scale. The company embodies the kind of foundational technology we seek to back, and we are excited to support the team as they continue to define the future of AI security." "AI agents gravitate toward third-party applications. That's where the data lives, that's where the work happens, and that's exactly where the risk lives too," said Hasan Imam, CEO of Obsidian Security. "Frontier and open-source models alike are pushing agents deeper into these environments faster than most security teams can track. More than 70% of our customers already let agents into third-party apps, and that number is only going up. We intend to be the platform that protects enterprises from agents going rogue in third-party applications, so enterprises get the full return on every agent they deploy. That's the future we're building toward." Closing the gap between AI agent adoption and AI agent governance. Enterprise AI agents, whether built on platforms like Microsoft Copilot Studio, Salesforce Agentforce and n8n, or operating as autonomous developer agents like Anthropic's Claude Code and Cowork, increasingly reach into data warehouses (Databricks, Snowflake), developer infrastructure (GitHub, GitLab), CRM, sales systems (Salesforce, HubSpot), and collaboration tools (Notion, Slack) and other third-party applications. These applications hold source code, regulated data, and intellectual property and an unsecured agent can leak, modify, or delete that data at machine speed. Security teams consistently report three top concerns: agents taking destructive or irreversible actions, unsanctioned agents connecting to critical systems without approval, and agents reaching sensitive data they were never meant to access. Recent incidents underscore the stakes from an AI agent that triggered a 13-hour cloud outage after being granted overly broad permissions, to an agent that deleted decades of irreplaceable personal files, to an agent that circumvented an application's native guardrails to delete a company's production database and backups. Obsidian has been building toward exactly this moment. Its runtime governance detects and blocks privilege escalation, excessive data access and policy violations for agents built on agentic platforms like Microsoft Copilot, n8n, Google Vertex, Amazon Bedrock, OpenAI and others. That's backed by complete inventory of every agent, MCP server and LLM running in third party systems, so security teams know what's connected before something goes wrong. Today's announcement builds directly on that foundation. Obsidian's new AI security capabilities. 1. Agent Access Governance to Claude Code and Cowork: Building on existing coverage for platforms like Copilot Studio, OpenAI, Salesforce Agentforce, n8n, and more, Obsidian extends its AI agent security to Anthropic's Claude platform, giving security teams the ability to discover, govern, and enforce what Claude Code and Cowork agents can access and do inside their most critical third-party applications. The capability set includes restricting dangerous agent permissions to production data, managing agent access to sensitive files, right-sizing excessive access, controlling unsanctioned MCP and tool usage, and preventing destructive agent actions at runtime. 2. Runtime Protection for AI Agents: Enforce real-time guardrails for agents built with Microsoft Copilot, and Anthropic Claude, detecting and blocking privilege escalation, excessive data access, and policy violations at execution time, before impact occurs, based on risk factors aligned to OWASP standards and industry best practices. Security cannot credibly govern agents if control only happens after misuse. With real-time enforcement from Obsidian, governance shifts from reactive monitoring to preventative action. 3. MCP Server Inventory: Gain complete visibility into every MCP server across the enterprise, mapped to the agents that invoke them, enabling security teams to identify unsanctioned MCP usage and assess the downstream blast radius of agentic connections to backend systems and services. By surfacing the execution layer behind agents, Obsidian extends governance to the infrastructure and tools agents actually invoke, exposing all agentic risk without stitching together fragmented dashboards. 4. LLM Inventory: Track every large language model powering agents in the environment to spot when models are switched or substituted, giving security and compliance teams continuous assurance that only sanctioned models drive enterprise agents. Security teams will no longer be surprised by new agentic behavior. They will always know which models are operating inside their environment. Additional resources. Watch Obsidian Security CEO, Hasan Imam share more about today's announcement at: https://youtu.be/jEQZwaa8coA About Obsidian Security Obsidian Security secures the AI-first enterprise, governing data, AI and agents inside third-party applications. Trusted by Fortune 1000 and Global 2000 enterprises, Obsidian gives security teams visibility into what's connected, controls to enforce what's allowed, and the runtime context to govern AI and agent activity before it causes damage inside critical business systems. Headquartered in Palo Alto, California, Obsidian is backed by Crescent Cove Advisors, Menlo Ventures, Norwest Venture Partners, IVP, Greylock, GV, and Wing. For more information, visit www.obsidiansecurity.com.

Financial Post
Aug 4th, 2026
Obsidian raises $85 million Series D to scale AI Agent security growth.

Obsidian raises $85 million Series D to scale AI Agent security growth. Business Wire Published Aug 04, 2026 Article content Company Achieves Unicorn Status with Global Enterprise Adoption of Obsidian's AI Security Platform Accelerating Article content * Company valued at $1.1B with world's largest and most complex enterprises deploying agents with Obsidian's AI security platform * Trusted by 60 of the Fortune 500 companies including major financial institutions, social media networks and top telecom providers to prevent rogue agent activity in third-party applications * Series D funding, led by Crescent Cove Advisors, fuels Obsidian's R&D to secure enterprises against next-gen frontier models exploiting vulnerabilities in third-party applications Article content Advertisement 1 Story continues below This advertisement has not loaded yet, but your article continues below. Article content PALO ALTO, Calif. - Obsidian Security, the leading platform securing non-human identities and AI agents across third-party applications, today announced $85 million in Series D financing led by Crescent Cove Advisors, with participation from all existing investors including Greylock Partners and Menlo Ventures. The round follows accelerating customer growth with more than 100 customers now spending over $100K annually and over 14 customers spending more than $1 million today. As enterprises adopt AI agents built on next-gen models across platforms like Anthropic's Claude, OpenAI's ChatGPT, and Microsoft Copilot Studio, they are increasingly turning to Obsidian to secure how those agents operate inside the third-party applications that run their business. Article content Obsidian Security Achieves Unicorn Status with $1.1B Valuation Article content Top Stories Interested in more newsletters? Browse here. Article content Obsidian has spent years preparing for this moment. Non-human identities outnumber human identities 144 to 1 inside third-party applications, and agents built on frontier models are multiplying that gap further, landing in an environment where fixing exposure already takes months. As enterprises adopt agents from multiple AI ecosystems at once, agent misbehavior is becoming more common, and security teams need one durable control point across all of them. That need has driven Obsidian's growth among the world's largest organizations across the Fortune 500 and Global 2000 and that scale is now a strength in itself. As more enterprises adopt Obsidian, its network intelligence compounds, turning patterns spotted at one company into faster protection for every customer on the platform. Article content Obsidian will use the funding to extend that lead, bringing its platform to more of the Fortune 500 and Global 2000 as the standard for securing what AI agents can access and do. Article content "AI is fundamentally changing how enterprises operate, creating new infrastructure challenges that legacy security models weren't designed to address," said Jun Hong Heng, Founder and Chief Investment Officer of Crescent Cove Advisors. "Obsidian recognized that shift early and is building the platform enterprises need to securely adopt AI at scale. The company embodies the kind of foundational technology we seek to back, and we are excited to support the team as they continue to define the future of AI security." Article content "AI agents gravitate toward third-party applications. That's where the data lives, that's where the work happens, and that's exactly where the risk lives too," said Hasan Imam, CEO of Obsidian Security. "Frontier and open-source models alike are pushing agents deeper into these environments faster than most security teams can track. More than 70% of our customers already let agents into third-party apps, and that number is only going up. We intend to be the platform that protects enterprises from agents going rogue in third-party applications, so enterprises get the full return on every agent they deploy. That's the future we're building toward." Article content Advertisement 2 Story continues below This advertisement has not loaded yet, but your article continues below. Article content Closing the Gap Between AI Agent Adoption and AI Agent Governance Article content Enterprise AI agents, whether built on platforms like Microsoft Copilot Studio, Salesforce Agentforce and n8n, or operating as autonomous developer agents like Anthropic's Claude Code and Cowork, increasingly reach into data warehouses (Databricks, Snowflake), developer infrastructure (GitHub, GitLab), CRM, sales systems (Salesforce, HubSpot), and collaboration tools (Notion, Slack) and other third-party applications. These applications hold source code, regulated data, and intellectual property and an unsecured agent can leak, modify, or delete that data at machine speed. Article content Security teams consistently report three top concerns: agents taking destructive or irreversible actions, unsanctioned agents connecting to critical systems without approval, and agents reaching sensitive data they were never meant to access. Recent incidents underscore the stakes from an AI agent that triggered a 13-hour cloud outage after being granted overly broad permissions, to an agent that deleted decades of irreplaceable personal files, to an agent that circumvented an application's native guardrails to delete a company's production database and backups. Article content Obsidian has been building toward exactly this moment. Its runtime governance detects and blocks privilege escalation, excessive data access and policy violations for agents built on agentic platforms like Microsoft Copilot, n8n, Google Vertex, Amazon Bedrock, OpenAI and others. That's backed by complete inventory of every agent, MCP server and LLM running in third party systems, so security teams know what's connected before something goes wrong. Today's announcement builds directly on that foundation. Article content Obsidian's New AI Security Capabilities Article content 1. Agent Access Governance to Claude Code and Cowork: Building on existing coverage for platforms like Copilot Studio, OpenAI, Salesforce Agentforce, n8n, and more, Obsidian extends its AI agent security to Anthropic's Claude platform, giving security teams the ability to discover, govern, and enforce what Claude Code and Cowork agents can access and do inside their most critical third-party applications. The capability set includes restricting dangerous agent permissions to production data, managing agent access to sensitive files, right-sizing excessive access, controlling unsanctioned MCP and tool usage, and preventing destructive agent actions at runtime. Advertisement 1 This advertisement has not loaded yet. Advertisement 2 Article content 2. Runtime Protection for AI Agents: Enforce real-time guardrails for agents built with Microsoft Copilot, and Anthropic Claude, detecting and blocking privilege escalation, excessive data access, and policy violations at execution time, before impact occurs, based on risk factors aligned to OWASP standards and industry best practices. Security cannot credibly govern agents if control only happens after misuse. With real-time enforcement from Obsidian, governance shifts from reactive monitoring to preventative action. Article content 3. MCP Server Inventory: Gain complete visibility into every MCP server across the enterprise, mapped to the agents that invoke them, enabling security teams to identify unsanctioned MCP usage and assess the downstream blast radius of agentic connections to backend systems and services. By surfacing the execution layer behind agents, Obsidian extends governance to the infrastructure and tools agents actually invoke, exposing all agentic risk without stitching together fragmented dashboards. Article content 4. LLM Inventory: Track every large language model powering agents in the environment to spot when models are switched or substituted, giving security and compliance teams continuous assurance that only sanctioned models drive enterprise agents. Security teams will no longer be surprised by new agentic behavior. They will always know which models are operating inside their environment. Article content Additional Resources Article content Watch Obsidian Security CEO, Hasan Imam share more about today's announcement at: https://youtu.be/jEQZwaa8coA Article content About Obsidian Security Article content Obsidian Security secures the AI-first enterprise, governing data, AI and agents inside third-party applications. Trusted by Fortune 1000 and Global 2000 enterprises, Obsidian gives security teams visibility into what's connected, controls to enforce what's allowed, and the runtime context to govern AI and agent activity before it causes damage inside critical business systems. Headquartered in Palo Alto, California, Obsidian is backed by Crescent Cove Advisors, Menlo Ventures, Norwest Venture Partners, IVP, Greylock, GV, and Wing. For more information, visit www.obsidiansecurity.com. Article content View source version on businesswire.com: Article content Advertisement 2 This advertisement has not loaded yet. Quick Picks