Full-Time

AI Product Engineer

Mathspace

Mathspace

51-200 employees

Adaptive math instruction with real-time personalization

No salary listed

Sydney NSW, Australia + 1 more

More locations: Remote in Australia

Remote

Remote work requires some timezone overlap with Sydney.

Category
Software Engineering (2)
,
Required Skills
LLM
Python
React.js
Machine Learning
GraphQL
RAG
TypeScript
Observability

Get referred to Mathspace

See people who can refer or advise you

Requirements
  • At least 5 years of industry experience in product-focused full-stack or backend engineering.
  • Proficiency with React, TypeScript, Python, and GraphQL.
  • Hands-on experience building and deploying large-language-model-powered applications in production.
  • Familiarity with retrieval-augmented generation, prompt engineering, evaluation frameworks, and LLMOps best practices.
  • Product intuition and user empathy, particularly in educational contexts.
  • Ability to collaborate cross-functionally with pedagogy, design, and engineering teams.
Responsibilities
  • Design and build AI-powered learning experiences integrating large language models into student- and teacher-facing applications.
  • Prototype, test, and deploy LLM-based features including math-specific feedback, adaptive hints, automated question generation, and teacher co-pilot tools.
  • Work across the stack using React, TypeScript, Python, and GraphQL.
  • Experiment with prompting, retrieval-augmented generation, vector search, and fine-tuning strategies to optimize student learning outcomes.
  • Collaborate with curriculum and pedagogy teams to ensure AI experiences are pedagogically sound and aligned with educational values.
  • Contribute to AI infrastructure and LLMOps processes, including evaluation pipelines, prompt versioning, and observability tools.
  • Design safeguards for appropriate use of large language models in educational contexts.
Desired Qualifications
  • A desire to move quickly, learn continuously, and build products for students and teachers.

Mathspace personalizes mathematics instruction and assessment using an adaptive algorithm that changes in real time to match a student’s strengths and gaps. Its system provides step-by-step guidance with hints and video lessons linked to each practice question, making practice feel like a personal tutor. Teachers can use ready-made digital materials aligned to national curricula or assign custom practice to students, supporting both self-directed learning and structured class work. The platform stands out by combining real-time adaptation with curriculum-aligned content and instructional support for every question. The goal is to improve math learning outcomes by delivering tailored practice and feedback that fits each student’s needs.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

Sydney, Australia

Founded

2010

Get referred to Mathspace

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Mathspace was shortlisted for the 2026 BETT Innovation Award, strengthening brand credibility.
  • The Desmos partnership broadens classroom usefulness and deepens adoption in Virginia.
  • MiloAI’s Chat Moderation System addresses parent and teacher anxiety around student-facing AI tools.

What critics are saying

  • The September 3, 2026 breach exposed 1,079,819 AU and NZ users, crushing trust.
  • Mathspace missed Metabase’s August 6 patch; another internal reporting flaw can trigger a second breach.
  • Schools can switch to Pearson, Khan Academy, or Desmos if Mathspace’s security failures persist.

What makes Mathspace unique

  • Mathspace sells school-aligned math practice with embedded teacher oversight and AI tutoring.
  • MiloAI’s moderation system gives teachers escalation control over student chat safety.
  • Desmos integration and standards-focused workflows keep Mathspace tightly embedded in classroom instruction.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Flexible Work Hours

Remote Work Options

Professional Development Budget

Company News

IT Security News
Sep 7th, 2026
Mathspace Breach Exposes Data of 1.08 million in Australia, New Zealand.

Mathspace Breach Exposes Data of 1.08 million in Australia, New Zealand. 2026-09-07 21:09 Mathspace says a breach exposed data tied to nearly 1.08 million people in Australia and New Zealand after attackers exploited a self-hosted Metabase flaw. Read the original article: AssuranceAmerica disclosed a data breach affecting nearly 7 million people after attackers compromised an employee account. The post AssuranceAmerica Data Breach Exposes Nearly 7 Million Drivers appeared first on eSecurity Planet. This article has been indexed from eSecurity PlanetRead the original article: AssuranceAmerica Data Breach Exposes Nearly 7 Million Drivers Book Security Audits July 9, 2026 KDDI disclosed a breach that may have exposed up to 14.2 million email accounts after attackers exploited a third-party software vulnerability. The post KDDI Data Breach May Expose 14.2 Million Email Accounts appeared first on eSecurity Planet. This article has been indexed from eSecurity PlanetRead the original article: KDDI Data... June 29, 2026 A massive Coupang breach exposed nearly 34 million customers, highlighting insider-risk dangers and gaps in South Korea's data protections. The post Coupang Breach Exposes Data of Nearly 34 Million Customers appeared first on eSecurity Planet. This article has been indexed from eSecurity PlanetRead the original article: Coupang Breach Exposes Data... December 1, 2025

Cryptika
Sep 7th, 2026
Online maths learning platform Mathspace disclosed data breach impacts 1 million users.

Online maths learning platform Mathspace disclosed data breach impacts 1 million users. Spread the love Online maths learning platform Mathspace has confirmed a data breach that exposed the personal information of more than one million students, parents, guardians, and school staff across Australia and New Zealand, after attackers exploited a critical flaw in its internal reporting software. The Sydney-based edtech company, which is widely used in classrooms across both countries, said on 3 September 2026 that unauthorized parties had accessed an internal reporting system and downloaded records belonging to students, their families, teachers, and Mathspace's own employees. In total, 1,079,819 people were affected, making it one of the largest education-sector breaches reported in the region this year. Mathspace data breach. According to Mathspace's disclosure, attackers exploited a security vulnerability in the company's self-hosted Metabase installation, an open-source business intelligence tool used for internal reporting. The flaw, tracked as CVE-2026-72898, was an unauthenticated SQL injection accessible through Metabase's password-reset API endpoint, and it allowed attackers to inject arbitrary SQL commands and seize administrator access without needing valid credentials. Metabase disclosed the critical, actively exploited vulnerability on 6 August 2026 and rated it the maximum CVSS score of 10.0, releasing patched versions the same day. CISA added the flaw to its Known Exploited Vulnerabilities catalog within days, underscoring how quickly threat actors began weaponizing it against internet-facing instances. Mathspace, however, did not act on the advisory in time. The company admitted that its "existing vulnerability-notification process did not identify and escalate that advisory for action." Unauthorized access to its Australian reporting database began on 10 August, just four days after the patch became available, and attackers exfiltrated data on 27 August. Mathspace only updated its Metabase instance on 29 August, after a separate, later notice drew its attention to the issue, and it did not initially perform the additional compromise checks Metabase recommended for systems that had remained vulnerable during that window. That gap meant the earlier intrusion went undetected until a review of historical access logs on 3 September confirmed unauthorized access had occurred before the patch was applied. The compromised records included user IDs, usernames, first and last names, email addresses, country, time zone, account type, email verification status, last active date, last login date, and account creation date. Not every field was present for every individual affected. Mathspace emphasized that no passwords, password hashes, single sign-on tokens, API credentials, academic records, assessment results, or learning activity data were exposed, and that the stolen data did not directly link accounts to specific schools, though the company acknowledged this could be inferred for schools using identifiable email domains. It said it has "no evidence so far" that the stolen data has been published, sold, or otherwise misused, and the attacker's identity remains unknown. Mathspace began emailing school contacts about the incident on 4 September and has urged recipients to verify any suspicious breach-related communication directly through its official data-breach response channel rather than clicking embedded links. The company has taken the affected reporting system offline, notified schools, education departments, and cybersecurity authorities, and says it is revising its advisory-escalation and post-patch verification processes to prevent a recurrence. Affected students, parents, and staff are advised to treat unexpected emails referencing Mathspace or their school with caution, avoid reusing passwords across services, and monitor accounts for unusual password-reset requests or login activity. Learn 7 Metric-Gated AI SOC Deployment Phases - Download Free AI SOC Deployment Playbook 2026. The post online maths learning platform Mathspace disclosed data breach impacts 1 million users appeared first on cyber security News. June 14, 2026 The Office of the Maine Attorney General has temporarily taken its public-facing data breach reporting database offline after discovering that an unknown entity submitted fabricated breach notifications targeting two major online platforms, VRChat and Discord, in what officials are calling a deliberate abuse of the state's breach... June 14, 2026 In "Cybersecurity News - Original News Source is cybersecuritynews.com" Managed service providers (MSPs) are increasingly popular cyberattack targets. These entities often have numerous endpoints and distributed networks that create many opportunities for adversaries seeking weaknesses to exploit. Security awareness training is just one aspect of defense efforts, but it is important since attackers directly target unsuspecting humans. What are... December 14, 2025 In "Cybersecurity News - Original News Source is cybersecuritynews.com" May 8, 2026 In "Cybersecurity News - Original News Source is krebsonsecurity.com"

NetmanageIT
Sep 7th, 2026
Mathspace discloses data breach affecting over 1 million people

Mathspace discloses data breach affecting over 1 million people BleepingComputer 07 Sep 2026

Seven West Media
Sep 7th, 2026
Mathspace: Data of more than one million people exposed during breach.

Mathspace: Data of more than one million people exposed during breach. Australians students, parents, guardians and staff have been caught up in the major cyber attack. The personal data of more than one million students, parents, guardians and school staff in Australia and New Zealand has been exposed during a cyber security attack on online learning platform Mathspace. "Unauthorised parties" accessed an internal reporting system in August to swipe names, email addresses and user IDs, among other information. Mathspace staff records were also affected. "We're truly sorry this happened and are taking steps to prevent similar breaches in the future," the company's chief technology officer Alvin Savoy said. "Protecting the information entrusted to us by students, families and schools is our responsibility." Savoy said there is no evidence the data has been "published, distributed, sold or otherwise misused". "Identity of the attacker remains unknown," he said. Savoy said customer passwords, academic records and results, single sign-on tokens and other customer authentication credentials were not exposed during the digital breach. Hackers were able to obtain administrator access to software used for internal reporting as early as August 10, before names and other data was downloaded on August 27. The breach was confirmed and the compromised system taken offline on Thursday. Authorities in Australia and New Zealand have been alerted, and state and territory education departments have been informed. "A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected," Savoy said. Former users may be impacted too, because an "account does not need to be currently active for information retained in the reporting database to be affected". Lingering threat from data breaches. Savoy said the "incident is real" but that not every message referring to it will be genuine. Mathspace said caution should be shown and that any email or call relating to the breach should be checked independently. It was only in late August that experts warned about the lingering threat Australians face in the wake of recent cyberhacks. Digidentity managing director Fred Slikker said the danger is not just confined to the weeks after a breach. "Stolen information can be retained, traded and combined with data from future incidents," Slikker said. "Australians affected by a breach therefore face a continuing risk of impersonation and identity misuse, even after they have changed their password or replaced a compromised card."

BleepingComputer
Sep 7th, 2026
Mathspace discloses data breach affecting over 1 million people.

Mathspace discloses data breach affecting over 1 million people. * September 7, 2026 * 09:05 AM * 0 Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. Founded in Sydney in 2010, Mathspace is now used by thousands of schools across Australia, New Zealand, the United States, and the United Kingdom (3,432 in Australia and 3,557 abroad according to statistics reported by the company in 2023). In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attackers gained access to the company's systems and stole personal information belonging to school staff and students, as well as their parents and guardians. "On 3 September 2026, we confirmed that unauthorised parties had accessed an internal reporting system used by Mathspace and downloaded information on students, their parents or guardians, and school staff. Mathspace staff records were also affected," Savoy said. "Attackers exploited a security vulnerability in our self-hosted installation of Metabase, software we use for internal reporting. The vulnerability allowed attackers to obtain administrator access to that system without a legitimate login." While the data theft was confirmed on September 3, the threat actors gained access to the compromised systems on August 10 and downloaded the data from Mathspace's Australian reporting database on August 27. Savoy noted that only students and school staff from Australia and New Zealand had their data stolen in the incident. Although the attackers didn't steal credentials, academic records and information, in some cases they may have been able to link some impacted accounts to their schools. "A total of 1,079,819 people were affected, comprising students, staff, and parents or guardians combined. Only people in Australia and New Zealand were affected," he added. "No academic records, learning activities, results, assessment records, passwords (hashes), authentication tokens, SSO credentials, or API credentials were exposed. The exposed data did not include records linking user accounts to their schools. However, for schools with identifiable email domains, we understand this may be possible." Savoy also warned affected students and school staff that attackers may target them using the stolen data, and advised them to watch for suspicious account-related activity, such as changes to account details and password-reset messages. Metabase breaches claimed by ShinyHunters. This breach adds to a string of other incidents impacting the Metabase instances of multiple other companies worldwide over the last month, As BleepingComputer previously reported, threat actors exploited a critical Metabase SQL injection zero-day vulnerability to breach customer instances and steal data after gaining administrator access. Trezor revealed on August 13 that attackers stole the data of nearly 14,000 customers after hacking its shipping and logistics provider, ShipMonk. On Friday, it warned that the number of affected individuals has risen to 81,000. Although Trezor has yet to attribute the attack to a specific threat actor or hacking group, BleepingComputer has learned that ShipMonk has received extortion emails from the ShinyHunters extortion gang. ShinyHunters also added Metabase to its dark web leak site on August 11. The list of affected companies in this campaign also includes laptop maker Framework and online form-building platform Tally, which have also disclosed data breaches after their Metabase instances were hijacked. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.