AppSec Jobs
← Back to all jobs

Cohere

Senior Software Engineer, Secure Agents

TorontoWebsite

Full details on LinkedIn

The complete job description, requirements, and application details are available on the original posting.


About Cohere

Cohere is an enterprise artificial intelligence platform based in Toronto, Canada, founded in 2019. The company specializes in building foundational models and AI solutions that help organizations automate processes, enhance productivity, and turn data into actionable insights. Cohere serves various sectors, including financial services, healthcare, manufacturing, energy, and the public sector. Cohere offers a range of products, including generative models for multilingual content generation, retrieval and search models for organizing large datasets, and enterprise workspace solutions designed for secure AI applications. Their healthcare-specific platform, Cohere Health, provides clinical intelligence solutions for healthcare payers. The company emphasizes multilingual capabilities, enterprise-grade security, and a unified platform that combines generative and retrieval AI, making it well-suited for organizations with specific data and compliance needs. Cohere's notable customers include Fujitsu, Oracle, and the Royal Bank of Canada.

Industry

information technology & services

Employees

850

99 engineers

Revenue

$100M

Website

Visit →

Security at Cohere

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

Cohere's AppSec philosophy is driven by a "security-first culture"and a "defense-in-depth"risk approach, aiming to be the "leading security-first enterprise AI company."The final risk authority is "delegated by Cohere's CEO to Cohere's Chief Scientist."They conduct "annual third-party audits and penetration tests"and maintain a "Bug Bounty program."Their approach involves integrating security "throughout the software development lifecycle"and performing "robust vulnerability management testing"before major model releases. Explicit language describing "developer-first"versus "gatekeeping"is not publicly available.

Security Team

  • An information security team has been established at Cohere to govern cybersecurity, with executive risk decision-making "delegated by Cohere's CEO to Cohere's Chief Scientist."Key public-facing leaders were not found in the scraped sources.
  • The company size is estimated at "201-500 employees."Active AppSec-related job postings, such as "Senior Security Engineer"and "Senior Software Engineer, Secure Agents,"indicate common skill patterns like "vulnerability management, SAST, DAST"and a focus on being "empathetic to developer concerns."Public evidence of named AppSec leaders and direct reporting chains was not found.

Key Initiatives

  • Cohere's AppSec initiatives include conducting "annual third-party audits and penetration tests"and operating a "Bug Bounty program."Vulnerability management is a key security operation function, and they implement "Secure Product Lifecycle controls,"encompassing security requirements gathering, threat modeling, code reviews, penetration testing, and bug bounty programs. They also "Integrate security into our applications throughout the software development lifecycle"as a shift-left practice.
  • No direct public evidence was found for a "Security Champions Program,"explicit recent initiatives (last 6 months), or specific SLA/MTTR statements.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.