We're hiring an Enterprise Platform Engineer to build the foundational systems that make Cursor ready for the world's largest engineering organizations
Today we have basic organizations, simple IAM primitives, early audit logs, analytics APIs, and admin APIs — but enterprise customers need much more. You will design and build the platform layer that powers organization management, access control, compliance, and administrative tooling across Cursor's product surface. This is a deeply technical IC role focused on building correct, secure, and scalable enterprise infrastructure — not gluing together vendor SDKs
Build and evolve our organization management system — multi-level org structures, groups, roles, lifecycle, and provisioning via SCIM, so admins can manage thousands of seats without friction
Design and implement RBAC with fine-grained roles, permissions, and resource scopes that cover organizations, teams, agents, and other resources — balancing security with developer ergonomics
Extend enterprise settings and policies — org-wide defaults, security policies (allowed models, MCPs, Tools, network restrictions), and configuration inheritance across different products
Deepen our audit logging infrastructure — comprehensive, queryable, tamper-evident audit trails that satisfy customer-specific compliance requirements
Build admin APIs and internal tooling that enterprise admins, customer success, and sales engineering depend on to manage organizations, investigate access issues, and onboard large accounts
Ship compliance features end-to-end — SSO enforcement, session management, allowlisting, data analytics, and the controls that procurement and security teams require before signing
Partner with product, security, and infrastructure teams to define enterprise platform abstractions that scale across the product without slowing down feature development
You will own organization management, RBAC and authorization, enterprise settings and policies, audit logs, admin APIs, and compliance-related platform features. You will be a technical authority on how Cursor models identity, access, and governance for enterprise customers
You will not own SSO/IdP integration at the protocol level (we use WorkOS) or billing and payments
Security and correctness are part of the job, but the goal is to build systems with enough rigor and observability that enterprise operations are boring — not to manually triage every access control edge case