2 min lesson
Turn truth-seeking into a working method with AI
Put this idea into your own words: "Tie the story to the value by name, once, at the end."
Step 1 of 2
Turn truth-seeking into a working method with AI
A security FDE at Cursor runs his whole practice on four tenets, and they're worth adopting because they translate the value into an actual workflow you can describe. Models need context the way a delegate would - be clear about the task and what good looks like, though you no longer have to spend hours on prompt engineering. Assume the model may be wrong: build the workflow around any single fact being fabricated. When in doubt, demand proof. And lean on agents to ramp into unfamiliar systems, because they search fast and there are no dumb questions.
Pushing back on a confident model is the same reflex as pushing back on a confident claim about a threat. Make it concrete: when you're not sure, say show me the code, show me the snippet, draw me the architecture diagram and check the proof yourself. That suspicion isn't cynicism - it's how you keep an accurate model of reality when one of your inputs is an LLM.
“Being suspicious of the model will come naturally to us. And it doesn't mean that it's useless. It just means that you build workflows around assuming that any individual fact you get could be wrong.”
“I cared too much about security” is the strength-in-disguise that fails on contact. So does a mistake with no real cost. The interviewer is calibrating whether you can hold an accurate model of reality under pressure, so the failure has to have actually hurt and the correction has to be yours.
Tie the story to the value by name, once, at the end. “That's what truth-seeking means to me on a security team - the threat model is only useful if I'll update it the moment reality disagrees.” Naming the value after you've earned it with the story is far stronger than claiming it up front.