2 min lesson
Ask questions that reveal seniority
Draft your own two-sentence 'why Cursor' for the security role, then self-check it: does it name the agent threat model or a specific security feature and would it survive a 'say more' follow-up?
Step 1 of 3
Ask questions that reveal seniorityInsider-only, security-flavored
“How do you currently think about indirect prompt injection reaching command execution - where's the trust boundary you most worry about?”
“What's the hardest open problem in the agent sandbox right now?”
“What does a security feature look like when engineers adopt it without being told - any recent one that landed especially well?”
“Where does security still create friction you wish it didn't?”
“Where can security reduce the most risk this year - product, cloud or the agent platform?”
“How does an opinionated security decision actually get made and stick on a flat team?”
“What's the false-positive vs miss tradeoff like on the review running across effectively every PR?”
“What classes of bug does it catch well and what still needs a human?”
Turn one question into a soft exchange of views. After they answer the sandbox question, offer your own take: “The cleanest agent sandbox I've reasoned about treats every tool call as untrusted input and scopes file writes to the workspace by default - curious whether you've landed somewhere similar.” It signals seniority and keeps the conversation two-way.
Don't assert facts about Cursor's internal security architecture you can't support - you're talking to the people who built it. If you haven't verified how their sandbox or review pipeline works, say “I'd guess” or “I'd want to confirm” and frame it as curiosity. And skip anything answered on the careers page; aim every question at something only an insider could tell you.