Remote job
Founding Security Systems Engineer
Job details
About this role
Role overview This is a founding-level security engineering role on a small team building a runtime authorization layer for AI agents. The platform evaluates proposed agent actions before execution, choosing to allow, block, or require human approval, and records evidence about the decision and outcome. The work is hands-on across backend, runtime, SDKs, and integrations, with direct exposure to regulated-industry and government customers and a potential path to CTO based on demonstrated leadership.
Responsibilities - Design, build, test, deploy, and operate security-critical backend and runtime components that enforce agent authorization in production - Strengthen authorization policy, identity and instruction provenance, evidence integrity, and high-impact action attestation - Build secure agent-harness components across tool execution, state, identity propagation, approval gates, sandbox boundaries, retries, timeouts, and evidence capture - Maintain SDK, API, proxy, and MCP integration paths across Go, Rust, Python, and TypeScript - Build model and plugin supply-chain controls, including signed manifests, artifact verification, capability boundaries, and egress policy - Improve latency, availability, observability, failure handling, and tenant isolation - Work directly with regulated-industry and government customers, turning recurring integration needs into durable product capabilities - Produce architecture decision records, runbooks, threat models, and test evidence that stand without oral context
Requirements - A track record of designing, building, and operating security-sensitive production systems and verifying their critical properties - Strong systems judgement and the ability to make and explain difficult security tradeoffs - Comfort working in a small, fast-moving founding team, with strong opinions and the ability to push back constructively - Proficiency across at least one of Go, Rust, Python, or TypeScript for backend and runtime work - Experience with authorization, identity, isolation, and audit logging concepts applied to production systems - Excellent written communication, including the ability to author architecture decisions, threat models, and runbooks
Nice to have - Background in runtime security, sandboxing, or agent and tool-execution frameworks - Familiarity with MCP, signed manifests, or supply-chain controls for models and plugins - Experience working with regulated or government customers and their compliance requirements
Benefits and work setup - Full-time role based in New York City, San Francisco Bay Area, or remote within the U.S. and Canada - Periodic travel to NYC, Washington D.C., San Francisco, and customer locations for team offsites, industry events, and customer engagements - Hiring process: an introduction call about the role, a technical working session with both AI-free and AI-enabled segments, a practical exercise grounded in security and systems judgement, and reference checks - Hiring timing depends on funding and funded customer work; applications are reviewed as they arrive