Jobleads-US
San Francisco / Global
You have blocked notifications
Oops! You have blocked notifications. Click here for more info
You have blocked notifications, please check your browser settings.
You're currently subscribed to job notifications
Subscribe to notifications
You will no longer receive notifications
San Francisco / Global
Our client is building AI coworkers for IT teams: a security-focused product where an agent registers as a governed identity in a customer's directory, requests scoped access per task, escalates for human approval, and drives systems it was never given an API for.
About the Role: This is a backend- and systems-heavy founding engineering role where \"full-stack\" means owning the product and system end-to-end. You'll build the workflow engine for long-running human and agent work (durable state, retries, idempotency, approvals, replay, compensation, auditability), and design identity and authorization for humans, services, and agents (principals, delegation, scoped sessions, tenant isolation, traceable authority).
You’ll build a versioned policy engine for who or what can perform which action on which resource under what context; own secure storage and use of customer production keys, OAuth tokens, and admin credentials (isolation, rotation, episodic injection, revocation, blast-radius containment); own the boundary between probabilistic model behavior and deterministic execution (validation, evals, release gates); build isolated virtual environments and dev boxes for agents (reproducible state, observability, resource controls, safe teardown); and ship the interfaces and APIs to author, approve, inspect, debug, and operate these systems in production.
What You'll Own: The workflow engine for long-running human + agent work: durable state, retries, idempotency, approvals, replay, compensation, auditability
Identity and authorization for humans, services, and agents: principals, delegation, scoped sessions, tenant isolation, traceable authority
A versioned policy engine (who/what can do which action on which resource, under what context)
Secure storage and use of customer keys, OAuth tokens, and admin credentials: isolation, rotation, episodic injection, revocation, blast-radius containment
The probabilistic-to-deterministic execution boundary: validation, evals, release gates
Isolated virtual environments and dev boxes for agents: reproducible state, observability, resource controls, safe teardown
The interfaces and APIs to author, approve, inspect, debug, and operate these systems in production
Requirements - Must-Have: Has designed and operated complex production systems, and can explain what broke, how they recovered, and what changed
Strongest in backend and systems architecture, but can work across frontend, data, infrastructure, and product
Depth in one or more of: IAM/authorization, policy systems, workflow orchestration, security, multi-tenant SaaS, agent infrastructure, MDM, ITSM, enterprise integrations, or virtualized execution
Thinks in invariants, threat models, failure modes, and user outcomes
Works well from ambiguity and moves quickly without trading away correctness, security, or operability
Able to work in person in SF, Monday to Friday, at startup intensity
Strong candidates may also: Have built permission graphs, non-human identity, secrets platforms, privileged access, or delegated authorization
Have built workflow runtimes, reconciliation systems, sandboxes, simulation/evaluation infrastructure, or developer environments
Have been an early engineer who owned architecture, production, and customer-facing product
Job Details: Experience: 4+ Years
Equity: 1% - 2%
Visa Sponsorship: H-1B, O-1, OPT
Employment Type: Full-Time
Work Type: In-person
Benefits & Perks: Meals in office
Health insurance
Unlimited PTO
#J-18808-Ljbffr
San Francisco / Global
San Francisco / Global
Oakland / Global
San Francisco / Global
San Francisco / Global
San Francisco / Global