5 часов назад
Staff Platform Engineer (AI Agent Infrastructure & Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Staff Platform Engineer (AI Agent Infrastructure & Security) (Kubernetes/GCP/AI agents): Building and operating Maestro's secure multi-tenant control plane and per-user AI agent runtime on private GKE with an accent on identity, credential isolation, service-to-service trust, and fleet reliability. Focus on designing adversarial-workload security, governing delegated agent actions, operating 500+ isolated pods, and delivering auditable infrastructure through Terraform, observability, and progressive delivery.
Location: Remote in the US, with potential transition to a hybrid, hub-centric model based in Miami, San Francisco, or New York.
Company
is a Series B fintech company building an AI-powered WhatsApp remittance platform for Latin immigrants in the U.S., using AI, blockchain, and stablecoins for cross-border payments.
What you will do
- Architect, build, and operate Maestro's multi-tenant control plane and per-user runtime on private GKE.
- Implement Kubernetes operators, Helm charts, gVisor sandboxing, workload identity, network policies, and per-user isolation.
- Design security controls for identity separation, short-lived credentials, encrypted OAuth tokens, zero-credential egress, and least-privilege access.
- Enforce service-to-service trust with Istio mTLS, SPIFFE, signed request claims, and deny-by-exception networking.
- Operate the 500+ pod fleet with health monitoring, scale-to-zero, resource packing, SRE-grade availability, and recovery.
- Own Terraform, CI/CD, progressive delivery, OpenTelemetry, audit pipelines, human approvals, and governed agent integrations.
Requirements
- 8+ years of software or infrastructure engineering experience owning large-scale, security-critical distributed systems.
- Deep production Kubernetes experience with operators, CRDs, controller-runtime, Helm, runtime isolation, multi-tenancy, fleet operations, cloud architecture, and Terraform.
- Applied security expertise in workload identity, SPIFFE/SPIRE, service mesh mTLS, OAuth 2.0/OIDC, token exchange, KMS encryption, zero-trust, and adversarial workload threat modeling.
- Excellent Go and/or Python skills with strong systems architecture judgment.
- Production experience with OpenTelemetry, monitoring, tracing, audit design, SLOs, incident response, and cost/performance engineering.
- Hands-on experience with production LLM or agent systems, including tool calling, orchestration, human-in-the-loop controls, model routing, and guardrails.
Culture & Benefits
- Remote work environment with offices in Miami and Mexico City and a planned hybrid hub strategy.
- Initial stock options grant and annual performance bonus.
- Health, dental, and vision plans plus a 401(k) with employer match.
- Unlimited PTO and paid parental leave.
- Continuous learning opportunities and growth in an entrepreneurial environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →