We use essential cookies

Please Accept our Privacy Policy

Senior/Staff Founding Full-Stack Engineer, Agent Systems

Thomas Talent Network

San Francisco, CA • 10/3/2026

Job Description

Job Description

Our client is building AI coworkers for IT teams: a security-focused product where an agent registers as a governed identity in a customer's directory, requests scoped access per task, escalates for human approval, and drives systems it was never given an API for.

About the Role:

This is a backend- and systems-heavy founding engineering role where "full-stack" means owning the product and system end-to-end. You'll build the workflow engine for long-running human and agent work (durable state, retries, idempotency, approvals, replay, compensation, auditability), and design identity and authorization for humans, services, and agents (principals, delegation, scoped sessions, tenant isolation, traceable authority).

You'll build a versioned policy engine for who or what can perform which action on which resource under what context; own secure storage and use of customer production keys, OAuth tokens, and admin credentials (isolation, rotation, ephemeral injection, revocation, blast-radius containment); own the boundary between probabilistic model behavior and deterministic execution (validation, evals, release gates); build isolated virtual environments and dev boxes for agents (reproducible state, observability, resource controls, safe teardown); and ship the interfaces and APIs to author, approve, inspect, debug, and operate these systems in production.

What You'll Own:

- The workflow engine for long-running human + agent work: durable state, retries, idempotency, approvals, replay, compensation, auditability

- Identity and authorization for humans, services, and agents: principals, delegation, scoped sessions, tenant isolation, traceable authority

- A versioned policy engine (who/what can do which action on which resource, under what context)

- Secure storage and use of customer keys, OAuth tokens, and admin credentials: isolation, rotation, ephemeral injection, revocation, blast-radius containment

- The probabilistic-to-deterministic execution boundary: validation, evals, release gates

- Isolated virtual environments and dev boxes for agents: reproducible state, observability, resource controls, safe teardown

- The interfaces and APIs to author, approve, inspect, debug, and operate these systems in production

Requirements - Must-Have:

1. Has designed and operated complex production systems, and can explain what broke, how they recovered, and what changed

2. Strongest in backend and systems architecture, but can work across frontend, data, infrastructure, and product

3. Depth in one or more of: IAM/authorization, policy systems, workflow orchestration, security, multi-tenant SaaS, agent infrastructure, MDM, ITSM, enterprise integrations, or virtualized execution

4. Thinks in invariants, threat models, failure modes, and user outcomes

5. Works well from ambiguity and moves quickly without trading away correctness, security, or operability

6. Able to work in person in SF, Monday to Friday, at startup intensity

Strong candidates may also:

- Have built permission graphs, non-human identity, secrets platforms, privileged access, or delegated authorization

- Have built workflow runtimes, reconciliation systems, sandboxes, simulation/evaluation infrastructure, or developer environments

- Have been an early engineer who owned architecture, production, and customer-facing product

Job Details:

- Experience: 4+ Years

- Equity: 1% - 2%

- Visa Sponsorship: H-1B, O-1, OPT

- Employment Type: Full-Time

- Work Type: In-person

Benefits & Perks:

- Meals in office

- Health insurance

- Unlimited PTO