Stand out for this role — generate a tailored resume and cover letter in about a minute.
Sycamore is building the trusted agent operating system for the enterprise. We are a small, engineering-led team collaborating with Fortune 500 enterprises to design and deploy agentic apps with strong security and centralized control.
You will work on the agent-facing control plane, registry, identity, and the model gateway, shaping where and how agents operate within customer environments. This role emphasizes ensuring correctness, security, and scalable architecture.
Build the control plane that decides which agents exist, what they may do, whose authority they act under, and what they cost.
Sycamore is building the trusted agent operating system for the enterprise. Our platform helps companies build, deploy, and orchestrate agentic apps that take on real operational work, with the security and control large organizations need.
We are a small, engineering-led team working directly with Fortune 500 enterprises. We have raised $65M from Coatue and Lightspeed, along with other investors and industry leaders.
If Core AI decides what happens inside a single agent run, AI Services decides which agents exist, what each is permitted to do, whose authority it acts under, what it costs, and how it reaches the outside world. These are chokepoints: a control that exists here holds for every agent on the platform, and a mistake here is a platform-wide mistake. The work splits into two halves, and most people end up touching both.
The registry that makes an agent discoverable and describable, the identity and delegation machinery that lets it act on a person’s behalf, and the integration surface through which it reaches customer systems. The central design problem is authority: an agent needs to do real work in a customer’s environment without ever holding a credential it could leak, without exceeding what the person who asked for it could do themselves, and in a way that stays attributable afterwards. A permissive default on the integration surface is not a bug report, it is an incident.
Every model call on the platform goes through one hop we control. That hop decides which upstream serves the request, what happens when the upstream is overloaded or rate-limited, how long the caller waits, what the call costs, whose budget it lands on, and what may be recorded about it. Concentrating that in one place is what makes the guarantees possible and what makes the work demanding: the gateway must be fast, must not become a single point of failure, and must be right about cost, because an attribution bug is not a reporting inconvenience when budgets are enforced against it. We do not run our own inference. There are no GPUs and no self-hosted serving stack; the sophistication is in routing, economics, provider abstraction, and control.
Our current AI Services environment includes Python cloud services built on FastAPI and Pydantic; Go services for identity and token issuance; PostgreSQL; a self-hosted model gateway fronting multiple providers; protocol-based tool execution over MCP, including both outbound tool use and an inbound gateway with OAuth; OAuth credential vaulting for customer system integrations; durable workflows; and cloud-native deployment on Kubernetes.
We use automated tests, coding agents, traces, evaluations, and production feedback as part of everyday engineering, and we lean heavily on contract tests to keep independently deployed services honest with each other.
This is context, not a checklist. We do not require previous experience with every language, framework, provider, or tool in our stack. Comparable experience building API platforms, identity and authorization systems, integration platforms, gateways and proxies, or developer platforms is highly relevant.
Experience with cost or usage accounting where the numbers are enforced rather than merely reported is a strong signal, and so is having operated a gateway or proxy that everything else depended on. Neither is required.