- As a Senior Backend Engineer on the Defensive Agent team, you’ll build the platform that NodeZero’s defensive agents run on. Our AI researchers define what these agents should reason about, you build the systems that make that work in production, across thousands of customer tenants, without breaking anything
- That means real distributed systems problems, not glue code. They execute inside customer environments under tight isolation, credential, and egress constraints
- And when an agent proposes a change in production, the platform has to be able to simulate it, stage it, gate it on approval, roll it back, and prove after the fact exactly what happened and on whose authority
- This is a platform role. You’ll own the runtime, the tool layer, the orchestration, the connector framework, and the observability that makes agent behavior debuggable
- You’ll work closely with our AI researchers, but you are not being hired to tune prompts — you are being hired to build the substrate that makes their work shippable and safe
- Build and own the agent execution runtime: durable, resumable, long-running workflows with checkpointing, idempotent steps, cancellation, and timeouts at both the step and run level
- Design and implement the tool layer that agents act through — a registry with versioning, schema validation, per-tenant enablement, and authorization enforced server-side rather than by the model
- Build the connector framework for third-party security control planes (EDR, firewall, identity, SIEM, cloud IAM)
- Implement the safe-change pipeline: dry-run and simulation, blast-radius classification, approval gates for high-impact actions, staged rollout, rollback, and an immutable per-tenant audit trail
- Extend NodeZero’s tenant isolation model to agents that take write actions, covering execution boundaries, egress control, quotas, and cross-tenant leakage in caches, indexes, and logs
- Develop core product features in ETL and GraphQL to support data processing and retrieval for agent context, run history, and remediation state
- Build the ETL pipelines that turn pentest and remediation outcomes into the datasets our researchers train and evaluate against
- Instrument everything. Distributed tracing across an agent run, cost and token accounting per tenant, and the tooling to answer “why did the agent do that” without guessing
- Partner with AI researchers, attack engineers, and product to take capabilities from prototype to production, and feed platform constraints back into research direction early rather than late
Benefits
- Growth Opportunities: Be part of a dynamic and growing team with numerous career advancement opportunities
- Innovation-Driven Culture: Work in a collaborative environment that encourages creativity and out-of-the-box thinking
- Flexible Work Environment: Enjoy the convenience and work-life balance that comes with remote work
- Inclusive and Diverse Team: We value diversity and promote an inclusive culture where everyone can thrive
7+ yrs professional software engineering experience using modern object-oriented or functional languages (Python, Go, Scala, C++, TypeScript, etc)Expert proficiency in SQLBachelor’s Degree in Computer Science, Computer Engineering or related fieldA track record of shipping and operating production services, including on-call ownershipDemonstrated experience designing and operating distributed systems in production: asynchronous workflows, queues, retries, idempotency, and partial failureExperience building applications on cloud computing platforms such as AWS, Azure, GCP, using container technologies such as Docker and KubernetesExperience with a durable execution (such as Temporal) or workflow engine or having built equivalent checkpointing yourselfExperience building agentic or LLM-backed systems in productionExperience building multi-tenant platforms with hard isolation requirements, workload identity, and short-lived credential brokeringExperience integrating a long tail of third-party APIs behind a normalized abstractionFamiliarity with security control planes and their APIs — EDR (CrowdStrike, SentinelOne, Microsoft Defender), firewalls, SIEM, cloud IAMExperience with database architectures including relational (PostgreSQL) and graph (Neo4j), and experience building GraphQL backendsExperience with observability tooling (Datadog, Prometheus, Grafana) and distributed tracingAwareness of prompt injection and untrusted-input handling in systems where an agent consumes data from the environment it operates in