Senior Runtime Security Engineer

Xage Security

Palo Alto (CA)

On-site

USD 140,000 - 170,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity

Job summary

Xage Security, headquartered in Palo Alto, CA, seeks a Senior Runtime Security & Systems Engineer to build the runtime security layer powering Agent Sentry, the enforcement plane of our Zero Trust AI Gateway platform.

You will design OS-level interception, runtime monitoring, sandboxing, identity controls, and tamper-resistant audit infrastructure to secure AI agents across Linux, macOS, and Windows environments.

Qualifications

  • 3-5+ years building production security, systems, or infrastructure software.
  • Strong programming skills in Go or C/C++ for high-performance security-critical systems.
  • Experience with OS internals, runtime security, kernel instrumentation, security telemetry, sandboxing, or container isolation.
  • Strong understanding of host security, privilege escalation, runtime exploitation, and endpoint threats.
  • Experience with eBPF, Linux kernel development, Windows Kernel, or macOS security frameworks.

Responsibilities

  • Build runtime monitoring across Linux, macOS, and Windows using eBPF, Endpoint Security Framework, ETW, and OS-level APIs.
  • Capture and analyze process execution, filesystem activity, network events, and agent behaviors.
  • Develop secure agent isolation using containers, OS-native sandboxes, and lightweight virtualization (containerd, runc, Firecracker, Wasm).
  • Design runtime controls to prevent unauthorized agent actions and reduce security risks.
  • Build agent identity infrastructure supporting registration, authentication, cryptographic attestation, short-lived credentials, and automated credential rotation.
  • Develop lifecycle governance for agent onboarding, authorization, monitoring, and decommissioning.
  • Integrate runtime telemetry with policy engines to enable real-time access decisions, inline enforcement, and automated containment.

Skills

Go
C/C++
OS internals
Runtime security

Tools

eBPF
Kernel instrumentation
Security telemetry
Container isolation

Job description

Cyberattacks on critical infrastructure, government, and private enterprises are at an all time high – and only growing more urgent by the day. Xage is a global leader in zero trust access and protection at the forefront of solving this pressing issue. We are pioneering a secure tomorrow by empowering organizations worldwide to connect anyone to anything, while delivering unparalleled defense against every cyber threat.

We have built tremendous momentum across governments and commercial enterprises around the world, and it’s just the beginning. Recognized by Forbes as one of America’s Best Startup Employers, Xage prioritizes creativity, collaboration, and innovation in pursuit of our mission. We are headquartered in Palo Alto, CA and have global teams across North America and EMEA.

We’re passionate about solving problems that have positive, real-world consequences for the lives of everyday people. We hope you’ll join us in the fight against cyberattacks and safeguarding critical infrastructure.

About the Role

We are seeking a Senior Runtime Security & Systems Engineer to build the runtime security layer powering Agent Sentry, the enforcement plane of our Zero Trust AI Gateway platform.

While traditional AI security focuses on inspecting prompts and responses, Agent Sentry provides runtime visibility and control for autonomous AI agents wherever they execute—across Linux, macOS, and Windows environments. It monitors and governs agent activity including prompts, tool calls, API requests, generated outputs, filesystem access, process execution, shell/PowerShell activity, and agent-to-agent communications.

In this role, you will design and productionize OS-level interception, runtime monitoring, sandboxing, identity controls, and tamper-resistant audit infrastructure to secure AI agents operating across enterprise environments.

You will work across systems engineering, operating system security, distributed infrastructure, and zero-trust architecture to build the foundation for secure autonomous AI deployments.

Key Responsibilities

Cross-Platform Runtime Security & Sandboxing

  • Build runtime monitoring and interception across Linux, macOS, and Windows using technologies such as eBPF, Endpoint Security Framework, ETW, and OS-level security APIs.
  • Capture and analyze process execution, filesystem activity, network events, and agent behaviors.
  • Develop secure agent isolation using containers, OS-native sandboxes, and lightweight virtualization (containerd, runc, Firecracker, Wasm).
  • Design runtime controls to prevent unauthorized agent actions and reduce security risks.

Agent Identity, Lifecycle & Policy Enforcement

  • Build agent identity infrastructure supporting registration, authentication, cryptographic attestation, short-lived credentials, and automated credential rotation.
  • Develop lifecycle governance for agent onboarding, authorization, monitoring, and decommissioning.
  • Integrate runtime telemetry with policy engines to enable real-time access decisions, inline enforcement, and automated containment.

Required Qualifications & Expertise

  • 3-5+ years building production security, systems, or infrastructure software.
  • Strong programming skills in Go, C/C++ with experience developing high-performance, security-critical systems.
  • Experience with OS internals, runtime security, kernel instrumentation, security telemetry, sandboxing, or container isolation.
  • Strong understanding of host security, privilege escalation, runtime exploitation, and endpoint threats.
  • Experience with eBPF, Linux kernel development, Windows Kernel, or macOS security frameworks.

Preferred Qualifications

  • Experience building EDR/XDR, runtime security, endpoint protection, or cloud workload security platforms.
  • Experience securing AI agents, LLM applications, or autonomous systems.
  • Familiarity with Kubernetes security, service mesh, and cloud-native security.
  • Familiarity with zero-trust architectures, identity systems, PKI, mTLS, SPIFFE/SPIRE, OAuth/OIDC, and credential management.
  • Salary Range: $140,000 – $170,000 p/yr + Equity
  • We will process visa transfers and immigration
  • Work with founders and executives closely and participate in all aspects of company building
  • Early stage opportunity in a massive sized market with proven traction and growing rapidly
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Runtime Security Engineer for AI Agents
Senior Runtime Security Engineer for AI Agents

Xage Security • Palo Alto (CA)

On-site
USD 140,000 - 170,000
Equity
Senior Software Engineer – Zero Trust for Agentic AI
Senior Software Engineer – Zero Trust for Agentic AI

xage, inc • Palo Alto (CA)

On-site
USD 140,000 - 200,000
Health, dental, and vision coverage
Visa transfer and immigration support
Opportunity to work closely with executive leadership
Software Engineer – Backend
Software Engineer – Backend

xage, inc • Palo Alto (CA)

On-site
Security-Focused Full Stack Engineer — IAM & Zero Trust, Equity
Security-Focused Full Stack Engineer — IAM & Zero Trust, Equity

xage, inc • Palo Alto (CA)

On-site
Zero-Trust Backend Engineer (Go) for Secure Edge Systems
Zero-Trust Backend Engineer (Go) for Secure Edge Systems

xage, inc • Palo Alto (CA)

On-site
Senior Engineer, Secure Remote Access & Zero Trust
Senior Engineer, Secure Remote Access & Zero Trust

xage, inc • Palo Alto (CA)

Remote
Full Stack Engineer
Full Stack Engineer

xage, inc • Palo Alto (CA)

On-site
Early in Career Software Engineer (Security Products)
Early in Career Software Engineer (Security Products)

xage, inc • Palo Alto (CA)

On-site
USD 100,000 - 115,000
Equity
Visa transfers
Product Security Engineer – Red Team/Pen Testing
Product Security Engineer – Red Team/Pen Testing

xage, inc • Palo Alto (CA)

On-site
USD 140,000 - 170,000
Visa transfers and immigration
Product Safety Engineer (Red Team)
Product Safety Engineer (Red Team)

Xage Security • Palo Alto (CA)

On-site
USD 170,000 - 200,000