Senior/Staff Founding Full-Stack Engineer, Agent Systems

Thomas Talent Network, LLC

San Francisco (CA)

On-site

USD 180,000 - 260,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Meals in office
Health insurance
Unlimited PTO

Job summary

Our client in San Francisco is hiring a founding backend engineer to own end-to-end system design for an AI coworker platform. You will build a durable workflow engine, secure identity models, and policy-driven authorization across human, service, and agent interactions.

You will also implement isolated environments for agents, plus scalable APIs to manage, audit, and operate production systems with strong emphasis on security and reliability.

Qualifications

  • Designed and operated complex production systems with clear incident history.
  • Backend and systems architecture expertise, with cross-domain collaboration.
  • Depth in IAM/authorization, policy systems, workflow orchestration, or multi-tenant SaaS.
  • Thinks in invariants, threat models, failure modes, and user outcomes.
  • Able to work through ambiguity without sacrificing security or operability.
  • Willingness to work in person in SF, Monday to Friday, startup tempo.

Responsibilities

  • Own the workflow engine for long-running human and agent work: durable state, retries, idempotency, approvals, replay, compensation, auditability.
  • Design identity and authorization for humans, services, and agents: principals, delegation, scoped sessions, tenant isolation, traceable authority.
  • Build a versioned policy engine: who/what can do which action on which resource, under what context.
  • Secure storage and use of customer keys, OAuth tokens, and admin credentials: isolation, rotation, episodic injection, revocation, blast-radius containment.
  • Define the boundary between probabilistic model behavior and deterministic execution: validation, evals, release gates.
  • Create isolated virtual environments and dev boxes for agents: reproducible state, observability, resource controls, safe teardown.
  • Provide interfaces and APIs to author, approve, inspect, debug, and operate these systems in production.

Job description

Our client is building AI coworkers for IT teams: a security-focused product where an agent registers as a governed identity in a customer's directory, requests scoped access per task, escalates for human approval, and drives systems it was never given an API for.


About the Role:

This is a backend- and systems-heavy founding engineering role where \"full-stack\" means owning the product and system end-to-end. You'll build the workflow engine for long-running human and agent work (durable state, retries, idempotency, approvals, replay, compensation, auditability), and design identity and authorization for humans, services, and agents (principals, delegation, scoped sessions, tenant isolation, traceable authority).


You’ll build a versioned policy engine for who or what can perform which action on which resource under what context; own secure storage and use of customer production keys, OAuth tokens, and admin credentials (isolation, rotation, episodic injection, revocation, blast-radius containment); own the boundary between probabilistic model behavior and deterministic execution (validation, evals, release gates); build isolated virtual environments and dev boxes for agents (reproducible state, observability, resource controls, safe teardown); and ship the interfaces and APIs to author, approve, inspect, debug, and operate these systems in production.


What You'll Own:


  • The workflow engine for long-running human + agent work: durable state, retries, idempotency, approvals, replay, compensation, auditability

  • Identity and authorization for humans, services, and agents: principals, delegation, scoped sessions, tenant isolation, traceable authority

  • A versioned policy engine (who/what can do which action on which resource, under what context)

  • Secure storage and use of customer keys, OAuth tokens, and admin credentials: isolation, rotation, episodic injection, revocation, blast-radius containment

  • The probabilistic-to-deterministic execution boundary: validation, evals, release gates

  • Isolated virtual environments and dev boxes for agents: reproducible state, observability, resource controls, safe teardown

  • The interfaces and APIs to author, approve, inspect, debug, and operate these systems in production


Requirements - Must-Have:


  1. Has designed and operated complex production systems, and can explain what broke, how they recovered, and what changed

  2. Strongest in backend and systems architecture, but can work across frontend, data, infrastructure, and product

  3. Depth in one or more of: IAM/authorization, policy systems, workflow orchestration, security, multi-tenant SaaS, agent infrastructure, MDM, ITSM, enterprise integrations, or virtualized execution

  4. Thinks in invariants, threat models, failure modes, and user outcomes

  5. Works well from ambiguity and moves quickly without trading away correctness, security, or operability

  6. Able to work in person in SF, Monday to Friday, at startup intensity


Strong candidates may also:


  • Have built permission graphs, non-human identity, secrets platforms, privileged access, or delegated authorization

  • Have built workflow runtimes, reconciliation systems, sandboxes, simulation/evaluation infrastructure, or developer environments

  • Have been an early engineer who owned architecture, production, and customer-facing product


Job Details:


  • Experience: 4+ Years

  • Equity: 1% - 2%

  • Visa Sponsorship: H-1B, O-1, OPT

  • Employment Type: Full-Time

  • Work Type: In-person


Benefits & Perks:


  • Meals in office

  • Health insurance

  • Unlimited PTO


Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior/Staff Founding Full-Stack Engineer, Agent Systems
Senior/Staff Founding Full-Stack Engineer, Agent Systems

Thomas Talent Network • San Francisco (CA)

On-site
USD 200,000 - 300,000
Forward Deployed Engineer
Forward Deployed Engineer

Aionia Group • San Francisco (CA)

On-site
USD 200,000 - 325,000
Full-Stack Engineer
Full-Stack Engineer

Ersilia • San Francisco (CA)

On-site
USD 200,000 - 400,000
Platform Engineer
Platform Engineer

Docflow Labs Inc • Los Angeles (CA)

On-site
USD 150,000 - 185,000
Health insurance
Founding Full-Stack Engineer — AI Security Platform
Founding Full-Stack Engineer — AI Security Platform

Thomas Talent Network • San Francisco (CA)

On-site
USD 200,000 - 300,000
Software Engineer
Software Engineer

Worky • San Francisco (CA)

On-site
USD 180,000 - 250,000
Competitive equity
Relocation package
Unlimited PTO
+2
Full Stack Engineer
Full Stack Engineer

Worky • San Francisco (CA)

On-site
USD 150,000 - 275,000
On-site in San Francisco
Forward Deployed AI Engineer (TypeScript) - Remote - USA
Forward Deployed AI Engineer (TypeScript) - Remote - USA

FullStack • Town of Florida (NY)

Remote
USD 120,000 - 190,000
Competitive salary
Paid time off
Remote work
+5
Founding Engineer - Applied AI
Founding Engineer - Applied AI

Ersilia • San Francisco (CA)

On-site
USD 170,000 - 210,000
Unlimited PTO
Health insurance
Visa sponsorship
Full-Stack Engineer, Agent Management Platform
Full-Stack Engineer, Agent Management Platform

crewAI, Inc. • San Francisco (CA), Northern (KY)

On-site
USD 180,000 - 240,000