Staff Platform Engineer (Runtime & Security)

felix

United States

On-site

USD 170,000 - 210,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Competitive salary
Initial stock options grant
Annual performance bonus
Health, dental, and vision plans
401(k) with employer match
Unlimited PTO
Paid parental leave
Growth opportunities in a dynamic env

Job summary

Félix is seeking a highly technical Staff Platform Engineer to own the platform and security foundations of Maestro, Félix's internal AI teammate. You will design and operate the multi-tenant control plane on private GKE, enforce strong identity, and ensure safe, scalable deployment for 500+ pods.

Responsibilities include building IaC with Terraform for GCP projects, workflows for CI/CD, and OpenTelemetry integration for end-to-end observability.

Qualifications

  • 8+ years in software/infrastructure engineering.
  • Deep production Kubernetes experience with operators/CRDs.
  • Security-focused with workload identity, IAM, and zero-trust patterns.
  • Go and/or Python expertise; ownership of services and tooling.
  • Observability and SRE fundamentals; OpenTelemetry.
  • Ability to guide engineers and align decisions across Product/Security/Leadership.

Responsibilities

  • Own the Maestro platform architecture and multi-tenant control plane on private GKE.
  • Lead end-to-end security model including identity separation and tokens.
  • Harden service-to-service trust with Istio mTLS and network policies.
  • Operate the fleet with health, scaling, and safe operational tooling for 500+ pods.
  • Own IaC and delivery with Terraform for GCP projects and CI/CD workflows.
  • Make audit a product feature by integrating OpenTelemetry across the stack.
  • Partner on agent-layer integrations (OpenClaw gateway, model routing).
  • Define platform and security best practices and mentor engineers.

Skills

Kubernetes mastery
Go
Python
Security engineering
Distributed systems
Leadership

Tools

Terraform
GCP
OpenTelemetry
Istio
CI/CD

Job description

About Us

At Félix, we are building the indispensable financial companion for Latinos in the US. We combine an AI-powered, conversational-first interface with real-time financial infrastructure to make cross-border money movement as easy as sending a text. Starting with fast, affordable remittances powered by AI and crypto rails, we are expanding into credit, savings, and wallet services to support the complete immigrant financial journey. Our ambition is to deliver a white-glove financial experience with the simplicity of a conversation to a community the traditional financial system has historically overlooked.

We are a hyper-growth Series C company, backed by over $300 million in funding from top-tier global investors, including Andreessen Horowitz, QED, Castle Island, Switch Ventures, HTwenty, Monashees, General Catalyst Customer Value Fund. This isn't just about the numbers; it's a testament to the trust our investors have in our vision and our team. Additionally, Félix was selected as an “Endeavour Entrepreneur” and was a recipient of the CrossTech Fintech Startups Award.

Joining Félix means you will be part of a team building a legacy, a company that will outlive us all. This is a rare opportunity to apply your skills to a deeply meaningful mission—serving a community that has been underserved for too long because we are obsessed with our customers. We get things done with urgency and focus, driven by extreme ownership over our impact. We collaborate without ego, fostering radical transparency and fierce loyalty so we can grow together. Because we aim for insanely great rather than just good enough, we stay insatiably curious—always experimenting, building the future today, and delivering a product that truly makes our users' lives better.

About the Role

We're looking for a highly technical Staff Platform Engineer to lead the platform and security foundations of Maestro — Félix's internal, identity-aware AI teammate. Maestro already runs at meaningful scale (500+ per-user pods on private GKE) and lives where work happens: Slack, incident rooms, and an emerging agentic intranet, acting across our toolchain (GitHub, Google Workspace, ClickUp, Notion, PagerDuty, New Relic).

The interesting problems here are not prompts or models. Once an AI teammate can open a pull request, page an engineer, or query production, the hard questions become identity, credentials, isolation, blast radius, and audit. This is a platform and security role for an agentic system — you'll own the secure, multi-tenant runtime that makes delegated AI work safe at scale.

You'll be the technical anchor for Maestro's infrastructure and security within the AI team: architecting the control plane, hardening the runtime, running the fleet, and shaping what the platform needs next as adoption grows. AI is the domain you'll operate in — deep platform and security engineering is the craft we're hiring for.

Responsibilities
  • Own the Maestro platform architecture. Design, build, and operate the multi-tenant control plane and per-user runtime on private GKE — the Kubernetes operators (CRDs/controller-runtime), Helm charts, gVisor-sandboxed pods, and per-user isolation primitives (KSA/GSA, Workload Identity, NetworkPolicy, per-user workspaces) that reconcile one user into a fully wired, isolated environment.
  • Lead the security model end to end. Treat the LLM and its tools as adversarial. Own identity separation (requester / actor / persona), JIT short-lived scoped tokens, an encrypted OAuth refresh-token vault (CMEK/Cloud KMS), zero-credential egress patterns, and a policy layer that decides whose credentials an agent uses — never the prompt.
  • Harden service-to-service trust. Enforce mesh identity with Istio mTLS + SPIFFE, signed request claims (JWS) to prevent confused-deputy issues, and deny-by-exception networking across the fleet (Istio AuthorizationPolicy + Kubernetes NetworkPolicy).
  • Operate the fleet, not the bot. Build fleet health, scale-to-zero, resource packing, and safe operational tooling for 500+ pods, with the SRE-grade availability, latency, and recovery the platform demands.
  • Own IaC and delivery. Drive Terraform for the dedicated GCP projects (VPC, private GKE, GPU/gVisor node pools, Cloud SQL, Memorystore, GSM, Artifact Registry), plus CI/CD and progressive delivery for control-plane and runtime components.
  • Make audit a product feature. Own the OpenTelemetry pipeline (logs/metrics/traces) fanning out to Cloud Logging, BigQuery, and New Relic, capturing gateway, kernel/gVisor syscall, and real-time SecOps events so "who asked, which persona acted, which credentials were used, did the user confirm?" is always answerable.
  • Enforce human-in-the-loop and guardrails. Build the approval flows for irreversible actions (writes, merges, admin ops) and the read-only, model-immutable guardrail mounts (identity, instructions, curated skills).
  • Integrate the agent layer, safely. Partner on the OpenClaw gateway, controlled tool wrappers, and model routing (Vertex AI for stakes, self-hosted Ollama for volume) — ensuring every agent capability is a governed capability, not a raw CLI or API key.
  • Set the technical direction. Define platform and security best practices, mentor senior and mid-level engineers, and map Maestro's next infrastructure needs as it scales.
Requirements
  • Experience: 8+ years in software/infrastructure engineering, with a proven track record owning large-scale, security-critical distributed systems end to end.
  • Platform & Kubernetes mastery (Staff bar): Deep, hands-on Kubernetes in production — operators/CRDs and controller-runtime, Helm, runtime isolation (gVisor or equivalent), multi-tenancy, and fleet operations at scale. Strong cloud-native architecture on GCP (or AWS/Azure), and IaC with Terraform.
  • Security & identity depth (Staff bar): Strong applied security engineering — workload identity (SPIFFE/SPIRE, Workload Identity Federation), service mesh mTLS (Istio), OAuth 2.0 / OIDC, token exchange, JIT/short-lived scoped credentials, secrets/KMS envelope encryption, least-privilege and zero-trust patterns, and threat modeling for adversarial workloads (confused-deputy, prompt injection, data exfiltration).
  • Systems & code: Excellent Go and/or Python, with deep system-architecture judgment. Comfortable owning services, operators, and tooling in production.
  • Observability & LLMOps: Production-grade monitoring, tracing, and audit design (OpenTelemetry), plus SRE fundamentals — SLOs, incident response, cost/performance engineering.
  • Ownership & leadership: High autonomy in an early-stage squad — independently diagnose bottlenecks, propose architecture, and ship it. Proven ability to grow engineers through architectural guidance, not just code review, and to align technical decisions with stakeholders across Product, Security, and Leadership.
  • Nice to Have — AI Exposure: Prior hands-on experience with agentic systems or LLM infrastructure is a plus, but strong platform and security fundamentals take priority.
  • These are the applicable requisites, although equivalent competencies in any of the above will also be considered.
What We Offer
  • Competitive salary
  • Initial stock options grant
  • Annual performance bonus
  • Health, dental, and vision plans
  • 401(k) with employer match
  • Continuous learning opportunities
  • Unlimited PTO
  • Paid parental leave
  • Empowering opportunities for growth in a dynamic entrepreneurial environment
What We Offer
  • Competitive salary
  • Initial stock options grant
  • Annual performance bonus
  • Health, dental, and vision plans
  • Continuous learning opportunities
  • 401(k) with employer match
  • Unlimited PTO
  • Paid parental leave
  • Empowering opportunities for growth in a dynamic entrepreneurial environment
Equal Opportunity Employer

At Félix, we are committed to providing equal employment opportunities to all qualified employees and applicants without regard to race, religion, nationality, sex, sexual orientation, gender identity, age, or disability. This policy applies to all terms and conditions of employment, including recruitment, hiring, placement, promotion, training, compensation, benefits, and termination.

Want to learn more about our privacy practices? Check out our Privacy Policy.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Platform Engineer
Staff Platform Engineer

felix • New York (NY)

On-site
USD 180,000 - 240,000
Competitive salary
Initial stock options grant
Annual performance bonus
+6
Staff Platform Engineer
Staff Platform Engineer

felix • United States

On-site
USD 180,000 - 260,000
Competitive salary
Stock options
Annual performance bonus
+5
Senior Site Reliability Engineer
Senior Site Reliability Engineer

Félix • Miami (FL)

On-site
MXN 2,042,000 - 3,063,000
Competitive salary
Stock options
Annual performance bonus
+6
Senior Software Engineer (Fintech Platform)
Senior Software Engineer (Fintech Platform)

Worky • Seattle (WA)

On-site
USD 140,000 - 190,000
Stock options
Annual performance bonus
Health plans
+5
Staff Software Engineer (Platform Core Team)
Staff Software Engineer (Platform Core Team)

Worky • Seattle (WA)

Hybrid
USD 175,000 - 220,000
Hybrid working model
Stock options
Annual performance bonus
+4
Senior Software Engineer (Fintech Platform)
Senior Software Engineer (Fintech Platform)

Felix • Seattle (WA)

On-site
USD 140,000 - 190,000
Initial stock options grant
Annual performance bonus
Health, dental, and vision plans
+5
AI Product Lead
AI Product Lead

Félix • New York (NY)

On-site
USD 180,000 - 250,000
Stock options
Annual bonus
Health insurance
+4
AI Product Lead
AI Product Lead

Félix • San Francisco (CA)

On-site
USD 180,000 - 250,000
Stock options
Annual bonus
Health, dental, vision plans
+3
Head of Fintech Partnerships
Head of Fintech Partnerships

Félix • San Francisco (CA)

On-site
USD 170,000 - 250,000
Initial stock options grant
Annual performance bonus
Health, dental, and vision plans
+4
Semi-Senior Software Engineer
Semi-Senior Software Engineer

Worky • Seattle (WA)

Hybrid
USD 120,000 - 160,000
Initial stock options grant
Annual performance bonus
Health, dental, and vision plans
+5