Senior Product Engineer, Out-of-Band Policy Engine, AI Platform
Brak informacji o wynagrodzeniu
SeniorFull-time
#447771·Dodano wczoraj·0
Źródło: Redpanda DataTech Stack / Keywords
CedarOpen Policy AgentRegoXACMLLLMGitHubAPI gatewayproxypolicy-as-code
Firma i stanowisko
Redpanda is a platform that combines streaming, SQL analytics, and intelligent connectivity with a governance layer for enterprise AI agents, enforcing governance outside the agent's data path.
Wymagania
- 5+ years in software development building policy enforcement or authorization systems in live request paths
- Experience with policy-as-code systems like Cedar, Open Policy Agent (Rego), XACML, or similar
- Solid understanding of AI agent and LLM system failure modes including prompt injection and data exfiltration
- Comfortable with adversarial testing mindset designing for attackers
- Experience working with distributed teams and using GitHub, and being a self-starter
- Strong verbal and written communication skills with demonstrated technical ownership
Nice to have:
- Direct experience with Cedar or comparable policy-as-code languages
- Experience building or operating security-critical proxies or gateways (API gateway, service mesh sidecar, egress/ingress proxy)
- Experience designing or running red-team/adversarial evaluation harnesses, including LLM-as-judge evaluation
- Experience with LLM guardrail, content safety, or prompt-injection defense systems
- Experience with audit/compliance logging pipelines suitable for external security or regulatory review
Obowiązki
- Take the out-of-band policy engine from prototype to production, integrating the Cedar-based enforcement proxy into the AI gateway
- Build out the two-tier policy composition model and develop an authoring experience for writing, testing, and validating policies
- Extend authorable policy operators across authorization, data exposure, and semantic gating, including deferred-approval state for human reviews
- Record every enforcement decision as an audited, attributable record
- Maintain and extend the adversarial certification harness with multi-turn red-team adversary, blinded judge, and deterministic leak metrics
- Collaborate with design-partner customers in security-focused industries to understand security review requirements
- Raise systemic challenges and impediments to management
- Discuss strategic topics with peers to shape product roadmap and team processes
- Track progress, assess risks, and communicate contingency and mitigation plans
Redpanda Data
15 aktywnych ofert