Senior Product Engineer, Out-of-Band Policy Engine, AI Platform

Brak informacji o wynagrodzeniu
SeniorFull-time
#447771·Dodano wczoraj·0
Źródło: Redpanda Data
Aplikuj teraz

Tech Stack / Keywords

CedarOpen Policy AgentRegoXACMLLLMGitHubAPI gatewayproxypolicy-as-code

Firma i stanowisko

Redpanda is a platform that combines streaming, SQL analytics, and intelligent connectivity with a governance layer for enterprise AI agents, enforcing governance outside the agent's data path.

Wymagania

  • 5+ years in software development building policy enforcement or authorization systems in live request paths
  • Experience with policy-as-code systems like Cedar, Open Policy Agent (Rego), XACML, or similar
  • Solid understanding of AI agent and LLM system failure modes including prompt injection and data exfiltration
  • Comfortable with adversarial testing mindset designing for attackers
  • Experience working with distributed teams and using GitHub, and being a self-starter
  • Strong verbal and written communication skills with demonstrated technical ownership

Nice to have:

  • Direct experience with Cedar or comparable policy-as-code languages
  • Experience building or operating security-critical proxies or gateways (API gateway, service mesh sidecar, egress/ingress proxy)
  • Experience designing or running red-team/adversarial evaluation harnesses, including LLM-as-judge evaluation
  • Experience with LLM guardrail, content safety, or prompt-injection defense systems
  • Experience with audit/compliance logging pipelines suitable for external security or regulatory review

Obowiązki

  • Take the out-of-band policy engine from prototype to production, integrating the Cedar-based enforcement proxy into the AI gateway
  • Build out the two-tier policy composition model and develop an authoring experience for writing, testing, and validating policies
  • Extend authorable policy operators across authorization, data exposure, and semantic gating, including deferred-approval state for human reviews
  • Record every enforcement decision as an audited, attributable record
  • Maintain and extend the adversarial certification harness with multi-turn red-team adversary, blinded judge, and deterministic leak metrics
  • Collaborate with design-partner customers in security-focused industries to understand security review requirements
  • Raise systemic challenges and impediments to management
  • Discuss strategic topics with peers to shape product roadmap and team processes
  • Track progress, assess risks, and communicate contingency and mitigation plans
Redpanda Data

Redpanda Data

15 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz