EngineeringThe AI Agent Instrumentation Tax: Lessons from 1,000 Hours of Runtime Telemetry StagingRead the post →
← All roles
Full-time · W-2New York City preferred · U.S. remote possible

Founding Security Systems Engineer

Build and own the security-critical systems that authorize AI-agent actions before they execute.

Aten Security builds Thoth, a runtime authorization layer for AI agents. Thoth evaluates proposed actions before execution, can allow, block, or require human approval, and records evidence about the decision and outcome.

The core enforcement path exists. We need an engineer who can turn difficult security ideas into dependable product capabilities, integrate them into customer environments, and own the result in production.

This is a hands-on engineering role with a potential path to CTO based on demonstrated technical leadership, delivery, customer trust, and team building—not tenure or title expectations.

How we hire

High Energy. High Intelligence. Low Ego.

H₂O is Aten's standard for enthusiasm, competence, and character. We look for people who create momentum, exercise sound judgment, and put truth and the mission ahead of credit.

Read our hiring philosophy

What you will own

  • Design, build, test, deploy, and operate security-critical backend and runtime components.
  • Strengthen authorization policy, identity and instruction provenance, evidence integrity, and high-impact action attestation.
  • Build secure agent-harness components across tool execution, state, identity propagation, approval gates, sandbox boundaries, retries, timeouts, and evidence capture.
  • Maintain SDK, API, proxy, and MCP integration paths across Go, Rust, Python, and TypeScript.
  • Build model and plugin supply-chain controls, including signed manifests, artifact verification, capability boundaries, and egress policy.
  • Improve latency, availability, observability, failure handling, and tenant isolation.
  • Work directly with regulated-industry and government customers while turning recurring integration needs into durable product capabilities.
  • Write architecture decisions, runbooks, threat models, and test evidence that stand without oral context.

Milestones, not activity theater.

First week

Run Thoth locally, trace one governed action end to end, and submit a useful, verified pull request within three to five business days.

First 30 days

Own a production-relevant component with explicit security invariants, telemetry, failure behavior, and prioritized follow-up work.

First 90 days

Ship a meaningful capability with tests, observability, rollout guidance, and an operator runbook.

First 180 days

Own a major runtime-security area and lead a customer integration without creating a one-off product fork.

What we are looking for

  • A record of building and operating security-sensitive distributed systems in production.
  • Strong backend and systems fundamentals across APIs, concurrency, data modeling, networking, reliability, performance, and failure analysis.
  • Production depth in Go or Rust and the ability to become productive quickly in the other.
  • Experience with authorization, identity, policy engines, audit systems, security telemetry, developer infrastructure, or adjacent control-plane products.
  • Experience building or operating an agent harness beyond a prompt wrapper.
  • Practical production experience with AWS, Terraform, containers, observability, and incident response.
  • The ability to threat-model a design, implement it, test its invariants, and explain its limits.

Useful experience

  • MCP, agent frameworks, LLM applications, or AI security
  • Cryptographic evidence, software supply-chain security, policy as code, or workload identity
  • Financial services, healthcare, defense, or another regulated environment
  • FIPS-oriented deployments, NIST 800-171, CMMC, FedRAMP, or air-gapped systems
  • Azure identity, networking, or customer integrations

Our working stack

  • Go for core APIs and the control plane
  • Rust for endpoint binaries and selected ingestion and runtime services
  • Python for model inference, policy evaluation, and security research services
  • TypeScript, React, and Next.js for SDK and product surfaces
  • AWS, Terraform, containers, Kubernetes, PostgreSQL, MongoDB, and Redis

How we evaluate

We use a hybrid process because the job requires both independent engineering judgment and effective use of AI. You should be able to reason without a model, then use one to move faster while reviewing its output critically.

  1. 1A focused introduction call about the role and what you have built.
  2. 2A technical working session with an AI-free segment and an AI-enabled segment.
  3. 3A practical exercise grounded in security, systems judgment, and clear tradeoffs.
  4. 4Reference checks and a mutual discussion of the evaluation period and start timing.

Location and travel

New York City preferred · U.S. remote possible

Periodic travel to New York City, Washington, D.C., San Francisco, and customer sites.