Skip to main content
Posted August 23, 2026

Senior/Staff Founding Full-Stack Engineer, Agent Systems

Thomas Talent Network
San Francisco, CA, US Full Time

Job Description

Job Description

Confidential client — a Pre-seed startup (1-10 employees) building AI coworkers for IT teams: a security-focused product where an agent registers as a governed identity in a customer's directory, requests scoped access per task, escalates for human approval, and drives systems it was never given an API for. Raised a $6M seed round, backed by a strong bench of operator-angels from across IT and security. Several design partners today and a founding team of three. Full-Time, In-person, San Francisco, CA. Experience: 4+ years. Salary: $200,000-$300,000/yr. Visa sponsorship: H-1B, O-1, OPT.

About the Role: This is a backend- and systems-heavy founding engineering role where "full-stack" means owning the product and system end to end. You'll build the workflow engine for long-running human and agent work (durable state, retries, idempotency, approvals, replay, compensation, auditability), and design identity and authorization for humans, services, and agents (principals, delegation, scoped sessions, tenant isolation, traceable authority). You'll build a versioned policy engine for who or what can perform which action on which resource under what context; own secure storage and use of customer production keys, OAuth tokens, and admin credentials (isolation, rotation, ephemeral injection, revocation, blast-radius containment); own the boundary between probabilistic model behavior and deterministic execution (validation, evals, release gates); build isolated virtual environments and dev boxes for agents (reproducible state, observability, resource controls, safe teardown); and ship the interfaces and APIs to author, approve, inspect, debug, and operate these systems in production.

What You'll Own:

- The workflow engine for long-running human + agent work: durable state, retries, idempotency, approvals, replay, compensation, auditability

- Identity and authorization for humans, services, and agents: principals, delegation, scoped sessions, tenant isolation, traceable authority

- A versioned policy engine (who/what can do which action on which resource, under what context)

- Secure storage and use of customer keys, OAuth tokens, and admin credentials: isolation, rotation, ephemeral injection, revocation, blast-radius containment

- The probabilistic-to-deterministic execution boundary: validation, evals, release gates

- Isolated virtual environments and dev boxes for agents: reproducible state, observability, resource controls, safe teardown

Company stage: Pre-seed. Work type: In-person (San Francisco, CA).

Sign up for Job Alerts