3 hours ago
Responsibilities
- Design and build services that enforce scoped permissions, tool-call validation, and limits on what AI agents can read, write, or send.
- Implement data access controls that protect PII and sensitive records within approved boundaries.
- Build reusable guardrail libraries and SDKs for agent workflows.
- Design detection and containment for prompt injection, tool misuse, data exfiltration, and other agent-specific failures.
- Create automated tests, red-team harnesses, tamper-evident audit logs, and decision trails.
- Partner with product, platform, and ML engineering to review agent capabilities and identify missing guardrails.
- Own guardrail APIs, documentation, and developer experience.
- Define and measure guardrail effectiveness, workflow coverage, false positive and negative rates, and detection and containment times.
Requirements
- 5 to 8 years of experience as a software engineer building and shipping production systems, including meaningful work in security, data protection, or trust and safety.
- Strong general-purpose programming skills in Python, Go, TypeScript, or similar languages.
- Experience with or strong working knowledge of production AI agents, tool use, function calling, and orchestration frameworks such as LangChain or LangGraph.
- Knowledge of PII handling, access control, encryption, and least privilege.
- Experience designing services and APIs used by other engineers, with clear interfaces and predictable failure modes.
- Working cloud experience with AWS, GCP, or Azure sufficient to build and deploy services securely.
- Comfort working across the software development lifecycle and designing low-friction developer guardrails.
- Strong written English and the ability to write usable documentation and runbooks.
- Preferred experience building LLM or agent guardrails, including prompt-injection defenses, content filtering, or output validation.
- Preferred background handling sensitive customer data in healthcare, government, or financial services.
- Familiarity with policy-as-code, secrets management, or software supply-chain security tooling is preferred.
- Prior startup experience and comfort working autonomously are preferred.
Benefits
- The role provides real ownership and a defined guardrail surface across the platform.
- Production code directly shapes the safety of AI agents operating on customer data.
- The role is focused on building rather than policy or compliance advising.
Categories
About Brain Co.
We're building an AI platform and applications for the world's most important institutions. Learn more at https://brain.co/
