Senior Product Engineer, Out-of-Band Policy Engine, AI Platform at Redpanda Data | Job-Scouts.com

Senior Product Engineer, Out-of-Band Policy Engine, AI Platform

Redpanda Data
full-time senior US/Canada - Eastern Region Remote
This position is sourced from Redpanda Data's career page . Apply through Job-Scouts to track your application status.

Job Description

Redpanda is the first runtime and control plane for agent-data interaction — a unified platform that combines streaming, SQL analytics, and intelligent connectivity with the governance layer enterprise AI agents need in production.

Built on infrastructure already trusted by Fortune 500 companies and fast-growing startups, Redpanda enforces governance entirely outside the agent's data path, controlling what agents see, limiting what they do, and capturing a tamper-proof record of everything they touch, so organizations never have to choose between innovation and control.

About the Role:

In-band defenses for AI agents — a system prompt telling a model to behave, or an LLM reviewing its own tool calls — share the same failure mode: they trust the thing they're supposed to be constraining. The out-of-band policy engine is Redpanda's answer to that problem, and one of the fundamental thrusts of how we think about the product: a policy proxy that sits at the tool boundary and enforces outside the model entirely. The agent's prompt and tool surface stay byte-identical; the proxy is the thing deciding whether a call is authorized, needs its response masked or filtered, requires a scope-narrowing rewrite, or has to be deferred into a human-approval step. In our own adversarial benchmarking, this approach held its defense in 99.8% of attempts, against 94.8% for an in-band LLM guardrail reviewer and 85.6% for prompt-only defenses — the gap is the whole argument for building this the hard way.

The policy language is ratified and a working prototype exists — nine authorable operators spanning authorization, data exposure, and semantic gating; two-tier policy composition; and a red-team-plus-blinded-judge benchmark harness that certifies enforcement rather than just asserting it. What's ahead is turning that prototype into production infrastructure: wiring it into our AI gateway as the real enforcement path, building out the authoring experience so policies are something a security team can write and test with confidence, and landing every decision as an audited, replayable record. We're looking for a Senior Product Engineer to help build that — this is a high-ownership, deeply technical role at the center of how Redpanda makes agentic AI safe enough for security teams to say yes to.

You are:

• Someone who thinks about security enforcement the way an adversary would — comfortable reasoning about what a policy doesn't cover, not just what it does

• Excited to roll up your sleeves and do what it takes to deliver objective results

• Drawn to hard, precise systems problems — this is a proxy sitting in the request path of every governed tool call, where correctness and latency both matter

• Eager to thrive with the thrill and ethos of a fast growing startup

• Accountable, bring a sense of ownership, and are self-driven

You have:

• 5+ years of experience in software development, including building systems that enforce authorization or policy decisions in a live request path (a proxy, gateway, or middleware layer, not just a batch or offline check)

• Experience with policy-as-code systems such as Cedar, Open Policy Agent (Rego), XACML, or comparable authorization frameworks

• A solid understanding of AI agent and LLM system failure modes — prompt injection, tool misuse, data exfiltration through model output — and why defenses that live inside the model's own reasoning loop are fundamentally weaker than defenses that don't

• Comfortable with the mindset of adversarial testing: designing for attackers who are actively trying to defeat what you build, not just for well-behaved input

• Comfortable working with a globally distributed engineering team, collaborating on GitHub, in the open, and a self starter

• Strong verbal and written communication skills and demonstrated technical ownership

You will:

• Take the out-of-band policy engine from benchmarked prototype to production: wiring the Cedar-based enforcement proxy into our AI gateway as the real guardrail path for governed tool calls

• Build out the two-tier policy composition model — a per-tool-server data-owner ceiling composed with per-agent narrowing, most-restrictive wins — and the authoring experience that lets a security or compliance team write, test, and validate policies with confidence

• Extend the set of authorable policy operators across authorization, data exposure, and semantic gating, including the deferred-approval state that routes a call into human review rather than allowing or blocking it outright

• Land every enforcement decision as an audited, attributable record — the kind of durable evidence a customer's security team can actually review after the fact

• Maintain and extend the adversarial certification harness (multi-turn red-team adversary, blinded judge, deterministic leak metrics) so enforcement claims stay backed by evidence as the system evolves

• Work directly with design-partner customers in security-conscious industries to understand what a real security review actually demands of a policy engine, and feed that back into what you build

• Bring up difficult and/or systemic challenges and impediments to the attention of your manager

• Actively discuss strategic topics with peers to help shape the product's roadmap and how the team works

• Track progress, assess risks, and actively communicate contingency and mitigation plans for the systems you own

Kindly highlight if applicable to you:

• Direct experience with Cedar (AWS's policy language) specifically, or deep experience with a comparable policy-as-code language

• Experience building or operating a proxy or gateway that sits in a security-critical request path in production (API gateway, service mesh sidecar, egress/ingress proxy, or similar)

• Experience designing or running red-team / adversarial evaluation harnesses, including working with an LLM-as-judge evaluation setup

• Experience with LLM guardrail, content-safety, or prompt-injection defense systems, especially having seen their failure modes firsthand

• Experience with audit/compliance logging pipelines, especially ones that need to hold up as evidence for external security or regulatory review

U.S. base salary range for this role is $205,000 - $230,000. Our salary ranges are determined by role, level, and location. We strive to consider each candidate's job-related skills, location, experience, relevant education or training to determine individual base salary. Your talent partner will share more about the specific salary range for your preferred location during the hiring process.

Join Redpanda if you’d enjoy being part of a fast-moving, diverse, people-first organization with team members around the globe and a culture based on trust, transparency, communication, and kindness. You'll dive into a nimble, high-impact team with the latest AI tools — and the budget to actually use them.

Requirements

Department: Engineering

Location

US/Canada - Eastern Region

Similar open positions