E

Senior Software Engineer, Sandboxing Infrastructure

engradar United State
Visa Sponsorship Relocation
Apply
AI Summary

Design, build, and operate secure, scalable sandboxing infrastructure for executing untrusted AI-generated code and tool calls. Focus on isolation, performance, and reliability for research and product use cases. Collaborate with cross-functional teams to ensure safe, efficient, and observable execution environments.

Key Highlights
Build and maintain sandboxing infrastructure for untrusted code execution at scale
Balance security (containers, microVMs, gVisor-style kernels) with performance and latency
Own end-to-end reliability, observability, and abuse detection for sandboxed environments
Key Responsibilities
Design and implement isolated execution environments for untrusted model-generated code and tool calls
Develop scheduling, resource management, and lifecycle systems for efficient sandbox provisioning and teardown
Collaborate with researchers and product teams to define and expose sandboxing primitives for safe, user-friendly access
Instrument sandboxes for observability, abuse detection, and rapid response to novel security threats
Ensure end-to-end reliability, performance, and security of the sandboxing platform
Technical Skills Required
Linux internals (namespaces, cgroups, seccomp, capabilities, networking) Isolation/virtualization technologies (containers, microVMs, sandboxed runtimes) Systems programming and performance optimization
Benefits & Perks
Generous health, dental, and vision benefits
Unlimited paid time off (PTO)
Paid parental leave
Nice to Have
Experience securing systems against adversarial or untrusted code
Threat modeling and hardening expertise
Familiarity with Kubernetes or similar orchestration systems
Open-source contributions to infrastructure or security tooling
Interest in AI agent tool execution and safe execution environments

Job Description


EngRadar / Thinking Machines Lab

Software Engineer, Sandboxing

Thinking Machines Lab

Remote San Francisco Full-time Posted today

Apply directly →

The mission of Thinking Machines is to build AI that extends human will and judgment.

Software Engineer, Sandboxing

San Francisco, California

The mission of Thinking Machines is to build AI that extends human will and judgment. We are training frontier models with Inkling, developing Tinker to let people make models their own, and crafting interfaces that broaden human-AI communication. We believe the future worth building is human, and we're hiring people who want to build it.

About The Role

Our models and agents increasingly need to run code, use tools, and take actions in the world — safely, reliably, and at scale. The Core Services team builds the sandboxing infrastructure that makes this possible: the isolated execution environments where models write and run code, browse, and interact with tools, both for our researchers during training and for external users building on Tinker.

We're hiring a software engineer to help design, build, and operate this sandboxing platform. You'll work on the systems that isolate and constrain untrusted, model-generated code, and that scale to support thousands of concurrent executions across the company. This is foundational infrastructure: every research experiment and every product surface that lets a model take action depends on it being fast, secure, and dependable.

What You'll Do

  • Design, build, and operate sandboxed execution environments for running untrusted, model-generated code and tool calls at scale.
  • Improve isolation boundaries using technologies such as containers, microVMs, or gVisor-style kernels, balancing security against startup latency and throughput.
  • Build the scheduling, resource-management, and lifecycle systems that provision, reuse, and tear down sandboxes efficiently under heavy concurrent load.
  • Partner with researchers and Tinker's product team to expose sandboxing primitives that are simple to use and hard to misuse.
  • Instrument sandboxes for observability and abuse detection, and respond to novel escape or exploitation attempts as they're discovered.
  • Own reliability and performance of the sandboxing platform end-to-end, from API design down to the underlying virtualization layer.

Skills And Qualifications

Minimum qualifications:

  • Bachelor's degree or equivalent experience in computer science, engineering, or similar.
  • Proficiency in at least one backend language (we use Python or Rust).
  • Experience building or operating isolation or virtualization technology, such as containers, microVMs (e.g. Firecracker, Cloud Hypervisor), or sandboxed runtimes (e.g. gVisor, Kata Containers).
  • Solid grounding in Linux internals relevant to isolation: namespaces, cgroups, seccomp, capabilities, and networking.
  • Comfort operating across the stack and owning projects end-to-end.
  • Thrive in a highly collaborative environment involving many, different cross-functional partners and subject matter experts.

Preferred Qualifications

  • Experience securing systems that execute untrusted or adversarial code, including threat modeling and hardening against sandbox escapes.
  • Familiarity with running large-scale, multi-tenant infrastructure on Kubernetes or similar orchestration systems.
  • Experience with performance-sensitive systems programming and reducing cold-start latency for ephemeral compute.
  • Track record of contributing to open-source infrastructure or security tooling.
  • Interest in how AI agents use tools and code execution, and how that shapes the design of safe execution environments.

Logistics

  • Location: This role is based in San Francisco, CA.
  • Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $300,000 - $450,000 USD.
  • Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
  • Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.

As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.

Posted by Thinking Machines Lab on their own careers page — you apply directly, no recruiter in between. View original / apply →

More at Thinking Machines Lab

T

Software Engineer, Research Acceleration

Thinking Machines Lab

Remote San Francisco

6mo ago

T

Software Engineer, Platform, Tinker

Thinking Machines Lab

Remote San Francisco

4mo ago

T

Network Engineer, Supercomputing

Thinking Machines Lab

Remote San Francisco

2mo ago

T

Reliability Engineer, Supercomputing

Thinking Machines Lab

Remote San Francisco

2mo ago

Apply directly → Browse Full-Stack Jobs

Similar Jobs

Explore other opportunities that match your interests

Fuel Systems Test Engineering Manager

Programming
5h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Caterpillar Inc.

United State

Applied AI Field Researcher

Programming
8h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

anthropic

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Associate

torentify

United State

Subscribe our newsletter

New Things Will Always Update Regularly