About The Position

Redpanda is seeking a Senior Product Engineer to build and productionize its Out-of-Band Policy Engine for AI agents. This role is central to Redpanda's mission of making agentic AI safe for enterprise use by providing a policy proxy that enforces governance outside the agent's data path. The engine controls agent actions, filters responses, and records all interactions, offering a more robust security solution than in-band defenses. The current focus is on transforming a working prototype into production infrastructure, integrating it with the AI gateway, enhancing the authoring experience for security teams, and ensuring all decisions are auditable and replayable.

Requirements

  • 5+ years of experience in software development, including building systems that enforce authorization or policy decisions in a live request path (a proxy, gateway, or middleware layer, not just a batch or offline check).
  • Experience with policy-as-code systems such as Cedar, Open Policy Agent (Rego), XACML, or comparable authorization frameworks.
  • A solid understanding of AI agent and LLM system failure modes — prompt injection, tool misuse, data exfiltration through model output — and why defenses that live inside the model's own reasoning loop are fundamentally weaker than defenses that don't.
  • Comfortable with the mindset of adversarial testing: designing for attackers who are actively trying to defeat what you build, not just for well-behaved input.
  • Comfortable working with a globally distributed engineering team, collaborating on GitHub, in the open, and a self starter.
  • Strong verbal and written communication skills and demonstrated technical ownership.

Nice To Haves

  • Direct experience with Cedar (AWS's policy language) specifically, or deep experience with a comparable policy-as-code language.
  • Experience building or operating a proxy or gateway that sits in a security-critical request path in production (API gateway, service mesh sidecar, egress/ingress proxy, or similar).
  • Experience designing or running red-team / adversarial evaluation harnesses, including working with an LLM-as-judge evaluation setup.
  • Experience with LLM guardrail, content-safety, or prompt-injection defense systems, especially having seen their failure modes firsthand.
  • Experience with audit/compliance logging pipelines, especially ones that need to hold up as evidence for external security or regulatory review.

Responsibilities

  • Take the out-of-band policy engine from benchmarked prototype to production: wiring the Cedar-based enforcement proxy into our AI gateway as the real guardrail path for governed tool calls.
  • Build out the two-tier policy composition model — a per-tool-server data-owner ceiling composed with per-agent narrowing, most-restrictive wins — and the authoring experience that lets a security or compliance team write, test, and validate policies with confidence.
  • Extend the set of authorable policy operators across authorization, data exposure, and semantic gating, including the deferred-approval state that routes a call into human review rather than allowing or blocking it outright.
  • Land every enforcement decision as an audited, attributable record — the kind of durable evidence a customer's security team can actually review after the fact.
  • Maintain and extend the adversarial certification harness (multi-turn red-team adversary, blinded judge, deterministic leak metrics) so enforcement claims stay backed by evidence as the system evolves.
  • Work directly with design-partner customers in security-conscious industries to understand what a real security review actually demands of a policy engine, and feed that back into what you build.
  • Bring up difficult and/or systemic challenges and impediments to the attention of your manager.
  • Actively discuss strategic topics with peers to help shape the product's roadmap and how the team works.
  • Track progress, assess risks, and actively communicate contingency and mitigation plans for the systems you own.

Benefits

  • Team members around the globe
  • Culture based on trust, transparency, communication, and kindness
  • Nimble, high-impact team
  • Latest AI tools
  • Budget to use AI tools
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service