# Software Engineer, Sandboxing

**Company:** [Thinking Machines Lab](https://hotfix.jobs/companies/thinking-machines-lab)
**Location:** San Francisco, CA
**Role:** Backend Engineering
**Salary:** $300k – $450k/yr
**Skills:** Python, Rust, Containers, Microvms, Gvisor, Kata Containers, Linux, Namespaces, Cgroups, Seccomp, Kubernetes, Threat Modeling, Virtualization
**Posted:** 2026-08-26

> Build and operate secure, scalable sandboxing infrastructure for untrusted, model-generated code and tool calls. The role requires backend programming, virtualization or isolation experience, and strong knowledge of Linux security primitives.

## Job Description

## Responsibilities
- Design, build, and operate sandboxed execution environments for untrusted, model-generated code and tool calls at scale.
- Improve isolation boundaries using containers, microVMs, or gVisor-style kernels while balancing security, startup latency, and throughput.
- Build scheduling, resource-management, and lifecycle systems to provision, reuse, and tear down sandboxes efficiently under heavy concurrent load.
- Partner with researchers and product teams to expose sandboxing primitives that are simple to use and difficult to misuse.
- Instrument sandboxes for observability and abuse detection, and respond to escape or exploitation attempts.
- Own platform reliability and performance end-to-end, from API design through the underlying virtualization layer.

## Requirements
- Bachelor's degree or equivalent experience in computer science, engineering, or a similar field.
- Proficiency in at least one backend language, such as Python or Rust.
- Experience building or operating isolation or virtualization technology, including containers, microVMs, or sandboxed runtimes.
- Strong knowledge of Linux isolation internals, including namespaces, cgroups, seccomp, capabilities, and networking.
- Ability to operate across the stack and own projects end-to-end.
- Ability to collaborate with cross-functional partners and subject-matter experts.

## Nice-to-haves
- Experience securing systems that execute untrusted or adversarial code, including threat modeling and sandbox-escape hardening.
- Familiarity with large-scale, multi-tenant infrastructure on Kubernetes or similar orchestration systems.
- Experience with performance-sensitive systems programming and reducing cold-start latency for ephemeral compute.
- Contributions to open-source infrastructure or security tooling.
- Interest in AI-agent tool use and code execution and their implications for safe execution environments.

## Compensation and Benefits
- Annual salary: **$300,000–$450,000 USD**.
- Health, dental, and vision benefits.
- Unlimited paid time off.
- Paid parental leave.
- Relocation support.

## Similar jobs

- [Backend Software Engineer - Codex for Finance](https://hotfix.jobs/jobs/62f48384-2f64-470a-a767-f343d81adf49) - OpenAI - San Francisco, CA - $293k – $325k/yr
- [Software Engineer, Host Assurance](https://hotfix.jobs/jobs/8e75c9b0-63a5-4e79-ac17-757b5f1b56fe) - OpenAI - San Francisco, CA - $266k – $445k/yr
- [Product Engineer, Ona](https://hotfix.jobs/jobs/fced2e7b-d946-44bb-8c1c-50640be580c3) - OpenAI - San Francisco, CA - $255k – $445k/yr
- [Software Engineer - Identity and Authorization](https://hotfix.jobs/jobs/e15f1f39-fea6-4109-b3d1-9d7ca030d633) - Baseten - San Francisco, CA - $240k – $285k/yr
- [Software Engineer](https://hotfix.jobs/jobs/6a07ad4a-8519-4cf3-8100-9d81f075ffb5) - Stripe - Seattle, WA - $235k – $286k/yr

**Apply:** https://hotfix.jobs/jobs/d5312ce5-70cc-417d-a666-febfbebda511
**Canonical:** https://hotfix.jobs/jobs/d5312ce5-70cc-417d-a666-febfbebda511