Principal Software Engineer, Agent Policy Fabric at NVIDIA | Santa Clara, CA, USA | Rezi

Principal Software Engineer, Agent Policy Fabric at NVIDIA

Principal Software Engineer, Agent Policy Fabric

NVIDIA · Santa Clara, CA, USA

1 months ago

Principal Software Engineer, Agent Policy Fabric

NVIDIA · Santa Clara, CA, USA

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Cloud Engineering & Services team is building an enterprise governance layer for agentic systems, including signed policy, runtime verification, and credential mediation. This role will mature the Agent Policy Fabric (APF) into a robust core platform for governed agent action, focusing on signed policy, Runtime Policy Verifier, projection, conformance, and failure modes.

Responsibilities

  • Own APF Core Services: Build and harden the Runtime Policy Verifier, signed policy bundle verification, trust-root handling, freshness, rollback protection, subject binding to attested runtime context, revocation checks, and authorization APIs.
  • Design Policy Projection: Implement deterministic projections from the canonical APF policy into OpenShell-native runtime policy, adapter constraints, credential constraints, audit requirements, and model-visible tool hints.
  • Build Conformance and Verification: Create golden fixtures, compatibility tests, negative tests, fuzz/property tests, and conformance suites.
  • Collaborate with Runtime Owners: Engage with OpenShell and Infrastructure engineers on public runtime interfaces for projection consumption, runtime context attestation, approved adapter paths, direct egress verification, and admission/rejection semantics.
  • Own cross-team work with OpenShell and other runtime owners to land public substrate interfaces APF composes against.
  • Drive Architecture Maturity: Define versioning, schema compatibility, latency budgets, availability behavior, fail-closed defaults, last-known-good policy handling, and engineering review artifacts.
  • Evolve technical specifications: Write specifications, defend claims in security and architecture reviews, drive open-decision resolution, and turn contracts into engineering artifacts.

Requirements

  • Bachelor's degree (or equivalent experience) with 15+ years of industry experience in systems software, security engineering, distributed systems, or policy infrastructure.
  • Strong programming skills in Rust, Go, C++, or Python.
  • Experience designing production services, APIs, schemas, policy engines, authorization systems, or signed artifact pipelines.
  • Familiarity with Linux systems, IPC or service-to-service APIs, protobuf/gRPC or equivalent wire formats, CI, test automation, release engineering, and cloud or enterprise deployment environments.
  • Practical experience with authorization, cryptographic signatures, trust roots, revocation, subject binding, rollback protection, secure-by-default failure handling, and zero-trust architecture patterns.
  • Ability to write streamlined technical specifications, align multiple engineering owners, defend bounded claims, and turn architecture into buildable interfaces.

Skills

  • Rust
  • Go
  • C++
  • Python
  • Production services design
  • API design
  • Schema design
  • Policy engines
  • Authorization systems
  • Signed artifact pipelines
  • Linux systems
  • IPC
  • Service-to-service APIs
  • Protobuf
  • gRPC
  • CI
  • Test automation
  • Release engineering
  • Cloud deployment
  • Enterprise deployment
  • Authorization
  • Cryptographic signatures
  • Trust roots
  • Revocation
  • Subject binding
  • Rollback protection
  • Secure-by-default failure handling
  • Zero-trust architecture
  • Technical specification writing
  • Architecture leadership
  • OPA/Rego
  • Cedar
  • Zanzibar-style authorization
  • Policy compilers
  • Sandbox policy
  • Runtime enforcement systems
  • Agent frameworks
  • Tool-call governance
  • Sandboxed execution
  • OpenShell-like runtime substrates
  • MCP-style tool routing
  • Credential isolation for agents
  • Sigstore
  • TUF
  • in-toto
  • HSM-backed signing
  • Package provenance
  • Signed configuration
  • Enterprise trust-root distribution
  • Property testing
  • Model checking
  • Symbolic execution
  • Red-team findings
  • Bounded verification
  • RFC contribution (identity, supply-chain, policy)

Experience Level

  • 15+ years of industry experience

Education Level

  • Bachelor's degree or equivalent experience

Salary/Compensations

  • 272,000 USD - 431,250 USD

Benefits

  • Equity
  • Generous benefits package

About the Company

  • NVIDIA pioneered accelerated computing. Today, our AI infrastructure powers global intelligence, transforming every industry.
  • We have some of the most forward-thinking and versatile people in the world working with us, and our engineering teams are growing fast in some of the most impactful fields of our generation: AI, Data Engineering, Data Science.

Equal Opportunity

  • NVIDIA is committed to fostering an inclusive work environment and proud to be an equal opportunity employer.
  • As we highly value diversity in our current and future employees, we do not discriminate (including in our hiring and promotion practices) on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status or any other characteristic protected by law.