Software Engineer, Sandboxing at Thinking Machines Lab | CA, US | Rezi

Software Engineer, Sandboxing at Thinking Machines Lab

Software Engineer, Sandboxing

Thinking Machines Lab · CA, US

3 days ago

Software Engineer, Sandboxing

Thinking Machines Lab · CA, US

4 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Core Services team builds the sandboxing infrastructure that enables models and agents to safely and reliably run code, use tools, and take actions in the world. This role involves designing, building, and operating this platform, which is foundational for research experiments and product surfaces that rely on model actions.

Responsibilities

  • Design, build, and operate sandboxed execution environments for running untrusted, model-generated code and tool calls at scale.
  • Improve isolation boundaries using technologies such as containers, microVMs, or gVisor-style kernels, balancing security against startup latency and throughput.
  • Build the scheduling, resource-management, and lifecycle systems that provision, reuse, and tear down sandboxes efficiently under heavy concurrent load.
  • Partner with researchers and Tinker's product team to expose sandboxing primitives that are simple to use and hard to misuse.
  • Instrument sandboxes for observability and abuse detection, and respond to novel escape or exploitation attempts as they're discovered.
  • Own reliability and performance of the sandboxing platform end-to-end, from API design down to the underlying virtualization layer.

Requirements

  • Bachelor's degree or equivalent experience in computer science, engineering, or similar.
  • Proficiency in at least one backend language (Python or Rust).
  • Experience building or operating isolation or virtualization technology, such as containers, microVMs (e.g. Firecracker, Cloud Hypervisor), or sandboxed runtimes (e.g. gVisor, Kata Containers).
  • Solid grounding in Linux internals relevant to isolation: namespaces, cgroups, seccomp, capabilities, and networking.
  • Comfort operating across the stack and owning projects end-to-end.
  • Thrive in a highly collaborative environment involving many, different cross-functional partners and subject matter experts.
  • Experience securing systems that execute untrusted or adversarial code, including threat modeling and hardening against sandbox escapes.
  • Familiarity with running large-scale, multi-tenant infrastructure on Kubernetes or similar orchestration systems.
  • Experience with performance-sensitive systems programming and reducing cold-start latency for ephemeral compute.
  • Track record of contributing to open-source infrastructure or security tooling.
  • Interest in how AI agents use tools and code execution, and how that shapes the design of safe execution environments.

Skills

  • Python
  • Rust
  • Containers
  • MicroVMs
  • gVisor-style kernels
  • Linux internals
  • Namespaces
  • Cgroups
  • Seccomp
  • Capabilities
  • Networking
  • Kubernetes
  • Systems programming

Location

  • San Francisco, California

Work Type

  • Onsite

Experience Level

  • Mid-level
  • Senior

Education Level

  • Bachelor's degree or equivalent experience

Salary/Compensations

  • $300,000 - $450,000 USD

Benefits

  • Generous health, dental, and vision benefits
  • Unlimited PTO
  • Paid parental leave
  • Relocation support

About the Company

  • The mission of Thinking Machines is to build AI that extends human will and judgment.
  • We are training frontier models with Inkling, developing Tinker to let people make models their own, and crafting interfaces that broaden human-AI communication.
  • We believe the future worth building is human, and we're hiring people who want to build it.

Equal Opportunity

  • As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.
  • Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.