Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AI
API @ 4
Agentic Systems
Audit
Distributed Systems @ 8
Go @ 7
Linux @ 3
Protobuf @ 3
Python @ 7
Rust @ 7
Scoping @ 6
Security @ 8
gRPC @ 3
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
NVIDIA's Cloud Engineering & Services team is building an enterprise governance layer for agentic systems, including signed policy, runtime verification, policy projection, credential mediation, detector verdict handling, and common audit across runtime substrates and enterprise integrations.
The Principal Software Engineer, Agent Policy Fabric (APF) Core Platform will mature the scoped APF v0 proof-of-life into a robust core platform for governed agent action. This role will build the foundations for signed policy, the Runtime Policy Verifier, projection, conformance, and failure modes that future APF deployments depend on.
Responsibilities
- Build and harden APF Core Services, including the Runtime Policy Verifier, signed policy bundle verification, trust-root handling, freshness, rollback protection, subject binding to attested runtime context, revocation checks, and authorization APIs used by APF-compatible enforcement points.
- Implement deterministic projections from canonical APF policy into OpenShell-native runtime policy, adapter constraints, credential constraints, audit requirements, and model-visible tool hints while preserving the atomic projection-admission contract.
- Create golden fixtures, compatibility tests, negative tests, fuzz/property tests, and conformance suites to verify that APF-compatible runtimes and adapters honor the same contract.
- Collaborate with OpenShell and Infrastructure engineers on public runtime interfaces for projection consumption, runtime context attestation, approved adapter paths, direct egress verification, and admission/rejection semantics.
- Own cross-team work with OpenShell and other runtime owners to land public substrate interfaces, including runtime-context attestation, approved adapter path declaration, projection acceptance and rejection semantics, quarantine, and stop-session hooks. Land each interface as a public RFC or PR.
- Define versioning, schema compatibility, latency budgets, availability behavior, fail-closed defaults, last-known-good policy handling, and engineering review artifacts for Product Security, Fleet, Identity, and partner teams.
- Write technical specifications, defend bounded claims in security and architecture reviews, drive open-decision resolution, and turn working-draft contracts into engineering artifacts that Product Security, Fleet, Identity, and partner runtimes can adopt.
Requirements
- Bachelor's degree or equivalent experience, with 15+ years of industry experience in systems software, security engineering, distributed systems, or policy infrastructure.
- Strong programming skills in Rust, Go, C++, or Python.
- Experience designing production services, APIs, schemas, policy engines, authorization systems, or signed artifact pipelines.
- Familiarity with Linux systems, IPC or service-to-service APIs, protobuf/gRPC or equivalent wire formats, CI, test automation, release engineering, and cloud or enterprise deployment environments.
- Practical experience with authorization, cryptographic signatures, trust roots, revocation, subject binding, rollback protection, secure-by-default failure handling, and zero-trust architecture patterns.
- Ability to write streamlined technical specifications, align multiple engineering owners, defend bounded claims, and turn working-draft architecture into buildable interfaces without over-scoping the runtime.
Preferred Qualifications
- Experience with OPA/Rego, Cedar, Zanzibar-style authorization, policy compilers, sandbox policy, or runtime enforcement systems.
- Familiarity with agent frameworks, tool-call governance, sandboxed execution, OpenShell-like runtime substrates, MCP-style tool routing, or credential isolation for agents.
- Experience with Sigstore, TUF, in-toto, HSM-backed signing, package provenance, signed configuration, or enterprise trust-root distribution.
- Experience using property testing, model checking, symbolic execution, red-team findings, or bounded verification to constrain security claims.
- Experience contributing to RFCs in identity, supply-chain, or policy spaces, including IETF, OpenID Foundation, FIDO Alliance, CNCF, or NIST.
Benefits
- Base salary range: USD 272,000–431,250 per year.
- Equity and benefits are available.
- NVIDIA uses AI tools in its recruiting processes.
- NVIDIA is an equal opportunity employer committed to an inclusive work environment.
- Applications will be accepted at least until June 26, 2026.
More jobs at Nvidia
Research Engineer, Interactive World Models - New College Grad 2026
Nvidia · Santa Clara, United States
USD 108,000-195,500 per year
Senior Security Engineer, Infrastructure Security Engineering - DGX Cloud
Nvidia · Canada
CAD 170,000-275,000 per year
Systems Software Engineer - AI and Cloud
Nvidia · Santa Clara, United States
USD 124,000-241,500 per year
Senior Engineering Manager, Infrastructure Security Engineering - DGX Cloud
Nvidia · Canada
CAD 245,000-295,000 per year
Senior Compute Platform Engineer, LSF
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Similar jobs
Staff+ Software Engineer, Infrastructure (Distributed Systems)
Anthropic · New York City, United States, San Francisco, United States, Seattle, United States
USD 320,000-485,000 per year
Systems Generalist, GPT Infrastructure
OpenAI · San Francisco, United States, Seattle, United States
USD 293,000-445,000 per year
Senior Software Engineer, Core Infrastructure Services - DGX Cloud
Nvidia · United States
USD 168,000-322,000 per year
Staff Backend Software Engineer, Agent Platform
SentinelOne · United States
USD 156,000-215,000 per year
Senior Storage Software Engineer, DGXC Data Services
Nvidia · Santa Clara, United States
USD 152,000-287,500 per year
Autonomous Agent Engineer
Nvidia · Santa Clara, United States
USD 184,000-356,500 per year
Senior Backend Engineer
Teleport · United Kingdom, United States
USD 180,900-342,000 per year
Software Engineer, Codex Enterprise
OpenAI · San Francisco, United States
USD 230,000-385,000 per year