Software Engineer, Sandboxing

Thinking Machines Lab

$300K — $350K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, engineering, or similar.
  • Proficient in backend languages, specifically Python or Rust.
  • Experience with isolation or virtualization technologies like containers and microVMs.
  • Knowledge of Linux internals relevant to isolation and security.
  • Ability to manage projects independently from end-to-end.
  • Strong collaboration skills to engage with cross-functional teams.

Responsibilities

  • Design, build, and manage sandboxed environments for untrusted code execution at scale.
  • Enhance isolation boundaries using advanced technologies for security optimization.
  • Develop systems for scheduling and resource management of sandboxing.
  • Collaborate with research and product teams to simplify sandboxing interfaces.
  • Implement observability measures and respond to security breaches in real-time.
  • Ensure platform reliability and performance across all system layers.

Benefits

  • Generous health, dental, and vision benefits.
  • Unlimited paid time off (PTO).
  • Paid parental leave.
  • Relocation support available.
Full Job Description
About the Role

Our models and agents increasingly need to run code, use tools, and take actions in the world - safely, reliably, and at scale. The Core Services team builds the sandboxing infrastructure that makes this possible: the isolated execution environments where models write and run code, browse, and interact with tools, both for our researchers during training and for external users building on Tinker.

We're hiring a software engineer to help design, build, and operate this sandboxing platform. You'll work on the systems that isolate and constrain untrusted, model-generated code, and that scale to support thousands of concurrent executions across the company. This is foundational infrastructure: every research experiment and every product surface that lets a model take action depends on it being fast, secure, and dependable.

What You'll Do
  • Design, build, and operate sandboxed execution environments for running untrusted, model-generated code and tool calls at scale.
  • Improve isolation boundaries using technologies such as containers, microVMs, or gVisor-style kernels, balancing security against startup latency and throughput.
  • Build the scheduling, resource-management, and lifecycle systems that provision, reuse, and tear down sandboxes efficiently under heavy concurrent load.
  • Partner with researchers and Tinker's product team to expose sandboxing primitives that are simple to use and hard to misuse.
  • Instrument sandboxes for observability and abuse detection, and respond to novel escape or exploitation attempts as they're discovered.
  • Own reliability and performance of the sandboxing platform end-to-end, from API design down to the underlying virtualization layer.
Skills and Qualifications

Minimum qualifications:
  • Bachelor's degree or equivalent experience in computer science, engineering, or similar.
  • Proficiency in at least one backend language (we use Python or Rust).
  • Experience building or operating isolation or virtualization technology, such as containers, microVMs (e.g. Firecracker, Cloud Hypervisor), or sandboxed runtimes (e.g. gVisor, Kata Containers).
  • Solid grounding in Linux internals relevant to isolation: namespaces, cgroups, seccomp, capabilities, and networking.
  • Comfort operating across the stack and owning projects end-to-end.
  • Thrive in a highly collaborative environment involving many, different cross-functional partners and subject matter experts.

Preferred qualifications:
  • Experience securing systems that execute untrusted or adversarial code, including threat modeling and hardening against sandbox escapes.
  • Familiarity with running large-scale, multi-tenant infrastructure on Kubernetes or similar orchestration systems.
  • Experience with performance-sensitive systems programming and reducing cold-start latency for ephemeral compute.
  • Track record of contributing to open-source infrastructure or security tooling.
  • Interest in how AI agents use tools and code execution, and how that shapes the design of safe execution environments.
Logistics
  • Location: This role is based in San Francisco, CA.
  • Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $300,000 - $350,000 USD.
  • Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
  • Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.

Similar Jobs

More Jobs at Thinking Machines Lab

  • Global Public Policy
    $300K — $360K *
    San Francisco, CA 94112 (San Francisco County)
    Education, Government & Non-Profit
    In-Person
  • Global Public Policy
    $300K — $360K *
    Washington, DC 20011 (District Of Columbia County)
    Enterprise Technology
    In-Person
  • Product Policy
    $300K — $360K *
    San Francisco, CA 94112 (San Francisco County)
    Consumer Technology
    In-Person
  • Research, Tinker, RL Systems
    $350K — $475K *
    San Francisco, CA 94112 (San Francisco County)
    Consumer Technology
    In-Person
  • Technical Recruiter
    $200K — $275K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Software Engineer, Sandboxing jobs: