×
Register Here to Apply for Jobs or Post Jobs. X

Principal Software Engineer, Agent Policy Fabric

Job in Durham, Durham County, North Carolina, 27703, USA
Listing for: NVIDIA
Full Time position
Listed on 2026-07-06
Job specializations:
  • Software Development
    DevOps, Software Engineer, Backend Developer
Salary/Wage Range or Industry Benchmark: 272000 - 431250 USD Yearly USD 272000.00 431250.00 YEAR
Job Description & How to Apply Below

Overview

NVIDIA is widely recognized as one of the most desirable employers, with some of the world's most dedicated people working for us. The Cloud Engineering & Services team is building an enterprise governance layer for agentic systems: signed policy, runtime verification, policy projection, credential mediation, detector verdict handling, and common audit across runtime substrates and enterprise integrations. We are looking for a Principal Software Engineer, Agent Policy Fabric (APF) Core Platform, to join our Cloud Engineering & Services team and mature the scoped APF v0 proof-of-life into a robust core platform for governed agent action.

You will play a critical role in building the foundations for signed policy, Runtime Policy Verifier, projection, conformance, and failure mode that future APF deployments depend on.

Responsibilities
  • Own APF Core Services: Build and harden the Runtime Policy Verifier, signed policy bundle verification, trust-root handling, freshness, rollback protection, subject binding to attested runtime context, revocation checks, and authorization APIs used by APF-compatible enforcement points.
  • Design Policy Projection: Implement deterministic projections from the canonical APF policy into Open Shell-native runtime policy, adapter constraints, credential constraints, audit requirements, and model-visible tool hints, while preserving the atomic projection-admission contract.
  • Build Conformance and Verification: Create golden fixtures, compatibility tests, negative tests, fuzz/property tests, and conformance suites that prove APF-compatible runtimes and adapters honor the same contract.
  • Collaborate with Runtime Owners: Engage alongside Open Shell and Infrastructure engineers on public runtime interfaces for projection consumption, runtime context attestation, approved adapter paths, direct egress verification, and admission/rejection semantics.
  • Land the Runtime integration surfaces: Own the cross-team work with Open Shell and other runtime owners to land public substrate interfaces APF composes against — runtime-context attestation, approved adapter path declaration, projection acceptance and rejection semantics, quarantine, and stop-session hooks. Land each as a public RFC or PR.
  • Drive Architecture Maturity: Define versioning, schema compatibility, latency budgets, availability behavior, fail-closed defaults, last-known-good policy handling, and engineering review artifacts for Product Security, Fleet, Identity, and partner teams.
  • Evolve technical specifications: Write specifications, defend bounded claims in security and architecture reviews, drive open-decision resolution, and turn working-draft contracts into engineering artifacts that Product Security, Fleet, Identity, and partner runtimes can adopt.
What We Need To See
  • Bachelor's degree (or equivalent experience) with 15+ years of industry experience in systems software, security engineering, distributed systems, or policy infrastructure.
  • Technical Core: Strong programming skills in Rust, Go, C++, or Python; experience designing production services, APIs, schemas, policy engines, authorization systems, or signed artifact pipelines.
  • Infrastructure Familiarity: Linux systems, IPC or service-to-service APIs, protobuf/gRPC or equivalent wire formats, CI, test automation, release engineering, and cloud or enterprise deployment environments.
  • Security Engineering: Practical experience with authorization, cryptographic signatures, trust roots, revocation, subject binding, rollback protection, secure-by-default failure handling, and zero-trust architecture patterns.
  • Architecture Leadership: Ability to write streamlined technical specifications, align multiple engineering owners, defend bounded claims, and turn working-draft architecture into buildable interfaces without over-scoping the runtime.
Ways To Stand Out From The Crowd
  • Runtime Policy Systems: Experience with OPA/Rego, Cedar, Zanzibar-style authorization, policy compilers, sandbox policy, or runtime enforcement systems.
  • Agent Runtime Security: Familiarity with agent frameworks, tool-call governance, sandboxed execution, Open Shell-like runtime substrates, MCP-style tool…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary