×
Register Here to Apply for Jobs or Post Jobs. X

Principal Software Engineer, Agent Policy Fabric

Job in Santa Clara, Santa Clara County, California, 95053, USA
Listing for: NVIDIA Gruppe
Full Time position
Listed on 2026-07-24
Job specializations:
  • Software Development
    DevOps, Backend Developer
Salary/Wage Range or Industry Benchmark: 272000 - 431250 USD Yearly USD 272000.00 431250.00 YEAR
Job Description & How to Apply Below

Position Overview

NVIDIA's Cloud Engineering & Services team is seeking a Principal Software Engineer for the Agent Policy Fabric (APF) Core Platform. The candidate will mature APF v0 proof‑of‑life into a robust core platform to enable governed agent action.

Responsibilities
  • Own APF Core Services: build and harden the Runtime Policy Verifier, signed policy bundle verification, trust‑root handling, freshness, rollback protection, subject binding to attested runtime context, revocation checks, and authorization APIs used by APF‑compatible enforcement points.
  • Design Policy Projection: implement deterministic projections from the canonical APF policy into Open Shell‑native runtime policy, adapter constraints, credential constraints, audit requirements, and model‑visible tool hints while preserving the atomic projection‑admission contract.
  • Build Conformance and Verification: create golden fixtures, compatibility tests, negative tests, fuzz/property tests, and conformance suites that prove APF‑compatible runtimes and adapters honor the same contract.
  • Collaborate with Runtime Owners: work with Open Shell and Infrastructure engineers on public runtime interfaces for projection consumption, runtime context attestation, approved adapter paths, direct egress verification, and admission/rejection semantics.
  • Land the Runtime integration surfaces: drive cross‑team work with Open Shell and other runtime owners to land public substrate interfaces APF composes against – runtime‑context attestation, approved adapter path declaration, projection acceptance and rejection semantics, quarantine, and stop‑session hooks. Land each as a public RFC or PR.
  • Drive Architecture Maturity: define versioning, schema compatibility, latency budgets, availability behavior, fail‑closed defaults, last‑known‑good policy handling, and engineering review artifacts for Product Security, Fleet, Identity, and partner teams.
  • Evolve technical specifications: write specifications, defend bounded claims in security and architecture reviews, drive open‑decision resolution, and turn working‑draft contracts into engineering artifacts that Product Security, Fleet, Identity, and partner runtimes can adopt.
Qualifications
  • Bachelor's degree (or equivalent experience) with 15+ years of industry experience in systems software, security engineering, distributed systems, or policy infrastructure.
  • Strong programming skills in Rust, Go, C++, or Python; experience designing production services, APIs, schemas, policy engines, authorization systems, or signed artifact pipelines.
  • Linux systems, IPC or service‑to‑service APIs, protobuf/gRPC or equivalent wire formats, CI, test automation, release engineering, and cloud or enterprise deployment environments.
  • Practical experience with authorization, cryptographic signatures, trust roots, revocation, subject binding, rollback protection, secure‑by‑default failure handling, and zero‑trust architecture patterns.
  • Architectural leadership: ability to write streamlined technical specifications, align multiple engineering owners, defend bounded claims, and turn working‑draft architecture into buildable interfaces without over‑scoping the runtime.
Preferred Experience
  • Runtime Policy Systems: experience with OPA/Rego, Cedar, Zanzibar‑style authorization, policy compilers, sandbox policy, or runtime enforcement systems.
  • Agent Runtime Security: familiarity with agent frameworks, tool‑call governance, sandboxed execution, Open Shell‑like runtime substrates, MCP‑style tool routing, or credential isolation for agents.
  • Supply Chain and Signing: experience with Sigstore, TUF, in‑toto, HSM‑backed signing, package provenance, signed configuration, or enterprise trust‑root distribution.
  • Formal or Adversarial Verification: experience using property testing, model checking, symbolic execution, red‑team findings, or bounded verification to constrain security claims.
  • Standards engagement: experience contributing to RFCs in identity, supply‑chain, or policy spaces (IETF, OpenID Foundation, FIDO Alliance, CNCF, NIST).
Benefits and Compensation

Your base salary will be determined based on location, experience, and the pay of employees in similar positions. The base salary range is $272,000 – $431,250 USD. You will also be eligible for equity and benefits. This position offers a competitive salary and a generous benefits package.

Equal Opportunity Statement

NVIDIA is committed to fostering an inclusive work environment and is an equal‑opportunity employer. NVIDIA does not discriminate on the basis of race, religion, color, national origin, gender, gender expression, sexual orientation, age, marital status, veteran status, disability status, or any other characteristic protected by law.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary