Staff AI Platform Engineer
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 1d ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 30d ago
The date the source published, not the day we noticed it (2026-09-01). Last seen at its source 1h ago.
We have tracked this listing since 11 Sep 2026 (20 days). The employer's own board has carried it every time we have read it, most recently 1 hour ago.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
San Francisco
The description states no restriction of its own. This is the source's own tag.
Pay
$141k–194.7k/yr
Read out of the job description by us, not from a structured field. Shown in the posting's own currency and period; we never convert.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
lever employer's own board first seen 20d ago · last seen 1h ago
The listing
What you will do
- Drive the business-side Bedrock runtime and gateway configuration - model access, cost attribution, content-filtering guardrails, model pinning, and quota management, behind an AWS/Okta-SSO'd gateway - co-owned with our DevX lead, who leads the shared-substrate architecture.
- Build and run the MCP fleet - ship, secure, and patch self-hosted and managed MCP servers for business apps and databases, and own the MCP registry. Partner with IT to graduate MCPs into stable, IT-managed assets.
- Make the secure path the easy path without administering identity or devices yourself: author the MDM config payload and the Okta-group-to-IAM mapping that IT pushes and enforces, and specify the desktop client setup and auth flows for non-technical employees.
- Build the AI and agent-triggered automations (approvals, spend alerts, agent-initiated workflows); general business automation stays with IT.
- Own the technical direction for the agent-hosting substrate other teams build on - the design docs and standards, not just the code. There is no existing pattern today; you set it, and other teams adopt it as their default.
- Define what "healthy" and "safe to ship" mean for every agent and MCP server on the platform - the cost, usage, and reliability telemetry (the Bedrock-to-Snowflake pipeline, identity-matched, with threshold alerting), plus a tiered-autonomy model: what stays read-only, what can act, what needs a human in the loop or a rollback path.
- Build the governance that standard requires. Route workflows by data sensitivity, enforce least privilege and auditability, and keep unproven models sandboxed away from production data.
- Drive alignment across IT, Security, and DevX on the platform's direction - get multiple teams building against a written standard without owning their roadmaps.
What you will bring with you
What we look for
When you join Sysdig, you can expect
- Extra days off to prioritize your well-being
- 401(k) Retirement Savings Plan with a 3% company match
- Maternity and Parental Leave
- Mental health support for you and your family through the Modern Health app
- Full health benefits package for you and your family