Senior Engineer (AI Governance)
Job description
About the role
You will architect and own the governance frameworks that define how AI agents interact with enterprise tools and data. This role centers on building the systems that enforce policy, monitor behavior, and secure the entire lifecycle of tool access. You will design and implement the controls that ensure AI agents operate within the boundaries set by security, compliance, and business stakeholders. You will manage the intricate relationship between identity, permissions, and runtime enforcement for AI-driven workflows. Your work will directly determine the trustworthiness and operational safety of AI deployments within large organizations. You will translate abstract governance requirements into concrete, scalable software systems that protect the enterprise without hindering innovation. This position requires a deep understanding of security principles and the ability to communicate effectively with both technical and non-technical audiences. You will be a foundational member of the engineering team, shaping the standards and practices that define StackOne's approach to AI infrastructure.
Key facts
What you'll do
- Oversee the complete lifecycle of tool access, encompassing enrollment, provisioning, credential rotation, and revocation for AI agents.
- Design and implement policy enforcement engines that dictate which AI agents can interact with specific tools, scopes, and datasets based on defined rules.
- Develop ongoing posture assessment systems that identify risky scopes, outdated permissions, and anomalous usage patterns across AI agent interactions.
- Create high-performance instrumentation and telemetry mechanisms to monitor tool interactions while ensuring no added latency in the request path.
- Enhance identity integrations through OAuth 2.1, Single Sign-On (SSO), and System for Cross-domain Identity Management (SCIM) to maintain alignment with enterprise identity protocols.
- Establish detection and response strategies to recognize, investigate, and mitigate anomalous or potentially harmful behaviors exhibited by AI agents in production.
- Collaborate closely with cross-functional teams, including product, security, and operations, to ensure cohesive governance policies and security measures.
- Conduct rigorous testing and validation of governance and security systems to guarantee reliability, performance, and compliance with internal and external standards.
- Stay current on the latest trends, threats, and technologies in AI governance and security to continuously evolve and improve organizational systems.
- Provide mentorship, guidance, and technical leadership to junior engineers, fostering a culture of learning, curiosity, and responsible innovation within the team.
- Document all processes, system designs, governance frameworks, and operational procedures to ensure clarity, consistency, and effective knowledge sharing.
- Partner with infrastructure teams to integrate governance capabilities into the broader StackOne platform, ensuring seamless interoperability and scalability.
- Analyze audit logs and access patterns to generate insights that inform improvements in security controls and user experience.
- Evaluate and recommend new tools, libraries, and frameworks that can enhance the efficiency and effectiveness of governance operations.
Requirements
- Demonstrated experience managing production systems from initial conception through deployment and ongoing maintenance in a live environment.
- Familiarity with the development or maintenance of API gateways, Mobile Device Management (MDM) or Unified Endpoint Management (UEM) platforms, and Endpoint Detection and Response (EDR) or Extended Detection and Response (XDR) systems.
- Proven track record in designing and implementing policy or rules engines, with a focus on model creation, evaluation logic, and runtime enforcement mechanisms.
- In-depth knowledge of identity management systems and protocols, including OAuth/OIDC, SAML, Single Sign-On (SSO), and SCIM, with a strong emphasis on the principle of least privilege.
- Experience with telemetry, observability, and instrumentation practices, particularly as they relate to monitoring and securing the request path in distributed systems.
- Hands-on experience with AI agents, including the development or utilization of Managed Control Plane (MCP) servers and the implementation of robust governance guardrails.
- A strong understanding of security and compliance frameworks, with the ability to apply practical controls that align with organizational risk tolerance.
- The ability to work effectively in a hybrid environment, balancing independent focus with collaborative team discussions during scheduled working hours.
Nice to have
- Expertise in security domains such as vulnerability management, threat detection, or compliance with established frameworks like SOC 2 and ISO 27001.
- Experience in creating products, tools, or APIs specifically designed for developer consumption and adoption.
- A background of meaningful contribution to open-source projects, technical specifications, or the creation of detailed engineering documentation.
Practical notes
This position is hybrid, typically requiring two days per week in our London office, although we are open to discussing flexible work arrangements that accommodate individual needs. The compensation package includes EMI share options as part of the total rewards strategy. Benefits encompass 25 days of annual leave, with additional days accrued based on tenure, along with private health insurance that covers dental and optical care. There is a daily lunch allowance of £15 to support meal expenses during office days, a £1,000 allowance for home office setup supplemented by an annual £500 top-up for ongoing needs, and access to Cycle2Work and electric vehicle schemes to support sustainable commuting. The team organizes annual offsite events in attractive locations such as Croatia and Portugal, promoting team bonding, collaboration, and professional growth in a relaxed environment.