
What you will do
- Drive the business-side Bedrock runtime and gateway configuration - model access, cost attribution, content-filtering guardrails, model pinning, and quota management, behind an AWS/Okta-SSO'd gateway - co-owned with our DevX lead, who leads the shared-substrate architecture.
- Build and run the MCP fleet - ship, secure, and patch self-hosted and managed MCP servers for business apps and databases, and own the MCP registry. Partner with IT to graduate MCPs into stable, IT-managed assets.
- Make the secure path the easy path without administering identity or devices yourself: author the MDM config payload and the Okta-group-to-IAM mapping that IT pushes and enforces, and specify the desktop client setup and auth flows for non-technical employees.
- Build the AI and agent-triggered automations (approvals, spend alerts, agent-initiated workflows); general business automation stays with IT.
- Own the technical direction for the agent-hosting substrate other teams build on - the design docs and standards, not just the code. There is no existing pattern today; you set it, and other teams adopt it as their default.
- Define what "healthy" and "safe to ship" mean for every agent and MCP server on the platform - the cost, usage, and reliability telemetry (the Bedrock-to-Snowflake pipeline, identity-matched, with threshold alerting), plus a tiered-autonomy model: what stays read-only, what can act, what needs a human in the loop or a rollback path.
- Build the governance that standard requires. Route workflows by data sensitivity, enforce least privilege and auditability, and keep unproven models sandboxed away from production data.
- Drive alignment across IT, Security, and DevX on the platform's direction - get multiple teams building against a written standard without owning their roadmaps.
What you will bring with you
- 6+ years in software engineering, platform engineering, or DevOps, including ownership of something in production that others depended on.
- Hands-on AWS - IAM, ECS or Lambda, CloudWatch, and working VPC knowledge. Required, not a bonus.
- Full-stack range - backend services, APIs, CI/CD, containerized deployments.
- Builder - you can write an MCP server or API integration from scratch, not just wire up a managed connector.
- Hands-on with LLMs - comfortable with LLM APIs, prompt engineering, and agent development; you've shipped something with them.
- Self-direction - you can take an underspecified task and figure out the ambiguous parts to create impactful solutions.
What we look for
- A bias to ship, and to automate the thing you just did by hand.
- Willingness to own the boring parts: upgrades, credentials, quotas, on-call reality.
- Candor: you raise problems and disagreements early, including when a platform choice looks wrong.
- Judgment about when to buy instead of build. We would rather run a small, coherent stack than a perfect, sprawling one.
When you join Sysdig, you can expect
You will be redirected to the company website to complete your application.







