// agents · open role
Agentic Security Engineer
Secure the design of our agents, their tools, and the limits of their autonomy.
// about the role
unpwnd is a security company building an autonomous purple team — a swarm of AI agents that audits code, proves what it finds, and hands back the fix. You’ll own the security of that swarm itself: how agents are scoped, what their tools can reach, and what happens when an agent is wrong.
// what you’ll do
- Design the boundaries between agents, their tools, and the systems they touch.
- Build the guardrails that keep an autonomous swarm inside its mandate — scoping, permissions, sandboxing.
- Harden every tool an agent can call: least privilege, validated I/O, bounded blast radius.
- Red-team our own agents — prompt injection, tool abuse, and exfiltration paths.
// what we’re looking for
- You’ve shipped production systems where LLM agents call real tools.
- You threat-model autonomy by instinct: what an agent can reach, and the cost when it’s wrong.
- You’re fluent in sandboxing, capability scoping, and untrusted-input handling.
- You design for failure modes, not just the happy path.
// bonus
- Internals of an agent framework or orchestration runtime.
- Isolation tech — gVisor, Firecracker, seccomp, WASM sandboxes.
- An offensive-security background.
// how we hire
A short async intro, a paid work sample on a real problem, then conversations with the team. No whiteboard trivia, no take-home marathons.
Applying · Agentic Security Engineer
Tell us why you.
No résumé, no cover letter. Your GitHub, where to reach you, and a paragraph on why unpwnd.