Sword HealthRemote · Remote - Portugal€50k-€72k
Thinking Machines LabPosted 2d ago
Software Engineer, Sandboxing
Software Engineer, Sandboxing at Thinking Machines Lab scores 85 out of 100 on AI centrality, which makes it a Level 4 role on this board.
AI in this role
Design, build, and operate sandboxed execution infrastructure for safely running untrusted model-generated code.
The mission of Thinking Machines is to build AI that extends human will and judgment. We are training frontier models with Inkling, developing Tinker to let people make models their own, and crafting interfaces that broaden human-AI communication. We believe the future worth building is human, and we're hiring people who want to build it.
About the Role
Our models and agents increasingly need to run code, use tools, and take actions in the world — safely, reliably, and at scale. The Core Services team builds the sandboxing infrastructure that makes this possible: the isolated execution environments where models write and run code, browse, and interact with tools, both for our researchers during training and for external users building on Tinker.
We're hiring a software engineer to help design, build, and operate this sandboxing platform. You'll work on the systems that isolate and constrain untrusted, model-generated code, and that scale to support thousands of concurrent executions across the company. This is foundational infrastructure: every research experiment and every product surface that lets a model take action depends on it being fast, secure, and dependable.
What You'll Do
Design, build, and operate sandboxed execution environments for running untrusted, model-generated code and tool calls at scale.
Improve isolation boundaries using technologies such as containers, microVMs, or gVisor-style kernels, balancing security against startup latency and throughput.
Build the scheduling, resource-management, and lifecycle systems that provision, reuse, and tear down sandboxes efficiently under heavy concurrent load.
Partner with researchers and Tinker's product team to expose sandboxing primitives that are simple to use and hard to misuse.
Instrument sandboxes for observability and abuse detection, and respond to novel escape or exploitation attempts as they're discovered.
Own reliability and performance of the sandboxing platform end-to-end, from API design down to the underlying virtualization layer.
Skills and Qualifications
Minimum qualifications:
Bachelor's degree or equivalent experience in computer science, engineering, or similar.
Proficiency in at least one backend language (we use Python or Rust).
Experience building or operating isolation or virtualization technology, such as containers, microVMs (e.g. Firecracker, Cloud Hypervisor), or sandboxed runtimes (e.g. gVisor, Kata Containers).
Solid grounding in Linux internals relevant to isolation: namespaces, cgroups, seccomp, capabilities, and networking.
Comfort operating across the stack and owning projects end-to-end.
Thrive in a highly collaborative environment involving many, different cross-functional partners and subject matter experts.
Preferred qualifications:
Experience securing systems that execute untrusted or adversarial code, including threat modeling and hardening against sandbox escapes.
Familiarity with running large-scale, multi-tenant infrastructure on Kubernetes or similar orchestration systems.
Experience with performance-sensitive systems programming and reducing cold-start latency for ephemeral compute.
Track record of contributing to open-source infrastructure or security tooling.
Interest in how AI agents use tools and code execution, and how that shapes the design of safe execution environments.
Logistics
Location: This role is based in San Francisco, CA.
Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $300,000 - $350,000 USD.
Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- How do you decide when an AI agent can act on its own versus asking for approval first?
- Tell me about a project where virtualization was part of your work. What did you do?
- Tell me about a project where containers was part of your work. What did you do?
- Tell me about a project where microvms was part of your work. What did you do?
- Tell me about a project where backend engineering was part of your work. What did you do?
Adapt your resume
- List these exact terms on your resume: AI Agents, Virtualization, Containers, Microvms, and Backend Engineering. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
- Lead with what you built, trained or shipped — this role is judged on the AI system itself, not the tools around it.
Want your resume actually rewritten for this job?
The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.
Similar roles
Software Engineering roles rated Level 4 at other companies.
GitLabRemote · Bangalore, India
AmazonUS, TX, Austin$116k
AmazonUS, CA, Cupertino$129k
AmazonIN, TS, Hyderabad
More jobs at Thinking Machines Lab
Thinking Machines LabSan Francisco$300k-$360k
Thinking Machines LabSan Francisco$300k-$360k



