Founding Infrastructure Engineer

Arrows Group — United States · Posted ~3 hours ago

Senior Visa History ✓

Skills

Infrastructure engineering Containers Workload isolation Azure Autoscaling Async worker systems Security Network egress control Azure Container Apps Bicep LLM agents Sandboxing

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Join an early-stage company as a founding infrastructure engineer and own the platform that executes large volumes of AI-agent workloads. You will build secure sandboxing for untrusted code, operate an autoscaling asynchronous worker fleet, manage container infrastructure, control network access, and lead infrastructure decisions as the system scales from zero to hundreds of workers.

Highlights

Founding-level ownership of core infrastructure with major influence over future technical decisions. The role tackles challenging problems in secure sandboxing, large-scale asynchronous workloads, autoscaling, and infrastructure efficiency.

Description

About the Company You'll own the platform every one of our agents runs on — the execution layer that turns a 3,000-sheet drawing set into hundreds of verified engineering findings. That means the async worker fleet, the agent sandboxes, the LLM traffic layer, and the document-processing pipeline underneath all of it. The headline focus is our agent sandboxing platform: sandboxed code execution for LLM agents— warm pools for instant startup, strict isolation, and controlled network egress for untrusted agent-generated code. We run on Azure Container Apps and Bicep today. We look for deep expertise in containers, workload isolation, and Azure infrastructure rather than any specific toolchain. You will lead our infrastructure decisions going forward. About the Role What you'll do: Own the agent sandboxing platform and keep it fast, cheap, and secure as agent traffic grows. Run the async worker fleet that processes thousands of drawing sheets per project, autoscaling from zero to hundreds of jobs and back. Own the LLM traffic layer: keep multi-tenant traffic fair, fast, and metered — every token accounted for in customer billing. Keep streaming reliable: chat and progress updates that survive deploys and disconnects. Scale document processing: rendering, OCR, and extraction pipelines where one project can be tens of gigabytes of drawings. Own CI/CD, reliability, and cost — from the self-hosted runner fleet to incident response to the Azure bill. Ship in the codebase: contribute to our Python/FastAPI backend alongside product engineers. Responsibilities Own the agent sandboxing platform and keep it fast, cheap, and secure as agent traffic grows.Run the async worker fleet that processes thousands of drawing sheets per project, autoscaling from zero to hundreds of jobs and back.Own the LLM traffic layer: keep multi-tenant traffic fair, fast, and metered — every token accounted for in customer billing.Keep streaming reliable: chat and progress updates that survive deploys and disconnects.Scale document processing: rendering, OCR, and extraction pipelines where one project can be tens of gigabytes of drawings.Own CI/CD, reliability, and cost — from the self-hosted runner fleet to incident response to the Azure bill.Ship in the codebase: contribute to our Python/FastAPI backend alongside product engineers.4+ years building and operating backend or distributed systems in production, including cloud infrastructure (Azure, AWS, GCP); Azure preferred. Required Skills Strong Python — our deploy and environment tooling is Python.Deep production container experience. Azure Container Apps or similar preferred; AKS depth transfers.Workload isolation and sandboxing: Linux primitives (namespaces, seccomp, bubblewrap/gVisor-class tooling) and safe execution of untrusted code.Expert infrastructure as code in any major tool — we use Bicep today.CI/CD ownership with GitHub Actions or Azure DevOps.Azure identity and networking: Entra ID, managed identities, RBAC, VNets, private endpoints.Production Postgres and Redis operations.Observability: OpenTelemetry, Log Analytics/KQL, incident response.Rapid prototyping with AI coding agents (Claude Code or Codex), and the judgment to review and verify what they produce.