Description
NVIDIA's Cloud Engineering & Services team is seeking a Principal Software Engineer to work on the Agent Policy Fabric (APF) Core Platform. The successful candidate will play a critical role in building the foundations for the signed policy, Runtime Policy Verifier, projection, conformance, and failure mode that future APF deployments depend on.
The APF Core Platform is an enterprise governance layer for agentic systems, responsible for signed policy, runtime verification, policy projection, credential mediation, detector verdict handling, and common audit across runtime substrates and enterprise integrations.
Key responsibilities include:
- Building and hardening the Runtime Policy Verifier, signed policy bundle verification, trust-root handling, freshness, rollback protection, subject binding to attested runtime context, revocation checks, and authorization APIs
- Designing Policy Projection to implement deterministic projections from the canonical APF policy into OpenShell-native runtime policy, adapter constraints, credential constraints, audit requirements, and model-visible tool hints
- Creating conformance and verification tests, including golden fixtures, compatibility tests, negative tests, fuzz/property tests, and conformance suites
- Collaborating with runtime owners to engage on public runtime interfaces for projection consumption, runtime context attestation, approved adapter paths, direct egress verification, and admission/rejection semantics
- Driving architecture maturity by defining versioning, schema compatibility, latency budgets, availability behavior, fail-closed defaults, last-known-good policy handling, and engineering review artifacts
- Evolving technical specifications and turning working-draft contracts into engineering artifacts
Requirements:
- Bachelor's degree with 15+ years of industry experience in systems software, security engineering, distributed systems, or policy infrastructure
- Strong programming skills in Rust, Go, C++, or Python
- Experience designing production services, APIs, schemas, policy engines, authorization systems, or signed artifact pipelines
- Familiarity with Linux systems, IPC or service-to-service APIs, protobuf/gRPC or equivalent wire formats, CI, test automation, release engineering, and cloud or enterprise deployment environments
- Practical experience with authorization, cryptographic signatures, trust roots, revocation, subject binding, rollback protection, secure-by-default failure handling, and zero-trust architecture patterns
Preferred qualifications:
- Experience with OPA/Rego, Cedar, Zanzibar-style authorization, policy compilers, sandbox policy, or runtime enforcement systems
- Familiarity with agent frameworks, tool-call governance, sandboxed execution, OpenShell-like runtime substrates, MCP-style tool routing, or credential isolation for agents
- Experience with Sigstore, TUF, in-toto, HSM-backed signing, package provenance, signed configuration, or enterprise trust-root distribution
- Formal or adversarial verification experience using property testing, model checking, symbolic execution, red-team findings, or bounded verification
- Experience contributing to RFCs in identity, supply-chain, or policy spaces
This listing is enriched and indexed by YubHub. To apply, use the employer's original posting:
https://nvidia.wd5.myworkdayjobs.com/en-US/NVIDIAExternalCareerSite/job/US-CA-Santa-Clara/Principal-Software-Engineer--Agent-Policy-Fabric_JR2019848