- Jobs
- Always Further (Nono.sh)
- Principal Software Engineer
Principal Software Engineer
Full-timePrincipal
Tech Stack
RustPythonLinux SecurityCryptographyAgent Security
Agent Workflow
Build the layer between agentic reasoning and system execution - intercepting, classifying, and validating every agent intent against security policy. OS-level sandboxing and cryptographic provenance for AI agents.
About the Role
Always Further - Principal Software Engineer Remote (UK Preferred) | Founding engineer role
Founded by the team who created Sigstore (used to secure npm, PyPI, brew, and provide attestations for GitHub releases, Nvidia, and Google for AI model signing). Now building nono.sh agent security tooling.
The company provides OS-level sandboxing and cryptographic provenance for AI agents:
- nono: macOS Seatbelt and Linux Landlock for default-deny access controls
- Sigstore: cryptographic signing for tamper-evident audit trails of agent actions
- Deepfabric: hardened AI models through adversarial testing
Key Responsibilities:
- Build the layer between agentic reasoning and system execution - intercepting, classifying, and validating every agent intent against security policy before it runs
- Design systems that capture and cryptographically verify every instruction and action, maintaining ground truth in environments prone to hallucination and injection
- Architect fine-grained, time-scoped primitives that allow least-privilege permissions with controlled, auditable escalation
- Work with research to stress-test security primitives at scale
- Turn emerging threat vectors (prompt injection, tool misuse, privilege escalation) into adaptive defenses
Requirements:
- Deep Linux kernel security (LSM, seccomp-bpf, namespaces, system call tracing)
- Multi-language production experience
- Strong Rust skills with Python for tooling
- Cryptographic supply chain knowledge (Sigstore/in-toto familiarity valued)
- Comfortable with AI-assisted development tools
- 0-to-1 startup experience
- Clear communication abilities
Compensation: Highly competitive equity stake plus pre-seed base salary (specific figures not disclosed).