boxxkite
← All roles

Founding Infrastructure & Security Engineer

SecurityRemote (India)Full-time · Founding team

Own boxxkite's isolation model end to end: pod security context, network policy, the sidecar's privilege boundary, and egress control. Run real clusters, try to escape them on purpose, and tell us the truth about what you find.

Apply →

About boxxkite

boxxkite is a self-hostable, Kubernetes-native sandbox for AI agent code execution — one isolated pod per session, network access denied by default, with a framework-agnostic tool surface on top. The core is open source under Apache 2.0, and there's a hosted beta running the same code.

We run arbitrary, agent-generated code for a living, so the isolation model isn't a feature — it is the product, and it is our reputation. The security page and the repo's SECURITY.md are the honest version of where that stands today, including what we haven't solved.

Why this role exists

  • Security isn't a feature here, it's the whole product — we run arbitrary, agent-generated code for a living, so the isolation model is our reputation.
  • We don't need someone to review our Kubernetes manifests. We need someone who runs the thing for real, tries to break out of the sandbox on purpose, and reports back honestly.
  • Today that job is done by one person, part-time, alongside everything else.

What you'll do

  • Own the isolation model end to end — pod security context, network policies, the sidecar's privilege boundary, egress controls.
  • Stand up real clusters, not just review YAML, and stress-test them: escape the sandbox, reach the host, talk to another tenant's pod.
  • Own the security-review gate on every PR touching deploy/, sidecar/, or the sandbox manager's security-context construction.
  • Push the audit-log and takeover-channel security story further — we already ship tamper-evident hash-chained audit logs; take them somewhere better.
  • Be the person who says “no, that's not safe to ship” and is right about it.

What we're looking for

  • Real production Kubernetes experience — not “used it”, but configured RBAC, network policies, and pod security standards for a multi-tenant system.
  • A genuine offensive mindset: you'd rather find the hole yourself than have a researcher find it first.
  • Comfortable reading and writing Go or Python at a systems level — our sidecar is Python/FastAPI, and you should move between languages without ceremony.
  • Bonus: container-escape or sandbox-isolation research, a CTF background, or a disclosure history you can point to.

Compensation

Competitive cash, plus meaningful early-employee equity.

We benchmark cash against the top of the market for the level and location rather than against what we can get away with, and every founding hire gets a real equity grant. We'll put the specific band on the table in the first call, before you spend time on anything else.

How we hire

  1. 01

    A 30-minute call

    What you've built, what broke, what you'd do differently. No trivia, no whiteboard.

  2. 02

    A take-home, 4–5 hours

    Unpaid, and hard-capped at 4–5 hours precisely because it is. You'll do it against the real product — hosted signup or a self-hosted clone — not a toy repo. Five calendar days, and ask for more if you need it.

  3. 03

    A walkthrough, 60 minutes

    You drive. Two-thirds on what you built, one third on what you deliberately left out — the omissions are usually the interesting part.

  4. 04

    A conversation with the founder

    Comp, equity, what the first 90 days actually look like, and your questions.

How to apply

Send us something you've actually broken — a CTF writeup, a real vuln you found, a sandbox you escaped — more than a resume.

Prefer email? Write to careers@boxxkite.com directly instead.

Curious what the take-home looks like? Go create a free account or clone the repo and run something in a sandbox. Every one of our assignments starts there.

Other open roles