Staff Platform Engineer, AI Agent Infrastructure & Security
AI summary of the role
Staff Platform Engineer owning the secure, multi-tenant runtime and security model for Maestro, Félix's internal AI teammate that operates across Slack and toolchains at scale (500+ per-user pods on private GKE).
What you’ll do
- Own the Maestro platform architecture: multi-tenant control plane and per-user runtime on private GKE, including Kubernetes operators, Helm, gVisor-sandboxed pods, and per-user isolation primitives.
- Lead the security model end to end: identity separation, JIT short-lived scoped tokens, encrypted OAuth token vault, zero-credential egress, and policy layer for credential use.
- Harden service-to-service trust with Istio mTLS + SPIFFE, signed request claims, and deny-by-exception networking.
- Operate the fleet at scale: fleet health, scale-to-zero, resource packing, and SRE-grade availability for 500+ pods.
What you’ll bring
- 8+ years in software/infrastructure engineering with a track record owning large-scale, security-critical distributed systems.
- Deep hands-on Kubernetes in production: operators/CRDs, controller-runtime, Helm, gVisor or equivalent isolation, multi-tenancy, fleet operations.
- Strong applied security engineering: SPIFFE/SPIRE, Workload Identity Federation, Istio mTLS, OAuth 2.0/OIDC, JIT credentials, secrets/KMS encryption, zero-trust patterns.
- Excellent Go and/or Python with deep system-architecture judgment.
Technologies
Kubernetes · GKE · gVisor · Terraform · Istio · SPIFFE · OAuth 2.0 · OIDC · OpenTelemetry · Go · Python · Vertex AI
About Felix Pago
WhatsApp-native remittance and immigrant-finance platform that lets U.S. Latinos send money across Latin America using conversational AI and stablecoin-enabled backend rails.
Series B · 100–200 people
Source and classification
Internal deployment & tooling · Evidence for this classification:
technical Staff Platform Engineer to lead the platform and security foundations of Maestro — Félix's internal, identity-aware AI teammate. Maestro already runs at meaningful scale (500+ per-user pods on private GKE) and lives where work happens: Slack, incident rooms, and an emerging agentic intranet, acting across our toolchain (GitHub, Google Workspace, ClickUp, Notion, PagerDuty, New Relic). The interesting problems here are not prompts or models. Once an AI teammate can open a pull request, page an engineer, or query production, the hard questions become identity, credentials, isolation, blast radius, and audit. This is a platform and security role for an agentic system — you'll own the secure, multi-tenant runtime that makes delegated AI work safe at scale. You'll be the technical anchor for Maestro's infrastructure and security within the AI team: architecting the control plane,
More from the job description
About Us At Félix, we're building the financial ecosystem for Latin immigrants in the U.S., starting with a revolution in remittances. Our core product is an AI-powered chatbot built on WhatsApp, allowing our users to send money home as easily as sending a text message. We leverage cutting-edge technology like AI, blockchain, and stablecoins to make cross-border payments faster, more affordable, and more accessible than ever before. We are a hyper-growth Series B company, backed by over $100 million in funding from top-tier global investors, including QED, Castle Island, Switch Ventures, HTwenty, Monashees, and General Catalyst Customer Value Fund. This isn't just about the numbers; it's a testament to the trust our investors have in our vision and our team. Additionally, Félix was selected as an “Endeavour Entrepreneur” and was a recipient of the CrossTech Fintech Startups Award. We are a group of extremely talented and dedicated high-performers, united by our shared obsession with a single goal: empowering our customers. We are all owners of Félix, driven by a bias for action and a true experimentation spirit to get shit done with urgency and focus. Joining Félix means you will be part of a team building a legacy, a company that will outlive us all. This is a rare opportunity to apply your skills to a deeply meaningful mission—serving a community that has been underserved [... source excerpt omitted ...] orkspace, ClickUp, Notion, PagerDuty, New Relic). The interesting problems here are not prompts or models. Once an AI teammate can open a pull request, page an engineer, or query production, the hard questions become identity, credentials, isolation, blast radius, and audit. This is a platform and security role for an agentic system — you'll own the secure, multi-tenant runtime that makes delegated AI work safe at scale. You'll be the technical anchor for Maestro's infrastructure and security within the AI team: architecting the control plane, hardening the runtime, running the fleet, and shaping what the platform needs next as adoption grows. AI is the domain you'll operate in — [... source excerpt omitted ...] I key. Set the technical direction. Define platform and security best practices, mentor senior and mid-level engineers, and map Maestro's next infrastructure needs as it scales. Requirements Experience: 8+ years in software/infrastructure engineering, with a proven track record owning large-scale, security-critical distributed systems end to end. Platform & Kubernetes mastery (Staff bar): Deep, hands-on Kubernetes in production — operators/CRDs and controller-runtime, Helm, runtime isolation (gVisor or equivalent), multi-tenancy, and fleet operations at scale. Strong cloud-native architecture on GCP (or AWS/Azure), and IaC with Terraform. Security & identity depth (Staff bar): S
Employer postings · Data from · Sources