You will build and evolve the orchestration layer that runs code in secure, sandboxed execution environments. This platform enables secure execution of user and agent-generated code by enforcing strong isolation guarantees while maintaining a seamless developer experience. You will work at the intersection of container runtimes, system-level security, and developer tooling, shaping how compute is safely executed across MathWorks.
Role & responsibilities:
- Design and develop Go services for orchestrating containerized execution across Docker, Podman, and other sandboxed execution environments
- Manage the full lifecycle of sandboxed execution sessions: provisioning, execution, artifact handling, and teardown
- Design and enforce isolation boundaries to mitigate risks such as credential exposure, data exfiltration, and uncontrolled network access
- Enable cross-platform execution (Linux, macOS, Windows; amd64/arm64)
- Design developer-facing APIs and CLI workflows to simplify secure execution
- Collaborate closely with Security, Reliability Engineering,
and Infrastructure teams to devlier robust and scalable solutions
Minimum qualifications:
- Proficiency with Go Language
- A bachelor's degree and 6 years of professional work experience (or a master's degree and 3 years of professional work experience, or a PhD degree, or equivalent experience) is required.
Additional qualifications:
- Experience with runtime security or monitoring tools (Falco, Sysdig)
- Familiarity with OCI specifications, image registries.
- Experience with Kubernetes or orchestration platforms
- Experience designing developer-facing tools (CLI/API platforms)
- Track record of driving technical direction across team boundaries including the communication, relationship-building, and stakeholder alignment needed to influence engineering practices at an organizational level
- Strong written and verbal communication skills, with the ability to explain complex technical decisions to both engineering and non-engineering audiences