13 Aug
|
Boxxkite
|
India
Location: Remote (India) · Type: Full time, founding team
About boxxkite
boxxkite is a self-hostable, Kubernetes-native sandbox for AI agent code execution — one isolated pod per session, network access denied by default. We're open source (Apache 2.0), with a hosted cloud offering on top. Security isn't a feature for us, it's the whole product: we run arbitrary, agent-generated code for a living, so our isolation model is our reputation.
Why this role exists
We need someone who doesn't just review our Kubernetes manifests and network policies — we need someone who runs the thing for real, tries to break out of the sandbox on purpose, and tells us the truth about what they find. Right now that job is done by one person, part-time, alongside everything else.
What you'll do
- Own the isolation model end to end: pod security context, network policies, the sidecar's privilege boundary, egress controls
- Stand up real clusters (not just review YAML) and stress-test them — try to escape the sandbox, try to reach the host, try to talk to another tenant's pod
- Own the security-review gate on every PR that touches deploy/, sidecar/, or the sandbox manager's security-context construction
- Build out the audit-log and takeover-channel security story further (we already do tamper-evident hash-chained audit logs; help us go further)
- Be the person who says "no, that's not safe to ship" and is right about it
What we're looking for
- Real production Kubernetes experience — not "used it," but configured RBAC, network policies, and pod security standards for a multi-tenant system
- A genuine offensive mindset: you'd rather find the hole yourself than have a researcher find it first
- Comfortable reading and writing Go or Python at a systems level (our sidecar is Python/FastAPI; comfortable moving between languages)
- Bonus: prior container-escape or sandbox-isolation research, CTF background, or a security disclosure history you can point to
📌 Founding Infrastructure (India)
🏢 Boxxkite
📍 India