What you'll own
Fig's product is built around an AI agent that security analysts and detection engineers work with directly. It investigates coverage questions against live enterprise security data, authors and tests detection logic, and tunes noisy alerting.
That agent is already in production with enterprise design partners. Now we need to make it dependable and scalable enough for GA.
You will own that evolution: the agent architecture, its evaluation and quality system, and the production engineering around it. This is a hands-on senior IC role with real architectural authority - you set the technical direction and you write the code.
The agent operates inside customer security environments, where a wrong action can become a customer incident. Correctness, isolation, observability, and evaluation are not polish. They are the product.
What you'll do
Agent architecture: Design the evolution from today's production single-agent system to a multi-agent one: orchestration, task decomposition, runtime and framework choices, and a migration path that does not break what design partners already rely on.
Agent capability: Own the prompts, context, skills, and tool design that make the agent genuinely good at detection engineering across multiple security platforms, not just plausible-sounding.
Evaluation platform: Build the harnesses, judges, and golden datasets that turn "the agent feels better" into a number, plus the CI gates that keep regressions from shipping.
Reliability and safety: Keep long-running agentic sessions healthy in production, and build the isolation and guardrails required of an agent working inside enterprise security environments.
Production debugging: Work real failures from production traces, and turn each one into an eval case that can never regress silently.
Technical direction: Make the calls on architecture, sequencing, and quality bar and be accountable for the outcome, including raising how AI-natively the whole team builds.
Cross-team partnership: Partner with product and customer-facing teams on what the agent should do, and with platform teams on the data and integrations it depends on.
Requirements
Senior engineering depth: You have 6+ years of experience building and operating production software, with strong backend and distributed-systems fundamentals and experience designing APIs and services.
Shipped agents, not demos: You have taken an LLM agent system with tool use, multi-turn interaction, and planning to real users, and you can talk concretely about how it failed and what you did about it.
Architectural judgment: Informed opinions on single-agent vs. multi-agent design, orchestration patterns, and the current framework and SDK landscape, with the pragmatism to pick the boring option when boring wins.
Eval discipline: You have built or owned evaluation for an LLM system, including golden datasets, LLM-as-judge with calibration, and regression gates in CI, and you can quote the metrics you moved.
Tool design instincts: You know when a deterministic tool beats a model call, how to design tool contracts an LLM will not misuse, and how to keep cost and latency under control.
Distributed systems fluency: Streaming, stateful services, and the operational instincts to keep long-running agent sessions alive in production.
Ownership in ambiguity: You can lead an area as a hands-on IC in an early-stage environment with little existing structure. Security domain experience such as SIEM platforms, SOC workflows, detection engineering, or security query languages, and experience with modern agent SDKs and protocols such as MCP, are strong advantages.