Skip to content

Careers

A bug here breaks someone’s laptop.

Not a page load. Not a metric. A machine that a person needs to do their job, possibly several thousand of them at once. Read that sentence again before you apply, because everything about how we work follows from it.

How that changes the work

Rollback is designed before the action is

No remediation ships without a tested rollback procedure and a declared reversibility flag. "We will add rollback later" is not a plan we accept in review.

We ship behind a policy, not a flag

New capability arrives as an action that is approval-required by default, and earns unattended status with evidence. Nothing goes out enabled.

Incident review is blameless and public internally

Every bate — a failed and rolled-back action — is a first-class object with a record. We read them. We publish the aggregate rate on the customer console.

On-call is real and it is compensated

Small rotation, generous handoff, and a hard rule that the person who shipped is the person who is paged.

We write things down

Design docs before code for anything touching the decision path. The audit record is the product; internal legibility is the same discipline pointed inward.

Slow is a valid answer

The sequencing rule we will not break: no customer runs unattended autonomy until the contracts, the insurance, the policy engine, the sandbox, the kill switch and the rollback are all shipped and tested. Nobody gets to argue that one.

Open roles

  • Systems engineer — Talon (Rust)

    Remote · US or EU timezone overlap

    The endpoint agent. Windows service and macOS daemon, sandboxed execution, rollback snapshots, privilege escalation through platform brokers with drop-back in the same call. You will spend real time on the failure paths, because the failure paths are the product.

    work@kestrel.io
  • Backend engineer — Creance & Flightlog

    Remote · US timezone

    The deterministic policy engine and the append-only audit store. This is the code an auditor, an insurer and a hostile security reviewer will read line by line. If you like writing things that are boring, exhaustively tested and provably correct, this is the best job here.

    work@kestrel.io
  • Product engineer — Eyrie

    Remote · US timezone

    The console. A virtualised table that holds 100,000 rows, a policy editor that renders rules as English sentences, and an audit viewer that has to make an autonomous decision legible to someone who is angry. Density and keyboard ergonomics matter more here than motion design.

    work@kestrel.io
  • Security engineer — Quarry review pipeline

    Remote · US timezone

    You own the review gate on every remediation action that ships: authoring standard, sandbox fleet testing, risk tiering, the reversible flag, signing. You will also be the named engineer on customer security reviews, and you have a veto on the trust centre.

    work@kestrel.io

No take-home longer than three hours, and we pay for it. No whiteboard algorithms. You will read a real design doc from the decision path and tell us what you would change, and we will listen, because that is also the job.