Principal Engineer, Confidential AI
Opaque Systems · San Francisco, CA
—
Jul 25, 2026
San Francisco, CA
Jul 26, 2026
What this job asks for AI summary
A principal-level engineering role focused on integrating an open agent-governance stack — covering agent manifests, tracing, and confidential model context protocols — into commercial platform products built on hardware-rooted trust using TEEs such as AMD SEV-SNP, Intel TDX, and NVIDIA Confidential Computing. The work spans policy enforcement inside secure enclaves, scaling confidential agent workloads across multi-cloud Kubernetes environments, shipping production platform offerings, and contributing technically to external standards bodies. Suits a senior engineer with deep systems and confidential computing experience alongside open-source and customer-facing credentials.
Principal level · 10+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 680 people nationally plausibly meet what this posting asks for (software developers). range 140–1,000
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $138,970 (middle half $107,524–$175,762).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
No work location or metro is specified in the posting; the role appears to be remote-friendly given the distributed/multi-cloud scope, but this is not explicitly stated.
The TEE/confidential computing requirement (SEV-SNP, TDX, NVIDIA CC) is listed as a single grouped requirement; all three are captured as separate skills with cross-alternatives to reflect that depth in any one TEE platform likely satisfies the gate.
Go and/or Rust are listed together as a fluency requirement; both are captured as required with each as the other's alternative. Python and agent frameworks are listed in the same sentence — Python is marked required, while the specific agent frameworks (LangChain, LangGraph, CrewAI, AutoGen) are treated as a group where familiarity with any satisfies the requirement; LangChain is the primary with the others as alternatives.
AKS and GKE appear only in the narrative describing the scaling work ('multi-cloud Confidential Containers'), not in a formal requirements section, so they are marked preferred.
Cedar, SBOM/supply-chain, and verifiable credentials are explicitly listed under 'Bonus' and are marked preferred.
The alternative occupation code 15-1299 (Computer Occupations, All Other) is noted because this role spans deep systems/hardware (TEE, attestation) and application software in an emerging confidential-AI niche that doesn't map cleanly to a single standard occupation; 15-1252 Software Developers is the best fit given the primary emphasis on building and shipping platform software.
No compensation figures are provided in the posting.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): cryptographic engineering.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.