Live opening · Posted 6 days ago

Head of Product Engineering

Vantio AI · Pittsburgh, PA (Remote)
Linkedin Yes
You are 6 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 6 days ago
CompanyVantio AI
LocationPittsburgh, PA (Remote)
Work modeYes
SourceLinkedin
Listed6 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
11 min from Linkedin publishing this role to us finding it
9 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
74,235 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

VANTIO
Vantio AI, Inc. · Pittsburgh, PA · vantio.ai
Head of Product Engineering
Vantio AI, Inc. · Pittsburgh, PA or Remote (US Eastern overlap)
About Vantio
Vantio is building the infrastructure control layer for autonomous AI.
Organizations are deploying AI agents faster than they can answer a basic question: what is this agent actually authorized to do, and what proves it? Application-level wrappers and policy documents do not answer that. We think the answer has to live below the agent — on the infrastructure itself.
Our product suite is three planes:
Optics observes supported agent activity — destination, process, volume, timing — without storing prompts or completions.
Phantom Engine enforces authority at the kernel on enrolled Linux hosts, including when an agent leaves the expected application path. Patent pending.
Vantio Enterprise makes delegated authority owned, bounded, reviewable, revocable, and auditable.
The interesting part is not any one plane. It is the chain between them — correlating what the application layer recorded against what the kernel actually saw.
The role
You would own the product suite. All three planes, end to end: the architecture, the specification it is proved against, the engineering, the testing, and the technical direction as agent capability keeps increasing.
This is a hands-on principal-level seat, not a management one.
What you would work on
Non-disableable enforcement: LSM-BPF hooks, program and map pinning, tamper detection on the event path, fail-closed behavior when authority state is lost.
Portability onto Linux hosts we do not operate — CO-RE and BTF, across kernel versions and distributions we did not choose.
Cross-plane correlation: reconciling kernel-observed activity against application-layer records, and making the gap meaningful rather than noisy.
Evidence customers can verify independently of us — append-only records, durable ledgers, exports that survive scrutiny.
A vendor-neutral control specification defining the invariants the suite is proved against — one that other platforms could integrate with, and that we can be falsified against.
Supportability as a first-class product concern: install, enroll, upgrade, rollback, uninstall, and honest disclosure of unsupported paths.
The five-year architecture: hardware anchoring, identity and authority modeling across agents and workloads, and where a kernel-anchored authority model holds or breaks as agents get more capable.
What we are looking for
Required:
Production eBPF enforcement experience — not tracing. You have shipped programs that return a denial and block the operation, not just emit telemetry. This distinction matters more to us than years of experience.
Strong Linux kernel internals, and fluency with the BPF verifier as a security boundary rather than an obstacle.
CO-RE and BTF portability in the real world — you have moved an agent across kernels and distributions and dealt with helpers, map types, and attach points that were not there.
Rust, or the willingness to go deep in it quickly. Our kernel layer is Rust.
Hands-on with TC and egress enforcement, uprobes, process and cgroup scoping.
You have taken a host-level agent from working-in-the-lab to running on customer infrastructure you did not control — and owned what happened next.
Valued:
Authorization architecture — identity and delegation modeling, multi-tenant isolation.
Evidence and audit design.
Kubernetes node-agent deployment under capabilities rather than blanket privilege.
Specification writing that outlived the implementation it was written for.
Prior work on Falco, Tetragon, Cilium, Tracee, Aya, or comparable commercial agents.
How we work
Worth knowing before you apply, because it is not for everyone:
We do not round up. There is a hard internal line between what is shipped and proved versus what is on the roadmap, and it holds in code comments, documentation, sales conversations, and this posting.
We do not use absolute language. No unbreakable, no tamper-proof, no cannot be bypassed. Security products that talk that way are lying, and customers eventually find out.
Producing a result is not the same as proving it. Independent verification precedes any claim that something works.
Scope is deliberately narrow: Linux host authority. Not endpoint detection, not network security products, never physical-safety functions. We would rather be excellent at one boundary than adequate at five.
Honest context on stage
We would rather you hear this from us than discover it in month two.
Vantio is early. The suite is proven in our own lab and on our own infrastructure. It has not yet been installed on a customer host, and we do not have design partners in production. Getting there is the central objective of this role, and it is the work we most need help with.
If you want a role where the hard architectural questions are already answered, this is not it. If the appeal is that they are not, we should talk.
Practicalities
Pittsburgh, PA preferred; remote considered with US Eastern overlap.
Principal or staff-plus level. Meaningful equity — we will be direct about the tradeoff between cash and ownership.
Reports to the CEO. Path to CTO on written criteria, shared at offer.
Applying
Email zach@vantio.ai. Skip the cover letter.
Instead, tell us about one time you shipped kernel-level enforcement that had to hold on infrastructure you did not control — what broke, and what you changed. If your work is public, send links and tell us which parts are yours.
If you would rather start with a conversation than an application, that is fine too.

Work arrangement
Yes

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App