Location: Bengaluru
Mission: Live at the intersection of app runtime & security. Protect applications in a fundamental way so that developers can build great application services and not be constantly looking over their shoulder. BlueRock is changing the landscape of App runtime security.
What You'll Build:
BlueRock Agentic Sandbox: Be part of the team developing our flagship multi-language runtime security platform
Deep-Trace Observability: Build the infra that hooks into frameworks like CrewAI, Google ADK, and OpenAI Agents to monitor and intercept malicious intent in real-time
End-to-End Hardening: Secure the entire lifecycle from agent orchestration to execution
Required Qualifications:
Systems Generalist: You have 5+ years of experience and aren't afraid to go below the surface of the API
Python: Ideally, a mastery of the internals like wrapt-based monkey-patching, bytecode manipulation, and custom import hooks
JS/Node.js Wizard: You understand ESM loader hooks and how to handle native addon (.node) integrations
Agent Fluent: You've spent time with LangChain, CrewAI, or similar frameworks.
Experience with instrumentation and observability frameworks like OpenTelemetry, Datadog etc.
Experience working with AI and with AI code generation (such as Claude Code, Cursor, CoPilot)
Experience building and deploying applications to the cloud (such as AWS, GCP, Azure)
Preferred Qualifications:
Experience with protocols like MCP (Model Context Protocol) or A2A
A "Hacker Mindset" (OWASP expertise, understanding deserialization, SSRF, and privilege escalation)
Experience with Container Runtimes (OCI, containers) or a love for Rust
Experience with K8s or similar orchestration frameworks
About BlueRock:
BlueRock is a well-funded, early stage cybersecurity company founded by experienced security minded entrepreneurs. Our mission is to change the game in cybersecurity. Attackers are exploiting in hours. The dependency tree is exploding. Developers are drowning in vulnerability debt. BlueRock changes the game, enabling organizations to shift from chasing CVEs and exploits to proactively protecting the foundations of applications and computing, so that developers can build great applications without looking over their shoulders.


