ABOUT ASLAN Our national security apparatus was designed for an adversary that congregated and operate in the physical world. The threats disrupting our way of life today have gone faceless, borderless, and beyond the reach of any human operator. Aslan builds the autonomous agents that reach them, unmask them, and stop them, before a life can be lost, a household can be bankrupted, innocence can be stolen, or our can be nation subverted. In 12 months we've gone from founding to live operational tasking and pilots across multiple national security and law enforcement partners. We've proven it works. This role makes it permanent. We’ve raised $20M to date from Khosla Ventures, XYZ, BoxGroup, 2048, Liquid 2, Precursor Ventures, and others. ROLE We're looking for a platform engineer to own how Aslan's system gets into the hands of operators and stays running once it's there. Our agents need open internet connectivity to do their job, but the operators who task them and consume the intelligence sit in government environments with real security and compliance requirements. Your job is making those two worlds work together cleanly, repeatably, and in a way that satisfies an Authorizing Official. Today that means self-contained deployment kits that one engineer can transport and stand up in an afternoon. Near-term it means permanent racked installations at customer sites, a cloud backend that serves as the management plane across multiple deployments, support for IC environments with tighter security postures, and the ability for operators across multiple sites to work from a single pane. You'll build all of it with the compliance architecture baked in from day one. The most important architectural decision you'll own is the authorization boundary: keeping the internet-connected execution layer outside the ATO boundary while building an operator interface inside it that meets NIST 800-53 controls and can be assessed and authorized without turning every deployment into a year-long compliance project. Get this right and every future ATO is smooth. Get it wrong and we're re-architecting under pressure. RESPONSIBILITIES - Own the full deployment lifecycle from portable field kits through permanent installations at customer sites, making every deployment predictable and repeatable regardless of form factor or environment. - Architect the system's security and compliance posture from day one, including the authorization boundary, NIST 800-53 controls, and the documentation an Authorizing Official needs to say yes. - Build the operator interface to support multiple concurrent users with role-based access control, per-user audit trails, and session management. - Own the compute and orchestration layer across constrained edge hardware and cloud, including the synchronization between them. - Build the cloud backend that serves as the management plane, update distribution, and centralized monitoring as deployments multiply. - Build the intelligence output pipeline from each deployment to the customer, evolving from manual delivery toward automated transfer as requirements demand. - Adapt the deployment and security model for customer environments with varying network constraints, classification levels, and security postures. WHAT YOU BRING - 5+ years of platform or infrastructure engineering. Senior judgment, not just senior title. - You've gotten a system through RMF/ATO, or built one that did. Not theoretical. - You've shipped on constrained hardware in the field and in the cloud, and made them behave the same. - Containerization, orchestration, infrastructure-as-code, Linux. Instinctive, not reference-manual. - You think in trust boundaries and attack surfaces and can explain both to an engineer and an AO. - You build things that run unattended and recover without you. - DMV-based, occasional time at customer sites. BONUS POINTS - You've deployed into IC or classified environments and lived to tell about it - FedRAMP experience, particularly the agency ATO path - Device orchestration or fleet management at scale - CMMC Level 2 certification or building within a compliant enclave - Cross-domain transfer mechanisms between classification levels - ML/AI serving in production (GPU scheduling, model serving, inference optimization) - Active, recent, or eligibility for a U.S. security clearance (TS preferred)