
This role owns Ambi's US↔China data-compliance boundary and builds the AI-agent tooling that lets the China R&D team operate safely without crossing it. Ambi's compliance model requires user data and related operations to stay in the US; the China team can't directly access sensitive data or production systems. So this engineer owns day-to-day operations of the US production environment (data storage, key management, decryption services) and designs/builds an AI-agent platform that lets the China R&D team perform operational tasks — deployments, log lookups, monitoring queries — through conversational/tool-calling interfaces (function calling, MCP) instead of direct system access. It's a rare blend of DevOps/SRE + security/compliance + applied AI-agent engineering, working closely with legal counsel and coordinating constantly with a China-based team across time zones and languages.
What You'll Do
- Own day-to-day operations of the US production environment: data storage, key management, decryption services
- Design and build an AI-agent platform giving the China R&D team a safe, indirect way to operate (deployments, log lookups, monitoring) via function calling / MCP instead of direct access
- Implement agent-layer guardrails — data masking, scoped permissions, approval workflows — so the agent performs tasks but never exposes raw sensitive data
- Maintain complete, auditable logs of all operations
- Work with legal counsel to implement US data-compliance requirements (e.g., CCPA) on the technical side
- Manage access control, security monitoring, and incident response for US infrastructure
Requirements
- DevOps/SRE or infrastructure engineering experience; cloud (AWS/GCP/Azure), Kubernetes, CI/CD
- Experience building AI-agent systems; LLM tool-calling and agent frameworks (LangChain, MCP, etc.)
- Security/compliance background (encryption, key management, access control) — a strong plus
- Comfortable coordinating remotely across time zones and languages with a China-based team
Execution and Ownership
- Owns a boundary end to end — the compliance line is theirs to hold and build around
- Comfortable with ambiguity and a fast-moving pre-launch environment
- Cross-functional with legal, US ops, and China R&D
Nice-to-Have
- Similar cross-border data-compliance architectures (e.g., TikTok-style setups)
- Startup experience
Who Will Thrive Here
- An infra/SRE engineer who's also genuinely built agent tooling (function calling / MCP), not one or the other
- Someone who wants to own a high-stakes compliance boundary and design the guardrails around it
- Security/compliance-minded, comfortable with legal and cross-border data constraints
- Effective coordinating async with a China-based R&D team across languages
- Thrives in a fast, pre-launch, ambiguous environment