--- title: 'Senior Engineer (AI Governance) at StackOne' canonical: 'https://feeny.ai/job/senior-engineer-ai-governance-stackone-london-kwjtgz6gf9kx' type: 'job' last_seen: '2026-09-06' --- # Senior Engineer (AI Governance) at StackOne - **Company:** StackOne - **Location:** London, United Kingdom - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-07-14 - **Last confirmed live:** 2026-09-06 - **Apply:** https://jobs.ashbyhq.com/stackone/e8632d34-7a5c-4cdc-994b-6275a4fda308 ## Job description ## About StackOne StackOne is the integration infrastructure for AI agents. Backed by GV and Workday Ventures ($24M raised), we make it possible for any AI agent — whether our customers build it into their product or buy it off the shelf — to take real action across the enterprise stack. Our platform gives agents 430+ connectors and 26,000+ pre-built actions, an AI connector builder for everything not covered yet, and the production layer agents actually need: semantic tool discovery that cuts token use by up to 80%, managed authentication and per-action permissions, the most accurate prompt injection defense on the market, and end-to-end observability. Join us on our fast trajectory to build the future of agentic integrations. Own how enterprises govern the tools their agents can reach: the enrollment, provisioning, policy, posture, and identity-bound access layer that does for agent tooling what MDM and EDR (Jamf, Iru, CrowdStrike) do for devices, and what API gateways do for API traffic, at gateway scale. ## Why this role exists StackOne is the tools gateway for agents: the secure, token-efficient layer through which AI agents reach 200+ enterprise SaaS systems. As enterprises connect agents to real tools and real data, governance becomes the defining problem: who or what may invoke which tool, with which scopes, against which data, under which conditions, and how you catch it when something drifts, misbehaves, or turns into a vulnerability. The mental model What MDM, EDR, and identity platforms did for devices & software access, and what API gateways did for API traffic, applied to the tools agents use: - Enroll & inventory devices → register and inventory the tools agents can reach (servers, APIs, connected accounts) - Provision apps and configs to devices → provision agent and user access to specific tools and scopes - Compliance baselines and config profiles → policy for tool, scope, and data access, with conditional rules and guardrails - Authenticate, authorize, and rate-limit every API call (API gateway) → authenticate, authorize, and govern every tool call an agent makes through the gateway - Continuous posture and vulnerability monitoring → continuous posture monitoring of connected tools and their usage - Telemetry, detection, and response (EDR) → instrumentation of tool traffic, anomaly and abuse detection, containment controls - Bind device identity to the corporate IdP → bind agent and tool access to enterprise identity (OAuth 2.1, SSO, SCIM) ## What you'll work on - Provisioning lifecycle for tool access — enroll, grant, rotate, revoke — across our managed auth and connector-profile layer, so builders and end users never hand-wire OAuth apps. - Policy and enforcement — shape the authoring, versioning, and runtime enforcement of access policies (including LLM assisted policy generation): which agent, which tool, which scope, which data classes, conditional on identity and context. This is central to our agent-permissioning work. - Posture and risk — continuous assessment of connected tools and the SaaS behind them; surface risky scopes, stale grants, and anomalous invocation patterns. - Instrumentation and telemetry — deepen structured, queryable visibility into the tool calls flowing through the gateway, with the latency discipline of a system on the hot path. - Identity integration — extend our OAuth 2.1, SSO, and SCIM story so policy and provisioning stay bound to enterprise identity rather than bolted on. - Detection and response — the agent-era analog of EDR: define what "bad" looks like, surface it, and give operators the controls to contain it. ## What we're looking for - Strong software engineering fundamentals — comfortable owning a system end-to-end in production. - Built or operated at least one of: an API gateway / management platform (Kong, Apigee, Zuplo, AWS API Gateway, and similar), MDM/UEM (Jamf, Kandji, Intune, Workspace ONE, Google Workspace MDM), EDR/XDR (CrowdStrike, SentinelOne, Palo Alto Network, and similar), or a comparable policy-driven provisioning, posture, or access-control platform. Crossover across more than one of these is a real plus. - Built a policy or rules engine — authoring model, evaluation, enforcement, versioning. You know the difference between expressing a policy and enforcing it at runtime. - Identity systems — OAuth/OIDC, SAML, SSO, SCIM — with a real grasp of scopes, grants, token lifecycle, and least privilege in practice. - Telemetry and instrumentation of a system on the request path, and the trade-offs of monitoring without adding meaningful latency. - LLM an AI experience - you've used if not built MCP servers before, you understand the governance and guardrails problems linked to AI usage and have created AI Agents before ## Nice to have - Security background: vulnerability management, threat detection, or compliance posture (SOC 2 / ISO 27001 environments). - Experience shipping a product that other developers configure and rely on (platform / API empathy). - Built or contributed in public (OSS, specs, write-ups). Who you'll work with Reporting into engineering leadership, partnering closely with the founders (Romain, CEO; Guillaume, CTO) and the security and platform engineers. This is a high-ownership role on a strategic pillar of StackOne's roadmap. You'll set be able to the technical direction for how StackOne governs agent access to tools, for the IT and security leaders who decide whether agents get to touch real systems. ## Benefits - Join one of Europe's fastest-growing startups. - Work alongside an experienced team, with backgrounds from Google, Microsoft, Oracle, Coinbase, JP Morgan, and more. - Meaningful share options (EMI) — share in the company's success as we grow. - Flexible hours and hybrid working — some flexibility in start and finish times, with 2 days minimum in our London office (come in more if you prefer!) - 25 days holiday + 1 additional day per year of tenure. - Private health insurance — including dental & optical. - £15/day lunch budget when working from our London office, up to £180/month. - £1,000 for your home office setup + £500/year top-up. - Health, fitness and gift card discounts. - Cycle2Work and Electric Cars scheme. - Annual team offsites to sunny spots (last ones were in Croatia and Portugal ☀️) We’re open to discussing flexible arrangements – please share any preferences in your application. We believe diversity drives innovation. We encourage individuals from all backgrounds to apply. As an equal-opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees. ## About StackOne ## Company Overview - **One-liner**: StackOne provides integration infrastructure that connects AI agents to any SaaS system with 420+ pre-built connectors and prompt injection defense. - **Entity Type**: Private (Series A — $24M total funding) - **Headquarters**: Newbury, Berkshire, United Kingdom (registered office; team distributed globally across Europe and the United States) - **Founded**: 2023 - **Founders**: Romain Sestier (Co-Founder & CEO), Guillaume Lebedel (Co-Founder & CTO) ## Core Business - **Primary industry**: Integration infrastructure for AI agents; enterprise software connectivity - **Target customers**: B2B developers and companies building or deploying AI agents (including off-the-shelf agents like Claude and Cursor) that need to take action across HRIS, ATS, CRM, LMS, IAM, documents, and other business applications - **Mission or purpose**: Fuel innovation by connecting AI agents to software — let the agent think, StackOne takes action - **Customer verticals**: Enterprise, SMB, and platform companies (customers include Drata, Attensi, Localyze) ## Products & Services - **StackOne Platform**: Core integration infrastructure that exposes 25,000+ pre-built actions across 330+ connectors (now 420+). Handles authentication, rate limiting, retries, data transformation, and governance. Supports MCP, A2A, AI Action SDK (Python/TypeScript), and direct REST APIs. - **StackOne Defender**: Open-source prompt injection detection library (two-tier defense: pattern matching in ~1ms + ML classifier in ~10ms) that scans tool responses before they reach the LLM. F1 score 0.87-0.88, runs in-process with no external API calls. - **Falcon Execution Engine**: Next-generation engine that runs every agent action across REST, GraphQL, SOAP, and proprietary APIs. Handles auth, retries, errors, data transformation, and per-provider throttling. - **Connector Builder**: Allows creation of production-ready connectors for any API (including SOAP, OData, proprietary) in minutes, declared as YAML in Git. - **Permissions API**: Normalizes RBAC, scopes, and ACLs across all integrations into a single model with sub-millisecond checks and per-tenant scoping. - **Audit Trail & Compliance**: Full logging of every API call, permission check, and credential use. SOC 2 Type II, GDPR, HIPAA, and CCPA compliant. Privacy-first architecture — no customer data stored by default. ## Market Standing - **Valuation/Market Cap**: Not disclosed - **Key Metric**: Total funding raised — $24M - Seed: $3.6M (Q2 2024, led by Episode 1 and Playfair; angel investment from Co-Founder of GitHub in Q2 2023) - Series A: $20M (May 2025, led by GV/Google Ventures, with Workday Ventures, XTX Ventures, Episode 1, Playfair, and angels from OpenAI, DeepMind, Microsoft, Mulesoft) - **Notable Investors/Partners**: GV (Google Ventures), Workday Ventures, XTX Ventures, Episode 1, Playfair Capital - **Growth Signals**: Surpassed 1 billion API calls; 420+ connectors and 25,000+ actions; customers across three continents; one of the fastest-growing AI agent infrastructure platforms; expanded from 20 integrations in Q4 2023 to 330+ in 2025 ## Competitive Advantages - **Privacy-first architecture**: No customer data persisted by default — proxies requests in real-time, nothing to breach. - **Multi-protocol support**: MCP, A2A, SDKs, REST — agents connect however they want. - **Two-tier prompt injection defense**: Open-source Defender catches threats in <4ms with 88.7% accuracy; runs in-process with no additional latency or cost. - **Declarative connectors as code**: Every connector is a YAML file in Git — reviewable, testable, reproducible. - **Certified compliance**: SOC 2 Type II, HIPAA, GDPR, CCPA — unlike many unification APIs. - **Low-latency execution engine (Falcon)**: Handles rate limits, retries, and transforms data in real-time, optimized for agent context windows. ## Strategic Focus - Continue investing in R&D for its state-of-the-art tool-calling LLM and expanding the breadth and depth of integrations. - Scale enterprise adoption by deepening governance, permissions, and audit capabilities. - Build out developer ecosystem (MCP servers, open-source tools) to lower friction for AI agent developers. - Expand across new categories (IAM, messaging, documents) and increase action coverage per connector. ## Why Work Here - **Culture & team**: Founded by a pair (CEO Romain Sestier and CTO Guillaume Lebedel) who have worked together for over a decade at Oracle, JP Morgan, Google, Microsoft, and other top tech companies. Team is distributed across Europe and the US. - **Remote/hybrid**: Distributed team with global operations — location flexibility. Open roles include Engineering (AI, Platform, Security, UI) and GTM. - **Growth stage**: Post-Series A ($20M from GV) — well-funded, high-growth phase with product-market fit and accelerating adoption (1B+ API calls). Opportunity to shape the infrastructure layer for the AI agent era. - **Engineering focus**: Emphasis on security, low latency, open-source contributions (Defender), and building for developers. Stack includes modern AI/ML tooling, ONNX models, and multi-protocol systems. - **Perks**: Competitive compensation, equity (startup), and the chance to work on the critical security/compliance layer for enterprise AI agents. ## Sources 1. [stackone.com](https://www.stackone.com/) 2. [stackone.com/company](https://www.stackone.com/company/) 3. [stackone.com/press](https://www.stackone.com/press/stackone-raises-20m-series-a-led-by-gv-google-ventures-to-reinvent-saas-and-ai-agent-integrations/) 4. [linkedin.com/company/stackonehq](https://www.linkedin.com/company/stackonehq) 5. [jobs.ashbyhq.com/stackone](https://jobs.ashbyhq.com/stackone) ## Other roles at StackOne - [Account Executive](https://feeny.ai/job/account-executive-stackone-remote-1qrdqf8qgfa6) - [Account Executive](https://feeny.ai/job/account-executive-stackone-london-4zkh896mv0my) — London, United Kingdom - [Senior Platform Engineer](https://feeny.ai/job/senior-platform-engineer-stackone-london-v5g9mzhpmhcb) — London, United Kingdom - [Security Engineer](https://feeny.ai/job/security-engineer-stackone-london-zrnr121kng2g) — London, United Kingdom