Ring 0 is open to design partners running agents against production systems. Request access

Careers

Ring 0 problems, eleven people.

We are building a hypervisor, a policy engine, and an audit chain that a bank will accept. The problems are unglamorous, deep, and mostly about being correct when it would be easier not to be.

01 / how we work

Every engineer is on call, including the founders.

There is no ops team to absorb our mistakes, which is the fastest way we know to keep the mistakes rare. If you ship a policy change that fails open at 3am, you are the one who finds out.

We write proposals before meetings, because a document exposes a weak argument in a way a slide does not. Most decisions get made in comments rather than a room.

Compensation
Top of the local market in cash, with equity that we explain properly — strike price, preference stack, and what it is likely worth in the bad case.
Location
Distributed across London, Berlin, and Bangalore. Roles are remote within UTC±3 unless the listing says otherwise, because on-call needs overlap.
Hours
No heroics. A boundary built by exhausted people is a boundary with holes in it.
Interviewing
A conversation, a paid work sample against a real problem from our backlog, and a day with the team. No whiteboard algorithms, no take-home that eats your weekend for free.
Writing
You will write a lot: proposals, threat models, postmortems, and documentation. Engineers who cannot write struggle here.

02 / open roles

Kernel engineer

London or remote (UTC±3)Rust · Firecracker · KVM

Own the host agent and the VM lifecycle: boot times, snapshot and restore, device surface, jailer configuration. You will care about the difference between 148ms and 90ms.

Control plane engineer

Remote (UTC±3)Go · Postgres · gRPC

Scheduling, policy evaluation, the credential broker, and the evidence chain. The correctness bar is high because a wrong decision here is a security incident, not a bug.

Security engineer

London or BerlinThreat modelling · appsec · detection

Attack our own boundary. Build the test suite that tries to escape the sandbox, exfiltrate through the gateway, and forge an approval. Publish what you find.

Developer experience engineer

Remote (UTC±3)TypeScript · Python · docs

The SDKs, the adapters, and the CLI. Adoption lives or dies on whether the first integration takes an afternoon or a fortnight.

Forward-deployed engineer

London, Berlin, or New YorkCustomer-facing · policy design

Sit with design partners, write their first policy file with them, and bring back the things we got wrong. Half engineering, half product.

No role that fits? Write to work@velone.in with something you have built and what you would want to own here. We read all of it.

03 / questions

Do you hire juniors?

Rarely, and honestly: at eleven people we cannot give the mentorship a strong junior deserves. That will change. If you are early-career and the work sample is excellent, we will still talk.

Is the equity meaningful?

At seed stage with eleven people, yes, and we will show you the maths including the scenarios where it is worth nothing. Anyone who tells you equity is a sure thing is selling something.

Remote or office?

Both exist and neither is second-class. Two of the five current engineers have never been to an office; decisions happen in writing precisely so that stays true.

What is the hardest thing about working here?

The correctness bar. In most products a bug is a bad experience; here a bug can be an agent doing something to a customer's production system that we said was impossible. That pressure is constant and it is not for everyone.

Ring 0

Send us something you built.

A repository, a postmortem, a threat model. We care more about that than a CV.

curl -fsSL velone.in/install.sh | sh