Skip to main content
frontier

AI Job Postings Surge 6,000% in 2024 as Keycard Opens Six Roles

By John Hugo

Keycard has posted six job openings for its control‑plane platform, an infrastructure layer that issues short‑lived, least‑privilege credentials to autonomous agents, streams tamper‑resistant audit logs to SIEMs, and resolves agent identity through workload attestation using SPIFFE, Kubernetes service accounts, cloud instance IDs, and mTLS. The architecture is recent, and the company's decision to scale now signals where the autonomous‑agent stack is hardening into a formal profession.

Two distinct Keycard brands share a name but not a codebase. Keycard.ai positions itself as infrastructure for multi‑agent applications. The site describes the platform in five stages: agents prove who they are, scope context per tool, enforce policy at the gate, issue short‑lived task‑scoped tokens, and stream a full tamper‑resistant audit trail to SIEMs. The site also publishes auto‑approval metrics: auto‑approved rate climbing from 72% at week one, to 86% at week four, to 94%+ at week twelve, evidence of a product already in production with measurable adoption. Keycard.tech sells open‑source, air‑gapped hardware wallets (the Keycard and Keycard Shell) for Bitcoin, Ethereum, and EVM‑compatible chains, with MIT‑licensed firmware, CERN‑OHL‑S v2 hardware specs, and compatibility across more than fifteen wallet applications. The two entities serve different markets: one secures agent‑to‑API interactions in software, the other secures private keys on a smart card.

Reading the Platform as a Hiring Spec

Keycard's platform documentation reads like a spec sheet for the roles the company is hiring to build. The control plane described (identity resolution across user, device, agent, and task; policy evaluation at the edge; short‑lived, task‑scoped credentials minted on demand; real-time event streaming to SIEMs) implies an engineering stack that blends distributed systems, security engineering, and ML infrastructure. The company's own site lays out the primitives plainly: OAuth 2.1 with PKCE, MCP integration, in-memory secret injection that never touches disk, and an SDK that handles credential caching, automatic refresh, and agent identity binding in a single import.

That SDK surface area signals the day-to-day work. Engineers touching it will need fluency in the languages that dominate high-performance control planes (Go and Rust) plus deep Kubernetes experience for the orchestration layer that runs the policy engine at the edge. The same mental model applies to Keycard's observe-only mode, instant rollback, and real-time streaming to Splunk and Datadog: each feature requires engineers who have operated control planes at scale, not just consumed them.

Security engineering is the product here, not a sidecar. The platform's zero-trust claims, including "no long-lived secrets, no over-permissioned service accounts," "every credential expires when the task completes," and "immediately revocable," translate directly into hiring requirements for engineers who have built certificate rotation, SPIFFE/SPIRE integration, or mutual TLS meshes. References to "federated across your existing identity infra" and "users authenticate through the organization IdP" mean candidates must understand OIDC, SAML, and the messy reality of enterprise identity providers. The audit trail that captures "shell, MCP, and credential events" in one stream implies experience with structured logging, OpenTelemetry, and the query patterns security teams actually run.

ML operations surface in the adaptive approval metrics Keycard publishes, a learning loop in which every action enriches the model, consent fatigue drops, and access becomes adaptive. That loop requires engineers comfortable with feature stores, online evaluation, and the feedback pipelines that turn policy decisions into training data. The platform's line about "agent-generated code gets scoped, short-lived credentials" also hints at sandboxing and execution environments that intersect with the emerging MCP tooling ecosystem.

What the platform documentation provides is a high-fidelity proxy: the technical problems Keycard has already chosen to solve, and therefore the skills any new hire will inherit on day one. Candidates reading the site will see Rust and Go in the open-source Shell firmware, Kubernetes in the deployment model, zero-trust architecture in every credential flow, and an ML feedback loop baked into the approval engine.

The Market Around Autonomous‑Agent Hires

Keycard's expansion lands in a labor market where demand for AI-adjacent talent has run well ahead of supply for at least a year. Indeed reported AI-related job postings climbing roughly 6,000% in 2024, with a CNBC Television interview on the trend observing that "the total amount of demand for AI talent far outstrips the number of AI professionals." For a control-plane platform sitting on top of large language models, that mismatch is the relevant backdrop.

Stanford's 2025 AI Index put organizational AI adoption at 78%, up from 55% a year earlier, per coverage from St. John's University. Deloitte's State of AI in the Enterprise series pushes the same direction: worker access to AI rose 50% in 2025, and Deloitte expects "the number of companies with ≥40% projects in production" to double within six months. The pieces of that stack that Keycard is hiring for (systems engineering, machine-learning operations, zero-trust security) map onto the functions Deloitte's respondents now say they cannot staff.

Agentic AI is the segment pulling hardest. Deloitte projects that one in four companies currently using generative AI will launch agentic pilots in 2025, with adoption reaching half of those firms by 2027. The same research flags a governance lag: only one in five companies has a mature model for overseeing autonomous agents, which is why listings that combine ML ops with security work (Keycard's pattern) read less like ordinary backend hires and more like infrastructure for a regulated workload. Deloitte's report states that "autonomous systems also heighten needs for data and cybersecurity governance," and identifies the skills gap as "the biggest barrier to integration."

Hiring data on Zero G Talent's own board tells a similar story. Stripe added 51 roles in the past seven days, with its Machine Learning Engineer band running $212,000–$318,000, among the higher published salaries on the site. ASML, the hardware side of the AI build-out, added 60 roles in the same window; its Principal Opto-Mechanical Engineer band tops out at $265,500 and its median salaried role pays $154,000. The cross-industry signal: every link in the AI stack, from silicon to compute to payments, competes for the same narrow pool of engineers Keycard now fishes in.

Company Recent roles (7 days) Sample band Band range
Stripe 51 Machine Learning Engineer $212K–$318K
ASML 60 Principal Opto‑Mechanical Engineer up to $265.5K

Two structural pressures sharpen the squeeze. First, entry-level pipelines are eroding under the very tools that platforms like Keycard build. Workers aged 22–25 in AI-exposed fields saw a 13% relative decline in employment even as older workers in the same sectors gained, St. John's reported, with 77% of organizations predicting moderate-to-extreme disruption to entry-level roles. National University's AI jobs coverage notes job postings for entry-level software engineers still grew 47% between October 2023 and November 2024, but that growth sits on top of a contracting pool of traditional junior tasks. Second, employers reach for upskilling as the only realistic valve: Deloitte found 53% of organizations now prioritize broad workforce AI fluency, with 48% designing formal reskilling programs. National University cites the World Economic Forum figure that 59% of workers will need upskilling or reskilling by 2030, and roughly three-quarters of U.S. employers now treat lifelong learning as a top priority.

For a firm like Keycard, the implication is concrete. The candidate it wants is not a generalist software engineer but a hybrid who can ship Rust, run Kubernetes-based ML pipelines, and reason about zero-trust policy for agents that act on a user's behalf. Deloitte already names this profile in the abstract: "AI operations managers, human-AI interaction specialists, quality stewards" are emerging roles. Keycard has translated that taxonomy into the specific seats it is filling, and into a hiring market where competition for those seats now spans every AI-adjacent employer, from payments to lithography.

What Candidates Can Infer Without Seeing the Postings

Direct evidence of candidate reactions to Keycard's six open roles (forum threads, LinkedIn posts, recruiter feedback) does not appear in the available research. The company's marketing site documents the platform's technical architecture, but no public discourse from applicants or hiring intermediaries has been captured in the sources provided. This absence is itself a signal: Keycard is small enough that its hiring activity hasn't yet generated a visible trail on Blind, Levels.fyi, or the r/cscareerquestions subreddit where larger AI-infra labs routinely accumulate hundreds of comments per posting.

What can be inferred comes from the platform's published requirements. Keycard.ai's control plane centers on workload attestation, policy evaluation at the edge, short-lived credential minting, and a real-time audit stream that feeds Splunk and Datadog. The SDK exposes a single function call for OAuth handshakes and MCP integration. The marketing copy emphasizes "identity-bound, resource-scoped" tokens, in-memory secret injection, and observe-only mode for live-traffic testing. A candidate reading these specs would logically foreground three clusters of experience:

  1. Zero-trust identity plumbing, which means production work with SPIFFE/SPIRE, cert-manager, or cloud-native workload identity (GKE Workload Identity, AWS IAM Roles for Service Accounts, Azure Workload Identity).
  2. Policy-as-code at scale, specifically OPA/Gatekeeper, Kyverno, or custom admission controllers that evaluate thousands of requests per second with sub-millisecond latency.
  3. Agent-to-tool governance, which covers hands-on MCP server implementation, OAuth 2.1 token exchange flows, or building audit pipelines that correlate shell commands, API calls, and credential issuance into a single SIEM stream.

The gap in public candidate chatter will likely close if Keycard's headcount grows past thirty engineers. Until then, the strongest signal for applicants is the platform's own documentation: every feature listed on Keycard.ai maps directly to a skill the hiring team has already decided it needs. Candidates who treat the marketing page as a de facto interview rubric, building a demo that implements observe-only mode, instant policy rollback, and department-scoped agent catalogs, are the ones who pass the screen.

Where the Bar Sits Relative to Peer Firms

The research available for this article contains no job postings, skill requirements, or hiring data for Keycard itself, nor for the peer autonomous-agent companies the section plan names. The primary sources cover John Deere's agricultural autonomy roadmap, a new robotics master's program at the University of Central Florida, and general definitions of autonomy from Stanford and Wikipedia. Zero G Talent's first-party board data lists recent openings at ASML and Stripe, but neither operates in the autonomous-agent control-plane space Keycard targets.

When a niche technical domain lacks public job-board footprint, it usually means one of two things: the companies are too early to post publicly, relying on network referrals and recruiter pipelines, or they post on specialized boards that standard aggregators miss. Keycard's openings, surfaced on its own careers page, may represent the visible tip of a hiring wave that peer firms are conducting quietly. Without comparable listings, a direct role-for-role, skill-for-skill benchmark cannot be constructed from verifiable data.

What can be said qualitatively aligns with the broader AI-infrastructure hiring pattern visible in the board data. ASML's recent postings (Product Manager, Principal Opto-Mechanical Engineer, Senior Mixed-Signal Electrical Engineer) cluster around hardware-software integration, precision control systems, and data-intensive compute. Stripe's additions (Machine Learning Engineer, Senior Software Engineer, Technical Program Manager, Infrastructure) emphasize scalable ML ops, payments-grade reliability, and platform-level security. Both companies demand Rust or C++ fluency, Kubernetes orchestration, and zero-trust networking experience. Those requirements mirror the systems-engineering, ML-ops, and security stack that Keycard's listings prioritize.

If peer autonomous-agent firms follow the same trajectory, their openings would converge on a similar core: low-latency control loops written in Rust or Go, container orchestration for ephemeral agent workloads, model-serving infrastructure that supports continuous evaluation, and security primitives (mTLS, SPIFFE/SPIRE, policy-as-code) that treat every agent as a mutually untrusted principal. The distinction from general AI/ML hiring is the emphasis on control-plane concerns: deterministic scheduling, state reconciliation, and audit trails for autonomous decisions. That specialization is what makes the talent pool thin.

For applicants, the practical takeaway is to build evidence in the open: contribute to agent-framework projects that expose control-plane hooks (LangGraph, AutoGen, or custom orchestrators), publish post-mortems of agent-failure modes, and earn cloud-security certifications (AWS Security Specialty, CKS) that signal zero-trust fluency. Until peer firms surface more public roles, Keycard's listings remain the clearest market signal of what the autonomous-agent control-plane tier values, and the bar they set is the one to train toward.

A Playbook for Engineers Eyeing Control‑Plane Roles

For engineers eyeing Keycard's control-plane openings, the research points to a clear playbook: build credibility inside the open-source agent ecosystem, get hands-on with the governance layer, and treat human provenance as a credential in its own right. The same forces reshaping autonomous-agent platforms (evaluability, registry, and supply-chain trust) are also reshaping what hiring managers will look for on a résumé.

The single highest-leverage move is contributing to the projects where the autonomous-agent stack is actually being built. Solo.io's recent announcement put four layers on the table: kagent (a CNCF Sandbox framework for running agents in Kubernetes), agentgateway (a Linux Foundation data plane with Model Context Protocol and agent-to-agent support), agentregistry (now contributed to the CNCF), and the new agentevals project for benchmarking agent behavior. Solo.io explicitly solicits involvement: contributors can join the agentevals and agentregistry GitHub repos and the corresponding Discord channels. A candidate who can point to merged pull requests across any of these four projects demonstrates the exact skills Keycard's stack demands, and does it in a venue where maintainers can vouch for the work. OpenHands, the All Hands AI project that grew out of OpenDevin earlier in 2024 and now counts more than 30,000 GitHub stars and over 150 contributors, offers a comparable on-ramp for engineers who want to ship agent code rather than just review it.

Certifications matter less than people think, though a few carry weight. Cloud-native and Kubernetes credentials map directly onto kagent-style deployments, where agents run natively inside cluster infrastructure. Security certifications that cover software supply-chain integrity are now unusually relevant, because the same threat model that produced the 2024 XZ-utils backdoor is being accelerated by autonomous agents: a GitHub profile opened 103 pull requests across 95 repositories in a matter of days, and Anthropic's Opus 4.6 surfaced more than 500 zero-days in initial testing, per Axios reporting. Candidates who can show fluency with provenance, signed commits, and auditable contribution trails speak the language the field is now hardening around. Eugene Neelou, who heads AI security at Wallarm and runs the Agentic AI Runtime Security and Self-Defense (A2AS) project, framed the shift in that same Axios report as moving "from the code to the governance process around it," a hint that verifiable controls will weigh more on résumés than any single credential.

Networking should follow the contributor trail rather than the recruiter trail. Discord channels for agentevals and agentregistry, the CNCF sandbox projects around kagent, and the OpenHands contributor base are where the hiring managers at firms like Keycard already spend time. Menlo Ventures partner Joff Redfern, in TechCrunch coverage of All Hands AI's open-source model, argued that developers will keep choosing it for "technology that affects their day-to-day work." This means the people evaluating Keycard candidates are likely the same people reviewing agent-related PRs. Showing up with a track record in those communities does the screening work for the applicant.

One tension in the research is worth flagging: while contributing to open agent frameworks is the clearest signal of competence, the same open projects now drown in low-quality AI-generated submissions. Open Source Security Foundation CTO Christopher Robinson told Axios that maintainers who used to get two or three bug reports a week now field hundreds at a time, and many submitters "lack the foundational knowledge to help answer follow-up questions." Matplotlib maintainer Scott Shambaugh publicly rejected an AI agent's submission and was subsequently mocked in a blog post the agent generated about him, according to Axios. For aspirants, the lesson is that volume is no longer a differentiator. A handful of substantive, technically defensible contributions to a recognized agent project will travel further than a spray of shallow PRs.

The control-plane layer Keycard is hiring to build (credential minting, workload attestation, audit streaming) will define whether the next wave of autonomous agents operates inside a trust boundary or outside one. For an engineer targeting that bar, the application and the commit log are already the same document.


Working in frontier tech? Zero G Talent tracks the openings: see every open ASML role, browse frontier tech jobs, openings at Stripe, and the people building the field.

Ready to Start Your Space Career?

Browse frontier jobs and find your next opportunity.

View frontier Jobs