The opportunity
At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers.
What you'll do
Own the agentic coding roadmap. Set direction for interactive and autonomous: agent modes, entry points (Slack, web, CLI), and the orchestration model for multi-step/multi-repo agent work.
Agentic code review. Own its accuracy/coverage roadmap, and make the real: tradeoff calls between review quality, PR merge speed, and per-review inference cost — backed by data, not vibes.
Set the security and risk posture for autonomous coding agents at Gusto.: Decide what an agent can do unsupervised, own the sandboxing/permission-scoping model, and drive the underlying hardening (runtime isolation, secrets handling, blast-radius containment) needed to run agent workloads safely.
Set and enforce AI infrastructure spend guardrails for your team, translating: raw usage data into judgment calls about what's legitimate cost of doing the job vs. what needs a conversation.
Lead and grow a team of senior engineers working across ambiguous,: fast-moving problem spaces — recruit, mentor, run the hiring loop, and make calibration/leveling calls you can defend.
Be a direct strategic partner to engineering leadership (including the CTO): on where AI-native software development is heading at Gusto, grounded in what's actually shippable, not vendor hype.
What they're looking for
- + years of engineering people leadership experience, including managing: senior engineers through ambiguous, rapidly-changing technical problems (not just well-scoped roadmap execution)
- Direct, hands-on experience with agentic coding tools: you are a daily power user of Claude Code, Cursor, Codex, or equivalent, not someone who has read about them
- Experience owning a significant vendor or infrastructure contract from: technical requirements through legal and procurement close
- Comfort making autonomy/risk tradeoff calls on AI systems without a dedicated: security team making the call for you — you understand the shape of the risk (e.g., prompt injection, credential exposure, permission bypass) well enough to scope it yourself