AI Agent Security Architect
Replit · Foster City, CA
About this role
**AI Agent Security Architect** Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. --- ## About the Role We’re looking for an **AI Agent Security Architect** to serve as the primary technical authority for Replit’s autonomous and AI agent security blueprint. In this role, you’ll design, implement, and maintain runtime defense systems, guardrail frameworks, and sandboxing architectures that govern AI agents executing code, invoking tools, and reasoning across our platform. You’ll lead high-impact AI security initiatives and help bridge the gap between non-deterministic AI behavior and rigorous cybersecurity controls for both engineering and executive leadership. --- ## What You’ll Do - **AI Agent Security Strategy & Technical Execution** - **AI Agent Security Blueprint:** Define long-term vision and architectural patterns for securing autonomous agent workflows, **Model Context Protocol (MCP)** integrations, multi-turn reasoning loops, and multi-agent coordination. - **Runtime Guardrails & Policy Enforcement:** Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections. - **Agent Execution & Tool Sandboxing:** Partner with Infrastructure and AppSec to design secure, short-lived, micro-isolated environments (e.g., **microVMs**, **WebAssembly**, container sandboxes) for safe code execution, shell commands, and host OS interactions. - **Agentic Threat Modeling & Red Teaming:** Conduct threat modeling for non-deterministic systems; lead automated and manual AI red-teaming to uncover vulnerabilities in **RAG context pipelines**, vector stores, and tool-calling interfaces. - **Identity, Delegation & Least Privilege:** Architect fine-grained permission models and step-up **Human-in-the-Loop (HITL)** authorization patterns so agents never exceed delegated privileges or misuse API keys. - **Context & Memory Boundary Security:** Design strict data isolation and poisoning prevention controls for vector databases, RAG pipelines, and long-term conversation memories across multi-tenant workloads. - **Risk Management & Cross-Functional Enablement** - **AI Security Source of Truth:** Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities. - **Contribution to Risk Register:** Identify, quantify, and document non-deterministic and agentic security risks (e.g., **OWASP Top 10 for LLMs & AI Agents**, **MITRE ATLAS**) for the Cybersecurity Risk Register. - **Auditability & Observability:** Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements. - **Compliance & Sales Enablement:** Partner with GRC to translate AI security controls into enterprise-ready audit documentation (e.g., **ISO 42001**, **NIST AI RMF**, **EU AI Act** readiness) and support Sales on complex enterprise security inquiries. --- ## Required Skills & Experience - **6+ years** in security engineering or security architecture, including **2+ years** focused on **AI/ML security**, **LLM applicat
Listing freshness
CronJobs last confirmed this listing 19h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.