AI Agent Security Architect
Security Engineer · Senior · Full Time
Opens Replit's application page
Role
What you'll do.
Replit seeks an AI Agent Security Architect to serve as the primary technical authority for designing and implementing security frameworks governing autonomous AI agents. This critical role requires architecting runtime defense systems, guardrail frameworks, and sandboxing architectures for AI agents executing code and tools across Replit's platform. You will bridge non-deterministic AI behavior with rigorous cybersecurity controls, leading AI security initiatives and translating complex agentic vulnerabilities for both engineering teams and executive leadership.
Responsibilities
- AI Agent Security Blueprint Architecture: Define the long-term vision and architectural patterns for securing autonomous agent workflows, including Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination frameworks. Establish security standards that enable safe agent operation while maintaining platform flexibility.
- Runtime Guardrails and Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections. Implement policy enforcement mechanisms that adapt to evolving agentic threat vectors.
- Agent Execution and Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated execution environments using technologies such as microVMs, WebAssembly, and container sandboxes. Enable agents to dynamically execute code, run shell commands, and interact with host operating systems safely.
- Agentic Threat Modeling and Red Teaming: Conduct specialized threat modeling against non-deterministic AI systems and lead automated and manual AI red-teaming initiatives. Uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces specific to agentic architectures.
- Identity, Delegation, and Least Privilege Framework: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns ensuring agents never exceed delegated user privileges or misuse API keys. Design delegation models that support enterprise-grade access control requirements.
- Context and Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads. Prevent context contamination and unauthorized information leakage.
- Security Documentation and SDK Evangelism: Define, document, and maintain authoritative secure design patterns and security SDKs for engineering teams building internal or customer-facing AI agent capabilities. Serve as the source of truth for AI security practices across the organization.
- Risk Register and Compliance Management: Identify, quantify, and document non-deterministic and agentic security risks including OWASP Top 10 for LLMs and AI Agents, and MITRE ATLAS frameworks. Contribute to and maintain the Cybersecurity Risk Register with accurate agentic security risk representation.
- Auditability and Observability Standards: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly. Support incident response, forensics, and governance requirements through comprehensive observability frameworks.
- Enterprise Compliance and Sales Enablement: Partner with GRC teams to translate complex AI security controls into enterprise-ready audit documentation including ISO 42001, NIST AI Risk Management Framework, and EU AI Act readiness. Support Sales on complex enterprise security inquiries regarding AI safety and governance.
Qualifications
What we look for.
Technical
AI/ML Security Expertise
At least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks. Deep understanding of agentic architectures, protocols including Model Context Protocol (MCP), and frameworks such as LangChain, AutoGen, CrewAI, and ReAct.
Agentic Threat Vectors and Attack Surface Knowledge
Hands-on expertise with threat vectors unique to agentic AI including Indirect Prompt Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, Context Contamination, and token-level attacks. Ability to identify and mitigate non-deterministic AI vulnerabilities.
Programming Proficiency
Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling, guardrails, and policy enforcement mechanisms.
Runtime Sandboxing and Isolation Technologies
Hands-on experience designing and implementing runtime sandboxing and isolation technologies such as Firecracker, gVisor, Docker, WebAssembly, and container-based execution environments for dynamic code execution scenarios.
Security Frameworks and Standards
Strong background applying safety standards and risk frameworks including OWASP Top 10 for LLMs and AI Agents, NIST AI Risk Management Framework (NIST AI RMF), MITRE ATLAS, and other industry-recognized AI security governance models.
Threat Modeling for Non-Deterministic Systems
Expertise in conducting threat modeling and risk analysis for non-deterministic AI systems, including RAG pipelines, vector database security, and multi-agent coordination architectures.
Vector Database and RAG Security
Technical knowledge of vector store architectures, retrieval-augmented generation (RAG) pipeline security, embedding poisoning, and context isolation in multi-tenant environments.
Education
Computer Science or Cybersecurity Foundation
Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent professional certifications (CISSP, CCSK, or similar) demonstrating foundational security knowledge.
Experience
Security Engineering and Architecture
6+ years of professional experience in security engineering or security architecture roles, demonstrating progression in technical security leadership and complex system design.
AI Security Track Record
At least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks in production environments.
Security Documentation and Technical Authorship
Proven experience authoring, maintaining, and evangelizing technical security architecture documentation and secure design patterns. Track record of creating security resources for engineering teams.
Enterprise Risk Management
Demonstrated contribution to enterprise Cybersecurity Risk Registers, including identifying, quantifying, and documenting security risks for executive stakeholder review.
Cross-Functional Technical Leadership
Experience bridging technical engineering teams and executive leadership. Proven ability to translate complex security concepts, non-deterministic AI risks, and compliance requirements for diverse audiences.
Skills
Required
Agentic AI Architecture Knowledge
Deep understanding of Model Context Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies. Knowledge of multi-agent coordination and reasoning chain architectures.
Python, Go, or TypeScript/JavaScript
Proficiency in at least one of these languages with ability to review code, build security tooling, implement guardrails, and evaluate agentic framework security implementations.
Threat Modeling and Red Teaming
Expertise in conducting threat modeling exercises, leading red team assessments, and identifying vulnerabilities in complex systems. Specific experience with AI and agentic threat landscapes.
Security Architecture and Design
Ability to architect enterprise-grade security solutions including permission models, sandboxing environments, guardrail systems, and compliance frameworks that scale across multi-tenant platforms.
Technical Communication and Documentation
Exceptional ability to communicate complex non-deterministic AI risks, security architecture decisions, and compliance requirements to both deep technical engineers and executive stakeholders.
AI Security Frameworks and Standards
Applied knowledge of OWASP Top 10 for LLMs and AI Agents, NIST AI Risk Management Framework, MITRE ATLAS, ISO 42001, and EU AI Act requirements for AI safety governance.
Observability and Logging Systems
Experience designing tamper-evident logging, telemetry standards, and audit trails for compliance, forensics, and incident response in regulated environments.
Preferred
Firecracker, gVisor, and WebAssembly Experience
Nice to haveHands-on experience designing and implementing runtime sandboxing solutions using Firecracker microVMs, gVisor security layers, or WebAssembly-based isolation for dynamic code execution.
Vector Database Security
Nice to haveSpecific expertise in securing vector databases, preventing embedding poisoning attacks, and designing RAG pipeline security architectures in production AI systems.
Enterprise GRC and Compliance
Nice to haveExperience working with Governance, Risk, and Compliance (GRC) teams on enterprise audit preparation, compliance documentation, and security control implementation for regulatory requirements.
LLM and Foundation Model Security
Nice to haveBackground in securing large language models, managing model context windows, preventing system prompt leaks, and implementing semantic firewalls for LLM applications.
Multi-Tenant Security Architecture
Nice to haveExperience designing security controls for multi-tenant platforms with strict data isolation requirements, context boundaries, and privilege escalation prevention mechanisms.
Human-in-the-Loop (HITL) Authorization Systems
Nice to haveDesign experience implementing step-up authorization patterns, delegation frameworks, and human oversight systems for autonomous agent operations in critical use cases.
Compensation
Pay and benefits.
Base·USD 230 – 350
Full posting
Original listing.
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We are looking for an AI Agent Security Architect to function as the primary technical
authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you
will design, implement, and maintain the runtime defense systems, guardrail
frameworks, and sandboxing architectures that govern AI agents executing code,
invoking tools, and reasoning across our platform. You will be a key technical
contributor—leading high-impact AI security initiatives and bridging the gap between
non-deterministic AI behavior and rigorous cybersecurity controls for both engineering
and executive leadership.
What You'll Do
AI Agent Security Strategy & Technical Execution
AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination.
Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections.
Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely.
Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces.
Identity, Delegation & Least Privilege: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns for agents acting on behalf of users—ensuring agents never exceed the delegated privileges of the end user or misuse API keys.
Context & Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads.
Risk Management & Cross-Functional Enablement
Maintain the AI Security Source of Truth: Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities.
Contribution to Risk Register: Identify, quantify, and document non-deterministic and agentic security risks (e.g., OWASP Top 10 for LLMs & AI Agents, MITRE ATLAS), ensuring they are accurately represented in the Cybersecurity Risk Register.
Auditability & Observability: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements.
Compliance & Sales Enablement: Partner with GRC to translate complex AI security controls into enterprise-ready audit documentation (e.g., ISO 42001, NIST AI RMF, EU AI Act readiness) and support Sales on complex enterprise security inquiries regarding AI safety.
Required Skills & Experience
6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks.
Deep understanding of agentic architectures and protocols (e.g., Model Context. Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies).
Hands-on expertise with threat vectors unique to agentic AI: Indirect Prompt
Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, and Context Contamination.
Strong background in applying safety standards and risk frameworks such as OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS.
Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling or guardrails.
Experience authoring, maintaining, and evangelizing technical security architecture documentation.
Exceptional ability to communicate complex non-deterministic AI risks to both deep technical engineers and executive stakeholders.
Proven track record of contributing to an enterprise Cybersecurity Risk Register.
Bonus Qualifications
Experience designing runtime sandboxing and isolation technologies (e.g., Firecracker, gVisor, Docker, WebAssembly) for dynamic code execution environments.
Full-Time Employee Benefits Include:
💰 Competitive Salary & Equity
💹 401(k) Program with a 4% match (US Only)
⚕️ Health, Dental, Vision and Life Insurance
🩼 Short Term and Long Term Disability
🚼 Paid Parental, Medical, Caregiver Leave
🏝 Flexible Time Off (FTO) + Holidays
🚗 Commuter Benefits (In-Office & US Only)
📱 Monthly Wellness Stipend
🧑💻 Autonomous Work Environment
🖥 In Office Set-Up Reimbursement (In-Office Only)
🚀 Quarterly Team Gatherings
☕ In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
Interviewing + Culture at Replit
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
Redirects to Replit's application page.
Other roles
More at Replit.
Forward Deployed Engineer
Senior
Product Engineer, New Products
Senior
Data Scientist, Trust & Safety
Senior
Product Engineer, Product Platform (Frontend)
Senior
Security Engineer - Vuln Management (Infra)
Mid