AI Agent Security Architect

Security Engineer · Senior · Full Time

Foster City, CAUSD 230 – 3502d ago
Apply for this role

Opens Replit's application page

Role

What you'll do.

Replit seeks an AI Agent Security Architect to serve as the primary technical authority for designing and implementing security frameworks governing autonomous AI agents. This critical role requires architecting runtime defense systems, guardrail frameworks, and sandboxing architectures for AI agents executing code and tools across Replit's platform. You will bridge non-deterministic AI behavior with rigorous cybersecurity controls, leading AI security initiatives and translating complex agentic vulnerabilities for both engineering teams and executive leadership.

Responsibilities

  • AI Agent Security Blueprint Architecture: Define the long-term vision and architectural patterns for securing autonomous agent workflows, including Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination frameworks. Establish security standards that enable safe agent operation while maintaining platform flexibility.
  • Runtime Guardrails and Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections. Implement policy enforcement mechanisms that adapt to evolving agentic threat vectors.
  • Agent Execution and Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated execution environments using technologies such as microVMs, WebAssembly, and container sandboxes. Enable agents to dynamically execute code, run shell commands, and interact with host operating systems safely.
  • Agentic Threat Modeling and Red Teaming: Conduct specialized threat modeling against non-deterministic AI systems and lead automated and manual AI red-teaming initiatives. Uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces specific to agentic architectures.
  • Identity, Delegation, and Least Privilege Framework: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns ensuring agents never exceed delegated user privileges or misuse API keys. Design delegation models that support enterprise-grade access control requirements.
  • Context and Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads. Prevent context contamination and unauthorized information leakage.
  • Security Documentation and SDK Evangelism: Define, document, and maintain authoritative secure design patterns and security SDKs for engineering teams building internal or customer-facing AI agent capabilities. Serve as the source of truth for AI security practices across the organization.
  • Risk Register and Compliance Management: Identify, quantify, and document non-deterministic and agentic security risks including OWASP Top 10 for LLMs and AI Agents, and MITRE ATLAS frameworks. Contribute to and maintain the Cybersecurity Risk Register with accurate agentic security risk representation.
  • Auditability and Observability Standards: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly. Support incident response, forensics, and governance requirements through comprehensive observability frameworks.
  • Enterprise Compliance and Sales Enablement: Partner with GRC teams to translate complex AI security controls into enterprise-ready audit documentation including ISO 42001, NIST AI Risk Management Framework, and EU AI Act readiness. Support Sales on complex enterprise security inquiries regarding AI safety and governance.

Qualifications

What we look for.

Technical

  • AI/ML Security Expertise

    At least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks. Deep understanding of agentic architectures, protocols including Model Context Protocol (MCP), and frameworks such as LangChain, AutoGen, CrewAI, and ReAct.

  • Agentic Threat Vectors and Attack Surface Knowledge

    Hands-on expertise with threat vectors unique to agentic AI including Indirect Prompt Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, Context Contamination, and token-level attacks. Ability to identify and mitigate non-deterministic AI vulnerabilities.

  • Programming Proficiency

    Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling, guardrails, and policy enforcement mechanisms.

  • Runtime Sandboxing and Isolation Technologies

    Hands-on experience designing and implementing runtime sandboxing and isolation technologies such as Firecracker, gVisor, Docker, WebAssembly, and container-based execution environments for dynamic code execution scenarios.

  • Security Frameworks and Standards

    Strong background applying safety standards and risk frameworks including OWASP Top 10 for LLMs and AI Agents, NIST AI Risk Management Framework (NIST AI RMF), MITRE ATLAS, and other industry-recognized AI security governance models.

  • Threat Modeling for Non-Deterministic Systems

    Expertise in conducting threat modeling and risk analysis for non-deterministic AI systems, including RAG pipelines, vector database security, and multi-agent coordination architectures.

  • Vector Database and RAG Security

    Technical knowledge of vector store architectures, retrieval-augmented generation (RAG) pipeline security, embedding poisoning, and context isolation in multi-tenant environments.

Education

  • Computer Science or Cybersecurity Foundation

    Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent professional certifications (CISSP, CCSK, or similar) demonstrating foundational security knowledge.

Experience

  • Security Engineering and Architecture

    6+ years of professional experience in security engineering or security architecture roles, demonstrating progression in technical security leadership and complex system design.

  • AI Security Track Record

    At least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks in production environments.

  • Security Documentation and Technical Authorship

    Proven experience authoring, maintaining, and evangelizing technical security architecture documentation and secure design patterns. Track record of creating security resources for engineering teams.

  • Enterprise Risk Management

    Demonstrated contribution to enterprise Cybersecurity Risk Registers, including identifying, quantifying, and documenting security risks for executive stakeholder review.

  • Cross-Functional Technical Leadership

    Experience bridging technical engineering teams and executive leadership. Proven ability to translate complex security concepts, non-deterministic AI risks, and compliance requirements for diverse audiences.

Skills

Required

  • Agentic AI Architecture Knowledge

    Deep understanding of Model Context Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies. Knowledge of multi-agent coordination and reasoning chain architectures.

  • Python, Go, or TypeScript/JavaScript

    Proficiency in at least one of these languages with ability to review code, build security tooling, implement guardrails, and evaluate agentic framework security implementations.

  • Threat Modeling and Red Teaming

    Expertise in conducting threat modeling exercises, leading red team assessments, and identifying vulnerabilities in complex systems. Specific experience with AI and agentic threat landscapes.

  • Security Architecture and Design

    Ability to architect enterprise-grade security solutions including permission models, sandboxing environments, guardrail systems, and compliance frameworks that scale across multi-tenant platforms.

  • Technical Communication and Documentation

    Exceptional ability to communicate complex non-deterministic AI risks, security architecture decisions, and compliance requirements to both deep technical engineers and executive stakeholders.

  • AI Security Frameworks and Standards

    Applied knowledge of OWASP Top 10 for LLMs and AI Agents, NIST AI Risk Management Framework, MITRE ATLAS, ISO 42001, and EU AI Act requirements for AI safety governance.

  • Observability and Logging Systems

    Experience designing tamper-evident logging, telemetry standards, and audit trails for compliance, forensics, and incident response in regulated environments.

Preferred

  • Firecracker, gVisor, and WebAssembly Experience

    Nice to have

    Hands-on experience designing and implementing runtime sandboxing solutions using Firecracker microVMs, gVisor security layers, or WebAssembly-based isolation for dynamic code execution.

  • Vector Database Security

    Nice to have

    Specific expertise in securing vector databases, preventing embedding poisoning attacks, and designing RAG pipeline security architectures in production AI systems.

  • Enterprise GRC and Compliance

    Nice to have

    Experience working with Governance, Risk, and Compliance (GRC) teams on enterprise audit preparation, compliance documentation, and security control implementation for regulatory requirements.

  • LLM and Foundation Model Security

    Nice to have

    Background in securing large language models, managing model context windows, preventing system prompt leaks, and implementing semantic firewalls for LLM applications.

  • Multi-Tenant Security Architecture

    Nice to have

    Experience designing security controls for multi-tenant platforms with strict data isolation requirements, context boundaries, and privilege escalation prevention mechanisms.

  • Human-in-the-Loop (HITL) Authorization Systems

    Nice to have

    Design experience implementing step-up authorization patterns, delegation frameworks, and human oversight systems for autonomous agent operations in critical use cases.

Compensation

Pay and benefits.

Base·USD 230 – 350

Full posting

Original listing.

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are looking for an AI Agent Security Architect to function as the primary technical

authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you

will design, implement, and maintain the runtime defense systems, guardrail

frameworks, and sandboxing architectures that govern AI agents executing code,

invoking tools, and reasoning across our platform. You will be a key technical

contributor—leading high-impact AI security initiatives and bridging the gap between

non-deterministic AI behavior and rigorous cybersecurity controls for both engineering

and executive leadership.

What You'll Do

  • AI Agent Security Strategy & Technical Execution

  • AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination.

  • Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections.

  • Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely.

  • Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces.

  • Identity, Delegation & Least Privilege: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns for agents acting on behalf of users—ensuring agents never exceed the delegated privileges of the end user or misuse API keys.

  • Context & Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads.

  • Risk Management & Cross-Functional Enablement

  • Maintain the AI Security Source of Truth: Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities.

  • Contribution to Risk Register: Identify, quantify, and document non-deterministic and agentic security risks (e.g., OWASP Top 10 for LLMs & AI Agents, MITRE ATLAS), ensuring they are accurately represented in the Cybersecurity Risk Register.

  • Auditability & Observability: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements.

  • Compliance & Sales Enablement: Partner with GRC to translate complex AI security controls into enterprise-ready audit documentation (e.g., ISO 42001, NIST AI RMF, EU AI Act readiness) and support Sales on complex enterprise security inquiries regarding AI safety.

Required Skills & Experience

  • 6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks.

  • Deep understanding of agentic architectures and protocols (e.g., Model Context. Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies).

  • Hands-on expertise with threat vectors unique to agentic AI: Indirect Prompt

  • Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, and Context Contamination.

  • Strong background in applying safety standards and risk frameworks such as OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS.

  • Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling or guardrails.

  • Experience authoring, maintaining, and evangelizing technical security architecture documentation.

  • Exceptional ability to communicate complex non-deterministic AI risks to both deep technical engineers and executive stakeholders.

  • Proven track record of contributing to an enterprise Cybersecurity Risk Register.

Bonus Qualifications

  • Experience designing runtime sandboxing and isolation technologies (e.g., Firecracker, gVisor, Docker, WebAssembly) for dynamic code execution environments.

Full-Time Employee Benefits Include:

💰 Competitive Salary & Equity

💹 401(k) Program with a 4% match (US Only)

⚕️ Health, Dental, Vision and Life Insurance

🩼 Short Term and Long Term Disability

🚼 Paid Parental, Medical, Caregiver Leave

🏝 Flexible Time Off (FTO) + Holidays

🚗 Commuter Benefits (In-Office & US Only)

📱 Monthly Wellness Stipend

🧑‍💻 Autonomous Work Environment

🖥 In Office Set-Up Reimbursement (In-Office Only)

🚀 Quarterly Team Gatherings

☕ In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

Interviewing + Culture at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Redirects to Replit's application page.

Other roles

More at Replit.

View all 28 roles