AI Agent Security Architect

Posted 11 Hours Ago
Be an Early Applicant
Foster City, CA, USA
Hybrid
230K-350K Annually
Senior level
Artificial Intelligence • Cloud • Machine Learning • Software • Database • App development • Generative AI
Introducing Replit Agent 4 - built to unlock your creativity. Plan. Design. Build. All at once.
The Role
Design and lead Replit’s AI agent security architecture, including runtime guardrails, semantic firewalls, sandboxing, threat modeling, red teaming, identity delegation, data isolation, observability, and auditability. Establish secure design patterns, SDKs, risk-register contributions, and compliance documentation for agentic systems. Partner with engineering, infrastructure, AppSec, GRC, executives, and sales to address AI security risks involving prompt injection, tool misuse, data poisoning, context contamination, and autonomous code execution.
Summary Generated by Built In

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are looking for an AI Agent Security Architect to function as the primary technical

authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you

will design, implement, and maintain the runtime defense systems, guardrail

frameworks, and sandboxing architectures that govern AI agents executing code,

invoking tools, and reasoning across our platform. You will be a key technical

contributor—leading high-impact AI security initiatives and bridging the gap between

non-deterministic AI behavior and rigorous cybersecurity controls for both engineering

and executive leadership.

What You'll Do

  • AI Agent Security Strategy & Technical Execution

  • AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination.

  • Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections.

  • Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely.

  • Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces.

  • Identity, Delegation & Least Privilege: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns for agents acting on behalf of users—ensuring agents never exceed the delegated privileges of the end user or misuse API keys.

  • Context & Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads.

  • Risk Management & Cross-Functional Enablement

  • Maintain the AI Security Source of Truth: Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities.

  • Contribution to Risk Register: Identify, quantify, and document non-deterministic and agentic security risks (e.g., OWASP Top 10 for LLMs & AI Agents, MITRE ATLAS), ensuring they are accurately represented in the Cybersecurity Risk Register.

  • Auditability & Observability: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements.

  • Compliance & Sales Enablement: Partner with GRC to translate complex AI security controls into enterprise-ready audit documentation (e.g., ISO 42001, NIST AI RMF, EU AI Act readiness) and support Sales on complex enterprise security inquiries regarding AI safety.

Required Skills & Experience

  • 6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks.

  • Deep understanding of agentic architectures and protocols (e.g., Model Context. Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies).

  • Hands-on expertise with threat vectors unique to agentic AI: Indirect Prompt

  • Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, and Context Contamination.

  • Strong background in applying safety standards and risk frameworks such as OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS.

  • Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling or guardrails.

  • Experience authoring, maintaining, and evangelizing technical security architecture documentation.

  • Exceptional ability to communicate complex non-deterministic AI risks to both deep technical engineers and executive stakeholders.

  • Proven track record of contributing to an enterprise Cybersecurity Risk Register.

Bonus Qualifications

  • Experience designing runtime sandboxing and isolation technologies (e.g., Firecracker, gVisor, Docker, WebAssembly) for dynamic code execution environments.

Full-Time Employee Benefits Include:

💰 Competitive Salary & Equity

💹 401(k) Program with a 4% match (US Only)

⚕️ Health, Dental, Vision and Life Insurance

🩼 Short Term and Long Term Disability

🚼 Paid Parental, Medical, Caregiver Leave

🏝 Flexible Time Off (FTO) + Holidays

🚗 Commuter Benefits (In-Office & US Only)

📱 Monthly Wellness Stipend

🧑‍💻 Autonomous Work Environment

🖥 In Office Set-Up Reimbursement (In-Office Only)

🚀 Quarterly Team Gatherings

☕ In Office Amenities (In-Office Only)

Want to learn more about what we are up to?

  • Self-driving Company

  • Replit Agent at Scale

  • AI Adoption

  • Build Open-Source Apps

     

Interviewing + Culture at Replit

  • Operating Principles

  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Skills Required

  • 6+ years of experience in security engineering or security architecture
  • At least 2+ years dedicated to AI/ML security, LLM application security, or securing agentic frameworks
  • Deep understanding of agentic architectures and protocols, including MCP, LangChain, AutoGen, CrewAI, ReAct, and vector databases
  • Hands-on expertise with indirect prompt injection, goal hijacking, tool parameter tampering, data poisoning, and context contamination
  • Experience applying OWASP Top 10 for LLMs and AI Agents, NIST AI RMF, and MITRE ATLAS
  • Proficiency in Python, Go, or TypeScript/JavaScript
  • Track record of reviewing code and building functional security tooling or guardrails
  • Experience authoring, maintaining, and evangelizing technical security architecture documentation
  • Exceptional communication of complex AI risks to technical engineers and executive stakeholders
  • Proven track record contributing to an enterprise Cybersecurity Risk Register
  • Experience designing runtime sandboxing and isolation technologies such as Firecracker, gVisor, Docker, or WebAssembly

Replit Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Replit and has not been reviewed or approved by Replit.

  • Parental & Family Support Parental leave spans up to 24 weeks for birth parents with additional paid medical, bonding, and family‑care leave. These policies are characterized as generous compared to common U.S. tech norms.
  • Healthcare Strength Medical, dental, and vision coverage are paired with an employer‑funded HSA plus life and disability insurance. Options like FSA/DFSA and mental‑health support further reinforce the health offering.
  • Wellbeing & Lifestyle Benefits Monthly wellness stipends, learning and development funds, and recognition programs add ongoing value beyond cash compensation. Office meals, commuter benefits, and onsite amenities enhance day‑to‑day experience for those near the HQ.

Replit Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
300 Employees
Year Founded: 2016

What We Do

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide and over 500,000 business users, Replit is democratizing software development by removing traditional barriers to application creation.

Similar Jobs

JPMorganChase Logo JPMorganChase

Sales Manager

Financial Services
Hybrid
2 Locations
289097 Employees

Snap Inc. Logo Snap Inc.

Art Director

Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
Hybrid
2 Locations
5000 Employees
111K-196K Annually

Braze Logo Braze

Scientist

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
San Francisco, CA, USA
2000 Employees
184K-332K Annually

Braze Logo Braze

Lead Product Marketing, Decisioning Services

Marketing Tech • Mobile • Software
Easy Apply
Hybrid
San Francisco, CA, USA
2000 Employees
134K-220K Annually

Similar Companies Hiring

LTX Thumbnail
Robotics • Conversational AI • Generative AI
Jerusalem, Israel
200 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account