AI Agent Security Architect

Replit

Northern, Foster City (KY, CA)

Hybrid

USD 180,000 - 240,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

401(k) plan with 4% match
Health insurance
Dental insurance
Vision insurance
Life insurance
Short-term & long-term disability
Parental leave
Flexible time off
Commuter benefits
Wellness stipend
In-office setup reimbursement
Quarterly team gatherings
In-office amenities

Job summary

Replit is seeking an AI Agent Security Architect to lead the security blueprint for autonomous agents. You will design runtime defenses, guardrails, and sandboxing architectures that govern agent code execution, tool use, and reasoning across the platform.

You will bridge non-deterministic AI behavior with formal cybersecurity controls for engineering teams and leadership. You will drive risk modeling, threat simulations, and secure design documentation while collaborating with GRC, Sales, and

Qualifications

  • 6+ years in security engineering or architecture with 2+ years in AI/ML security or agentic security.
  • Deep understanding of agentic architectures and MCP, LangChain, AutoGen, CrewAI, ReAct, and vector databases.
  • Hands-on experience with threats unique to agentic AI: indirect prompt injection, hijacking, tampering, data poisoning.
  • Strong background in OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS.
  • Proficiency in Python, Go, or TypeScript/JavaScript with security tooling experience.
  • Experience documenting and evangelizing security architecture to engineers and executives.
  • Excellent ability to communicate complex AI risks to technical and non-technical stakeholders.
  • Proven track record contributing to an enterprise Cybersecurity Risk Register.

Responsibilities

  • AI Agent Security Strategy & Technical Execution across the platform.
  • Define long-term security blueprint for autonomous agent workflows and MCP integrations.
  • Design runtime guardrails, semantic firewalls, and real-time verification filters.
  • Partner with Infra and AppSec to build secure sandboxed environments for code execution.
  • Lead agentic threat modeling and red-teaming for RAG, vector stores, and tool calls.
  • architect HITL authorization to enforce least privilege for agents acting for users.
  • Implement strict data isolation for vector DBs, RAG pipelines and multi-tenant memories.
  • Maintain secure design patterns and SDKs; contribute to risk registers and audits.
  • Develop tamper-evident logging and observability for reasoning chains and tools.
  • Translate security controls into enterprise audit docs and support sales on inquiries.

Skills

AI/ML security
Threat modeling
Security architecture
Non-deterministic AI risk
Code review & tooling
Security policies & guardrails
GRC & compliance
Communication to execs

Tools

LangChain
AutoGen
CrewAI
ReAct frameworks
Vector databases
WebAssembly
Firecracker
gVisor
Docker
Python
Go
TypeScript/JavaScript

Job description

Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.

About the Role

We are looking for an AI Agent Security Architect to function as the primary technical authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you will design, implement, and maintain the runtime defense systems, guardrail frameworks, and sandboxing architectures that govern AI agents executing code, invoking tools, and reasoning across our platform. You will be a key technical contributor—leading high-impact AI security initiatives and bridging the gap between non-deterministic AI behavior and rigorous cybersecurity controls for both engineering and executive leadership.

What You’ll Do
  • AI Agent Security Strategy & Technical Execution
  • AI Agent Security Blueprint: Define the longterm vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination.
  • Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections.
  • Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely.
  • Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces.
  • Identity, Delegation & Least Privilege: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns for agents acting on behalf of users—ensuring agents never exceed the delegated privileges of the end user or misuse API keys.
  • Context & Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads.
  • Risk Management & Cross-Functional Enablement
  • Maintain the AI Security Source of Truth: Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities.
  • Contribution to Risk Register: Identify, quantify, and document non-deterministic and agentic security risks (e.g., OWASP Top 10 for LLMs & AI Agents, MITRE ATLAS), ensuring they are accurately represented in the Cybersecurity Risk Register.
  • Auditability & Observability: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements.
  • Compliance & Sales Enablement: Partner with GRC to translate complex AI security controls into enterprise-ready audit documentation (e.g., ISO 42001, NIST AI RMF, EU AI Act readiness) and support Sales on complex enterprise security inquiries regarding AI safety.
Required Skills & Experience
  • 6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks.
  • Deep understanding of agentic architectures and protocols (e.g., Model Context. Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies).
  • Hands‑on expertise with threat vectors unique to agentic AI: Indirect Prompt
  • Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, and Context Contamination.
  • Strong background in applying safety standards and risk frameworks such as OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS.
  • Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling or guardrails.
  • Experience authoring, maintaining, and evangelizing technical security architecture documentation.
  • Exceptional ability to communicate complex non-deterministic AI risks to both deep technical engineers and executive stakeholders.
  • Proven track record of contributing to an enterprise Cybersecurity Risk Register.
Bonus Qualifications
  • Experience designing runtime sandboxing and isolation technologies (e.g., Firecracker, gVisor, Docker, WebAssembly) for dynamic code execution environments.
Full-Time Employee Benefits Include:
  • Competitive Salary & Equity
  • 401(k) Program with a 4% match (US Only)
  • Health, Dental, Vision and Life Insurance
  • Short Term and Long Term Disability
  • Paid Parental, Medical, Caregiver Leave
  • Flexible Time Off (FTO) + Holidays
  • Commuter Benefits (In-Office & US Only)
  • Monthly Wellness Stipend
  • Autonomous Work Environment
  • In Office Set-Up Reimbursement (In-Office Only)
  • Quarterly Team Gatherings
  • In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
  • Self-driving Company
  • Replit Agent at Scale
  • AI Adoption
  • Build Open-Source Apps
Interviewing + Culture at Replit
  • Operating Principles
  • Reasons not to work at Replit

To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Software Engineer, Agent Platform
Staff Software Engineer, Agent Platform

Replit • California (MO)

Hybrid
USD 150,000 - 210,000
Competitive Salary & Equity
401(k) Program with 4% match (US Only)
Health, Dental, Vision and Life
+7
Staff Software Engineer, Agent Platform
Staff Software Engineer, Agent Platform

Replit • Foster City (CA)

Hybrid
USD 130,000 - 160,000
Competitive Salary & Equity
401(k) Program with a 4% match
Health, Dental, Vision and Life Insurance
+9
Senior AI Builder
Senior AI Builder

Replit • California (MO)

Hybrid
USD 120,000 - 160,000
Competitive Salary & Equity
401(k) with 4% match
Health, Dental, Vision insurance
+2
Software Engineer, Developer Experience
Software Engineer, Developer Experience

Replit • California (MO)

Hybrid
USD 150,000 - 230,000
Competitive Salary & Equity
401(k) Match
Health, Dental, Vision
+8
Data Scientist, Trust & Safety
Data Scientist, Trust & Safety

Replit • United States

On-site
USD 140,000 - 190,000
Health insurance
Equity opportunities
401(k) plan with match
+1
Product Engineer, New Products
Product Engineer, New Products

Replit • California (MO)

Hybrid
USD 150,000 - 190,000
Health, Dental, Vision
401(k) with match
Paid time off
+1
Data Scientist, Trust & Safety
Data Scientist, Trust & Safety

Neura Market • Foster City (CA)

On-site
USD 150,000 - 210,000
Health, Dental, Vision
401(k) match
Paid parental leave
+2
Data Scientist, Trust & Safety
Data Scientist, Trust & Safety

Replit • California (MO)

On-site
USD 150,000 - 210,000
Competitive salary & equity
401(k) match
Health, dental, vision & life insure.
+8
Senior Software Engineer, Replit Cloud
Senior Software Engineer, Replit Cloud

Replit • California (MO)

On-site
USD 150,000 - 210,000
Competitive Salary & Equity
401(k) Program with a 4% match (US)
Health, Dental, Vision and Life Inѕ</n
+9
Field Engineer
Field Engineer

Replit • California (MO)

Hybrid
USD 150,000 - 230,000
Salary & Equity
401k match
Health insurance
+9