Senior Enterprise AI Security & Governance Architect

Alexander Chapman

San Francisco (CA)

On-site

USD 180,000 - 260,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Alexander Chapman is seeking an experienced security architect to own the architecture of an AI-enabled desktop and agent platform for engineering work. You will define stable control-plane interfaces, implement delegation and policy enforcement, and ensure strong provenance, auditable events, and secure default configurations across enterprise deployments.

The role requires hands-on code, threat modeling, and collaboration with product, security, IAM, legal, and GTM teams to bring

Qualifications

  • Approximately 10+ years building security, identity, platform, or distributed systems with staff-level technical leadership across teams.
  • Deep, hands-on expertise with OAuth 2.0, OIDC, delegated authorization, enterprise federation, token lifecycles, conditional access/device signals, workload identity, secrets management, and least-privilege design.
  • Experience designing authorization systems or policy enforcement points using patterns or technologies such as OPA, Cedar, RBAC/RBAC-like models, or purpose-built policy engines.
  • Strong systems knowledge across desktop endpoints and cloud services: Windows/macOS process and credential boundaries, local IPC, proxies, TLS/mTLS, SSE/streaming APIs, service identities, private networking, and secure updates.
  • Experience building auditable event pipelines with integrity protection, correlation identifiers, OpenTelemetry or equivalent, SIEM integrations, immutable storage, retention controls, and incident-reconstruction workflows.
  • Ability to write production-quality code in Python and/or TypeScript and to prototype across identity providers, gateways, agents, connectors, and observability systems.
  • Practical threat-modeling and secure-design experience for untrusted content, prompt injection, tool invocation, generated code, plugins, software supply chain, and data exfiltration paths.
  • Excellent customer-facing judgment: able to explain architectural truth clearly, avoid unverified claims, negotiate compensating controls, and turn enterprise requirements into testable product outcomes.

Responsibilities

  • Define stable, versioned control-plane interfaces so customers can change agents or models without altering identity, authorization, egress, or evidence controls.
  • Build reference implementations and production components for delegated authentication, short-lived credentials, policy enforcement, gateway integration, evidence export, and emergency revocation.
  • Design the action taxonomy and approval semantics for engineering agents; ensure protected operations are administrator-locked, observable, attributable, and fail-closed.
  • Establish provenance and context-integrity patterns: cited source packs, content hashes, separation of system policy from retrieved data, untrusted-content labeling, and prompt-injection defenses.
  • Instrument the full path from desktop to connector, gateway, model, and engineering application; define event schemas and integrate with customer SIEM and immutable archives.
  • Create and test deployment profiles for cloud, customer gateway/BYOK, customer-hosted, and disconnected environments, including proxy, TLS, streaming, updates, licensing, and support paths.
  • Lead technical workshops with enterprise IAM and security teams; state what is known, identify gaps, and turn them into scoped engineering work and acceptance tests.
  • Partner with product and engineering leaders on sequencing, design reviews, secure defaults, migration paths, and build-versus-integrate decisions across the security roadmap.
  • Run threat modeling, adversarial testing, design reviews, and incident-readiness exercises for local agents, connectors, model routes, plugins, generated code, and cloud services.
  • Mentor engineers and raise the bar for secure distributed-systems design, evidence-based customer commitments, and operable security controls.

Skills

OAuth 2.0 / OIDC
Policy enforcement
Least privilege design
Identity and access management
Threat modeling
Python / TypeScript
Auditable event pipelines
OpenTelemetry / SIEM
Security architecture leadership
Cross-team collaboration

Tools

OPA
Cedar
OpenTelemetry
TLS/mTLS

Job description

Alexander Chapman is seeking an experienced security architect to own the architecture of an AI-enabled desktop and agent platform for engineering work. You will define stable control-plane interfaces, implement delegation and policy enforcement, and ensure strong provenance, auditable events, and secure default configurations across enterprise deployments.

The role requires hands-on code, threat modeling, and collaboration with product, security, IAM, legal, and GTM teams to bring

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

AI Governance Security Architect - Enterprise Platform
AI Governance Security Architect - Enterprise Platform

Buchanan Technologies • Dallas (TX)

On-site
USD 80,000 - 110,000
Remote AI Security Architect for Enterprise AI
Remote AI Security Architect for Enterprise AI

Aimpoint Digital • Atlanta (GA)

On-site
USD 120,000 - 150,000
AI Security & Trust Engineer — Enterprise Equity
AI Security & Trust Engineer — Enterprise Equity

Alex AI • San Francisco (CA)

On-site
USD 180,000 - 240,000
Medical, dental, and vision insurance
FSA, DCFSA, HSA options
Flexible paid time off (PTO)
+5
AI Security Architect: Enterprise-Scale Guardrails Lead
AI Security Architect: Enterprise-Scale Guardrails Lead

TechDigital Group • Bolingbrook (IL)

On-site
USD 160,000 - 230,000
Enterprise AI Governance Architect & Guardrails
Enterprise AI Governance Architect & Guardrails

Cliff Services Inc • Vienna (VA)

On-site
USD 120,000 - 180,000
AI Security Architect
AI Security Architect

TechDigital Group • Bolingbrook (IL)

On-site
USD 160,000 - 230,000
Executive AI Security Architect – Enterprise Governance
Executive AI Security Architect – Enterprise Governance

SMBC • Charlotte (NC)

Hybrid
USD 150,000 - 210,000
Hybrid work model
Accommodations during candidacy
Staff Enterprise AI Security & Governance Architect
Staff Enterprise AI Security & Governance Architect

Alexander Chapman • San Francisco (CA)

On-site
USD 180,000 - 260,000
Senior AI Security Engineer — Enterprise AI Guardrails
Senior AI Security Engineer — Enterprise AI Guardrails

Affirm • Los Angeles (CA)

On-site
USD 204,000 - 290,000
Health coverage
Stipends for tech setup
Flexible time off
+1
Remote AI Security Architect for Enterprise Architecture
Remote AI Security Architect for Enterprise Architecture

CSAA • Delaware

Remote
USD 187,000 - 249,000
Annual bonus eligibility
Remote-first culture
401(k) with company match