Staff Enterprise AI Security & Governance Architect

Alexander Chapman

San Francisco (CA)

On-site

USD 180,000 - 260,000

Full time

5 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Alexander Chapman is seeking an experienced security architect to own the architecture of an AI-enabled desktop and agent platform for engineering work. You will define stable control-plane interfaces, implement delegation and policy enforcement, and ensure strong provenance, auditable events, and secure default configurations across enterprise deployments.

The role requires hands-on code, threat modeling, and collaboration with product, security, IAM, legal, and GTM teams to bring

Qualifications

  • Approximately 10+ years building security, identity, platform, or distributed systems with staff-level technical leadership across teams.
  • Deep, hands-on expertise with OAuth 2.0, OIDC, delegated authorization, enterprise federation, token lifecycles, conditional access/device signals, workload identity, secrets management, and least-privilege design.
  • Experience designing authorization systems or policy enforcement points using patterns or technologies such as OPA, Cedar, RBAC/RBAC-like models, or purpose-built policy engines.
  • Strong systems knowledge across desktop endpoints and cloud services: Windows/macOS process and credential boundaries, local IPC, proxies, TLS/mTLS, SSE/streaming APIs, service identities, private networking, and secure updates.
  • Experience building auditable event pipelines with integrity protection, correlation identifiers, OpenTelemetry or equivalent, SIEM integrations, immutable storage, retention controls, and incident-reconstruction workflows.
  • Ability to write production-quality code in Python and/or TypeScript and to prototype across identity providers, gateways, agents, connectors, and observability systems.
  • Practical threat-modeling and secure-design experience for untrusted content, prompt injection, tool invocation, generated code, plugins, software supply chain, and data exfiltration paths.
  • Excellent customer-facing judgment: able to explain architectural truth clearly, avoid unverified claims, negotiate compensating controls, and turn enterprise requirements into testable product outcomes.

Responsibilities

  • Define stable, versioned control-plane interfaces so customers can change agents or models without altering identity, authorization, egress, or evidence controls.
  • Build reference implementations and production components for delegated authentication, short-lived credentials, policy enforcement, gateway integration, evidence export, and emergency revocation.
  • Design the action taxonomy and approval semantics for engineering agents; ensure protected operations are administrator-locked, observable, attributable, and fail-closed.
  • Establish provenance and context-integrity patterns: cited source packs, content hashes, separation of system policy from retrieved data, untrusted-content labeling, and prompt-injection defenses.
  • Instrument the full path from desktop to connector, gateway, model, and engineering application; define event schemas and integrate with customer SIEM and immutable archives.
  • Create and test deployment profiles for cloud, customer gateway/BYOK, customer-hosted, and disconnected environments, including proxy, TLS, streaming, updates, licensing, and support paths.
  • Lead technical workshops with enterprise IAM and security teams; state what is known, identify gaps, and turn them into scoped engineering work and acceptance tests.
  • Partner with product and engineering leaders on sequencing, design reviews, secure defaults, migration paths, and build-versus-integrate decisions across the security roadmap.
  • Run threat modeling, adversarial testing, design reviews, and incident-readiness exercises for local agents, connectors, model routes, plugins, generated code, and cloud services.
  • Mentor engineers and raise the bar for secure distributed-systems design, evidence-based customer commitments, and operable security controls.

Skills

OAuth 2.0 / OIDC
Policy enforcement
Least privilege design
Identity and access management
Threat modeling
Python / TypeScript
Auditable event pipelines
OpenTelemetry / SIEM
Security architecture leadership
Cross-team collaboration

Tools

OPA
Cedar
OpenTelemetry
TLS/mTLS

Job description

My client is building an AI-enabled desktop and agent platform for engineering work. Enterprise customers want to experiment with the best agent and model for each workflow while keeping the enterprise control plane in their own hands. This role owns the architecture - and enough of the implementation - to make that operating model real.

You will connect a local-first desktop and engineering-tool runtime to customer identity, policy, gateway, logging, and evidence systems. You will turn customer security questions into durable product capabilities: attributable delegated access, least privilege, controlled egress, human approval for state changes, trustworthy provenance, independent audit, and staged deployment gates.

This is not a policy-only or review-only position. The person must set cross-product technical direction, write critical-path code and prototypes, resolve ambiguous enterprise trust boundaries, and align engineering, product, customer security, IAM, legal, and go-to-market teams around decisions that hold up in production.

What you will do
  1. 1. Define stable, versioned control-plane interfaces so customers can change agents or models without changing identity, authorization, egress, approval, retention, or evidence controls.
  2. 2. Build reference implementations and production components for delegated authentication, short-lived credentials, policy enforcement, gateway integration, evidence export, and emergency revocation.
  3. 3. Design the action taxonomy and approval semantics for engineering agents; make protected operations administrator-locked, observable, attributable, and fail-closed.
  4. 4. Establish provenance and context-integrity patterns: cited source packs, content hashes, separation of system policy from retrieved data, untrusted-content labeling, and prompt-injection defenses.
  5. 5. Instrument the full path from desktop to connector, gateway, model, and engineering application; define event schemas and integrate with customer SIEM and immutable archives.
  6. 6. Create and test deployment profiles for their cloud, customer gateway/BYOK, customer-hosted, and disconnected environments, including proxy, TLS, streaming, updates, licensing, and support paths.
  7. 7. Lead technical workshops with enterprise IAM and security teams. State what is known, identify what must be verified, and convert gaps into scoped engineering work and acceptance tests.
  8. 8. Partner with product and engineering leaders on sequencing, design reviews, secure defaults, migration paths, and build-versus-integrate decisions across the enterprise security roadmap.
  9. 9. Run threat modeling, adversarial testing, design reviews, and incident-readiness exercises for local agents, connectors, model routes, plugins, generated code, and cloud services.
  10. 10. Mentor engineers and raise the bar for secure distributed-systems design, evidence-based customer commitments, and operable security controls.
Required experience
  1. 11. Approximately 10+ years building security, identity, platform, or distributed systems, including demonstrated Staff-level technical leadership across teams. Equivalent depth matters more than a specific year count.
  2. 12. Deep, hands-on expertise with OAuth 2.0, OIDC, delegated authorization, enterprise federation, token lifecycles, conditional access/device signals, workload identity, secrets management, and least-privilege design.
  3. 13. Experience designing authorization systems or policy enforcement points using patterns or technologies such as OPA, Cedar, relationship-based access control, or purpose-built policy engines.
  4. 14. Strong systems knowledge across desktop endpoints and cloud services: Windows/macOS process and credential boundaries, local IPC, proxies, TLS/mTLS, SSE/streaming APIs, service identities, private networking, and secure updates.
  5. 15. Experience building auditable event pipelines with integrity protection, correlation identifiers, OpenTelemetry or equivalent, SIEM integrations, immutable storage, retention controls, and incident-reconstruction workflows.
  6. 16. Ability to write production-quality code in Python and/or TypeScript and to prototype across identity providers, gateways, agents, connectors, and observability systems.
  7. 17. Practical threat-modeling and secure-design experience for untrusted content, prompt injection, tool invocation, generated code, plugins, software supply chain, and data exfiltration paths.
  8. 18. Excellent customer-facing judgment: able to explain architectural truth clearly, avoid unverified claims, negotiate compensating controls, and turn enterprise requirements into testable product outcomes.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IAM Security Engineer
IAM Security Engineer

Gala Solutions • Denver (CO)

On-site
USD 150,000 - 210,000
Senior/Staff Security Engineer
Senior/Staff Security Engineer

Wise Insight • San Francisco (CA)

On-site
USD 150,000 - 210,000
Senior Security Engineer – AI & Application Security
Senior Security Engineer – AI & Application Security

Identify Security • United States

On-site
USD 140,000 - 210,000
IT Client Engineer
IT Client Engineer

Figureai • San Jose (CA)

On-site
USD 120,000 - 180,000
IT Client Engineer
IT Client Engineer

Figure • San Jose (CA)

On-site
USD 180,000 - 210,000
IT Client Engineer
IT Client Engineer

Figure- • San Jose (CA)

On-site
USD 120,000 - 180,000
Senior AI Engineer, Architect
Senior AI Engineer, Architect

PepsiCo • Plano (TX)

On-site
USD 130,000 - 160,000
Security Architect| Enterprise AI Governance Platform
Security Architect| Enterprise AI Governance Platform

Buchanan Technologies • Dallas (TX)

On-site
USD 80,000 - 110,000
Sr Security Engineer
Sr Security Engineer

Adobe • Seattle (WA)

On-site
USD 120,000 - 160,000
Member of Technical Staff (Security) - AI Infrastructure
Member of Technical Staff (Security) - AI Infrastructure

Hamilton Barnes Associates Limited • United States

On-site
USD 213,000 - 288,000
Equity
Full Healthcare