AI Agent Security Architect
Replit · Foster City, CA
- Compensation
- $230 - $350/yr
- Location
- Foster City, CA
- Workplace
- Remote
- Employment
- Full time
- Posted
- 3 days ago
About a minute 25 sent a week, free No card
- I read this posting
- Rewrite your resume against it
- Draft the cover letter, score the fit
Prefer Replit’s own form? Open the original posting
About this role
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
About the Role
We are looking for an AI Agent Security Architect to function as the primary technical
authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you
will design, implement, and maintain the runtime defense systems, guardrail
frameworks, and sandboxing architectures that govern AI agents executing code,
invoking tools, and reasoning across our platform. You will be a key technical
contributor - leading high-impact AI security initiatives and bridging the gap between
non-deterministic AI behavior and rigorous cybersecurity controls for both engineering
and executive leadership.
What You'll Do
AI Agent Security Strategy & Technical Execution
AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination.
Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections.
Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely.
Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces.
Identity, Delegation & Least Privilege: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns for agents acting on behalf of users - ensuring agents never exceed the delegated privileges of the end user or misuse API keys.
Context & Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads.
Risk Management & Cross-Functional Enablement
Maintain the AI Security Source of Truth: Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities.
Contribution to Risk Register: Identify, quantify, and document non-deterministic and agentic security risks (e.g., OWASP Top 10 for LLMs & AI Agents, MITRE ATLAS), ensuring they are accurately represented in the Cybersecurity Risk Register.
Auditability & Observability: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements.
Compliance & Sales Enablement: Partner with GRC to translate complex AI security controls into enterprise-ready audit documentation (e.g., ISO 42001, NIST AI RMF, EU AI Act readiness) and support Sales on complex enterprise security inquiries regarding AI safety.
Required Skills & Experience
6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks.
Deep understanding of agentic architectures and protocols (e.g., Model Context. Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies).
Hands-on expertise with threat vectors unique to agentic AI: Indirect Prompt
Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, and Context Contamination.
Strong background in applying safety standards and risk frameworks such as OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS.
Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling or guardrails.
Experience authoring, maintaining, and evangelizing technical security architecture documentation.
Exceptional ability to communicate complex non-deterministic AI risks to both deep technical engineers and executive stakeholders.
Proven track record of contributing to an enterprise Cybersecurity Risk Register.
Bonus Qualifications
Experience designing runtime sandboxing and isolation technologies (e.g., Firecracker, gVisor, Docker, WebAssembly) for dynamic code execution environments.
Full-Time Employee Benefits Include:
💰 Competitive Salary & Equity
💹 401(k) Program with a 4% match (US Only)
⚕️ Health, Dental, Vision and Life Insurance
🩼 Short Term and Long Term Disability
🚼 Paid Parental, Medical, Caregiver Leave
🏝 Flexible Time Off (FTO) + Holidays
🚗 Commuter Benefits (In-Office & US Only)
📱 Monthly Wellness Stipend
🧑💻 Autonomous Work Environment
🖥 In Office Set-Up Reimbursement (In-Office Only)
🚀 Quarterly Team Gatherings
☕ In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
Interviewing + Culture at Replit
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
As published by Replit. Applications are handled on their site.
About Replit
We’re on a mission to make programming collaborative, accessible, and fun for everyone. Creating the future of computing is a team effort, though
All 84 openings at ReplitOne click, then it is written
Apply to Replit with a resume written for this role.
Queue AI Agent Security Architect and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Replit’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Replit
See all- 2 days ago
- 3 days ago
- 3 days ago
- 6 days ago
- 6 days ago
- Last week
Similar roles elsewhere
See more- 4 weeks ago
- 5 weeks ago
Senior Technical Program Manager, Security
ReplitFoster City, CaliforniaRemote
$190k - $250k/yrSeniorEngineering - 2 months ago
Product Engineer, Product Platform (Frontend)
ReplitFoster City, CARemote
$200k - $300k/yrMid levelEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Replit publishes. Refolk is not the employer and does not handle their hiring. Applications go to Replit directly.