# AI Agent Security Architect

**Company:** [Replit](https://hotfix.jobs/companies/replit)
**Location:** Foster City, CA
**Role:** Security Engineering
**Salary:** $230 – $350/hr
**Experience:** 6+ years
**Skills:** Ai Security, Security Architecture, Model Context Protocol, LangChain, Autogen, Crewai, React, Vector Databases, Python, Go, TypeScript, Webassembly, Docker, Firecracker, Gvisor
**Posted:** 2026-09-01

> Design and lead security architecture for Replit’s autonomous AI agents, including runtime guardrails, sandboxing, threat modeling, least-privilege delegation, and observability. Requires 6+ years in security engineering or architecture and specialized experience securing AI/ML or agentic systems.

## Job Description

## Responsibilities
- Define Replit’s long-term security architecture for autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination.
- Architect runtime guardrails, semantic firewalls, real-time intent verification, and policy enforcement to prevent goal hijacking, prompt leaks, and indirect prompt injection.
- Design secure, short-lived, micro-isolated execution environments for agents running code, shell commands, and tools.
- Conduct agentic threat modeling and lead automated and manual AI red-teaming across RAG pipelines, vector stores, and tool-calling interfaces.
- Build fine-grained permission, delegation, and Human-in-the-Loop authorization patterns based on least privilege.
- Design data isolation and poisoning-prevention controls for vector databases, RAG pipelines, and long-term memories in multi-tenant workloads.
- Maintain authoritative AI security design patterns and SDKs for engineering teams.
- Identify and document agentic security risks in the cybersecurity risk register.
- Establish tamper-evident logging and telemetry for agent reasoning chains, tool execution, and context assembly.
- Support GRC and Sales with AI security controls, audit documentation, and enterprise security inquiries.

## Requirements
- 6+ years of security engineering or security architecture experience, including at least 2 years focused on AI/ML security, LLM application security, or agentic frameworks.
- Deep understanding of agentic architectures and protocols, including MCP, LangChain, AutoGen, CrewAI, ReAct, and vector databases.
- Hands-on experience with indirect prompt injection, goal hijacking, tool parameter tampering, data poisoning, and context contamination.
- Strong knowledge of OWASP Top 10 for LLMs and AI Agents, NIST AI RMF, and MITRE ATLAS.
- Proficiency in Python, Go, or TypeScript/JavaScript, with experience reviewing code and building security tooling or guardrails.
- Experience authoring and maintaining technical security architecture documentation.
- Ability to communicate complex AI risks to technical and executive audiences.
- Experience contributing to an enterprise cybersecurity risk register.

## Nice-to-haves
- Experience designing runtime sandboxing and isolation technologies such as Firecracker, gVisor, Docker, or WebAssembly.
- Familiarity with ISO 42001 and EU AI Act readiness.

## Compensation and Benefits
- Salary and equity.
- 401(k) program with a 4% match for US employees.
- Health, dental, vision, and life insurance.
- Short- and long-term disability coverage.
- Paid parental, medical, and caregiver leave.
- Flexible time off and holidays.
- Commuter benefits for in-office US employees.
- Monthly wellness stipend.
- Autonomous work environment.
- In-office setup reimbursement.
- Quarterly team gatherings and in-office amenities.

## Similar jobs

- [Senior Security Support Analyst](https://hotfix.jobs/jobs/8dd54fca-ab77-4ee7-936d-4ff2b036df8e) - Coalition Security - Remote - $94k – $140k/yr
- [SOC Lead](https://hotfix.jobs/jobs/1b4ce51d-67b7-4000-a328-a6f0e74f22a6) - Idme - McLean, VA - $96k – $112k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/9286e91d-ca35-4449-bb47-da0dc51b2aaa) - ConductorOne - Remote - $100k – $200k/yr
- [Senior Incident Responder](https://hotfix.jobs/jobs/b6cdf982-dad3-4c25-be1a-310793748d2e) - BlackCloak - Remote - $105k – $115k/yr
- [Senior Information Security Engineer](https://hotfix.jobs/jobs/36efd016-44f1-4b75-b872-b00cdcbd95a3) - Supernova Technology - Chicago, IL - $110k – $140k/yr

**Apply:** https://hotfix.jobs/jobs/4b17fbed-7548-499f-8444-b22d6f0ba1e2
**Canonical:** https://hotfix.jobs/jobs/4b17fbed-7548-499f-8444-b22d6f0ba1e2