Position Overview
We are building the next-generation Agent security product to protect enterprise AI workloads at scale. As our Agent Security Expert, you will define the technical architecture for real-time agent defense and lead the product's security roadmap in a fast-emerging global market. You will work at the intersection of application security, AI safety, and systems engineering, shaping how enterprises safely deploy autonomous agents across their digital infrastructure.
What You'll Do
- Own the end-to-end technical architecture of our Agent security product, making principled trade-offs across detection coverage, latency, and operational overhead.
- Design and implement runtime guardrails — including prompt injection defense, unauthorized tool-call interception, behavioral drift detection, and real-time credential leak prevention.
- Architect MCP and tool-chain supply-chain security capabilities against tool poisoning, cross-origin privilege escalation, and transitive trust abuse.
- Build an automated agent red-teaming pipeline to continuously discover vulnerabilities, generate adversarial test cases, and harden defenses before production deployment.
- Partner with product, engineering, and threat intelligence teams to translate emerging attack patterns into shipped security features, and mentor junior engineers on security-first design.
What We're Looking For
- 8+ years of hands-on experience in security engineering, systems engineering, or a closely related field, with a track record of shipping production security components.
- Deep expertise in at least two of: application security, cloud-native security, identity and access management (IAM), or offensive/defensive security operations.
- Proficient in at least two of Go, Python, Rust, or C++, with experience building high-concurrency security services or detection pipelines.
- Strong working knowledge of the LLM/Agent stack — RAG architectures, function calling, MCP protocol, and mainstream agent frameworks — and the unique attack surfaces they introduce.
- Experience researching or shipping enterprise security products (EDR, CNAPP, AI-SPM, or equivalent); familiarity with sandboxing, eBPF, or container/virtualization isolation is a strong plus.