--- title: 'AI Agent Security Architect at Replit' canonical: 'https://feeny.ai/job/ai-agent-security-architect-replit-foster-city-kmf659p8tp4j' type: 'job' last_seen: '2026-09-08' --- # AI Agent Security Architect at Replit - **Company:** [Replit](https://feeny.ai/companies/replit) - **Location:** Foster City, CA - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-09-01 - **Last confirmed live:** 2026-09-08 - **Apply:** https://jobs.ashbyhq.com/replit/df7b6d30-9da1-4ace-8121-17c2aa55aa6f ## Job description Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation. ## About the Role We are looking for an AI Agent Security Architect to function as the primary technical authority for Replit’s autonomous and AI agent security blueprint. In this critical role, you will design, implement, and maintain the runtime defense systems, guardrail frameworks, and sandboxing architectures that govern AI agents executing code, invoking tools, and reasoning across our platform. You will be a key technical contributor—leading high-impact AI security initiatives and bridging the gap between non-deterministic AI behavior and rigorous cybersecurity controls for both engineering and executive leadership. ## What You'll Do - AI Agent Security Strategy & Technical Execution - AI Agent Security Blueprint: Define the long-term vision and architectural patterns for securing autonomous agent workflows, Model Context Protocol (MCP) integrations, multi-turn reasoning loops, and multi-agent coordination. - Runtime Guardrails & Policy Enforcement: Architect and deploy dynamic input/output guardrail systems, semantic firewalls, and real-time intent verification filters to prevent goal hijacking, system prompt leaks, and indirect prompt injections. - Agent Execution & Tool Sandboxing: Partner with Infrastructure and AppSec teams to design secure, short-lived, micro-isolated environments (e.g., microVMs, WebAssembly, container sandboxes) where agents can dynamically execute code, run shell commands, and interact with host operating systems safely. - Agentic Threat Modeling & Red Teaming: Conduct specialized threat modeling against non-deterministic systems. Lead automated and manual AI red-teaming initiatives to uncover vulnerabilities in RAG context pipelines, vector stores, and tool-calling interfaces. - Identity, Delegation & Least Privilege: Architect fine-grained permission models and step-up Human-in-the-Loop (HITL) authorization patterns for agents acting on behalf of users—ensuring agents never exceed the delegated privileges of the end user or misuse API keys. - Context & Memory Boundary Security: Design strict data isolation and poisoning prevention controls for vector databases, retrieval-augmented generation (RAG) pipelines, and long-term conversation memories across multi-tenant workloads. - Risk Management & Cross-Functional Enablement - Maintain the AI Security Source of Truth: Define, document, and maintain authoritative secure design patterns and SDKs for engineering teams building internal or customer-facing AI agent capabilities. - Contribution to Risk Register: Identify, quantify, and document non-deterministic and agentic security risks (e.g., OWASP Top 10 for LLMs & AI Agents, MITRE ATLAS), ensuring they are accurately represented in the Cybersecurity Risk Register. - Auditability & Observability: Design tamper-evident logging and telemetry standards for agent reasoning chains, tool execution history, and context assembly to support incident response, forensics, and GRC requirements. - Compliance & Sales Enablement: Partner with GRC to translate complex AI security controls into enterprise-ready audit documentation (e.g., ISO 42001, NIST AI RMF, EU AI Act readiness) and support Sales on complex enterprise security inquiries regarding AI safety. Required Skills & Experience - 6+ years of experience in security engineering or security architecture, with at least 2+ years dedicated specifically to AI/ML security, LLM application security, or securing agentic frameworks. - Deep understanding of agentic architectures and protocols (e.g., Model Context. Protocol (MCP), LangChain, AutoGen, CrewAI, ReAct frameworks, and vector database technologies). - Hands-on expertise with threat vectors unique to agentic AI: Indirect Prompt - Injection, Goal Hijacking, Tool Parameter Tampering, Data Poisoning, and Context Contamination. - Strong background in applying safety standards and risk frameworks such as OWASP Top 10 for LLMs & AI Agents, NIST AI RMF, and MITRE ATLAS. - Proficiency in Python, Go, or TypeScript/JavaScript with a proven track record of reviewing code and building functional security tooling or guardrails. - Experience authoring, maintaining, and evangelizing technical security architecture documentation. - Exceptional ability to communicate complex non-deterministic AI risks to both deep technical engineers and executive stakeholders. - Proven track record of contributing to an enterprise Cybersecurity Risk Register. Bonus Qualifications - Experience designing runtime sandboxing and isolation technologies (e.g., Firecracker, gVisor, Docker, WebAssembly) for dynamic code execution environments. Full-Time Employee Benefits Include: 💰 Competitive Salary & Equity 💹 401(k) Program with a 4% match (US Only) ⚕️ Health, Dental, Vision and Life Insurance 🩼 Short Term and Long Term Disability 🚼 Paid Parental, Medical, Caregiver Leave 🏝 Flexible Time Off (FTO) + Holidays 🚗 Commuter Benefits (In-Office & US Only) 📱 Monthly Wellness Stipend 🧑‍💻 Autonomous Work Environment 🖥 In Office Set-Up Reimbursement (In-Office Only) 🚀 Quarterly Team Gatherings ☕ In Office Amenities (In-Office Only) Want to learn more about what we are up to? - Self-driving Company https://replit.com/blog/self-driving-company - Replit Agent at Scale https://replit.com/blog/evaluating-and-improving-agent-at-scale - AI Adoption https://replit.com/blog/ai-adoption - Build Open-Source Apps https://replit.com/build/open-source-app-builder Interviewing + Culture at Replit - Operating Principles https://blog.replit.com/operating-principles - Reasons not to work at Replit https://blog.replit.com/reasons-not-to-join-replit To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds. ## About Replit ## Company Overview - **One-liner**: Replit is an agentic creation platform that enables anyone to turn ideas into real, working software using AI-powered tools, a collaborative browser-based IDE, and full-stack infrastructure. - **Entity Type**: Private (Series D) - **Headquarters**: Foster City, California, United States - **Founded**: 2016 - **Founders**: Amjad Masad, Haya Odeh, Faris Masad ## Core Business - Primary industry/industries: Developer Tools, AI-Powered Software Development, Cloud-Based IDE - Target customers: Individual developers, learners, non-programmers, enterprise teams (B2B, B2C) - Mission or purpose statement: To empower one billion creators by making software creation more accessible, immediate, and real, regardless of technical background. ## Products & Services - **Replit Agent (Agent 4)**: An AI agent that writes production-ready code, evolves it, and handles the coordination and execution of building apps. Users describe and publish projects using natural language. - **Collaborative IDE**: A browser-based, full-stack integrated development environment that allows real-time coding and collaboration, with no local setup required. - **Replit Platform (Core)**: A full-stack cloud solution including built-in services for Authentication, Database, Hosting, and Monitoring, enabling scalable app development from day one. - **Integrations**: Connects to 100+ services and APIs, including OpenAI, Stripe, and Google Workspace. - **Enterprise Controls**: Features include SSO/SAML, SOC 2 compliance, admin controls, and secure screening services. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed (Series D) - **Key Metric**: Total Funding of $872M raised (as of latest Series D); over 50 million users on the platform. - **Notable Investors/Partners**: Not detailed in search results, but the company is well-funded at the Series D stage with a strong investor base. - **Growth Signals**: Over 50 million creators on the platform; rapid adoption of AI Agent capabilities; expansion into enterprise with Forward Deployed Engineering; active hiring across 28+ open roles as of mid-2026. ## Competitive Advantages - **Agentic Creation**: The "Agent 4" feature allows non-programmers to build and ship software through natural language, radically lowering the barrier to entry. - **All-in-One Platform**: Combines IDE, AI, hosting, database, authentication, and monitoring in a single, browser-based environment, eliminating setup friction. - **Full-Stack Infrastructure**: Offers scalable services (Auth, DB, Hosting) that work out of the box, enabling rapid prototyping and deployment without DevOps overhead. - **Massive User Base**: 50M+ creators provide a strong network effect and a rich ecosystem for learning and sharing. ## Strategic Focus - **Democratizing Software Creation**: Focus on making software creation as intuitive as using a smartphone, targeting the "next billion creators" beyond traditional developers. - **AI-Native Development**: Prioritizing AI agents (Agent 4) that handle complex coding and coordination, allowing humans to focus on ideas and planning. - **Enterprise Adoption**: Building enterprise-grade security (SOC 2, SSO) and dedicated Forward Deployed Engineering teams to capture business customers. - **Platform Ecosystem**: Expanding integrations and third-party services to make the platform a central hub for all software creation needs. ## Why Work Here - **Culture**: Described as a place for "builders who care about craft, speed, and making things that matter." The company values "ideas first. Proof matters. Momentum wins." - **Work Style**: "In person, on purpose." Replit emphasizes working from its HQ in Foster City, believing that proximity accelerates decisions and improves work quality. It operates a hybrid model with a strong in-office expectation. - **Compensation & Benefits**: - Competitive salary, equity, and performance bonus - Health, dental, and vision insurance with HSA contributions ($2k individual / $4k family) - 24 weeks paid birth-parent leave; 12 weeks paid bonding and family care leave - 401K with company matching - $1,000 annual learning & development reimbursement - Monthly wellness stipend, commuter benefits, and in-office meals (breakfast, lunch, dinner) - Flexible time off and paid sick leave - **Engineering Culture**: Strong emphasis on building resilient, scalable systems (Kubernetes, GCP). Roles like Staff Infrastructure Engineer and GRC Engineer indicate a mature, security-conscious engineering environment. ## Sources 1. [replit.com/careers](https://replit.com/careers) 2. [replit.com/about](https://replit.com/about) 3. [replit.com](https://replit.com/) 4. [tryjeremy.com/companies/replit](https://tryjeremy.com/companies/replit) 5. [jobs.ashbyhq.com/replit](https://jobs.ashbyhq.com/replit) ## Other roles at Replit - [Cohort 0](https://feeny.ai/job/cohort-0-replit-foster-city-9qgx2vpykne6) — Foster City, CA - [Learning Experiences Creator](https://feeny.ai/job/learning-experiences-creator-replit-foster-city-j76ttn67ggbm) — Foster City, CA - [Legal Operations Manager](https://feeny.ai/job/legal-operations-manager-replit-foster-city-vvmg0ffrmhrs) — Foster City, CA - [Mid-Market Account Manager](https://feeny.ai/job/mid-market-account-manager-replit-foster-city-wkhdp50frw73) — Foster City, CA - [Support Systems Lead (NYC)](https://feeny.ai/job/support-systems-lead-nyc-replit-new-york-jww52bg2br8x) — New York, NY - [Support Systems Lead (Foster City)](https://feeny.ai/job/support-systems-lead-foster-city-replit-foster-city-ve93df5afrc9) — Foster City, CA - [Director of Product Design](https://feeny.ai/job/director-of-product-design-replit-foster-city-rzhv29ay6b1q) — Foster City, CA - [Forward Deployed Engineer](https://feeny.ai/job/forward-deployed-engineer-replit-foster-city-sjfk5dgczbg7) — Foster City, CA - [Director of Compensation Strategy](https://feeny.ai/job/director-of-compensation-strategy-replit-foster-city-dr2wq26g194b) — Foster City, CA - [Social Media Support Specialist (NYC, Weekend Shift, Sunday to Thursday)](https://feeny.ai/job/social-media-support-specialist-nyc-weekend-shift-sunday-to-thursday-replit-new-wwqfv271dfkq) — New York, NY