Back to jobs

PRINCIPAL ARCHITECT — AI-NATIVE SECURITY PLATFORM

Openvpn
Contractlead

Job description

The Role You will own architectural coherence and technical direction across CipherScale’s AI-native platform . A major near- term responsibility is defining and evolving the boundary between AI reasoning, the MCP capability layer, the CipherScale Controller, and customer infrastructure. This is not a traditional enterprise architecture position. We are looking for a builder who can move between emerging standards, security architecture, product strategy, prototypes, code, and production engineering. Our philosophy is that we are a small, close-knit team, and we care deeply about you: • Competitive pay rates • Fully remote work environments • Self-managed time off Important: • This will be a permanent employment opportunity for candidates based in Spain. For other locations, it will be a B2B contract. What You Will Own AI-Native Platform Architecture • Define how AI agents securely discover, reason about, and invoke CipherScale capabilities. • Establish strict separation between probabilistic AI reasoning and deterministic security-sensitive execution. • Design for CipherScale AI Admin, external AI clients, enterprise integrations, and future machine-to-machine interactions. MCP Architecture • Own strategy for MCP Tools, Resources, Apps/UI, long-running Tasks, human-in-the-loop interactions, discovery, authentication, authorization, schema design, and extensions. • Continuously track relevant MCP specifications, SEPs, SDKs, security guidance, and ecosystem changes. • Translate important changes into architecture decisions before implementation choices make adoption expensive. Security Architecture • Zero Trust and least privilege • Human, workload, and agent identity • OAuth/OIDC, RBAC/ABAC/ReBAC • Credential isolation, ephemeral authorization, secrets and key management • Prompt injection, confused-deputy attacks, tool poisoning, data exfiltration, and privilege escalation • Auditability, policy enforcement, and non-repudiation Core principle: the model may reason, recommend, and request actions, but it must never become the authorization authority. Distributed Systems & Cloud Architecture • Control-plane and data-plane separation • SaaS and self-hosted enterprise architectures • Multi-tenancy, Kubernetes, AWS, Azure, and GCP • Asynchronous workflows and event-driven systems • Gateways, proxies, service identity, high availability, and failure recovery • Observability and OpenTelemetry About CipherScale CipherScale is building an AI-native Zero Trust security platform for a world where enterprise infrastructure is increasingly operated by humans and autonomous agents through natural language, agent protocols, and machine- to-machine capabilities. • AI agents and agentic systems • Model Context Protocol (MCP) • Zero Trust, identity, and authorization • Networking and distributed systems • Cloud infrastructure and enterprise security Role summary: A hands-on principal architect who will own architectural coherence across CipherScale’s AI-native security platform, with particular responsibility for agentic systems, MCP, Zero Trust, distributed systems, cloud infrastructure, and security boundaries.