PRINCIPAL ARCHITECT — AI-NATIVE SECURITY PLATFORM
Openvpn
Contractlead
Job description
The Role
You will own architectural coherence and technical direction across CipherScale’s AI-native platform . A major near- term responsibility is defining and evolving the boundary between AI reasoning, the MCP capability layer, the CipherScale Controller, and customer infrastructure.
This is not a traditional enterprise architecture position. We are looking for a builder who can move between emerging standards, security architecture, product strategy, prototypes, code, and production engineering.
Our philosophy is that we are a small, close-knit team, and we care deeply about you:
•
Competitive pay rates
•
Fully remote work environments
•
Self-managed time off
Important:
•
This will be a permanent employment opportunity for candidates based in Spain. For other locations, it will be a B2B contract.
What You Will Own
AI-Native Platform Architecture
• Define how AI agents securely discover, reason about, and invoke CipherScale capabilities.
• Establish strict separation between probabilistic AI reasoning and deterministic security-sensitive execution.
• Design for CipherScale AI Admin, external AI clients, enterprise integrations, and future machine-to-machine interactions.
MCP Architecture
• Own strategy for MCP Tools, Resources, Apps/UI, long-running Tasks, human-in-the-loop interactions, discovery, authentication, authorization, schema design, and extensions.
• Continuously track relevant MCP specifications, SEPs, SDKs, security guidance, and ecosystem changes.
• Translate important changes into architecture decisions before implementation choices make adoption expensive.
Security Architecture
• Zero Trust and least privilege
• Human, workload, and agent identity
• OAuth/OIDC, RBAC/ABAC/ReBAC
• Credential isolation, ephemeral authorization, secrets and key management
• Prompt injection, confused-deputy attacks, tool poisoning, data exfiltration, and privilege escalation
• Auditability, policy enforcement, and non-repudiation
Core principle: the model may reason, recommend, and request actions, but it must never become the authorization authority.
Distributed Systems & Cloud Architecture
• Control-plane and data-plane separation
• SaaS and self-hosted enterprise architectures
• Multi-tenancy, Kubernetes, AWS, Azure, and GCP
• Asynchronous workflows and event-driven systems
• Gateways, proxies, service identity, high availability, and failure recovery
• Observability and OpenTelemetry
About CipherScale
CipherScale is building an AI-native Zero Trust security platform for a world where enterprise infrastructure is increasingly operated by humans and autonomous agents through natural language, agent protocols, and machine- to-machine capabilities.
• AI agents and agentic systems
• Model Context Protocol (MCP)
• Zero Trust, identity, and authorization
• Networking and distributed systems
• Cloud infrastructure and enterprise security
Role summary: A hands-on principal architect who will own architectural coherence across CipherScale’s AI-native security platform, with particular responsibility for agentic systems, MCP, Zero Trust, distributed systems, cloud infrastructure, and security boundaries.