DevSecOps Engineer (TypeScript & Agentic AI)
Job description
About the role
You will own the design and implementation of security guardrails specifically for agentic AI workflows, including tool-use sandboxing, prompt-injection defenses, and MCP server hardening. You will build and maintain internal developer platforms in TypeScript that make the secure path the easy path for shipping AI features. You will threat-model new capabilities alongside product engineers, especially those involving LLM integrations and autonomous agents. You will lead incident response for security events and coordinate cross-functional postmortems focused on system improvement. You will partner closely with AI and ML teams to define trusted action boundaries and responsible deployment practices for autonomous agents. You will mentor engineers across the organization on secure coding patterns for TypeScript and the unique risks of LLM-driven systems. You will integrate and tune detection and prevention controls across the full development lifecycle, from code to runtime.
Key facts
What you'll do
Design and implement guardrails for agentic AI workflows - including tool-use sandboxing, prompt-injection defenses, MCP server hardening, secret scoping for agents, and runtime policy enforcement.
Build internal tooling in TypeScript: SDKs, CLI utilities, GitHub Actions, custom linters, and developer-facing dashboards that make the secure path the easy path.
Threat-model new features alongside product engineers, especially those involving LLM integrations, autonomous agents, or third-party tool calls.
Integrate and tune SAST, DAST, SCA, secret scanning, and IaC scanning (Terraform, Kubernetes manifests, Helm) into pull-request workflows with low-friction feedback loops.
Lead incident response for security events, coordinating cross-functionally and producing blameless postmortems that improve our systems, not assign blame.
Partner with the AI/ML team on responsible deployment of agents - defining what "trusted action" means, what telemetry we need, and how we contain blast radius when an agent misbehaves.
Mentor engineers across the org on secure coding patterns in TypeScript and on the unique risks of building with LLMs and agent frameworks.
Collaborate with platform and infrastructure teams to embed security into CI/CD pipelines, container images, and Kubernetes controls.
Evaluate and drive adoption of security tools that integrate smoothly into developer workflows without sacrificing coverage or accuracy.
Contribute to architecture decisions that affect observability, auditability, and compliance for AI-driven systems at scale.
Participate in on-call rotations and respond to production security alerts with clear communication and actionable remediation steps.
Champion secure development practices through documentation, code samples, and enablement sessions that reduce friction for shipping teams.
Continuously measure the effectiveness of security controls and iterate based on detection efficacy, developer feedback, and emerging threats.
Represent Arize AI in technical discussions with partners and customers around security and compliance for AI applications.
Requirements
4+ years of hands-on experience in DevSecOps, application security, or platform security roles.
Strong working knowledge of TypeScript and the Node.js ecosystem.
Practical experience securing cloud infrastructure (AWS, GCP, or Azure), containers, and Kubernetes.
Fluency with modern CI/CD tooling (GitHub Actions, or similar) and IaC (Terraform, Pulumi).
Genuine curiosity about AI/ML systems and the security implications of agentic behavior.
Experience implementing security controls in automated pipelines and runtime environments.
Strong understanding of identity and access management, encryption in transit and at rest, and secrets management.
Ability to collaborate closely with cross-functional teams and communicate tradeoffs clearly to both technical and non-technical stakeholders.
Practical notes
The role is based in a Remote/Hybrid model with a preference for candidates in the Southern California area. There are no specified working hour constraints in the posting, and the engagement type is listed as See source. Compensation details are not provided in the source material. Travel requirements are not specified beyond the location guidance. Visa sponsorship information is not detailed in the provided source, and no application deadline is mentioned. You should expect collaboration with AI and ML teams, platform engineers, and product teams in a fast-moving environment focused on observability and evaluation for agentic AI systems.