Arize AI is the leading AI & Agent Engineering observability and evaluation platform, empowering AI engineers to ship high-performing, reliable agents and applications. They are seeking a DevSecOps Engineer to embed security into the software shipping process, focusing on designing secure workflows and tools for agentic AI systems.
Responsibilities:
- Design and implement guardrails for agentic AI workflows — including tool-use sandboxing, prompt-injection defenses, MCP server hardening, secret scoping for agents, and runtime policy enforcement
- Build internal tooling in TypeScript: SDKs, CLI utilities, GitHub Actions, custom linters, and developer-facing dashboards that make the secure path the easy path
- Threat-model new features alongside product engineers, especially those involving LLM integrations, autonomous agents, or third-party tool calls
- Integrate and tune SAST, DAST, SCA, secret scanning, and IaC scanning (Terraform, Kubernetes manifests, Helm) into pull-request workflows with low-friction feedback loops
- Lead incident response for security events, coordinating cross-functionally and producing blameless postmortems that improve our systems, not assign blame
- Partner with the AI/ML team on responsible deployment of agents — defining what "trusted action" means, what telemetry we need, and how we contain blast radius when an agent misbehaves
- Mentor engineers across the org on secure coding patterns in TypeScript and on the unique risks of building with LLMs and agent frameworks
Requirements:
- 4+ years of hands-on experience in DevSecOps, application security, or platform security roles
- Strong working knowledge of TypeScript and the Node.js ecosystem
- Practical experience securing cloud infrastructure (AWS, GCP, or Azure), containers, and Kubernetes
- Fluency with modern CI/CD tooling (GitHub Actions, or similar) and IaC (Terraform, Pulumi)
- Genuine curiosity about — and ideally hands-on experience with agentic AI systems: LLM tool use, function calling, MCP, agent frameworks (LangGraph, OpenAI Agents SDK, Anthropic SDK, etc.), and the emerging security patterns around them
- A collaboration-first mindset. You write clearly, give feedback kindly, and would rather pair on a problem than throw a Jira ticket over the wall
- Comfort with ambiguity — the security playbook for agentic systems is being written in real time, and you want to help write it
- Experience with prompt-injection research, LLM red-teaming, or AI safety/evals work
- Contributions to open-source, especially in the TypeScript or AI or Security ecosystems
- Familiarity with SOC 2, ISO 27001, or similar compliance frameworks — and opinions on how to satisfy them without crushing engineering velocity
- Background in incident response or detection engineering at a fast-moving company