Remote/Hybrid (SoCal) Hybrid Employment

Arize AI is hiring a DevSecOps Engineer (TypeScript & Agentic AI)

Responsibilities

  • Create safeguards for AI agent operations, including sandboxing tools, defending against prompt injection, securing server access, limiting secret exposure, and enforcing runtime policies.
  • Develop internal tools using TypeScript, such as SDKs, command-line utilities, GitHub Actions, custom code checkers, and dashboards that promote secure development practices.
  • Collaborate with product engineers to assess threats in new features, particularly those involving large language models, autonomous agents, or external tool integrations.
  • Implement and refine static, dynamic, and software composition analysis tools, along with infrastructure-as-code scanning, into pull request pipelines with fast, actionable feedback.
  • Lead responses to security incidents, working across teams to resolve issues and authoring post-incident reviews focused on system improvement rather than fault-finding.
  • Work closely with AI/ML teams to ensure safe deployment of agents by defining trusted behaviors, required monitoring data, and containment strategies for failures.
  • Guide engineers company-wide in writing secure code with TypeScript and understanding the distinct risks in developing with language models and agent frameworks.

Compensation

Competitive salary and equity package

Work Arrangement

Hybrid or remote options available

Team

Security team collaborating across engineering and AI/ML functions

Responsibilities

  • Design and implement guardrails for agentic AI workflows — including tool-use sandboxing, prompt-injection defenses, MCP server hardening, secret scoping for agents, and runtime policy enforcement.
  • Build internal tooling in TypeScript: SDKs, CLI utilities, GitHub Actions, custom linters, and developer-facing dashboards that make the secure path the easy path.
  • Threat-model new features alongside product engineers, especially those involving LLM integrations, autonomous agents, or third-party tool calls.
  • Integrate and tune SAST, DAST, SCA, secret scanning, and IaC scanning (Terraform, Kubernetes manifests, Helm) into pull-request workflows with low-friction feedback loops.
  • Lead incident response for security events, coordinating cross-functionally and producing blameless postmortems that improve our systems, not assign blame.
  • Partner with the AI/ML team on responsible deployment of agents — defining what "trusted action" means, what telemetry we need, and how we contain blast radius when an agent misbehaves.
  • Mentor engineers across the org on secure coding patterns in TypeScript and on the unique risks of building with LLMs and agent frameworks.

Available for qualified candidates

About company
Arize AI
Arize AI is the leading AI & Agent Engineering observability and evaluation platform, empowering AI engineers to ship high-performing, reliable agents and applications. Arize AX unifies build, test, and run in a single workspace to help teams ship faster with confidence.
All jobs at Arize AI Visit website
Job Details
Category security
Posted 21 hours ago