ShyftLabs
Website:
shyftlabs.io
Job details:
Key Responsibilities• Framework evaluation: Own the evaluation of agentic AI frameworks and architectures, assessing them from a security, identity, and data-flow perspective.
• Approved path ownership: Define and maintain an approved, repeatable build-and-deploy path for agentic workflows — the reference architecture, guardrails, and checklist teams follow to take an agent from prototype to production safely.
• Secure architecture: Design and review secure architectures for cloud-native and agentic applications, with a focus on AWS and GCP.
• Threat modeling: Lead threat modeling for agentic systems specifically — covering tool and function-calling misuse, excessive agency, prompt injection, data exfiltration, and unsafe autonomous actions — and turn findings into concrete mitigations.
• Early engagement: Partner with product and engineering teams during design to review proposed agent architectures and unblock them against the approved path, rather than gatekeeping after the fact.
• Agent identity: Define identity, permissioning, and least-privilege models for agents and the tools and APIs they can invoke.
• Pipeline integration: Collaborate with DevOps and Platform teams to embed agentic-workflow guardrails into CI/CD pipelines and Infrastructure as Code.
• Risk and vulnerability management: Support risk assessment and vulnerability management for agentic and cloud-native systems, including triage, prioritization, and remediation guidance.
• Advisory: Act as the go-to security advisor for agentic AI questions from cross-functional teams based in the Americas.
• Horizon scanning: Stay current on the fast-evolving agentic AI landscape and continuously refine the approved path as the ecosystem matures.
Required Qualifications• 5–8 years of experience in Application Security, Cloud Security, or Security Architecture roles.
• Hands-on familiarity with agentic AI frameworks and concepts (e.g., agent-orchestration frameworks such as LangGraph or similar). You do not need to be a model researcher, but you understand how agents plan, use tools, and act autonomously — and where that introduces risk.
• Strong hands-on experience securing applications and infrastructure on AWS and/or GCP; multi-cloud experience is a plus.
• Solid understanding of secure architecture design principles, threat modeling methodologies (e.g., STRIDE), and the OWASP Top 10 and OWASP ASVS.
• Proven ability to turn architecture evaluations into practical, repeatable standards other teams can self-serve against.
• Experience with Infrastructure as Code (Terraform, CloudFormation, or similar) and CI/CD security practices.
• Familiarity with container and orchestration security (Docker, Kubernetes).
• Excellent written and verbal communication skills in English; comfortable working with distributed, cross-cultural teams.
Preferred Qualifications• Direct hands-on experience building, evaluating, or securing agentic AI systems in production.
• Familiarity with the OWASP Top 10 for LLM Applications.
• Experience with SAST/DAST tooling, secure code review, or application penetration testing.
• Prior experience defining governance frameworks or centers of excellence for emerging technology.
Education & Certifications• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field — or equivalent hands-on experience.
• Security certifications such as AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, CISSP, or OSCP are a plus.
Click on Apply to know more.