Platform Security [US]

Brain Co.•San Francisco, CA

About The Position

We’re looking for a Platform Security Engineer to build the guardrails that keep our AI agents safe to run on real customer data. This isn’t a policy or compliance role—it’s a builder role. You’ll design and ship the code that constrains what an agent can access, do, and expose: scoped credentials, data access boundaries, action validation, and audit trails, so product teams can put agents in front of sensitive government, healthcare, and enterprise data with confidence. You’ll work as a software engineer embedded with our product and agent-platform teams—writing production code, not just policy—to make the secure path the only path an agent can take.

Requirements

  • 5 to 8 years as a software engineer building and shipping production systems, with meaningful time spent on security, data protection, or trust & safety problems
  • Strong general-purpose programming skills (Python, Go, TypeScript, or similar), comfortable designing services and APIs other engineers depend on, not just writing scripts or config
  • Experience with or strong working knowledge of how AI agents operate in production, tool use, function calling, orchestration frameworks (LangChain, LangGraph, or similar)
  • Solid grasp of data protection fundamentals: PII handling, access control, encryption, and least privilege, and how they hold up once an agent is in the loop
  • Comfortable designing systems used by other engineers—clear interfaces, sensible defaults, predictable failure modes
  • Working cloud experience (AWS, GCP, or Azure) sufficient to build and deploy services securely
  • Comfortable across the SDLC, understands how developers work and designs guardrails that don’t create friction
  • Strong written English; able to write documentation and runbooks engineers actually read

Nice To Haves

  • Direct experience building guardrails or safety layers for LLM/agent systems—prompt injection defenses, content filtering, output validation
  • Background in regulated industries (healthcare, government, financial services) handling sensitive customer data
  • Familiarity with policy-as-code, secrets management, or software supply-chain security tooling
  • Prior startup experience; comfort with ambiguity and working autonomously

Responsibilities

  • Design and build the guardrail services that mediate actions an AI agent takes, scoped permissions, tool-call validation, and hard limits on what an agent can read, write, or expose
  • Write production code for data access controls that keep customer PII and sensitive records inside approved boundaries, even when an agent is orchestrating the request
  • Build reusable guardrail libraries and SDKs so product engineers can drop data protection and permissioning into new agent workflows without reinventing it each time
  • Design detection and containment for agent-specific failure modes, prompt injection, tool misuse, data exfiltration attempts, and build automated tests and red-team harnesses to catch them before production
  • Instrument agents with tamper-evident audit logs and decision trails so every customer-data access is explainable after the fact
  • Partner with product, platform and ML engineering to review new agent capabilities before launch and flag where guardrails are missing
  • Own the developer experience for guardrails: clear APIs, documentation, and low-friction integration so engineers adopt controls instead of routing around them
  • Help define and measure guardrail effectiveness, coverage across security workflows, false positive/negative rates, mean time to detect and contain
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service