OpenVPN logo

Principal Architect — AI-Native Security Platform

OpenVPN·Salary not specified

Primary stack

KubernetesAIAPISaaS

Job description

About the Position

Principal Architect - AI-Native Security Platform

  • Remote
  • Spain, Andalucía, Spain
  • Poland, Mazowieckie, Poland
  • Andorra, Canillo, Andorra
  • Brussels, Brussels, Belgium
  • Bosnia and Herzegovina, Federacija Bosne i Hercegovine, Bosnia and Herzegovina
  • Albania, Berat, Albania
  • Sofia, Sofia, Bulgaria
  • Zagreb, Zagrebačka županija, Croatia
  • Nicosia, Lefkosia, Cyprus
  • Praha, Praha, Hlavní město, Czechia
  • Tallinn, Harjumaa, Estonia
  • Germany, Berlin, Germany
  • Budapest, Budapest, Hungary
  • Valletta, Valletta, Malta
  • Chișinău, Chișinău, Moldova, Republic of
  • Montenegro, Andrijevica, Montenegro
  • North Macedonia, Veles, North Macedonia
  • Lisbon, Lisboa, Portugal
  • Romania, București, Romania
  • Bratislava, Bratislavský kraj, Slovakia
  • Ljubljana, Ljubljana, Slovenia
  • +20 more

The Role

You will own architectural coherence and technical direction across CipherScale’s AI-native platform. A major near-term responsibility is defining and evolving the boundary between AI reasoning, the MCP capability layer, the CipherScale Controller, and customer infrastructure.

This is not a traditional enterprise architecture position. We are looking for a builder who can move between emerging standards, security architecture, product strategy, prototypes, code, and production engineering.

Our philosophy is that we are a small, close-knit team, and we care deeply about you:

  • Competitive pay rates
  • Fully remote work environments
  • Self-managed time off

Important:

  • This will be a permanent employment opportunity for candidates based in Spain. For other locations, it will be a B2B contract.

Responsibilities

AI-Native Platform Architecture

  • Define how AI agents securely discover, reason about, and invoke CipherScale capabilities.
  • Establish strict separation between probabilistic AI reasoning and deterministic security-sensitive execution.
  • Design for CipherScale AI Admin, external AI clients, enterprise integrations, and future machine-to-machine interactions.

MCP Architecture

  • Own strategy for MCP Tools, Resources, Apps/UI, long-running Tasks, human-in-the-loop interactions, discovery, authentication, authorization, schema design, and extensions.
  • Continuously track relevant MCP specifications, SEPs, SDKs, security guidance, and ecosystem changes.
  • Translate important changes into architecture decisions before implementation choices make adoption expensive.

Security Architecture

  • Zero Trust and least privilege
  • Human, workload, and agent identity
  • OAuth/OIDC, RBAC/ABAC/ReBAC
  • Credential isolation, ephemeral authorization, secrets and key management
  • Prompt injection, confused-deputy attacks, tool poisoning, data exfiltration, and privilege escalation
  • Auditability, policy enforcement, and non-repudiation

Core principle: the model may reason, recommend, and request actions, but it must never become the authorization authority.

Distributed Systems & Cloud Architecture

  • Control-plane and data-plane separation
  • SaaS and self-hosted enterprise architectures
  • Multi-tenancy, Kubernetes, AWS, Azure, and GCP
  • Asynchronous workflows and event-driven systems
  • Gateways, proxies, service identity, high availability, and failure recovery
  • Observability and OpenTelemetry

Requirements

Required Strengths

  • Distributed systems and cloud architecture
  • Security architecture and Zero Trust
  • Identity and authorization
  • API and protocol design
  • Agentic AI systems and MCP or comparable agent/tool protocols
  • SaaS / multi-tenant architecture
  • Kubernetes and cloud-native systems
  • Networking, event-driven systems, observability, and key management
  • Strong software engineering skills and ability to prototype

What Matters Most

  • Learning velocity - reads specifications, follows emerging standards, prototypes quickly, and recognizes architectural shifts early.
  • Systems thinking - naturally reasons about trust boundaries, failure modes, data flows, state, scaling, and operability.
  • Security mindset - asks how a system can fail or be abused, not only how it works.
  • Product judgment - understands how architecture affects speed, trust, customer value, and differentiation.

What We Don’t Want

  • Governance-heavy enterprise architecture without implementation responsibility
  • Architecture-by-PowerPoint or process-first TOGAF bureaucracy
  • Pure prompt engineering without distributed-systems and security depth
  • Treating AI as simply another REST client
  • Technology recommendations without hands-on validation

We Offer

  • Competitive salary and comprehensive benefits
  • A senior ownership role with responsibility for a critical engineering surface
  • The autonomy to define platform strategy, standards, and technical direction
  • The opportunity to build foundational systems with immediate, measurable impact
  • A fast-moving, AI-native engineering environment
  • Direct collaboration with technical leadership and product engineers
  • Support to experiment, automate, and introduce better ways of working
  • A culture that values speed, ownership, sound judgment, and reliable delivery

About the Company

CipherScale is building an AI-native Zero Trust security platform for a world where enterprise infrastructure is increasingly operated by humans and autonomous agents through natural language, agent protocols, and machine-to-machine capabilities.

  • AI agents and agentic systems
  • Model Context Protocol (MCP)
  • Zero Trust, identity, and authorization
  • Networking and distributed systems
  • Cloud infrastructure and enterprise security

Role summary: A hands-on principal architect who will own architectural coherence across CipherScale’s AI-native security platform, with particular responsibility for agentic systems, MCP, Zero Trust, distributed systems, cloud infrastructure, and security boundaries.

© OpenVPN. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.

Київ, Львів, United States, Pleasanton CA

More at OpenVPN

All 6 roles

Similar jobs

Popular searches