
Principal Architect — AI-Native Security Platform
Primary stack
Job description
About the Position
Principal Architect - AI-Native Security Platform
- Remote
- Spain, Andalucía, Spain
- Poland, Mazowieckie, Poland
- Andorra, Canillo, Andorra
- Brussels, Brussels, Belgium
- Bosnia and Herzegovina, Federacija Bosne i Hercegovine, Bosnia and Herzegovina
- Albania, Berat, Albania
- Sofia, Sofia, Bulgaria
- Zagreb, Zagrebačka županija, Croatia
- Nicosia, Lefkosia, Cyprus
- Praha, Praha, Hlavní město, Czechia
- Tallinn, Harjumaa, Estonia
- Germany, Berlin, Germany
- Budapest, Budapest, Hungary
- Valletta, Valletta, Malta
- Chișinău, Chișinău, Moldova, Republic of
- Montenegro, Andrijevica, Montenegro
- North Macedonia, Veles, North Macedonia
- Lisbon, Lisboa, Portugal
- Romania, București, Romania
- Bratislava, Bratislavský kraj, Slovakia
- Ljubljana, Ljubljana, Slovenia
- +20 more
The Role
You will own architectural coherence and technical direction across CipherScale’s AI-native platform. A major near-term responsibility is defining and evolving the boundary between AI reasoning, the MCP capability layer, the CipherScale Controller, and customer infrastructure.
This is not a traditional enterprise architecture position. We are looking for a builder who can move between emerging standards, security architecture, product strategy, prototypes, code, and production engineering.
Our philosophy is that we are a small, close-knit team, and we care deeply about you:
- Competitive pay rates
- Fully remote work environments
- Self-managed time off
Important:
- This will be a permanent employment opportunity for candidates based in Spain. For other locations, it will be a B2B contract.
Responsibilities
AI-Native Platform Architecture
- Define how AI agents securely discover, reason about, and invoke CipherScale capabilities.
- Establish strict separation between probabilistic AI reasoning and deterministic security-sensitive execution.
- Design for CipherScale AI Admin, external AI clients, enterprise integrations, and future machine-to-machine interactions.
MCP Architecture
- Own strategy for MCP Tools, Resources, Apps/UI, long-running Tasks, human-in-the-loop interactions, discovery, authentication, authorization, schema design, and extensions.
- Continuously track relevant MCP specifications, SEPs, SDKs, security guidance, and ecosystem changes.
- Translate important changes into architecture decisions before implementation choices make adoption expensive.
Security Architecture
- Zero Trust and least privilege
- Human, workload, and agent identity
- OAuth/OIDC, RBAC/ABAC/ReBAC
- Credential isolation, ephemeral authorization, secrets and key management
- Prompt injection, confused-deputy attacks, tool poisoning, data exfiltration, and privilege escalation
- Auditability, policy enforcement, and non-repudiation
Core principle: the model may reason, recommend, and request actions, but it must never become the authorization authority.
Distributed Systems & Cloud Architecture
- Control-plane and data-plane separation
- SaaS and self-hosted enterprise architectures
- Multi-tenancy, Kubernetes, AWS, Azure, and GCP
- Asynchronous workflows and event-driven systems
- Gateways, proxies, service identity, high availability, and failure recovery
- Observability and OpenTelemetry
Requirements
Required Strengths
- Distributed systems and cloud architecture
- Security architecture and Zero Trust
- Identity and authorization
- API and protocol design
- Agentic AI systems and MCP or comparable agent/tool protocols
- SaaS / multi-tenant architecture
- Kubernetes and cloud-native systems
- Networking, event-driven systems, observability, and key management
- Strong software engineering skills and ability to prototype
What Matters Most
- Learning velocity - reads specifications, follows emerging standards, prototypes quickly, and recognizes architectural shifts early.
- Systems thinking - naturally reasons about trust boundaries, failure modes, data flows, state, scaling, and operability.
- Security mindset - asks how a system can fail or be abused, not only how it works.
- Product judgment - understands how architecture affects speed, trust, customer value, and differentiation.
What We Don’t Want
- Governance-heavy enterprise architecture without implementation responsibility
- Architecture-by-PowerPoint or process-first TOGAF bureaucracy
- Pure prompt engineering without distributed-systems and security depth
- Treating AI as simply another REST client
- Technology recommendations without hands-on validation
We Offer
- Competitive salary and comprehensive benefits
- A senior ownership role with responsibility for a critical engineering surface
- The autonomy to define platform strategy, standards, and technical direction
- The opportunity to build foundational systems with immediate, measurable impact
- A fast-moving, AI-native engineering environment
- Direct collaboration with technical leadership and product engineers
- Support to experiment, automate, and introduce better ways of working
- A culture that values speed, ownership, sound judgment, and reliable delivery
About the Company
CipherScale is building an AI-native Zero Trust security platform for a world where enterprise infrastructure is increasingly operated by humans and autonomous agents through natural language, agent protocols, and machine-to-machine capabilities.
- AI agents and agentic systems
- Model Context Protocol (MCP)
- Zero Trust, identity, and authorization
- Networking and distributed systems
- Cloud infrastructure and enterprise security
Role summary: A hands-on principal architect who will own architectural coherence across CipherScale’s AI-native security platform, with particular responsibility for agentic systems, MCP, Zero Trust, distributed systems, cloud infrastructure, and security boundaries.
© OpenVPN. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.
Київ, Львів, United States, Pleasanton CA
More at OpenVPN
All 6 roles
Senior DevOps / Platform Engineer
OpenVPN · Belgium +4

C++ Developer
OpenVPN · Belgium +4

Product Manager (Billing systems and AS Hub)
OpenVPN · Czechia +4

Senior Python Engineer
OpenVPN · Czechia +4
Similar jobs

Lead Azure AI Security Engineer
EPAM · Poland

Senior Director, AI Solutions
Intellias · Spain +4

Senior Director, AI Solutions
Intellias · Spain +4

Senior Director, AI Solutions
Intellias · Spain +4