Platform Security [US]
AI in this role
Rebuild how the world works, to make institutions work better for the people they serve.
About Brain Co.Brain Co. builds AI-native operating systems for large, regulated institutions. Each system is built for a specific industry, powered by agents that push real workflows forward. Underneath it all is Atlas, our proprietary platform that keeps customers in control, secure by design, and never locked into one model.
Why NowBrain Co. is entering its next phase of production deployments on a national scale with an elite team built from Palantir, Google, Meta, and Nvidia, and a growing footprint across government, insurance, health, and financial services.
Joining now means shaping both the company and a new category of applied AI. Every project here ships to production and is expected to create measurable customer value and impact.
You'll work alongside exceptional peers on some of the hardest problems in applied AI. It’s the kind of work you'll still be proud of in ten years from now.
About the Role:
We’re looking for a Platform Security Engineer to build the guardrails that keep our AI agents safe to run on real customer data. This isn’t a policy or compliance role—it’s a builder role. You’ll design and ship the code that constrains what an agent can access, do, and expose: scoped credentials, data access boundaries, action validation, and audit trails, so product teams can put agents in front of sensitive government, healthcare, and enterprise data with confidence.
You’ll work as a software engineer embedded with our product and agent-platform teams—writing production code, not just policy—to make the secure path the only path an agent can take.
What You’ll Build & Ship
Design and build the guardrail services that mediate actions an AI agent takes, scoped permissions, tool-call validation, and hard limits on what an agent can read, write, or send
Write production code for data access controls that keep customer PII and sensitive records inside approved boundaries, even when an agent is orchestrating the request
Build reusable guardrail libraries and SDKs so product engineers can drop data protection and permissioning into new agent workflows without reinventing it each time
Design detection and containment for agent-specific failure modes, prompt injection, tool misuse, data exfiltration attempts, and build automated tests and red-team harnesses to catch them before production
Instrument agents with tamper-evident audit logs and decision trails so every customer-data access is explainable after the fact
Partner with product, platform and ML engineering to review new agent capabilities before launch and flag where guardrails are missing
Own the developer experience for guardrails: clear APIs, documentation, and low-friction integration so engineers adopt controls instead of routing around them
Help define and measure guardrail effectiveness, coverage across security workflows, false positive/negative rates, mean time to detect and contain
What We’re Looking For
Required
5 to 8 years as a software engineer building and shipping production systems, with meaningful time spent on security, data protection, or trust & safety problems
Strong general-purpose programming skills (Python, Go, TypeScript, or similar), comfortable designing services and APIs other engineers depend on, not just writing scripts or config
Experience with or strong working knowledge of how AI agents operate in production, tool use, function calling, orchestration frameworks (LangChain, LangGraph, or similar)
Solid grasp of data protection fundamentals: PII handling, access control, encryption, and least privilege, and how they hold up once an agent is in the loop
Comfortable designing systems used by other engineers—clear interfaces, sensible defaults, predictable failure modes
Working cloud experience (AWS, GCP, or Azure) sufficient to build and deploy services securely
Comfortable across the SDLC, understands how developers work and designs guardrails that don’t create friction
Strong written English; able to write documentation and runbooks engineers actually read
Nice to Have
Direct experience building guardrails or safety layers for LLM/agent systems—prompt injection defenses, content filtering, output validation
Background in regulated industries (healthcare, government, financial services) handling sensitive customer data
Familiarity with policy-as-code, secrets management, or software supply-chain security tooling
Prior startup experience; comfort with ambiguity and working autonomously
Why This Role
You’ll have real ownership and clear scope: a defined guardrail surface across our platform, and the mandate to build. Your code will ship into production and directly shape how safely our agents operate on customer data as the platform grows. If you’re a software engineer who wants to spend more time building than advising, this is that role.
To apply, send your CV and a brief note on a guardrail, safety control, or piece of security tooling you’ve built to [hiring contact].
How we rate this
Platform Security [US] at Brain Co rates 87 out of 100 for how much of the daily work is AI. That makes it Builds AI (AI Level 4 of 4). The level is about AI in the job, not seniority.
Builds AI. The job is building AI systems.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- How do you decide when an AI agent can act on its own versus asking for approval first?
- Walk me through how you've used LangChain in your day-to-day work.
- What are the limits of LangGraph that you've run into, and how did you work around them?
- How would you decide a model or AI system is ready to ship?
- Tell me about a time a model underperformed in production. How did you find out, and what did you change?
Adapt your resume
- List these exact terms on your resume: AI Agents, LangChain, and LangGraph. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
- Lead with what you built, trained or shipped — this role is judged on the AI system itself, not the tools around it.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new remote AI jobs (Builds AI ●●●●) by email
One email a week with the new remote AI jobs (Builds AI ●●●●), each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that build AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step