Skip to job description
Home Security Fabric AI Servers FAQ Resources Careers Contact Sales

AI Security & Governance Engineering

Principal Agentic Security & Governance Engineer

Convert agentic risk into enforceable controls, adversarial tests, measurable behavior, and verifiable evidence.

Remote/Hybrid, United States; periodic customer and production-site travel Full-time Reports to Chief Technology Officer

Job Description

We’re looking for a Principal Agentic Security & Governance Engineer - someone who can convert agentic risk into enforceable software controls, adversarial tests, measurable behavior, and customer-verifiable evidence.

Think of this as the engineer responsible for making sure an autonomous system does not merely receive instructions, but operates inside a clearly defined and technically enforced boundary.

You don’t write a policy deck and hand it to another team. You design agent identity, authorization, delegation, memory boundaries, egress restrictions, approval gates, tool permissions, resource limits, audit systems, and termination controls. Then you attempt to bypass them.

You will help define the security model beneath the Woven Security Fabric and Agentic Orchestration Governance platform. Your work must answer the questions serious enterprise customers will ask:

Who is this agent? What is it permitted to do? Which credentials can it use? What information can it access? Which tools can it invoke? Can it delegate authority? How much can it spend? When must a human approve an action? What happens when policy is violated? What evidence remains afterward?

This role requires deep security thinking, strong software engineering ability, practical experience with distributed systems, and a willingness to test assumptions through direct attack.

In Your Day-to-Day, You Will

  • Own the agentic security threat model across agents, models, tools, credentials, data sources, memory systems, orchestration layers, human approvals, external services, and infrastructure.
  • Design and implement per-agent identity, workload identity, trust-token issuance, credential binding, session controls, and identity lifecycle management.
  • Build fine-grained authorization systems that determine which tools, actions, data sources, services, models, and workflows an agent may access.
  • Establish least-privilege defaults so agents receive only the authority required for a defined task and duration.
  • Design scoped credential systems that reduce standing access, prevent credential reuse, limit delegation, and constrain the consequences of compromise.
  • Build policy-as-code systems that allow security and governance requirements to be versioned, tested, reviewed, approved, and enforced consistently.
  • Create approval gates and human-intervention points for sensitive, irreversible, costly, legally significant, or high-impact actions.
  • Implement resource-governance controls, including time limits, token or model budgets, compute limits, tool-use limits, transaction thresholds, rate limits, and termination conditions.
  • Design delegation controls governing whether, when, and how one agent may create work for another agent or transfer authority.
  • Define memory and information boundaries, including what an agent may store, retrieve, retain, share, summarize, or expose across tasks and identities.
  • Build network and egress controls that limit which external services, domains, protocols, and endpoints an agent or supporting service may contact.
  • Create kill switches, circuit breakers, quarantine procedures, and safe-failure behaviors for policy violations, unexpected behavior, compromised credentials, or runaway workflows.
  • Design tamper-evident audit systems capable of recording identity, policy decisions, tool calls, approvals, data access, resource consumption, delegation, errors, and termination events.
  • Build security evaluation and adversarial-testing harnesses covering prompt injection, unauthorized tool use, policy bypass, privilege escalation, credential misuse, data leakage, unsafe delegation, excessive resource consumption, and audit evasion.
  • Make security testing part of every production release, with defined pass-or-fail criteria for critical controls.
  • Map product claims to technical evidence, identifying the enforcement point, test method, observable result, and customer-facing proof for each major security claim.
  • Develop customer-readable security architecture documents, control inventories, threat models, technical diagrams, evidence packages, and security-questionnaire responses.
  • Support technical demonstrations by showing not only successful agent workflows, but how the platform blocks, records, contains, and explains prohibited behavior.
  • Partner with the Platform & Release Engineer to integrate authorization tests, policy tests, adversarial evaluations, audit verification, and dependency checks into the release process.
  • Partner with the Hardware Production Engineer on device identity, secure boot, trusted hardware, cryptographic key protection, firmware integrity, and system-level trust assumptions.
  • Partner with the Deputy Forward-Deployed Enterprise Engineer to understand customer policies and translate them into supported, testable controls rather than custom promises.
  • Support incident investigation and response, including containment, root-cause analysis, evidence preservation, corrective action, and control improvement.

Requirements

  • Significant hands-on experience in security engineering, application security, identity and access management, distributed-systems security, AI security, authorization systems, or a related field.
  • Strong software engineering ability in one or more languages such as Python, Go, Rust, TypeScript, Java, or a comparable language.
  • Deep understanding of authentication, authorization, workload identity, credentials, secrets, certificates, trust boundaries, and least privilege.
  • Experience designing or reviewing policy-enforcement systems, access-control systems, security middleware, identity services, or security-sensitive distributed applications.
  • Practical threat-modeling experience, including the ability to identify assets, trust boundaries, attack paths, abuse cases, failure modes, and mitigations.
  • Experience building automated security tests, adversarial tests, fuzzing systems, abuse-case tests, or other repeatable validation methods.
  • Understanding of modern AI and agentic architectures, including models, prompts, tools, retrieval systems, memory, orchestration, APIs, and autonomous workflows.
  • Ability to reason about the difference between a policy statement and an actual enforcement mechanism.
  • Experience working with logs, audit records, event pipelines, evidence collection, incident investigation, and security telemetry.
  • Ability to explain complex security architecture to software engineers, executive leadership, customer security teams, auditors, and enterprise decision-makers.
  • Willingness to challenge product assumptions, identify uncomfortable failure cases, and prevent unsupported security claims from reaching customers.
  • High agency and independence, with the ability to move from architecture to code to adversarial validation without waiting for a large supporting team.

A specific degree or certification is not required. We care about the systems you have secured, the controls you have built, the failures you have found, and the evidence you can show.

Preferred Experience

  • Multi-agent systems, AI evaluation, model security, LLM applications, autonomous workflows, or agent orchestration.
  • Policy languages and authorization systems such as OPA/Rego, Cedar, Zanzibar-style authorization, capability systems, or comparable approaches.
  • OAuth, OIDC, mTLS, workload identity, service identity, PKI, signed tokens, short-lived credentials, or cryptographic attestation.
  • Secure enclaves, trusted platform modules, hardware security modules, confidential computing, or hardware-rooted identity.
  • Prompt-injection testing, tool-use security, model-behavior evaluation, data-exfiltration testing, or AI red teaming.
  • Tamper-evident logging, signed event records, append-only data systems, or verifiable audit trails.
  • Enterprise governance, control mapping, technical assurance, security architecture review, or audit-evidence production.
  • On-premise, private-cloud, air-gapped, regulated, government, financial, healthcare, industrial, or critical-infrastructure environments.
  • Incident response, digital forensics, detection engineering, or security operations.
  • Early-stage product development where you personally created the security architecture rather than reviewing a finished system.

What Success Looks Like

During your first 30 days, you will produce an initial threat model, identify the highest-risk trust boundaries, review the existing control architecture, and create a prioritized security-engineering plan.

Within 60 days, you will establish a formal control inventory, define enforcement and evidence requirements, and implement automated tests for the most consequential agentic abuse cases.

Within 90 days, Island Mountain should be able to demonstrate per-agent identity, scoped authority, restricted tool access, resource governance, approval controls, safe termination, and exportable audit evidence in a repeatable test environment.

Within six months, the company should have a security evaluation suite that runs as part of the release process, a documented control architecture suitable for enterprise review, and a clear technical response to the most important attack paths affecting agentic systems.

About the Team

We’re Island Mountain, building secure, customer-controlled infrastructure for enterprise AI and autonomous systems.

Our product suite includes Summit Series private compute, the Woven Security Fabric, and Agentic Orchestration Governance - technology designed to give organizations greater control over where AI workloads run, which tools and information agents can access, how actions are authorized, how resources are consumed, and how system activity is recorded.

We are moving from advanced product development into repeatable production and enterprise deployment.

We do not believe governance should exist only in documentation. It should be visible in architecture, expressed in code, tested under pressure, and supported by evidence.

You will help establish what governed agentic infrastructure means in practice.

Ready to Apply?

Send the following to [email protected]:

  • The title of the position
  • Your résumé, LinkedIn profile, GitHub profile, or relevant project history
  • Examples of security controls, authorization systems, evaluations, or threat models you personally built
  • A brief description of an important security assumption you disproved
  • Three to five points describing what you would aim to accomplish during your first 90 days

The door is open.

---

Apply directly

Show us the work you have owned.

Applications are delivered to [email protected]. Include concrete evidence: systems built, failures diagnosed, controls tested, or deployments carried through.

PDF, DOC, or DOCX.

Or apply by email

How we hire

Demonstrated ability over pedigree.

Island Mountain values demonstrated ability, sound judgment, direct ownership, and clear communication.

We encourage applications from people whose experience was gained through traditional employment, independent work, military or public service, entrepreneurship, open-source contribution, skilled technical practice, or nontraditional education.

You do not need to meet every preferred qualification to apply. Requirements describe the work that must be performed; preferred experience identifies backgrounds that may help someone become effective more quickly.

Our hiring process may include:

  1. An introductory conversation focused on motivation, experience, and role alignment
  2. A technical conversation with the responsible executive or engineering lead
  3. A practical work sample based on a realistic Island Mountain problem
  4. A final discussion about ownership, operating style, compensation, and first-90-day expectations

We do not use irrelevant puzzles or performative interview exercises. Our practical assessments are designed to show how you think, communicate, prioritize, document, and execute.

Island Mountain is hiring. The door is open.