Arize AI logo
Arize AI·

DevSecOps Engineer (TypeScript & Agentic AI) - Arize AI

About Arize

AI is rapidly transforming the world. As generative AI reshapes industries, teams need powerful ways to monitor, troubleshoot, and optimize their AI systems. That’s where we come in. Arize AI is the leading AI & Agent Engineering observability and evaluation platform, empowering AI engineers to ship high-performing, reliable agents and applications. From first prototype to production scale, Arize AX unifies build, test, and run in a single workspace—so teams can ship faster with confidence.

We’re a Series C company backed by top-tier investors, with over $135M in funding and a rapidly growing customer base of 150+ leading enterprises and Fortune 500 companies. Customers like Booking.com, Uber, Siemens, and PepsiCo leverage Arize to deliver AI that works.

The Opportunity

We're hiring a DevSecOps Engineer to embed security into how we ship software — not as a gate at the end, but as a capability woven through every pipeline, repo, and runtime. You'll work across a TypeScript-heavy stack (Node.js services, Next.js frontends, internal platform tools) and play a central role in how we securely design, deploy, and operate agentic AI systems — autonomous and semi-autonomous AI agents that take real actions on behalf of users and engineers.

This role is deeply collaborative. You'll spend significant time pairing across departments. If you believe security is best delivered as developer experience, you'll feel right at home.

What You'll Do

  • Design and implement guardrails for agentic AI workflows — including tool-use sandboxing, prompt-injection defenses, MCP server hardening, secret scoping for agents, and runtime policy enforcement.
  • Build internal tooling in TypeScript: SDKs, CLI utilities, GitHub Actions, custom linters, and developer-facing dashboards that make the secure path the easy path.
  • Threat-model new features alongside product engineers, especially those involving LLM integrations, autonomous agents, or third-party tool calls.
  • Integrate and tune SAST, DAST, SCA, secret scanning, and IaC scanning (Terraform, Kubernetes manifests, Helm) into pull-request workflows with low-friction feedback loops.
  • Lead incident response for security events, coordinating cross-functionally and producing blameless postmortems that improve systems.
  • Partner with the AI/ML team on responsible deployment of agents — defining what "trusted action" means, what telemetry is needed, and how to contain blast radius when an agent misbehaves.
  • Mentor engineers across the organization on secure coding patterns in TypeScript and on the unique risks of building with LLMs and agent frameworks.

What We're Looking For

  • 4+ years of hands-on experience in DevSecOps, application security, or platform security roles.
  • Strong working knowledge of TypeScript and the Node.js ecosystem.
  • Practical experience securing cloud infrastructure (AWS, GCP, or Azure), containers, and Kubernetes.
  • Fluency with modern CI/CD tooling (GitHub Actions or similar) and IaC (Terraform, Pulumi).
  • Genuine curiosity about — and ideally hands-on experience with — agentic AI systems: LLM tool use, function calling, MCP, agent frameworks (LangGraph, OpenAI Agents SDK, Anthropic SDK, etc.), and emerging security patterns.
  • A collaboration-first mindset, writing clearly, giving thoughtful feedback, and prioritizing pairing.
  • Comfort with ambiguity as security patterns for agentic systems evolve in real time.

Bonus Points

  • Experience with prompt-injection research, LLM red-teaming, or AI safety/evals work.
  • Contributions to open-source software, especially in TypeScript, AI, or security ecosystems.
  • Familiarity with compliance frameworks like SOC 2 or ISO 27001, and how to satisfy them without harming engineering velocity.
  • Background in incident response or detection engineering at a fast-moving organization.

Timezone overlap

UTC-6–-5

Open to

US

Sign in to track applications and earn points.

More roles at Arize AI

Similar remote roles