> Markdown version of [/jobs/ext/3040205-platform-security-engineer](https://www.wearedevelopers.com/jobs/ext/3040205-platform-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Platform Security Engineer - **Company:** Brain Corporation - **Location:** San Francisco, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Audit Trail, Automation of Tests, Microsoft Azure, Computer Programming, Customer Data Management, Data Security, Python (Programming Language), Key Management, Machine Learning, Systems Development Life Cycle, Role-Based Access Control, TypeScript, Enterprise Data Management, Policy as Code, Scripting, Large Language Models, Build Management, Kubernetes, Production Code, Virtual Agents, Golang - **Published:** September 23, 2026 - **Apply:** https://startup.jobs/platform-security-us-brain-co-10151364 ## About the Role * 5 to 8 years as a software engineer building and shipping production systems, with meaningful time spent on security, data protection, or trust & safety problems * Strong general-purpose programming skills (Python, Go, TypeScript, or similar), comfortable designing services and APIs other engineers depend on, not just writing scripts or config * Experience with or strong working knowledge of how AI agents operate in production, tool use, function calling, orchestration frameworks (LangChain, LangGraph, or similar) * Solid grasp of data protection fundamentals: PII handling, access control, encryption, and least privilege, and how they hold up once an agent is in the loop * Comfortable designing systems used by other engineers-clear interfaces, sensible defaults, predictable failure modes * Working cloud experience (AWS, GCP, or Azure) sufficient to build and deploy services securely * Comfortable across the SDLC, understands how developers work and designs guardrails that don't create friction * Strong written English; able to write documentation and runbooks engineers actually read, * Direct experience building guardrails or safety layers for LLM/agent systems-prompt injection defenses, content filtering, output validation * Background in regulated industries (healthcare, government, financial services) handling sensitive customer data * Familiarity with policy-as-code, secrets management, or software supply-chain security tooling * Prior startup experience; comfort with ambiguity and working autonomously ## Description We're looking for a Platform Security Engineer to build the guardrails that keep our AI agents safe to run on real customer data. This isn't a policy or compliance role-it's a builder role. You'll design and ship the code that constrains what an agent can access, do, and expose: scoped credentials, data access boundaries, action validation, and audit trails, so product teams can put agents in front of sensitive government, healthcare, and enterprise data with confidence. You'll work as a software engineer embedded with our product and agent-platform teams-writing production code, not just policy-to make the secure path the only path an agent can take. What You'll Build & Ship * Design and build the guardrail services that mediate actions an AI agent takes, scoped permissions, tool-call validation, and hard limits on what an agent can read, write, or send * Write production code for data access controls that keep customer PII and sensitive records inside approved boundaries, even when an agent is orchestrating the request * Build reusable guardrail libraries and SDKs so product engineers can drop data protection and permissioning into new agent workflows without reinventing it each time * Design detection and containment for agent-specific failure modes, prompt injection, tool misuse, data exfiltration attempts, and build automated tests and red-team harnesses to catch them before production * Instrument agents with tamper-evident audit logs and decision trails so every customer-data access is explainable after the fact * Partner with product, platform and ML engineering to review new agent capabilities before launch and flag where guardrails are missing * Own the developer experience for guardrails: clear APIs, documentation, and low-friction integration so engineers adopt controls instead of routing around them * Help define and measure guardrail effectiveness, coverage across security workflows, false positive/negative rates, mean time to detect and contain ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [How to Stop Your Agents From Going Rogue - Arnav Gupta](https://www.wearedevelopers.com/videos/2152-how-to-stop-your-agents-from-going-rogue-arnav-gupta) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) - [The day the chatbot asked for sudo](https://www.wearedevelopers.com/videos/100038-the-day-the-chatbot-asked-for-sudo) ## Related Articles - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)