Rodeo
Get started

cipherscale

Principal Architect - AI Native Security Platform

United Kingdom
Posted about 24 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Principal Architect / AI-Native Security Platform

CipherScale | Full-Time | Senior Individual Contributor / Technical Leadership

Role summary

A hands-on principal architect who will own architectural coherence across CipherScale’s AI-native security platform, with particular responsibility for agentic systems, MCP, Zero Trust, distributed systems, cloud infrastructure, and security boundaries.

About CipherScale

CipherScale is building an AI-native Zero Trust security platform for a world where enterprise infrastructure is increasingly operated by humans and autonomous agents through natural language, agent protocols, and machine-to-machine capabilities.

  • AI agents and agentic systems
  • Model Context Protocol (MCP)
  • Zero Trust, identity, and authorisation
  • Networking and distributed systems
  • Cloud infrastructure and enterprise security

The Role

You will own architectural coherence and technical direction across CipherScale’s AI-native platform. A major near-term responsibility is defining and evolving the boundary between AI reasoning, the MCP capability layer, the CipherScale Controller, and customer infrastructure.

This is not a traditional enterprise architecture position. We are looking for a builder who can move between emerging standards, security architecture, product strategy, prototypes, code, and production engineering.

What You Will Own

1) AI-Native Platform Architecture

  • Define how AI agents securely discover, reason about, and invoke CipherScale capabilities.
  • Establish strict separation between probabilistic AI reasoning and deterministic security-sensitive execution.
  • Design for CipherScale AI Admin, external AI clients, enterprise integrations, and future machine-to-machine interactions.

2) MCP Architecture

  • Own strategy for MCP Tools, Resources, Apps/UI, long-running Tasks, human-in-the-loop interactions, discovery, authentication, authorisation, schema design, and extensions.
  • Continuously track relevant MCP specifications, SEPs, SDKs, security guidance, and ecosystem changes.
  • Translate important changes into architecture decisions before implementation choices make adoption expensive.

3) Security Architecture

  • Zero Trust and least privilege
  • Human, workload, and agent identity
  • OAuth/OIDC, RBAC/ABAC/ReBAC
  • Credential isolation, ephemeral authorization, secrets and key management
  • Prompt injection, confused-deputy attacks, tool poisoning, data exfiltration, and privilege escalation
  • Auditability, policy enforcement, and non-repudiation

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Core principle: the model may reason, recommend, and request actions, but it must never become the authorization authority.

4) Distributed Systems & Cloud Architecture

  • Control-plane and data-plane separation
  • SaaS and self-hosted enterprise architectures
  • Multi-tenancy, Kubernetes, AWS, Azure, and GCP
  • Asynchronous workflows and event-driven systems
  • Gateways, proxies, service identity, high availability, and failure recovery
  • Observability and OpenTelemetry

5) Capability & Protocol Design

Help define semantic, agent-consumable capabilities rather than simply mirroring REST endpoints. Examples include deploy_gateway(), preview_gateway_deployment(), diagnose_gateway(), grant_access(), investigate_access_problem(), evaluate_policy_change(), and review_security_posture().

Example Architecture Problem

An administrator tells CipherScale AI: “Deploy a CipherScale gateway into our production AWS VPC in Frankfurt.” The architecture may need to support: intent → capability discovery → MCP tool → identity and authorization → required information → deployment preview → interactive approval → credential acquisition → asynchronous deployment → Controller → AWS → progress monitoring → verification → audit.

Then the constraints change: the Controller runs inside the customer environment, cannot accept inbound connections, topology data cannot leave Germany, the AI may be prompt-injected, and the same capability must also work for an external enterprise agent. Your job is to design an architecture that remains coherent as those constraints evolve.

6) Architectural Leadership

  • Architecture Decision Records (ADRs) and architectural invariants
  • Trust-boundary documentation and threat models
  • Cross-team design reviews and protocol/API conventions
  • Architecture diagrams and technical debt identification
  • Technology radar and fast prototypes for uncertain architectural bets

Architecture should accelerate engineering, not become bureaucracy.

Hands-On Expectations

  • Read production code and review important PRs
  • Build prototypes and test emerging protocols/SDKs
  • Debug distributed systems and validate assumptions experimentally
  • Work directly with senior engineers on architecture-critical implementations

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

We expect approximately 20–30% hands-on technical work, especially in new or uncertain architectural areas.

What We’re Looking For

You likely have deep experience building complex distributed platforms, security products, cloud infrastructure, networking systems, developer platforms, or similarly demanding systems. More important than years of experience is evidence that you have personally designed systems that survived real-world scale, security threats, organizational complexity, and changing requirements.

Required Strengths

  • Distributed systems and cloud architecture
  • Security architecture and Zero Trust
  • Identity and authorization
  • API and protocol design
  • Agentic AI systems and MCP or comparable agent/tool protocols
  • SaaS / multi-tenant architecture
  • Kubernetes and cloud-native systems
  • Networking, event-driven systems, observability, and key management
  • Strong software engineering skills and ability to prototype

What Matters Most

  • Learning velocity - reads specifications, follows emerging standards, prototypes quickly, and recognizes architectural shifts early.
  • Systems thinking - naturally reasons about trust boundaries, failure modes, data flows, state, scaling, and operability.
  • Security mindset - asks how a system can fail or be abused, not only how it works.
  • Product judgment - understands how architecture affects speed, trust, customer value, and differentiation.

What We Don’t Want

  • Governance-heavy enterprise architecture without implementation responsibility
  • Architecture-by-PowerPoint or process-first TOGAF bureaucracy
  • Pure prompt engineering without distributed-systems and security depth
  • Treating AI as simply another REST client
  • Technology recommendations without hands-on validation

How We Will Interview

We will use real CipherScale architecture problems rather than relying primarily on algorithm puzzles. Candidates will be asked to design an AI-driven, Zero Trust infrastructure workflow and then respond as security, deployment, residency, and protocol constraints change.

We are evaluating reasoning quality, tradeoff judgment, trust-boundary design, practical implementation instincts, and the ability to turn architecture into something engineers can build.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Distributed Systems
Zero Trust Architecture
AI Agentic Systems
Model Context Protocol (MCP)
Cloud Infrastructure
Identity and Authorization
API Design
Kubernetes
SaaS Architecture
Network Security
OAuth/OIDC
RBAC/ABAC/ReBAC
Threat Modeling
Event-Driven Systems
Observability
Prototyping

Location

United Kingdom

Sign up to applySee more jobs like this