New The Skills of Tomorrow: how AI-exposed is every skill in 2026? See the data →
NVIDIA

Principal Security Architect, Agent Policy Fabric

NVIDIA
Apply →
senior full-time

First indexed 24 Jun 2026

Description

NVIDIA's Cloud Engineering & Services team is seeking a Principal Security Architect to lead cross-company security architecture for agentic AI. The successful candidate will use Agent Policy Fabric as a starting point for enterprise agent governance, coordinating efforts among security product teams, OpenShell, and runtime groups.

Job Summary: The Principal Security Architect will define the cross-company reference architecture for governed agent actions, including durable policies, runtime controls, adapter boundaries, credential mediation, detector response, audit correlation, failure modes, and production-readiness criteria.

Key Responsibilities:

  • Lead Enterprise Agent Security Architecture: Define the cross-company reference architecture for governed agent actions.
  • Drive APF as a Governance Starting Point: Translate Agent Policy Fabric concepts into executive-ready decision papers, engineering standards, threat models, control objectives, and implementation achievements.
  • Align Cross-Organization Owners: Partner with Product Security, OpenShell, Omnistation, Identity, IT, Fleet/MDM, SecOps, 3S, legal/privacy, and corporate-resource owners to define who owns each control surface and how agent workflows move from proof-of-life to enterprise pilot.
  • Build Security Review and Adoption: Establish review patterns for agent workflows, including policy authoring, approval, signing, runtime admission, credential issuance, direct-egress controls, audit evidence, managing anomalies, and break-glass procedures.
  • Represent the Architecture: Brief senior leaders, customer-facing teams, and partner engineering teams on NVIDIA's agent security posture, APF maturation path, open decisions, known limitations, and the evidence required before broader deployment.

Requirements:

  • Bachelor's degree (or equivalent experience) with 15+ years of industry experience in security architecture, product security, enterprise security platforms, identity and access management, cloud security, or infrastructure governance.
  • Security Architecture Leadership: Validated ability to lead ambiguous, cross-functional security initiatives across product, platform, infrastructure, IT, and security operations teams.
  • Agent AI Security Judgment: Practical understanding of agentic AI risks, tool-call governance, prompt-injection limits, sandbox boundaries, credential exposure risks, audit requirements, and the difference between containment, authorization, and monitoring.
  • Enterprise Control Design: Experience designing controls around identity, authorization, policy, secrets, network egress, runtime isolation, telemetry, SIEM integration, exception workflows, and compliance evidence.
  • Executive and Engineering Communication: Ability to write crisp architecture memos, decision records, threat models, standards, and adoption plans that are useful to both senior leaders and implementation teams.

Nice to Have:

  • Agent Governance Experience: Experience securing agent platforms, AI copilots, autonomous workflows, MCP-style tool systems, sandboxed runtimes, or governed access to enterprise SaaS and engineering systems.
  • Policy and Identity Depth: Familiarity with OPA/Rego, Cedar, Zanzibar-style authorization, OAuth/OIDC, SAML, workload identity, delegated authorization, signed configuration, or enterprise trust-root distribution.
  • Large-Scale Security Programs: Track record driving company-wide security architecture across multiple business units, including standards, rollout plans, risk acceptance, exception handling, and measurable adoption.
  • External-Facing Architecture: Experience explaining security architecture to executives, customers, partners, standards bodies, or field teams while preserving bounded claims and clear implementation caveats.