The Role
You will own architectural coherence and technical direction across CipherScale’s AI-native platform. A major near- term responsibility is defining and evolving the boundary between AI reasoning, the MCP capability layer, the CipherScale Controller, and customer infrastructure.
This is not a traditional enterprise architecture position. We are looking for a builder who can move between emerging standards, security architecture, product strategy, prototypes, code, and production engineering.
Our philosophy is that we are a small, close-knit team, and we care deeply about you:
-
Competitive pay rates
-
Fully remote work environments
-
Self-managed time off
Important:
-
This will be a permanent employment opportunity for candidates based in Spain. For other locations, it will be a B2B contract.
What You Will Own
AI-Native Platform Architecture
- Define how AI agents securely discover, reason about, and invoke CipherScale capabilities.
- Establish strict separation between probabilistic AI reasoning and deterministic security-sensitive execution.
- Design for CipherScale AI Admin, external AI clients, enterprise integrations, and future machine-to-machine interactions.
MCP Architecture
- Own strategy for MCP Tools, Resources, Apps/UI, long-running Tasks, human-in-the-loop interactions, discovery, authentication, authorization, schema design, and extensions.
- Continuously track relevant MCP specifications, SEPs, SDKs, security guidance, and ecosystem changes.
- Translate important changes into architecture decisions before implementation choices make adoption expensive.
Security Architecture
- Zero Trust and least privilege
- Human, workload, and agent identity
- OAuth/OIDC, RBAC/ABAC/ReBAC
- Credential isolation, ephemeral authorization, secrets and key management
- Prompt injection, confused-deputy attacks, tool poisoning, data exfiltration, and privilege escalation
- Auditability, policy enforcement, and non-repudiation
Core principle: the model may reason, recommend, and request actions, but it must never become the authorization authority.
Distributed Systems & Cloud Architecture
- Control-plane and data-plane separation
- SaaS and self-hosted enterprise architectures
- Multi-tenancy, Kubernetes, AWS, Azure, and GCP
- Asynchronous workflows and event-driven systems
- Gateways, proxies, service identity, high availability, and failure recovery
- Observability and OpenTelemetry
About CipherScale
CipherScale is building an AI-native Zero Trust security platform for a world where enterprise infrastructure is increasingly operated by humans and autonomous agents through natural language, agent protocols, and machine- to-machine capabilities.
- AI agents and agentic systems
- Model Context Protocol (MCP)
- Zero Trust, identity, and authorization
- Networking and distributed systems
- Cloud infrastructure and enterprise security
Role summary: A hands-on principal architect who will own architectural coherence across CipherScale’s AI-native security platform, with particular responsibility for agentic systems, MCP, Zero Trust, distributed systems, cloud infrastructure, and security boundaries.
What We’re Looking For
You likely have deep experience building complex distributed platforms, security products, cloud infrastructure, networking systems, developer platforms, or similarly demanding systems. More important than years of experience is evidence that you have personally designed systems that survived real-world scale, security threats, organizational complexity, and changing requirements.
Required Strengths
- Distributed systems and cloud architecture
- Security architecture and Zero Trust
- Identity and authorization
- API and protocol design
- Agentic AI systems and MCP or comparable agent/tool protocols
- SaaS / multi-tenant architecture
- Kubernetes and cloud-native systems
- Networking, event-driven systems, observability, and key management
- Strong software engineering skills and ability to prototype
What Matters Most
- Learning velocity — reads specifications, follows emerging standards, prototypes quickly, and recognizes architectural shifts early.
- Systems thinking — naturally reasons about trust boundaries, failure modes, data flows, state, scaling, and operability.
- Security mindset — asks how a system can fail or be abused, not only how it works.
- Product judgment — understands how architecture affects speed, trust, customer value, and differentiation.
What We Don’t Want
- Governance-heavy enterprise architecture without implementation responsibility
- Architecture-by-PowerPoint or process-first TOGAF bureaucracy
- Pure prompt engineering without distributed-systems and security depth
- Treating AI as simply another REST client
- Technology recommendations without hands-on validation
How We Will Interview
We will use real CipherScale architecture problems rather than relying primarily on algorithm puzzles. Candidates will be asked to design an AI-driven, Zero Trust infrastructure workflow and then respond as security, deployment, residency, and protocol constraints change.
We are evaluating reasoning quality, tradeoff judgment, trust-boundary design, practical implementation instincts, and the ability to turn architecture into something engineers can build.
Success in the First 90 Days
- 30 days: understand the current architecture, identify key risks, and review the AI/MCP implementation against the current ecosystem.
- 60 days: establish architectural invariants, strengthen the ADR process, define MCP capability architecture, and document critical trust boundaries.
- 90 days: validate the architecture through working implementations of representative AI-native workflows, including at least one complex multi-step infrastructure operation.
Why This Role Matters
AI agents are moving from answering questions to operating infrastructure. That transition creates a new security boundary. CipherScale intends to build at that boundary. We need an architect who can help us design not only for today’s AI ecosystem, but for the one emerging over the next several years.
What We Offer
-
Competitive salary and comprehensive benefits
-
A senior ownership role with responsibility for a critical engineering surface
-
The autonomy to define platform strategy, standards, and technical direction
-
The opportunity to build foundational systems with immediate, measurable impact
-
A fast-moving, AI-native engineering environment
-
Direct collaboration with technical leadership and product engineers
-
Support to experiment, automate, and introduce better ways of working
-
A culture that values speed, ownership, sound judgement, and reliable delivery