Full-Time
Blockchain-backed security for industrial OT systems
$150k - $180k/yr
Palo Alto, CA, USA
In Person
See people who can refer or advise you
Xage Security provides cybersecurity solutions for industrial environments, protecting critical operations across sectors like oil and gas, manufacturing, and utilities. Its main product, the Xage Fabric, is a blockchain-backed security fabric that uses identity fingerprints and distributed enforcement to secure industrial devices, OT networks, and IoT across edge-to-cloud with no single point of failure. It also offers Multi-Factor Authentication and Zero Trust Access Management to ensure only authorized personnel can access critical systems. The goal is to protect industrial infrastructure by delivering interoperable, scalable security for distributed OT/IT environments, sold as a subscription with ongoing updates and consulting services.
Company Size
51-200
Company Stage
Series B
Total Funding
$72M
Headquarters
Palo Alto, California
Founded
2017
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Competitive salary & equity
Health, dental, & vision insurance
Visa transfers and immigration
Xage Security has expanded its Critical Asset Protection platform to cover modern digital systems beyond industrial assets. The zero trust security solution now protects business applications, cloud services, enterprise AI agents, and other digital assets from AI-driven cyber attacks. The expansion addresses growing security challenges. Microsoft reports threat actors are exploiting known vulnerabilities faster than before, whilst the 2026 Verizon DBIR found organisations faced 50 per cent more critical vulnerabilities to patch compared to the previous year. Xage's platform uses identity-based microsegmentation to hide assets, broker access, restrict lateral movement, and control human and machine actions. The company argues this preemptive approach is necessary as AI enables attackers to discover vulnerabilities, automate reconnaissance, and adapt attacks faster than security teams can deploy patches. The California-based company positions itself as the leader in identity-based zero trust for high-stakes environments.
Securing Agentic AI with Xage resource-layer controls. June 17, 2026 Duncan Greatwood, CEO of Xage Security detailed the company's approach to securing agentic AI by shifting focus from bypassable, prompt-level guardrails to strict action-level controls at the resource layer. This protection is delivered via Xage's overlay fabric architecture, which provides end-to-end visibility and traceability across industrial and IT environments, mapping exactly where machine-to-machine actions originate before they hit critical systems. To mitigate the risk of prompt jailbreaks and rogue autonomous agents, Xage introduced an AI-focused resource gateway. Positioned directly in front of sensitive assets like financial and HR databases, this gateway enforces zero-trust boundaries by verifying whether an agent is explicitly authorized to execute a requested action. As boards grow increasingly concerned with AI cyber risk, organizations are exposing mission-critical data to long-lived, autonomous agents without adequate guardrails. To combat this, Duncan stressed the necessity of automated quarantine, isolation, and termination mechanisms for when an agent behaves unexpectedly. In more recent news, Xage announced its Zero Trust for Agentic AI solution, which provides visibility and control over AI agents. Backed by this recent integration with NVIDIA, Xage enables safe AI connectivity to high-value systems, though operational challenges remain regarding how to apply these resource-level policies consistently across messy, heterogeneous enterprise environments.
Xage XPAM named Best PAM Platform by The Hacker News. Reading time: 3 mins Xage XPAM has been named Best Privileged Access Management Platform in the 2026 Cybersecurity Stars Awards, presented by The Hacker News. The award recognizes Xage's innovation in securing privileged access across distributed IT, OT, cloud, edge, and AI environments, helping organizations modernize access security without the complexity of legacy PAM solutions. What you'll learn. * Why Xage XPAM was recognized as Best Privileged Access Management Platform * How modern PAM requirements have evolved beyond traditional IT environments * What differentiates Xage XPAM from legacy PAM solutions * How organizations can secure privileged access across IT, OT, cloud, edge, and AI systems What makes Xage XPAM a leading privileged access management platform? Xage XPAM was recognized for delivering modern privileged access management (PAM) across distributed enterprise environments, including operational technology (OT), cloud infrastructure, remote operations, and AI-powered systems. As cyberattacks increasingly target identities and privileged accounts, organizations need PAM solutions that extend beyond traditional data centers. Xage XPAM secures access across the entire enterprise through a unified, identity-centric architecture that reduces risk while simplifying operations. The Cybersecurity Stars Awards recognize organizations that demonstrate innovation, technical excellence, and measurable impact in solving today's cybersecurity challenges. Being named Best Privileged Access Management Platform validates Xage's vision for securing modern enterprises through identity-first security. How is Xage XPAM different from traditional PAM solutions? Unlike legacy PAM platforms that rely on centralized architectures and complex deployments, Xage XPAM was designed for distributed operations. Built on the Xage Fabric Platform, Xage XPAM enables organizations to: * Secure privileged access across IT, OT, cloud, edge, and AI environments * Enforce least-privilege access policies across distributed operations * Provide secure just-in-time access for employees, contractors, and third-party vendors * Enforce zero standing privilege and reduce static credential usage with critical assets * Reduce dependence on traditional VPN-based access models * Support disconnected and remote operational environments * Maintain visibility and control without sacrificing operational resilience By combining privileged access management, identity governance, and Zero Trust principles into a unified platform, Xage helps organizations strengthen security while reducing operational complexity. Why does modern PAM need to support AI and OT? Modern enterprises now manage privileged access across human users, machine identities, OT, and AI-powered workflows. Critical infrastructure operators, manufacturers, energy providers, transportation networks, and industrial organizations increasingly operate across hybrid environments that span data centers, cloud platforms, remote sites, and AI-enabled applications. Traditional PAM solutions were not designed for this reality. Xage XPAM helps organizations govern privileged access consistently across both human and non-human identities while maintaining the reliability required for mission-critical operations. Building momentum in Privileged Access Management. This recognition builds on Xage's continued momentum in the privileged access management market, including its recent Cybersecurity Excellence Award recognition for PAM innovation. As identity-based attacks continue to grow and organizations expand digital operations, PAM remains one of the most important components of a modern cybersecurity strategy. Xage remains committed to helping organizations secure their most critical systems, users, and operations through resilient, distributed, and identity-centric security solutions. Key takeaways. * Xage XPAM was named Best Privileged Access Management Platform by The Hacker News. * The award recognizes innovation in securing distributed enterprise environments. * Xage XPAM protects privileged access across IT, OT, cloud, edge, and AI systems. * The platform combines PAM, identity governance, and Zero Trust principles. * Organizations can modernize access security without the complexity of legacy PAM architectures. Frequently asked questions. What is the Cybersecurity Stars award for Best Privileged Access Management Platform? The award recognizes cybersecurity vendors delivering exceptional innovation, effectiveness, and impact in privileged access management. Xage XPAM was selected for its ability to secure modern distributed environments across IT, OT, cloud, edge, and AI systems. What is Xage XPAM? Xage XPAM is a privileged access management solution that secures access to critical systems, applications, infrastructure, and AI-powered environments through identity-centric security policies and Zero Trust controls. The platform helps organizations govern and monitor privileged access for both human and non-human identities across IT, OT, cloud, edge, and AI ecosystems. Who benefits from Xage XPAM? Organizations operating distributed environments - including critical infrastructure, manufacturing, energy, transportation, utilities, and other industrial sectors - benefit from Xage XPAM's ability to secure privileged access across diverse environments. As organizations adopt AI-powered applications, agents, and workflows, Xage XPAM provides consistent governance, visibility, and control across both human and machine identities. How does Xage XPAM support AI security? Xage XPAM helps organizations manage and govern privileged access for AI-driven workflows and machine identities, providing consistent policy enforcement and visibility across both human and non-human users. See how Xage XPAM helps organizations secure privileged access across distributed IT, OT, cloud, edge, and AI environments.
Senior Software Engineer - Zero Trust for Agentic AI. About Xage. Cyberattacks on critical infrastructure, government, and private enterprises are at an all time high - and only growing more urgent with AI. Xage is a global leader in zero trust access and protection at the forefront of solving this pressing issue. Xage Security and Science Applications International Corporation is pioneering a secure tomorrow by empowering organizations worldwide to connect anyone to anything, while delivering unparalleled defense against every cyber threat. Xage Security and Science Applications International Corporation has built tremendous momentum across governments and commercial enterprises around the world, and it's just the beginning. Recognized by Forbes as one of America's Best Startup Employers, Xage prioritizes creativity, collaboration, and innovation in pursuit of its mission. Xage Security and Science Applications International Corporation is headquartered in Palo Alto, CA and have global teams across North America, EMEA, and APJ. Xage Security and Science Applications International Corporation is passionate about solving problems that have positive, real-world consequences for the lives of everyday people. Xage Security and Science Applications International Corporation hope you'll join Xage Security and Science Applications International Corporation in the fight against cyberattacks and safeguarding critical systems. About the role. Xage Security and Science Applications International Corporation is seeking an experienced and visionary Senior Software Engineer to design and build its next-generation Zero Trust for Agentic AI platform. As AI agents evolve from sandboxed pilots into autonomous systems capable of executing real-world actions, invoking APIs, and accessing sensitive databases across hybrid cloud and operational technology (OT) environments, security must evolve with them. In this role, you will build the critical security fabric that moves past simple prompt/output monitoring and into deterministic runtime visibility and control. You will engineer the gateways, proxies, and identity management systems that protect autonomous AI agents, Large Language Models (LLMs), and enterprise resources from prompt injection, rogue behavior, data leakage, and privilege escalation. Location: Palo Alto, CA Salary Range: $140K to $200K Key responsibilities. * Architect AI Gateways & Sentries: Design and develop the runtime components (like Xage Agent Sentry and Resource Gateway) to encapsulate AI agents, intercepting and inspecting inputs, outputs, tool calls, and API interactions. * Implement Deterministic Access Controls: Build jailbreak-proof, identity-based permissioning models and agent entitlements to enforce strict least-privilege access across APIs, SaaS applications, Model Context Protocol (MCP) servers, and databases. * Analyze Behavioral Anomalies: Build intelligent monitoring systems that establish a baseline for normal agent behavior and leverage ML to flag deviations, catching rogue agent actions or privilege escalation attempts before they hit critical infrastructure. * Develop Agent Identity Management: Create robust, centralized frameworks for agent registration, lifecycle management, and automated credential rotation to eliminate hardcoded secrets and shared service account vulnerabilities. * Build End-to-End Visibility Pipelines: Engineer high-throughput, tamperproof logging mechanisms to capture and audit every prompt, action, tool call, and resource access for comprehensive governance. * Scale a Distributed Security Fabric: Ensure security controls deploy seamlessly across multi-cloud, on-premises, and edge/OT environments via a unified, resilient platform. Required skills and qualifications. Technical requirements. * Backend & Systems Engineering: 3-5+ years of experience building high-performance, distributed, and scalable enterprise software (preferred languages: Go, Python, C or C++). * Machine Learning & AI Security: Strong hands-on experience deploying ML models in production environments. Familiarity with NLP, LLM alignment/guardrails (e.g., Llama Guard, NeMo Guardrails), and implementing low-latency inference at the proxy/gateway level. * AI/LLM Integration & Protocols: Deep understanding of the Agentic AI lifecycle, tool-calling mechanisms, and emerging integration protocols like MCP (Model Context Protocol) and REST APIs. * Security & Zero Trust Architecture: Solid foundation in application security, API gateway design, proxy architectures (e.g., Envoy), identity access management (IAM), and credential management/rotation. * Infrastructure & Edge: Experience with containerization (Docker, Kubernetes) and deploying applications across hybrid environments (Cloud, SaaS, and Edge/OT). Soft skills & Experience. * Experience in cybersecurity product development, specifically in AI Security (Securing LLMs/Agents, prompt injection mitigation) is highly preferred. * Strong systems-level thinking with the ability to build predictive boundaries around dynamic, runtime AI behaviors. * Strong communication skills to collaborate with AI researchers, security analysts, and enterprise architecture teams. Key business impacts you will deliver. * Enable High-Stakes AI Deployment: Turn risky, sandboxed AI experiments into secure, production-ready enterprise tools. * Mitigate Modern Threats: Directly block harmful agent behaviors and data exfiltration before they impact the business. * Simplify AI Complexity: Provide enterprises with a "single pane of glass" view to trust, govern, and audit their autonomous AI workforces. Perks. * Competitive salary and equity * Health, dental, and vision coverage * Visa transfer and immigration support * Opportunity to work closely with founders and executive leadership * High-growth environment with significant market opportunity Awards and recognition. Xage Security has experienced explosive growth and received numerous awards and recognition, including: * Named one of Forbes' America's Best Startup Employers (2024, 2025, 2026) * Awarded $17M contract with U.S. Space Force * Recognized by Gartner and Forrester in multiple cybersecurity categories * Multiple industry awards including CRN, IoT Breakthrough, and American Business Awards
Xage Security is integrating its Zero Trust for Agentic AI solution with NVIDIA's Vera BlueField-4 STX and DOCA security capabilities to provide line-speed visibility and policy enforcement across AI factory environments. The partnership aims to deliver identity-based Zero Trust security for autonomous AI agents accessing sensitive data and systems. Xage's solution will run natively in NVIDIA's DOCA architecture, providing end-to-end visibility and control across AI interactions including users, agents, models and resources. The integration creates a closed-loop security model where DOCA infrastructure observes runtime behaviour whilst Xage evaluates identity and policy, with enforcement controls working through DOCA-OvS. The combined solution targets enterprises, government agencies and critical infrastructure operators looking to deploy agentic AI with enhanced security, governance and audit capabilities whilst preserving AI performance.