Staff Software Security Engineer
The Staff Software Security Engineer will secure large-scale AI clusters and multicloud infrastructure through network controls, identity management, secure development workflows, and threat modeling. The role requires 8+ years of software engineering experience, strong systems programming skills, and deep cloud and Kubernetes security expertise.
About the job
Responsibilities
- Build security for large-scale AI clusters across multiple clouds and bare-metal data centers, including IAM, network segmentation, and encryption controls.
- Design and implement network security controls, including default-deny ingress and egress, segmentation across research, training, and production environments, private connectivity across clouds and data centers, cloud firewall policy, and mTLS with service identity.
- Ship security controls as secure defaults using infrastructure as code and GitOps workflows so new clusters, VPCs, and data center links inherit appropriate boundaries.
- Build visibility into network traffic and boundary drift, including detection of exfiltration paths and safe automated remediation.
- Design secure-by-default development workflows and CI/CD pipelines across services, with Kubernetes security, container orchestration, and identity management.
- Threat model and assess risk for complex multicloud and networked environments.
- Partner with infrastructure networking, cluster, and data center teams during design to incorporate security requirements into topology, routing, and firewall decisions.
- Mentor engineers and contribute to Security team hiring and growth.
Requirements
- 8–15+ years of software engineering experience implementing and maintaining critical systems at scale.
- Strong software engineering skills in Python or a systems language such as Go, Rust, C, or C++.
- Experience operating critical systems at scale using DevOps and cloud automation practices, including infrastructure as code.
- Hands-on network security engineering in cloud or on-premises environments, including VPC design, cloud firewall policy, egress control, private service connectivity, or network segmentation.
- Working knowledge of Kubernetes security and networking, including network policy, service identity, and container hardening.
- Experience with threat modeling and risk assessment for networked and multicloud systems.
- Track record of engineering excellence through high standards, constructive code reviews, and mentorship.
- Clear communication skills and ability to translate technical concepts across organizational levels.
- Experience supporting fast-paced startup engineering teams.
- Bachelor’s degree or equivalent combination of education, training, and experience in a relevant field.
Nice-to-haves
- Secured Kubernetes networking at scale, including CNI, network policy, service mesh, or mTLS rollouts.
- Experience in high-assurance environments where security controls must be evidenced.
- Experience with interconnects and private connectivity between cloud providers and physical data centers.
- Management-plane and out-of-band network security experience.
- Experience building network traffic visibility or exfiltration detection systems.
- Exposure to large-scale distributed training and its networking requirements.
- Experience leading cross-functional security initiatives.
- Experience managing infrastructure through automated configuration and policy enforcement.
- Experience hardening containerized applications and enforcing security policies.
Compensation
- Annual salary: £255,000–£325,000 GBP.
Skills
Python, Go, Rust, C, C++, Infrastructure As Code, GitOps, Kubernetes, Kubernetes Security, Network Security, IAM, Vpc, Mtls, Network Segmentation, Threat Modeling
Similar jobs
Security Engineering jobsLeads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Maintains Mozilla’s information security management system and leads ISO 27001 and SOC 2 compliance activities, including audit readiness, policy governance, remediation tracking, and stakeholder coordination. Requires at least five years in information security, GRC, or compliance and strong audit experience.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Leads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.