Member of Technical Staff - Security
The foundational security hire will own security architecture, threat modeling, infrastructure and AI-specific defenses, incident response, and compliance for a frontier AI platform. The role requires 5+ years in security engineering plus expertise in cloud, Kubernetes, distributed systems, Python, and Rust or another systems language.
About the job
Responsibilities
- Own threat modeling across multi-tenant training infrastructure, sandboxed execution environments, APIs, and internal tooling.
- Design and implement zero-trust networking, identity and access controls, secure-by-default patterns, secrets management, supply-chain integrity, and container hardening.
- Architect tenant isolation and data-boundary enforcement for hosted reinforcement-learning workloads.
- Develop security frameworks for AI infrastructure, including model-weight protection, training-data isolation, checkpoint integrity, gradient privacy, and secure RL training loops.
- Build defenses against AI-specific threats such as prompt injection, model exfiltration, and adversarial environment manipulation.
- Manage external penetration tests and build an internal red-team practice.
- Lead vulnerability management, including triage, remediation SLAs, and root-cause analysis.
- Build security monitoring, alerting, runtime security, audit logging, and forensic capabilities across distributed clusters, Kubernetes, cloud, applications, containers, and sandboxes.
- Own incident-response playbooks, drills, postmortems, and security operations.
- Drive SOC 2 Type II and other enterprise compliance readiness.
- Support customer security questionnaires, architecture reviews, trust documentation, and security-related enterprise deals.
Requirements
- 5+ years of experience in security engineering, infrastructure security, or offensive security, ideally with multi-tenant cloud or compute infrastructure.
- Deep experience with cloud security, preferably GCP, Kubernetes security, and container-runtime hardening.
- Ability to read, write, and audit Python and Rust or another strong systems-level language.
- Experience with network security in distributed systems, including service mesh, mTLS, and network segmentation.
- Experience managing external penetration tests and turning findings into engineering action.
- Strong fundamentals in cryptography, identity and access management, and secure software development lifecycles.
Nice to Have
- Experience securing GPU infrastructure or machine-learning training pipelines.
- Offensive-security experience, including CTFs, bug bounties, or red-team engagements.
- Familiarity with AI threat models such as model extraction, training-data poisoning, and sandbox escape.
- Experience building security programs from scratch at a high-growth startup.
- SOC 2, ISO 27001, or FedRAMP experience.
- Contributions to open-source security tooling.
- Familiarity with eBPF, Falco, or similar runtime-security tools.
Compensation
- Cash compensation: $180,000–$350,000+, plus significant equity incentives.
- Flexible work arrangement, including remote work or the San Francisco office.
- Visa sponsorship and relocation support.
- Professional development budget and team off-sites.
Skills
Cloud Security, GCP, Kubernetes, Container Security, Python, Rust, Network Security, Service Mesh, Mtls, Cryptography, Identity Access Management, Threat Modeling, Penetration Testing, Incident Response, Ebpf
Similar jobs
Security Engineering jobsOwn and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Build and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.