Skip to content
TailscaleTailscale

Security Infrastructure Engineer

This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.

About the job

Responsibilities

  • Design and build security controls across cloud platforms, operating systems, Kubernetes, networks, and CI/CD to defend against sophisticated adversaries and insider threats.
  • Identify and implement security and privacy features, bug fixes, and defense-in-depth improvements across the codebase.
  • Audit infrastructure for technical security weaknesses, identify mitigations, and drive issues to resolution.
  • Support engineering decisions through threat modeling, security analysis, and technical expertise.
  • Act as a subject matter expert during security incidents, focusing on infrastructure-level containment and remediation.
  • Spend approximately 25–50% of the role writing software.

Requirements

  • Expertise securing cloud platforms such as AWS, including multi-cloud networks and infrastructure and cloud-agnostic system design.
  • Familiarity with container, orchestration, authentication, and authorization security.
  • Knowledge of web and Internet security fundamentals, including WAFs, TLS, PKI, and DNS security.
  • Proficiency in at least one programming language; Go is used at Tailscale.
  • Experience with Infrastructure as Code tools such as Terraform and Ansible.
  • Prior experience in infrastructure security, security operations, threat modeling and prioritization, or digital forensics and incident response.
  • Knowledge of operating-system internals, security mechanisms, and common networking protocols.
  • Ability to work independently and collaboratively, give and receive constructive feedback, and take a practical, risk-based approach to security controls.

Compensation and Benefits

  • Base salary range: CA$218,420–CA$273,360.
  • Equity incentive plan and comprehensive benefits, including health, vision, and dental coverage.
  • Employer-funded retirement contributions matching employee contributions dollar-for-dollar, up to 0.75% of eligible compensation annually.
  • Remote-first work environment, coworking support, social events, and team retreats.
  • $1,500 USD annually for professional development.
  • Flexible paid time off.
  • Company-owned laptop, monthly home internet reimbursement, and $500 USD for home-office customization.
  • Paid parental leave top-ups of 20 weeks for birthing parents and 16 weeks for non-birthing parents.

Skills

AWS, Kubernetes, Terraform, Ansible, Go, Cloud Security, Container Security, Threat Modeling, Tls, Pki, Dns Security, Waf, Incident Response, Networking Protocols, Operating Systems

Fluidstack

Fluidstack

New York, NY
Security Engineer, Threat Intelligence
$220k+/yrOn-siteSecurity Engineering

The Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.