Leads hands-on security engineering for AI platforms, enterprise infrastructure, model-serving systems, customer workloads, and agentic automation. The role requires 10+ years of technical security experience, strong programming and cloud security skills, and expertise in identity, runtime protection, authorization, and AI security.
Salary not listed
On-site10+ YOESecurity Engineering
About the role
Responsibilities
Define security architecture and build controls for AI platforms, training and inference workflows, model-serving systems, customer workloads, developer workflows, and agentic systems.
Develop reusable AI and agent security patterns for identity, authorization, delegated authority, scoped tool access, MCPs, connectors, secrets, approvals, isolation, auditability, and governance.
Design runtime controls that constrain execution, access, data exposure, model and tool interaction, and blast radius.
Build security capabilities as code using infrastructure as code, configuration as code, policy as code, GitOps, CI/CD, and automated validation.
Define secure development patterns for AI systems, agents, prompts, tools, models, policies, evaluations, releases, and rollback.
Automate security reviews, policy checks, evidence collection, control validation, and remediation.
Instrument AI, agent, and platform activity with telemetry, traceability, policy decisions, audit logs, anomaly signals, and response workflows.
Lead hands-on security reviews and influence product, platform, infrastructure, and security architecture through practical design changes and reusable controls.
Requirements
10+ years of experience in security engineering, platform security, infrastructure security, product security, or related technical security roles.
Strong hands-on engineering ability in Python and at least one additional production programming language.
Experience designing, building, operating, and improving security controls as production systems.
Strong cloud and infrastructure security experience, preferably with AWS, including IAM, networking, secrets management, logging, and cloud-native control planes.
Deep understanding of identity and access systems, including SSO, MFA, OAuth, service accounts, workload identity, authorization, privileged access, and least privilege.
Practical experience securing runtime environments such as containers, Kubernetes, isolated workloads, secure development environments, distributed compute platforms, or production service infrastructure.
Familiarity with AI security, LLM application security, agentic workflows, MCPs, prompt injection, autonomous coding agents, or AI platform security.
Ability to reason about cross-system risk involving identity, data, models, tools, networks, workflows, approvals, and automation.
Strong written communication skills and ability to influence senior technical stakeholders across Security, Product, IT, Infrastructure, and Engineering.
Relevant Experience
AI, ML, training, inference, model serving, or large-scale compute.
Coding agents, agent platforms, MCP servers, internal developer platforms, or AI-assisted development environments.
Policy as code, authorization services, runtime enforcement layers, or security control platforms.
Software delivery security, including source control, CI/CD, build systems, artifacts, provenance, signing, and release gates.
Detection, investigation, and response workflows for cloud, infrastructure, identity, AI, or agents.
Compensation and Benefits
Build a breakthrough AI platform beyond the constraints of the GPU.
Publish and open source cutting-edge AI research.
Work on one of the fastest AI supercomputers in the world.
Enjoy job stability with startup vitality.
Work in a simple, non-corporate culture that respects individual beliefs.
Continuous learning, growth, and support.
Skills
PythonAWSIAMKubernetesOAuthmcpspolicy as codeCI/CDGitOpsInfrastructure As Codesecrets managementworkload identityContainersprompt injectionCloud Security
Lead end-to-end incident response for frontier AI infrastructure, building detection logic, playbooks, and forensic tooling from the ground up while investigating threats across cloud, endpoint, network, and physical systems at gigawatt scale. Requires hands-on experience leading major incidents, proactive threat hunting, and standing up IR programs.
330k – 380k/yrOn-site7+ YOESecurity Engineering
Principal Product Researcher
HuntressUnited States
Lead Windows threat detection research and EDR sensor development for SMB customers. Requires deep Windows kernel expertise, reverse engineering, EDR bypass testing, and AI-augmented research to build innovative, automated defenses.
200k – 230k/yrRemote7+ YOESecurity Engineering
Principal Security Engineer
SquareCalifornia
Principal Security Engineer responsible for setting the bar for software security excellence at Block. Defines multi-year technical strategy, leads development of high-leverage security solutions and infrastructure across business units, drives Secure by Design culture, and mentors InfoSec teams. Requires 10+ years shipping production software with 5+ years scaling security practices.
319k – 479k/yrOn-site10+ YOESecurity Engineering
Principal Engineer
CloudflareUnited States
Principal Engineer on Cloudflare's Cloudforce One threat operations team. Architect and build large-scale distributed systems for threat detection, intelligence, and abuse mitigation across the global network, Kubernetes, and edge platforms. Requires 15+ years cybersecurity and 10+ years distributed systems experience.
Salary not listedHybrid15+ YOESecurity Engineering
Principal Network Security Architect
Cerebras SystemsUnited States
Leads the architecture and evolution of secure, resilient enterprise, data center, and cloud networks supporting high-performance AI infrastructure. Requires 10+ years of large-scale network engineering experience, deep routing and fabric expertise, cloud networking knowledge, and strong automation skills.
Salary not listedOn-site10+ YOESecurity Engineering