Infrastructure Engineer, Security
Owns and evolves security infrastructure across compute, storage, networking, and data platforms for foundation models. Architects secure patterns, manages identities/secrets, builds threat models, and automates security checks in Kubernetes/cloud environments. Requires strong systems programming and infra experience.
About the job
What You’ll Do
- Architect security patterns for platforms and services, including network segmentation, service-to-service authentication, RBAC, and policy enforcement in Kubernetes and cloud environments.
- Manage identity, access, and secrets for humans and services: workload and cross-cloud identity, least-privilege IAM, and secrets management.
- Build secure platforms for data ingestion, processing, and curation: classification, encryption, access controls, and safe sharing patterns across teams.
- Write threat models and review designs with researchers and engineers to help them ship features and experiments in a safe, scalable way.
- Automate security checks and build guardrails: policy-as-code, secure infrastructure baselines, validation in CI/CD, and tools that make the secure path the easiest one.
Skills and Qualifications
Minimum qualifications
- Bachelor’s degree or equivalent experience in engineering, or similar.
- Strong background with containers and orchestration (Kubernetes) and how to secure them (namespaces, network policies, pod security, admission controls, etc.)
- Practical experience with Infrastructure as Code (Terraform or similar), including secure patterns for provisioning networks, IAM, and shared services.
- Solid understanding of cloud networking and security: VPCs, load balancers, service discovery, mTLS, firewalls, and zero-trust-style architectures.
- Proficiency with a systems language such as Rust and scripting in Python for building platform components and internal tools.
- Evidence of owning complex, production-critical systems, including debugging issues that span infra, security, and application layers.
Preferred qualifications
- Experience with ML infrastructure, GPU clusters, or large-scale training environments (schedulers, job queues, shared storage, multi-tenant clusters).
- Background in AI labs, HPC environments, or ML-heavy organizations where both security and performance are first-class concerns.
- Experience profiling and tuning high-throughput systems, and an ability to reason about the cost of additional security layers.
- Talks, blogs, or publications on infrastructure security, distributed systems, or performance engineering.
- Open-source contributions to security, orchestration, observability, or infrastructure tooling.
- Familiarity with securing specialized hardware (GPUs, TPUs) and their integrations into training and inference pipelines.
Logistics
Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $200,000 - $475,000 USD.
Benefits: Generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.
Skills
Kubernetes, Terraform, Rust, Python, IAM, Vpcs, Mtls, RBAC, CI/CD, Gpu Clusters
Similar jobs
Security Engineering jobsThe Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.
Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.
The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.