Skip to content
FalFal

Staff Security Engineer, Infrastructure

Designs and implements security controls for cloud infrastructure, Kubernetes workloads, GPU compute, networking, and AI data systems. Requires 8+ years in security engineering with expertise in cloud security, Zero Trust, IaC, and automation.

About the job

What You’ll Do

Build & Harden Infrastructure Security

  • Design and implement security controls across:
    • Cloud infrastructure
    • Kubernetes and containerized workloads
    • Networking, service meshes, and edge systems
    • CI/CD pipelines and deployment systems
    • Secure compute environments for GPU workloads and model execution

Identity, Secrets & Access

  • Machine identity and workload authentication
  • Secrets management and encryption (e.g., Vault, KMS)
  • Least-privilege access and short-lived credentials
  • Implement Zero Trust principles across infrastructure

Secure AI & Data Systems

  • Protect model weights, inference endpoints, and customer data
  • Design secure data access pathways and isolation mechanisms
  • Ensure safe multi-tenant execution environments

Automation & Security Tooling

  • Build security guardrails directly into infrastructure and CI/CD
  • Use Infrastructure-as-Code (Terraform, Pulumi) to enforce secure defaults
  • Continuously identify and remediate security gaps through automation

Threat Modeling & Risk Reduction

  • Identify and mitigate risks across infrastructure layers
  • Defend against both external attackers and insider threats
  • Drive projects like network isolation, encryption, and secure service communication

Cross-Functional Collaboration

  • Partner with platform, infra, and ML teams to drive shift-left security
  • Enable engineers to move fast with secure-by-default systems
  • Contribute to a strong security culture across the company

What We’re Looking For

Core Requirements

  • 8+ years in security engineering, infrastructure, or SRE
  • Strong understanding of:
    • Cloud security (AWS, GCP, or Azure)
    • Networking fundamentals (segmentation, firewalls, Zero Trust)
    • Linux systems and container security (Docker, Kubernetes)
  • Experience building or securing production infrastructure at scale

Security Expertise

  • Deep knowledge of:
    • Authentication & authorization systems
    • Secrets management and cryptography basics
    • Common vulnerabilities and attack vectors
    • Ability to design security controls across multiple layers (infra → app)

Engineering Skills

  • Proficiency in at least one language (Go, Python, or similar)
  • Experience with Infrastructure-as-Code (Terraform preferred)
  • Strong automation mindset—security should scale with systems

Nice to Have

  • Experience with:
    • GPU infrastructure or ML systems
    • Multi-tenant platform isolation
    • Service mesh / zero-trust architectures
    • High-growth startup environments

Skills

Kubernetes, Docker, Terraform, AWS, GCP, Azure, Zero Trust, Vault, Kms, Go, Python, Linux, Service Mesh, CI/CD, Infrastructure As Code

Coinbase

Coinbase

United States

Senior Staff Software Engineer, Platform - IAM
$254k+/yrRemote12+ YOESecurity Engineering

Leads the multi-year technical strategy and architecture for Coinbase’s identity and access management platform across hundreds of systems and engineering teams. Requires 12+ years of software engineering experience, deep IAM and workload identity expertise, production Go, and distributed-systems experience on AWS.

Nuro

Nuro

Mountain View, CA

Senior/Staff Systems Safety Engineer, Platform Systems
$132k+/yrOn-site7+ YOESecurity Engineering

Drives system-level safety architecture, requirements, analyses, and validation for autonomous-vehicle hardware and firmware. Requires automotive functional-safety experience, safety-critical system architecture, fault management, and proficiency reading C and writing Python or MATLAB.

Anthropic

Anthropic

San Francisco, CA
Customer Trust Specialist
$255k+/yrHybrid10+ YOESecurity Engineering

Handles complex customer-facing security engagements for regulated enterprises, including audits, questionnaires, contract terms, executive briefings, and trust documentation. Requires broad security expertise, strong writing, independent judgment, and 10+ years of security experience, including leadership experience preferred.

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.