Staff Security Engineer, Infrastructure
Designs and implements security controls for cloud infrastructure, Kubernetes workloads, GPU compute, networking, and AI data systems. Requires 8+ years in security engineering with expertise in cloud security, Zero Trust, IaC, and automation.
About the job
What You’ll Do
Build & Harden Infrastructure Security
- Design and implement security controls across:
- Cloud infrastructure
- Kubernetes and containerized workloads
- Networking, service meshes, and edge systems
- CI/CD pipelines and deployment systems
- Secure compute environments for GPU workloads and model execution
Identity, Secrets & Access
- Machine identity and workload authentication
- Secrets management and encryption (e.g., Vault, KMS)
- Least-privilege access and short-lived credentials
- Implement Zero Trust principles across infrastructure
Secure AI & Data Systems
- Protect model weights, inference endpoints, and customer data
- Design secure data access pathways and isolation mechanisms
- Ensure safe multi-tenant execution environments
Automation & Security Tooling
- Build security guardrails directly into infrastructure and CI/CD
- Use Infrastructure-as-Code (Terraform, Pulumi) to enforce secure defaults
- Continuously identify and remediate security gaps through automation
Threat Modeling & Risk Reduction
- Identify and mitigate risks across infrastructure layers
- Defend against both external attackers and insider threats
- Drive projects like network isolation, encryption, and secure service communication
Cross-Functional Collaboration
- Partner with platform, infra, and ML teams to drive shift-left security
- Enable engineers to move fast with secure-by-default systems
- Contribute to a strong security culture across the company
What We’re Looking For
Core Requirements
- 8+ years in security engineering, infrastructure, or SRE
- Strong understanding of:
- Cloud security (AWS, GCP, or Azure)
- Networking fundamentals (segmentation, firewalls, Zero Trust)
- Linux systems and container security (Docker, Kubernetes)
- Experience building or securing production infrastructure at scale
Security Expertise
- Deep knowledge of:
- Authentication & authorization systems
- Secrets management and cryptography basics
- Common vulnerabilities and attack vectors
- Ability to design security controls across multiple layers (infra → app)
Engineering Skills
- Proficiency in at least one language (Go, Python, or similar)
- Experience with Infrastructure-as-Code (Terraform preferred)
- Strong automation mindset—security should scale with systems
Nice to Have
- Experience with:
- GPU infrastructure or ML systems
- Multi-tenant platform isolation
- Service mesh / zero-trust architectures
- High-growth startup environments
Skills
Kubernetes, Docker, Terraform, AWS, GCP, Azure, Zero Trust, Vault, Kms, Go, Python, Linux, Service Mesh, CI/CD, Infrastructure As Code
Similar jobs
Security Engineering jobsLeads the multi-year technical strategy and architecture for Coinbase’s identity and access management platform across hundreds of systems and engineering teams. Requires 12+ years of software engineering experience, deep IAM and workload identity expertise, production Go, and distributed-systems experience on AWS.
Drives system-level safety architecture, requirements, analyses, and validation for autonomous-vehicle hardware and firmware. Requires automotive functional-safety experience, safety-critical system architecture, fault management, and proficiency reading C and writing Python or MATLAB.
Handles complex customer-facing security engagements for regulated enterprises, including audits, questionnaires, contract terms, executive briefings, and trust documentation. Requires broad security expertise, strong writing, independent judgment, and 10+ years of security experience, including leadership experience preferred.
Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.