Software Engineer, Infrastructure Security
Designs and builds production-grade security services like auth systems, proxies, and key management for OpenAI's GPU clusters, multi-cloud infrastructure, and AI workloads. Requires strong software engineering in Python/Go/Rust, experience with critical security infra, and cloud security expertise.
About the job
Responsibilities
- Architect and implement production-grade security services (e.g., auth services, access brokers, secure proxies, key-management infrastructure) that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD.
- Partner with infrastructure and research engineers to embed security into high-performance compute clusters, enabling rapid model training and deployment without compromising protection.
- Develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments.
- Drive high-impact initiatives such as line-speed encryption, machine identity, and network isolation, continuously raising the security bar for emerging AI workloads.
- Lead or participate in design reviews and threat models to ensure new systems launch with strong security foundations and operational excellence.
Requirements
- Strong software engineering skills in languages such as Python, Go, Rust, or C/C++, with a track record of shipping and operating high-reliability distributed services.
- Experience building or operating critical security infrastructure (e.g., auth services, service-to-service proxies, certificate or key-management systems).
- Deep understanding of security principles, best practices, and common vulnerabilities.
- Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design.
- Familiarity with container and orchestration security (Kubernetes, service meshes) and modern authentication/authorization standards (OIDC, mTLS, SPIFFE/SPIRE).
- A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.
- A track record of delivering scalable solutions and driving impactful changes across infrastructure in real-world projects.
- Strong analytical and problem-solving skills, with an ability to think critically and objectively assess security risks.
- Excellent communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.
- Excitement about collaborating with cross-functional teams to build secure, reliable systems that scale globally.
Skills
Python, Go, Rust, C++, Kubernetes, AWS, Azure, GCP, Mtls, OIDC, Spiffe, Spire, Service Meshes
Similar jobs
Security Engineering jobsBuild and lead a Security Quality Management System for agentic and human-led SOC investigations, establishing quality standards, sampling, validation, reporting, and corrective actions. The role requires 5+ years in quality, governance, operational excellence, or controls, plus security operations and people-management experience.
Develop and maintain secure platform software spanning authentication, authorization, communications, data access, and automated security testing. The role requires 5+ years of security-focused software development experience, strong coding skills, and expertise in cloud and container security.
Leads vulnerability management and application-security initiatives across the technology stack, securing operating-system images, open-source dependencies, CI/CD pipelines, containers, and cloud-native systems. Requires 5+ years of application-security experience, coding ability, and expertise in vulnerability-scanning practices.
Own and strengthen Onebrief’s corporate security stack across endpoints, identity, SaaS, Zero Trust, and monitoring. The role emphasizes security automation, configuration-baseline enforcement, telemetry integration, and continuously validated compliance controls.
The Security Engineer will secure cloud infrastructure, engineering systems, APIs, model-training environments, and GPU clusters while supporting rapid delivery. The role requires hands-on cloud security, IAM, secrets and certificate management, compliance ownership, vulnerability monitoring, and incident response experience.