Skip to content
Topaz LabsTopaz Labs

Staff Security Engineer

Owns security for hybrid infrastructure including AWS cloud, on-premise GPU clusters, and corporate endpoints. Conducts penetration testing, secures AI models, and manages identity/tools like Jamf and Active Directory. Requires 7+ years hands-on security experience.

About the job

Responsibilities

  • Secure hybrid infrastructure (AWS & colo): configure firewalls, manage physical network security, harden Linux GPU clusters.
  • Manage corporate & endpoint security: oversee macOS fleet with Jamf, identity management via Active Directory.
  • Conduct hands-on penetration testing on internal networks, office infrastructure, and AI applications.
  • Secure AI supply chain: protect model weights during training, storage, and delivery.

Requirements

  • 7+ years in security engineering (infrastructure, corporate IT, offensive security).
  • Deep experience with AWS security (IAM, VPC), compliance (SOC II, Vanta).
  • Expert in Jamf for macOS and Active Directory for identity.
  • Physical & network security: firewalls, VPNs, switching in offices/colos.
  • Manual penetration testing (network, web app).
  • Proficiency in Python/Bash scripting.

Nice-to-Haves

  • Experience securing on-device software/desktop apps (Windows/macOS).

Skills

AWS, IAM, Vpc, Jamf, Active Directory, Linux, Firewalls, Vpns, Penetration Testing, Python, Bash, Soc Ii, Vanta, Network Security, Gpu Clusters

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Okta

Okta

Bellevue, WA
Staff Identity Governance and Access Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.

Twilio

Twilio

United States

Staff Security Engineer
$156k+/yrRemote7+ YOESecurity Engineering

Leads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.

Ironclad

Ironclad

San Francisco, CA

Staff IAM Engineer
$170k+/yrHybrid4+ YOESecurity Engineering

Own security-critical identity and corporate security controls, managing IAM platforms, SSO/MFA integrations, RBAC policies, and endpoint trust for macOS/Windows environments.

Okta

Okta

Bellevue, WA
Staff Identity Engineer
$161k+/yrOn-site7+ YOESecurity Engineering

Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.