Skip to content
xAIxAI

Infrastructure Security Engineer

Designs and implements secure cloud architectures across AWS, GCP, and Azure, develops IaC with security controls, conducts audits, and integrates security into CI/CD pipelines. Requires 3-5 years experience, bachelor's degree, and proficiency in cloud platforms and IaC tools.

About the job

Responsibilities

  • Design and implement secure cloud architectures across multiple cloud platforms (e.g., AWS, GCP, Azure)
  • Develop and maintain Infrastructure as Code (IaC) templates with embedded security controls
  • Conduct regular security assessments and audits of cloud infrastructure and services
  • Implement and manage cloud security tools and services (e.g., CSPM, CWPP, CASB)
  • Collaborate with development teams to ensure security best practices are integrated into CI/CD pipelines
  • Monitor and respond to security events and incidents in cloud environments
  • Develop and maintain cloud security policies, standards, and procedures
  • Stay current with emerging cloud security threats and mitigation strategies

Basic Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or a related field
  • 3-5 years of experience in cloud security or related roles
  • Strong understanding of cloud security principles, compliance frameworks, and best practices
  • Proficiency in at least one cloud platform (AWS, GCP, or Azure) and associated security services
  • Experience with Infrastructure as Code tools (e.g., Terraform, CloudFormation)
  • Familiarity with containerization technologies and their security implications
  • Knowledge of network security concepts and protocols
  • Experience with scripting languages (e.g., Python, Bash) for automation and tool development

Preferred Skills and Experience

  • Relevant security certifications (e.g., CCSP, CSSK, AWS Security Specialty)
  • Experience with multi-cloud environments and cloud-to-cloud security
  • Knowledge of DevSecOps practices and tools
  • Familiarity with regulatory compliance requirements (e.g., GDPR, HIPAA, PCI DSS)
  • Experience with Kubernetes and container security
  • Experience in building custom cloud security tools or integrations
  • Interest in leveraging AI for cloud security monitoring and automation
  • Contributions to open-source cloud security projects
  • Experience with securing AI/ML workloads in cloud environments

Compensation and Benefits

$200,000 - $340,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks.

Skills

AWS, GCP, Azure, Terraform, CloudFormation, Kubernetes, Python, Bash, Cspm, Cwpp, Casb, CI/CD, DevSecOps

OpenAI

OpenAI

San Francisco, CA
Red Team Specialist - Cyber
$198k+/yrHybridSecurity Engineering

The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.

Vercel

Vercel

San Francisco, CA
Software Engineer, Trust & Safety
$196k+/yrHybrid5+ YOESecurity Engineering

Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.

1Password

1Password

United States
Manager, Security Incident Response
$192k+/yrRemote5+ YOESecurity Engineering

Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.

Decagon

Decagon

San Francisco, CA

Governance, Risk, and Compliance Manager - Privacy
$190k+/yrOn-site5+ YOESecurity Engineering

Own and operate Decagon’s privacy and GRC programs, including regulatory compliance, data governance, customer security engagements, audits, and cross-functional privacy initiatives. The role requires 5+ years of GRC experience, strong communication and project management skills, and familiarity with enterprise security controls.

Anthropic

Anthropic

San Francisco, CA
Safeguards Policy Analyst, Cyber Harms
$190k+/yrHybridSecurity Engineering

The analyst develops and evaluates cyber product policies, enforcement guidance, controlled-access frameworks, and launch-review inputs for AI systems. The role requires strong policy writing, cybersecurity or platform-enforcement familiarity, technical security literacy, and cross-functional communication.