Own and improve Polymarket's AWS security posture by designing and enforcing security controls in infrastructure code, managing cloud telemetry and detection, and driving compliance. Requires 4+ years cloud security experience, deep AWS expertise, and IaC skills.
180k – 250k/yr
Remote4+ YOESecurity Engineering
About the role
Responsibilities
Own and continuously improve Polymarket's AWS security posture across accounts, regions, and services — including IAM policies, SCPs, VPC segmentation, and account-level security baselines.
Review and contribute to IaC modules that encode security defaults; integrate automated security checks into the deployment pipeline including policy-as-code validation and misconfiguration scanning.
Own cloud-side security telemetry: CloudTrail, GuardDuty, Security Hub, Config Rules, VPC Flow Logs, and S3 access logging.
Develop and tune detection logic for cloud-specific threats; partner with the SOC team on alert fidelity, incident response runbooks, and AWS-level investigations.
Govern secrets management using AWS Secrets Manager and SSM Parameter Store; manage KMS key policies, rotation, and envelope encryption patterns.
Drive remediation of findings from AWS Inspector, Security Hub, and third-party CSPM tooling; maintain benchmarks aligned to CIS AWS Foundations.
Support audit and compliance activities (SOC 2, PCI-DSS, or similar) and conduct regular access reviews to identify and remediate privilege creep.
Requirements
4+ years of experience in cloud security, cloud engineering, or a security-focused infrastructure role.
Deep, hands-on expertise with AWS security services: IAM, SCP, GuardDuty, Security Hub, CloudTrail, Config, KMS, WAF, Inspector, and VPC.
Hands-on experience writing infrastructure as code (Pulumi, Terraform, CDK, or equivalent) with a security-first mindset.
Strong understanding of AWS networking and how misconfigurations translate to real attack surface.
Proficiency in at least one scripting or programming language (Python, TypeScript, or Go) for automation and tooling.
Ability to evaluate architectural decisions for security risk and communicate findings clearly to engineering peers.
Nice-to-Haves
Familiarity with Pulumi, specifically TypeScript-based stacks.
Familiarity with Web3, blockchain infrastructure, or crypto-sector threat models.
Experience securing containerized workloads on ECS or EKS, including image scanning and runtime security.
AWS certifications: Security Specialty, Solutions Architect — Professional, or equivalent.
Exposure to SOC 2 Type II or PCI-DSS cloud control requirements.
Compensation & Benefits
Competitive salary & equity.
Unlimited PTO.
Full Health, Vision, & Dental coverage.
401k match.
Hardware setup: new MacBook Pro, big display, & accessories.
Designs and implements network security architectures using firewalls, VPNs, and IDS/IPS. Conducts vulnerability assessments, monitors threats with SIEM tools, ensures compliance, and automates security responses. Requires expertise in security tools and certifications like CISSP.
Leads vulnerability response for cloud-native AI platform, managing intake, triage, validation, remediation coordination, and bug bounty programs. Requires expertise in reproducing web/app/cloud vulnerabilities and operating disclosure processes.
180k – 325k/yr
HybridSecurity Engineering
Security Engineer - Azure Government
xAIPalo Alto, CA +1
Designs, implements, and maintains security controls in Azure Gov Cloud, focusing on threat detection, identity management, network security, and compliance with FedRAMP/CMMC. Requires 3+ years cloud security experience, Azure expertise, US security clearance eligibility, and scripting proficiency.
180k – 440k/yr
Hybrid3+ YOESecurity Engineering
Security Engineer, Infrastructure Security
OpenAISan Francisco, CA +3
Designs and builds security controls for infrastructure including GPU clusters, multi-cloud setups, datacenters, Kubernetes, and networks to protect AI models and data from advanced threats. Requires deep security expertise, cloud platform knowledge, and proactive problem-solving across on-prem and cloud environments.
184k – 385k/yr
RemoteSecurity Engineering
Software Engineer, Infrastructure Security
OpenAISan Francisco, CA +2
Designs and builds production-grade security services like auth systems, proxies, and key management for OpenAI's GPU clusters, multi-cloud infrastructure, and AI workloads. Requires strong software engineering in Python/Go/Rust, experience with critical security infra, and cloud security expertise.