Infrastructure Security Engineer

Talenthopllc โ€” United States ยท Posted ~4 hours ago

๐Ÿ”“ Log in to save this job, tailor your resume & track your apply process โ€” 7 days free, no card needed.

Log in to add to target list

Description

This is a Fully Remote Job About Our Client: The organization operates at the intersection of artificial intelligence, art, and science, focusing on developing world models that simulate real-world experiences. These models aim to accelerate learning through simulation, addressing challenges that language models alone cannot solve, such as robotics, disease, and scientific discovery. By advancing general-purpose simulation, the organization seeks to impact storytelling, scientific progress, and the expansion of human frontiers. About the Opportunity: The INFRASTRUCTURE SECURITY ENGINEER role is responsible for securing the platform that supports model training and deployment. This position ensures the integrity and security of Kubernetes clusters, cloud identity and access management, software supply chains, tenant isolation, and research infrastructure. The engineer's work enables safe and efficient operation of frontier video models, protecting the platform in a complex environment that differs from typical SaaS security needs. Responsibilities: Design and implement security controls within Kubernetes ecosystems, including admission policies, RBAC, workload identity, network policies, and runtime hardening.Harden the software supply chain from dependency intake to deployment, including package firewalling, artifact signing, provenance, and admission controls.Manage cloud IAM and identity architecture focusing on least-privilege access, short-lived credentials, and workload federation.Secure research infrastructure and training pipelines, safeguarding access to model weights and datasets without hindering users.Conduct threat modeling for new platform components and translate findings into actionable requirements.Develop guardrails for AI agents and developer tools operating within the infrastructure.Write infrastructure as code and policy as code, maintaining rigorous review and rollout processes.Support incident response by providing clear information on system operations and necessary shutdown actions. Requirements: Practical experience securing Kubernetes in production environments, including admission policies, RBAC, and workload identity.Knowledge of cloud IAM and networking on major cloud platforms, including identity federation and short-lived credentials.Experience with infrastructure as code and GitOps deployment methodologies.Programming skills in Python, Typescript, Rust, or similar languages for tooling development.Understanding of software supply chain attacks and mitigations such as signing, provenance, SBOMs, and admission enforcement.Strong communication skills for creating design documents, threat models, and explaining security concepts.Good judgment in enforcing controls and managing change impacts. Preferred Qualifications: Experience securing GPU or HPC compute, training pipelines, or research environments.Familiarity with policy engines and admission controllers like Kyverno, OPA Gatekeeper, or Falco.Knowledge of multi-tenant isolation designs in cloud environments.Experience preparing security architecture evidence for audits such as SOC 2 or ISO 27001.Contributions to open source or published work in cloud or Kubernetes security. Pay Range and Compensation Package: The pay range and compensation package for this role will be determined based on the candidate's experience, skills, and other relevant factors. Equal Opportunity Statement: Our client is an equal opportunity employer. They celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, or national origin. Note: TalentHop is a recruitment partner of this role. Please note that all employment decisions, including candidate assessment, interviews, hiring, compensation, and employment terms, are made exclusively by the hiring employer.