Infrastructure Security Engineer
New York • FullTime
Posted 4mo ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
AI Infrastructure Engineer
About the job
AI needs a new infrastructure layer, and this role is central to building it at Modal. We are seeking an Infrastructure Security Engineer to design and secure the core systems powering our platform. This position emphasizes building security directly into our infrastructure, covering aspects like container isolation, orchestration, identity, and secrets management within a multi-tenant, cloud-native environment. You will collaborate closely with engineering teams to establish secure primitives and ensure the platform's resilience, scalability, and trustworthiness by design. This is a hands-on, deeply technical role focused on practical implementation rather than compliance or policy.
Responsibilities
- Design and improve isolation mechanisms for multi-tenant workloads, including containers and sandboxing.
- Strengthen security boundaries between customers, workloads, and internal systems.
- Identify and mitigate risks in distributed, dynamic compute environments.
- Secure and harden containerized workloads and orchestration systems like Kubernetes.
- Improve workload isolation, scheduling boundaries, and runtime protections.
- Evaluate tradeoffs in multi-tenant execution models.
- Design and improve authentication and authorization systems across services.
- Implement strong service-to-service identity and least-privilege access patterns.
- Improve access controls across infrastructure and internal systems.
- Build and maintain systems for securely managing secrets, tokens, and credentials.
- Improve secret rotation, auditing, and access controls.
- Reduce secret sprawl and integrate secure patterns into developer workflows.
- Secure cloud environments across providers (AWS, GCP, etc.) with a focus on consistency and portability.
- Improve network boundaries, service segmentation, and access controls.
- Embed security into infrastructure-as-code and deployment systems.
- Work closely with product and infrastructure teams to design secure systems.
- Review architecture and code for security risks and provide actionable guidance.
- Identify patterns in risks and drive cross-cutting improvements.
Requirements
- Experience securing cloud-native infrastructure and distributed systems in production.
- Background in infrastructure, backend, or security engineering.
- Experience working in multi-tenant or high-scale environments.
- Strong understanding of containerization and orchestration systems (e.g., Kubernetes or similar).
- Experience designing or securing isolation mechanisms in multi-tenant systems.
- Solid understanding of authentication, authorization, and service identity models.
- Experience with secrets management and secure handling of credentials.
- Strong foundation in networking concepts (segmentation, service communication, access boundaries).
- Builder mentality, focused on design and implementation.
- Pragmatic approach to security in fast-moving environments.
- Comfortable working deeply with engineers and influencing system design.
- Experience with sandboxing or runtime isolation technologies (e.g., gVisor, Firecracker, seccomp, or similar) is preferred.
- Familiarity with kernel-level or low-level isolation primitives is preferred.
- Experience securing Kubernetes or similar orchestration systems in production is preferred.
- Background in developer infrastructure, compute platforms, or multi-tenant systems is preferred.