Manager of Technology & Security Engineering

New York, NY FullTime

Posted 16d ago

Job Location

New York, NY

Tech Stack

Remote Work Policy

On-site

Employment Type

FullTime

Categories

Applied AI Engineer

About the job

Reflection is a research lab dedicated to making intelligence open and accessible. We build open models that empower individuals to control their intelligence and shape the future of AI. The Head of Technology & Security Engineering will architect and operate the security engineering foundation protecting our corporate environment, multi-cloud research infrastructure, and significant GPU training capacity. This leadership role encompasses the full technical security stack, from end-user compute and zero-trust access to cloud security, detection engineering, and security-as-code, enabling rapid research progress without compromising rigor. Positioned at the intersection of security engineering, infrastructure, and research operations, this role is crucial for safeguarding sensitive assets like model weights, training data, and GPU capacity, while maintaining a low-friction environment for researchers and engineers. The ideal candidate possesses deep technical expertise and executive presence to lead the security engineering function, represent the company's security posture, and manage vendor and contractual risks.

Responsibilities

  • Design and manage a resilient corporate device fleet across Linux, macOS, Windows, and specialized hardware like NVIDIA GPU workstations.
  • Transition the fleet from restrictive MDM policies to intelligent posture verification and cryptographic device binding.
  • Secure diverse local toolchains and developer environments without disrupting researcher and engineer workflows.
  • Architect cloud-native security controls for multi-cloud environments housing large-scale GPU clusters.
  • Establish IAM governance, network segmentation, and isolation boundaries for training infrastructure and model assets.
  • Partner with infrastructure and research teams to ensure security controls scale with GPU capacity.
  • Implement continuous, context-aware authorization using modern mesh networks and proxies.
  • Enforce hardware-backed authentication across all corporate and production planes.
  • Eliminate standing access in favor of just-in-time, verifiable authorization.
  • Ensure all infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code.
  • Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.
  • Build repeatable, auditable deployment pipelines for provable security posture.
  • Develop telemetry pipelines for high-fidelity logs to support large-scale detection.
  • Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks.
  • Continuously tune detection coverage against an assumed-breach threat model.
  • Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
  • Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.
  • Own front-line defenses, including physical security and data center security operations.

Requirements

  • 20+ years of deep engineering experience at high-valuation companies or in defense-grade environments.
  • Proven technical leadership in building and operating security engineering functions at scale.
  • Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
  • Experience leading vendor risk, procurement security reviews, and legal contract negotiations.
  • Experience with front-line defenses for AI companies, including physical and data center security operations.
  • Deep familiarity with Linux and macOS internals, including securing specialized hardware (NVIDIA GPUs) without breaking developer environments.
  • Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.
  • Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.
  • Ability to operate as both an executive leader and a hands-on builder, transitioning between strategy and implementation.
  • A "guardrails, not gates" philosophy, building systems that assume compromise and focus on virtualization, sandboxing, and data isolation.
  • An adversarial mindset focused on designing systems under the assumption of endpoint compromise.

About Reflection ai

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.