MTS, Technology & Security Engineering
New York, NY • FullTime
Posted 11h ago
Remote Work Policy
On-site
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Reflection is a research lab dedicated to making intelligence open and accessible. We build open models that empower users to control their intelligence and shape the future of AI. As a MTS for Technology & Security Engineering, you will be responsible for architecting and operating the security engineering foundation that protects our corporate environment, multi-cloud research infrastructure, and significant GPU training capacity. This role is pivotal in defining how a frontier AI company safeguards its most sensitive assets, including model weights, training data, and GPU capacity, while maintaining a low-friction environment for researchers and engineers. The ideal candidate possesses deep technical expertise and the executive presence to lead a security engineering function, represent our security posture to stakeholders, and manage vendor and contractual risks.
Responsibilities
- Design and manage a resilient corporate device fleet across Linux, macOS, Windows, and specialized hardware like NVIDIA GPU workstations.
- Transition the fleet from restrictive MDM policies to intelligent posture verification and cryptographic device binding.
- Secure diverse local toolchains and developer environments without disrupting researcher and engineer workflows.
- Architect cloud-native security controls for multi-cloud environments housing significant GPU clusters.
- Establish appropriate IAM governance, network segmentation, and isolation boundaries for training infrastructure and model assets.
- Partner with infrastructure and research teams to ensure security controls scale with GPU capacity.
- Implement continuous, context-aware authorization using modern mesh networks and proxies.
- Enforce hardware-backed authentication across all corporate and production planes.
- Eliminate standing access in favor of just-in-time, verifiable authorization.
- Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code.
- Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.
- Build repeatable, auditable deployment pipelines for provable security posture.
- Build telemetry pipelines for high-fidelity logs to support detection at scale.
- Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks.
- Continuously tune detection coverage against an assumed-breach threat model.
- Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
- Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.
- Own front-line defenses, including physical security and data center security operations.
Requirements
- 7+ years of deep engineering experience at high-valuation companies or in defense-grade environments.
- Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.
- Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
- Experience leading vendor risk, procurement security reviews, and legal contract negotiations.
- Experience with front-line defenses for an AI company, including physical security and data center security operations.
- Deep familiarity with Linux and macOS internals, including securing specialized hardware (NVIDIA GPUs) without breaking developer environments.
- Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.
- Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.
- Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation.
- A 'guardrails, not gates' philosophy, building systems that assume compromise and focus on virtualization, sandboxing, and data isolation.