Infrastructure Security Engineer

Remote Remote FullTime

Posted 7h ago

Remote Work Policy

Fully remote

Employment Type

FullTime

Categories

AI Infrastructure Engineer

About the job

We are seeking an Infrastructure Security Engineer to join our Security team and secure the platform used for training and serving our AI models. This role involves a unique challenge compared to securing typical SaaS products, as it encompasses research compute, large training datasets, a fast-moving build pipeline, and AI-assisted tooling. You will be responsible for Kubernetes platform security, cloud identity and access management, software supply chain security, tenant isolation in the serving layer, and the research infrastructure supporting our models. This is a hands-on engineering position where you will write policy, tooling, and infrastructure code, contributing directly to production-ready controls.

Responsibilities

  • Design and implement security controls for Kubernetes environments, including admission policy, RBAC, workload identity, network policy, and runtime hardening.
  • Secure the software supply chain from dependency intake through build and deployment, incorporating package firewalling, artifact signing, provenance, and admission controls.
  • Manage and architect cloud IAM and identity, focusing on least-privilege roles, short-lived credentials, and workload federation.
  • Protect research infrastructure and training pipelines, ensuring secure access to model weights and datasets without hindering user productivity.
  • Conduct threat modeling for new platform components and translate findings into actionable requirements.
  • Develop guardrails for AI agents and developer tooling operating within the infrastructure.
  • Write infrastructure as code and policy as code, applying rigorous review and rollout processes to security configurations.
  • Provide critical support to the incident response team by offering rapid insights into system functionality and shutdown procedures during infrastructure-related incidents.

Requirements

  • Proven experience securing Kubernetes in production, including writing admission policies, debugging RBAC and workload identity issues, and understanding cluster compromise vectors.
  • Proficiency in cloud IAM and networking on at least one major cloud platform, with practical knowledge of identity federation and short-lived credentials.
  • Experience with infrastructure as code and GitOps deployment methodologies, integrating security changes into standard deployment pipelines.
  • Ability to write production-level code in languages such as Python, Typescript, or Rust for building tooling.
  • Solid understanding of software supply chain attacks and effective controls like signing, provenance, SBOMs, and admission enforcement.
  • Excellent written communication skills for design documents, threat models, and explanations to non-security engineers.
  • Strong judgment in determining which controls to enforce, recommend, and how to deploy critical changes without disruption.

About runway

Get new AI jobs in your inbox

A weekly digest of the newest AI engineering roles.

© 2026 AI Job Board. All rights reserved.