Назад
Company hidden
13 дней назад

Member of Technical Staff — Security (AI Infrastructure)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Member of Technical Staff — Security (AI Infrastructure): Building security architecture, compliance controls, monitoring systems, and secure practices for AI infrastructure, backend systems, cloud platforms, and customer-facing APIs with an accent on SOC 2 readiness, threat modeling, and infrastructure and application security. Focus on designing incident response and disaster recovery plans, auditing authentication and multi-tenancy isolation, implementing vulnerability management, and leading vendor and customer security processes.

Location: Palo Alto, United States

Company

hirify.global is an infrastructure-first AI company building open systems for large-scale model inference and training.

What you will do

  • Build and document internal security architecture, controls, threat models, incident response, and business continuity plans.
  • Define SOC 2 audit scope, maintain inventories of infrastructure and dependencies, and document data flows and control ownership.
  • Improve network, API, cloud, container, supply-chain, secrets management, and data protection security.
  • Design security logging, monitoring, SIEM/SOAR integrations, alerting, runbooks, vulnerability scans, and penetration testing processes.
  • Lead SOC 2 audit coordination and prepare responses to vendor questionnaires, RFPs, and customer security requests.
  • Enable engineering teams to adopt secure development practices and integrate security into CI/CD and deployment processes.

Requirements

  • 4+ years of experience in security, infrastructure, backend systems, or equivalent hands-on security work.
  • Strong knowledge of AWS, GCP, or Azure, including IAM, networking, data protection, and secrets management.
  • Hands-on experience with Kubernetes, container security, or infrastructure-as-code, plus Linux/Unix administration.
  • Understanding of network security, authentication and authorization, cryptography, secure coding, OWASP Top 10, and common vulnerabilities.
  • Experience with vulnerability assessments, penetration testing, security audits, or building security programs.
  • Bachelor's degree in computer science, engineering, cybersecurity, or equivalent professional experience.

Nice to have

  • Experience with SOC 2 or other compliance programs, export control, security policies, playbooks, and operational runbooks.
  • Background in founding or early-stage startups and pragmatic security program development.
  • Experience with ML infrastructure, GPU or compute management, or high-performance systems.
  • Knowledge of supply-chain security, open-source risk, dependency management, or relevant security certifications.

Culture & Benefits

  • Founding-team security role with broad ownership across infrastructure, products, and operations.
  • Pragmatic, autonomous environment focused on prioritization and avoiding unnecessary over-engineering.
  • Opportunity to establish security practices before external auditors and enterprise customers arrive.
  • Equal employment opportunity regardless of legally protected characteristics.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →