Назад
5 дней назад

Infrastructure Security Engineer (AI)

240 000 - 290 000$
Формат работы
remote (Global)
Тип работы
fulltime
Английский
b2
Страна
France/UK/US +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Infrastructure Security Engineer (AI): Securing the Kubernetes, cloud identity, software supply chain, tenant isolation, and research infrastructure used to train and serve frontier video models with an accent on production security controls and AI-focused platform environments. Focus on designing admission policies, hardening build and deployment pipelines, securing model data and training systems, and building infrastructure guardrails that withstand real-world attacks.

Location: Remote. Remote hiring is available; offices are located in New York, San Francisco, Seattle, London, Paris, and Tel Aviv. The stated salary range applies to candidates in the U.S.; compensation may vary outside the U.S.

Salary: $240,000–$290,000 per year

Company

Runway builds AI world models and frontier video models that simulate the world by combining art and science.

What you will do

  • Design and ship Kubernetes security controls, including admission policies, RBAC, workload identity, network policies, and runtime hardening.
  • Harden the software supply chain through package firewalling, artifact signing, provenance tracking, SBOMs, and deployment admission controls.
  • Own cloud IAM and identity architecture, including least-privilege roles, short-lived credentials, and workload federation.
  • Secure research infrastructure, training pipelines, model weights, datasets, and multi-tenant serving environments.
  • Threat-model platform components, build guardrails for AI agents and developer tooling, and implement infrastructure and policy as code.
  • Support incident response by explaining infrastructure behavior and identifying containment actions.

Requirements

  • Production experience securing Kubernetes, including admission policies, RBAC, workload identity, and cluster compromise analysis.
  • Working knowledge of cloud IAM, networking, identity federation, and short-lived credentials on a major cloud platform.
  • Experience with infrastructure as code and GitOps-style deployment.
  • Ability to write production tooling in Python, TypeScript, Rust, or another programming language.
  • Understanding of software supply chain attacks and controls such as signing, provenance, SBOMs, and admission enforcement.
  • Strong technical writing, threat-modeling, and judgment around security control design and rollout.

Nice to have

  • Experience securing GPU or HPC compute, training pipelines, or research environments.
  • Experience with Kyverno, OPA Gatekeeper, Falco, or similar policy engines and admission controllers.
  • Experience designing multi-tenant cloud isolation with ABAC, scoped credentials, and per-tenant boundaries.
  • Experience preparing security architecture evidence for SOC 2, ISO 27001, or customer assessments.
  • Open-source contributions or published work in cloud or Kubernetes security.

Culture & Benefits

  • Remote work with access to offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.
  • Work alongside creative, open-minded, caring, and ambitious colleagues.
  • Commitment to diversity, equal opportunity, and pay equity.
  • Salary is determined based on market rates, experience, skills, qualifications, and internal equity.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →