Назад
Company hidden
3 дня назад

Member of Technical Staff, Vulnerability Management (AI)

200 000 - 400 000$
Формат работы
remote (только USA)/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Member of Technical Staff, Vulnerability Management (AI): Managing vulnerability investigations for vLLM, an open-source AI inference engine, with an accent on source-code analysis, infrastructure security, and coordinated remediation. Focus on reproducing reported issues, assessing technical impact, coordinating fixes and security advisories, and strengthening secure development practices.

Location: San Francisco, California; remote work may be considered within the United States for exceptional candidates

Annual salary: $200,000–$400,000 USD plus equity

Company

hirify.global develops vLLM, an open-source AI inference engine focused on making model inference faster and more cost-effective.

What you will do

  • Own hirify.global’s side of the vLLM vulnerability-management process.
  • Investigate vulnerability reports by reading source code, debugging unfamiliar systems, reproducing issues, and determining root cause.
  • Assess architecture, trust boundaries, deployment assumptions, affected behavior, and practical security impact.
  • Coordinate vulnerability resolution, security advisories, fixes, and releases with maintainers, security teams, researchers, and external collaborators.
  • Develop security best practices, regression tests, deployment guidance, and documentation for vLLM.

Requirements

  • Hands-on product security experience focused on infrastructure software or complex software systems.
  • Ability to analyze source code, reproduce reported issues, explain root cause, and assess security impact.
  • Strong understanding of software architecture, trust boundaries, deployment assumptions, and component interactions.
  • Ability to independently manage vulnerability investigations and prioritize risks based on evidence.
  • Strong written and verbal communication, discretion with sensitive reports, and effective collaboration with engineers and security researchers.

Nice to have

  • Experience with open-source infrastructure security, vulnerability resolution, CVE, and coordinated-disclosure workflows.
  • Familiarity with vLLM, inference engines, ML infrastructure, or complex distributed software.
  • Experience preparing security advisories, assessing affected versions, or coordinating software releases.
  • Experience building security tooling or automation and converting recurring vulnerabilities into maintainable fixes, tests, or documentation.

Culture & Benefits

  • Work primarily in open source alongside vLLM maintainers and external security collaborators.
  • On-site work in San Francisco, with exceptional US-based remote candidates considered.
  • Equity is included in the compensation package.
  • Visa sponsorship is available on a case-by-case basis.
  • Benefits depend on the final role location.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →