Experience: 5+ years
- Design and manage a highly resilient corporate device fleet spanning Linux, macOS, Windows and specialized hardware such as NVIDIA GPU workstations.
- Shift the fleet away from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without reducing assurance.
- Secure diverse local toolchains and developer environments without breaking the workflows researchers and engineers depend on.
- Architect cloud-native security controls across multi-cloud environments that contain multi-million-dollar GPU clusters.
- Establish IAM governance, network segmentation, and isolation boundaries appropriate to the scale and sensitivity of training infrastructure and model assets.
- Partner with infrastructure and research teams to ensure security controls scale with GPU capacity rather than constrain it.
- Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One).
- Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across every corporate and production plane.
- Eliminate standing and persistent access in favor of just-in-time, verifiable authorization.
- Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi).
- Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.
- Build repeatable, auditable deployment pipelines that make security posture provable rather than assumed.
- Build telemetry pipelines that ingest high-fidelity logs into a cloud-native data lake to support detection at scale.
- Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks across corporate and production environments.
- Continuously tune detection coverage against an assumed-breach threat model, prioritizing time-to-detect and blast-radius containment.
- Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
- Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.
- Own front-line defenses for a frontier AI company, including physical security and data center security operations.
- 20+ years of deep engineering experience at high-valuation companies, or in defense-grade environments.
- Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.
- Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
- Experience leading vendor risk, procurement security reviews, and legal contract negotiations.
- Experience with front-line defenses for an AI company, including physical security and data center security operations.
- Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments.
- Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.
- Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.
- Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation.
- A "guardrails, not gates" philosophy - understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation.
- An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately.
- Motivated by building - comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization.
Search Manager of Technology & Security Engineering jobs near New York, NY → Browse all live jobs
This posting was published by Reflectionai on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.