Reflectionai

Manager of Technology & Security Engineering

Full-time · New York, NY
✓ Verified live on the employer's own system · added 27 days ago
Save search
Mid-level · 5+ yrs exp

Requirements

Experience: 5+ years

Skills & tools

LinuxMobile App DeploymentSecurityDevopsRecordkeepingEmbeddedOperationsTeam Leadership
Apply on company site ↗ See your fit → free

Full job description

- Design and manage a highly resilient corporate device fleet spanning Linux, macOS, Windows and specialized hardware such as NVIDIA GPU workstations.

- Shift the fleet away from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without reducing assurance.

- Secure diverse local toolchains and developer environments without breaking the workflows researchers and engineers depend on.

- Architect cloud-native security controls across multi-cloud environments that contain multi-million-dollar GPU clusters.

- Establish IAM governance, network segmentation, and isolation boundaries appropriate to the scale and sensitivity of training infrastructure and model assets.

- Partner with infrastructure and research teams to ensure security controls scale with GPU capacity rather than constrain it.

- Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One).

- Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across every corporate and production plane.

- Eliminate standing and persistent access in favor of just-in-time, verifiable authorization.

- Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi).

- Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.

- Build repeatable, auditable deployment pipelines that make security posture provable rather than assumed.

- Build telemetry pipelines that ingest high-fidelity logs into a cloud-native data lake to support detection at scale.

- Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks across corporate and production environments.

- Continuously tune detection coverage against an assumed-breach threat model, prioritizing time-to-detect and blast-radius containment.

- Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.

- Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.

- Own front-line defenses for a frontier AI company, including physical security and data center security operations.

- 20+ years of deep engineering experience at high-valuation companies, or in defense-grade environments.

- Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.

- Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.

- Experience leading vendor risk, procurement security reviews, and legal contract negotiations.

- Experience with front-line defenses for an AI company, including physical security and data center security operations.

- Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments.

- Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.

- Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.

- Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation.

- A "guardrails, not gates" philosophy - understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation.

- An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately.

- Motivated by building - comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization.

More jobs at Reflectionai

Similar jobs near New York, NY

Tell me when more Manager of Technology & Security Engineering jobs post near New York, NY We re-check every listing against the employer’s own board — no résumé needed.

Search Manager of Technology & Security Engineering jobs near New York, NY → Browse all live jobs

This posting was published by Reflectionai on their own careers system and is shown here with a direct link to apply there. Employers: for corrections or removal, contact jobs@veritahire.com.