Reflection logo
ReflectionPosted 1 month ago

Manager of Technology & Security Engineering

On-siteSan Francisco, California, United States

Full TimeSenior LevelStartup

Job Summary

Design and manage a resilient corporate device fleet spanning Linux, macOS, Windows, and NVIDIA GPU workstations using posture verification and cryptographic binding. Architect cloud-native security controls across multi-cloud environments to protect multi-million-dollar GPU clusters, establishing IAM governance and network segmentation. Implement continuous, context-aware zero-trust access with hardware-backed authentication and just-in-time authorization. Ensure 100% infrastructure and endpoint configurations are declared in code with automated CI/CD validation. Build telemetry pipelines for behavioral detection engineering to ingest high-fidelity logs and detect sophisticated post-exploitation techniques. Support SOC 2, ISO 27001, FedRAMP, and customer audits while leading vendor risk assessments and legal contract negotiations. Operate across engineering, infrastructure, and physical security to defend a frontier AI company's model weights and training data.

Required Qualifications

  • 20+ years of deep engineering experience at high-valuation companies, or in defense-grade environments
  • Battle-tested technical leadership with a track record of building and operating security engineering functions at scale
  • Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews
  • Experience leading vendor risk, procurement security reviews, and legal contract negotiations
  • Experience with front-line defenses for an AI company, including physical security and data center security operations
  • Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments
  • Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives
  • Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration
  • Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation
  • A 'guardrails, not gates' philosophy — understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation
  • An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately
  • Motivated by building — comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce