Manager of Technology & Security Engineering
On-siteSan Francisco, California, United States
Job Summary
Design and manage a resilient corporate device fleet spanning Linux, macOS, Windows, and NVIDIA GPU workstations using posture verification and cryptographic binding. Architect cloud-native security controls across multi-cloud environments to protect multi-million-dollar GPU clusters, establishing IAM governance and network segmentation. Implement continuous, context-aware zero-trust access with hardware-backed authentication and just-in-time authorization. Ensure 100% infrastructure and endpoint configurations are declared in code with automated CI/CD validation. Build telemetry pipelines for behavioral detection engineering to ingest high-fidelity logs and detect sophisticated post-exploitation techniques. Support SOC 2, ISO 27001, FedRAMP, and customer audits while leading vendor risk assessments and legal contract negotiations. Operate across engineering, infrastructure, and physical security to defend a frontier AI company's model weights and training data.
Required Qualifications
- 20+ years of deep engineering experience at high-valuation companies, or in defense-grade environments
- Battle-tested technical leadership with a track record of building and operating security engineering functions at scale
- Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews
- Experience leading vendor risk, procurement security reviews, and legal contract negotiations
- Experience with front-line defenses for an AI company, including physical security and data center security operations
- Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments
- Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives
- Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration
- Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation
- A 'guardrails, not gates' philosophy — understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation
- An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately
- Motivated by building — comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.