
Infrastructure Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Design and implement security controls across Kubernetes clusters, including admission policies, RBAC, workload identity, network policies, and runtime hardening.
• Strengthen the software supply chain from dependency intake through to build and deployment.
• Manage cloud IAM and identity architecture, focusing on least-privilege roles, short-lived credentials, and workload federation.
• Secure research infrastructure and training pipelines, encompassing model weights and datasets.
• Conduct threat modeling for new platform components and convert findings into actionable requirements.
• Create guardrails for AI agents and developer tools operating within the infrastructure.
• Write infrastructure as code and policy as code.
• Assist in incident response for infrastructure-related issues with prompt system analysis and containment strategies.
• Collaborate with platform and engineering teams to deploy production security controls.
• Practical experience securing Kubernetes in production, including admission policies, RBAC, and workload identity.
• Proficient knowledge of cloud IAM and networking on at least one major cloud platform.
• Familiarity with identity federation and short-lived credentials.
• Experience with infrastructure as code and GitOps-style deployment methodologies.
• Proficiency in writing Python, TypeScript, Rust, or another language for tooling development.
• Understanding of software supply chain attacks and relevant controls, including signing, provenance, SBOMs, and admission enforcement.
• Ability to produce clear technical documentation for design documents, threat models, and engineering explanations.
• Sound judgment regarding the enforcement of security controls and the safe implementation of breaking changes.
• Experience in securing GPU or HPC-style computing, training pipelines, or research environments is advantageous.
• Familiarity with policy engines and admission controllers such as Kyverno, OPA Gatekeeper, or Falco is a plus.
• Experience with multi-tenant isolation design, ABAC, scoped credentials, and per-tenant boundaries is a plus.
• Experience in producing security architecture evidence for SOC 2, ISO 27001, or other audits is a plus.
• Contributions to open source projects or published work in cloud or Kubernetes security are beneficial.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Flexible work hours and remote working options.
• Opportunities for professional development and continuing education.
• Collaborative and inclusive team culture.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.