> Markdown version of [/jobs/ext/2710659-infrastructure-security-engineer](https://www.wearedevelopers.com/jobs/ext/2710659-infrastructure-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Infrastructure Security Engineer - **Company:** Ai, Inc - **Location:** New York, United States - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Cloud Computing, Cloud Computing Security, Computer Networks, Distributed Systems, Identity and Access Management, Key Management, Cloud Platform System, Backend, Containerization, Kubernetes - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/infrastructure-security-engineer-modal-com-8108275 ## About the Role Core Experience * Experience securing cloud-native infrastructure and distributed systems in production * Background in infrastructure, backend, or security engineering * Experience working in multi-tenant or high-scale environments Technical Depth * Strong understanding of containerization and orchestration systems (e.g., Kubernetes or similar) * Experience designing or securing isolation mechanisms in multi-tenant systems * Solid understanding of authentication, authorization, and service identity models * Experience with secrets management and secure handling of credentials * Strong foundation in networking concepts (segmentation, service communication, access boundaries) Mindset * Builder mentality, you design and implement, not just review * Pragmatic approach to security in fast-moving environments * Comfortable working deeply with engineers and influencing system design, * Experience with sandboxing or runtime isolation technologies (e.g., gVisor, Firecracker, seccomp, or similar) * Familiarity with kernel-level or low-level isolation primitives * Experience securing Kubernetes or similar orchestration systems in production * Background in developer infrastructure, compute platforms, or multi-tenant systems ## Description We're looking for an Infrastructure Security Engineer to design and secure the core systems that power our platform. This role focuses on building security directly into our infrastructure-from container isolation and orchestration to identity and secrets management in a multi-tenant, cloud-native environment. You'll work closely with engineering teams to define secure primitives and ensure our platform is resilient, scalable, and trustworthy by design. This is a hands-on, deeply technical role focused on real systems, not compliance or policy. What You'll Do: Platform & Runtime Security * Design and improve isolation mechanisms for multi-tenant workloads (containers, sandboxing, execution environments) * Strengthen boundaries between customers, workloads, and internal systems * Identify and mitigate risks in distributed, dynamic compute environments Container & Orchestration Security * Secure and harden containerized workloads and orchestration systems (e.g., Kubernetes or similar) * Improve workload isolation, scheduling boundaries, and runtime protections * Evaluate tradeoffs in multi-tenant execution models Identity & Access Management * Design and improve authentication and authorization systems across services * Implement strong service-to-service identity and least-privilege access patterns * Improve access controls across infrastructure and internal systems Secrets & Key Management * Build and maintain systems for securely managing secrets, tokens, and credentials * Improve rotation, auditing, and access controls * Reduce secret sprawl and integrate secure patterns into developer workflows Cloud & Infrastructure Security * Secure cloud environments across providers (AWS, GCP, etc.) with a focus on consistency and portability * Improve network boundaries, service segmentation, and access controls * Embed security into infrastructure-as-code and deployment systems Engineering Partnership * Work closely with product and infrastructure teams to design secure systems from the ground up * Review architecture and code for security risks and provide actionable guidance * Identify patterns in risks and drive cross-cutting improvements ## Related Videos - [Developing the Backend with Stefan Lingler, CTO at Shpock](https://www.wearedevelopers.com/videos/100360-developing-the-backend-with-stefan-lingler-cto-at-shpock) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Nest.js - TypeScript in the backend can also be clean](https://www.wearedevelopers.com/videos/1033-nest-js-typescript-in-the-backend-can-also-be-clean) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Trustworthy AI Starts at Deployment: 5 Checks Before You Ship](https://www.wearedevelopers.com/magazine/753-trustworthy-ai-starts-at-deployment-5-checks-before-you-ship) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai)