> Markdown version of [/jobs/ext/3077491-infrastructure-security-engineer](https://www.wearedevelopers.com/jobs/ext/3077491-infrastructure-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Infrastructure Security Engineer - **Company:** The Runway - **Location:** New York, NY, United States (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Cyber Security, Computer Networks, Software Design Documents, Python (Programming Language), Open Source Technology, Role-Based Access Control, TypeScript, Rust (Programming Language), Policy as Code, Cloud Platform System, Kubernetes - **Published:** September 25, 2026 - **Apply:** https://startup.jobs/infrastructure-security-engineer-runwayml-10182607 ## About the Role * Hands-on experience securing Kubernetes in production: you've written admission policies, debugged RBAC and workload identity problems and understand how a cluster gets compromised * Working knowledge of cloud IAM and networking on at least one major cloud platform, including how identity federation and short-lived credentials actually work * Experience with infrastructure as code and GitOps-style deployment, and the habit of shipping security changes through the same pipeline as everything else * Comfort writing Python, Typescript, Rust or another language to build tooling, not just scripts * An understanding of software supply chain attacks and the controls that stop them: signing, provenance, SBOMs, admission enforcement * Clear writing. Design docs, threat models and explanations to engineers who don't work in security are all part of the job * Judgment about which controls to enforce, which to recommend and how to roll out a breaking change without breaking the company Even better if you have * Experience securing GPU or HPC-style compute, training pipelines or research environments * Experience with policy engines and admission controllers (Kyverno, OPA Gatekeeper, Falco or similar) * Multi-tenant isolation design in a cloud environment: ABAC, scoped credentials, per-tenant boundaries * Experience producing security architecture evidence for SOC 2, ISO 27001 or other audits and customer assessments * Open source contributions or published work in cloud or Kubernetes security ## Description * Design and ship security controls in our Kubernetes ecosystem: admission policy, RBAC, workload identity, network policy and runtime hardening across every cluster we run * Harden the software supply chain from dependency intake through build and deploy, including package firewalling, artifact signing and provenance, and admission controls that block what doesn't pass * Own cloud IAM and identity architecture: least-privilege roles, short-lived credentials and workload federation * Secure research infrastructure and training pipelines, including access to model weights and datasets, without slowing down the people using them * Threat model new platform components before they ship and turn the findings into concrete requirements the owning team can act on * Build guardrails for AI agents and developer tooling operating inside our infrastructure * Write infrastructure as code and policy as code, and treat security configuration with the same review and rollout discipline as any other change * Give the incident response team what they need when infrastructure is involved: fast answers about how a system works and what to shut off ## Related Videos - [Do TypeScript without TypeScript](https://www.wearedevelopers.com/videos/327-do-typescript-without-typescript) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Vuejs and TypeScript- Working Together like Peanut Butter and Jelly](https://www.wearedevelopers.com/videos/127-vuejs-and-typescript-working-together-like-peanut-butter-and-jelly) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Learning Kubernetes made easy with KubeCampus](https://www.wearedevelopers.com/magazine/348-learning-kubernetes-made-easy-with-kubecampus) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)