Infrastructure Engineer, Security

Thinking Machines Lab

San Francisco (CA)

On-site

USD 200,000 - 475,000

Full time

2 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
Relocation support

Job summary

Thinking Machines Lab is seeking an infrastructure engineer to own and evolve its security foundation across compute, storage, networking, and data platforms. You’ll shape controls and tooling so security is default, partnering with research and product teams to move quickly while protecting models, data, and environments.

You will design security patterns, manage identities and secrets, and build secure data handling pipelines with guardrails that make secure paths the easiest option.

Qualifications

  • Bachelor’s degree in engineering or equivalent.
  • Experience securing Kubernetes workloads and service meshes.
  • Terraform or similar IaC for secure provisioning.
  • Knowledge of cloud networking: VPCs, load balancers, mTLS, firewalls.
  • Proficient in Rust and Python for platform components.

Responsibilities

  • Architect security patterns for platforms and services.
  • Manage identity, access, and secrets with least-privilege IAM.
  • Build secure data ingestion, processing, and sharing patterns.
  • Write threat models and review designs with researchers and engineers.
  • Automate security checks, policy-as-code, and CI/CD guardrails.

Skills

Kubernetes security
Terraform IaC
Cloud networking
Rust
Python scripting
Production systems

Education

Bachelor’s degree or equivalent

Tools

Terraform
Kubernetes

Job description

Thinking Machines Lab's mission is to empower humanity through advancing collaborative general intelligence. We're building a future where everyone has access to the knowledge and tools to make AI work for their unique needs and goals.

We are scientists, engineers, and builders who’ve created some of the most widely used AI products, including ChatGPT and Character.ai, open-weights models like Mistral, as well as popular open source projects like PyTorch, OpenAI Gym, Fairseq, and Segment Anything.

About the Role

We’re looking for an infrastructure engineer to own and evolve the security infrastructure that underpins our foundation models. In this role, you’ll work across compute, storage, networking, and data platforms, making sure our systems are secure, reliable, and built to scale. You’ll shape controls, architecture, and tooling so that security is part of how the platform works by default. You’ll partner closely with research and product teams, enabling them to move quickly while keeping our models, data, and environments protected.

What You’ll Do
  • Architect security patterns for platforms and services, including network segmentation, service-to-service authentication, RBAC, and policy enforcement in Kubernetes and cloud environments.
  • Manage identity, access, and secrets for humans and services: workload and cross-cloud identity, least-privilege IAM, and secrets management.
  • Build secure platforms for data ingestion, processing, and curation: classification, encryption, access controls, and safe sharing patterns across teams.
  • Write threat models and review designs with researchers and engineers to help them ship features and experiments in a safe, scalable way.
  • Automate security checks and build guardrails: policy-as-code, secure infrastructure baselines, validation in CI/CD, and tools that make the secure path the easiest one.
Skills and Qualifications
  • Bachelor’s degree or equivalent experience in engineering, or similar.
  • Strong background with containers and orchestration (e.g., Kubernetes) and how to secure them (namespaces, network policies, pod security, admission controls, etc.)
  • Practical experience with Infrastructure as Code (Terraform or similar), including secure patterns for provisioning networks, IAM, and shared services.
  • Solid understanding of cloud networking and security: VPCs, load balancers, service discovery, mTLS, firewalls, and zero-trust-style architectures.
  • Proficiency with a systems language such as Rust and scripting in Python for building platform components and internal tools.
  • Evidence of owning complex, production-critical systems, including debugging issues that span infra, security, and application layers.
Preferred qualifications
  • Experience with ML infrastructure, GPU clusters, or large-scale training environments (schedulers, job queues, shared storage, multi-tenant clusters).
  • Background in AI labs, HPC environments, or ML-heavy organizations where both security and performance are first-class concerns.
  • Experience profiling and tuning high-throughput systems, and an ability to reason about the cost of additional security layers.
  • Talks, blogs, or publications on infrastructure security, distributed systems, or performance engineering.
  • Open-source contributions to security, orchestration, observability, or infrastructure tooling.
  • Familiarity with securing specialized hardware (GPUs, TPUs) and their integrations into training and inference pipelines.
Logistics
  • Location: This role is based in San Francisco, California.
  • Compensation: Depending on background, skills and experience, the expected annual salary range for this position is $200,000 - $475,000 USD.
  • Visa sponsorship: We sponsor visas. While we can't guarantee success for every candidate or role, if you're the right fit, we're committed to working through the visa process together.
  • Benefits: Thinking Machines offers generous health, dental, and vision benefits, unlimited PTO, paid parental leave, and relocation support as needed.

As set forth in Thinking Machines' Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Thinking Machines Lab will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of the California Fair Chance Act, the San Francisco Fair Chance Ordinance, and any other applicable state or local fair chance ordinance or law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer, Security
Software Engineer, Security

Thinking Machines Lab • San Francisco (CA)

On-site
USD 350,000 - 475,000
Generous health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
Software Engineer Security
Software Engineer Security

Thinking Machines Lab • San Francisco (CA)

On-site
USD 350,000 - 475,000
Generous health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
Software Engineer, Security
Software Engineer, Security

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 350,000 - 475,000
Health, dental, and vision benefits
Unlimited PTO
Parental leave
+1
Software Engineer, Systems Generalist
Software Engineer, Systems Generalist

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 350,000 - 475,000
Visa sponsorship
Relocation support
Health benefits
Security Engineer, Infrastructure Security
Security Engineer, Infrastructure Security

OpenAI • United States

On-site
USD 230,000 - 385,000
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

OpenAI • United States

On-site
USD 230,000 - 385,000
Security Engineer, Infrastructure Security
Security Engineer, Infrastructure Security

OpenAI • Seattle (WA)

On-site
USD 230,000 - 385,000
Research Engineer, Infrastructure, Training Systems
Research Engineer, Infrastructure, Training Systems

Thinking Machines Lab Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 350,000 - 475,000
Health benefits
Unlimited PTO
Parental leave
+1
Software Engineer, Infrastructure Security
Software Engineer, Infrastructure Security

Coinscapture • Los Angeles (CA), Northern (KY)

Hybrid
USD 180,000 - 240,000
Security Engineer, Infrastructure Security
Security Engineer, Infrastructure Security

Coinscapture • Northern (KY)

Hybrid
USD 180,000 - 240,000