Infrastructure Security Engineer

Modal

New York (NY)

On-site

USD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading tech company in New York is seeking an Infrastructure Security Engineer to enhance the security of their platform's core systems. This hands-on role involves designing secure infrastructures, working closely with engineers to develop effective isolation mechanisms, and managing authentication and secrets systems. Candidates should have extensive experience in cloud-native environments, container orchestration (like Kubernetes), and a builder mentality to implement security solutions effectively.

Qualifications

  • Experience securing cloud-native infrastructure and distributed systems.
  • Strong understanding of containerization and orchestration systems.
  • Solid foundation in networking concepts and service identity models.

Responsibilities

  • Design and improve isolation mechanisms for multi-tenant workloads.
  • Secure and harden containerized workloads and orchestration systems.
  • Build and maintain systems for securely managing secrets and credentials.

Skills

Cloud-native infrastructure security
Containerization and orchestration (Kubernetes)
Networking concepts (segmentation, access boundaries)
Authentication and authorization designs

Job description

The Role:

We’re looking for an Infrastructure Security Engineer to design and secure the core systems that power our platform. This role focuses on building security directly into our infrastructure—from container isolation and orchestration to identity and secrets management in a multi-tenant, cloud-native environment.

You’ll work closely with engineering teams to define secure primitives and ensure our platform is resilient, scalable, and trustworthy by design.

This is a hands‑on, deeply technical role focused on real systems, not compliance or policy.

What You’ll Do:
Platform & Runtime Security
  • Design and improve isolation mechanisms for multi‑tenant workloads (containers, sandboxing, execution environments)
  • Strengthen boundaries between customers, workloads, and internal systems
  • Identify and mitigate risks in distributed, dynamic compute environments
Container & Orchestration Security
  • Secure and harden containerized workloads and orchestration systems (e.g., Kubernetes or similar)
  • Improve workload isolation, scheduling boundaries, and runtime protections
  • Evaluate tradeoffs in multi‑tenant execution models
Identity & Access Management
  • Design and improve authentication and authorization systems across services
  • Implement strong service‑to‑service identity and least‑privilege access patterns
  • Improve access controls across infrastructure and internal systems
Secrets & Key Management
  • Build and maintain systems for securely managing secrets, tokens, and credentials
  • Improve rotation, auditing, and access controls
  • Reduce secret sprawl and integrate secure patterns into developer workflows
Cloud & Infrastructure Security
  • Secure cloud environments across providers (AWS, GCP, etc.) with a focus on consistency and portability
  • Improve network boundaries, service segmentation, and access controls
  • Embed security into infrastructure‑as‑code and deployment systems
    Engineering Partnership
    • Work closely with product and infrastructure teams to design secure systems from the ground up
    • Review architecture and code for security risks and provide actionable guidance
    • Identify patterns in risks and drive cross‑cutting improvements
    Requirements:
    Core Experience
    • Experience securing cloud‑native infrastructure and distributed systems in production
    • Background in infrastructure, backend, or security engineering
    • Experience working in multi‑tenant or high‑scale environments
    Technical Depth
    • Strong understanding of containerization and orchestration systems (e.g., Kubernetes or similar)
    • Experience designing or securing isolation mechanisms in multi‑tenant systems
    • Solid understanding of authentication, authorization, and service identity models
    • Experience with secrets management and secure handling of credentials
    • Strong foundation in networking concepts (segmentation, service communication, access boundaries)
    Mindset
    • Builder mentality, you design and implement, not just review
    • Pragmatic approach to security in fast‑moving environments
    • Comfortable working deeply with engineers and influencing system design
    Preferred Qualifications:
    • Experience with sandboxing or runtime isolation technologies (e.g., gVisor, Firecracker, seccomp, or similar)
    • Familiarity with kernel-level or low-level isolation primitives
    • Experience securing Kubernetes or similar orchestration systems in production
    • Background in developer infrastructure, compute platforms, or multi‑tenant systems
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Infrastructure Security Engineer
Infrastructure Security Engineer

Modal Labs • New York (NY)

On-site
Cloud-Native Infrastructure Security Engineer
Cloud-Native Infrastructure Security Engineer

Modal Labs • New York (NY)

On-site
Infrastructure Security Engineer
Infrastructure Security Engineer

The available sources do not contain information about the company name for rounx.com. • United States

On-site
USD 150,000 - 230,000
Security Engineer
Security Engineer

Juicebox • San Francisco (CA)

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

factory • San Francisco (CA)

On-site
USD 120,000 - 150,000
Infrastructure Security Engineer
Infrastructure Security Engineer

The Material Group • San Francisco (CA)

On-site
USD 180,000 - 240,000
Equity
Comprehensive medical, dental, vision,
Life and disability insurance
+4
Senior Platform Security Engineer
Senior Platform Security Engineer

Career Techniques • Dallas (TX)

Hybrid
USD 100,000 - 140,000
Senior DevSecOps Engineer – Cloud Infrastructure Security
Senior DevSecOps Engineer – Cloud Infrastructure Security

Partnerverse • Saint Cloud (MN)

On-site
USD 140,000 - 190,000
Security Engineer(Cloud & Kubernetes)
Security Engineer(Cloud & Kubernetes)

TechDigital Group • Frisco (TX)

On-site
USD 100,000 - 130,000
Security Engineer, Infrastructure
Security Engineer, Infrastructure

Scale AI, Inc. • Washington

On-site
USD 237,000 - 297,000