Member of Technical Staff — Security Engineering

Causal Labs

San Francisco, Northern (CA, KY)

Hybrid

USD 150,000 - 230,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Causal Labs in San Francisco develops a Large Physics foundation model. We seek a security engineer to design and operate the security posture across our engineering stack, protecting research environments, model weights, and customer integrations while maintaining rapid iteration.

You will own enterprise identity federation, zero-trust boundaries, and secure deployment pipelines across Kubernetes, Slurm, and cloud platforms. Strong systems and cloud security background required.

Qualifications

  • Proven track record building and securing production systems in cloud environments (AWS, GCP, or Azure).
  • Experience with IAM, network perimeters, KMS/encryption, and secrets management.

Responsibilities

  • Architect secure network perimeters and isolated storage environments.
  • Protect model weights and checkpoints; secure execution environments.
  • Secure data ingestion pipelines; guard against tampering and poisoning.
  • Manage enterprise identity federation and mTLS; ensure audit logs and compliance.
  • Integrate security testing and threat detection into deployment workflows (Kubernetes, Slurm, APIs).

Skills

Security engineering
Cloud security
IAM & encryption
Linux systems
Docker & Kubernetes
Infrastructure as Code
Python
Go
Rust

Tools

Kubernetes
Slurm
Okta
Entra ID
Terraform
Pulumi

Job description

Our mission is general causal intelligence; AI that is capable of (1) predicting the future and (2) identifying the actions to alter it.

To achieve this breakthrough, we are building a Large Physics foundation Model (LPM) because physical systems, unlike text or images, are governed by verifiable cause and effect. We believe that scaling on physics will enable an understanding of causality required to predict and control physical systems, starting with weather.

Our founding team has built and deployed AI against the physical world in robotics, drug discovery, and particle physics at institutions like DeepMind, Waymo, Cruise, Insitro, Nabla Bio, and CERN.

About Security at Causal Labs

As we build and deploy our Large Physics Model, we operate an environment that spans petabytes of continuous physical observations, massive distributed GPU clusters, and high-stakes customer deployments.

Your mission is to design and operate the security posture across our entire engineering stack. You will ensure our research environments, proprietary model weights, software infrastructure, and customer integrations remain secure, all while maintaining the rapid iteration and engineering velocity our researchers need.

Responsibilities

  • Enterprise Infrastructure & Cloud Isolation: Architect secure network perimeters, private data transmission channels (e.g., PrivateLink, VPNs), and isolated single/multi-tenant storage environments. Implement access controls and customer-managed encryption (KMS/BYOK) across petabyte-scale data stores.

  • Model IP & Weight Protection: Design zero-trust boundaries, encrypted storage, and secure execution environments to protect proprietary foundation model weights and checkpoints against exfiltration during storage, distributed multi-node training, and serving.

  • Pipeline Integrity & AI Threat Defense: Secure our data ingestion pipelines against tampering and data poisoning. Threat-model and defend against AI-specific vulnerabilities, including adversarial inputs, model extraction attacks, and data memorization/regurgitation risks using output guardrails and privacy-preserving techniques.

  • Enterprise Auth & Governance: Own enterprise identity federation (SAML 2.0/OIDC with Okta, Entra ID) and machine-to-machine authentication (mTLS). Implement immutable audit logging, cryptographic erasure, and compliance controls required for enterprise CISOs and SOC 2 / FedRAMP environments.

  • Security Engineering & SDLC: Partner with Infrastructure, Research, and Forward Deployed teams to build automated security testing, threat detection, and vulnerability scanning directly into our deployment workflows, orchestrators (Kubernetes, Slurm), and customer-facing APIs.

What we're looking for

  • Demonstrated Hands-on Security Engineering: Proven track record building and securing production systems in cloud environments (AWS, GCP, or Azure) or large-scale distributed systems. Practical mastery of core primitives: IAM, network perimeters, KMS/encryption, and secrets management.

  • Strong Systems & Software Background: Hands-on experience with Linux systems, networking, container security (Docker, Kubernetes), Infrastructure-as-Code (Terraform or Pulumi), and proficiency in languages like Python, Go, or Rust.

  • Understanding of ML Platform Security: Practical grasp of the security challenges unique to ML platforms—protecting high-value model weights, securing distributed training pipelines, data lineage/poisoning, and AI-specific threat vectors.

  • Adaptable & High Agency: Comfort conducting architectural security reviews, digging into complex distributed systems, and adapting fast to new technical constraints or bespoke enterprise customer environments.

  • Bias Toward Real-World Impact: Pragmatic mindset—delivering security solutions that actually work for users under pressure, balancing rigor with engineering velocity.

  • End-to-End Ownership: Ability to take deliverables autonomously from initial threat modeling and requirements all the way through execution, deployment, and monitoring.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Member of Technical Staff — Security Engineering
Member of Technical Staff — Security Engineering

Kindredventures • San Francisco (CA)

On-site
USD 140,000 - 230,000
Member of Technical Staff — Product Engineering
Member of Technical Staff — Product Engineering

Causal Labs • San Francisco (CA)

On-site
USD 150,000 - 190,000
Member of Technical Staff — Product Engineering
Member of Technical Staff — Product Engineering

Kindredventures • San Francisco (CA)

On-site
USD 115,000 - 165,000
Senior Security Engineer - ML Platform & Cloud Infra
Senior Security Engineer - ML Platform & Cloud Infra

Causal Labs • San Francisco (CA), Northern (KY)

Hybrid
USD 150,000 - 230,000
Infrastructure Engineer, Security
Infrastructure Engineer, Security

Thinking Machines Lab • San Francisco (CA)

On-site
USD 200,000 - 475,000
Health, dental, and vision benefits
Unlimited PTO
Paid parental leave
+1
Security Engineer for Large-Scale ML Infrastructure
Security Engineer for Large-Scale ML Infrastructure

Kindredventures • San Francisco (CA)

On-site
USD 140,000 - 230,000
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Member of Technical Staff — Research Engineering, Evaluation
Member of Technical Staff — Research Engineering, Evaluation

Kindredventures • San Francisco (CA)

On-site
USD 140,000 - 200,000
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Senior Lead Security Engineer, AI
Senior Lead Security Engineer, AI

JPMorgan Chase & Co. • Columbus (OH)

On-site
USD 180,000 - 230,000