Member of Technical Staff, Security Engineering

General Diffusion, Inc.

San Francisco, Northern (CA, KY)

Hybrid

USD 180,000 - 280,000

Full time

10 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

General Diffusion, Inc. is building AI compute engineers that predict the consequences of placement before a workload touches production, across a bare-metal, multi-architecture testbed.

As an MTS in Security Engineering, you will make the authority around those agents-identities, tool calls, workloads, and releases-narrow, revocable, isolated, and traceable, including when inputs are adversarial. This role secures who and what can act; Safety & Verification remains responsible for the

Qualifications

  • Platform or product security engineering experience in systems where code can trigger consequential infrastructure actions.
  • Strong Linux security fundamentals and practical experience designing workload identity, service-to-service authorization, secrets handling, and least-privilege access controls.
  • Experience securing isolation boundaries such as containers, virtual machines, sandboxes, or similar multi-tenant execution environments, with clear understanding of their failure modes.
  • Experience hardening CI/CD and software supply chains, including dependency risk, artifact integrity or provenance, and deploy-time policy enforcement.
  • Ability to threat-model agentic or automation-heavy systems and translate adversarial scenarios into testable controls rather than relying on instructions or model behavior alone.
  • Practical incident-response judgment: can investigate an access-control or isolation failure from telemetry, contain it, and convert lessons into durable engineering changes.

Responsibilities

  • Threat-model the paths from agent output to runtime, fleet, and release actions; turn findings into explicit trust boundaries, abuse cases, and prioritized engineering work.
  • Build workload and service identity controls with short-lived, scoped credentials, authorization checks at downstream boundaries, and prompt revocation for compromised or retired access.
  • Engineer isolation for untrusted workloads and tool integrations, with deliberate controls on filesystem, network, device, and secret access appropriate to each execution path.
  • Establish secure build and deployment controls: protect source and dependency intake, preserve artifact provenance, and enforce policy checks before privileged environments accept releases.
  • Develop adversarial test coverage for agent and tool misuse—including indirect instruction attacks, confused-deputy paths, privilege escalation, and attempts to escape workload boundaries—and keep the cases reproducible as regressions.
  • Make privileged actions reconstructible through security-relevant audit signals, detections, and incident runbooks; partner with Fleet on operational response without taking ownership of fleet operation.

Job description

Member of Technical Staff, Security Engineering

Make agent authority, isolation, and deployment paths enforceable and auditable.

Status Open

Area Security

General Diffusion is building AI compute engineers that predict the consequences of placement before a workload touches production, across a bare-metal, multi-architecture testbed. As an MTS in Security Engineering, you will make the authority around those agents-identities, tool calls, workloads, and releases-narrow, revocable, isolated, and traceable, including when inputs are adversarial. This role secures who and what can act; Safety & Formal Verification remains responsible for the correctness and independently enforced permissibility of actions.

01 / The work

What you'll work on
  • Threat-model the paths from agent output to runtime, fleet, and release actions; turn findings into explicit trust boundaries, abuse cases, and prioritized engineering work.
  • Build workload and service identity controls with short-lived, scoped credentials, authorization checks at downstream boundaries, and prompt revocation for compromised or retired access.
  • Engineer isolation for untrusted workloads and tool integrations, with deliberate controls on filesystem, network, device, and secret access appropriate to each execution path.
  • Establish secure build and deployment controls: protect source and dependency intake, preserve artifact provenance, and enforce policy checks before privileged environments accept releases.
  • Develop adversarial test coverage for agent and tool misuse—including indirect instruction attacks, confused-deputy paths, privilege escalation, and attempts to escape workload boundaries—and keep the cases reproducible as regressions.
  • Make privileged actions reconstructible through security-relevant audit signals, detections, and incident runbooks; partner with Fleet on operational response without taking ownership of fleet operation.
02 / The background
What you bring
  • Hands-on platform or product security engineering experience in systems where code can trigger consequential infrastructure actions.
  • Strong Linux security fundamentals and practical experience designing workload identity, service-to-service authorization, secrets handling, and least-privilege access controls.
  • Experience securing isolation boundaries such as containers, virtual machines, sandboxes, or similar multi-tenant execution environments, with clear understanding of their failure modes.
  • Experience hardening CI/CD and software supply chains, including dependency risk, artifact integrity or provenance, and deploy-time policy enforcement.
  • Ability to threat-model agentic or automation-heavy systems and translate adversarial scenarios into testable controls rather than relying on instructions or model behavior alone.
  • Practical incident-response judgment: can investigate an access-control or isolation failure from telemetry, contain it, and convert lessons into durable engineering changes.
03 / The evidence
What progress looks like
  • A reviewed security architecture maps identities, trust boundaries, privileged tools, sensitive assets, and revocation paths across the agent-to-runtime flow; its open risks have named owners and tracked mitigations.
  • Representative privileged actions execute through scoped identities and independently enforced authorization checks, with evidence from access tests showing that expired, over-scoped, or cross-boundary requests are denied and logged.
  • A repeatable adversarial evaluation suite exercises high-risk agent and workload abuse paths, and its results inform regression tests, incident playbooks, and release criteria for the security-relevant interfaces.
04 / In the system
Where this role fits

Owns security of who and what can act; Safety & Verification owns correctness of allowed actions.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Enterprise AI Security & Governance Architect
Staff Enterprise AI Security & Governance Architect

Alexander Chapman • San Francisco (CA)

On-site
USD 180,000 - 260,000
Member of Technical Staff, Safety & Formal Verification
Member of Technical Staff, Safety & Formal Verification

General Diffusion, Inc. • San Francisco (CA), Northern (KY)

Hybrid
USD 180,000 - 260,000
MTS - Engineering (Security)
MTS - Engineering (Security)

Collinear AI, Inc. • San Francisco (CA)

On-site
USD 140,000 - 200,000
Member of Technical Staff, Security
Member of Technical Staff, Security

Mount Thor • San Francisco (CA)

On-site
USD 190,000 - 230,000
Principal Application & AI Security Engineer
Principal Application & AI Security Engineer

DNV Group • Houston (TX), Northern (KY)

Hybrid
USD 150,000 - 185,000
Security Lead
Security Lead

Sunset • New York (NY)

On-site
USD 170,000 - 230,000
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Platform Security [US]
Platform Security [US]

Brain Co. • San Francisco (CA)

On-site
USD 140,000 - 210,000
Principal Security Engineer
Principal Security Engineer

Valmar Holdings LLC. • Village of Williamsville (NY)

Hybrid
USD 140,000 - 200,000
Member of Technical Staff (Security) - AI Infrastructure
Member of Technical Staff (Security) - AI Infrastructure

Hamilton Barnes Associates Limited • United States

On-site
USD 213,000 - 288,000
Equity
Full Healthcare