Turn this role into an interview — a resume and cover letter built around what this employer wants.
Reflection seeks a Senior MTS for Technology & Security Engineering to architect and operate the security foundation across our multi-cloud research infra, protecting model weights, training data, and GPU capacity.
The role blends security engineering with research operations, requiring hands-on depth and executive leadership to represent security posture to auditors and customers while negotiating vendor risk.
Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.
As a MTS for Technology & Security Engineering is responsible for architecting and operating the security engineering foundation that protects the organization’s corporate environment, multi-cloud research infrastructure, and multi-million-dollar GPU training capacity. This leader owns the full technical security stack — from end-user compute and zero-trust access to cloud and container security, detection engineering, and security-as-code — ensuring the organization can move at research speed without sacrificing rigor.
Sitting at the intersection of security engineering, infrastructure, and research operations, this role is uniquely positioned to define how a frontier AI company protects its most sensitive assets — model weights, training data, and GPU capacity — while preserving the low-friction environment researchers and engineers need to do their best work. The ideal candidate brings deep, hands-on technical depth alongside the executive presence to lead a security engineering function, represent the organization’s security posture to auditors and enterprise customers, and negotiate vendor and contractual risk.
This is a high-visibility, high-impact role that operates across engineering, infrastructure, legal, and physical security. Success requires the ability to design guardrails rather than gates, build systems that assume compromise, and operate credibly as both an executive leader and a hands-on builder.
High-Performance End User Compute (EUC)
Design and manage a highly resilient corporate device fleet spanning Linux, macOS, Windows and specialized hardware such as NVIDIA GPU workstations.
Shift the fleet away from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without reducing assurance.
Secure diverse local toolchains and developer environments without breaking the workflows researchers and engineers depend on.
Securing the Research & Training Boundary
Architect cloud-native security controls across multi-cloud environments that contain multi-million-dollar GPU clusters.
Establish IAM governance, network segmentation, and isolation boundaries appropriate to the scale and sensitivity of training infrastructure and model assets.
Partner with infrastructure and research teams to ensure security controls scale with GPU capacity rather than constrain it.
Phishing-Resistant Zero-Trust Access
Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One).
Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across every corporate and production plane.
Eliminate standing and persistent access in favor of just-in-time, verifiable authorization.
Security as Code (SaC)
Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi).
Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.
Build repeatable, auditable deployment pipelines that make security posture provable rather than assumed.
Behavioral Detection Engineering
Build telemetry pipelines that ingest high-fidelity logs into a cloud-native data lake to support detection at scale.
Compliance, Audit & Vendor Risk
Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
Experience & Background
7+ years of deep engineering experience at high-valuation companies, or in defense-grade environments.
Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.
Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.
Experience leading vendor risk, procurement security reviews, and legal contract negotiations.
Experience with front-line defenses for an AI company, including physical security and data center security operations.
Skills & Capabilities
Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments.
Mindset & Approach
We believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.
We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.
Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.
Stock options: Everyone who joins and contributes to Reflection's success gets to share in the upside through stock options.
Health & wellness: Comprehensive medical, dental, vision, and life, with an annual wellness allowance.
Meals: Lunch and dinner are provided in the office daily.
Life & family: 22 weeks paid parental leave for all new birthing and non-birthing parents, including adoptive and surrogate journeys.
Vacation days: Unlimited paid time off in the U.S. and 30 days in the U.K.
Sponsorship support: We sponsor visas to help exceptional talent join our team and support long-term immigration pathways where applicable.
Team building: We have regular off-sites, happy hours, and team celebrations.
Export Control Notice: This position may require access to technology or source code subject to the U.S. Export Administration Regulations. Any offer of employment for this role may be conditioned on the Company's ability to provide the candidate with access to such technology or source code in compliance with applicable U.S. export control laws, which may require the Company to seek government authorization.