Staff Security Engineer in Dallas

Energy Jobline ZR

Dallas (TX)

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical coverage (100% for employees)
PTO 15 days
Personal days 5
401k matching

Job summary

Topaz Labs is seeking a Principal Security Engineer to own security across our hybrid infrastructure, from AWS to colo data centers and from training clusters to the office network. You will be hands-on, shaping security posture while enabling creative workflows.

You will perform penetration testing, secure the AI model supply chain, and manage endpoint security for macOS devices using Jamf, alongside AD governance. This role is onsite in Dallas.

Qualifications

  • 7+ years of security engineering experience across infrastructure, IT, and offensive security.
  • Deep hands-on cloud security and compliance experience (AWS, IAM, VPC, SOC II).
  • Experience with endpoint management and governance tools (Jamf, AD).
  • Physical and network security experience in office/colo environments.
  • Hands-on penetration testing of networks and web apps.Competent scripting (Python/Bash) for automation.

Responsibilities

  • Own security across hybrid infrastructure (AWS & Colo) and data centers.
  • Manage corporate endpoints and devices (macOS) with Jamf; oversee AD governance.
  • Conduct regular hands-on penetration tests on internal networks, office infrastructure, and AI apps.
  • Design systems to secure the AI supply chain: weights, storage, delivery, tamper-proofing.
  • Collaborate with teams to balance security with creative workflows.

Skills

Cloud security
Endpoint management
Penetration testing
Python scripting
Bash scripting
Linux internals
Networking
IAM management
Active Directory

Tools

Jamf
Active Directory

Job description

Job DescriptionJob Description We use AI to do things that were previously impossible. Topaz Labs builds professional-grade software that uses deep learning to enhance image and video quality. Over 1 million photographers and designers trust us with their work, including teams at Apple, Netflix, NASA, and Disney. We’ve processed over 1 billion images, achieved massive revenue growth, and we’re only getting started.

We are a small, profitable, and product-led team that values craftsmanship and impact over activity. We don’t just ship features; we solve hard problems to help creatives do their best work.

As our first Principal Security Engineer, you will own the security posture for the entire organization—from the cloud to the colo, and from the training cluster to the office network.

This is not a high-level compliance role. You will be reporting directly to the Head of AI Engine, but your scope spans the entire company. You must be willing to get your hands dirty.

We operate a hybrid infrastructure: AWS, massive on-premise GPU training clusters in our colocation facility, and a corporate fleet of devices. Your mission is to secure every layer of this stack. You will have complete autonomy to architect security for our compute resources, manage office/colo networks, and harden our endpoints.

About the role
  • Secure the Hybrid Infrastructure (AWS & Colo): You will be the single owner for security across our cloud environments and our physical colocation data centers. This includes configuring firewalls, managing physical network security, and hardening our Linux GPU clusters.
  • Corporate & Endpoint Security: You will own the security of our internal tools and devices. You will manage our fleet (primarily macOS) using Jamf and oversee management via Active Directory.
  • You ensure our creative workflows are secure without being obstructive.
  • Hands-On Penetration Testing: We don't just rely on external audits. You will regularly conduct hands-on penetration tests against our internal networks, office infrastructure, and AI applications to find vulnerabilities before anyone else does.
  • Secure the AI Supply Chain: Our models are our most valuable IP. You will design systems to protect our model weights during training, storage, and delivery, ensuring they are tamper-proof and secure from theft or reverse engineering.
About you
  • You are a hands-on generalist. You are just as comfortable configuring an IAM policy in AWS as you are setting up a switch in a colocation rack or writing a script for Jamf.
  • You have a craftsmanship mentality. You take personal pride in building systems that are robust, elegant, and secure by default. You don't just patch holes; you eliminate entire classes of vulnerabilities.
  • You are an infrastructure . You are fluent in Linux internals, networking, and container orchestration. You understand the unique security challenges of cloud, distributed, and HPC environments.
  • You value truth over comfort. You are willing to have hard conversations about risk and prioritize fixing root causes over applying band-aids.
  • You think like an attacker. You don't wait for a report to tell you something is wrong. You actively probe our defenses (office, colo, and cloud) to prove they work.
Qualifications
  • 7+ years of experience in security engineering, with a mix of infrastructure, corporate IT, and offensive security.
  • Deep hands-on experience with cloud security and compliance (AWS, IAM, VPC, SOC II, Vanta).
  • Proven experience with Endpoint Management & : Expert-level knowledge of Jamf for macOS management and Active Directory (or modern equivalents) for governance.
  • Physical & Network Security: Experience securing physical office networks and colocation facilities (firewalls, VPNs, switching).
  • Offensive Security: Demonstrated ability to perform manual penetration testing (network and web app).Proficiency in scripting (Python/Bash) to automate security tasks.
  • Bonus: Experience securing on-device software or desktop applications (Windows/macOS).


This is a unique role for someone interested at a high-growth tech software company. We offer strong base salary, plus significant ownership that scales with the company's growth. We also offer 100% covered medical/dental/vision for employees, 15 days annual PTO, 5 personal days plus holidays, and 401k matching.

This is a full-time onsite role in Dallas, TX, and we will ask you to relocate if you're not in the area.

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Security Engineer
Staff Security Engineer

Topaz Labs • Emeryville (CA)

On-site
USD 130,000 - 160,000
100% covered medical/dental/vision
15 days annual PTO
401k matching
Staff Security Engineer
Staff Security Engineer

Topaz Labs • Dallas (TX)

On-site
USD 150,000 - 210,000
100% covered medical/dental/vision
15 days annual PTO
401k matching
Member of Technical Staff - Security
Member of Technical Staff - Security

Prime Intellect • San Francisco (CA), Northern (KY)

On-site
USD 180,000 - 350,000
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Senior Engineer, Application Security
Senior Engineer, Application Security

Cvent • Virginia (MN)

On-site
USD 120,000 - 160,000
Hybrid work model
Competitive benefits package
Staff Security Engineer
Staff Security Engineer

Robots and Pencils • United States

Remote
USD 160,463,000 - 220,636,000
Security Engineer
Security Engineer

10a Labs • United States

On-site
USD 105,000 - 125,000
Health, dental, and vision coverage
Generous PTO and paid holidays
401(k) plan
+1
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Senior Security Engineer, Product Security
Senior Security Engineer, Product Security

United States Digital Space LLC • United States

On-site
USD 140,000 - 190,000
Member of Technical Staff (Security) - AI Infrastructure
Member of Technical Staff (Security) - AI Infrastructure

Hamilton Barnes Associates Limited • United States

On-site
USD 213,000 - 288,000
Equity
Full Healthcare