Staff Security Engineer, Infrastructure

The Consensus

San Francisco (CA)

On-site

USD 180,000 - 260,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Health plan
Dental & Vision

Job summary

fal.ai is seeking a Security Engineer, Infrastructure to secure its AI platform across multi-cloud environments, GPUs, and data pipelines. You’ll design and implement security controls spanning cloud, Kubernetes, networking, and secrets management, enabling secure by-default workflows for fast developers.

This role emphasizes hands-on engineering, cross-functional collaboration, and a strong security culture as fal.ai continues to scale its generative media infrastructure.

Qualifications

  • 8+ years in security engineering, infrastructure, or SRE.
  • Strong knowledge of cloud security and Zero Trust.
  • Experience securing production infrastructure at scale.

Responsibilities

  • Secure core AI platform infrastructure across cloud, Kubernetes, and networks.
  • Implement Zero Trust and identity/secrets controls across systems.
  • Design security guardrails with IaC (Terraform, Pulumi) to enforce secure defaults.
  • Collaborate with platform, infra, and ML teams to shift security left.

Skills

Cloud security
Networking
Linux security
Container security (Docker/Kubernetes)
Production infra at scale

Tools

Terraform
Vault
KMS

Job description

fal is the generative media ecosystem powering the next generation of AI products. We build the infrastructure, tools, and model access that teams need to move from idea to production, and do it at scale without compromise. For developers and enterprises, fal is the foundation that makes generative media not just possible, but practical: a unified platform where high-performance inference, orchestration, and observability come together to unlock new categories of AI-native products.

As generative media reshapes industries across a market projected to grow by hundreds of billions over the next decade, fal is becoming the ecosystem that ambitious teams build on.

fal is the generative media ecosystem powering the next generation of AI products. We build the infrastructure, tools, and model access that teams need to move from idea to production, and do it at scale without compromise. For developers and enterprises, fal is the foundation that makes generative media not just possible, but practical: a unified platform where high-performance inference, orchestration, and observability come together to unlock new categories of AI-native products.

As generative media reshapes industries across a market projected to grow by hundreds of billions over the next decade, fal is becoming the ecosystem that ambitious teams build on.

About the Role

We're looking for a Security Engineer, Infrastructure to secure the core systems that power fal.ai's platform: GPU compute, multi-cloud environments, networking, and data pipelines. You'll operate across the full stack, from cloud and Kubernetes to identity, networking, and secrets, designing and implementing security controls that scale with a high-performance AI platform. This role is highly hands-on and systems-oriented, sitting at the intersection of security, infrastructure, and distributed systems.

What You’ll Do
Build & Harden Infrastructure Security

Design and implement security controls across:

  • Cloud infrastructure
  • Kubernetes and containerized workloads
  • Networking, service meshes, and edge systems
  • CI/CD pipelines and deployment systems
  • Secure compute environments for GPU workloads and model execution
Identity, Secrets & Access
  • Machine identity and workload authentication
  • Secrets management and encryption (e.g., Vault, KMS)
  • Least-privilege access and short-lived credentials
  • Implement Zero Trust principles across infrastructure
Secure AI & Data Systems
  • Protect model weights, inference endpoints, and customer data
  • Design secure data access pathways and isolation mechanisms
  • Ensure safe multi-tenant execution environments
Automation & Security Tooling
  • Build security guardrails directly into infrastructure and CI/CD
  • Use Infrastructure-as-Code (Terraform, Pulumi) to enforce secure defaults
  • Continuously identify and remediate security gaps through automation
Threat Modeling & Risk Reduction
  • Identify and mitigate risks across infrastructure layers
  • Defend against both external attackers and insider threats
  • Drive projects like network isolation, encryption, and secure service communication
Cross-Functional Collaboration
  • Partner with platform, infra, and ML teams to drive shift-left security
  • Enable engineers to move fast with secure-by-default systems
  • Contribute to a strong security culture across the company
What We’re Looking For
Core Requirements
  • 8+ years in security engineering, infrastructure, or SRE
  • Strong understanding of:
    • Cloud security (AWS, GCP, or Azure)
    • Networking fundamentals (segmentation, firewalls, Zero Trust)
    • Linux systems and container security (Docker, Kubernetes)
    • Experience building or securing production infrastructure at scale
Security Expertise

Deep knowledge of:

  • Authentication & authorization systems
  • Secrets management and cryptography basics
  • Common vulnerabilities and attack vectors
  • Ability to design security controls across multiple layers (infra to app)
Engineering Skills
  • Proficiency in at least one language (Go, Python, or similar)
  • Experience with Infrastructure-as-Code (Terraform preferred)
  • Strong automation mindset - security should scale with systems
Nice to Have

Experience with:

  • GPU infrastructure or ML systems
  • Multi-tenant platform isolation
  • Service mesh / zero-trust architectures
  • High-growth startup environments
What Makes This Role Unique
  • Work on cutting-edge AI infrastructure security (not just SaaS)
  • Secure GPU clusters, model execution, and real-time inference systems
  • High ownership: design systems from first principles
  • Direct impact on developer trust and platform reliability
Our Security Philosophy
  • Secure-by-default > bolt-on security
  • Enable developers, don't block them
  • Automate everything
  • Assume breach, design for resilience
Compensation & Benefits
  • Competitive salary + equity
  • Full health, dental, and vision coverage
  • Opportunity to work on frontier AI infrastructure
Why fal.ai

You'll help define what security looks like for the next generation of AI infrastructure where performance, scale, and safety all matter.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Security Engineer, InfrastructureSan Francisco
Staff Security Engineer, InfrastructureSan Francisco

fal • San Francisco (CA)

On-site
USD 130,000 - 160,000
Competitive salary + equity
Full health, dental, and vision coverage
Opportunity to work on frontier AI infrastructure
Staff Security Engineer, Infrastructure
Staff Security Engineer, Infrastructure

fal • San Francisco (CA)

On-site
USD 130,000 - 160,000
Competitive salary + equity
Full health, dental, and vision coverage
Opportunity to work on frontier AI infrastructure
Senior Security Engineer: AI Infrastructure & GPU Compute
Senior Security Engineer: AI Infrastructure & GPU Compute

The Consensus • San Francisco (CA)

On-site
USD 180,000 - 260,000
Equity
Health plan
Dental & Vision
Security Engineer
Security Engineer

Cerebro • San Francisco (CA)

On-site
USD 180,000 - 240,000
Equity
Benefits package
Security Engineer - Member of Technical Staff
Security Engineer - Member of Technical Staff

Simile • San Francisco (CA)

On-site
USD 200,000 - 400,000
Equity grants
Comprehensive medical, dental, and vision coverage
Flexible time off policies
Platform Security Engineer
Platform Security Engineer

Future Secure AI • Austin (TX)

On-site
USD 130,000 - 160,000
Flexible work environment
State-of-the-art technology
Competitive salary
Platform Security Engineer Austin, TX
Platform Security Engineer Austin, TX

Future Secure AI Pty • Austin (TX)

On-site
USD 120,000 - 160,000
Flexible work environment
Competitive salary
High-performance culture
+1
Data Security Engineer
Data Security Engineer

General Intuition & Medal • New York (NY)

On-site
USD 100,000 - 150,000
Competitive salary and equity
Comprehensive medical, dental, and vision coverage
401(k)
+4
Software Engineer, Site Reliability
Software Engineer, Site Reliability

Fal • San Francisco (CA)

On-site
USD 180,000 - 250,000
Relocation assistance to San Francisco
Visa sponsorship
Competitive salary and equity
+1
Senior Member of Technical Staff - Infrastructure Security
Senior Member of Technical Staff - Infrastructure Security

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Significant compensation and equity opportunity
Work across cloud, Kubernetes, GPU infrastructure, CI/CD, and platform engineering