← Все вакансии/Lead/fal-ai
LeadOfficeSan Francisco

Staff Security Engineer

FA
fal-ai
Уровень
Lead
Формат
Office
О роли

Описание вакансии

About the company

fal is the generative media ecosystem powering the next generation of AI products. We build the infrastructure, tools, and model access that teams need to move from idea to production, and do it at scale without compromise.

Responsibilities
  • Build & Harden Infrastructure Security: Design and implement security controls across cloud infrastructure, Kubernetes and containerized workloads, networking, service meshes, and edge systems, CI/CD pipelines and deployment systems, secure compute environments for GPU workloads and model execution.
  • Identity, Secrets & Access: Machine identity and workload authentication, secrets management and encryption (e.g., Vault, KMS), least-privilege access and short-lived credentials, implement Zero Trust principles across infrastructure.
  • Secure AI & Data Systems: Protect model weights, inference endpoints, and customer data, design secure data access pathways and isolation mechanisms, ensure safe multi-tenant execution environments.
  • Automation & Security Tooling: Build security guardrails directly into infrastructure and CI/CD, use Infrastructure-as-Code (Terraform, Pulumi) to enforce secure defaults, continuously identify and remediate security gaps through automation.
  • Threat Modeling & Risk Reduction: Identify and mitigate risks across infrastructure layers, defend against both external attackers and insider threats, drive projects like network isolation, encryption, and secure service communication.
  • Cross-Functional Collaboration: Partner with platform, infra, and ML teams to drive shift-left security, enable engineers to move fast with secure-by-default systems, contribute to a strong security culture across the company.
Requirements
  • 8+ years in security engineering, infrastructure, or SRE
  • Strong understanding of: Cloud security (AWS, GCP, or Azure), networking fundamentals (segmentation, firewalls, Zero Trust), Linux systems and container security (Docker, Kubernetes)
  • Experience building or securing production infrastructure at scale
  • Deep knowledge of: authentication & authorization systems, secrets management and cryptography basics, common vulnerabilities and attack vectors
  • Ability to design security controls across multiple layers (infra → app)
  • Proficiency in at least one language (Go, Python, or similar)
  • Experience with Infrastructure-as-Code (Terraform preferred)
  • Strong automation mindset—security should scale with systems
Conditions
  • Competitive salary + equity
  • Full health, dental, and vision coverage
  • Opportunity to work on frontier AI infrastructure
Стек и навыки

С чем работаем