You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
Inferact

Member of Technical Staff, Vulnerability Management

  • Office
  • 6+ years

Salary

$200,000 - 400,000/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Inferact's mission is to grow vLLM as the world's AI inference engine and accelerate AI progress by making inference cheaper and faster. Founded by the creators and core maintainers of vLLM, we sit at the intersection of models and hardware, a position that took years to build.

About the Role

We're looking for a Member of Technical Staff, Vulnerability Management to own Inferact's side of vLLM's vulnerability-management process and help keep a critical piece of AI infrastructure secure and production-grade. You'll develop a deep understanding of vLLM's architecture, independently investigate vulnerability reports, and turn technical findings into clear, actionable work for the core team.

Working primarily in open source, you'll collaborate with vLLM maintainers, Red Hat counterparts, security firms, and researchers working with frontier AI models. You'll drive reports from initial triage through analysis and resolution, helping coordinate fixes, security advisories, and releases under the project's established process. You'll also identify practical security best practices that strengthen vLLM as it evolves. This is a hands-on product security role that combines technical investigation, sound judgment, and ownership of follow-through.

vLLM's vulnerability-management process

Requirements

  • Minimum qualifications:
  • Hands-on product security experience, with a strong orientation toward infrastructure software and the security of complex software systems.
  • Ability to read source code, debug unfamiliar systems, reproduce reported issues, and explain root cause and practical security impact rather than simply forward findings.
  • Strong systems reasoning, including the ability to understand architecture, trust boundaries, deployment assumptions, and how different software components interact.
  • Ability to learn vLLM's core architecture and independently manage vulnerability investigations while bringing in maintainers where their expertise is needed.
  • Sound prioritization and risk-assessment judgment, with clear documentation of evidence, affected behavior, remediation needs, and next steps.
  • Strong written and verbal communication, discretion with sensitive reports, and the ability to work constructively with engineers, researchers, and external security collaborators.
  • Preferred qualifications:
  • Experience with vulnerability management and security best practices for open-source infrastructure software.
  • Experience coordinating vulnerability resolution across reporters, maintainers, security teams, and software releases.
  • Familiarity with vLLM, inference engines, ML infrastructure, or similarly complex distributed software; prior vLLM contributions are helpful but not required.
  • Experience preparing security advisories, assessing affected versions, and working with CVE and coordinated-disclosure workflows.
  • Experience translating security findings into practical architecture reviews, regression tests, secure development practices, or deployment guidance.
  • Bonus points if you have:
  • Helped resolve vulnerabilities in an open-source infrastructure project and can explain your technical contribution and coordination with maintainers.
  • Built security tooling or automation that improved investigation quality or reduced repetitive triage work.
  • Turned recurring vulnerability patterns into maintainable fixes, tests, or documentation that helped prevent similar issues.
  • Logistics
  • Location: This role is based in San Francisco, California. Will consider remote in the US for exceptional candidates.
  • Compensation: Depending on background, skills, and experience, the expected annual salary range for this position is $200,000 - $400,000 USD + equity.
  • Visa sponsorship: We sponsor visas on a case-by-case basis.
  • Benefits: Applicable benefits will be confirmed based on the final role location.

Where you’d work

From the office

The office

Visa sponsored

About the company

Inferact

  • Industry: AI

Office in San Francisco, United States

2 of their 12 open roles are remote

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 22 checks run
  • 2 red flags

Still hiring?

14 checks

No red flags

How crowded?

8 checks

2 red flags

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details12 facts · Role, Location, Compensation, Employment, Company
Seniority
Staff
Type
Full-time
Equity
Equity offered
Industry
AI
Region
United States
Pay period
Annual
Show 6 more factsShow less

Role

Category
DevOps & Infrastructure
Seniority
Staff
Experience
6+ years

Location

Work model
Office
Region
United States
Office
  • San Francisco, United States
Visa sponsorship
Sponsored

Compensation

Salary
$200,000 - 400,000 / year
Pay period
Annual
Equity
Equity offered

Employment

Type
Full-time

Company

Industry
AI

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Lead IT Engineer

    Salary by agreement

    • Remote
    • Lead & Manager
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Site Reliability Engineer

    Salary by agreement

    • Remote
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason