RadixArk is looking for a Member of Technical Staff — Security to champion both our internal security posture and help us prepare for vendor audits and compliance requirements. As our first dedicated security engineer, you'll lay the foundation for security practices across our infrastructure, products, and operations—ensuring we can confidently serve enterprise customers and pass SOC 2 audits.
This is a unique opportunity to shape security from the ground up at a fast-growing AI infrastructure company. You'll work across backend systems, cloud infrastructure, and customer-facing APIs to build security into our products and processes before external auditors arrive.
Responsibilities
Security Posture & Compliance:
Build and document our internal security architecture, controls, and practices
Create threat models for our systems and products that interact with customer data
Develop an Incident Response Plan (IRP) and Business Continuity/Disaster Recovery (BC/DR) plan
Establish vulnerability and patch management processes with clear SLAs
Prepare security documentation for vendor audits, including SOC 2 readiness
System Scoping & Inventory:
Define which systems and data handle customer data to determine SOC 2 audit scope
Create and maintain an inventory of infrastructure, applications, and third-party dependencies
Classify data flows and identify security boundaries between in-house and outsourced components
Document which security controls are managed internally vs. outsourced to vendors (AWS, GCP, etc.)
Understanding of regulatory compliance frameworks (SOC 2 is a plus; export control is a major plus for us)
Preferred Experience:
Background in founding or early-stage startups—you understand scrappy, pragmatic security (not over-engineering on day one)
Experience with ML infrastructure, GPU/compute management, or high-performance systems
Involvement in SOC 2 audits or other compliance programs
Experience writing security policies, playbooks, and operational runbooks
Familiarity with supply-chain security, open-source risk, or dependency management
Education & Background:
Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent professional experience
Relevant security certifications (CISSP, CISM, CEH, OSCP, etc.) are a plus but not required
Notes for Candidates
We're looking for someone who is pragmatic, autonomous, and genuinely excited about security as a core part of our business—not someone looking for a checklist compliance role. You should be comfortable with ambiguity, able to prioritize ruthlessly, and willing to help across all of ops/finance/legal as needed (that's the reality of founding team hires at a Series A startup).
If you have questions about the role, security priorities, or company direction, we'd love to hear from you.
About RadixArk
RadixArk is an infrastructure-first company built by engineers who've shipped production AI systems, created SGLang (30K+ GitHub stars, the fastest open LLM serving engine), and developed Miles (our large-scale RL framework). Founded by AI infrastructure veterans from xAI and NVIDIA, we're on a mission to democratize frontier-level AI infrastructure by building world-class open systems for inference and training. Our team has optimized kernels serving billions of tokens daily, designed distributed training systems coordinating 10,000+ GPUs, and contributed to infrastructure that powers leading AI companies and research labs.