You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
RadixArk

Member of Technical Staff — Security

  • Office
  • 6+ years

Salary

Not stated

Similar roles pay $170K - 235K a year · our estimate

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

About the Role

RadixArk is looking for a Member of Technical Staff — Security to champion both our internal security posture and help us prepare for vendor audits and compliance requirements. As our first dedicated security engineer, you'll lay the foundation for security practices across our infrastructure, products, and operations—ensuring we can confidently serve enterprise customers and pass SOC 2 audits.

This is a unique opportunity to shape security from the ground up at a fast-growing AI infrastructure company. You'll work across backend systems, cloud infrastructure, and customer-facing APIs to build security into our products and processes before external auditors arrive.

Responsibilities

  • Security Posture & Compliance:
  • Build and document our internal security architecture, controls, and practices
  • Create threat models for our systems and products that interact with customer data
  • Develop an Incident Response Plan (IRP) and Business Continuity/Disaster Recovery (BC/DR) plan
  • Establish vulnerability and patch management processes with clear SLAs
  • Prepare security documentation for vendor audits, including SOC 2 readiness
  • System Scoping & Inventory:
  • Define which systems and data handle customer data to determine SOC 2 audit scope
  • Create and maintain an inventory of infrastructure, applications, and third-party dependencies
  • Classify data flows and identify security boundaries between in-house and outsourced components
  • Document which security controls are managed internally vs. outsourced to vendors (AWS, GCP, etc.)
  • Infrastructure & Application Security:
  • Review and improve network security: firewalls, intrusion detection/prevention (IDS/IPS), DDoS mitigation
  • Audit API authentication, authorization, rate limiting, and multi-tenancy isolation
  • Implement secrets management and secure configuration practices
  • Review cloud IAM, networking, and data protection (encryption in transit and at rest)
  • Evaluate container and supply-chain security practices
  • Security Monitoring & Operations:
  • Design and implement security logging and monitoring systems
  • Set up SIEM/SOAR tooling or evaluate and integrate centralized logging
  • Establish security alerting, incident response procedures, and runbooks
  • Conduct regular vulnerability scans and penetration tests
  • Vendor & Customer Security:
  • Develop security processes to answer vendor questionnaires and RFPs
  • Create documentation for customers on security controls, certifications, and data handling
  • Lead the SOC 2 audit process—coordinate with internal teams and external auditors
  • Stay informed on relevant compliance frameworks (SOC 2, HIPAA, Export Control, etc.)
  • Team Enablement:
  • Enforce secure development practices to engineers
  • Help teams understand threat models relevant to their work
  • Build security into CI/CD pipelines and deployment processes
  • Experience & Requirements
  • Core Technical Skills:
  • 4+ years working on security, infrastructure, or backend systems (or equivalent combination of hands-on experience and security training)
  • Strong understanding of cloud platforms: AWS, GCP, or Azure (IAM, networking, data protection, secrets management)
  • Proficiency in Linux/Unix system administration and command-line tools
  • Hands-on experience with Kubernetes, container security, or infrastructure-as-code
  • Solid understanding of network security, authentication/authorization protocols, and cryptography basics
  • Experience conducting vulnerability assessments, penetration testing, or security audits
  • Security Expertise:
  • Demonstrated experience building or improving security programs (threat modeling, security architecture, incident response)
  • Knowledge of secure coding practices, OWASP Top 10, and common vulnerability types (SQLi, XSS, CSRF, etc.)
  • Familiarity with security tools: vulnerability scanners, SIEM, secret management systems, IDS/IPS
  • Understanding of regulatory compliance frameworks (SOC 2 is a plus; export control is a major plus for us)
  • Preferred Experience:
  • Background in founding or early-stage startups—you understand scrappy, pragmatic security (not over-engineering on day one)
  • Experience with ML infrastructure, GPU/compute management, or high-performance systems
  • Involvement in SOC 2 audits or other compliance programs
  • Experience writing security policies, playbooks, and operational runbooks
  • Familiarity with supply-chain security, open-source risk, or dependency management
  • Education & Background:
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent professional experience
  • Relevant security certifications (CISSP, CISM, CEH, OSCP, etc.) are a plus but not required
  • Notes for Candidates
  • We're looking for someone who is pragmatic, autonomous, and genuinely excited about security as a core part of our business—not someone looking for a checklist compliance role. You should be comfortable with ambiguity, able to prioritize ruthlessly, and willing to help across all of ops/finance/legal as needed (that's the reality of founding team hires at a Series A startup).
  • If you have questions about the role, security priorities, or company direction, we'd love to hear from you.
  • About RadixArk
  • RadixArk is an infrastructure-first company built by engineers who've shipped production AI systems, created SGLang (30K+ GitHub stars, the fastest open LLM serving engine), and developed Miles (our large-scale RL framework). Founded by AI infrastructure veterans from xAI and NVIDIA, we're on a mission to democratize frontier-level AI infrastructure by building world-class open systems for inference and training. Our team has optimized kernels serving billions of tokens daily, designed distributed training systems coordinating 10,000+ GPUs, and contributed to infrastructure that powers leading AI companies and research labs.

Where you’d work

From the office

About the company

RadixArk

  • Industry: AI

Office in Palo Alto, United States

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 18 checks run
  • 1 red flag

Still hiring?

12 checks

No red flags

How crowded?

6 checks

1 red flag

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details10 facts · Role, Location, Compensation, Company
Tech stack
  • AWS
  • Kubernetes
  • Azure
  • Linux
  • CI/CD
  • LLMs
Seniority
Staff
Industry
AI
Region
United States
Pay period
Annual
Show 5 more factsShow less

Role

Category
DevOps & Infrastructure
Seniority
Staff
Experience
4+ years
Tech stack
  • AWS
  • Kubernetes
  • Azure
  • Linux
  • CI/CD
  • LLMs

Location

Work model
Office
Region
United States
Office
  • Palo Alto, United States

Compensation

Salary
Salary by agreement
Pay period
Annual

Company

Industry
AI

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Lead IT Engineer

    Salary by agreement

    • Remote
    • Lead & Manager
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Site Reliability Engineer

    Salary by agreement

    • Remote
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason