MTS - Engineering (Security)
- Hiring from
- India, United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
About the role
As a Member of Technical Staff - Engineering (Security), you will own security across Collinear's infrastructure, products, and customer data. We build RL environments and training data for frontier AI labs and large enterprises. They trust us with sensitive data and access to their systems, and many of our environments run AI agents that are being trained to find and exploit vulnerabilities.
This is a senior, hands-on role. You will work alongside our researchers and engineering team to set the direction for, and implement, new security measures.
What you'll do
Harden the sandboxes where AI agents run untrusted code, including cyber tasks where agents are actively trying to break out
Own AWS security, including IAM design, least-privilege access, network boundaries, and short-lived credentials in place of long-lived keys
Build detection and response across our cloud and Kubernetes environments, and tune alerts so the team acts on them
Protect customer data from the moment it arrives to the moment we deliver, including access controls, secure delivery, and PII removal at terabyte scale
Lead customer security reviews and compliance work, from security questionnaires and supplier onboarding to SOC 2
Secure our software supply chain, including dependencies, CI/CD, secrets, and our GitHub organization
Set guardrails for engineers and coding agents that work directly against production infrastructure
Test our systems the way an attacker would, and fix what you find
About you
You have 8+ years of experience in security engineering, much of it securing cloud infrastructure in production
You have deep hands-on experience with AWS security, including IAM, CloudTrail, GuardDuty, KMS, and VPC design
You have an offensive security background, such as penetration testing, red teaming, or vulnerability research, and use it to decide what to defend first
You have isolated untrusted workloads with containers or microVMs, using tools such as gVisor, Firecracker, or Kata Containers, and know where that isolation tends to fail
You write production-quality code, ideally in Python, and prefer automation to manual process
You have built or grown a security program at a startup, and know how to prioritize when you can't fix everything at once
You explain risk clearly to engineers, leadership, and customers' security teams