SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Runway is hiring an Infrastructure Security Engineer to secure the platform on which frontier video models are trained and served. This is a hands-on engineering role on the Security team, focused on protecting a unique environment that combines research compute, large training datasets, fast-moving build pipelines, and AI-assisted developer tooling.
You will design and ship security controls across Runway's Kubernetes ecosystem, including admission policies, RBAC, workload identity, network policies, and runtime hardening. You'll harden the software supply chain from dependency intake through build and deploy, implementing package firewalling, artifact signing, provenance tracking, and admission controls. You'll own cloud IAM and identity architecture, implementing least-privilege roles, short-lived credentials, and workload federation.
A key part of this role is securing research infrastructure and training pipelines—controlling access to model weights and datasets without slowing down researchers. You'll threat-model new platform components before they ship, build guardrails for AI agents and developer tooling, and write infrastructure-as-code and policy-as-code with the same rigor as production changes. You'll also support the incident response team with fast answers about system behavior and remediation options.
Runway's platform is fundamentally different from typical SaaS security challenges. The environment includes GPU/HPC-style compute, research workflows, and frontier AI models, requiring security approaches tailored to this context.
REQUIREMENTS:
- Hands-on production experience securing Kubernetes: admission policies, RBAC, workload identity troubleshooting, and cluster compromise scenarios
- Working knowledge of cloud IAM and networking on at least one major cloud platform, including identity federation and short-lived credentials
- Experience with infrastructure-as-code and GitOps-style deployment, shipping security changes through standard pipelines
- Proficiency writing Python, TypeScript, Rust, or similar languages for tooling (not just scripts)
- Understanding of software supply chain attacks and controls: signing, provenance, SBOMs, admission enforcement
- Strong technical writing: design docs, threat models, and explanations for non-security engineers
- Judgment about which controls to enforce vs. recommend, and how to roll out breaking changes safely
EVEN BETTER IF YOU HAVE:
- Experience securing GPU or HPC-style compute, training pipelines, or research environments
- Experience with policy engines and admission controllers (Kyverno, OPA Gatekeeper, Falco, or similar)
- Multi-tenant isolation design in cloud environments: ABAC, scoped credentials, per-tenant boundaries
- Experience producing security architecture evidence for SOC 2, ISO 27001, or other compliance audits
- Open source contributions or published work in cloud or Kubernetes security
About Runway
AI / Data / Infrastructure; Media / Creator Economy — generative AI tools for video and creative production.