SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
RadixArk, an AI infrastructure company founded by veterans from xAI and NVIDIA, is seeking a Member of Technical Staff — Security to build the company's security foundation from the ground up. As the first dedicated security engineer, you will champion both internal security posture and prepare the organization for vendor audits and SOC 2 compliance.
Key responsibilities span multiple domains:
**Security Posture & Compliance:** Build and document internal security architecture, controls, and practices. Create threat models for systems handling customer data. Develop an Incident Response Plan (IRP) and Business Continuity/Disaster Recovery (BC/DR) plan. Establish vulnerability and patch management processes with clear SLAs. Prepare security documentation for vendor audits, including SOC 2 readiness.
**System Scoping & Inventory:** Define which systems and data handle customer data to determine SOC 2 audit scope. Create and maintain an inventory of infrastructure, applications, and third-party dependencies. Classify data flows and identify security boundaries between in-house and outsourced components. Document which security controls are managed internally vs. outsourced to vendors (AWS, GCP, etc.).
**Infrastructure & Application Security:** Review and improve network security including firewalls, intrusion detection/prevention (IDS/IPS), and DDoS mitigation. Audit API authentication, authorization, rate limiting, and multi-tenancy isolation. Implement secrets management and secure configuration practices. Review cloud IAM, networking, and data protection (encryption in transit and at rest). Evaluate container and supply-chain security practices.
**Security Monitoring & Operations:** Design and implement security logging and monitoring systems. Set up SIEM/SOAR tooling or evaluate and integrate centralized logging. Establish security alerting, incident response procedures, and runbooks. Conduct regular vulnerability scans and penetration tests.
**Vendor & Customer Security:** Develop security processes to answer vendor questionnaires and RFPs. Create documentation for customers on security controls, certifications, and data handling. Lead the SOC 2 audit process—coordinate with internal teams and external auditors. Stay informed on relevant compliance frameworks (SOC 2, HIPAA, Export Control, etc.).
**Team Enablement:** Enforce secure development practices to engineers. Help teams understand threat models relevant to their work. Build security into CI/CD pipelines and deployment processes.
The company is looking for someone pragmatic, autonomous, and genuinely excited about security as a core part of the business—not a checklist compliance role. You should be comfortable with ambiguity, able to prioritize ruthlessly, and willing to help across ops/finance/legal as needed (typical for founding team hires at a Series A startup).
**Requirements:**
**Core Technical Skills:**
- 4+ years working on security, infrastructure, or backend systems (or equivalent combination of hands-on experience and security training)
- Strong understanding of cloud platforms: AWS, GCP, or Azure (IAM, networking, data protection, secrets management)
- Proficiency in Linux/Unix system administration and command-line tools
- Hands-on experience with Kubernetes, container security, or infrastructure-as-code
- Solid understanding of network security, authentication/authorization protocols, and cryptography basics
- Experience conducting vulnerability assessments, penetration testing, or security audits
**Security Expertise:**
- Demonstrated experience building or improving security programs (threat modeling, security architecture, incident response)
- Knowledge of secure coding practices, OWASP Top 10, and common vulnerability types (SQLi, XSS, CSRF, etc.)
- Familiarity with security tools: vulnerability scanners, SIEM, secret management systems, IDS/IPS
- Understanding of regulatory compliance frameworks (SOC 2 is a plus; export control is a major plus)
**Preferred Experience:**
- Background in founding or early-stage startups—understanding scrappy, pragmatic security
- Experience with ML infrastructure, GPU/compute management, or high-performance systems
- Involvement in SOC 2 audits or other compliance programs
- Experience writing security policies, playbooks, and operational runbooks
- Familiarity with supply-chain security, open-source risk, or dependency management
**Education & Background:**
- Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent professional experience
- Relevant security certifications (CISSP, CISM, CEH, OSCP, etc.) are a plus but not required