SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 200,000 - 400,000 / annual
Inferact, founded by the creators and core maintainers of vLLM, is building the world's AI inference engine. The company sits at the intersection of models and hardware, working to accelerate AI progress by making inference cheaper and faster.
You will own Inferact's side of vLLM's vulnerability-management process, ensuring a critical piece of AI infrastructure remains secure and production-grade. This is a hands-on product security role combining technical investigation, sound judgment, and ownership of follow-through.
Key responsibilities:
- Develop deep understanding of vLLM's architecture and independently investigate vulnerability reports
- Turn technical findings into clear, actionable work for the core team
- Collaborate with vLLM maintainers, Red Hat counterparts, security firms, and researchers working with frontier AI models
- Drive reports from initial triage through analysis and resolution
- Coordinate fixes, security advisories, and releases under the project's established process
- Identify practical security best practices that strengthen vLLM as it evolves
- Read source code, debug unfamiliar systems, and reproduce reported issues
- Explain root cause and practical security impact of vulnerabilities
- Assess risk and prioritize work with sound judgment
- Document evidence, affected behavior, remediation needs, and next steps
- Communicate clearly and discretely with engineers, researchers, and external security collaborators
You'll work primarily in open source, collaborating across a distributed team of maintainers and security partners.
REQUIREMENTS:
Minimum qualifications:
- Hands-on product security experience with strong orientation toward infrastructure software and security of complex software systems
- Ability to read source code, debug unfamiliar systems, reproduce reported issues, and explain root cause and practical security impact
- Strong systems reasoning, including understanding of architecture, trust boundaries, deployment assumptions, and software component interactions
- Ability to learn vLLM's core architecture and independently manage vulnerability investigations while bringing in maintainers where needed
- Sound prioritization and risk-assessment judgment with clear documentation of evidence, affected behavior, remediation needs, and next steps
- Strong written and verbal communication, discretion with sensitive reports, and ability to work constructively with engineers, researchers, and external security collaborators
Preferred qualifications:
- Experience with vulnerability management and security best practices for open-source infrastructure software
- Experience coordinating vulnerability resolution across reporters, maintainers, security teams, and software releases
- Familiarity with vLLM, inference engines, ML infrastructure, or similarly complex distributed software; prior vLLM contributions helpful but not required
- Experience preparing security advisories, assessing affected versions, and working with CVE and coordinated-disclosure workflows
- Experience translating security findings into practical architecture reviews, regression tests, secure development practices, or deployment guidance
Bonus:
- Helped resolve vulnerabilities in an open-source infrastructure project and can explain technical contribution and coordination with maintainers
- Built security tooling or automation that improved investigation quality or reduced repetitive triage work
- Turned recurring vulnerability patterns into maintainable fixes, tests, or documentation that helped prevent similar issues