SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Fireworks is a Series D AI platform company (valued at $17.5B) backed by NVIDIA, Sequoia, Benchmark, and others, enabling enterprises to build, train, and serve specialized AI models tailored to their data and workflows.
As a Security Engineer (MTS level), you will design and operate security controls across Fireworks' AI infrastructure, platforms, and internal systems. This is a hands-on technical role focused on embedding security throughout the technology stack—from cloud-native architectures to AI model serving.
Key responsibilities include:
- Design and build security-focused software and platform capabilities (encryption, IAM, secure API gateways, model sandboxing) protecting customer data and models across multi-cloud infrastructure
- Perform security reviews of cloud-native architectures (Kubernetes, distributed data stores) and build continuous monitoring, anomaly detection, and automated response systems
- Embed security into CI/CD pipelines using DevSecOps practices (automated scanning, policy enforcement, secure-by-default workflows)
- Apply a build-over-buy philosophy, developing in-house security tooling where it provides better control and integration
- Build and operate a comprehensive vulnerability management program across applications, containers, cloud infrastructure, and dependencies
- Operate security operations including detection engineering, alert triage, incident response, and post-incident analysis
- Participate in red/blue team exercises and tabletop simulations to strengthen security resilience
- Embed compliance and regulatory controls (SOC 2, ISO 27001, ISO 42001, HIPAA, PCI-DSS, GDPR) into infrastructure and product layers
Required qualifications:
- 3–7 years of software or security engineering experience with focus on security, infrastructure, or cloud-native systems
- Proficiency in Python and/or Go for production-grade systems
- Strong understanding of cloud-native architectures on GCP (network segregation, authentication, authorization, encryption, intrusion detection)
- Hands-on experience with Kubernetes, Docker, and containerized production environments
- Familiarity with security tooling in managed CI/CD environments (GitHub Actions, Harness, CircleCI)
- Solid Linux system administration, debugging, and command-line automation experience
- Familiarity with modern identity and access controls (SAML, OAuth, OIDC, SSO, RBAC/ABAC)
Preferred qualifications include experience with zero-trust architectures, multi-cloud deployments, large-scale Kubernetes platforms, infrastructure-as-code (Terraform), data protection techniques, microservice security, LLM/ML platform security, detection engineering, IAM/PAM platforms, container supply chain security, and compliance tooling.