SlipstreamJobsFresh Startup & VC-Backed Jobs

MTS, Technology & Security Engineering

Reflection AI - New York, NY, USA - In-office - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Reflection AI is seeking an MTS (Member of Technical Staff) for Technology & Security Engineering to architect and operate the security engineering foundation protecting the organization's corporate environment, multi-cloud research infrastructure, and GPU training capacity. You will own the full technical security stack, from end-user compute and zero-trust access to cloud and container security, detection engineering, and security-as-code. This role sits at the intersection of security engineering, infrastructure, and research operations, uniquely positioned to protect frontier AI assets—model weights, training data, and GPU capacity—while preserving the low-friction environment researchers need. Key responsibilities include: **High-Performance End User Compute (EUC):** Design and manage a resilient corporate device fleet spanning Linux, macOS, Windows, and specialized hardware (NVIDIA GPU workstations). Shift from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without sacrificing assurance. Secure diverse local toolchains and developer environments. **Securing the Research & Training Boundary:** Architect cloud-native security controls across multi-cloud environments containing multi-million-dollar GPU clusters. Establish IAM governance, network segmentation, and isolation boundaries appropriate to training infrastructure and model assets. Partner with infrastructure and research teams to ensure controls scale with GPU capacity. **Phishing-Resistant Zero-Trust Access:** Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One). Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across corporate and production planes. Eliminate standing access in favor of just-in-time, verifiable authorization. **Security as Code (SaC):** Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi). Eliminate configuration drift through automated CI/CD validation and continuous compliance checks. Build repeatable, auditable deployment pipelines. **Behavioral Detection Engineering:** Build telemetry pipelines ingesting high-fidelity logs into a cloud-native data lake. Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks. Continuously tune detection coverage against an assumed-breach threat model. **Compliance, Audit & Vendor Risk:** Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews. Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations. Own front-line defenses including physical security and data center security operations. You will operate as both an executive leader and hands-on builder, representing the organization's security posture to auditors and enterprise customers, and negotiating vendor and contractual risk. Success requires designing guardrails rather than gates, building systems that assume compromise, and operating credibly across engineering, infrastructure, legal, and physical security. **Requirements:** - 7+ years of deep engineering experience at high-valuation companies or in defense-grade environments - Battle-tested technical leadership with a track record of building and operating security engineering functions at scale - Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews - Experience leading vendor risk, procurement security reviews, and legal contract negotiations - Experience with front-line defenses for an AI company, including physical security and data center security operations - Deep familiarity with Linux and macOS internals, including securing specialized hardware (NVIDIA GPUs) without breaking developer environments - Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives - Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration - Ability to operate as both an executive leader and hands-on builder, moving fluidly between strategy and implementation - "Guardrails, not gates" philosophy—understands that blocking researchers from pulling libraries or mounting filesystems means security has failed - Adversarial mindset that designs systems assuming endpoint compromise, focusing on limiting blast radius, eliminating persistent access, and detecting post-compromise activity - Motivated by building in ambiguous, fast-moving environments where security infrastructure matures alongside a rapidly scaling research organization

Similar roles