{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/mtls"},"x-facet":{"type":"skill","slug":"mtls","display":"Mtls","count":5},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_b6611499-8b7"},"title":"AI Identity Architect","description":"<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI.\\n\\nOkta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.\\n\\nThis work requires a relentless drive to solve complex challenges with real-world stakes.\\n\\nWe are looking for builders and owners who operate with speed and urgency and execute with excellence.\\n\\nThis is an opportunity to do career-defining work.\\n\\nWe&#39;re all in on this mission.\\n\\nIf you are too, let&#39;s talk.\\n\\nThe Identity Team\\n\\nThe Identity team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution through identifying and resolving risks to the employees, product, and most importantly, our customers.\\n\\nWith the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business.\\n\\nThe AI Identity Architect Opportunity\\n\\nReporting to the VP of Identity &amp; Access Management, this role will be an AI Identity Pioneer, not just an IAM expert.\\n\\nYour &quot;been there, done that&quot; experience in securing autonomous agents at scale is your superpower.\\n\\nYou’ve seen how traditional OAuth flows break under agentic pressure, you’ve felt the pain of &quot;Secret Zero&quot; in a LangChain loop, and you know exactly where the industry’s current tools fall short.\\n\\nAt Okta, you won&#39;t just implement security; you will use your battle-tested experience to drive the product features needed to secure the next generation of identities.\\n\\nThe AI Identity Architect&#39;s mission is to own Okta’s enterprise identity strategy for autonomous AI agents.\\n\\nAs Customer Zero, you will implement Okta on Okta,validating identity patterns at production scale, feeding direct input into product roadmaps, and partnering with business units building internal agentic systems.\\n\\nWhat you’ll be doing\\n\\nProduct Vision &amp; Architecture (The &quot;Ratified R0&quot;)\\n\\nDrive the Roadmap: Act as a primary stakeholder for Okta’s product teams.\\n\\nTranslate your real-world experience securing agents into prioritized feature requests and product requirements.\\n\\nTarget State: Define a multi-year roadmap for Non-Human Identities (NHIs) and AI Agents aligned with Zero Trust (NIST 800-207) and Okta’s Secure Identity Commitment.\\n\\nPosture First: Use ISPM (Identity Security Posture Management) to discover unmanaged AI agents and eliminate &quot;Identity Debt&quot; across the enterprise.\\n\\nCross-App Access &amp; Brokered Delegation\\n\\nAgent-to-App Connectivity: Architect secure Cross-App Access patterns where agents act as intermediaries between enterprise systems.\\n\\nDelegated Authority: Refine how user identity is &quot;brokered&quot; to an agent (e.g. OAuth2 Token Exchange), ensuring the agent never has more power than the human user who triggered it.\\n\\nSession Scoping: Implement context-bound, short-lived tokens to prevent lateral movement by a compromised agent.\\n\\nOkta Customer Zero -- Validate and publish patterns using Okta primitives to secure the AI lifecycle for:\\n\\nOkta Identity Engine &amp; Auth0: Define how AI agents prove their identity within AuthN/AuthZ core concepts, implementing rigorous protocols for secure access delegation like OAuth2/OIDC, mTLS, and SPIFFE/SPIRE for workload attestation.\\n\\nOkta Privilege Access: Implement JIT/JEA access and ephemeral, vaulted secrets for agent tool-use.\\n\\nOkta Identity Governance &amp; Workflows: Automate the Joiner-Mover-Leaver (JML) lifecycle for agents, including automated certification and revocation.\\n\\nFine-Grained Authorization: Implement ReBAC for intent-bound decisions (e.g., &quot;Can this agent access the Finance API on behalf of the CFO?&quot;).\\n\\nServe as &quot;Customer Zero&quot; by architecting and stress-testing internal AI security frameworks, translating real-world deployment lessons into a continuous stream of public-facing white papers, blogs, and technical guides to steer industry best practices.\\n\\nAI Ecosystem &amp; Tech Stack Integration\\n\\nDefine how Okta identity is woven into modern AI orchestration layers:\\n\\nOrchestration: Secure identity patterns such as LangChain, LangGraph, AutoGPT, CrewAI, LlamaIndex, and Semantic Kernel.\\n\\nArchitect secure connectivity to AI model providers such as Azure OpenAI, AWS Bedrock, Google Vertex AI, OpenAI API, and Anthropic.\\n\\nWhat you’ll bring to the role\\n\\nThe &quot;Been There&quot; Factor: Proven track record of securing AI agents and non-human identities in a production environment.\\n\\nExperience: 7+ years in IAM/Security Architecture; proven strategy work across workforce, customer, and Non-Human Identities (NHIs).\\n\\nDeep knowledge of the core protocols OAuth2/OIDC (especially Token Exchange), SAML, mTLS, JWT, and Model Context Protocol (MCP).\\n\\nHands-on experience with Modern Identity framework SPIFFE/SPIRE.\\n\\nAbility to author Architecture Decision Records (ADR) and influence at the VP/CTO level, while simultaneously acting as a peer to Product Management.\\n\\nAnd extra credit if you have experience in any of the following!\\n\\nPrior work shaping identity strategy for autonomous/agent systems, multi-agent delegation, or brokered access patterns.\\n\\nExposure to policy-as-code (OPA/Cedar) and service-mesh identity.\\n\\nCertifications such as CISSP-ISSAP, CCSP, or TOGAF are welcome but not required or expected.\\n\\n#LI-SM1 #LI-Hybrid P21621_3398002</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_b6611499-8b7","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7749222","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$242,000-$332,000 USD","x-skills-required":["OAuth2/OIDC","SAML","mTLS","JWT","Model Context Protocol (MCP)","SPIFFE/SPIRE","Architecture Decision Records (ADR)","Policy-as-code (OPA/Cedar)","Service-mesh identity"],"x-skills-preferred":["LangChain","LangGraph","AutoGPT","CrewAI","LlamaIndex","Semantic Kernel","Azure OpenAI","AWS Bedrock","Google Vertex AI","OpenAI API","Anthropic"],"datePosted":"2026-04-18T15:57:24.671Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, California"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"OAuth2/OIDC, SAML, mTLS, JWT, Model Context Protocol (MCP), SPIFFE/SPIRE, Architecture Decision Records (ADR), Policy-as-code (OPA/Cedar), Service-mesh identity, LangChain, LangGraph, AutoGPT, CrewAI, LlamaIndex, Semantic Kernel, Azure OpenAI, AWS Bedrock, Google Vertex AI, OpenAI API, Anthropic","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":242000,"maxValue":332000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_5f7c499a-533"},"title":"Senior Software Engineer, Security","description":"<p>As a Senior Software Engineer in the Security organization at CoreWeave, you will design, build and deploy services, platforms and tools that help provide common foundational capabilities that various security programs and initiatives rely on to keep CoreWeave secure.</p>\n<p>Automation to eliminate manual steps involved in understanding security risks, remediating and preventing them would be the charter. The work sits at the intersection of engineering systems and regulatory requirements, translating requirements into scalable, reliable, production grade infrastructure. Often this means building production infrastructure from scratch in many cases, and would need end to end ownership of systems including design, development, testing and deployment including implementing effective integration pipelines (CI/CD) and offering a reliable production system that should be highly available and function at scale.</p>\n<p>You will partner closely with various security teams including GRC, platform engineering, and security domain teams to translate business needs into durable technical needs, while retaining full engineering ownership of how those systems are designed, built, and operated.</p>\n<p>In this role, you will:</p>\n<ul>\n<li>Design and build scalable systems.</li>\n<li>Develop control integrations and data pipelines to normalize security telemetry across IAM, logs, scanners, and CCM/GRC tools.</li>\n<li>Build metrics engines, dashboards, and insights pipelines that provide real-time visibility into compliance health and emerging risks.</li>\n</ul>\n<p>On this team, you will:</p>\n<ul>\n<li>Tackle security &amp; compliance puzzles at cutting-edge scale and complexity</li>\n<li>Collaborate with brilliant engineers who are redefining compliance adherence for cloud infrastructure.</li>\n<li>You&#39;ll have the freedom and responsibility to innovate, experiment, and influence how we establish assurance pipelines.</li>\n</ul>\n<p>Investing in our people is one of our top priorities, and we value candidates who can bring their diversified experiences to our teams. Here are some qualities we’ve found compatible with our team. We&#39;d love to talk about whether this aligns with your experience and interests and what you’re excited to work on next.</p>\n<p>Who You Are:</p>\n<p>Minimum Qualifications</p>\n<ul>\n<li>A Bachelor’s degree in Information Security, Computer Science, or a related field or equivalent job experience.</li>\n<li>At least 7+ years of hands-on experience in programming languages like Go.</li>\n<li>At least 3+ years of hands-on experience deploying and managing Kubernetes clusters in a production environment.</li>\n<li>Experience building high qps and critical distributed systems.</li>\n<li>Familiarity with modern CI/CD practices and Infrastructure-as-Code tooling.</li>\n<li>Proven experience building and deploying containerized applications.</li>\n<li>Strong experience with technical architectures involving data flows, event driven architecture, access controls, retention, and third-party integrations.</li>\n<li>Strong hands-on experience with cloud infrastructure (AWS, GCP).</li>\n</ul>\n<p>Preferred:</p>\n<ul>\n<li>Information Security Engineering experience.</li>\n<li>Expertise in major compliance and security frameworks (SOC 2, ISO 27001, PCI DSS, HIPAA, FedRAMP, NIST, CSF).</li>\n<li>Background in building automation for distributed cloud environments at scale.</li>\n<li>Experience with remote-access solutions like Teleport (real bonus points if you’ve submitted PRs on their product).</li>\n<li>Understanding of the SSO protocols, specifically OIDC and SAML.</li>\n<li>Hands-on experience with PKI and mTLS.</li>\n</ul>\n<p>If you&#39;re eager to elevate compliance into a creative, strategic force within a fast-paced, forward-thinking company, we&#39;d love to hear from you!</p>\n<p>The base salary range for this role is $165,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility).</p>\n<p>What We Offer</p>\n<p>The range we’ve posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs, including:</p>\n<ul>\n<li>Medical, dental, and vision insurance</li>\n<li>100% paid for by CoreWeave</li>\n<li>Company-paid Life Insurance</li>\n<li>Voluntary supplemental life insurance</li>\n<li>Short and long-term disability insurance</li>\n<li>Flexible Spending Account</li>\n<li>Health Savings Account</li>\n<li>Tuition Reimbursement</li>\n<li>Ability to Participate in Employee Stock Purchase Program (ESPP)</li>\n<li>Mental Wellness Benefits through Spring Health</li>\n<li>Family-Forming support provided by Carrot</li>\n<li>Paid Parental Leave</li>\n<li>Flexible, full-service childcare support with Kinside</li>\n<li>401(k) with a generous employer match</li>\n<li>Flexible PTO</li>\n<li>Catered lunch each day in our office and data center locations</li>\n<li>A casual work environment</li>\n<li>A work culture focused on innovative disruption</li>\n</ul>\n<p>Our Workplace</p>\n<p>While we prioritize a hybrid work environment, remote work may be considered for candidates located more than 30 miles from an office, based on role requirements for specialized skill sets. New hires will be invited to attend onboarding at one of our hubs within their first month. Teams also gather quarterly to support collaboration.</p>\n<p>California Consumer Privacy Act - California applicants only</p>\n<p>CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA), CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: careers@coreweave.com.</p>\n<p>Export Control Compliance</p>\n<p>This position requires access to export controlled information. To conform to U.S. Government export regulations applicable to that information, applicant must either be (A) a U.S. person, defined as a (i) U.S. citizen or national, (ii) U.S. lawful permanent resident (green card holder), (iii) refugee under 8 U.S.C. § 1157, or (iv) asylee under 8 U.S.C. § 1158, (B) eligible to access the export controlled information without a required export authorization, or (C) eligible and reasonably likely to obtain the required export authorization from the applicable U.S. government agency. CoreWeave may, for legitimate business reasons, decline to pursue any export licensing process.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_5f7c499a-533","directApply":true,"hiringOrganization":{"@type":"Organization","name":"CoreWeave","sameAs":"https://www.coreweave.com","logo":"https://logos.yubhub.co/coreweave.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/coreweave/jobs/4651859006","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$165,000 to $242,000","x-skills-required":["Go","Kubernetes","Cloud infrastructure","CI/CD practices","Infrastructure-as-Code tooling","Containerized applications","Technical architectures","Data flows","Event driven architecture","Access controls","Retention","Third-party integrations"],"x-skills-preferred":["Information Security Engineering","Compliance and security frameworks","Automation for distributed cloud environments","Remote-access solutions","SSO protocols","PKI and mTLS"],"datePosted":"2026-04-18T15:45:57.955Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Sunnyvale, CA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Go, Kubernetes, Cloud infrastructure, CI/CD practices, Infrastructure-as-Code tooling, Containerized applications, Technical architectures, Data flows, Event driven architecture, Access controls, Retention, Third-party integrations, Information Security Engineering, Compliance and security frameworks, Automation for distributed cloud environments, Remote-access solutions, SSO protocols, PKI and mTLS","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":165000,"maxValue":242000,"unitText":"YEAR"}}},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_ecbc33c4-890"},"title":"Director - Platform Engineering Lead - Aladdin","description":"<p><strong>About this role  Are you interested in building innovative technology that shapes the financial markets? Do you like working at the speed of a startup, but want to tackle some of the world&#39;s most sophisticated problems? Do you want to work with, and learn from, hands-on leaders in technology and finance?  At BlackRock, we are looking for an engineering team lead who loves to innovate and tackle sophisticated problems. We recognize that strength comes from diversity, and we will embrace your unique skills, curiosity, and passion while giving you the opportunity to grow technically and as an individual.  ### About the team  Our Platform Engineering division is at the forefront, crafting the foundation for Aladdin, an operating system crafted for investment managers. This system integrates real-time management of information, people, and technology, and is utilized by numerous financial institutions both internally and externally.  ### As the Engineering Lead you will:  - Provide strategic leadership to build a high-performance engineering team. You will grow technology leaders and connect the team to Aladdin Engineering&#39;s mission and outcomes. You will nurture engineering culture and ultimately drive execution. - Grow your technical knowledge and leadership skills to become one of the most productive technology teams at BlackRock; be an encouraging leader across the entire engineering organization - Work in partnership with our product managers, users/client base, and engineering teams to implement a product and technical roadmap. - Be an encouraging leader across the engineering organization to evangelize leading engineering practices, efficiency, and tooling. - Become a guide in the BlackRock user/provider model and develop technical expertise of the Aladdin platform; provide engineering best practices leadership across the team. - Take ownership of the technical vision and execution for our API and Identity Infrastructure, directly impacting the security, scalability, and extensibility of the Aladdin platform. - Drive significant improvements in the reliability, performance, and security of our authentication systems and API ecosystem.  ### What you&#39;ll need:  - Minimum of 5+ years of experience leading and managing engineering teams, coupled with 10+ years of overall technical experience in Financial Services or Technology. - Proven expertise in designing, developing, and deploying scalable and resilient systems using Java and GoLang, with a strong understanding of asynchronous processing and distributed architectures. Demonstrated ability to dive deep into code and troubleshoot complex technical issues. - Experience with Python for scripting and automation, and familiarity with modern front-end frameworks like Angular for full-stack understanding. - In-depth experience in building full stack applications from front-end to back-end. - Several years&#39; worth of experience in running Agile teams and can show your passion to improve yourself and your squads - Successful deliveries of technology-focused products through the entire product development lifecycle. - Showcase high-level designs &amp; blueprints along with the business value that these have achieved in your experience - Deep experience taking technical designs and translating them into measurable stories for your squad. - Demonstrated deep understanding and practical experience with a diverse range of authentication and authorization mechanisms, including but not limited to: OAuth 2.0/OpenID Connect, Basic Authentication, Certificate-Based Authentication, Mutual TLS (mTLS), and Transport Layer Security (TLS/SSL). - Experience designing and implementing secure APIs and microservices. - Strong understanding of security principles and best practices. - Experience with gRPC, including defining service contracts using Protocol Buffers and implementing gRPC clients and servers. - Hands-on experience in configuring, managing, and integrating with enterprise-grade Identity Providers such as Keycloak, Okta, or Azure AD. - Familiarity with SAML, JWT, and PKI infrastructure. - Goal setting, in alignment with Business, Technology, and BlackRock goals  ### Who you are:  - A passionate advocate for modern engineering practices, with a proven ability to influence and drive adoption of these practices across the organization. - Exceptional communication and interpersonal skills, with the ability to build consensus and influence decision-making at all levels. - Excited to learn about new technologies and strive to reach new levels of efficiencies in the platform we provide. - While providing leadership, remain hands-on with critical technical challenges, architecturereviews, and proof-of-concepts to guide the team and ensure technical excellence. - Participate in code reviews and contribute to key architectural decisions, setting a high standard for code quality and engineering practices.  ### Our benefits  To help you stay energized, engaged, and inspired, we offer a wide range of employee benefits including: retirement investment and tools designed to help you in building a sound financial future; access to education reimbursement; comprehensive resources to support your physical health and emotional well-being; family support programs; and Flexible Time Off (FTO) so you can relax, recharge, and be there for the people you care about.  ### Our hybrid work model  BlackRock&#39;s hybrid work model is designed to enable a culture of collaboration and apprenticeship that enriches the experience of our employees, while supporting flexibility for all. Employees are currently required to work at least 4 days in the office per week, with the flexibility to work from home 1 day a week. Some business groups may require more time in the office due to their roles and responsibilities. We remain focused on increasing the impactful moments that arise when we work together in person – aligned with our commitment to performance and innovation. As a new joiner, you can count on this hybrid model to accelerate your learning and onboarding experience here at BlackRock.  ### About BlackRock  At BlackRock, we are all connected by one mission: to help more and more people experience financial well-being. Our clients, and the people they serve, are saving for retirement, paying for their children&#39;s educations, buying homes and starting businesses. Their investments also help to strengthen the global economy: support businesses small and large; finance infrastructure projects that connect and power cities; and facilitate innovations that drive progress.  This mission would not be possible without our smartest investment – the one we make in our employees. It&#39;s why we&#39;re dedicated to creating an environment where our colleagues feel welcomed, valued, and supported with networks, benefits, and development opportunities to help them thrive.  For additional information on BlackRock, please visit @blackrock \\| Twitter: @blackrock \\| :</strong></p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_ecbc33c4-890","directApply":true,"hiringOrganization":{"@type":"Organization","name":"BlackRock","sameAs":"https://jobs.workable.com","logo":"https://logos.yubhub.co/view.com.png"},"x-apply-url":"https://jobs.workable.com/view/59HbTfvG4stK4et565FKAE/director---platform-engineering-lead---aladdin-in-edinburgh-at-blackrock","x-work-arrangement":"hybrid","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Java","GoLang","Python","Angular","gRPC","Protocol Buffers","OAuth 2.0/OpenID Connect","Basic Authentication","Certificate-Based Authentication","Mutual TLS (mTLS)","Transport Layer Security (TLS/SSL)","SAML","JWT","PKI infrastructure"],"x-skills-preferred":[],"datePosted":"2026-03-09T16:41:21.100Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Edinburgh, Scotland"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Finance","skills":"Java, GoLang, Python, Angular, gRPC, Protocol Buffers, OAuth 2.0/OpenID Connect, Basic Authentication, Certificate-Based Authentication, Mutual TLS (mTLS), Transport Layer Security (TLS/SSL), SAML, JWT, PKI infrastructure"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_41528416-21c"},"title":"Staff+ Software Security Engineer","description":"<p><strong>About Anthropic</strong></p>\n<p>Anthropic&#39;s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems.</p>\n<p><strong>About the Team</strong></p>\n<p>The Security Engineering team protects Anthropic&#39;s AI systems and maintains the trust of our users and society. We define the authentication architecture for our training infrastructure, design the cryptographic foundations that protect model weights and training data, and drive the developer security program that shapes how engineers build and ship software.</p>\n<p><strong>About the role:</strong></p>\n<ul>\n<li>Scope, design, and build complex security systems end to end, maintaining them through production and driving through ambiguous technical challenges with minimal oversight</li>\n<li>Identify systematic risks through threat modeling and risk assessment, then build the controls and infrastructure that address them</li>\n<li>Mentor engineers across the security team and broader engineering organisation, contribute to hiring, and grow security engineering culture at Anthropic</li>\n<li>Enable other teams to build their own security solutions by providing design pattern guidance and expanding security ownership beyond the security team</li>\n</ul>\n<p><strong>Developer security and supply chain</strong></p>\n<ul>\n<li>Build and advance our developer security program by embedding security practices into the software development lifecycle and developer workflows</li>\n<li>Harden CI/CD pipelines against supply chain attacks through isolated build environments, signed attestations, dependency verification, and automated policy enforcement</li>\n</ul>\n<p><strong>Identity and secrets management</strong></p>\n<ul>\n<li>Architect systems that protect sensitive assets including model weights, customer data, and training datasets</li>\n<li>Build and operate credential issuance, rotation, and workload authentication across our multi-cloud environments</li>\n</ul>\n<p><strong>Infrastructure security</strong></p>\n<ul>\n<li>Implement and maintain cloud security controls including IAM, network segmentation, VPC architecture, and encryption across our multi-cloud and on-prem environments</li>\n<li>Contribute to cluster security controls including RBAC policies, namespace isolation, workload identity, and pod security</li>\n<li>Contribute to continuous cloud security posture management using infrastructure-as-code scanning, misconfiguration detection, and automated remediation</li>\n</ul>\n<p><strong>Secure frameworks</strong></p>\n<ul>\n<li>Build critical security foundations including cryptographic frameworks, mTLS infrastructure, secure serialization, and authorization systems, designed to prevent entire classes of vulnerabilities and empower engineering teams to work securely without becoming security experts themselves</li>\n<li>Partner with product, research, infrastructure, and other security teams to ensure frameworks integrate smoothly with lower-layer security controls</li>\n</ul>\n<p><strong>You may be a good fit if you have:</strong></p>\n<ul>\n<li>At least 8 years of software engineering experience with deep security expertise, including leading complex security initiatives independently</li>\n<li>Bachelor&#39;s degree in Computer Science or equivalent industry experience</li>\n<li>Strong programming skills in Python or at least one systems language such as Go, Rust, or C/C++</li>\n<li>Deep understanding of identity systems, cryptographic primitives, and secrets management</li>\n<li>Working knowledge of Kubernetes security primitives including RBAC, namespaces, network policies, and service accounts</li>\n<li>Experience leading cross-functional security initiatives and navigating complex organisational dynamics</li>\n<li>Outstanding communication skills, translating technical concepts effectively across all levels of the organisation</li>\n<li>A track record of bringing clarity and ownership to ambiguous technical problems and driving them to resolution</li>\n<li>Low ego and high empathy, with a history of growing the engineers around you and supporting diverse, inclusive teams</li>\n<li>Passion for AI safety and the role security engineering plays in building trustworthy AI systems</li>\n</ul>\n<p><strong>Strong candidates may also have:</strong></p>\n<ul>\n<li>Designed or operated identity and secrets management systems for large-scale AI or cloud infrastructure</li>\n<li>Built security frameworks or libraries adopted across an engineering organisation</li>\n<li>Led a developer security program including supply chain security, secure build infrastructure, and SDLC integrations</li>\n<li>Built or secured CI infrastructure using Nix, Bazel, or Kubernetes-based deploy systems, with depth in toolchain issues, CI/CD pipelines, and developer workflow optimisation</li>\n<li>Implemented machine identity or workload authentication systems using SPIFFE/SPIRE, mTLS, or equivalent</li>\n<li>Understanding of Linux systems internals including namespaces, cgroups, and seccomp, and how these underpin container and workload isolation</li>\n<li>Contributed to the security architecture of multi-cloud environments including network segmentation, data protection, and access governance</li>\n<li>Experience with network security controls including admission controllers, CNI-level policy, service mesh security, and east-west traffic enforcement</li>\n<li>Experience building runtime security monitoring using eBPF or kernel security policies</li>\n</ul>\n<p><strong>Deadline to apply:</strong></p>\n<p>None, applications will be received on a rolling basis.</p>\n<p><strong>The annual compensation range for this role is listed below.</strong></p>\n<p>For sales roles, the range provided is the role’s On Target Earnings (&quot;OTE&quot;) range, meaning the total amount of money an employee is expected to earn in a year, including bonuses and other forms of compensation.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_41528416-21c","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Anthropic","sameAs":"https://job-boards.greenhouse.io","logo":"https://logos.yubhub.co/anthropic.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/anthropic/jobs/5120512008","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"The annual compensation range for this role is listed below.\n\nFor sales roles, the range provided is the role’s On Target Earnings (\"OTE\") range, meaning the total amount of money an employee is expected to earn in a year, including bonuses and other forms of compensation.","x-skills-required":["Python","Go","Rust","C/C++","Kubernetes","RBAC","namespaces","network policies","service accounts","identity systems","cryptographic primitives","secrets management"],"x-skills-preferred":["Nix","Bazel","Kubernetes-based deploy systems","SPIFFE/SPIRE","mTLS","Linux systems internals","namespaces","cgroups","seccomp","container and workload isolation","multi-cloud environments","network segmentation","data protection","access governance","admission controllers","CNI-level policy","service mesh security","east-west traffic enforcement","runtime security monitoring","eBPF","kernel security policies"],"datePosted":"2026-03-08T13:52:38.657Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"San Francisco, CA | New York City, NY | Seattle, WA"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Go, Rust, C/C++, Kubernetes, RBAC, namespaces, network policies, service accounts, identity systems, cryptographic primitives, secrets management, Nix, Bazel, Kubernetes-based deploy systems, SPIFFE/SPIRE, mTLS, Linux systems internals, namespaces, cgroups, seccomp, container and workload isolation, multi-cloud environments, network segmentation, data protection, access governance, admission controllers, CNI-level policy, service mesh security, east-west traffic enforcement, runtime security monitoring, eBPF, kernel security policies"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_14dd5de2-4dc"},"title":"Software Engineer, Infrastructure Security","description":"<p><strong>Software Engineer, Infrastructure Security</strong></p>\n<p><strong>Location</strong></p>\n<p>Remote - US; New York City; San Francisco; Seattle</p>\n<p><strong>Employment Type</strong></p>\n<p>Full time</p>\n<p><strong>Location Type</strong></p>\n<p>Remote</p>\n<p><strong>Department</strong></p>\n<p>Security</p>\n<p><strong>Compensation</strong></p>\n<ul>\n<li>SF, Seattle or NYC $230K – $385K • Offers Equity</li>\n<li>Zone A $207K – $346.5K • Offers Equity</li>\n<li>Zone B $184K – $308K • Offers Equity</li>\n</ul>\n<p>The base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. If the role is non-exempt, overtime pay will be provided consistent with applicable laws. In addition to the salary range listed above, total compensation also includes generous equity, performance-related bonus(es) for eligible employees, and the following benefits.</p>\n<p><strong>Benefits</strong></p>\n<ul>\n<li>Medical, dental, and vision insurance for you and your family, with employer contributions to Health Savings Accounts</li>\n<li>Pre-tax accounts for Health FSA, Dependent Care FSA, and commuter expenses (parking and transit)</li>\n<li>401(k) retirement plan with employer match</li>\n<li>Paid parental leave (up to 24 weeks for birth parents and 20 weeks for non-birthing parents), plus paid medical and caregiver leave (up to 8 weeks)</li>\n<li>Paid time off: flexible PTO for exempt employees and up to 15 days annually for non-exempt employees</li>\n<li>13+ paid company holidays, and multiple paid coordinated company office closures throughout the year for focus and recharge, plus paid sick or safe time (1 hour per 30 hours worked, or more, as required by applicable state or local law)</li>\n<li>Mental health and wellness support</li>\n<li>Employer-paid basic life and disability coverage</li>\n<li>Annual learning and development stipend to fuel your professional growth</li>\n<li>Daily meals in our offices, and meal delivery credits as eligible</li>\n<li>Relocation support for eligible employees</li>\n<li>Additional taxable fringe benefits, such as charitable donation matching and wellness stipends, may also be provided.</li>\n</ul>\n<p><strong>About the Team</strong></p>\n<p>Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity.</p>\n<p>The Security team protects OpenAI’s technology, people, and products. We are technical in what we build but operational in how we execute, and we support every product and research effort at OpenAI. Our tenets include prioritizing for impact, enabling researchers and developers, preparing for future transformative technologies, and fostering a strong, collaborative security culture.</p>\n<p><strong>About the Role</strong></p>\n<p>OpenAI is seeking a Security Software Engineer to join the Infrastructure Security (InfraSec) team.</p>\n<p>InfraSec safeguards the core of OpenAI’s research and production environments—GPU supercomputing clusters, multi-cloud infrastructure, datacenters, networking, storage, and the critical services that power our frontier AI models. Our charter spans everything from bare-metal hardware and firmware to Kubernetes clusters, service meshes, and the data pathways that carry highly sensitive model weights and user data.</p>\n<p>As a Security Software Engineer, you will design and build critical foundational services, such as authentication systems, egress/ingress proxies, access brokers, and key management platforms, that demand high standards of reliability, scalability, and software craftsmanship. These systems form the security backbone of OpenAI’s supercomputing environment and must remain robust under intense scale and adversarial pressure.</p>\n<p><strong>In this role, you will:</strong></p>\n<ul>\n<li>Architect and implement production-grade security services (e.g., auth services, access brokers, secure proxies, key-management infrastructure) that provide strong guarantees across hardware, operating systems, Kubernetes, networks, and CI/CD.</li>\n<li>Partner with infrastructure and research engineers to embed security into high-performance compute clusters, enabling rapid model training and deployment without compromising protection.</li>\n<li>Develop automation and detection tooling to continuously identify and mitigate risks in large-scale cloud and on-prem environments.</li>\n<li>Drive high-impact initiatives such as line-speed encryption, machine identity, and network isolation, continuously raising the security bar for emerging AI workloads.</li>\n<li>Lead or participate in design reviews and threat models to ensure new systems launch with strong security foundations and operational excellence.</li>\n</ul>\n<p><strong>You will thrive in this role if you have:</strong></p>\n<ul>\n<li>Strong software engineering skills in languages such as Python, Go, Rust, or C/C++, with a track record of shipping and operating high-reliability distributed services.</li>\n<li>Experience building or operating critical security infrastructure (e.g., auth services, service-to-service proxies, certificate or key-management systems).</li>\n<li>Deep understanding of security principles, best practices, and common vulnerabilities.</li>\n<li>Expertise in securing large-scale cloud platforms (e.g., Azure, AWS, GCP), including multi-cloud networks and cloud-agnostic system design.</li>\n<li>Familiarity with container and orchestration security (Kubernetes, service meshes) and modern authentication/authorization standards (OIDC, mTLS, SPIFFE/SPIRE).</li>\n<li>A proactive mindset, with the ability to identify and address security gaps or inefficiencies through automation and tooling.</li>\n<li>A track record of delivering scalable solutions and driving impactful changes across infrastructure in real-world projects.</li>\n<li>Strong analytical and problem-solving skills, with an ability to think critically and objectively assess security risks.</li>\n<li>Excellent communication skills, with the ability to convey complex security concepts to technical and non-technical stakeholders.</li>\n<li>Excitement about collaborating</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_14dd5de2-4dc","directApply":true,"hiringOrganization":{"@type":"Organization","name":"OpenAI","sameAs":"https://jobs.ashbyhq.com","logo":"https://logos.yubhub.co/openai.com.png"},"x-apply-url":"https://jobs.ashbyhq.com/openai/98ad9beb-4f91-496c-bd16-ac0b2a8d5bb2","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":"$230K – $385K","x-skills-required":["Python","Go","Rust","C/C++","Kubernetes","Service meshes","OIDC","mTLS","SPIFFE/SPIRE","Cloud security","Container security","Orchestration security","Authentication","Authorization","Security principles","Best practices","Common vulnerabilities"],"x-skills-preferred":["Cloud platforms","Multi-cloud networks","Cloud-agnostic system design","Automation","Detection tooling","Line-speed encryption","Machine identity","Network isolation"],"datePosted":"2026-03-06T18:29:27.261Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote - US; New York City; San Francisco; Seattle"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Python, Go, Rust, C/C++, Kubernetes, Service meshes, OIDC, mTLS, SPIFFE/SPIRE, Cloud security, Container security, Orchestration security, Authentication, Authorization, Security principles, Best practices, Common vulnerabilities, Cloud platforms, Multi-cloud networks, Cloud-agnostic system design, Automation, Detection tooling, Line-speed encryption, Machine identity, Network isolation","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":230000,"maxValue":385000,"unitText":"YEAR"}}}]}