Distinguished Engineer, End-to-End Security Architect
Own the end-to-end security architecture for a large-scale AI inference service platform, covering infrastructure, networking, APIs, operational controls, monitoring, customer assurance, and compliance readiness.
Responsibilities
- Own the end-to-end security architecture for the inference service platform
- Define security principles, threat models, trust boundaries, tenant isolation requirements, and architectural standards
- Establish security requirements for deployment environments, physical security, operational controls, access management, and asset protection
- Define platform security requirements across hardware, firmware, secure boot, attestation, software integrity, and lifecycle management
- Lead network and service isolation controls, secure communications, segmentation strategies, and administrative access protections
- Own authentication, authorisation, secrets management, encryption, key management, and data protection architecture
- Define privileged access management, audit requirements, access reviews, and emergency access procedures
- Establish logging, monitoring, telemetry, incident response, and security assurance requirements
- Partner with engineering and operations teams to implement, maintain, and validate security requirements
- Assess security posture against customer, contractual, regulatory, and internal requirements
- Support customer security reviews, audits, penetration testing, security questionnaires, and technical assurance discussions
- Provide technical leadership, architectural guidance, mentoring, and design review expertise
Requirements
- Advanced degree in a relevant technical discipline or equivalent practical experience
- Significant experience in security architecture, platform security, cloud security, infrastructure security, or large-scale service security
- Experience defining and owning security architecture for customer-facing platforms or large-scale production environments
- Deep understanding of threat modelling, zero-trust principles, tenant isolation, privileged access management, cryptographic controls, and secure operations
- Knowledge of trusted execution mechanisms, secure boot, attestation, firmware integrity, and supply-chain security
- Experience defining security requirements for data centre deployments and physical security controls
- Expertise in network security architecture, segmentation, management-plane protection, secure communications, monitoring, and access control
- Experience with key management, secrets management, certificate lifecycle management, and encryption technologies
- Experience securing APIs, deployment pipelines, service control planes, and operational tooling
- Understanding of logging, monitoring, incident response, security operations, and evidence management
- Experience supporting customer security reviews, audits, penetration testing, and executive-level security discussions
- Excellent communication, stakeholder management, and cross-functional leadership skills
Benefits
- Medical coverage
- Dental coverage
- Vision coverage
- Flexible Spending Accounts
- Health Savings Accounts
- Disability insurance
- Life insurance
- 401(k) retirement plan
- Commuter benefits
- Wellness services
- Employee Assistance Programme
- Flexible working arrangements