Infrastructure Security Engineer at Runway | Torre

Infrastructure Security Engineer

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Full-time

Legal agreement: Employment

Provide your expected compensation while applying
location_on
Remote (for United States residents)
Shared by
Emma of Torre.ai
about 12 hours ago

Responsibilities


We are building AI to simulate the world through merging art and science. We believe that world models are at the frontier of progress in artificial intelligence. Language models alone won't solve the world's hardest problems – robotics, disease, scientific discovery. Real progress requires models that experience the world and learn from their mistakes, the same way that humans do. And this kind of trial and error can be massively accelerated when done in simulation, rather than in the real world.About the roleOpen to hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.Runway is hiring an Infrastructure Security Engineer to secure the platform our models are trained and served on. The role covers Kubernetes platform security, cloud identity and access, software supply chain, tenant isolation in the serving layer and the research infrastructure behind our models.Securing a company that trains and serves frontier video models is a different problem from securing a typical SaaS product. The environment includes research compute, large training datasets, a fast-moving build pipeline, and engineers who work inside AI-assisted tooling every day. Each of those changes what an attack looks like and what the platform has to enforce to stop it.This is a hands-on engineering role on the Security team. You'll write policy, tooling and infrastructure code, work in the platform team's repositories, and ship controls that hold up in production.What you'll doDesign and ship security controls in our Kubernetes ecosystem: admission policy, RBAC, workload identity, network policy and runtime hardening across every cluster we runHarden the software supply chain from dependency intake through build and deploy, including package firewalling, artifact signing and provenance, and admission controls that block what doesn't passOwn cloud IAM and identity architecture: least-privilege roles, short-lived credentials and workload federationSecure research infrastructure and training pipelines, including access to model weights and datasets, without slowing down the people using themThreat model new platform components before they ship and turn the findings into concrete requirements the owning team can act onBuild guardrails for AI agents and developer tooling operating inside our infrastructureWrite infrastructure as code and policy as code, and treat security configuration with the same review and rollout discipline as any other changeGive the incident response team what they need when infrastructure is involved: fast answers about how a system works and what to shut offWhat you'll needHands-on experience securing Kubernetes in production: you've written admission policies, debugged RBAC and workload identity problems and understand how a cluster gets compromisedWorking knowledge of cloud IAM and networking on at least one major cloud platform, including how identity federation and short-lived credentials actually workExperience with infrastructure as code and GitOps-style deployment, and the habit of shipping security changes through the same pipeline as everything elseComfort writing Python, Typescript, Rust or another language to build tooling, not just scriptsAn understanding of software supply chain attacks and the controls that stop them: signing, provenance, SBOMs, admission enforcementClear writing. Design docs, threat models and explanations to engineers who don't work in security are all part of the jobJudgment about which controls to enforce, which to recommend and how to roll out a breaking change without breaking the companyEven better if you haveExperience securing GPU or HPC-style compute, training pipelines or research environmentsExperience with policy engines and admission controllers (Kyverno, OPA Gatekeeper, Falco or similar)Multi-tenant isolation design in a cloud environment: ABAC, scoped credentials, per-tenant boundariesExperience producing security architecture evidence for SOC 2, ISO 27001 or other audits and customer assessmentsOpen source contributions or published work in cloud or Kubernetes securityWorking at RunwayGreat things come from great teams. We'd love to hear from you.We're committed to creating a space where our employees can bring their full selves to work and have equal opportunity to succeed. So regardless of race, gender identity or expression, sexual orientation, religion, origin, ability, age, veteran status, if joining this mission speaks to you, we encourage you to apply.