687,385open jobs
40,039companies
97,916added this week
Browse all
Salary
$150k – $250k per year
Location
In office (San Jose)
Seniority
Senior · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Figure AI is an American robotics company founded in 2022 that develops general-purpose humanoid robots for commercial and household work. Its Figure 02 and Figure 03 machines combine custom actuators, battery systems and hands with the in-house Helix vision-language-action model, which lets one neural network drive both perception and motor control from natural-language instructions. Headquartered in San Jose, California, the company runs the BotQ manufacturing facility for high-volume production and has piloted its robots on logistics and automotive assembly work with commercial partners.

Figure is an AI Robotics company developing a general purpose humanoid. Our humanoid robot is designed for commercial tasks and the home. We are based in San Jose, CA and require 5 days/week in-office collaboration. It’s time to build.

We're looking for an Infrastructure Security Engineer to join the Security & Privacy team at Figure, focused on designing, implementing, and managing the security controls and frameworks that protect the company's backend services and infrastructure. This includes building strong foundations that let employees move quickly and safely: secure defaults, paved paths, and self-service guardrails.

We are an engineering team. Controls ship as code, changes are versioned and reviewed, and posture is measured rather than asserted. This is a senior, hands-on individual contributor role. Nobody arrives deep in all of it; we want real depth in one of endpoint engineering, identity and access, or application access design, working knowledge of the rest, and room to build depth here. This space is still being built out, so you'll also have latitude to shape the roadmap toward the work you find most interesting.

Responsibilities:

Partner across teams

  • Work with the DevOps and Infrastructure teams to securely roll out AI tooling across our infrastructure, securing the deployment path, service-to-service communication, and the network boundaries around these workloads.
  • Partner with the Networking team on data-center and cloud network security: NSGs, segmentation, VPC structure, private connectivity, and egress policy.
  • Enable the Detection & Response team by making every environment produce the telemetry they need, and provide environment access and context during incidents.

Authentication / Authorization

  • Own multi-cloud authentication and authorization: centralized SSO for human identities, workload identity and federated credentials for machine identities, and consistent, least-privilege access policy across cloud providers.
  • Extend that identity model to on-prem and neocloud environments, including hardware-rooted machine identity so all our infrastructure inherits the same authN/authZ guarantees as our cloud backends.
  • Drive the move away from long-lived reusable credentials toward sealed, short-lived, workload-scoped authentication, and build just-in-time, time-bound elevated access.

Visibility

  • Measure posture: build the tooling and pipelines for asset and identity inventory, configuration drift detection, and coverage metrics across cloud, on-prem, and neocloud environments.
  • Turn misconfiguration and vulnerability findings into tracked, closed-loop remediation across every environment class.

Networking

  • Advance our zero-trust networking model as the universal access layer: identity-aware, posture-gated access to internal services with no public IPs and no cross-environment traffic outside the overlay.
  • Design and enforce egress controls so workloads can't make arbitrary outbound calls.
  • Define the secure-by-default networking patterns other teams build on top of, so segmentation and access rules are versioned, reviewed, and auditable rather than hand-configured.

Requirements:

  • Experience and security knowledge of one or more domains and technologies: Kubernetes, containers, service mesh, networking, operating system internals, authentication/authorization protocols, and cloud security tools.
  • Experience developing and deploying services in multi-cloud environments, preferably familiar with a multi-cloud infrastructure spanning at least two of the three: Azure, AWS, or Google Cloud Platform.
  • 6+ years of security / software development experience.
  • Strong software engineering skills (not scripting or automation) skills in C/C++, Rust, Golang, Python or similar.
  • Passion for learning and helping others.
  • Excellent verbal and written communication skills, with high attention to detail.
  • BS/BA in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field

Bonus Qualifications:

  • Familiarity with zero-trust networking, posture-based access control, and egress/segmentation design.
  • Hands-on with workload identity / federated credentials, and secrets management.
  • Experience with delivering security controls as reviewed, versioned code.
  • Familiarity with securing AI/ML tool usage across infrastructure.
  • Track record of building self-service security tooling and paved paths that scale to a fast-moving engineering org.
  • Experience securing on-prem or neocloud alongside public cloud.

The US base salary range for this full-time position is between $150,000 - $250,000 annually.

The pay offered for this position may vary based on several individual factors, including job-related knowledge, skills, and experience. The total compensation package may also include additional components/benefits depending on the specific role. This information will be shared if an employment offer is extended.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
687,385 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Jose
$45k – $97k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Amersfoort
Python
AI/ML
LLM
DevOps
Rest API
Terraform
Ansible
GCP
OpenShift
Helm
GitLab CI
CI/CD
AWS
Kubernetes
Platform Engineering
AIOps
Incident Management
SLI/SLO/SLA
GitLab
IAM
Cybersecurity
Zero Trust
Apply
In office • Internship • Master's Degree
Python
Java
C++
DevOps
CI/CD
Git
Management
Agile
Apply
$108k – $178k per year • In office • Full-Time • Bachelor's Degree • Santa Clara • Seattle
Python
C++
AI/ML
Flash Attention
AI Agents
LLM
MLIR
Apache TVM
Apply
$100k – $115k per year • In office • Full-Time • United States
Python
SQL
DevOps
Splunk
Ansible
Azure DevOps
Azure
Grafana
Management
Agile
Apply
$86k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Seattle
Python
PowerShell
DevOps
Splunk
VMWare
Azure
Windows Server
Nagios
Apply
$160k – $250k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • San Jose
Python
TypeScript
DevOps
Terraform
Azure
Git
Kubernetes
QA
Playwright
Pytest
Vitest
Apply
$137k – $266k per year (Estimated) • In office • 5+ years exp • San Jose
Python
Management
Confluence
Jira
Apply
$80k – $105k per year • In office • Full-Time • San Jose
Apply
$80k – $90k per year • In office • Internship • Master's Degree • San Jose
Python
Robotics
Motion Planning
Apply
$90k – $206k per year (Estimated) • In office • Full-Time • San Jose
Apply
$56k – $64k per year • Remote • Full-Time • 5+ years exp • San Francisco • San Jose
Chips/EDA
OpenLane
Apply
$234k – $311k per year • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • San Jose
Apply
$158k – $193k per year • In office • Full-Time • 8+ years exp • San Jose
AI/ML
AI Agents
Apply
$234k – $311k per year • Equity • Remote/Hybrid • Full-Time • Bachelor's Degree • San Jose
Analytics
Tableau
Power BI
Apply
$164k – $204k per year • Remote/Hybrid • Full-Time • 5+ years exp • San Jose
AI/ML
Model Context Protocol
Cybersecurity
Zscaler
Zero Trust
Management
Agile
Apply
See all jobs
This is one of many
687,385 more open roles from verified company boards, updated every day.