{"id":586348,"url":"https://alion.io/job/point-one-inc-security-infrastructure-engineer","title":"Security & Infrastructure Engineer","company":{"id":449978,"name":"PointOne","domain":"pointone.com","url":"https://alion.io/company/point-one-inc","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Ashby","truth_index":{"grade":"C","score":58,"open_postings":13,"ghost_share":0.692,"stale_share":0,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"DevOps","role_family":"DevOps","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":160000,"max":220000,"currency":"USD","period":"year","gross":null,"usd_annual":220000},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"Anomaly Detection","optional":false},{"name":"AWS","optional":false},{"name":"AWS Lambda","optional":false},{"name":"IAM","optional":false},{"name":"Least Privilege","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false}],"status":"live","first_seen_at":"2026-03-02T15:31:43Z","employer_posted_date":"2026-03-02","last_verified_at":"2026-09-28T21:35:36Z","board_verified":true,"closed_at":null,"days_open":210,"trust":{"level":"ghost","repost_count":0,"flags":["stale","company_stale"],"days_open":209},"description":"About PointOne\nPointOne builds infrastructure for the legal industry, powering timekeeping and billing systems used by law firms and government agencies.\nWe build and operate systems that process the most confidential data for institutions working on the most sensitive matters. Security for us is a strategic priority.\nWe’re hiring a senior engineer to own the security, scalability, and cost efficiency of our AWS environment.\nThe Role\nLet’s start with what this isn’t:\nNot a GRC or paperwork-heavy compliance role\n\nNot a vulnerability-scanning-only position\n\nNot a “turn on GuardDuty and call it done” role\n\nYou will be shaping critical systems and making architectural decisions that materially affect risk and resilience.\nThis is a hands-on engineering role at the intersection of security, cloud architecture, and platform optimization.\nYou will harden our AWS infrastructure, reduce blast radius, eliminate unnecessary exposure, and ensure our systems scale efficiently and securely.\nWhat You'll Own\nInfrastructure Security\nDesign and enforce least-privilege IAM across services\n\nImplement permission boundaries and SCP strategy\n\nReduce attack surface across networking and service exposure\n\nImprove secrets management and KMS key segmentation\n\nLead threat modeling across core systems\n\nDesign blast-radius containment strategies\n\nDetection & Response\nStrengthen logging, monitoring, and anomaly detection\n\nEnsure logs are immutable and auditable\n\nBuild and test incident response playbooks\n\nReview new infrastructure designs for security risks\n\nScale & Cost\nOptimize AWS architecture for reliability and efficiency\n\nImprove Lambda/SQS concurrency and scaling patterns\n\nEvaluate and improve RDS scaling strategy\n\nDrive principled tradeoffs between isolation, performance, and cost\n\nWhat We're Looking For\n5+ years operating AWS infrastructure in production\n\nDeep IAM expertise (roles, policies, trust relationships, STS)\n\nStrong AWS networking knowledge (VPC, PrivateLink, Security Groups)\n\nExperience designing multi-account AWS environments\n\nHands-on experience responding to real security incidents\n\nStrong understanding of cloud attack vectors and privilege escalation\n\nExperience reducing cloud cost without compromising security\n\nComfortable working directly in CDK/Terraform and reviewing infrastructure code\n\nStrong plus: Experience in legal, fintech, government, or other high-sensitivity environments.\nWhy This Role Matters\nA security breach at PointOne would have consequences extending far beyond the survival of our company. This role exists to:\nProtect sensitive institutions\n\nRaise the engineering bar on secure system design\n\nBuild infrastructure that enterprise and government customers can trust\n\nYou will be a core architect of PointOne’s long-term security posture.\nThis is intense early-stage startup work. You will be expected to take ownership, bring structure to ambiguity, and build the connective tissue between our customers and our product.\nThe compensation for this position is determined by multiple factors, including prior experience and expertise. A competitive equity component will also be offered as part of the package. Benefits include comprehensive health, dental, and vision insurance, as well as meals in office, regular team events, and more!","description_format":"text","description_chars":3291,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity","Vision insurance"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Professional Services","Legal Services"],"lifecycle":[{"event":"open","at":"2026-09-10T04:47:11Z"}],"liveness":{"score":5,"band":"cold","label":"Long shot","p_open":1,"p_active":0.173,"p_room":0.28,"age_days":209,"expected_fill_days":30,"reasons":["conf:4","stale_co","ghost","win:tail","crowd:"],"computed_at":"2026-09-28T05:45:00Z"},"pay":{"stated_usd_annual":220000,"is_top_pay":true},"html_url":"https://alion.io/job/point-one-inc-security-infrastructure-engineer","json_url":"https://alion.io/job/point-one-inc-security-infrastructure-engineer.json","meta":{"generated_at":"2026-09-29T01:39:48Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1294,"day_limit":5000,"remaining_today":3706,"minute_limit":60,"resets_at":"2026-09-30T00:00:00Z"}}}