368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$207k – $390k per year (Estimated)
Location
In office (New York, San Francisco)
Seniority
Architect · 20+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Reflection AI is a company founded in 2024 by former Google DeepMind researchers who worked on AlphaGo and large language models. It builds autonomous coding agents and has committed to releasing frontier open-weight models as an American counterweight to Chinese open model releases. The company raised a very large round in 2025 to fund training at frontier scale.

Our Mission

Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.

Role Overview

The Head of Technology & Security Engineering is responsible for architecting and operating the security engineering foundation that protects the organization’s corporate environment, multi-cloud research infrastructure, and multi-million-dollar GPU training capacity. This leader owns the full technical security stack - from end-user compute and zero-trust access to cloud and container security, detection engineering, and security-as-code - ensuring the organization can move at research speed without sacrificing rigor.

Sitting at the intersection of security engineering, infrastructure, and research operations, this role is uniquely positioned to define how a frontier AI company protects its most sensitive assets - model weights, training data, and GPU capacity - while preserving the low-friction environment researchers and engineers need to do their best work. The ideal candidate brings deep, hands-on technical depth alongside the executive presence to lead a security engineering function, represent the organization’s security posture to auditors and enterprise customers, and negotiate vendor and contractual risk.

This is a high-visibility, high-impact role that operates across engineering, infrastructure, legal, and physical security. Success requires the ability to design guardrails rather than gates, build systems that assume compromise, and operate credibly as both an executive leader and a hands-on builder.

What You'll Do

High-Performance End User Compute (EUC)

  • Design and manage a highly resilient corporate device fleet spanning Linux, macOS, Windows and specialized hardware such as NVIDIA GPU workstations.

  • Shift the fleet away from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without reducing assurance.

  • Secure diverse local toolchains and developer environments without breaking the workflows researchers and engineers depend on.

Securing the Research & Training Boundary

  • Architect cloud-native security controls across multi-cloud environments that contain multi-million-dollar GPU clusters.

  • Establish IAM governance, network segmentation, and isolation boundaries appropriate to the scale and sensitivity of training infrastructure and model assets.

  • Partner with infrastructure and research teams to ensure security controls scale with GPU capacity rather than constrain it.

Phishing-Resistant Zero-Trust Access

  • Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One).

  • Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across every corporate and production plane.

  • Eliminate standing and persistent access in favor of just-in-time, verifiable authorization.

Security as Code (SaC)

  • Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi).

  • Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.

  • Build repeatable, auditable deployment pipelines that make security posture provable rather than assumed.

Behavioral Detection Engineering

  • Build telemetry pipelines that ingest high-fidelity logs into a cloud-native data lake to support detection at scale.

  • Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks across corporate and production environments.

  • Continuously tune detection coverage against an assumed-breach threat model, prioritizing time-to-detect and blast-radius containment.

Compliance, Audit & Vendor Risk

  • Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.

  • Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.

  • Own front-line defenses for a frontier AI company, including physical security and data center security operations.

What We're Looking For

Experience & Background

  • 20+ years of deep engineering experience at high-valuation companies, or in defense-grade environments.

  • Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.

  • Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.

  • Experience leading vendor risk, procurement security reviews, and legal contract negotiations.

  • Experience with front-line defenses for an AI company, including physical security and data center security operations.

Skills & Capabilities

  • Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments.

  • Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.

  • Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.

  • Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation.

Mindset & Approach

  • A “guardrails, not gates” philosophy - understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation.

  • An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately.

  • Motivated by building - comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization.

What We Offer:

We believe that to make intelligence open and accessible to all, you need to start at the foundation. Joining Reflection means building from the ground up as part of a talent-dense team. You will help define our future as a company, and help define the future of open foundational models.

We want you to do the most impactful work of your career with the confidence that you and the people you care about most are supported.

  • Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.

  • Stock options: Everyone who joins and contributes to Reflection's success gets to share in the upside through stock options.

  • Health & wellness: Comprehensive medical, dental, vision, and life, with an annual wellness allowance.

  • Meals: Lunch and dinner are provided in the office daily.

  • Life & family: 22 weeks paid parental leave for all new birthing and non-birthing parents, including adoptive and surrogate journeys.

  • Vacation days: Unlimited paid time off in the U.S. and 30 days in the U.K.

  • Sponsorship support: We sponsor visas to help exceptional talent join our team and support long-term immigration pathways where applicable.

  • Team building: We have regular off-sites, happy hours, and team celebrations.

Export Control Notice: This position may require access to technology or source code subject to the U.S. Export Administration Regulations. Any offer of employment for this role may be conditioned on the Company's ability to provide the candidate with access to such technology or source code in compliance with applicable U.S. export control laws, which may require the Company to seek government authorization.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
New York
$25k – $69k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru • Pune
Java
Python
AI/ML
AI Agents
AWS Bedrock
Fine-tuning
Google ADK
LangGraph
LLM
LoRA
RAG
Semantic Search
LangChain
PEFT
A2A
Amazon SageMaker
AWS Strands Agents
NIST AI RMF
Semantic Search
Model Context Protocol
DevOps
Amazon EC2
Amazon EKS
AWS
Azure
CI/CD
CloudFormation
Docker
GCP
Git
GitOps
gRPC
Kubernetes
OpenTelemetry
Rest API
Terraform
Vector
Amazon S3
IAM
GitLab
Apply
$27k – $70k per year (Estimated) • In office • Full-Time • Pune
JavaScript
SQL
TypeScript
Java
Java
Gradle
Hibernate
Maven
Spring Boot
Spring Framework
Databases
Apache Kafka
Oracle
Frontend
Angular
React.js
DevOps
AWS
CI/CD
Docker
Git
Jenkins
Kubernetes
OpenShift
Cybersecurity
SonarQube
Veracode
QA
Selenium
Swagger
Apply
$23k – $61k per year (Estimated) • In office • Full-Time • Pune
Go
Java
SQL
Java
Spring Boot
Databases
PostgreSQL
DevOps
Amazon EC2
AWS
AWS Fargate
CI/CD
CloudFormation
Docker
Git
Jenkins
Kubernetes
Terraform
Amazon ECS
GitLab
Apply
$25k – $68k per year (Estimated) • In office • Full-Time • Pune
Java
Java
Spring Boot
Frontend
GraphQL
DevOps
AWS
Azure
Azure DevOps
CI/CD
CloudFormation
Docker
GCP
Jenkins
Kubernetes
Shift-Left
Terraform
GitLab
Cybersecurity
Shift-Left Security
Zero Trust
Apply
$39k – $124k per year (Estimated) • In office • Full-Time • 4+ years exp • Bachelor's Degree • Israel
C#
Java
DevOps
Azure
Azure DevOps
CI/CD
Git
QA
Appium
TestNG
Apply
$133k – $266k per year (Estimated) • Equity • In office • Full-Time • 8+ years exp • San Francisco • London • New York
Databases
Apache Kafka
Delta Lake
Google BigQuery
Snowflake
AI/ML
Dagster
Flink
Great Expectations
DevOps
SLI/SLO/SLA
Apply
$179k – $363k per year (Estimated) • Equity • In office • Full-Time • Bachelor's Degree • New York • San Francisco • London
AI/ML
LLM
Reinforcement Learning
Synthetic Data
Post-training
Pre-training
Apply
$134k – $268k per year (Estimated) • Equity • In office • Full-Time • San Francisco • London • New York
AI/ML
NCCL
DevOps
Kubernetes
Apply
$76k – $165k per year (Estimated) • Equity • In office • Full-Time • 5+ years exp • San Francisco • New York
Cybersecurity
Okta
Apply
$202k – $349k per year (Estimated) • Equity • In office • Full-Time • San Francisco • London • New York
AI/ML
LLM
Reinforcement Learning
Post-training
Pre-training
Apply
$197k – $374k per year (Estimated) • In office • Full-Time • 8+ years exp • PhD • New York
AI/ML
AI Agents
Claude
LangChain
OpenAI
Vertex AI
Management
n8n
Zapier
Apply
$96k – $134k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • New York
JavaScript
Swift
TypeScript
Java
Java
Spring Framework
Databases
Apache Kafka
PostgreSQL
AI/ML
AI Agents
Claude
Copilot
Fine-tuning
Flink
LangChain
LangGraph
Llama
LlamaIndex
Prompt Engineering
PyTorch
RAG
TensorFlow
Transformers
Devin
Hugging Face
OpenAI
Frontend
Angular
React.js
Mobile
MVC
DevOps
AWS
CI/CD
Docker
Kubernetes
OpenShift
Splunk
Vector
GitHub
Analytics
Tableau
Apply
$150k – $180k per year • In office • Full-Time • PhD • New York
Python
AI/ML
Anthropic
Anthropic SDK
Computer Vision
Fine-tuning
LangChain
LlamaIndex
LLM
OpenAI
OpenAI SDK
RAG
DevOps
AWS
Azure
GCP
Apply
Senior AI Architect 2 hours ago
$131k – $136k per year • In office • Full-Time • 4+ years exp • Master's Degree • New York
Python
Databases
Databricks
AI/ML
Anthropic
Computer Vision
EU AI Act
LLMOps
OpenAI
DevOps
AWS
Azure
GCP
Terraform
Cybersecurity
GDPR
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
Databases
Databricks
Google BigQuery
SAP HANA
Snowflake
AI/ML
Knowledge Graph
DevOps
Azure
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.