368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$160k – $240k per year
Location
In office (San Diego)
Seniority
Staff
Employment
Full-Time
Overview
Company
Impact
Profile match
Shield AI is an American defence technology company founded in 2015 that builds autonomy software and uncrewed aircraft for military missions. Its Hivemind autonomy stack lets aircraft fly, navigate and complete objectives without GPS, a remote pilot or a communications link, which matters in contested environments where those links are jammed. Headquartered in San Diego, California, the company fields the V-BAT vertical take-off aircraft with United States and allied forces, licenses Hivemind to other manufacturers and is developing the X-BAT jet for high-end missions.

Job Description:

You'll be the senior technical owner for paved roads and secure-by-default engineering on the Security Engineering team. Your job is not to review and say no - it is to engineer the secure defaults, golden paths, and guardrails-as-code that make the secure way to build the easy way to build, across cloud, infrastructure, and CI/CD.

You will design, build, and operate the IaC modules, pipeline templates, internal libraries, and policy-as-code controls that the rest of the company consumes. You will engineer guardrails that block or flag the insecure path automatically, and replace recurring manual security work with durable mechanisms that don't depend on anyone remembering to do the right thing. As one of the most senior engineers on the team, you'll help shape and drive the technical direction for how secure-by-default works at Shield AI - partnering closely with a hands-on engineering lead - and raise the bar for everyone building on top of it.

This is a hands-on, build-heavy role. We are credible because we are technical - you'll read the code, the configs, the telemetry, and the architecture, and ship solutions durable enough to run without you.

What you'll do:

  • Build the secure defaults: Infrastructure-as-Code modules, CI/CD pipeline templates, internal libraries, and golden-path scaffolding that make the secure choice the easy choice.
  • Engineer guardrails as code - policy-as-code (OPA/Conftest), admission controllers, cloud guardrails (SCPs / org policy), and pre-commit and CI checks - so the insecure path is blocked or flagged automatically.
  • Own the platform security tooling that other teams consume, so they don't have to build their own; replace recurring manual work with durable, self-service mechanisms.
  • Embed security into the software and infrastructure supply chain: pipeline security, build/artifact integrity, dependency and container scanning, and secrets management.
  • Engineer workload and service identity controls (least privilege, short-lived credentials, federated trust) so zero-standing-privilege is real and observable.
  • Write and maintain production-quality code and infrastructure that backs these controls.
  • Partner with platform, infrastructure, and product engineering teams early - review high-blast-radius designs against the internal Security Engineering standard while the design can still change, and turn recurring findings into a missing paved road, not just another fix.
  • Set technical direction and standards for secure-by-default; document them so they can be applied without us, and mentor and raise the bar for other engineers.

Required qualifications:

  • Extensive experience in security engineering, platform/infrastructure engineering, DevSecOps, or a closely related field, with a track record of owning complex systems end-to-end.
  • Strong software engineering ability - you write, review, and ship production-quality code (any modern language) and treat infrastructure as software.
  • Hands-on experience building secure-by-default mechanisms: Infrastructure-as-Code, CI/CD pipeline security, and policy/guardrails as code.
  • Deep working knowledge of at least one major cloud provider and its security and identity model.
  • Demonstrated ability to design durable, automated solutions that reduce real risk without becoming a bottleneck - and to make explicit tradeoffs between security and the business.
  • Strong communication: you can explain a security concept to a product engineer in their language and to a leader in business terms, and you write recommendations people can act on.

Preferred qualifications:

  • Strong DevSecOps background with hands-on Kubernetes (admission control, OPA/Gatekeeper, workload identity) and Terraform (reusable secure modules, policy-as-code).
  • Production coding experience in Go, Python, and/or Rust; comfortable with scripting/automation in Bash and PowerShell.
  • Depth in Azure security and identity (Entra ID, Azure Policy, Management Group guardrails).
  • Experience securing AI/ML systems, pipelines, or workloads.
  • Offensive security / red team experience, with the ability to think like an attacker and translate those findings into stronger defaults and guardrails.
  • Experience with supply-chain security (SLSA, sigstore/cosign, SBOMs), container/image hardening, and secrets management.
  • Experience operating security tooling as an internal product consumed self-service by other engineering teams.
  • Bachelor's degree or equivalent professional certification and experience.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Diego
$68k – $85k per year • In office • Full-Time • Master's Degree • San Jose
Python
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
Bitbucket
CI/CD
CloudFormation
Docker
Git
Kubernetes
Terraform
Amazon S3
IAM
HPC
Cybersecurity
Least Privilege
Apply
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$118k – $142k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • El Segundo
C++
MATLAB
Python
SystemC
SystemVerilog
Verilog
VHDL
DevOps
CI/CD
QEMU
Chips/EDA
UVM
Apply
$129k – $232k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
C++
DevOps
CI/CD
Git
RTOS
Apply
$133k – $161k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Westminster
C++
Python
DevOps
CI/CD
SpaceTech
NASA cFS
Apply
$89k – $193k per year (Estimated) • In office • Internship • 3+ years exp • Bachelor's Degree • London
C++
Python
Robotics
ArduPilot
MAVLink
QGroundControl
ROS
Apply
$230k – $350k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
Apply
$240k – $350k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Design
SolidWorks
Apply
$160k – $240k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • Boston
C++
Python
AI/ML
AI Agents
Robotics
Motion Planning
Swarm Robotics
Apply
In office • Internship • 3+ years exp • Bachelor's Degree • Kyiv
C++
Python
Robotics
ArduPilot
MAVLink
QGroundControl
ROS
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
Databases
Databricks
Google BigQuery
SAP HANA
Snowflake
AI/ML
Knowledge Graph
DevOps
Azure
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 5+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
DevOps
SLI/SLO/SLA
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
$94k – $294k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Portland • Milwaukee • Dallas • Columbus
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.