368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$118k – $246k per year (Estimated)
Location
In office (Dallas)
Seniority
Staff · 7+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Topaz Labs is a Dallas company founded in 2005 that builds neural network software for enhancing photographs and video. Its products sharpen, denoise, upscale and interpolate frames, and are widely used by photographers, film restorers and video professionals. The company sells desktop applications rather than cloud services, which suits large media files and offline workflows.

We use AI to do things that were previously impossible. Topaz Labs builds professional-grade software that uses deep learning to enhance image and video quality. Over 1 million photographers and designers trust us with their work, including teams at Apple, Netflix, NASA, and Disney. We’ve processed over 1 billion images, achieved massive revenue growth, and we’re only getting started.We are a small, profitable, and product-led team that values craftsmanship and impact over activity. We don’t just ship features; we solve hard problems to help creatives do their best work.

As our first Principal Security Engineer, you will own the security posture for the entire organization -from the cloud to the colo, and from the training cluster to the office network.This is not a high-level compliance role. You will be reporting directly to the Head of AI Engine, but your scope spans the entire company. You must be willing to get your hands dirty.We operate a hybrid infrastructure: AWS, massive on-premise GPU training clusters in our colocation facility, and a corporate fleet of devices. Your mission is to secure every layer of this stack. You will have complete autonomy to architect security for our compute resources, manage office/colo networks, and harden our endpoints.

About the role

  • Secure the Hybrid Infrastructure (AWS & Colo): You will be the single owner for security across our cloud environments and our physical colocation data centers. This includes configuring firewalls, managing physical network security, and hardening our Linux GPU clusters.
  • Corporate & Endpoint Security: You will own the security of our internal tools and devices. You will manage our fleet (primarily macOS) using Jamf and oversee identity management via Active Directory.
  • You ensure our creative workflows are secure without being obstructive.
  • Hands-On Penetration Testing: We don't just rely on external audits. You will regularly conduct hands-on penetration tests against our internal networks, office infrastructure, and AI applications to find vulnerabilities before anyone else does.
  • Secure the AI Supply Chain: Our models are our most valuable IP. You will design systems to protect our model weights during training, storage, and delivery, ensuring they are tamper-proof and secure from theft or reverse engineering.

About you

  • You are a hands-on generalist. You are just as comfortable configuring an IAM policy in AWS as you are setting up a switch in a colocation rack or writing a script for Jamf.
  • You have a craftsmanship mentality. You take personal pride in building systems that are robust, elegant, and secure by default. You don't just patch holes; you eliminate entire classes of vulnerabilities.
  • You are an infrastructure native. You are fluent in Linux internals, networking, and container orchestration. You understand the unique security challenges of cloud, distributed, and HPC environments.
  • You value truth over comfort. You are willing to have hard conversations about risk and prioritize fixing root causes over applying band-aids.
  • You think like an attacker. You don't wait for a report to tell you something is wrong. You actively probe our defenses (office, colo, and cloud) to prove they work.

Qualifications

  • 7+ years of experience in security engineering, with a mix of infrastructure, corporate IT, and offensive security.
  • Deep hands-on experience with cloud security and compliance (AWS, IAM, VPC, SOC II, Vanta).
  • Proven experience with Endpoint Management & Identity: Expert-level knowledge of Jamf for macOS management and Active Directory (or modern equivalents) for identity governance.
  • Physical & Network Security: Experience securing physical office networks and colocation facilities (firewalls, VPNs, switching).
  • Offensive Security: Demonstrated ability to perform manual penetration testing (network and web app).Proficiency in scripting (Python/Bash) to automate security tasks.
  • Bonus: Experience securing on-device software or desktop applications (Windows/macOS).
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Dallas
$25k – $42k per year • Equity 0–0.2% • Remote • Full-Time • 3+ years exp
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $210k per year • Equity 0–0.5% • Remote • Full-Time • 3+ years exp • San Francisco
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
Team Lead DevOps 1 day ago
$23k – $62k per year (Estimated) • Remote • 5+ years exp • Moscow
Bash
Python
Erlang
Erlang
EMQX
Databases
Apache Kafka
ClickHouse
PostgreSQL
RabbitMQ
Redis
Redpanda
Trino
DevOps
Ansible
AWS
AWX
FinOps
HAProxy
Hetzner
Kubernetes
SLI/SLO/SLA
Terraform
Yandex Cloud
Amazon S3
Apply
$230k – $260k per year • Equity • Remote • Internship • Bachelor's Degree
Python
DevOps
Amazon EKS
AWS
Azure
CI/CD
GCP
Helm
Kubernetes
Terraform
Cybersecurity
FedRAMP
Orca Security
Apply
$120k – $250k per year • Equity 0.2–1% • In office • Full-Time • Master's Degree • Seattle
Python
AI/ML
Diffusion Models
Fine-tuning
PyTorch
Self-Supervised Learning
Apply
$110k – $160k per year • In office • Full-Time • 2+ years exp • Dallas
C++
JavaScript
Python
C++
Conan
DevOps
AWS
Azure
CI/CD
Apply
$110k – $150k per year • In office • Full-Time • 1+ year exp • Dallas
C++
C
C
FFmpeg
AI/ML
OpenCV
TensorRT
DevOps
HPC
Apply
$81k – $163k per year (Estimated) • In office • Full-Time • 2+ years exp • Bachelor's Degree • Dallas
C++
JavaScript
C++
Qt
Apply
$98k – $184k per year (Estimated) • In office • Full-Time • 3+ years exp • Dallas
Apply
$118k – $162k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree • Louisville • Fort Lauderdale • Washington • Chicago • Tampa
DevOps
Azure
GCP
Cybersecurity
HIPAA
Apply
Full Stack Engineer 27 min ago
$89k – $121k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree • Louisville • Nashville • Dallas
C#
C#
.NET
Databases
Oracle
Cybersecurity
HIPAA
Apply
$173k – $328k per year (Estimated) • In office • Full-Time • 12+ years exp • Dallas
Management
ServiceNow
Apply
$159k – $282k per year • In office • Full-Time • Bachelor's Degree • Minneapolis • Chicago • Phoenix • Raleigh • Dallas
Apply
$70k – $206k per year • In office • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
AI/ML
AI Agents
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.