Infrastructure Security Engineer

Security Engineer · Senior · Full Time

New YorkUSD 150k – 270k4mo ago
Apply for this role

Opens Modal's application page

Role

What you'll do.

Modal is seeking an Infrastructure Security Engineer to design and secure core systems powering their AI infrastructure platform. The ideal candidate will build robust security mechanisms for multi-tenant, cloud-native environments, focusing on container isolation, identity management, and infrastructure protection across distributed computing systems.

Responsibilities

  • Platform Security Design: Design and improve isolation mechanisms for multi-tenant workloads and containerized environments
  • Access Management: Implement robust authentication, authorization, and service identity systems with least-privilege access patterns
  • Infrastructure Protection: Secure cloud environments across providers with focus on consistency, network boundaries, and service segmentation
  • Secrets Management: Build and maintain secure systems for managing credentials, tokens, and implementing secure rotation practices
  • Security Engineering: Collaborate with product and infrastructure teams to embed security into system design and infrastructure-as-code

Qualifications

What we look for.

Technical

  • Cloud Infrastructure

    Proven experience securing cloud-native distributed systems in production environments

  • Container Security

    Advanced knowledge of containerization and orchestration security

  • Network Security

    Deep understanding of network segmentation, service communication, and access control

Education

  • Computer Science

    Bachelor's or equivalent experience in Computer Science, Cybersecurity, or related technical discipline

Experience

  • Production Systems

    Hands-on experience in multi-tenant or high-scale computing environments

  • Security Engineering

    Background in infrastructure, backend, or dedicated security engineering roles

Skills

Required

  • Cloud Security

    Expertise in securing cloud-native infrastructure and distributed systems

  • Kubernetes

    Strong understanding of containerization and orchestration security

  • Identity Management

    Experience with authentication, authorization, and service identity models

  • Networking Security

    Solid foundation in network segmentation and access control

Preferred

  • Runtime Isolation

    Nice to have

    Experience with sandboxing technologies like gVisor or Firecracker

  • Low-Level Security

    Nice to have

    Familiarity with kernel-level isolation primitives

  • Multi-Tenant Systems

    Nice to have

    Background in securing high-scale, multi-tenant environments

Tech stack

Languages

PythonGo

Frameworks

Zero Trust

Tools

KubernetesAWSGCPTerraform

Other

Container Security

Compensation

Pay and benefits.

Base·USD 150,000 – 270,000

Equity·Stock options

Benefits

  • Equity

    Stock options in a high-growth AI infrastructure startup

  • Healthcare

    Comprehensive medical, dental, and vision insurance

  • Professional Development

    Budget for conferences, training, and continuous learning

  • Flexible Work

    Remote-friendly work environment with potential NYC/SF office access

Process

Interview steps.

  1. 01

    Initial Screening

    Phone or video call with recruiting team to discuss background and role fit

  2. 02

    Technical Interview

    In-depth discussion of security architecture, system design, and technical capabilities

  3. 03

    Systems Design Challenge

    Practical assessment of infrastructure security design skills

  4. 04

    Team Interview

    Meetings with potential team members to assess collaboration and cultural fit

  5. 05

    Final Executive Interview

    Conversation with senior leadership to align on role expectations and company vision

Full posting

Original listing.

About Us:

Modal provides the infrastructure foundation for AI teams. With instant GPU access, sub-second container startups, and native storage, Modal makes it simple to train models, run batch jobs, and serve low-latency inference. We have thousands of customers who rely on us for production AI workloads, including Lovable, Scale AI, Substack, and Suno.

We're a fast-growing team based out of NYC, SF, and Stockholm. We've hit 9-figure ARR and recently raised a Series B at a $1.1B valuation. Our investors include Lux Capital, Redpoint Ventures, Amplify Partners, and Elad Gil.

Working at Modal means joining one of the fastest-growing AI infrastructure organizations at an early stage, with many opportunities to grow within the company. Our team includes creators of popular open-source projects (e.g. Seaborn, Luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.

The Role:

We’re looking for an Infrastructure Security Engineer to design and secure the core systems that power our platform. This role focuses on building security directly into our infrastructure—from container isolation and orchestration to identity and secrets management in a multi-tenant, cloud-native environment.

You’ll work closely with engineering teams to define secure primitives and ensure our platform is resilient, scalable, and trustworthy by design.

This is a hands-on, deeply technical role focused on real systems, not compliance or policy.

What You'll Do:

Platform & Runtime Security

  • Design and improve isolation mechanisms for multi-tenant workloads (containers, sandboxing, execution environments)

  • Strengthen boundaries between customers, workloads, and internal systems

  • Identify and mitigate risks in distributed, dynamic compute environments

Container & Orchestration Security

  • Secure and harden containerized workloads and orchestration systems (e.g., Kubernetes or similar)

  • Improve workload isolation, scheduling boundaries, and runtime protections

  • Evaluate tradeoffs in multi-tenant execution models

Identity & Access Management

  • Design and improve authentication and authorization systems across services

  • Implement strong service-to-service identity and least-privilege access patterns

  • Improve access controls across infrastructure and internal systems

Secrets & Key Management

  • Build and maintain systems for securely managing secrets, tokens, and credentials

  • Improve rotation, auditing, and access controls

  • Reduce secret sprawl and integrate secure patterns into developer workflows

Cloud & Infrastructure Security

  • Secure cloud environments across providers (AWS, GCP, etc.) with a focus on consistency and portability

  • Improve network boundaries, service segmentation, and access controls

  • Embed security into infrastructure-as-code and deployment systems

Engineering Partnership

  • Work closely with product and infrastructure teams to design secure systems from the ground up

  • Review architecture and code for security risks and provide actionable guidance

  • Identify patterns in risks and drive cross-cutting improvements

Requirements:

Core Experience

  • Experience securing cloud-native infrastructure and distributed systems in production

  • Background in infrastructure, backend, or security engineering

  • Experience working in multi-tenant or high-scale environments

Technical Depth

  • Strong understanding of containerization and orchestration systems (e.g., Kubernetes or similar)

  • Experience designing or securing isolation mechanisms in multi-tenant systems

  • Solid understanding of authentication, authorization, and service identity models

  • Experience with secrets management and secure handling of credentials

  • Strong foundation in networking concepts (segmentation, service communication, access boundaries)

Mindset

  • Builder mentality, you design and implement, not just review

  • Pragmatic approach to security in fast-moving environments

  • Comfortable working deeply with engineers and influencing system design

Preferred Qualifications:

  • Experience with sandboxing or runtime isolation technologies (e.g., gVisor, Firecracker, seccomp, or similar)

  • Familiarity with kernel-level or low-level isolation primitives

  • Experience securing Kubernetes or similar orchestration systems in production

  • Background in developer infrastructure, compute platforms, or multi-tenant systems

Redirects to Modal's application page.

Other roles

More at Modal.

View all 10 roles