安全工程师
Security Engineer
ABOUT BASETEN
Baseten 为全球最具活力的 AI 公司提供关键任务推理,如 Cursor、Notion、OpenEvidence、Abridge、Clay、Gamma 和 Writer。通过结合应用 AI 研究、灵活的基础架构和无缝的开发者工具,我们使处于 AI 前沿的公司能够将前沿模型投入生产。我们正在快速成长,并最近完成了 1.5 亿美元的 F 轮融资 https://www.baseten.co/blog/announcing-our-series-f/,由 Altimeter Capital、Conviction Partners 和 Spark Capital 领投。加入我们,帮助构建工程师们用来发布 AI 产品的平台。
THE ROLE
我们正在寻找一位经验丰富且积极主动的安全工程师,帮助我们构建、维护并持续提升我们快速增长的 ML 基础架构平台的安全态势。作为 Baseten 的首批专职安全人员之一,您将与工程和运维团队跨职能合作,确保我们达到保密性、完整性和可用性的最高标准。您将有机会从零开始塑造我们的安全策略和最佳实践,影响我们的平台如何处理内部和外部利益相关者的敏感数据。
RESPONSIBILITIES
- 安全架构与设计:与工程团队合作,设计和实现安全系统和基础架构,包括云(AWS/GCP)环境和容器编排平台。
- 漏洞管理:主导主动的漏洞评估、渗透测试和修复工作,确保我们的产品和基础架构保持安全。
- 事件响应:制定和维护事件响应流程,包括检测、分析、遏制、根除和事后审查。
- 身份和访问管理(IAM):监督 IAM 策略和工具,确保正确的人拥有对系统和数据的适当访问权限。
- 安全合规与审计:与运维团队紧密合作,确保符合相关标准(如 SOC 2、ISO 27001)并协助审计、政策制定和风险评估。
- 员工安全培训:开发并提供安全培训计划和文档,让团队了解最佳实践、社会工程威胁和安全编码标准。
- DevSecOps 集成:与 DevOps 团队合作,将安全嵌入 CI/CD 流水线,自动化安全检查并培养“安全即责任”的文化。
查看英文原文
ABOUT BASETEN
Baseten powers mission-critical inference for the world's most dynamic AI companies, like Cursor, Notion, OpenEvidence, Abridge, Clay, Gamma, and Writer. By uniting applied AI research, flexible infrastructure, and seamless developer tooling, we enable companies operating at the frontier of AI to bring cutting-edge models into production. We're growing quickly and recently raised our $1.5B Series F https://www.baseten.co/blog/announcing-our-series-f/, led by Altimeter Capital, Conviction Partners, and Spark Capital. Join us and help build the platform engineers turn to ship AI products.
THE ROLE
We are seeking an experienced and proactive Security Engineer to help us build, maintain, and continuously improve the security posture of our rapidly growing ML infrastructure platform. As one of the first dedicated security hires at Baseten, you will work cross-functionally with engineering and operations teams to ensure we’re meeting the highest standards of confidentiality, integrity, and availability. You’ll have an opportunity to shape our security strategy and best practices from the ground up, influencing the way our platform handles sensitive data for both internal and external stakeholders.
RESPONSIBILITIES
- Security architecture and design: Collaborate with engineering teams to design and implement secure systems and infrastructure, including cloud (AWS/GCP) environments and container orchestration platforms.
- Vulnerability management: Lead proactive vulnerability assessments, pen tests, and remediation efforts to ensure our products and infrastructure remain secure.
- Incident response: Develop and maintain incident response processes, including detection, analysis, containment, eradication, and post-incident reviews.
- Identity and access management (IAM): Oversee IAM strategies and tools to ensure the right people have the right level of access to our systems and data.
- Security compliance and audits: Work closely with operations to ensure compliance with relevant standards (e.g., SOC 2, ISO 27001) and assist with audits, policy creation, and risk assessments.
- Employee security training: Develop and deliver security training programs and documentation to keep our team informed about best practices, social engineering threats, and secure coding standards.
- DevSecOps integration: Partner with DevOps teams to embed security into the CI/CD pipeline, automating security checks and fostering a culture of “security as code.”
REQUIREMENTS
- 3+ years of experience in a Security Engineer or similar security-focused role, preferably in a fast-paced startup environment.
- Strong knowledge of cloud security (AWS/GCP), container security, and infrastructure-as-code best practices.
- Hands-on experience with security tooling (SIEM, IDS/IPS, vulnerability scanners) and scripting languages to automate security tasks.
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, and GDPR, and the ability to translate requirements into actionable security controls.
- Incident response expertise, including forensic analysis and root cause investigation.
- Excellent communication skills and the ability to collaborate with cross-functional teams to promote a security-first culture.
BENEFITS
- Competitive compensation, including meaningful equity
- (U.S. only) 100% coverage of medical, dental, and vision insurance for employee and dependents
- Flexible PTO policy including company wide Winter Break (our offices are closed from Christmas Eve to New Year's Day!)
- Paid parental leave
- Fertility and family-building stipend through Carrot
- Company-facilitated 401(k)
- Exposure to a variety of ML startups, offering unparalleled learning and networking opportunities.
Apply now to embark on a rewarding journey in shaping the future of AI! If you are a motivated individual with a passion for machine learning and a desire to be part of a collaborative and forward-thinking team, we would love to hear from you.
At Baseten, we are committed to fostering a diverse and inclusive workplace. We provide equal employment opportunities to all employees and applicants without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.
We are an Equal Opportunity Employer and will consider qualified applicants with criminal histories in a manner consistent with applicable law (by example, the requirements of the San Francisco Fair Chance Ordinance, where applicable).