Summary / TL;DR
About the Role We are looking for a hands-on, judgment-driven Security Infrastructure Engineer with real-world hardening or incident remediation experience, to build the identity and access layer for AI agents from the ground up. This is a newly incubated in-house project. AI agents are already calling APIs, moving funds and making decisions on their own, yet the industry's identity systems were designed for humans, not machines. We are building a different model: machine identities, short-lived credentials, and per-call authorization. As our first security infrastructure engineer, you will first implement identity, credentials and access control on our own systems, then grow that capability into the product itself. Responsibilities Drive the zero-trust access transformation: take all management planes, consoles and databases off the public internet and route them through a unified identity gateway, with mandatory authentication and MFA and no exposed ports Enforce least privilege by default across Kubernetes RBAC, cloud IAM and service accounts, and eliminate over-privileged "one identity runs everything" setups Establish machine identities and short-lived credentials for services and workloads to replace long-lived keys (a SPIFFE/SPIRE-style approach) Migrate secrets to Vault or cloud KMS, and put private keys and sensitive credentials under KMS/HSM custody with rotation and minimal exposure Regularly map exposed assets from an external attacker's perspective (FOFA/Shodan-style), and fix issues as soon as they are found Build audit logging and alerting on critical paths, and deliver an actionable incident response process with drills Requirements Hands-on attack surface reduction or incident remediation experience (core requirement). You have been through, and ideally led, a round of hardening or post-incident remediation. You understand what excessive privileges, readable credentials and exposed entry points mean in a real incident 3+ years of infrastructure security experience in Infrastructure Security, DevSecOps or SRE-Security Strong command of Kubernetes RBAC and IAM on at least one of AWS, GCP or Azure, plus network and ingress security Proficient with HashiCorp Vault or cloud KMS, with a clear understanding of why short-lived credentials are better than long-lived keys Experience implementing zero-trust access through identity gateways or strong authentication. Experience with Teleport, Cloudflare Zero Trust, HashiCorp Boundary or Tailscale is preferred Blockchain or Web3 experience is not required We value practical judgment in systematically shrinking the attack surface over the number of certifications you hold Preferred Qualifications Depth in workload identity: SPIFFE/SPIRE, service mesh identity (Envoy/Istio) and mTLS. Contributions to OAuth/OIDC, FIDO, SPIFFE or related standards and open-source communities Gateway-side experience (strongly preferred): you have built low-latency inline proxies or API gateways and kept P99 latency in check with tools such as APISIX, Envoy, Higress, Cloudflare Workers, Zscaler or Netskope. You can turn access control into online enforcement rather than audit-only Advanced key custody: HSM, MPC wallets or threshold signatures, and hash-chained transparency log engineering A background in cloud-native zero trust or offensive security, such as: teams like Wiz, Orca, Teleport, HashiCorp, Cloudflare or Tailscale the non-human identity space, including the SPIFFE/SPIRE community red teaming or penetration testing infrastructure security or SRE-Security teams at major tech companies