MTS Technology and Security Engineering

Reflection is an AI research lab building open frontier models and a full AI stack for developers, enterprises, and public-sector users.

New York, United States
About Reflection

Reflection develops open-weight AI models, open-source software for customizing and running agents, AI-factory infrastructure, and related solutions. Its current research emphasizes large language models, reinforcement learning, and agentic reasoning.

View jobs by Reflection

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will architect and operate security engineering across endpoint computing, multi-cloud research infrastructure, GPU training environments, access controls, security-as-code, detection engineering, compliance, and vendor risk. You will create resilient guardrails that protect sensitive systems while preserving effective researcher and developer workflows.

Requirements

  • 7+ years of deep engineering experience
  • Experience building and operating security engineering functions at scale
  • Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, audits, and security reviews
  • Experience leading vendor risk, procurement security reviews, and legal contract negotiations
  • Experience with physical and data-center security operations
  • Knowledge of Linux and macOS internals and NVIDIA GPU security
  • Expert knowledge of public cloud, IAM governance, Kubernetes, and container isolation
  • Knowledge of cloud security, Zero Trust, security operations, detection and response, automation, and orchestration

Responsibilities

  • Design and manage a resilient corporate device fleet across Linux, macOS, Windows, and NVIDIA GPU workstations
  • Implement posture verification and cryptographic device binding
  • Secure developer toolchains and local environments
  • Architect cloud-native security controls for multi-cloud GPU clusters
  • Establish IAM governance, network segmentation, and isolation boundaries
  • Implement continuous context-aware authorization and hardware-backed authentication
  • Replace standing access with just-in-time authorization
  • Declare infrastructure, endpoint configurations, IAM policies, and cloud environments as code
  • Build automated CI/CD validation and continuous compliance checks
  • Build telemetry pipelines for high-fidelity security logs
  • Detect post-exploitation, lateral movement, and living-off-the-land attacks
  • Support compliance, audits, vendor risk reviews, procurement reviews, and security contract negotiations
  • Own physical and data-center security operations

Benefits

  • Stock options
  • Comprehensive medical, dental, vision, and life insurance
  • Annual wellness allowance
  • Daily office lunch and dinner
  • 22 weeks of paid parental leave
  • Unlimited paid time off in the U.S.
  • 30 days of paid time off in the U.K.
  • Visa sponsorship support
  • Regular off-sites, happy hours, and team celebrations
MTS Technology and Security Engineering at Reflection | JobStash