Security Engineer Infrastructure Security
Figure is an AI robotics company developing general-purpose humanoid robots and its Helix vision-language-action AI system.
Funding history
About Figure
Figure develops and deploys general-purpose humanoid robots for commercial and household tasks. Its current Figure 03 robot is powered by Helix, an onboard generalist vision-language-action model; the company also operates the Index data-collection service.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will secure AI tooling, cloud and data-center networks, and service communications. You will own multi-cloud authentication and authorization, improve workload identity and credential controls, build posture and remediation systems, and define zero-trust network, egress, segmentation, and secure-by-default infrastructure patterns.
Requirements
- Security knowledge of Kubernetes, containers, service mesh, networking, operating system internals, authentication and authorization protocols, or cloud security tools
- Experience developing and deploying services in multi-cloud environments
- Familiarity with at least two of Azure, AWS, or Google Cloud Platform
- 6+ years of security or software development experience
- Strong software engineering skills in C, C++, Rust, Golang, Python, or similar
- Excellent verbal and written communication skills
Responsibilities
- Secure AI tooling deployments, service communications, and network boundaries
- Partner on data-center and cloud network security
- Provide telemetry, access, and context for incident response
- Own multi-cloud authentication and authorization
- Extend identity controls to on-premises and neocloud environments
- Replace long-lived credentials with short-lived, workload-scoped authentication
- Build tooling for inventory, configuration drift detection, and coverage metrics
- Drive remediation for misconfigurations and vulnerabilities
- Design zero-trust networking, egress controls, and secure-by-default network patterns
