Security Engineer

Open-source AI company that trains models, builds AI agents, and develops distributed-training infrastructure.

Series A14 current maintainers11 active leadsTeam intelligence

Maintainer signals as of 9/24/2026

Distributed
About Nous Research

Nous Research develops open AI models, the Hermes Agent, Nous Portal, and distributed-training technology. Its current site presents an installable, open-source agent and a paid cloud/model-access service.

View jobs by Nous Research

Skills

About the Role

You will secure multi-cloud production environments and deployment models. You will own security controls and readiness, harden identity and access management, lead vulnerability management and incident response, strengthen secure development practices, support enterprise security reviews, and address security risks across systems.

Requirements

  • 8+ years of security engineering experience
  • Infrastructure and multi-cloud security expertise
  • Production SaaS security experience
  • Kubernetes, identity, IAM, SSO, SAML, and SCIM knowledge
  • SOC 2 or ISO 27001 engineering program experience
  • Vulnerability management, incident response, access control, penetration testing, and secure software development knowledge
  • Agentic AI security knowledge
  • Regulated customer, financial services, or air-gapped deployment experience
  • Cloud-native detection and response tooling experience
  • Kernel-level sandboxing, network isolation, and agent security familiarity

Responsibilities

  • Own production security across AWS, GCP, Azure, and Vercel
  • Secure SaaS, VPC, Kubernetes, and air-gapped deployments
  • Secure the agent platform through sandboxing, isolation, identity, credential, egress, and trace controls
  • Own SOC 2 technical controls, evidence collection, remediation, and readiness
  • Harden identity and access management, SSO, SAML, access reviews, 2FA, and BYOD policies
  • Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring
  • Strengthen secure software development lifecycle controls
  • Complete security questionnaires, lead architecture reviews, and address penetration-testing requirements
  • Identify and address security risks with cross-functional partners