Security Engineer
Nous ResearchVisit Nous Research website
Open-source AI company that trains models, builds AI agents, and develops distributed-training infrastructure.
Nous Research on X (Twitter)Nous Research on DiscordNous Research on GitHubNous Research on Documentation
Maintainer signals as of 9/24/2026
Distributed
Funding history
About Nous Research
Nous Research develops open AI models, the Hermes Agent, Nous Portal, and distributed-training technology. Its current site presents an installable, open-source agent and a paid cloud/model-access service.
Skills
About the Role
You will secure multi-cloud production environments and deployment models. You will own security controls and readiness, harden identity and access management, lead vulnerability management and incident response, strengthen secure development practices, support enterprise security reviews, and address security risks across systems.
Requirements
- 8+ years of security engineering experience
- Infrastructure and multi-cloud security expertise
- Production SaaS security experience
- Kubernetes, identity, IAM, SSO, SAML, and SCIM knowledge
- SOC 2 or ISO 27001 engineering program experience
- Vulnerability management, incident response, access control, penetration testing, and secure software development knowledge
- Agentic AI security knowledge
- Regulated customer, financial services, or air-gapped deployment experience
- Cloud-native detection and response tooling experience
- Kernel-level sandboxing, network isolation, and agent security familiarity
Responsibilities
- Own production security across AWS, GCP, Azure, and Vercel
- Secure SaaS, VPC, Kubernetes, and air-gapped deployments
- Secure the agent platform through sandboxing, isolation, identity, credential, egress, and trace controls
- Own SOC 2 technical controls, evidence collection, remediation, and readiness
- Harden identity and access management, SSO, SAML, access reviews, 2FA, and BYOD policies
- Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring
- Strengthen secure software development lifecycle controls
- Complete security questionnaires, lead architecture reviews, and address penetration-testing requirements
- Identify and address security risks with cross-functional partners
