Security Engineer
Nous Research is an applied AI research group that develops and releases open-source AI models, datasets, and tools to democratize artificial intelligence.
Maintainer signals as of 9/2/2026
Funding history
About Nous Research
Nous Research is a leader in the development of human-centric language models and simulators, with a primary focus on model architecture, data synthesis, fine-tuning, and reasoning to align AI with real-world user experiences. As an applied research group, they aim to democratize AI development by releasing open-source resources like datasets (e.g., Hermes 3 Dataset), AI models (e.g., Hermes 3, DeepHermes), and frameworks. A key project is the Psyche Network, an open infrastructure for AI development, and they also engage in on-chain evaluations, indicating an intersection with blockchain technology. Additionally, Nous Research provides an OpenAI-compatible API for its models, operating on a pay-per-use basis with pricing determined by token consumption.
Skills
About the Role
You will own security across multi-cloud infrastructure, products, and enterprise deployments. You will secure SaaS and Kubernetes environments, harden identity and access controls, manage SOC 2 controls and evidence, lead vulnerability and incident-response work, improve secure development practices, and support enterprise security reviews.
Requirements
- 8+ years of security engineering experience
- Infrastructure and multi-cloud security expertise
- Experience securing production SaaS environments
- Kubernetes
- identity and IAM
- SSO
- SAML
- SCIM
- Experience implementing SOC 2 or ISO 27001 engineering programs
- Vulnerability management
- Incident response
- Access control
- Penetration testing
- Secure software development
- Knowledge of agent identity, tool permissions, prompt injection, and data provenance
Responsibilities
- Own production security across AWS, GCP, Azure, and Vercel
- Secure SaaS, dedicated VPC, self-hosted Kubernetes, and air-gapped deployments
- Secure the agent platform through sandboxing, isolation, identity, credential, egress, and trace-integrity controls
- Own SOC 2 technical controls, evidence collection, remediation, and readiness
- Harden identity and access management, SSO, SAML, least-privilege reviews, 2FA, and BYOD policies
- Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring
- Strengthen secure software development lifecycle controls
- Complete security questionnaires, lead architecture reviews, and address penetration-testing requirements
- Identify and address security risks with internal stakeholders
