Security Engineer

Nous Research is an applied AI research group that develops and releases open-source AI models, datasets, and tools to democratize artificial intelligence.

Series A0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/2/2026

Distributed
About Nous Research

Nous Research is a leader in the development of human-centric language models and simulators, with a primary focus on model architecture, data synthesis, fine-tuning, and reasoning to align AI with real-world user experiences. As an applied research group, they aim to democratize AI development by releasing open-source resources like datasets (e.g., Hermes 3 Dataset), AI models (e.g., Hermes 3, DeepHermes), and frameworks. A key project is the Psyche Network, an open infrastructure for AI development, and they also engage in on-chain evaluations, indicating an intersection with blockchain technology. Additionally, Nous Research provides an OpenAI-compatible API for its models, operating on a pay-per-use basis with pricing determined by token consumption.

View jobs by Nous Research

Skills

About the Role

You will own security across multi-cloud infrastructure, products, and enterprise deployments. You will secure SaaS and Kubernetes environments, harden identity and access controls, manage SOC 2 controls and evidence, lead vulnerability and incident-response work, improve secure development practices, and support enterprise security reviews.

Requirements

  • 8+ years of security engineering experience
  • Infrastructure and multi-cloud security expertise
  • Experience securing production SaaS environments
  • Kubernetes
  • identity and IAM
  • SSO
  • SAML
  • SCIM
  • Experience implementing SOC 2 or ISO 27001 engineering programs
  • Vulnerability management
  • Incident response
  • Access control
  • Penetration testing
  • Secure software development
  • Knowledge of agent identity, tool permissions, prompt injection, and data provenance

Responsibilities

  • Own production security across AWS, GCP, Azure, and Vercel
  • Secure SaaS, dedicated VPC, self-hosted Kubernetes, and air-gapped deployments
  • Secure the agent platform through sandboxing, isolation, identity, credential, egress, and trace-integrity controls
  • Own SOC 2 technical controls, evidence collection, remediation, and readiness
  • Harden identity and access management, SSO, SAML, least-privilege reviews, 2FA, and BYOD policies
  • Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring
  • Strengthen secure software development lifecycle controls
  • Complete security questionnaires, lead architecture reviews, and address penetration-testing requirements
  • Identify and address security risks with internal stakeholders