Staff Security Engineer, Infrastructure
fal is an active generative-media AI platform for developers, providing optimized model APIs, serverless deployment, and GPU compute.
Funding history
About fal
Founded in 2021 by Burkay Gur and Gorkem Yurtseven, fal provides infrastructure for production generative-media applications, including image, video, audio, 3D, and multimodal models.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will secure cloud, Kubernetes, networking, CI/CD, GPU compute, and data systems. You will implement identity, secrets, encryption, and least-privilege controls; protect model weights and customer data; automate security guardrails through infrastructure as code; identify and remediate risks; and partner with engineering functions to enable secure-by-default systems.
Requirements
- 8+ years in security engineering, infrastructure, or SRE
- Cloud security knowledge in AWS, GCP, or Azure
- Networking knowledge, including segmentation, firewalls, and Zero Trust
- Linux systems and container security knowledge, including Docker and Kubernetes
- Experience building or securing production infrastructure at scale
- Knowledge of authentication, authorization, secrets management, cryptography, vulnerabilities, and attack vectors
- Ability to design multilayer security controls
- Proficiency in Go, Python, or a similar language
- Infrastructure-as-code experience, preferably Terraform
- Experience with GPU infrastructure or ML systems
- Experience with multi-tenant platform isolation
- Experience with service mesh or zero-trust architectures
Responsibilities
- Design and implement security controls for cloud infrastructure, Kubernetes, networking, CI/CD, and GPU workloads
- Implement machine identity, workload authentication, secrets management, encryption, and least-privilege access
- Apply Zero Trust principles across infrastructure
- Protect model weights, inference endpoints, and customer data
- Design secure data-access pathways and multi-tenant isolation mechanisms
- Build automated infrastructure and CI/CD security guardrails
- Use infrastructure as code to enforce secure defaults
- Identify and remediate infrastructure security gaps through automation
- Identify and mitigate risks across infrastructure layers
- Drive network isolation, encryption, and secure service communication projects
- Partner with platform, infrastructure, and ML teams on shift-left security
Benefits
- Equity
- Visa sponsorship
- Relocation assistance to San Francisco
- Health, dental, and vision insurance
- Regular team events and offsites
