Back to Jobs
RunwayML
Engineering & Architecture 4h ago

Infrastructure Security Engineer

RunwayML
🌍Global
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

CybersecurityGitOpsKubernetesCloud IAMInfrastructure as Code

Want to know if you're a match for this job?

Calculate My Match Score

We are building AI to simulate the world through merging art and science. World models are at the frontier of progress in artificial intelligence. Language models alone won’t solve the world’s hardest problems—robotics, disease, scientific discovery. Real progress requires models that experience the world and learn from their mistakes, the same way humans do. This kind of trial and error can be massively accelerated when done in simulation, rather than in the real world.

World models offer the most clear path to general-purpose simulation, changing how stories are told, how scientific progress is made, and how the next frontiers of humanity are reached.

Our team consists of creative, open-minded, caring, and ambitious people who are determined to change the world. We aspire to continuously build impossible things, and our ability to do so relies on building an incredible team.

About the Role

Runway is hiring an Infrastructure Security Engineer to secure the platform our models are trained and served on. The role covers Kubernetes platform security, cloud identity and access, software supply chain, tenant isolation in the serving layer, and the research infrastructure behind our models.

Securing a company that trains and serves frontier video models is a different problem from securing a typical SaaS product. The environment includes research compute, large training datasets, a fast-moving build pipeline, and engineers who work inside AI-assisted tooling every day. Each of these changes what an attack looks like and what the platform has to enforce to stop it.

This is a hands-on engineering role on the Security team. You'll write policy, tooling, and infrastructure code, work in the platform team's repositories, and ship controls that hold up in production.What You'll Do

  • Design and ship security controls in our Kubernetes ecosystem: admission policy, RBAC, workload identity, network policy, and runtime hardening across every cluster we run
  • Harden the software supply chain from dependency intake through build and deploy, including package firewalling, artifact signing and provenance, and admission controls that block what doesn't pass
  • Own cloud IAM and identity architecture: least-privilege roles, short-lived credentials, and workload federation
  • Secure research infrastructure and training pipelines, including access to model weights and datasets, without slowing down the people using them
  • Threat model new platform components before they ship and turn the findings into concrete requirements the owning team can act on
  • Build guardrails for AI agents and developer tooling operating inside our infrastructure
  • Write infrastructure as code and policy as code, and treat security configuration with the same review and rollout discipline as any other change
  • Give the incident response team what they need when infrastructure is involved: fast answers about how a system works and what to shut off

What You'll Need

  • Hands-on experience securing Kubernetes in production: you've written admission policies, debugged RBAC and workload identity problems, and understand how a cluster gets compromised
  • Working knowledge of cloud IAM and networking on at least one major cloud platform, including how identity federation and short-lived credentials actually work
  • Experience with infrastructure as code and GitOps-style deployment, and the habit of shipping security changes through the same pipeline as everything else
  • Comfort writing Python, TypeScript, Rust, or another language to build tooling, not just scripts
  • An understanding of software supply chain attacks and the controls that stop them: signing, provenance, SBOMs, admission enforcement
  • Clear writing. Design docs, threat models, and explanations to engineers who don't work in security are all part of the job
  • Judgment about which controls to enforce, which to recommend, and how to roll out a breaking change without breaking the company

Even Better If You Have

  • Experience securing GPU or HPC-style compute, training pipelines, or research environments
  • Experience with policy engines and admission controllers (Kyverno, OPA Gatekeeper, Falco, or similar)
  • Multi-tenant isolation design in a cloud environment: ABAC, scoped credentials, per-tenant boundaries
  • Experience producing security architecture evidence for SOC 2, ISO 27001, or other audits and customer assessments
  • Open-source contributions or published work in cloud or Kubernetes security

How would you rate this job post?

See what other professionals think about this role.

banner

RunwayML is a technology company that specializes in AI and machine learning, empowering creatives to generate and manipulate digital content with unprecedented ease. By leveraging cutting-edge algorithms and intuitive interfaces, RunwayML provides a suite of innovative tools designed to streamline workflows, unlock new possibilities, and push the boundaries of what is possible in the realms of art, design, and beyond. With a strong focus on usability, accessibility, and scalability, RunwayML addresses the needs of a diverse range of users, from independent artists to large-scale enterprises, all while maintaining a commitment to advancing the state-of-the-art in AI research and development. Through its innovative products and services, RunwayML aims to democratize access to AI-powered creativity, fostering a vibrant community of like-minded individuals and organizations who share a passion for exploring the frontiers of digital expression. By harnessing the power of machine learning and artificial intelligence, RunwayML is poised to revolutionize the way we create, collaborate, and interact with digital media, opening up new avenues for artistic expression, entrepreneurial innovation, and technological advancement.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More