Padmi
Security Level 5 logo
Security Level 5

AI security · frontier model defense

Member of Technical Staff (Secure Infrastructure and Platform)

San Francisco Bay Area · Onsite$200k–$350k/yrPosted 27 days ago
SecurityUnspecifiedFull Time
Apply at Security Level 5

Opens the source posting on jobs.ashbyhq.com

Source description

About the role

View original

About Security Level 5

Security Level 5 is a Bay Area AI security nonprofit working with AI labs and US intelligence agencies to defend frontier models from priority nation-state-level threats. We're a small technical team, we move fast, and we're growing quickly this year.

The Mission

We're hiring for what's plausibly the most difficult, urgent, and interesting challenge in AI security engineering this decade (for humans, at least): designing and building the first datacenter purpose-built to Security Level 5, the standard for defending frontier AI labs against attackers with the resources of a nation-state and billion-dollar budgets. We're working on the first SL5 components this year and aiming for an at-scale SL5 datacenter build in 2027.

We wrote the first version of the standard with input from CISOs and senior security staff at the frontier labs, and US security and intelligence officials. Now we're designing the SL5 architectures purpose-built for frontier AI workloads, and standing up the reference tech stack to guide labs' buildouts. This stack has to hold against nation-states, not destroy researchers' productivity, not cost more than labs can pay, and ship in 2-3 years.

About the role

An SL5 datacenter requires infrastructure engineering at the frontier of security. You would set up and operate networks with extremely strict security properties, zero-trust concepts and bespoke security components, all without Internet access and still capable of training large models. The network you'll be building won't actually be SL5, but will implement the novel and difficult security interventions needed for it. We're looking for someone who has designed / operated large production infrastructure and wants to solve that problem under these constraints, from setting up the racks to maintaining orchestration.

What you'd work on

  • Designing and standing up the SL5 prototype compute platform: setting up racks, configuring networks and device security policy & attestation, imaging, enrollment, build server etc.

  • Deny-all, permit-by-exception execution with no live internet: measured boot and signed images on hosts, allow-listing enforcement, and the pipeline by which images and updates get built and signed.

  • Making the platform fast and usable for researchers despite the constraints, and re-shaping workflows where the old cloud-native habits don't survive contact with an air gap.

  • Co-developing the relevant infrastructure and machine-security sections of the SL5 standard with labs and government stakeholders.

  • Publishing research for technical and policy audiences (with appropriate sensitivity).

You'd be a fit if you

  • Have 5+ years building and operating production infrastructure at scale: cloud platform, SRE, datacenter, ML infra, or similar, ideally including GPU/accelerator fleets

  • Or have 2+ years building and stress-testing training infrastructure at a frontier AI lab. We've seen people without these credentials succeed at some of our most difficult tasks, so if that's you, let us know why you'll succeed anyway.

  • Are comfortable with the primitives this depends on: secure boot, attestation, code signing, key management, image/build pipelines, network segmentation

  • Have worked in, or can clearly reason about, environments where the internet isn't available and the host can't be trusted (air-gapped, classified, or otherwise hard-isolated)

  • Communicate clearly with both technical and non-technical stakeholders, including ML researchers whose cloud-native intuitions about tooling may need to be re-shaped

  • Want your security work to matter outside the company shipping it

Bonus

  • Experience with confidential computing, TEEs, or accelerator security features (memory isolation, interconnect encryption, attestation)

  • Experience running air-gapped, classified, or other high-side environments, or building cross-domain / data-diode transfer systems

  • Existing security clearances or clearance eligibility

  • Experience where infrastructure speed and security were in direct tension and you had to ship both

Logistics

Bay Area, in-person. This role's base salary range is $200,000 - $350,000 USD per year. We may be open to paying exceptional and/or highly experienced employees more than this. We also provide full benefits, including healthcare, dental, vision, 401k match, and more.

More at Security Level 5

Related open roles

View all roles
Member of Technical Staff (Secure Infrastructure and Platform) at Security Level 5 · Padmi