Modal logo

Infrastructure Security Engineer

Modal

New York, NYFull-time$150–270K/yrPosted 5mo agoStill listed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$150–270K/yr
Location
New York, NY
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Modal is hiring an Infrastructure Security Engineer. Modal is building a new AI infrastructure layer. The Infrastructure Security Engineer will design and secure core systems, focusing on container isolation, orchestration, identity, and secrets management in a multi-tenant cloud‑native environment. The role is hands‑on, technical, and works closely with product and infrastructure teams to embed security into the platform by design.

Key focus areas include Design and improve isolation mechanisms for multi-tenant workloads, Strengthen boundaries between customers, workloads, and internal systems, and Identify and mitigate risks in distributed, dynamic compute environments.

Successful candidates bring Experience Securing Cloud-Native Infrastructure In Production, Experience Securing Distributed Systems In Production, and Background In Infrastructure Engineering. Important skills include Container Isolation, Orchestration, Identity Management, Secrets Management, Multi-Tenant Cloud-Native Environment, and Platform Security. Preferred (not required): Sandboxing, gVisor, Firecracker, and seccomp.

Skills & qualifications

RequiredNice to have

Skills

Container IsolationOrchestrationIdentity ManagementSecrets ManagementMulti-Tenant Cloud-Native EnvironmentPlatform SecurityRuntime SecuritySandboxingExecution EnvironmentsDistributed Systems SecurityDynamic Compute EnvironmentsContainerized Workloads SecurityKubernetesWorkload IsolationScheduling BoundariesRuntime ProtectionsAuthenticationAuthorizationService-to-Service IdentityLeast-Privilege Access PatternsAccess ControlsKey ManagementSecrets RotationAuditingCloud SecurityAWSGCPNetwork BoundariesService SegmentationInfrastructure as CodeDeployment SystemsArchitecture ReviewCode ReviewSecuring Cloud-Native InfrastructureSecuring Distributed SystemsContainerizationService Identity ModelsSecure Handling of CredentialsNetworking ConceptsService CommunicationAccess BoundariesBuilder MentalityPragmatic Approach to SecurityInfluencing System DesigngVisorFirecrackerSeccompKernel-Level Isolation PrimitivesLow-Level Isolation Primitives

Qualifications

Experience Securing Cloud-Native Infrastructure in ProductionExperience Securing Distributed Systems in ProductionBackground in Infrastructure EngineeringBackground in Backend EngineeringBackground in Security EngineeringExperience Working in Multi-Tenant EnvironmentsExperience Working in High-Scale EnvironmentsExperience Designing Isolation Mechanisms in Multi-Tenant SystemsExperience With Secrets ManagementExperience With Sandboxing TechnologiesExperience With Runtime Isolation TechnologiesBackground in Developer Infrastructure

Full job description

ABOUT US:

AI needs a new infrastructure layer. We're building it at Modal.

Every era of computing brought new workloads that previous infrastructure couldn't support: mainframes, databases, and the cloud. Each time, the company that rebuilt the layer underneath defined the decade. AI is no different, except it touches everything instead of one slice, and the window to build the layer underneath it is open right now.

Our customers include category-defining companies like Lovable https://modal.com/blog/lovable-case-study, Ramp https://modal.com/blog/how-ramp-built-a-full-context-background-coding-agent-on-modal, Cognition, DoorDash, and Suno. They rely on Modal for instant GPU access, sub-second container starts, and native storage, so it's simple to serve low-latency inference, fine-tune models, and access production-ready sandboxes at scale.

We recently raised a $355M Series C https://modal.com/blog/modal-series-c at a $4.65B valuation, led by General Catalyst and Redpoint Ventures. We've crossed $300M+ ARR and grown fivefold since September.

Our team includes creators of popular open-source projects (e.g.,Seaborn https://github.com/mwaskom/seaborn,Luigi https://github.com/spotify/luigi), academic researchers, international olympiad medalists, and experienced engineering and product leaders with decades of experience.

THE ROLE:

We’re looking for an Infrastructure Security Engineer to design and secure the core systems that power our platform. This role focuses on building security directly into our infrastructure—from container isolation and orchestration to identity and secrets management in a multi-tenant, cloud-native environment.

You’ll work closely with engineering teams to define secure primitives and ensure our platform is resilient, scalable, and trustworthy by design.

This is a hands-on, deeply technical role focused on real systems, not compliance or policy.

WHAT YOU'LL DO:

Platform & Runtime Security

  • Design and improve isolation mechanisms for multi-tenant workloads (containers, sandboxing, execution environments)

  • Strengthen boundaries between customers, workloads, and internal systems

  • Identify and mitigate risks in distributed, dynamic compute environments

Container & Orchestration Security

  • Secure and harden containerized workloads and orchestration systems (e.g., Kubernetes or similar)

  • Improve workload isolation, scheduling boundaries, and runtime protections

  • Evaluate tradeoffs in multi-tenant execution models

Identity & Access Management

  • Design and improve authentication and authorization systems across services

  • Implement strong service-to-service identity and least-privilege access patterns

  • Improve access controls across infrastructure and internal systems

Secrets & Key Management

  • Build and maintain systems for securely managing secrets, tokens, and credentials

  • Improve rotation, auditing, and access controls

  • Reduce secret sprawl and integrate secure patterns into developer workflows

Cloud & Infrastructure Security

  • Secure cloud environments across providers (AWS, GCP, etc.) with a focus on consistency and portability

  • Improve network boundaries, service segmentation, and access controls

  • Embed security into infrastructure-as-code and deployment systems

Engineering Partnership

  • Work closely with product and infrastructure teams to design secure systems from the ground up

  • Review architecture and code for security risks and provide actionable guidance

  • Identify patterns in risks and drive cross-cutting improvements

REQUIREMENTS:

Core Experience

  • Experience securing cloud-native infrastructure and distributed systems in production

  • Background in infrastructure, backend, or security engineering

  • Experience working in multi-tenant or high-scale environments

Technical Depth

  • Strong understanding of containerization and orchestration systems (e.g., Kubernetes or similar)

  • Experience designing or securing isolation mechanisms in multi-tenant systems

  • Solid understanding of authentication, authorization, and service identity models

  • Experience with secrets management and secure handling of credentials

  • Strong foundation in networking concepts (segmentation, service communication, access boundaries)

Mindset

  • Builder mentality, you design and implement, not just review

  • Pragmatic approach to security in fast-moving environments

  • Comfortable working deeply with engineers and influencing system design

PREFERRED QUALIFICATIONS:

  • Experience with sandboxing or runtime isolation technologies (e.g., gVisor, Firecracker, seccomp, or similar)

  • Familiarity with kernel-level or low-level isolation primitives

  • Experience securing Kubernetes or similar orchestration systems in production

  • Background in developer infrastructure, compute platforms, or multi-tenant systems

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.