Member of Technical Staff — Security Engineering
Summary
Designs and enforces security for a cutting-edge AI startup building a Large Physics Model, protecting petabyte-scale data, GPU clusters, and customer deployments.
Our mission is general causal intelligence; AI that is capable of (1) predicting the future and (2) identifying the actions to alter it.
To achieve this breakthrough, we are building a Large Physics foundation Model (LPM) because physical systems, unlike text or images, are governed by verifiable cause and effect. We believe that scaling on physics will enable an understanding of causality required to predict and control physical systems, starting with weather.
Our founding team has built and deployed AI against the physical world in robotics, drug discovery, and particle physics at institutions like DeepMind, Waymo, Cruise, Insitro, Nabla Bio, and CERN.
About Security at Causal Labs
As we build and deploy our Large Physics Model, we operate an environment that spans petabytes of continuous physical observations, massive distributed GPU clusters, and high-stakes customer deployments.
Your mission is to design and operate the security posture across our entire engineering stack. You will ensure our research environments, proprietary model weights, software infrastructure, and customer integrations remain secure, all while maintaining the rapid iteration and engineering velocity our researchers need.
Responsibilities
Enterprise Infrastructure & Cloud Isolation: Architect secure network perimeters, private data transmission channels (e.g., PrivateLink, VPNs), and isolated single/multi-tenant storage environments. Implement access controls and customer-managed encryption (KMS/BYOK) across petabyte-scale data stores.
Model IP & Weight Protection: Design zero-trust boundaries, encrypted storage, and secure execution environments to protect proprietary foundation model weights and checkpoints against exfiltration during storage, distributed multi-node training, and serving.
Pipeline Integrity & AI Threat Defense: Secure our data ingestion pipelines against tampering and data poisoning. Threat-model and defend against AI-specific vulnerabilities, including adversarial inputs, model extraction attacks, and data memorization/regurgitation risks using output guardrails and privacy-preserving techniques.
Enterprise Auth & Governance: Own enterprise identity federation (SAML 2.0/OIDC with Okta, Entra ID) and machine-to-machine authentication (mTLS). Implement immutable audit logging, cryptographic erasure, and compliance controls required for enterprise CISOs and SOC 2 / FedRAMP environments.
Security Engineering & SDLC: Partner with Infrastructure, Research, and Forward Deployed teams to build automated security testing, threat detection, and vulnerability scanning directly into our deployment workflows, orchestrators (Kubernetes, Slurm), and customer-facing APIs.
What we're looking for
Demonstrated Hands-on Security Engineering: Proven track record building and securing production systems in cloud environments (AWS, GCP, or Azure) or large-scale distributed systems. Practical mastery of core primitives: IAM, network perimeters, KMS/encryption, and secrets management.
Strong Systems & Software Background: Hands-on experience with Linux systems, networking, container security (Docker, Kubernetes), Infrastructure-as-Code (Terraform or Pulumi), and proficiency in languages like Python, Go, or Rust.
Understanding of ML Platform Security: Practical grasp of the security challenges unique to ML platforms—protecting high-value model weights, securing distributed training pipelines, data lineage/poisoning, and AI-specific threat vectors.
Adaptable & High Agency: Comfort conducting architectural security reviews, digging into complex distributed systems, and adapting fast to new technical constraints or bespoke enterprise customer environments.
Bias Toward Real-World Impact: Pragmatic mindset—delivering security solutions that actually work for users under pressure, balancing rigor with engineering velocity.
End-to-End Ownership: Ability to take deliverables autonomously from initial threat modeling and requirements all the way through execution, deployment, and monitoring.