Infrastructure Security Engineer
Listed on 2026-10-01
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations
We are building AI to simulate the world through merging art and science.
We believe that world models are at the frontier of progress in artificial intelligence. Language models alone won’t solve the world’s hardest problems – robotics, disease, scientific discovery. Real progress requires models that experience the world and learn from their mistakes, the same way that humans do. And this kind of trial and error can be massively accelerated when done in simulation, rather than in the real world.
World models offer the most clear path to general-purpose simulation, changing how stories are told, how scientific progress is made and how the next frontiers of humanity are reached.
Our team consists of creative, open minded, caring and ambitious people who are determined to change the world. We aspire to continuously build impossible things and our ability to do so relies on building an incredible team. If you are driven to do the same, we’d love to hear from you.
About the roleOpen to hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.
Runway is hiring an Infrastructure Security Engineer to secure the platform our models are trained and served on. The role covers Kubernetes platform security, cloud identity and access, software supply chain, tenant isolation in the serving layer and the research infrastructure behind our models.
Securing a company that trains and serves frontier video models is a different problem from securing a typical SaaS product. The environment includes research compute, large training datasets, a fast-moving build pipeline, and engineers who work inside AI-assisted tooling every day. Each of those changes what an attack looks like and what the platform has to enforce to stop it.
This is a hands‑on engineering role on the Security team. You’ll write policy, tooling and infrastructure code, work in the platform team’s repositories, and ship controls that hold up in production.
What you’ll doDesign and ship security controls in our Kubernetes ecosystem: admission policy, RBAC, workload identity, network policy and runtime hardening across every cluster we run
Harden the software supply chain from dependency intake through build and deploy, including package firewalling, artifact signing and provenance, and admission controls that block what doesn’t pass
Own cloud IAM and identity architecture: least-privilege roles, short-lived credentials and workload federation
Secure research infrastructure and training pipelines, including access to model weights and datasets, without slowing down the people using them
Threat model new platform components before they ship and turn the findings into concrete requirements the owning team can act on
Build guardrails for AI agents and developer tooling operating inside our infrastructure
Write infrastructure as code and policy as code, and treat security configuration with the same review and rollout discipline as any other change
Give the incident response team what they need when infrastructure is involved: fast answers about how a system works and what to shut off
Hands‑on experience securing Kubernetes in production: you’ve written admission policies, debugged RBAC and workload identity problems and understand how a cluster gets compromised
Working knowledge of cloud IAM and networking on at least one major cloud platform, including how identity federation and short‑lived credentials actually work
Experience with infrastructure as code and Git Ops‑style deployment, and the habit of shipping security changes through the same pipeline as everything else
Comfort writing Python, Typescript, Rust or another language to build tooling, not just scripts
An understanding of software…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).