← Back to results

Member of Technical Staff, Vulnerability Management

Join Inferact as a Member of Technical Staff to manage vulnerability processes for vLLM's AI infrastructure.

Location
San Francisco, California, United States
Compensation
$200k–$400k/yr
Level
staff
Type
full time · Hybrid

Posted by employer 20 hours ago

First seen on Joblaze 8 hours ago

Last verified on the company career page 8 hours ago

Apply at Inferact → Save job Scanned from inferact.ai

What you'll build

  • Own vulnerability-management process
  • Investigate vulnerability reports
  • Coordinate fixes and security advisories
  • Identify security best practices
  • Collaborate with engineers and researchers

Must have

  • Hands-on product security experience
  • Ability to read source code
  • Strong systems reasoning
  • Sound prioritization and risk-assessment judgment
  • Strong written and verbal communication

Nice to have

  • Experience with vulnerability management for open-source software
  • Experience coordinating vulnerability resolution
  • Familiarity with vLLM or ML infrastructure
  • Experience preparing security advisories
  • Experience translating security findings into architecture reviews

Requirements

Visa
Sponsorship available

Not disclosed in this posting: years of experience.

Joblaze summary

In the role of Member of Technical Staff for Vulnerability Management at Inferact, the individual will oversee the vulnerability management process for vLLM, ensuring the security and reliability of this AI infrastructure. Key skills include hands-on product security experience, a strong grasp of complex software systems, and the ability to communicate effectively with various stakeholders. This position is suited for someone with a solid background in security practices, particularly in open-source environments, and a knack for technical investigation. The role involves collaboration with maintainers and external security experts, emphasizing a proactive approach to identifying and resolvin

Joblaze insights

  • Listed today — first seen on Joblaze October 3, 2026. Last confirmed on Inferact's careers page October 3, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 41% of 75 comparable staff security roles in United States we track (median $200,000 across 31 companies).
  • Vulnerability Management appears in 4.2% of 96 comparable staff security roles in United States.

Quick facts

Is the Member of Technical Staff, Vulnerability Management role remote?
It's hybrid — Inferact expects some on-site time in San Francisco, California, United States.
What's the salary range?
Inferact lists $200,000–$400,000 for this role.
Where is the role based?
Inferact is hiring for this position in San Francisco, California, United States.
What's the tech stack?
Joblaze extracted these technologies from the posting: Infrastructure software, Open Source, Vulnerability Management, security best practices, vLLM.
Does Inferact sponsor work visas for this role?
Yes — the posting indicates visa sponsorship is available for the right candidate.
What seniority level is this role?
Inferact targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Member of Technical Staff, Vulnerability Management role at Inferact.

From the original posting

About the Role

We're looking for a Member of Technical Staff, Vulnerability Management to own Inferact's side of vLLM's vulnerability-management process and help keep a critical piece of AI infrastructure secure and production-grade. You'll develop a deep understanding of vLLM's architecture, independently investigate vulnerability reports, and turn technical findings into clear, actionable work for the core team.

Working primarily in open source, you'll collaborate with vLLM maintainers, Red Hat counterparts, security firms, and researchers working with frontier AI models. You'll drive reports from initial triage through analysis and resolution, helping coordinate fixes, security advisories, and releases under the project's established process. You'll also identify practical security best practices that strengthen vLLM as it evolves. This is a hands-on product security role that combines technical investigation, sound judgment, and ownership of follow-through.

vLLM's vulnerability-management process

Skills and Qualifications

Minimum qualifications:

  • Hands-on product security experience, with a strong orientation toward infrastructure software and the security of complex software systems.

  • Ability to read source code, debug unfamiliar systems, reproduce reported issues, and explain root cause and practical security impact rather than simply forward findings.

  • Strong systems reasoning, including the ability to understand architecture, trust boundaries, deployment assumptions, and how different software components interact.

  • Ability to learn vLLM's core architecture and independently manage vulnerability investigations while bringing in maintainers where their expertise is needed.

  • Sound prioritization and risk-assessment judgment, with clear documentation of evidence, affected behavior, remediation needs, and next steps.

  • Strong written and verbal communication, discretion with sensitive reports, and the ability to work constructively with engineers, researchers, and external security collaborators.

     

Preferred qualifications:

  • Experience with vulnerability management and security best practices for open-source infrastructure software.

  • Experience coordinating vulnerability resolution across reporters, maintainers, security teams, and software releases.

  • Familiarity with vLLM, inference engines, ML infrastructure, or similarly complex distributed software; prior vLLM contributions are helpful but not required.

  • Experience preparing security advisories, assessing affected versions, and working with CVE and coordinated-disclosure workflows.

  • Experience translating security findings into practical architecture reviews, regression tests, secure development practices, or deployment guidance.

     

Bonus points if you have:

  • Helped resolve vulnerabilities in an open-source infrastructure project and can explain your technical contribution and coordination with maintainers.

  • Built security tooling or automation that improved investigation quality or reduced repetitive triage work.

  • Turned recurring vulnerability patterns into maintainable fixes, tests, or documentation that helped prevent similar issues.

Logistics

  • Location: This role is based in San Francisco, California. Will consider remote in the US for exceptional candidates.

  • Compensation: Depending on background, skills, and experience, the expected annual salary range for this position is $200,000 - $400,000 USD + equity.

  • Benefits: Applicable benefits will be confirmed based on the final role location.

Standard company text repeated across Inferact's postings is omitted here.

Similar positions

Inferact
Inferact
Member of Technical Staff, Forward Deployed Engineer
Inferact · San Francisco, California, United States
Inferact
Head of Engineering
Inferact · San Francisco
Inferact
Inferact
IT Systems & Operations Engineer
Inferact · San Francisco