← Back to results

MTS, Technology & Security Engineering

Lead the security engineering function at Reflection AI, ensuring robust protection for sensitive assets in a fast-paced research environment.

Location
New York, NY, United States
Compensation
Not disclosed
Level
lead
Type
full time

Posted by employer 2 days ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Reflection AI → Save job Scanned from reflection.ai

What you'll build

  • Design and manage a corporate device fleet
  • Architect cloud-native security controls
  • Implement continuous, context-aware authorization
  • Ensure infrastructure and configurations are declared in code
  • Build telemetry pipelines for detection

Must have

  • 7+ years of deep engineering experience
  • Experience supporting SOC 2, ISO 27001, FedRAMP
  • Experience leading vendor risk assessments
  • Experience with physical security and data center operations

Nice to have

  • Experience with specialized hardware security
  • Expert-level knowledge of public cloud architectures
  • Technical understanding of Kubernetes and container security

Requirements

Experience
7+ years
Visa
Sponsorship available

Not disclosed in this posting: compensation, work arrangement.

Benefits

Unlimited PTO Equity/Stock Options Team Building Health Insurance Parental Leave

Joblaze summary

In the role of MTS for Technology & Security Engineering, the individual is tasked with architecting and managing the security framework that safeguards Reflection AI's corporate and research environments. This position demands expertise in a range of technologies, including cloud security, zero-trust architectures, and security automation, alongside strong leadership capabilities to navigate complex security challenges. Ideal candidates will have extensive experience in high-stakes environments, particularly in security engineering, and a mindset geared towards enabling research while maintaining robust defenses.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 19, 2026. Last confirmed on Reflection AI's careers page September 19, 2026.
  • Terraform appears in 18.8% of 48 comparable lead security roles in United States; NIST CSF appears in 2.1% of 48 comparable lead security roles in United States.

Quick facts

How much experience is required?
At least 7 years of relevant experience for this MTS, Technology & Security Engineering role.
What's the tech stack?
Joblaze extracted these technologies from the posting: FedRAMP, IAM governance, ISO 27001, Kubernetes, Linux, NIST CSF.
Does Reflection AI sponsor work visas for this role?
Yes — the posting indicates visa sponsorship is available for the right candidate.
What seniority level is this role?
Reflection AI targets lead candidates for this position.
Is this full-time or contract?
Full-time for this MTS, Technology & Security Engineering role at Reflection AI.

From the original posting

Role Overview

As a MTS for Technology & Security Engineering is responsible for architecting and operating the security engineering foundation that protects the organization’s corporate environment, multi-cloud research infrastructure, and multi-million-dollar GPU training capacity. This leader owns the full technical security stack — from end-user compute and zero-trust access to cloud and container security, detection engineering, and security-as-code — ensuring the organization can move at research speed without sacrificing rigor.

Sitting at the intersection of security engineering, infrastructure, and research operations, this role is uniquely positioned to define how a frontier AI company protects its most sensitive assets — model weights, training data, and GPU capacity — while preserving the low-friction environment researchers and engineers need to do their best work. The ideal candidate brings deep, hands-on technical depth alongside the executive presence to lead a security engineering function, represent the organization’s security posture to auditors and enterprise customers, and negotiate vendor and contractual risk.

This is a high-visibility, high-impact role that operates across engineering, infrastructure, legal, and physical security. Success requires the ability to design guardrails rather than gates, build systems that assume compromise, and operate credibly as both an executive leader and a hands-on builder.

What You'll Do

High-Performance End User Compute (EUC)

  • Design and manage a highly resilient corporate device fleet spanning Linux, macOS, Windows and specialized hardware such as NVIDIA GPU workstations.

  • Shift the fleet away from restrictive MDM policies toward intelligent posture verification and cryptographic device binding, reducing friction without reducing assurance.

  • Secure diverse local toolchains and developer environments without breaking the workflows researchers and engineers depend on.

Securing the Research & Training Boundary

  • Architect cloud-native security controls across multi-cloud environments that contain multi-million-dollar GPU clusters.

  • Establish IAM governance, network segmentation, and isolation boundaries appropriate to the scale and sensitivity of training infrastructure and model assets.

  • Partner with infrastructure and research teams to ensure security controls scale with GPU capacity rather than constrain it.

Phishing-Resistant Zero-Trust Access

  • Implement continuous, context-aware authorization using modern mesh networks and proxies (e.g., Tailscale, Cloudflare One).

  • Enforce hardware-backed authentication (WebAuthn/FIDO2 keys) across every corporate and production plane.

  • Eliminate standing and persistent access in favor of just-in-time, verifiable authorization.

Security as Code (SaC)

  • Ensure 100% of infrastructure, endpoint configurations, IAM policies, and cloud environments are declared in code (Terraform/Pulumi).

  • Eliminate configuration drift through automated CI/CD validation and continuous compliance checks.

  • Build repeatable, auditable deployment pipelines that make security posture provable rather than assumed.

Behavioral Detection Engineering

  • Build telemetry pipelines that ingest high-fidelity logs into a cloud-native data lake to support detection at scale.

  • Detect sophisticated post-exploitation techniques, lateral movement, and living-off-the-land attacks across corporate and production environments.

  • Continuously tune detection coverage against an assumed-breach threat model, prioritizing time-to-detect and blast-radius containment.

Compliance, Audit & Vendor Risk

  • Support SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.

  • Lead vendor risk assessments, procurement security reviews, and security-related legal contract negotiations.

  • Own front-line defenses for a frontier AI company, including physical security and data center security operations.

What We're Looking For

Experience & Background

  • 7+ years of deep engineering experience at high-valuation companies, or in defense-grade environments.

  • Battle-tested technical leadership with a track record of building and operating security engineering functions at scale.

  • Experience supporting SOC 2, ISO 27001, FedRAMP, ISO 22237, ISO 22301, NIST CSF, customer audits, and enterprise security reviews.

  • Experience leading vendor risk, procurement security reviews, and legal contract negotiations.

  • Experience with front-line defenses for an AI company, including physical security and data center security operations.

Skills & Capabilities

  • Deep familiarity with Linux and macOS internals, including how to secure specialized hardware (NVIDIA GPUs) without breaking developer environments.

  • Expert-level knowledge of public cloud architectures, IAM governance at scale, and Kubernetes/container isolation primitives.

  • Technical understanding of cloud and infrastructure security, Kubernetes and container security, zero-trust architectures, security operations at scale, identity and access management, detection and response technologies, and security automation and orchestration.

  • Ability to operate as both an executive leader and a hands-on builder, moving fluidly between strategy and implementation.

Mindset & Approach

  • A “guardrails, not gates” philosophy — understands that blocking a researcher from pulling a Python library or mounting a filesystem means security has failed, and builds accordingly using virtualization, sandboxing, and data isolation.

  • An adversarial mindset that designs systems under the assumption the endpoint will be compromised, focusing defenses on limiting blast radius, eliminating persistent access, and detecting post-compromise activity immediately.

  • Motivated by building — comfortable operating in ambiguous, fast-moving environments where security infrastructure is maturing alongside a rapidly scaling research organization.

  • Top-tier compensation: Salary and equity structured to recognize and retain our talent globally.

Standard company text repeated across Reflection AI's postings is omitted here.

Similar positions

Reflection AI
MTS Lead, Technology & Security Engineering
Reflection AI · New York, NY
Reflection AI
MTS Lead, Product Security
Reflection AI · New York, NY, United States
Reflection AI
MTS, IT Engineer
Reflection AI · San Francisco, CA, United States
Reflection AI
MTS Lead, Identity and Access Management
Reflection AI · New York, NY