Security Engineer at xdof | San Francisco
xdof
Full-time|Hybrid|San Francisco Hybrid Join Our Team as a Security EngineerAt xdof, we're transforming the landscape of robotics. As frontier labs rush to develop versatile robots, the demand for high-quality training data has become a critical bottleneck. Our mission is to create robust data collection systems, operational capabilities, and an exabyte-scale data warehouse, supported by an advanced software toolchain, to empower our partners and propel the industry forward.As our enterprise partnerships expand, the significance of security in our infrastructure cannot be overstated. We are seeking a dedicated Security Engineer to take ownership of the security framework for our AWS environment and the externally-facing platform that our B2B customers rely on daily. Being part of an early-stage company means you will have the opportunity to influence security practices across our entire stack.Your ResponsibilitiesAs a Security Engineer, you will develop the controls and trust mechanisms that enable our platform to scale securely. Your projects may include:Designing and enforcing IAM policies and permission boundaries to ensure that every user and service operates under the principle of least privilege.Enhancing the security of external APIs integrated by our partners, focusing on authentication flows, threat modeling, rate limiting, and DDoS protection.Architecting a secure AWS infrastructure using Infrastructure as Code (IaC) and automated guardrails to catch misconfigurations before they reach production.Securing Kubernetes clusters through role-based access control (RBAC), network policies, admission controllers, and secrets management.Addressing lower-level security challenges, including firmware pipelines, on-device security, and secure data ingestion from robotics hardware.Who You AreCore Qualifications:5+ years of experience in security engineering or software engineering with a focus on security.Extensive hands-on experience with AWS security frameworks, including IAM, SCPs, VPCs, networking, logging, and encryption services.Proven track record of securing external-facing APIs and platforms, particularly in a B2B environment.Expertise in Infrastructure as Code and a GitOps approach to environment management.Proficiency in programming languages like Python or Go.You May Be a Great Fit If You:Have experience with embedded systems, firmware security, or securing hardware-software interfaces.Possess previous experience in robotics or AI-related fields.
Apr 11, 2026