About the job
Our Mission
At Reflection AI, our mission is to develop open superintelligence that is accessible to everyone.
We are creating advanced open weight models tailored for individuals, agents, enterprises, and even nations. Our talented team comprises AI researchers and industry veterans from renowned organizations such as DeepMind, OpenAI, Google Brain, Meta, Character. AI, Anthropic, and more.
Role Overview
Reflection. AI is seeking a motivated Member of Technical Staff - Security Engineer to establish our Application Security function while actively contributing to various projects across our Security Engineering organization. This role offers significant autonomy to design solutions and navigate both technical challenges and organizational dynamics. Ideal candidates will be those who excel in environments that prioritize ownership and possess a strong '0 to 1' mentality.
Key Responsibilities
Engage in engineering tasks for essential projects within the Security organization, including our agentic AI incident detection and response SOC, along with long-term internal AI agents.
Implement security measures for AI agents, encompassing sandboxes, identity, and authorization systems.
Develop a comprehensive software supply chain security strategy, including tooling and infrastructure with SCA/SBOM analysis.
Quickly deploy controls to address emerging supply chain threats.
Create and sustain a detailed threat model for our software stack.
Lead our penetration testing program based on prioritizations outlined in your threat model.
Establish and propagate foundational secure coding practices and architectural patterns pertinent to AI/ML systems.
Integrate Static Application Security Testing (SAST) tools within CI/CD pipelines for ongoing vulnerability assessments.
Design and execute a thorough Secure Software Development Lifecycle.
Required Qualifications
Proficiency in Python or Golang.
Demonstrated experience in architecting and constructing complex software systems.
Understanding of common application logic exploit vectors.
Experience in implementing and executing cross-functional projects with significant impact.
