N

Security Engineer

Nous Research United States

Blockchain Services · 51-200 employees

Yesterday
Remote security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Security Engineer will own end-to-end security for infrastructure, products, and enterprise deployments across a multi-cloud environment. Responsibilities include hardening the Hermes Agent platform, managing SOC 2 compliance, and leading vulnerability management and incident response efforts.

What they look for

Cloud Security Kubernetes Identity and Access Management SOC 2 Vulnerability Management Penetration Testing Incident Response Multi-cloud Security SAML SSO Infrastructure Security AI Security Kernel-level Sandboxing Network Isolation Secure Software Development Lifecycle

Requirements

Candidates must have 8+ years of security engineering experience with deep expertise in infrastructure and multi-cloud security. A strong background in Kubernetes, IAM, and compliance-driven engineering programs like SOC 2 or ISO 27001 is required.

Full description

The Role

As a Security Engineer at Nous Research, you'll own security end-to-end across our infrastructure, products, and enterprise deployments. Nous builds open-source AI language models and agents, including Hermes Agent, which is used by consumers and Fortune 500 enterprises across multi-tenant SaaS, dedicated VPC, self-hosted, and air-gapped environments.

This is a hands-on-keyboard role for someone who wants to harden multi-cloud infrastructure, secure a novel agentic AI platform, and build the security foundation regulated enterprise customers demand. You'll be the person focused full-time on protecting the company while helping the rest of the team continue shipping quickly.

Responsibilities

  • Own production security across a multi-cloud footprint spanning AWS, GCP, Azure, and Vercel.
  • Secure multi-tenant SaaS, dedicated VPC, self-hosted Kubernetes, and air-gapped deployments.
  • Secure the Hermes Agent platform across sandboxing, kernel-level file system and network isolation, agent identity, credential controls, egress controls, and trace integrity.
  • Own SOC 2 technical controls, evidence collection, remediation, and ongoing readiness.
  • Harden identity and access management, including SSO and SAML consolidation, least-privilege access reviews, 2FA, and BYOD policies.
  • Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring.
  • Strengthen the secure software development lifecycle through practical controls, including peer-review requirements, while maintaining high development velocity.
  • Support enterprise deals by completing security questionnaires, leading architecture reviews, and addressing penetration-testing requirements.
  • Partner across engineering, infrastructure, product, FDE, and operations to identify and address security risks.

Qualifications

  • 8+ years of security engineering experience, with deep hands-on expertise in infrastructure and multi-cloud security.
  • Track record securing production SaaS environments and owning security end-to-end at a fast-growing technology company.
  • Strong Kubernetes, identity, and IAM fundamentals, including familiarity with enterprise SSO, SAML, and SCIM.
  • Experience implementing compliance-driven engineering programs such as SOC 2 or ISO 27001 without allowing them to become checkbox exercises.
  • Strong understanding of vulnerability management, incident response, access controls, penetration testing, and secure software development practices.
  • Interest in securing agentic AI systems and addressing emerging risks across agent identity, tool permissions, prompt injection, and data provenance.
  • Ability to work effectively in a high-velocity, open-source-native engineering culture.
  • Security-minded by default and pragmatic in practice, with strong judgment around balancing protection and development speed.

Nice-to-Have

  • Experience supporting regulated customers, financial services organizations, or air-gapped deployments.
  • Prior experience securing AI, machine learning, or open-source systems.
  • Experience with detection and response tooling in cloud-native environments.
  • Familiarity with kernel-level sandboxing, network isolation, and agent security.
  • Experience supporting Fortune 500 security reviews, architecture assessments, and penetration-testing requirements.

Similar roles