Security Engineer

Baseten · Data AI · San Francisco, CA · EPD

Baseten is seeking an experienced Security Engineer to build and maintain the security posture of their ML infrastructure platform, which serves AI companies. The role involves security architecture, vulnerability management, incident response, IAM, compliance, employee training, and DevSecOps integration, with a focus on cloud and container security.

What you'd actually do

  1. Collaborate with engineering teams to design and implement secure systems and infrastructure, including cloud (AWS/GCP) environments and container orchestration platforms.
  2. Lead proactive vulnerability assessments, pen tests, and remediation efforts to ensure our products and infrastructure remain secure.
  3. Develop and maintain incident response processes, including detection, analysis, containment, eradication, and post-incident reviews.
  4. Oversee IAM strategies and tools to ensure the right people have the right level of access to our systems and data.
  5. Work closely with operations to ensure compliance with relevant standards (e.g., SOC 2, ISO 27001) and assist with audits, policy creation, and risk assessments.

Skills

Required

  • 3+ years of experience in a Security Engineer or similar security-focused role
  • Strong knowledge of cloud security (AWS/GCP), container security, and infrastructure-as-code best practices.
  • Hands-on experience with security tooling (SIEM, IDS/IPS, vulnerability scanners) and scripting languages to automate security tasks.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, and GDPR, and the ability to translate requirements into actionable security controls.
  • Incident response expertise, including forensic analysis and root cause investigation.
  • Excellent communication skills and the ability to collaborate with cross-functional teams

Nice to have

  • preferably in a fast-paced startup environment

What the JD emphasized

  • security posture of our rapidly growing ML infrastructure platform
  • shape our security strategy and best practices from the ground up
  • SOC 2, ISO 27001
  • security-first culture