- Company Name
- Decagon
- Job Title
- Senior Security Engineer, Infrastructure
- Job Description
-
**Job Title**
Senior Security Engineer, Infrastructure
**Role Summary**
Design, build, and maintain secure, scalable, and highly available multi‑tenant infrastructure on Google Cloud Platform (GCP) to support a conversational AI platform. Ensure enterprise‑grade reliability, compliance, and performance while enabling rapid growth and secure AI model deployment.
**Expectations**
- Minimum 5 years of experience designing production‑level infrastructure with a strong security focus, preferably for SaaS or enterprise software.
- Proven expertise in GCP architecture (Compute, Networking, Security, Managed Services).
- Advanced skills in Infrastructure as Code (IaC) and automated configuration management.
- Track record of meeting high availability (99.99 % uptime) and sub‑100 ms latency requirements for large‑scale, mission‑critical services.
- Experience implementing and maintaining SOC 2, ISO 27001, and related compliance frameworks.
**Key Responsibilities**
- Architect and deploy secure, isolated multi‑tenant environments for AI agents, ensuring data segregation and strict access controls.
- Develop and maintain IaC pipelines (Terraform, Ansible, or equivalent) for consistent, repeatable deployment across Dev, Test, and Prod.
- Design and implement container security, Kubernetes hardening, and service mesh (e.g., Istio) to protect workload communication.
- Build and monitor performance dashboards to guarantee sub‑100 ms response times under millions of concurrent conversations.
- Lead the creation of backup, disaster recovery, and incident response procedures for security infrastructure.
- Collaborate with DevOps, Security, and Product teams to embed security best practices into the CI/CD lifecycle.
- Stay current on emerging threats and recommend proactive mitigations for AI‑enabled attack vectors.
**Required Skills**
- GCP architecture: Compute Engine, Kubernetes Engine, VPC, IAM, Cloud Armor, Cloud KMS, Cloud Storage, Pub/Sub.
- IaC: Terraform or equivalent; Ansible or similar for configuration management.
- Container & cluster security: Kubernetes security best practices, RBAC, pod security policies, network policies.
- Service mesh: design, deployment, and monitoring (e.g., Istio, Linkerd).
- High‑availability and latency optimization: load balancing, auto‑scaling, caching, CDN integration.
- Compliance: SOC 2, ISO 27001, privacy regulations (GDPR, CCPA).
- Backup/DR: snapshotting, replication, playbooks for failover.
- Strong scripting (Python, Bash) and logging/monitoring tools (ELK, Prometheus, Grafana).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Engineering, Information Security, or related field (or equivalent practical experience).
- Relevant certifications preferred: GCP Professional Cloud Architect or Cloud Security Engineer, Certified Kubernetes Administrator (CKA), or equivalent security credentials.
San francisco, United states
On site
Senior
02-11-2025