- Company Name
- Isomorphic Labs
- Job Title
- Senior Security Engineer
- Job Description
-
**Job title:** Senior Security Engineer
**Role Summary:**
Design, implement, and manage security for AI‑driven drug discovery platforms and HPC infrastructure. Serve as a T‑shaped security lead overseeing architecture, IaC hardening, CI/CD security, threat modeling, incident response, zero trust IAM, compliance automation, and tooling development.
**Expectations:**
- Stakeholder collaboration on security requirements across product, DevOps, and compliance teams.
- Demonstrated ability to balance maximal security with rapid AI research velocity.
- Ownership of end‑to‑end security lifecycle from design to continuous improvement.
**Key Responsibilities:**
1. Conduct security reviews and threat modeling for evolving AI/HPC platforms.
2. Collaborate with DevOps/SRE to harden cloud infrastructure via IaC, policy‑as‑code, and network/VPC design.
3. Evaluate and secure third‑party AI, cloud, and SaaS integrations.
4. Implement automated security controls in CI/CD pipelines.
5. Act as L2/L3 escalation point for incidents and complex vulnerabilities.
6. Deploy and maintain Zero‑Trust IAM and least‑privilege access mechanisms.
7. Bridge technical controls and regulatory frameworks (GDPR, GxP, EU AI Act) using CSPM/automation.
8. Develop or integrate internal tooling to automate repetitive security tasks.
9. Manage full lifecycle of security controls: requirements, testing, rollout, and data‑driven improvement.
**Required Skills:**
- Deep knowledge of cloud security (GCP preferred): VPC, IAM, network hardening, native security services.
- Infrastructure‑as‑Code security: Terraform/CloudFormation, Policy as Code.
- CI/CD security: pipeline automation, scanning, and hardening.
- Threat modeling, risk assessment, and remediation planning.
- Incident response – L2/L3 – vulnerability remediation.
- Zero‑Trust architecture and IAM implementation.
- Compliance automation (GDPR, GxP, EU AI Act, CSPM).
- Programming/scripting (Python, Bash, or similar).
- Strong analytical, problem‑solving, and communication skills.
**Required Education & Certifications:**
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, or related field.
- Relevant security certifications (e.g., CISSP, CISM, GCP Professional Cloud Security Engineer, or equivalent).