All open positions

Open role · Security

Member of Technical Staff, Security Engineering

Make agent authority, isolation, and deployment paths enforceable and auditable.

General Diffusion is building AI compute engineers that predict the consequences of placement before a workload touches production, across a bare-metal, multi-architecture testbed. As an MTS in Security Engineering, you will make the authority around those agents—identities, tool calls, workloads, and releases—narrow, revocable, isolated, and traceable, including when inputs are adversarial. This role secures who and what can act; Safety & Formal Verification remains responsible for the correctness and independently enforced permissibility of actions.

What you’ll work on

  • Threat-model the paths from agent output to runtime, fleet, and release actions; turn findings into explicit trust boundaries, abuse cases, and prioritized engineering work.
  • Build workload and service identity controls with short-lived, scoped credentials, authorization checks at downstream boundaries, and prompt revocation for compromised or retired access.
  • Engineer isolation for untrusted workloads and tool integrations, with deliberate controls on filesystem, network, device, and secret access appropriate to each execution path.
  • Establish secure build and deployment controls: protect source and dependency intake, preserve artifact provenance, and enforce policy checks before privileged environments accept releases.
  • Develop adversarial test coverage for agent and tool misuse—including indirect instruction attacks, confused-deputy paths, privilege escalation, and attempts to escape workload boundaries—and keep the cases reproducible as regressions.
  • Make privileged actions reconstructible through security-relevant audit signals, detections, and incident runbooks; partner with Fleet on operational response without taking ownership of fleet operation.

What you bring

  • Hands-on platform or product security engineering experience in systems where code can trigger consequential infrastructure actions.
  • Strong Linux security fundamentals and practical experience designing workload identity, service-to-service authorization, secrets handling, and least-privilege access controls.
  • Experience securing isolation boundaries such as containers, virtual machines, sandboxes, or similar multi-tenant execution environments, with clear understanding of their failure modes.
  • Experience hardening CI/CD and software supply chains, including dependency risk, artifact integrity or provenance, and deploy-time policy enforcement.
  • Ability to threat-model agentic or automation-heavy systems and translate adversarial scenarios into testable controls rather than relying on instructions or model behavior alone.
  • Practical incident-response judgment: can investigate an access-control or isolation failure from telemetry, contain it, and convert lessons into durable engineering changes.

What progress looks like

  • A reviewed security architecture maps identities, trust boundaries, privileged tools, sensitive assets, and revocation paths across the agent-to-runtime flow; its open risks have named owners and tracked mitigations.
  • Representative privileged actions execute through scoped identities and independently enforced authorization checks, with evidence from access tests showing that expired, over-scoped, or cross-boundary requests are denied and logged.
  • A repeatable adversarial evaluation suite exercises high-risk agent and workload abuse paths, and its results inform regression tests, incident playbooks, and release criteria for the security-relevant interfaces.

Where this role fits

Owns security of who and what can act; Safety & Verification owns correctness of allowed actions.

Apply

Interested in this role?

Email your background and a short note about the work you would like to do.

careers@generaldiffusion.com

Apply via Email