Exa is building a search engine from scratch to serve every AI application. We build massive-scale infrastructure to crawl the web, train state-of-the-art embedding models to index it, and develop super high performant vector databases in Rust to search over it. We also own a $5M H200 GPU cluster that regularly lights up tens of thousands of machines.
We are hiring a Founding Security Engineer to build the protective shield for all of Exa’s systems. These systems include: processing web scale data, indexing hundreds of billions of pages, training foundational models on TBs of data, serving thousands of enterprise customers from our endpoints. You will be critical in making Exa run securely while ensuring our shipping velocity.
Desired Experience
You have hands-on experience in building and maintaining secure infrastructure
You know your way around cloud security fundamentals, including multi-account AWS permissions and architectures, IAM design, secure CI/CD pipelines
You are fluent in secrets management, key management, and certificate lifecycles (rotation, revocation, automation)
You have owned compliance efforts such as HIPPA, SOC2, etc.
You are comfortable with security hardening and any other details needed to make engineering systems run smoothly (VPN, development servers, etc.)
You are super vigilant about vulnerabilities, potential attacks, and abuse, and constantly think about how to operate securely with the introduction of new technologies (OS-level, AI coding agents, etc.)
Example Projects
Build a secrets management and rotation system used across distributed services, training jobs, and GPU clusters without impacting developer velocity
Build monitoring and alerting for anomalous behavior across APIs, internal services, and customer usage
Create security incident response playbooks and lead incident handling, from detection to post-mortem
This is an in-person opportunity in San Francisco. We're happy to sponsor international candidates (e.g., STEM OPT, OPT, H1B, O1, E3).
Sponsored