Security Engineer, Threat Intelligence
New York City, NY - USA
Job Summary
We exist to make humanity more free. For most of human history you farmed or you starved. Technology gave people more time for the things they wanted to do instead of things they had to do. Powerful AI will be the biggest lever for human choice weve ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who dont share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.
Were singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else rethinking every layer of the stack. We acquire power design and build data centers and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.
We hire people who care deeply about this problem space. If that is you please apply!
Be a barrel. Full autonomy. Own things end to end take on scope without being asked no permission required to operate outside your core role.
Insane urgency. We drive everything forward as fast as possible.
Reason from first principles. Challenge every assumption. Zero analogy thinking no egos the best idea wins.
Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
Build something that actually matters. If youre going to spend your time spend it on something that matters to the world.
Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.
Velocity. We drive everything forward as fast as possible.
First principles. Challenge every assumption. Zero analogy thinking no egos the best idea wins.
Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.
Examples of key problems the team is working on
Youre securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology and were standing up the compute to hold them faster than anyone ever has. A breach isnt a leak its the frontier walking out the door.
Build the entire security program from scratch. Most leaders inherit someone elses system and spend a career patching it. Here you own it end to end bare metal to boardroom as we scale across continents.
Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history and being responsible for the physical and logical security of that work makes everything else feel small.
Track the nation-state and advanced criminal actors most likely to target frontier AI infrastructure and turn their tooling infrastructure patterns and tradecraft into intelligence that changes what the program detects and hunts for.
Build and run the pipelines that collect enrich and correlate indicators then push them into the detection and agentic triage stack so intelligence becomes operational instantly.
Drive intelligence-led hunts across enterprise cloud identity data center IT and OT telemetry and convert findings into high-fidelity detections authored as code.
Perform hands-on malware phishing-infrastructure and attacker-tooling analysis to extract indicators TTPs and attribution signals that feed detection engineering and incident response in near real time.
Curate the inbound intelligence pipeline across commercial feeds open source government and peer relationships and prioritize what actually matters for the programs threat model.
Build and maintain the external intelligence-sharing relationships (ISACs peer AI and cloud security teams government partners) that keep the program ahead of active campaigns.
The below is a starting point. We always make space for exceptional people so if you dont fit this role exactly tell us where you would.
Youve tracked specific nation-state or advanced criminal actors as a core part of your job and you know their tooling infrastructure and targeting well enough to anticipate their next move.
You write production-quality Python (or similar) and have built the automation and data pipelines your intelligence work depended on end to end.
Youve done hands-on malware infrastructure and log analysis to develop and validate your own findings.
Youve authored quality detection logic (YARA Sigma or SIEM-native queries) that shipped to production and held up against real adversary activity.
Youve worked shoulder to shoulder with detection engineers and incident responders turning intelligence into detections hunting hypotheses and incident context while an event was still live.
You write intelligence that gets read and acted on distilling a complex campaign into a decision and a next step for an engineer or an executive.
Bonus: An active network in the threat intelligence community and a habit of sharing in both directions. Experience defending large-scale GPU or AI compute infrastructure data centers or multi-tenant cloud environments. Applying LLMs or agentic tooling to accelerate collection enrichment and analysis. Public research conference talks or open-source contributions in the CTI space.
Competitive total compensation package (salary equity).
Retirement or pension plan in line with local norms.
Health dental and vision insurance.
Generous PTO policy in line with local norms.
The base salary range for this position is $220000 - $280000 per year depending on experience skills qualifications and location. This range represents our good faith estimate of the compensation for this role at the time of posting. Total compensation may also include equity in the form of stock options.
We are committed to pay equity and transparency.
Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex national origin sexual orientation gender identity disability and protected veterans status or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email please email with your resume/CV the role youve applied for and the date you submitted your application-- someone from our recruiting team will be in touch.
Required Experience:
IC