hirly

Runway Ml

Infrastructure Security Engineer

Remote

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Runway Ml first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.4M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Stated salary
$240,000 – $290,000 per year
Country
US
Work mode
Remote-friendly
First seen by hirly
24 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

We are building AI to simulate the world through merging art and science.

We believe that world models are at the frontier of progress in artificial intelligence. Language models alone won’t solve the world’s hardest problems – robotics, disease, scientific discovery. Real progress requires models that experience the world and learn from their mistakes, the same way that humans do. And this kind of trial and error can be massively accelerated when done in simulation, rather than in the real world.

World models offer the most clear path to general-purpose simulation, changing how stories are told, how scientific progress is made and how the next frontiers of humanity are reached.

Our team consists of creative, open minded, caring and ambitious people who are determined to change the world. We aspire to continuously build impossible things and our ability to do so relies on building an incredible team. If you are driven to do the same, we'd love to hear from you.

About the role

* Open to hiring remote — we also have offices in New York, San Francisco, Seattle, London, Paris, and Tel Aviv.

Runway is hiring an Infrastructure Security Engineer to secure the platform our models are trained and served on. The role covers Kubernetes platform security, cloud identity and access, software supply chain, tenant isolation in the serving layer and the research infrastructure behind our models.

Securing a company that trains and serves frontier video models is a different problem from securing a typical SaaS product. The environment includes research compute, large training datasets, a fast-moving build pipeline, and engineers who work inside AI-assisted tooling every day. Each of those changes what an attack looks like and what the platform has to enforce to stop it.

This is a hands-on engineering role on the Security team. You'll write policy, tooling and infrastructure code, work in the platform team's repositories, and ship controls that hold up in production.

What you'll do

Design and ship security controls in our Kubernetes ecosystem: admission policy, RBAC, workload identity, network policy and runtime hardening across every cluster we run

Harden the software supply chain from dependency intake through build and deploy, including package firewalling, artifact signing and provenance, and admission controls that block what doesn't pass

Own cloud IAM and identity architecture: least-privilege roles, short-lived credentials and workload federation

Secure research infrastructure and training pipelines, including access to model weights and datasets, without slowing down the people using them

Threat model new platform components before they ship and turn the findings into concrete requirements the owning team can act on

Build guardrails for AI agents and developer tooling operating inside our infrastructure

Write infrastructure as code and policy as code, and treat security configuration with the same review and rollout discipline as any other change

Give the incident response team what they need when infrastructure is involved: fast answers about how a system works and what to shut off

What you'll need

Hands-on experience securing Kubernetes in production: you've written admission policies, debugged RBAC and workload identity problems and understand how a cluster gets compromised

Working knowledge of cloud IAM and networking on at least one major cloud platform, including how identity federation and short-lived credentials actually work

Experience with infrastructure as code and GitOps-style deployment, and the habit of shipping security changes through the same pipeline as everything else

Comfort writing Python, Typescript, Rust or another language to build tooling, not just scripts

An understanding of software supply chain attacks and the controls that stop them: signing, provenance, SBOMs, admission enforcement

Clear writing. Design docs, threat models and explanations to engineers who don't work in security are all part of the job

Judgment about which controls to enforce, which to recommend and how to roll out a breaking change without breaking the company

Even better if you have

Experience securing GPU or HPC-style compute, training pipelines or research environments

Experience with policy engines and admission controllers (Kyverno, OPA Gatekeeper, Falco or similar)

Multi-tenant isolation design in a cloud environment: ABAC, scoped credentials, per-tenant boundaries

Experience producing security architecture evidence for SOC 2, ISO 27001 or other audits and customer assessments

Open source contributions or published work in cloud or Kubernetes security

Runway strives to recruit and retain exceptional talent from diverse backgrounds while ensuring pay equity for our team. Our salary ranges are based on competitive market rates for our size, stage and industry, and salary is just one part of the overall compensation package we provide.

There are many factors that go into salary determinations, including relevant experience, skill level and qualifications assessed during the interview process, and maintaining internal equity with peers on the team. The range shared below is a general expectation for the function as posted, but we are also open to considering candidates who may be more or less experienced than outlined in the job description. In this case, we will communicate any updates in the expected salary range.

Lastly, the provided range is the expected salary for candidates in the U.S. Outside of those regions, there may be a change in the range, which again, will be communicated to candidates.

Working at Runway

Great things come from great teams. We’d love to hear from you.

We’re committed to creating a space where our employees can bring their full selves to work and have equal opportunity to succeed. So regardless of race, gender identity or expression, sexual orientation, religion, origin, ability, age, veteran status, if joining this mission speaks to you, we encourage you to apply.

More about Runway

Universal World Simulator

GWM-1

Gen-4.5

General World Models

Robotics SDK

Conversational Real-time Agents

Runway Studios

We're excited to be recognized as a best place to work:

Crain's | InHerSight | BuiltIn NYC | INC

Original posting on Runway Ml's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job