Sandboxaq

Staff DevSecOps & Infrastructure Engineer

Remote, USA Full Time

About SandboxAQ

SandboxAQ is a high-growth company delivering AI solutions that address some of the world's greatest challenges. The company’s Large Quantitative Models (LQMs) power advances in life sciences, financial services, navigation, cybersecurity, and other sectors.

We are a global team that is tech-focused and includes experts in AI, chemistry, cybersecurity, physics, mathematics, medicine, engineering, and other specialties. The company emerged from Alphabet Inc. as an independent, growth capital-backed company in 2022, funded by leading investors and supported by a braintrust of industry leaders. 

At SandboxAQ, we’ve cultivated an environment that encourages creativity, collaboration, and impact. By investing deeply in our people, we’re building a thriving, global workforce poised to tackle the world's epic challenges. Join us to advance your career in pursuit of an inspiring mission, in a community of like-minded people who value entrepreneurialism, ownership, and transformative impact. 

About The Role

The Cybersecurity Group at SandboxAQ is looking for a founding DevSecOps Engineer to build and embed security into our infrastructure and product lifecycle. You will be responsible for functionalizing AQtive Guard, our groundbreaking solution for modern non-human identity and cryptography management. This is a critical role where you will be the first dedicated security engineer on the team, establishing the security foundations for our products that are already launching globally with major organizations.

We’re looking for a hands-on engineer who will champion security best practices across our systems. A successful candidate will be comfortable designing, automating, and maintaining secure infrastructure for both on-premise and cloud environments, including local development environments and full CI/CD pipelines. You will work closely with a diverse team of cryptographers, developers, ML experts, and physicists to collaborate on delivering novel and secure solutions.

What You’ll Do

  • Design and implement a secure CI/CD pipeline, integrating security testing tools (e.g., SAST, DAST, SCA, and vulnerability scanning) to ensure high-quality, secure deliverables.
  • Automate security processes and controls throughout the software development lifecycle.
  • Work with teams of developers and cryptographers to integrate their advancements into new products, ensuring security is a core component from the design phase.
  • Build and maintain secure, scalable, and fault-tolerant architecture for our cloud (AWS) and on-premise deployments, using Infrastructure as Code (IaC) principles.
  • Lead vulnerability management and remediation efforts, conducting security reviews, risk assessments, and code audits.
  • Develop and maintain security tooling, incident response plans, and concise documentation for our systems and processes.
  • Champion a culture of security by mentoring developers on secure coding practices and security best practices.
  • Contribute to delivering AQtive Guard for FedRAMP compliance

Who You Are

  • US Citizenship and/or security clearance is required due to USG contract requirements
  • Strong experience with security best practices and implementing security controls in a cloud-native environment.
  • Strong experience using, building, and securing infrastructure in AWS.
  • Strong experience managing and orchestrating workloads using Docker and Kubernetes.
  • Proven experience defining secure infrastructure and processes as code using Terraform and managing CI systems.
  • Expertise in building and securing large-scale distributed systems.
  • Hands-on experience integrating and managing security tools within CI/CD pipelines.
  • Strong experience with a few scripting languages (e.g., Python, Bash).
  • Ability to work in a small team/rapid prototyping environment and deal with uncertainty and fluidity.

Nice to Haves

  • Experience with compliance frameworks (e.g., SOC 2, ISO 27001, or FedRAMP).
  • Familiarity with configuration management tools such as Ansible or Puppet.
  • Offensive security experience or certifications (e.g., OSCP).
  • Familiarity with Bazel.
  • Familiarity with streaming frameworks, especially Kafka and Kstreams.
  • Experience w/ enterprise security-tooling like Crowdstrike, Rapid7, or Snyk

The US base salary range for this full-time position is expected to be $183k-$256k per year. Our salary ranges are determined by role and level. Within the range, individual pay is determined by factors including job-related skills, experience, and relevant education or training. This role may be eligible for annual discretionary bonuses and equity.

SandboxAQ welcomes all.

We are committed to creating an inclusive culture where we have zero tolerance for discrimination. We invest in our employees' personal and professional growth. Once you work with us, you can’t go back to normalcy because great breakthroughs come from great teams and we are the best in AI and quantum technology.
 
We offer competitive salaries, stock options depending on employment type, generous learning opportunities, medical/dental/vision, family planning/fertility, PTO (summer and winter breaks), financial wellness resources, 401(k) plans, and more. 
 
Equal Employment Opportunity: All qualified applicants will receive consideration regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status.
 
Accommodations: We provide reasonable accommodations for individuals with disabilities in job application procedures for open roles. If you need such an accommodation, please let a member of our Recruiting team know.