logo
AI Resume Tailoring Sign in to use this AI Cover Letter Sign in to use this

Job Description

What MatX Is Building

MatX is on a mission to be the compute platform for AGI. We are developing vertically integrated full-stack solutions from silicon to systems, including hardware and software, to train and run the largest ML workloads for AGI. MatX is seeking a Senior Security Engineer to join our team as we create best-in-class silicon for high-performance and sustainable GenAI. The successful candidate for this role will be responsible for securing the software, build systems, and cloud infrastructure that MatX products are designed, verified, and delivered on.

As a Security Engineer reporting to our Security Lead, you'll work across a stack that spans RTL design flows, compilers and kernels, ML training infrastructure, and the cloud environments that host all of it. This is a generalist role by design. We are a startup, and we would rather hire one engineer who can move between breaking things, reviewing code, and hardening infrastructure than three specialists who each own a slice.

Your week might include a threat model with the compiler team, an adversarial look at an internal service, and a redesign of how our build artifacts get signed. Two areas in particular are where we want this hire to push us further than we are today: supply chain and build integrity, and bringing a real attacker's perspective to systems we have so far only reviewed defensively. You'll set direction rather than inherit a playbook, and you'll see the impact of your work quickly.

What You'll Do Here

  • Own and grow our supply chain and build integrity program - dependency and third-party IP provenance, artifact signing and code signing infrastructure, SBOM generation and consumption, reproducible builds, and hardening of CI/CD systems, build caches, and build runners. This is a priority area for us and the part of the role with the most room to define itself

  • Bring an adversarial perspective to our own systems: hands-on security assessment of our code and build tooling, internal services and dashboards, developer platforms, and the systems that hold our design data - including manual code review, application and API testing, and assessment of the infrastructure behind them

  • Conduct vulnerability research against the systems we build and depend on, and turn what you find into fixes and durable controls

  • Partner with software, compiler, ML, and silicon teams on threat modeling and design review for new systems, and translate the results into concrete engineering work rather than a list of findings

  • Harden our cloud infrastructure: identity and access management, network segmentation, secrets management, workload identity, infrastructure-as-code review, and guardrails that make the secure path the default path

  • Build and run our vulnerability management program - discovery, triage, prioritization based on real exploitability in our environment, and driving remediation to completion with the owning teams

  • Integrate security into the SDLC in ways engineers actually adopt: code scanning, dependency policy, pre-merge checks, secrets detection, and paved-road libraries and templates

  • Write the automation, tooling, and services that scale our security work - internal utilities, developer-facing tools, and the plumbing that makes findings actionable. This is an engineering role, not a governance role

  • Help protect highly sensitive IP and export-controlled technical data, working with our People, IT, and Legal teams on the controls that support it

Who You Are

  • 8+ years in security engineering, with real depth in at least two of the following and working competence across the rest: application and product security, offensive security, cloud infrastructure security, supply chain and build security, detection and response

  • Strong application security fundamentals: threat modeling, manual secure code review, common vulnerability classes and their mitigations, and experience running SAST, DAST, and SCA tooling against real applications, services, and APIs without drowning teams in false positives.

  • Hands-on offensive experience - penetration testing, red team engagements, or vulnerability research - with current-day fluency in application and cloud attack paths, and the judgment to know when an attacker's perspective is the fastest way to settle a design argument

  • Strong software engineering skills. You write and ship production-quality code (Go, Python, Rust, or similar) and are comfortable reading code in languages you don't write. You've built tools other engineers chose to use

  • Working knowledge of at least one major cloud provider (GCP, AWS, or Azure) - IAM models, network architecture, secrets management, logging - and the appetite to go deep on the parts you haven't owned yet

  • Familiarity with modern supply chain and build integrity concepts - artifact signing, provenance and attestation, SBOMs, CI/CD as an attack surface - and the interest to own that program end to end. We care more that you understand why build systems are a target than that you've already deployed a particular toolchain

  • A track record of shipping fixes with development teams rather than filing tickets at them. You've been the security person engineers actually wanted in the room

  • Comfort operating with ambiguity and breadth. You can prioritize the small number of things that actually reduce risk, say no to the rest, and explain both decisions to engineers and to leadership

Bonus Points If You Have

  • Direct experience implementing supply chain security tooling and standards - Sigstore/cosign, SLSA or equivalent build integrity frameworks, SBOM formats, reproducible builds

  • Experience with containers and infrastructure-as-code (Terraform or equivalent)

  • Experience securing environments with high-value IP or export-controlled technical data

  • Familiarity with EDA, hardware design, or ML training infrastructure and the security problems specific to them - large shared compute, HPC-style clusters, licensed third-party IP and tooling

  • Experience with hardware or firmware supply chain concerns: secure boot, firmware signing, code signing infrastructure, HSM or KMS-backed key management

  • Experience standing up a security function at a high-growth startup, including its first compliance efforts

  • Contributions to open source security tooling, published research, or conference talks

Compensation

The US base salary for this full-time position is determined based on a variety of factors including role, experience, location, job-related skills, and relevant education and training. Career length is only a guideline for compensation.

  • Early Career - $160,000 - $275,000 + equity

  • Mid Career - $175,000 - $400,000 + equity

  • Senior Career - $250,000 - $600,000 + equity



What We Offer

  • Time off: 4 weeks PTO (accrued) + 12 company Holidays + up to 3 weeks remote work

  • Health: Company-subsidized Medical (Kaiser or Anthem) for employees & dependents, Guardian Dental and Vision insurances for employee & dependents, and life insurance (employee only), plus HSA and FSA offerings via Lively.

  • Financial Wellbeing: Choose from Roth IRA or 401K (or both) retirement plans with up to 5% company contribution to 401K (even if you don't contribute). Also, 100% company-paid life insurance (up to $300K) and long-term disability insurances.

  • Professional Development: $1500 Professional Development Budget (per year)

  • Team Meals: MatX provides onsite team lunch & dinner Monday - Friday, with your choice of ordering via WeBox, Specialty’s or via our reimbursement system

  • Commute on Us: Commute on our company Uber account, or reimburse your train rides. Either way, we pay 100% for your daily commute.

  • MatX E[x]tras: $50/mo to use on the perk you value most

  • Cell & Internet Reimbursement: $35/mo for cellular and $40/mo for wifi

  • Mental Wellbeing: 100% paid mental health benefit via SpringHealth and Guardian EAP.

  • Support to Parents: Up to 12 weeks paid parental leave regardless of path to parenthood, 10 weeks pregnancy disability leave, flexible return-to-work hours, and Benepass reproductive health & parental benefit.

  • AI Resources: Up to $20K/month plus a dedicated internal AI Tooling Team to support your productivity

As part of our dedication to the diversity of our team and our focus on creating an inviting and inclusive work experience, MatX is committed to a policy of Equal Employment Opportunity and will not discriminate against an applicant or employee on the basis of race, color, religion, creed, national origin or ancestry, sex, gender, gender identity, gender expression, sexual orientation, age, physical or mental disability, medical condition, marital/domestic partner status, military and veteran status, genetic information or any other legally recognized protected basis under federal, state or local laws, regulations or ordinances.
---------

This position requires access to information that is subject to U.S. export controls. This offer of employment is contingent upon the applicant's capacity to perform job functions in compliance with U.S. export control laws without obtaining a license from U.S. export control authorities.
--------

MatX does not accept unsolicited resumes from individual recruiters or third-party recruiting agencies in response to job postings. No fee will be paid to third parties who submit unsolicited candidates directly to our hiring managers or People team and any resumes submitted are deemed to be the property of MatX.

Do you match this job?

Here is what this employer asked for. Sign in and we will fill in your half.

  • Role Security Engineer
  • Experience 3-4 years
  • Education Any
  • Work type Hybrid
  • Location United States
Check my match (free)
MatX
Enterprise Software · United States

MatX designs chips and systems for training and running large AI models.

All jobs at MatX
Job Overview

Approx. salary range

202K – 326K

Our estimate — this employer did not publish a salary

Our estimate, not the employer’s. Worked out from the middle half of 40 comparable roles on Neural Jobs that did publish a salary, in the same field, country and experience band. The real figure for this job may be different.

Eligibility
United States Right to work in the United States required.
Workplace
Hybrid
Job Posted:
13 hours ago
Job Type
Full Time
Education
Any
Experience
3-4 years

Share This Job: