Base Career helps you apply smarter for this job.
Key skills for this role
MatX is on a mission to be the compute platform for AGI. We are developing vertically integrated full-stack solutions from silicon to systems, including hardware and software, to train and run the largest ML workloads for AGI. MatX is seeking a Senior Security Engineer to join our team as we create best-in-class silicon for high-performance and sustainable GenAI. The successful candidate for this role will be responsible for securing the software, build systems, and cloud infrastructure that MatX products are designed, verified, and delivered on.
As a Security Engineer reporting to our Security Lead, you'll work across a stack that spans RTL design flows, compilers and kernels, ML training infrastructure, and the cloud environments that host all of it. This is a generalist role by design. We are a startup, and we would rather hire one engineer who can move between breaking things, reviewing code, and hardening infrastructure than three specialists who each own a slice.
Your week might include a threat model with the compiler team, an adversarial look at an internal service, and a redesign of how our build artifacts get signed. Two areas in particular are where we want this hire to push us further than we are today: supply chain and build integrity, and bringing a real attacker's perspective to systems we have so far only reviewed defensively. You'll set direction rather than inherit a playbook, and you'll see the impact of your work quickly.
Own and grow our supply chain and build integrity program - dependency and third-party IP provenance, artifact signing and code signing infrastructure, SBOM generation and consumption, reproducible builds, and hardening of CI/CD systems, build caches, and build runners. This is a priority area for us and the part of the role with the most room to define itself
Bring an adversarial perspective to our own systems: hands-on security assessment of our code and build tooling, internal services and dashboards, developer platforms, and the systems that hold our design data - including manual code review, application and API testing, and assessment of the infrastructure behind them
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
, USA
, USA
, USA
, USA
, USA
, USA
, USA
, USA
Conduct vulnerability research against the systems we build and depend on, and turn what you find into fixes and durable controls
Partner with software, compiler, ML, and silicon teams on threat modeling and design review for new systems, and translate the results into concrete engineering work rather than a list of findings
Harden our cloud infrastructure: identity and access management, network segmentation, secrets management, workload identity, infrastructure-as-code review, and guardrails that make the secure path the default path
Build and run our vulnerability management program - discovery, triage, prioritization based on real exploitability in our environment, and driving remediation to completion with the owning teams
Integrate security into the SDLC in ways engineers actually adopt: code scanning, dependency policy, pre-merge checks, secrets detection, and paved-road libraries and templates
Write the automation, tooling, and services that scale our security work - internal utilities, developer-facing tools, and the plumbing that makes findings actionable. This is an engineering role, not a governance role
Help protect highly sensitive IP and export-controlled technical data, working with our People, IT, and Legal teams on the controls that support it
8+ years in security engineering, with real depth in at least two of the following and working competence across the rest: application and product security, offensive security, cloud infrastructure security, supply chain and build security, detection and response
Strong application security fundamentals: threat modeling, manual secure code review, common vulnerability classes and their mitigations, and experience running SAST, DAST, and SCA tooling against real applications, services, and APIs without drowning teams in false positives.
Hands-on offensive experience - penetration testing, red team engagements, or vulnerability research - with current-day fluency in application and cloud attack paths, and the judgment to know when an attacker's perspective is the fastest way to settle a design argument
Strong software engineering skills. You write and ship production-quality code (Go, Python, Rust, or similar) and are comfortable reading code in languages you don't write. You've built tools other engineers chose to use
Working knowledge of at least one major cloud provider (GCP, AWS, or Azure) - IAM models, network architecture, secrets management, logging - and the appetite to go deep on the parts you haven't owned yet
Familiarity with modern supply chain and build integrity concepts - artifact signing, provenance and attestation, SBOMs, CI/CD as an attack surface - and the interest to own that program end to end. We care more that you understand why build systems are a target than that you've already deployed a particular toolchain
A track record of shipping fixes with development teams rather than filing tickets at them. You've been the security person engineers actually wanted in the room
Comfort operating with ambiguity and breadth. You can prioritize the small number of things that actually reduce risk, say no to the rest, and explain both decisions to engineers and to leadership
Direct experience implementing supply chain security tooling and standards - Sigstore/cosign, SLSA or equivalent build integrity frameworks, SBOM formats, reproducible builds
Experience with containers and infrastructure-as-code (Terraform or equivalent)
Experience securing environments with high-value IP or export-controlled technical data
Familiarity with EDA, hardware design, or ML training infrastructure and the security problems specific to them - large shared compute, HPC-style clusters, licensed third-party IP and tooling
Experience with hardware or firmware supply chain concerns: secure boot, firmware signing, code signing infrastructure, HSM or KMS-backed key management
Experience standing up a security function at a high-growth startup, including its first compliance efforts
Contributions to open source security tooling, published research, or conference talks
AI semiconductor company designing high-throughput chips for large language models and frontier AI labs.
Visit company websiteJobs and hiring trendsUSD 160000-600000 yearly / year
Full-time
Senior · 8+ years experience
Hybrid
Apply faster on company sites with our extension.