Security Engineer
MatXJob Title
Security Engineer
Role Summary
MatX is hiring a senior security engineer to secure software, build systems, and cloud infrastructure across our stack - from RTL and compiler toolchains to ML training infrastructure and cloud-hosted services. This is a hands-on engineering role focused on supply chain and build integrity, adversarial assessments, and making secure practices adoptable by development teams.
Experience Level
Senior - 8+ years of security engineering experience expected.
Responsibilities
Own and execute security work across code, build systems, and cloud infrastructure; translate findings into engineering work and durable controls.
- Establish and operate supply chain and build integrity program: provenance, artifact and code signing, SBOMs, reproducible builds, CI/CD hardening.
- Perform hands-on adversarial assessments: manual secure code review, API/app testing, and infrastructure attacks.
- Conduct vulnerability research and drive fixes from discovery to remediation with engineering teams.
- Lead threat modeling and design reviews with software, compiler, ML, and silicon teams.
- Harden cloud infrastructure: IAM, network segmentation, secrets management, workload identity, and IaC reviews.
- Build and run vulnerability management: discovery, triage, prioritization, and remediation tracking.
- Integrate security into the SDLC: code scanning, dependency policies, pre-merge checks, and developer-friendly libraries/templates.
- Develop automation and developer-facing tools to scale security operations.
- Support controls for protecting high-value and export-controlled technical data.
Requirements
Must-have technical skills and experience; concise list of essential and preferred qualifications.
- Must-have: 8+ years in security engineering with deep experience in at least two areas (application/product security, offensive security, cloud infra security, supply chain/build security, detection & response).
- Strong application security fundamentals: threat modeling, manual secure code review, SAST/DAST/SCA operations against real services.
- Hands-on offensive experience: penetration testing, red-team work, or vulnerability research with current cloud/app attack knowledge.
- Strong software engineering skills and experience shipping production-quality code (Go, Python, Rust, or similar).
- Working knowledge of at least one major cloud provider (GCP, AWS, or Azure) including IAM, networking, secrets, and logging.
- Familiarity with supply chain and build integrity concepts (artifact signing, provenance, SBOMs, CI/CD attack surface).
- Proven record of driving fixes with development teams and operating effectively in ambiguous startup environments.
Nice-to-have:
- Experience with Sigstore/cosign, SLSA or equivalent, SBOM formats, and reproducible builds.
- Containers and infrastructure-as-code (Terraform or equivalent).
- Experience securing environments with high-value IP or export-controlled data, or EDA/hardware/ML infra security.
- Firmware/secure-boot, HSM/KMS-backed key management, or code-signing infrastructure experience.
- Experience building an early security function at a high-growth startup; open-source contributions or published security research.
Education Requirements
Not specified.
About the Company
Company: MatX
Headquarters: Mountain View, California, USA
MatX specializes in creating faster chips for large language models (LLMs), focusing on innovative hardware and software solutions. The company fosters a collaborative and supportive work environment, welcoming candidates of all experience levels. Their approach prioritizes deep understanding and consideration of novel methods to drive efficiency and performance in their projects, particularly in silicon design and related engineering roles.
