Resolution
Posted 1mo ago

Security Engineer (Research Infrastructure)

Resolution
Berkeley or London or United States
$346k-$930k/yrHybridFull Time
Responsibilities
  • hardening pipelines
  • securing infrastructure
  • protecting data
Requirements
  • Seasoned security engineer with experience securing CI/CD
  • Terraform
  • Kubernetes
  • Multi-cloud (AWS/GCP), and supply-chain protections
  • Bachelor's degree or equivalent
  • Strong communication and pragmatic security approach
Technical tools mentioned
TerraformKubernetesGitHub ActionsGitLab CIAWSGCPMicrosoft Excel

Job description

About Resolution

Resolution does research on how to align artificial superintelligence (ASI). ASI may be developed in the next few years, but it is unclear whether alignment is on track to be ready in the same timeframe. We aim at higher a priori confidence in aligned outcomes by pursuing a portfolio of theory and empirics bets, any one of which — if it succeeds — would meaningfully advance the field. We invest heavily in research automation to accelerate progress, and we believe that stronger alignment theory unlocks higher automation: more principled approaches give us better filters for which directions of automated research are promising.

Resolution was founded in 2026 by researchers from UK AISI's Alignment Team, who ran the £30m Alignment Project, and Timaeus, who pioneered applying singular learning theory to alignment.

For more information, see our announcement.

About the Team

Resolution's work will involve sensitive frontier-relevant research and partnerships with AI labs. This role exists both to protect that work and to enable it: good security is what makes deeper lab partnerships possible. We draw a distinction between two closely related areas of security:

  • Research & infrastructure security. Securing how research actually runs: CI/CD pipelines, automated research agents, multi-cloud compute, and code/data/model-weight handling.

  • Corporate IT & security. The endpoint, identity, and collaboration scaffolding a distributed research org runs on, in combination with the compliance frameworks that unlock lab partnerships.

This role focuses on the former, covering security on the technical side of the organization. You would report to senior leadership and work closely with our security and engineering teams (as well as with our operations team).

In practice, we expect to grow the security team one hire at a time, so your initial set of responsibilities is likely to span both areas. We expect the distinction to clarify over time.

About the Role

You are the security architect for our research pipeline. You'll define how we securely conduct research across multiple cloud environments, partnering closely with engineering to make CI/CD, automated research agents, and large-scale compute secure by default. You would build a hardened environment where researchers and agents iterate at speed without risking data leakage, supply-chain compromise, and other security failures.

Responsibilities

1. Secure DevSecOps & CI/CD Orchestration

  • Pipeline Hardening: Build security guardrails directly into our CI/CD pipelines. Ensure that every deployment, whether manual or agent-driven, is automatically scanned, verified, and compliant.

  • Automated Verification: Establish workflows where our agents can test their own code and infrastructure changes against security policies before deploying to production environments.

  • Infrastructure as Code (IaC): Lead the implementation of "Compliance as Code." Automate the auditing and enforcement of security configurations across our AWS, GCP & neocloud footprints.

2. Supply Chain Security for Automated Research

  • Provenance and Integrity: In an environment where we rely heavily on automated coding agents, build systems to ensure the provenance of code and dependencies. Implement robust signing, SBOM (Software Bill of Materials) generation, and automated vulnerability management.

  • Agent Sandbox Security: Define and enforce security models for our research agents. Ensure that agents have the "least privilege" access required to execute experiments while remaining isolated from sensitive IP and credentials.

3. Multi-Cloud Research Infrastructure

  • Compute Security: Manage the security architecture for our high-compute research environments. We operate in a multi-cloud ecosystem; you will be responsible for consistent, zero-trust network segmentation and identity management across disparate cloud providers.

  • Research Data Protection: Develop and maintain the data handling protocols necessary for working with pre-publication research and potentially sensitive model weights.

4. Enabling Frontier Access

  • Compliance as a Competitive Advantage: Partner with AI labs to navigate security audits. You will bridge the gap between our "move fast" research culture and the high-bar security requirements of frontier model providers, turning compliance into an accelerator for our research agenda.

You May Be a Good Fit If You

  • Are a seasoned security engineer who writes code, with deep experience in Terraform, Kubernetes, and CI/CD tools (GitHub Actions, GitLab CI).

  • Have managed security across multiple cloud providers (AWS / GCP / neoclouds) and understand the nuance of securing ephemeral, high-compute research clusters.

  • Take a pragmatic approach to modern software supply chains and understand the unique risks of AI-driven development and how to mitigate them without killing velocity.

  • Understand the threat model of a high-value target for state-level actors and IP theft, and can build systems robust against sophisticated adversaries.

  • Can explain complex security trade-offs to lead researchers and scientists, saying "yes, safely" rather than just "no."

  • Are willing to use AI tools aggressively in your own workflow, with appropriate care to not get fooled!

  • Are motivated by alignment of artificial superintelligence (ASI) and want to contribute to it full-time.

Why This Role is Unique

At this organization, "Corporate Security" is a separate function. This role is focused on the Research Infrastructure. You will be working at the frontier of how automated alignment research is actually done. You will be building the security primitives for a new way of doing science: one where humans and machines collaborate to solve the most important problem of the 21st century.

Logistics

Salary: Your salary depends on the scope, autonomy, and impact we expect you to have while working at Resolution. The expected range of in-person salaries for this role is:

  • L4 (SWE II): $346,000

  • L5 (Senior SWE): $451,000

  • L6 (Staff SWE): $670,000

  • L7 (Senior Staff SWE): $930,000

We level using an internal adaptation of Google's standard levelling; the band above is indicative of where a strong candidate might come in.

Location: Berkeley, California. Remote may be considered in exceptional cases.

Benefits:

  • 5 weeks of paid vacation per year, in addition to public holidays.

  • Comprehensive healthcare insurance (medical, dental, vision).

  • Unlimited sick leave to prioritize your well-being.

  • An unconditional 401(k) contribution equal to 4% of your salary.

Visa sponsorship: We can sponsor visas for relocation to Berkeley.

Minimum education: A bachelor's degree in a field relevant to the role, or an equivalent combination of education, training, and/or professional experience that demonstrates comparable knowledge.

Deadline: Applications are rolling — please apply ASAP. We'll respond to applications within one week of receipt.

Start date: ASAP.

About Resolution

Conducts research on aligning artificial superintelligence with human intent.

Similar jobs

Security Engineer roles near Berkeley, California
16h
Save
Mark Applied
Hide
Security Engineer
San Francisco or New York City
$250k-$300k/yr OnsiteFull Time
Town
Town: AI-powered productivity assistant that automates workplace workflows.
Extensive security engineering experience, production coding ability, multi-tenant SaaS security expertise, cloud security knowledge, and experience with authentication, authorization, secrets, encryption, and threat modeling.
AWS, GCP, Google, Slack, CRM
18h
Save
Mark Applied
Hide
Security Engineer
Mountain View, California, United States
$120k-$150k/yr HybridFull Time
DataVisor
DataVisor: AI-powered fraud and financial crime detection for enterprises.
5+ YOERequires 5+ years of security engineering experience, including 2+ years in AI/ML security, AWS and GCP expertise, CSPM, AI/LLM security, threat modeling, cloud security, networking, and compliance knowledge.
AWS, GCP, IAM, EC2, S3, VPC, Compute Engine, Cloud Storage, CSPM, Claude, Amazon Bedrock, MCP, OWASP, OAuth, NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS, SIEM, SOAR, SOC 2, PCI DSS, ISO 27001, IPv4/IPv6, TCP/UDP, DHCP, HTTPS, FTP
21h
Save
Mark Applied
Hide
Lead Security Engineering - Terminals
Mountain View or San Diego
OnsiteFull Time
Logos Space
Logos Space: Develops secure LEO satellite networks for enterprise connectivity.
7+ YOEBachelor's degree in a related field, 7–10 years of security engineering experience, embedded hardware security expertise, and C/C++/Rust/Python programming skills. Knowledge of FIPS, Common Criteria, CSfC and secure provisioning required.
C, C++, Rust, Python, FIPS, Common Criteria, CSfC, 4G, 5G, PDCP, IPSEC, MACSEC, SDR
1d
Save
Mark Applied
Hide
Security Engineer II, Hybrid Cloud Guidelines
Seattle or Kirkland or San Jose or New York City
$123k-$174k/yr OnsiteFull Time
Google
GoogleNASDAQ: GOOGL: Provides online search, advertising, cloud computing, and consumer electronics.
1+ YOEBachelor's degree or equivalent experience, 1+ year coding in a general-purpose language, 1+ year in security assessments, design reviews, or threat modeling, and security engineering experience.
Terraform, Google Cloud Platform (GCP), VPC service controls (VPC-SC), IAM, AI assistants
1d
Save
Mark Applied
Hide
Security Engineer
San Francisco, California, United States
$134k-$180k/yr RemoteFull Time
Check Point Software Technologies
Check Point Software TechnologiesNASDAQ: CHKP: Provides network, cloud, and mobile cybersecurity solutions.
4+ YOERequires 4–8 years of engineering and pre-sales experience, strong analytical, problem-solving, communication, and presentation skills, network knowledge, and ability to design end-to-end security solutions.
RFI, RFP, CCNP, CISSP, CCSA, CCSE
2d
Save
Mark Applied
Hide
Senior Security Engineer, Device Platform Security Team
Sunnyvale or Seattle
$178k-$248k/yr OnsiteFull Time
Amazon
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOEBachelor's degree and 5+ years identifying security issues, assessing risks, and developing mitigations. Requires Linux and RTOS knowledge, vulnerability research, network security, cryptography, application security, and C code review.
Linux, C, C++, Ruby, Perl, Python, Bash, Android, Bluetooth, WiFi, Zigbee, Thread
2d
Save
Mark Applied
Hide
Security Engineer
San Mateo, California, United States
$155k-$190k/yr HybridFull Time
Cala Health
Cala Health: Develops non-invasive wearable neuromodulation therapies for chronic movement disorders.
3+ YOERequires 3+ years in security engineering, application security, or incident response; security tooling, CI/CD, cloud security, Python and Bash experience. U.S. work authorization or eligible sponsorship required.
Software Composition Analysis (SCA), Common Vulnerabilities and Exposures (CVEs), CI/CD, Snyk, Dependabot, Burp Suite, Splunk, Datadog, OWASP Top 10, CWE, Jenkins, GitHub Actions, GitLab CI, Python, Shell, Bash, Go, JavaScript, TypeScript, Rust, Docker, AWS, GCP, AWS Inspector, GuardDuty, Vanta, Checkov, TFLint, BugCroud, SIEM, EDR, IAM
2d
Save
Mark Applied
Hide
Principal Security Engineer | Cyber Defense Engineering
Santa Clara, California, United States
$221k-$387k/yr RemoteFull Time
ServiceNow
ServiceNowNYSE: NOW: Enterprise cloud platform for digital workflow automation.
15+ YOERequires 15+ years in security engineering, 5+ years in software engineering, enterprise-scale architecture, multi-domain security direction, and AI threat expertise. Bachelor's, master's, or PhD preferred.
LangChain, LangGraph, LLMs, RAG