Member of Technical Staff, Security at Mount Thor | CA, US | Rezi

Member of Technical Staff, Security at Mount Thor

Member of Technical Staff, Security

Mount Thor · CA, US

3 weeks ago

Member of Technical Staff, Security

Mount Thor · CA, US

21 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Member of Technical Staff, Security role.

Rezi rewrites your resume against Mount Thor's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Member of Technical Staff, Security posting at Mount Thor — free, in seconds.

About the Role

You will own security engineering and the CI/CD systems that build, test, and deploy Mount Thor’s software. Your responsibilities span software delivery, infrastructure automation, customer data protection, and the engineering controls behind enterprise compliance.

Responsibilities

  • Build security into our infrastructure and products.
  • Review designs, threat model systems, and implement protections across APIs, cloud environments, containers, host systems, and customer workload isolation.
  • Own CI/CD and DevOps engineering.
  • Build and operate our build, test, and deployment pipelines, runners, artifact repositories, and infrastructure automation.
  • Own environment provisioning, release workflows, deployment verification, and rollback.
  • Improve delivery speed, reliability, and developer experience.
  • Integrate security scanning, secrets management, artifact provenance, and access controls throughout these systems.
  • Own identity, access, and secrets management.
  • Implement least privilege, service identity, privileged access, credential rotation, and access reviews across production and internal systems.
  • Build access controls for both people and software agents.
  • Protect customer data throughout its lifecycle.
  • Build controls for data collection, access, encryption, retention, deletion, and logging.
  • Work with engineering and legal partners to translate privacy requirements and customer commitments into enforceable system behavior.
  • Build and operate our SOC 2 Type 2 controls.
  • Translate requirements into engineering work, automate evidence collection and control checks, coordinate technical walkthroughs with auditors, and drive findings through remediation.
  • Keep evidence connected to how production systems actually operate.
  • Own the engineering response to enterprise security requirements.
  • Lead technical security reviews with customers, explain our architecture and controls, evaluate requirements, and deliver the changes needed to support customer adoption.
  • Keep security documentation and customer commitments accurate.
  • Build detection and response capabilities.
  • Establish useful security telemetry, investigate threats, lead security incidents, and turn findings into lasting improvements.
  • Own vulnerability management and coordinate penetration testing and remediation.
  • Use agentic engineering throughout the work.
  • Use coding agents to investigate, implement, and validate changes.
  • Build tools that let agents inspect security posture, gather evidence, and perform bounded actions with appropriate authorization and auditability.

Requirements

  • Strong software engineering skills in Go, Python, Rust, or a similar language, with experience shipping and operating production software.
  • Hands-on experience securing cloud infrastructure, APIs, containers, and distributed systems.
  • Experience owning production CI/CD systems and infrastructure as code, including diagnosing failed builds and deployments, managing environments, and improving release reliability.
  • Experience securing CI/CD pipelines, build infrastructure, deployment workflows, and software dependencies.
  • Depth in identity and authorization, secrets management, encryption, network security, and tenant isolation.
  • Experience implementing and operating controls for SOC 2 Type 2 or a comparable security assurance program.
  • Practical knowledge of privacy and data protection, including access controls, data minimization, retention, and deletion.
  • Experience investigating security incidents, prioritizing vulnerabilities, and delivering remediation.
  • The ability to explain technical systems clearly to engineers, customers, auditors, and leadership.
  • A record of taking broad, ambiguous security work from design through implementation and production operation.

Skills

  • Go
  • Python
  • Rust
  • CI/CD
  • DevOps
  • Infrastructure as Code
  • Identity and Authorization
  • Secrets Management
  • Encryption
  • Network Security
  • Tenant Isolation
  • SOC 2 Type 2
  • Privacy and Data Protection
  • Incident Investigation
  • Vulnerability Management
  • Agentic Engineering
  • macOS
  • Apple Silicon
  • Host Security
  • Secure Boot
  • Hardware-backed Credentials
  • Compliance Automation
  • Policy-as-Code
  • Continuous Control Monitoring
  • Workload Identity
  • Artifact Signing
  • Build Provenance
  • Isolated Build Environments
  • Data Residency
  • Customer-Managed Encryption
  • Dedicated Environments
  • Coding Agents
  • Computer-use Systems
  • Execution of Untrusted Code

About the Company

  • Mount Thor makes Apple hardware (macOS and Apple Silicon) available and performant at datacenter scale for AI workloads.
  • We take consumer hardware and build the infrastructure platform around it to enable consumption as elastic compute exposed through developer-friendly interfaces.
  • Our customers use us to develop computer-use model capabilities, deploy long-running agents, and accelerate agentic engineering.