For Employers

Inferact

Member of Technical Staff, Vulnerability Management

Posted 2 days ago
$200K - $400K per year
5-10 years experience
Apply Now

Please mention DailyRemote when applying

?
Resume Match Score

See how much of this job your resume covers, and what’s missing.

Want a recruiter to go through it line by line?

Get professional review

Create a cover letter for this job

Upload your resume and we draft a letter for this exact role, tailored to what it asks for.

  • Tailored to this role
  • Based on your resume
  • Fully editable
AI Summary

You will own the vulnerability management process for vLLM, investigating reports and coordinating fixes with maintainers and security researchers. You will also drive security advisories and implement best practices to strengthen the infrastructure of this AI inference engine.

Overview

Inferact's mission is to grow vLLM as the world's AI inference engine and accelerate AI progress by making inference cheaper and faster. Founded by the creators and core maintainers of vLLM, we sit at the intersection of models and hardware, a position that took years to build.

About the Role

We're looking for a Member of Technical Staff, Vulnerability Management to own Inferact's side of vLLM's vulnerability-management process and help keep a critical piece of AI infrastructure secure and production-grade. You'll develop a deep understanding of vLLM's architecture, independently investigate vulnerability reports, and turn technical findings into clear, actionable work for the core team.

Working primarily in open source, you'll collaborate with vLLM maintainers, Red Hat counterparts, security firms, and researchers working with frontier AI models. You'll drive reports from initial triage through analysis and resolution, helping coordinate fixes, security advisories, and releases under the project's established process. You'll also identify practical security best practices that strengthen vLLM as it evolves. This is a hands-on product security role that combines technical investigation, sound judgment, and ownership of follow-through.

vLLM's vulnerability-management process

Skills and Qualifications

Minimum qualifications:

  • Hands-on product security experience, with a strong orientation toward infrastructure software and the security of complex software systems.

  • Ability to read source code, debug unfamiliar systems, reproduce reported issues, and explain root cause and practical security impact rather than simply forward findings.

  • Strong systems reasoning, including the ability to understand architecture, trust boundaries, deployment assumptions, and how different software components interact.

  • Ability to learn vLLM's core architecture and independently manage vulnerability investigations while bringing in maintainers where their expertise is needed.

  • Sound prioritization and risk-assessment judgment, with clear documentation of evidence, affected behavior, remediation needs, and next steps.

  • Strong written and verbal communication, discretion with sensitive reports, and the ability to work constructively with engineers, researchers, and external security collaborators.

     

Preferred qualifications:

  • Experience with vulnerability management and security best practices for open-source infrastructure software.

  • Experience coordinating vulnerability resolution across reporters, maintainers, security teams, and software releases.

  • Familiarity with vLLM, inference engines, ML infrastructure, or similarly complex distributed software; prior vLLM contributions are helpful but not required.

  • Experience preparing security advisories, assessing affected versions, and working with CVE and coordinated-disclosure workflows.

  • Experience translating security findings into practical architecture reviews, regression tests, secure development practices, or deployment guidance.

     

Bonus points if you have:

  • Helped resolve vulnerabilities in an open-source infrastructure project and can explain your technical contribution and coordination with maintainers.

  • Built security tooling or automation that improved investigation quality or reduced repetitive triage work.

  • Turned recurring vulnerability patterns into maintainable fixes, tests, or documentation that helped prevent similar issues.

Logistics

  • Location: This role is based in San Francisco, California. Will consider remote in the US for exceptional candidates.

  • Compensation: Depending on background, skills, and experience, the expected annual salary range for this position is $200,000 - $400,000 USD + equity.

  • Visa sponsorship: We sponsor visas on a case-by-case basis.

  • Benefits: Applicable benefits will be confirmed based on the final role location.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Others jobs →

AI Response Evaluator

Freelance France, Japan, Mexico +3 more $10K – $20K Others

Government Business Development Manager

Full Time United States Others

BCBA, LBA

Full Time United States $60000 - $100K per year Others

B2B-myyjiä logistiikka-alan myyntiin!

Full Time Finland Others

Entrepreneur in Residence - full-time (m/w/d)

Full Time Germany €4000 - €10000 per month Others

Head of Operations

Full Time United States Others
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Featuring 212,197+ Jobs in Others

Answer easy questions

Answer easy questions

212,197+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified