IT and Security Specialist
Epoch AI is looking for an IT and Security Specialist to own the systems, accounts and access the whole team depends on, and to set the security standards that protect our research and our data. You would decide who can reach what, run the accounts and tools we all work in, find and fix security risks yourself, and work with our engineers and researchers so that our protocols get followed rather than worked around. About the role
We want someone who can make Epoch meaningfully harder to attack without slowing the team down. Two things sit at the centre of the job. The first is access: who can reach which systems, and keeping that current as people join, move between projects and leave. The second is security itself, setting the standards and doing the hands-on work to make them real. You would work closely with our engineering and research teams, set standards that work in practice, and own the decisions behind them.
Day to day you would be finding and fixing security risks, doing the hands-on work yourself, and making calls on questions like how we implement 2FA. A lot of the job is judging whether a control is worth the friction it adds. Our default is not to add a process unless there is a clear reason for it. You would write very little code in this role, but you would work with engineers constantly.
An ideal candidate might have 5+ years across security and IT operations. Security judgement is the part we care most about: a practical, risk-based sense of which threats are worth a control and which are not. Having been the person who owns access at a growing organisation is useful but not essential. We would rather hire someone with strong security instincts who can pick up the access side than the other way round.
This role is fully remote, and we are able to hire in most locations between the US Pacific and Central European time zones. We invite anyone who is interested to apply, regardless of background, experience, or credentials. Please do not include a cover letter, photograph, or headshot of yourself, or any personal information that is not relevant to the role for which you're applying (including marital status, age, identity traits, etc.).
Applications are rolling; please apply quickly.
Key Responsibilities
- Set our security protocols and keep them current, without adding processes the team does not need.
- Identify and remediate security risks: both the hands-on technical work, and making sure engineers and researchers implement security measures correctly.
- Own implementation decisions, such as our approach to 2FA, and be able to explain the tradeoffs behind them.
- Partner with our engineering and research teams to set security standards that are workable in practice.
- Hold us to the standards we set, and keep them light enough that people actually follow them.
- Own who can reach what across Google Workspace, GitHub, AWS, Google Cloud, 1Password, Slack and Airtable, and grant, change and remove that access as people join, switch projects or leave.
- Hold the admin and owner roles on our core platforms, so that access decisions do not queue behind our COO.
- Run our cloud accounts and software subscriptions: new projects, IAM, budgets and quota increases, plus seats, licences, renewals and nonprofit pricing.
- Own the technical half of onboarding and offboarding: every account and group a new person needs on their first day, and a clean removal when someone leaves.
- Be the first person staff come to when something technical breaks. We are remote, so this is accounts and software rather than deskside hardware.
What we're looking for
- 5+ years of experience in security, DevSecOps, IT operations, or a similar field.
- Experience owning security at a medium-sized organisation, rather than only advising on it.
- Experience with complex technical and research projects, ideally in the AI space.
- Fluency working with engineers. You will write very little code in this role, but you will wor