IT and Security Specialist
- Role
- Security
- Experience
- Senior
- Employment
- Full-time
Open to UTC-8…UTC+1. Set where you work from to check your eligibility.
No BS summary
Security/IT specialist with 5+ years across security and IT operations. Needs practical security judgement, access ownership instincts, professional English, and ability to work remotely between US Pacific and Central European time zones.
Required languages
Epoch AI is looking for an IT and Security Specialist to own the systems, accounts and access the whole team depends on, and to set the security standards that protect our research and our data. You would decide who can reach what, run the accounts and tools we all work in, find and fix security risks yourself, and work with our engineers and researchers so that our protocols get followed rather than worked around. About the role We want someone who can make Epoch meaningfully harder to attack without slowing the team down. Two things sit at the centre of the job. The first is access: who can reach which systems, and keeping that current as people join, move between projects and leave. The second is security itself, setting the standards and doing the hands-on work to make them real. You would work closely with our engineering and research teams, set standards that work in practice, and own the decisions behind them.
Day to day you would be finding and fixing security risks, doing the hands-on work yourself, and making calls on questions like how we implement 2FA. A lot of the job is judging whether a control is worth the friction it adds. Our default is not to add a process unless there is a clear reason for it. You would write very little code in this role, but you would work with engineers constantly.
An ideal candidate might have 5+ years across security and IT operations. Security judgement is the part we care most about: a practical, risk-based sense of which threats are worth a control and which are not. Having been the person who owns access at a growing organisation is useful but not essential. We would rather hire someone with strong security instincts who can pick up the access side than the other way round.
This role is fully remote, and we are able to hire in most locations between the US Pacific and Central European time zones. We invite anyone who is interested to apply, regardless of background, experience, or credentials. Please do not include a cover letter, photograph, or headshot of yourself, or any personal information that is not relevant to the role for which you're applying (including marital status, age, identity traits, etc.). Applications are rolling; please apply quickly.
What you'll do
- Own the systems, accounts and access the whole team depends on.
- Set the security standards that protect Epoch AI's research and data.
- Decide who can reach what.
- Run the accounts and tools the team works in.
- Find and fix security risks yourself.
- Work with engineers and researchers so protocols get followed rather than worked around.
- Make Epoch meaningfully harder to attack without slowing the team down.
- Keep access current as people join, move between projects and leave.
- Set standards that work in practice and own the decisions behind them.
- Do hands-on security work and make calls on questions like how to implement 2FA.
- Judge whether a control is worth the friction it adds.
- Work with engineers constantly.
What they require
- 5+ years across security and IT operations.
- Practical, risk-based security judgement about which threats are worth a control and which are not.
- Strong security instincts.
- Professional level English proficiency.
- Submit all application materials in English.
- Preferred: Having been the person who owns access at a growing organisation.
- Preferred: Candidates who can overlap with UTC–8 (Pacific Time) and UTC+1 (Central European Time).
- Preferred: Candidates who can travel for three retreats per year.
Benefits
- Fully remote role.
- Inclusive, equitable, and supportive community.
- Opportunity to do your best work.
Epoch AI is a research institute that investigates trends in machine learning and the economic consequences of AI. Its mission is to develop a comprehensive, publicly accessible knowledge base on AI that informs policymakers, industry leaders, and society at large.