Logo for Epoch AI

IT and Security Specialist

Role overview

Qualifications

  • 5+ years of experience in security, DevSecOps, IT operations, or a similar field
  • Experience owning security at a medium-sized organisation
  • Fluency working with engineers
  • Experience with complex technical and research projects, ideally in the AI space

Responsibilities

  • Set our security protocols and keep them current, without adding processes the team does not need
  • Identify and remediate security risks, both the hands-on technical work, and making sure engineers and researchers implement security measures correctly
  • Own implementation decisions, such as our approach to 2FA, and be able to explain the tradeoffs behind them
  • Partner with our engineering and research teams to set security standards that are workable in practice

Key facts

Other skills

  • Communication
  • Teamwork
  • Problem Solving

About the company

Epoch AI logo

Epoch AI

Research & Scientific Services

Epoch AI is a multidisciplinary research institute investigating the trajectory of Artificial Intelligence (AI). We scrutinize the driving forces behind AI and forecast its ramifications on the economy and society. We emphasize making our research accessible through our reports, models and visualizations to help ground the discussion of AI on a solid empirical footing. Our goal is to create a healthy scientific environment, where claims about AI are discussed with the rigor they merit.

Company details

IndustryResearch & Scientific Services
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Epoch AI is looking for an IT and Security Specialist to own the systems, accounts and access the whole team depends on, and to set the security standards that protect our research and our data. You would decide who can reach what, run the accounts and tools we all work in, find and fix security risks yourself, and work with our engineers and researchers so that our protocols get followed rather than worked around.

About the role

We want someone who can make Epoch meaningfully harder to attack without slowing the team down. Two things sit at the centre of the job. The first is access: who can reach which systems, and keeping that current as people join, move between projects and leave. The second is security itself, setting the standards and doing the hands-on work to make them real. You would work closely with our engineering and research teams, set standards that work in practice, and own the decisions behind them.
 
Day to day you would be finding and fixing security risks, doing the hands-on work yourself, and making calls on questions like how we implement 2FA. A lot of the job is judging whether a control is worth the friction it adds. Our default is not to add a process unless there is a clear reason for it. You would write very little code in this role, but you would work with engineers constantly.
 
An ideal candidate might have 5+ years across security and IT operations. Security judgement is the part we care most about: a practical, risk-based sense of which threats are worth a control and which are not. Having been the person who owns access at a growing organisation is useful but not essential. We would rather hire someone with strong security instincts who can pick up the access side than the other way round.
 
This role is fully remote, and we are able to hire in most locations between the US Pacific and Central European time zones. We invite anyone who is interested to apply, regardless of background, experience, or credentials. Please do not include a cover letter, photograph, or headshot of yourself, or any personal information that is not relevant to the role for which you're applying (including marital status, age, identity traits, etc.). 

Applications are rolling; please apply quickly. 


Key Responsibilities
  • Set our security protocols and keep them current, without adding processes the team does not need.
  • Identify and remediate security risks: both the hands-on technical work, and making sure engineers and researchers implement security measures correctly.
  • Own implementation decisions, such as our approach to 2FA, and be able to explain the tradeoffs behind them.
  • Partner with our engineering and research teams to set security standards that are workable in practice.
  • Hold us to the standards we set, and keep them light enough that people actually follow them.
  • Own who can reach what across Google Workspace, GitHub, AWS, Google Cloud, 1Password, Slack and Airtable, and grant, change and remove that access as people join, switch projects or leave.
  • Hold the admin and owner roles on our core platforms, so that access decisions do not queue behind our COO.
  • Run our cloud accounts and software subscriptions: new projects, IAM, budgets and quota increases, plus seats, licences, renewals and nonprofit pricing.
  • Own the technical half of onboarding and offboarding: every account and group a new person needs on their first day, and a clean removal when someone leaves.
  • Be the first person staff come to when something technical breaks. We are remote, so this is accounts and software rather than deskside hardware.

  • What we're looking for
  • 5+ years of experience in security, DevSecOps, IT operations, or a similar field.
  • Experience owning security at a medium-sized organisation, rather than only advising on it.
  • Experience with complex technical and research projects, ideally in the AI space.
  • Fluency working with engineers. You will write very little code in this role, but you will work closely and constantly with people who do.
  • Experience running IT or security operations: identity, access, endpoints and cloud. Deep knowledge of Google Workspace administration and AWS IAM is a strong plus.
  • Comfort holding admin authority and making access decisions without a committee.
  • Familiarity with AI research and with what Epoch does is a plus. If you don’t tick all these boxes but think you would be a great fit, please consider applying anyway!


    Compensation & Benefits
  • Annual salary between $125,000 and $155,000 USD. 
  • Salaries are not restricted to USD, and contracts and payments are usually in local currencies. Conversions are based on one-year average exchange rates.
  • Fully remote environment, including flexible work hours. 
  • Competitive global benefits program, including a comprehensive health insurance program—including supplemental benefits specific to a local country, as available and mandated by local law—and life insurance and a pension plan, if applicable in your country.
  • Generous paid time off (PTO), including no specific annual limit, with 30 days PTO per year protected, unlimited personal and sick leave, and 4 months paid parental leave for permanent staff with at least 12 months of tenure (prorated parental leave if less than 12 months). 
  • A flexible and generous expense policy for you to spend on equipment and a large range of productivity tools or learning/development opportunities, including unlimited spending on AI tools, subject to regulations and manager approval. 
  • Paid work trips, including 3 staff retreats per year and relevant conferences.
  • Access to our very well-equipped offices in Berkeley, California, including paid meals, snacks, gym, and more. All staff, independently of where they are based, have access to the office for at least 20 days each year.
  • Additional Information

    While we welcome applicants from all time zones, we prefer candidates who can overlap with UTC–8 (Pacific Time) and UTC+1 (Central European Time), as most of our staff work in this range of time zones. We also prefer candidates who can travel: we hold three retreats per year, during which we record podcast episodes and other communication efforts.

    Please submit all of your application materials in English and note that we require professional level English proficiency.

    Epoch is committed to building an inclusive, equitable, and supportive community for you to thrive and do your best work. We’re committed to finding the best people for our team, so please don’t hesitate to apply for a role regardless of your age, gender identity/expression, political identity, personal preferences, physical abilities, veteran status, neurodiversity or any other background. Please email careers@epoch.ai if you have any questions about this role. However, we will not review applications submitted to this email address; please submit your application through the link on this page. 

    About Epoch AI

    Epoch AI is a research institute that investigates trends in machine learning and the economic consequences of AI. Our mission is to develop a comprehensive, publicly accessible knowledge base on AI that informs policymakers, industry leaders, and society at large.

    We strive to achieve both rigor and accessibility to our work, as exemplified by some of our most successful projects, including our database of AI models and our AI trends dashboard. Our body of research includes our work on compute trends (IJCN 2022), data scarcity (ICML 2024), and algorithmic progress (NeurIPS 2024). You can read more about our work and mission on our website and in this Time profile.

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    ·

    IT Security Manager Related jobs

    Other jobs at Epoch AI

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.