OVERVIEW
Physical Superintelligence is a startup with roots at Google, NVIDIA, Harvard, Meta, MIT, Oxford, Johns Hopkins, Cambridge, and the Perimeter Institute building AI systems to discover new physics at scale. We are seeking engineers to build platform infrastructure at the intersection of computational science, AI systems, and software engineering.
Our mission is to discover and commercialize transformative physics breakthroughs at scale with artificial superintelligence, safely, verifiably, and for broad public benefit.
The last century's golden age of physics gave us transistors, lasers, and nuclear energy. We believe artificial superintelligence will unlock the next one. We're creating the infrastructure to industrialize scientific discovery and usher in this new era.
We have one product: new physics, at scale.
ROLE AND
RESPONSIBILITIES
- Own end-to-end security strategy for PSI. Architect security into our AI platform, paid API, and enterprise customer engagements before they ship, not after. Application security, cloud security, identity and access management, secrets management, audit logging, and detection and response are yours to design and run.
- Lead SOC2 readiness and, at the right time, additional compliance programs such as ISO 27001 and customer-specific security questionnaires. Translate compliance
requirements
into engineering controls that engineers actually adopt, not paperwork that slows the team.
- Set the security bar in architecture and design reviews across the AI platform. Threat-model new runtimes, agent integrations, multi-tenant isolation, model-provider risk, training-data integrity, and customer-facing surfaces. Decide which risks are acceptable and which are not, with explicit reasoning the rest of the engineering team can trust.
- Build and lead the security function as PSI scales. Operate as the single technical security voice today; hire and grow a small high-leverage team over the next 18 months. Own incident response, third-party and model-provider risk, and the security relationship with enterprise customers in physics, energy, and adjacent verticals.
WHAT WE'RE LOOKING FOR
- Eight or more years in security engineering at scale, with a track record at companies known for security maturity (e.g., Google, Stripe, Cloudflare, Microsoft, Apple, Snowflake, Databricks, Palantir, or comparable). You have built security functions, not just contributed to them.
- Deep technical fluency across application security, cloud security on GCP, AWS, or Azure, identity and access management, and DevSecOps in Kubernetes-native environments. You read code, write Python for security tooling, and architect controls that engineers willingly adopt.