Skip to content

Open nowPosted 7 days ago

Member of Technical Staff, Vulnerability Management

Inferact34 open roles

Pay
$200,000 – $400,000 a year
Where
San Francisco
Work mode
On site
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowMember of Technical Staff, Vulnerability ManagementInferact · San Francisco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Inferact's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Inferact postings stay open a median of 19 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 7 days ago

Inferact median: 19 days open

The posting

OVERVIEW

Inferact's mission is to grow vLLM as the world's AI inference engine and accelerate AI progress by making inference cheaper and faster. Founded by the creators and core maintainers of vLLM, we sit at the intersection of models and hardware, a position that took years to build.

ABOUT THE ROLE

We're looking for a Member of Technical Staff, Vulnerability Management to own Inferact's side of vLLM's vulnerability-management process and help keep a critical piece of AI infrastructure secure and production-grade. You'll develop a deep understanding of vLLM's architecture, independently investigate vulnerability reports, and turn technical findings into clear, actionable work for the core team.

Working primarily in open source, you'll collaborate with vLLM maintainers, Red Hat counterparts, security firms, and researchers working with frontier AI models. You'll drive reports from initial triage through analysis and resolution, helping coordinate fixes, security advisories, and releases under the project's established process. You'll also identify practical security best practices that strengthen vLLM as it evolves. This is a hands-on product security role that combines technical investigation, sound judgment, and ownership of follow-through.

vLLM's vulnerability-management process https://docs.vllm.ai/en/latest/contributing/vulnerability_management/

SKILLS AND QUALIFICATIONS

Minimum qualifications:

- Hands-on product security experience, with a strong orientation toward infrastructure software and the security of complex software systems.

- Ability to read source code, debug unfamiliar systems, reproduce reported issues, and explain root cause and practical security impact rather than simply forward findings.

- Strong systems reasoning, including the ability to understand architecture, trust boundaries, deployment assumptions, and how different software components interact.

- Ability to learn vLLM's core architecture and independently manage vulnerability investigations while bringing in maintainers where their expertise is needed.

- Sound prioritization and risk-assessment judgment, with clear documentation of evidence, affected behavior, remediation needs, and next steps.

- Strong written and verbal communication, discretion with sensitive reports, and the ability to work constructively with engineers, researchers, and external security collaborators.

Preferred qualifications:

- Experience with vulnerability management and security best practices for open-source infrastructure software.

- Experience coordinating vulnerability resolution across reporters, maintainers, security teams, and software releases.

- Familiarity with vLLM, inference engines, ML infrastructure, or similarly complex distributed software; prior vLLM contributions are helpful but not required.

- Experience preparing security advisories, assessing affected versions, and working with CVE and coordinated-disclosure workflows.

- Experience translating security findings into practical architecture reviews, regression tests, secure development practices, or deployment guidance.

Bonus points if you have:

- Helped resolve vulnerabilities in an open-source infrastructure project and can explain your technical contribution and coordination with maintainers.

- Built security tooling or automation that improved investigation quality or reduced repetitive triage work.

- Turned recurring vulnerability patterns into maintainable fixes, tests, or documentation that helped prevent similar issues.

LOGISTICS

- Location: This role is based in San Francisco, California. Will consider remote in the US for exceptional candidates.

- Compensation: Depending on background, skills, and experience, the expected annual salary range for this position is $200,000 - $400,000 USD + equity.

- Visa sponsorship: We sponsor visas on a case-by-case basis.

- Benefits: Applicable benefits will be confirmed based on the final role location.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Inferact's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Inferact's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Inferact's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.