Higgsfield AI
Security Infrastructure Engineer (Almaty)
- Location
- Almaty, Kazakhstan, KZ
- Arrangement
- On-site
- Employment type
- Full-time
- Posted
- 23 July 2026 (about 2 months ago)
Checked 18 days agoApplications go to the employer, never to RoleSprint
About this role
WHY WORK AT HIGGSFIELD AI?
Higgsfield AI is the fastest-scaling generative AI company in history, hitting $500M in annual revenue run rate, 25M+ users worldwide, 6M+ generations per day, and powering 390 of Fortune 500 brands.
We're building at the absolute frontier of AI-powered video creation and next-generation creative tools. Joining Higgsfield means becoming part of a high-impact team shaping the future of AI-native experiences, at a company that isn't just moving fast, but rewriting what fast looks like.
Role Overview
We're looking for a hands-on Infrastructure Security Engineer to own security across our cloud and ML infrastructure — the platform that trains our models and serves millions of generations a day.
The work spans tenant isolation for user-deployed apps, GPU cluster security, and model protection from training pipeline to serving. You'll sit between Security, DevOps, and ML Engineering.
You'll own both immediate implementation work and long-term operational responsibility: cloud and ML infrastructure security, vulnerability management, monitoring, and access governance.
KEY RESPONSIBILITIES
We are looking for someone with experience in scaling high-growth startups who can make an immediate impact in the following areas:
Cloud & Network Security
- Evaluate, implement, and maintain cloud security tooling.
- Own infrastructure and container vulnerability management across our cloud environments, and drive remediation.
- Design and implement network segmentation to tighten internal security boundaries.
- Build centralized security monitoring across cloud infrastructure.
Corporate Access Control
- Own access governance and credential management across cloud and internal tooling.
- Partner with Engineering, DevOps, and IT to raise identity and access management standards.
Technical Leadership:
- Set the technical direction for infrastructure security and lead cross-functional projects turning the standards you set into tooling and guardrails engineers actually ship with.
Requirements:
Few people will match all of these. If you're strong on some and eager to learn the rest, apply anyway.
- 7+ years in infrastructure security or security engineering, including time at a high- growth startup.
- Deep hands-on experience securing a major cloud provider and a container orchestrator, managed with infrastructure-as-code (AWS, Kubernetes, Terraform).
- Experience securing ML workloads — training or inference infrastructure, GPU clusters, or model-serving platforms.
- Solid networking, operating systems, and cryptography fundamentals.
- Strong grasp of container and infrastructure security practices and vulnerability management.
- Comfortable working cross-functionally with DevOps, Engineering, and ML teams; able to independently find and close security gaps.
- High agency.
Nice to have
- Experience with sandboxing, container isolation, or secure execution environments for untrusted code.
- Experience with CSPM rollouts.
- Incident response and security monitoring experience.
- Familiarity with SOC 2 or similar frameworks.
WHAT WE OFFER:
- Competitive base salary in USD
- Equity: participation in the company’s stock option program, giving you the opportunity to share in the company’s long-term growth.
- On-site role in our Almaty office (we will relocate you from anywhere).
Work location
- Almaty, Kazakhstan, KZ
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Advertised by Higgsfieldai and published on Ashby, the applicant tracking system they use.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 23 July 2026, last checked 18 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.