Make intelligence open and accessible to all. Backed by Battery, Lightspeed and Sequoia.
About the role
The Head of Identity and Access Management is responsible for architecting, building, and operating Reflection’s identity infrastructure — the foundational security layer in an environment where the perimeter is entirely identity-based and the threat model includes sophisticated, highly motivated nation-state actors targeting intellectual property, training pipelines, and model weights.
What they're looking for
- 15+ years of dedicated experience in identity security, security architecture, or infrastructure engineering within high-growth startups, hyperscale cloud environments, or elite security teams
- Demonstrated track record of architecting and operating modern, zero-trust identity infrastructure at scale — including hardware-backed authentication, JIT credentialing, and workload identity systems
- Hands-on experience securing IAM boundaries across major cloud providers (AWS, GCP) and containerized environments, including Kubernetes identity federation and IAM roles for service accounts
- Practical experience building and operating privileged access management systems for large-scale compute environments, including GPU cluster access in cloud or neocloud contexts
- Prior experience partnering with detection and response teams to instrument identity telemetry and build adversary-focused detection logic targeting identity-layer attack techniques
- Deep, first-principles understanding of OAuth 2.0, OIDC, SAML, WebAuthn / FIDO2, and PKI — able to reason from cryptographic fundamentals, not just implement vendor tooling
More about this role
Reflection is a research lab making intelligence open and accessible for everyone to use, customize, and build on. We build open models that let anyone control their intelligence and help shape the future of AI. Our mission: make intelligence open and accessible to all.
The Head of Identity and Access Management is responsible for architecting, building, and operating Reflection’s identity infrastructure — the foundational security layer in an environment where the perimeter is entirely identity-based and the threat model includes sophisticated, highly motivated nation-state actors targeting intellectual property, training pipelines, and model weights. This leader will design and operate a bleeding-edge, zero-trust identity architecture that treats identity as software, eliminates static credentials, and protects Reflection’s researchers and massive-scale compute environments without introducing friction.
This is not a traditional enterprise IAM or Active Directory management role. The ideal candidate is a security architect and software engineer in equal measure — capable of mandating hardware-backed phishing-resistant authentication globally, building just-in-time credentialing...
Browse similar: AI jobs · AI startup jobs · Startup jobs · New York