Palo Alto, California
Product Security Engineer, Cloud & Infrastructure Security
Location: Palo Alto, CA (on-site)
About 1X
We’re an AI and robotics company based in Palo Alto, California, on a mission to build a truly abundant society through general-purpose robots capable of performing any kind of work autonomously.
We believe that to truly understand the world and grow in intelligence, humanoid robots must live and learn alongside us. That’s why we’re focused on developing friendly home robots designed to integrate seamlessly into everyday life.
We’re looking for curious, driven, and passionate people who want to help shape the future of robotics and AI. If this mission excites you, we’d be thrilled to hear from you and explore how you might contribute to our journey.
Role Overview
We are seeking a Product Security Engineer focused on cloud and infrastructure security to ensure the resilience and integrity of the platforms that power our robotics systems. In this role, you will design and enforce secure cloud architectures, identity and access management strategies, and CI/CD protections. You will also build and maintain security-critical services that enable secure communication, authentication, and data protection across our fleet. This position is key to safeguarding our systems at scale.
Responsibilities
Develop and maintain security critical cloud services, working closely with relevant teams
Implement infrastructure as code (IaC) security practices to ensure consistent, secure deployments and automated remediation of configuration drift
Design and manage identity and access management systems to enforce just-in-time access and least-privilege permissions across all cloud services
Protect CI/CD pipelines against poisoning and credential theft, enforce access controls, and validate artifact integrity throughout the software supply chain
Develop and maintain cloud-native security services including device authentication, data protection, and secure communication with the fleet
Architect secure cloud networks through VPC segmentation, traffic filtering, private connectivity, and access control mechanisms
Configure and operate cloud security posture management (CSPM) tooling, enforce protections against common misconfigurations, and correlate events for incident response across cloud and edge devices