Own Inferact's side of vLLM's vulnerability-management process, keeping critical AI inference infrastructure secure and production-grade. Independently investigate vulnerability reports, perform root-cause analysis, and drive findings from triage through coordinated resolution, advisories, and releases. Requires hands-on product security experience, strong systems reasoning, source-code debugging ability, and clear communication with maintainers, researchers, and external security collaborators.
Key Highlights
Founded by the creators and core maintainers of vLLM, working to make AI inference cheaper and faster
Hands-on product security role owning vulnerability triage, investigation, and coordinated disclosure for vLLM
Collaborate with vLLM maintainers, Red Hat counterparts, security firms, and frontier AI researchers in open source
Based in San Francisco, California; remote in the US considered for exceptional candidates
Salary range of $200,000 - $400,000 USD plus equity, with case-by-case visa sponsorship
Key Responsibilities
Own Inferact's side of vLLM's vulnerability-management process
Develop a deep understanding of vLLM's architecture, trust boundaries, and deployment assumptions
Independently investigate vulnerability reports, reproduce issues, and explain root cause and practical security impact
Drive reports from initial triage through analysis and resolution
Coordinate fixes, security advisories, and releases with maintainers, security teams, and reporters
Identify practical security best practices that strengthen vLLM as it evolves
Document evidence, affected behavior, remediation needs, and next steps with clear prioritization and risk assessment
Explore our comprehensive directory of visa sponsorship jobs from employers worldwide who are ready to sponsor talented international professionals.
Nice to Have
Experience with vulnerability management and security best practices for open-source infrastructure software
Experience coordinating vulnerability resolution across reporters, maintainers, security teams, and software releases
Familiarity with vLLM, inference engines, ML infrastructure, or similarly complex distributed software; prior vLLM contributions are helpful but not required
Experience preparing security advisories, assessing affected versions, and working with CVE and coordinated-disclosure workflows
Experience translating security findings into architecture reviews, regression tests, secure development practices, or deployment guidance
Experience resolving vulnerabilities in an open-source infrastructure project with demonstrated coordination with maintainers
Experience building security tooling or automation that improved investigation quality or reduced repetitive triage work
Experience turning recurring vulnerability patterns into maintainable fixes, tests, or documentation