RAND logo
RAND

RAND is an independent non-profit that regularly engages with senior stakeholders within the USG, allied governments, and relevant industry stakeholders. This position is a 3-year term appointment with a possibility of renewal, alongside options for longer-term employment. Salary range is $90,400 - $274,300, depending on experience and qualifications.

Open Source Research Resident, Emerging Technology & Security

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 1,001-5,000

Location

United States

Posted

1 day ago

Salary

$90.4K - $274.3K / year

Seniority

Mid Level

Job Description

Open Source Research Resident, Emerging Technology & Security

RAND

Role Description The RAND Center on AI, Security, and Technology's mission is to understand and address emerging threats to global security, particularly biosecurity and AI security. We are looking for an Open Source Research Resident to use online information to investigate and monitor emerging threats at the intersection of AI, biosecurity, and national security. You will build and maintain a picture of the actors, capabilities, and trends that matter most, and turn open-source signals into intelligence that drives concrete action. - Following developments in Chinese AI, compute, and the semiconductor supply chain - Tracking scientific and technical progress in high-consequence areas of biology, including emerging research directions such as mirror-life - Monitoring for early signs of AI loss of control, including indicators of misalignment, deceptive or power-seeking behavior, and failures of human oversight in frontier systems - Mapping technology and talent flows between the US and China - Analyzing Chinese progress in biosecurity and the life sciences Day to day, you will run investigations across a wide range of open and commercial sources, track technical and scientific developments, map organizations and talent networks, and produce clear, decision-ready assessments for both internal teams and external government and industry partners. Qualifications - Excellent analytic skills - Ability to communicate clearly and effectively, both orally and in writing - Ability to work effectively as a member of a multi-disciplinary team - Strong commitment to RAND's core values of quality and objectivity - Hands-on role with an operator's mindset - Motivated by mission-driven work - Track record of rigorous open-source analysis in a fast-paced environment - Experience spanning national security, technology, and foreign-actor tracking - Sharp analytic tradecraft with sound judgment about source reliability and significance - Comfortable working across ambiguity on novel questions - 5 years or more of relevant experience preferred - Familiarity with AI or the life sciences is a strong plus Requirements - A minimum of a Bachelor's degree in a relevant field is required - Relevant fields include: - Applied Mathematics - Applied Physics - Artificial Intelligence - Biology - Biostatistics - Business - Chemistry - Computer Engineering - Computer Science - Cybersecurity - Economics - Electrical Engineering - Engineering and Public Policy - Engineering Physics - Epidemiology - Geology - Health Services Management - Information Security - Information Technology - International Relations - Law - Machine Learning - Mathematics - National Security Policy - Natural and Physical Sciences - Philosophy - Physics - Policy Analysis - Political Science - Public Administration - Public Health - Public Policy - Security Studies - Statistics - Technology and Policy - Technical Discipline - or similar - Minimum experience requirements for an Associate Biosecurity Resident or Associate AI Policy Resident: - A PhD in a relevant field - OR a Master’s degree in the fields listed above with at least 3 years of relevant professional experience - OR a Bachelor’s degree in the fields listed above with at least 5 years of relevant professional experience - Minimum education and experience requirements for a Technical Resident, Associate I: - A Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, Information Security, Information Technology, Mathematics, Applied Mathematics, Physics, Applied Physics, Engineering Physics, Artificial Intelligence, Machine Learning, Engineering and Public Policy, Technology and Policy, National Security Policy, Policy Analysis, Political Science, International Relations, or similar AND 1 year AI-focused real-world experience - Ability to obtain and maintain a U.S. security clearance, which includes having U.S. citizenship, is preferred but not required Benefits - Health insurance coverage - Life and disability insurance - Savings plan - Paid time-off - Additional sabbatic pay when vacation is taken Company Description RAND is an independent non-profit that regularly engages with senior stakeholders within the USG, allied governments, and relevant industry stakeholders. This position is a 3-year term appointment with a possibility of renewal, alongside options for longer-term employment. Salary range is $90,400 - $274,300, depending on experience and qualifications.

Related Categories

Related Job Pages

More Security Engineer Jobs

OpenSpace logo

Senior Security Engineer

OpenSpace

OpenSpace is on a mission to bring new levels of transparency to construction.

Full TimeRemoteTeam 201-500H1B No Sponsor

Role Description Security is in OpenSpace's DNA. A significant portion of our core engineering team — including several of our most senior engineers — came together at a security SaaS company before OpenSpace, and that shows up in how we design systems, review code, and think about customer data. We run a mature program today: an external security partner handles pen testing and structured assessments, our DevOps and IT team owns infrastructure security, IAM, and endpoint, and product engineers carry real ownership of the code they ship. What we don't yet have is a dedicated in-house security engineer, and the surface area is growing fast — particularly as AI changes how code gets written and where sensitive data flows. This role is about going from strong to elite: building the proactive security review muscle that lives day-to-day inside the engineering org, rather than at the cadence of an external engagement. You'll partner with our existing security consultant rather than replace them. They keep running pen tests and structured assessments; you build the in-house practice that catches issues long before they reach one. What you will be doing: - Run proactive security reviews of new features, architectures, and third-party integrations before they ship - Build out our application and product security practice: threat modeling, design review, secure SDLC integration - Own our approach to AI-related security risk, including: - Securing our own AI/ML systems and the data flowing through them - Governing internal use of AI dev tools (Claude Code and similar) so we move fast without leaking sensitive data - Reviewing AI-assisted code contributions and helping us evolve our policies as the tooling matures - Partner with engineering teams to triage and remediate vulnerabilities from pen tests, customer findings, and internal discovery - Support our SOC 2 and ISO 27001 programs as a key technical contributor (compliance ownership lives elsewhere, but you'll be the engineering voice in the room) - Help mature our incident response practice and run security tabletop exercises - Build internal tooling and automation that scales security review without bottlenecking shipping - Work with our consultant on scoping pen tests, vendor assessments, and customer security reviews Qualifications - 5+ years in security engineering, application security, or product security - Hands-on experience doing proactive security review (threat modeling, design review, secure code review) on production systems - Strong fundamentals in web application security, cloud security (we run primarily on AWS and GCP), and modern auth patterns - Comfortable reading and reviewing code across at least one of our stacks (Python, Java/Kotlin, TypeScript) - A real point of view on how AI changes the security landscape, both as a new risk surface and as new tooling for defenders - Track record of working effectively in a startup or fast-moving environment where you have to prioritize ruthlessly and make tradeoffs - Ability to influence engineers without owning their roadmap Requirements - Nice to have: - Experience as the first or early security hire at a growth-stage company - Hands-on contributor experience with SOC 2 and/or ISO 27001 - Background in security automation, internal tooling, or open source security work - Familiarity with construction tech, geospatial systems, or computer vision Benefits - 🩺 100% employer-paid medical, dental, and vision coverage - 🌴 Flexible paid time off - 💰 401(k) with company match - 👶 Paid parental leave - 🏡 Home office stipend - 🤝 Employee referral program - ✈️ Annual company retreats and team gatherings Base Salary $180,000-$230,000 The “Base Salary: range represents the low and high end of the anticipated salary range for this position across all US locations including but not limited to CA, CO, NY, WA, NV, MD, CT and RI. The determination of this anticipated Base Salary involves the consideration of many factors in making compensation decisions including but not limited to: location of candidate, unique skill sets, experience, training, performance, licensure and certifications, as well as other business and organizational needs. Please note: We are unable to provide visa sponsorship or employment-based immigration support for this position. Applicants must be authorized to work in the country of employment without current or future sponsorship. #LI-Remote OpenSpace welcomes employees from varied backgrounds and walks of life, and it’s reflected in our diverse community. OpenSpace is proud to be an equal opportunity employer and is committed to providing equal employment opportunities to all employees and applicants for employment, without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

United States
$180K - $230K / year
Ionic Partners logo

Group Security & Compliance Manager

Ionic Partners

Helping companies overcome the second chasm

Full TimeRemoteTeam 11-50H1B No Sponsor

• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering

Argentina
$60K / year
Full TimeRemoteTeam 11-50Since 1998H1B No Sponsor

• Manage the network and security infrastructure • Ensure configuration, maintenance, and automation of connectivity and protection environments • Configure VIPs and Pools on F5 LTM • Renew SSL certificates on load balancers • Manage firewall rules on Check Point and Fortinet • Perform firewall audits • Block malicious IPs • Create and propagate VLANs • Manage switch ports via API • Manage Site-to-Site VPN tunnels • Manage IP addressing

Brazil
Nöord Technologies logo

Information Security Specialist

Nöord Technologies

Your Digital Transformation Partner

Full TimeRemoteTeam 11-50Since 2004H1B No Sponsor

• Threat monitoring • Proactively monitor and analyze security data to detect advanced threats and vulnerabilities. • Produce key indicators (risk and performance) and actionable intelligence to strengthen the organization’s security posture. • Manage security incidents, from initial analysis through full resolution. • Conduct post-incident reviews and recommend preventive measures. • Independently perform in-depth security assessments to identify vulnerabilities and recommend remediation strategies. • Maintain the information security risk register, oversee audits, and assess vendor security practices. • Develop information security awareness materials. • Act as a subject-matter advisor to support cybersecurity program objectives and compliance initiatives. • Draft, update, and maintain information security policies, procedures, and standards (access management, passwords, network security, PAP, etc.). • Ensure documentation aligns with best practices (NIST, ISO 27001, etc.). • Coordinate SOC 2 (Type 1 and Type 2) compliance activities, including audit readiness. • Document and implement required security controls. • Respond to security questionnaires from clients or partners (cybersecurity, privacy, business continuity, etc.). • Collaborate with internal teams to obtain relevant technical or organizational responses. • Participate in defining and implementing technical and organizational controls (access management, logging, backups, etc.). • Develop security response procedures (incident response, vulnerability management, SIEM alert handling, etc.). • Establish repeatable and well-documented processes.

Canada