About Starya
Starya develops AI for complex operations. We connect artificial intelligence, software, and data to transform real business processes with security, reliability, and control.
Our platform, NebulaOS, is the foundation for building, integrating, and operating these solutions. Our work combines engineering close to customers, product development, and a foundation of data, infrastructure, and security.
The challenge
Embed security in NebulaOS services, integrations, and operational paths. Translate threats into implementable requirements and help build and verify controls with component owners. Organize evidence and priorities to fix vulnerabilities, investigate incidents, and support release decisions, considering identity, isolation, data, and the effects of executed actions.
What you will do
- Model threats to journeys and integrations, mapping identities, data, tools, trust boundaries, and alternative execution paths. Produce abuse scenarios and protection requirements with owners and verification criteria, reviewing the design when purpose, model, or permissions change.
- Implement and review authorization with component engineers: roles, attributes, credential scope, and the binding between approval and executed parameters. Create denial tests for unauthorized actions, changes after approval, and direct access that could bypass the verification point.
- Build checks for isolation between organizations in APIs, queries, caches, files, queues, and support paths. Test reads and writes with different contexts, verify scope propagation, and document evidence of separation, including behavior when identity is missing or context is invalid.
- Integrate secret, credential, and technical access management into deployment and operational workflows. Implement or support rotation, revocation, and privilege reduction, check exposure in configuration and logs, and define with SRE how to validate changes and recover affected services.
- Investigate code, dependency, and configuration vulnerabilities, reproducing their effects and prioritizing fixes by exposure and consequence. Collaborate on corrections, add regression tests, and verify their effectiveness; record exceptions with justification, an owner, and a condition for reassessment.
- Test AI-specific threats such as malicious instructions in documents, unauthorized information extraction, and tool abuse. Verify effects in the target system and enforcement of permissions; build reproducible scenarios with appropriate data to guide Engineering and Research fixes.
What we look for
- Knowledge of application security, authentication, and authorization, with the ability to relate identity, resource, operation, and context to the control that must be implemented.
- Ability to code security fixes and tests, review code, and reproduce vulnerabilities, verifying control behavior in the real integration.
- Understanding of isolation between organizations and data protection in storage, transit, and processing, including support interfaces and context propagation between services.
- A foundation in networking, cloud, and containers to evaluate exposure, permissions, and secret management, working with infrastructure owners on implementation and validation.
- Ability to communicate risk with evidence, record recommendations, and prioritize fixes with Engineering and Product, protecting sensitive information during tests and investigations.
Additional experience
- Experience with security in AWS, OCI, or equivalent environments, including identity policies, declarative configurations, and automated checks in the delivery process.
- Experience analyzing software dependencies, artifacts, and pipelines, connecting provenance, publishing permissions, and fixes to the development lifecycle.
- Participation in AI application evaluation or incident response, with abuse scenarios, reproducible evidence, and collaboration between research, engineering, and operations.
Your impact
Your work will be tracked through test coverage of critical controls, treatment of vulnerabilities according to exposure, recurring failures, and review of exceptions. Evidence of isolation, authorization, and revocation helps decide whether to release changes. Analysis must consider what was actually verified and dependencies still being addressed.
Who you build with
You work with SWE and FDEs on control implementation, with Data on information paths, and with SRE on access and operational protection. Research contributes to AI scenarios and QA to regression testing. Security provides the technical assessment; risk acceptance is escalated to the designated authority with context for the decision.