We are building one of the most potentially consequential companies of the century. Our mission is to accelerate the world's transition to fusion energy while safeguarding humankind. This is not a normal company. This is not a normal job. We are committed for the long term to win.
About the RoleWe're hiring our first dedicated Security Engineer to own security across a growing and technically diverse footprint: cloud infrastructure, software development practices, control systems, and data collection pipelines. You'll work alongside our IT Systems Administrator, who owns day-to-day device/identity operations - you'll set the security strategy, standards, and technical controls, and partner with them on enforcement. This role sits at the intersection of cloud security, DevSecOps, and OT/control-systems security with real ownership from day one.
What We ValueObsess about the details — sloppy work costs us later, so do it right the first time.
Care — pick up the trash. Do things no one asks you to do. Go the extra mile because you care.
Act with urgency — every hour matters more than it feels like it does.
Be responsible for the outcome, not just the task; if it is not working, it remains your problem until it is fixed.
Assume good intent — disagree openly, then commit fully once a call is made.
Own security posture for AWS infrastructure managed via Terraform and Spacelift, including IAM policy review, secrets management, and network segmentation.
Partner with engineering to build security into the SDLC and CI/CD pipeline - code scanning, dependency/vulnerability management, secure defaults for new services.
Assess and secure control systems and data collection infrastructure.
Own and operate our security monitoring and detection tooling; triage alerts and build out detection coverage over time.
Define access-control standards (conditional access, least privilege, MFA policy) in IdP and across SaaS tools; partner with IT Admin on enforcement.
Define MDM security baselines (macOS/Windows) for IT to implement and maintain.
Build and lead incident response efforts when issues arise.
Track security risk across the environment and lay groundwork for relevant compliance frameworks as the company matures.
Run periodic security awareness efforts (phishing simulations, training) for a non-security-native team.
4+ years in a security engineering role spanning cloud security and application/DevSecOps work.
Strong hands-on experience with AWS and Infrastructure-as-Code (Terraform).
Practical experience with identity security — SSO/IdP policy (Okta or equivalent), conditional access, least-privilege design.
Experience with a security monitoring/detection platform (SIEM, EDR, or specialized tools) — alert triage, tuning, investigation.
Solid understanding of secure SDLC practices — SAST/DAST, dependency scanning, secrets management, code review for security issues.
Strong ability to communicate risk clearly to non-security stakeholders and make pragmatic trade-offs for a small, fast-moving company.
Direct experience securing control systems, OT, or industrial environments.
Experience with CI/CD-integrated IaC workflows (Spacelift or similar).
Experience with data collection pipeline security (data integrity, sensor/telemetry access controls).
Prior experience as employee #1 or #2 on a security team, building programs from scratch.
Compliance experience (SOC 2, ISO 27001, NIST, or sector-specific frameworks relevant to hardware/control systems companies).
Scripting/automation skills (Python, Go) to build custom detections or automate security tooling.
Experience in a company where hardware, CAD/simulation workstations, or physical systems intersect with traditional IT.
Comfortable being the sole dedicated security resource, setting strategy while partnering with IT for day-to-day enforcement.
Availability for incident response outside standard business hours when needed.
Based in or willing to work from our San Leandro, CA office given the control systems and hardware-adjacent scope of the role.
Occasional travel to other Fuse locations.
Willingness to obtain relevant certifications (e.g., AWS Security, GIAC/GSEC) if not already held, as the role and compliance needs mature.
Medical, dental, and vision coverage.
Relocation assistance for roles that require it.
Flexible time off. Take what you need, no accrual tracking.
2 weeks of paid time off built into the end of each year (subject to team and business needs).
10+ paid holidays.
Supportive leave of absence policies.
Paid leave for new parents.
Access to a 401(k) retirement plan.
Meals provided on site at our San Leandro and Napierville facilities.
To conform to U.S. Government technology export regulations, including the International Traffic in Arms Regulations (ITAR), you must be a U.S. citizen, lawful permanent resident of the U.S., protected individual as defined by 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.
Equal OpportunityFuse is an Equal Opportunity Employer; employment with Fuse is governed on the basis of merit, competence, and qualifications and will not be influenced by race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, ancestry, immigration status, sexual orientation, gender identity, marital status, mental or physical disability, or any other legally protected status.
Skills Required
- 4+ years of experience in security engineering spanning cloud security and application or DevSecOps work
- Strong hands-on experience with AWS and Terraform
- Practical experience with identity security, including SSO or IdP policies, conditional access, and least-privilege design
- Experience with security monitoring or detection platforms such as SIEM, EDR, or specialized tools, including alert triage, tuning, and investigation
- Understanding of secure SDLC practices, including SAST, DAST, dependency scanning, secrets management, and security-focused code review
- Ability to communicate security risk clearly to non-security stakeholders and make pragmatic trade-offs
- Ability to work as the sole dedicated security resource while partnering with IT on enforcement
- Availability for incident response outside standard business hours when needed
- Based in or willing to work from the San Leandro, California office
- Must meet ITAR eligibility requirements as a U.S. citizen, lawful permanent resident, protected individual, or person eligible to obtain required authorizations
- Willingness to obtain relevant certifications such as AWS Security or GIAC/GSEC
- Direct experience securing control systems, OT, or industrial environments
- Experience with CI/CD-integrated infrastructure-as-code workflows, including Spacelift or similar
- Experience securing data collection pipelines, including data integrity and sensor or telemetry access controls
- Experience as the first or second member of a security team building programs from scratch
- Compliance experience with SOC 2, ISO 27001, NIST, or relevant sector-specific frameworks
- Python or Go scripting and automation experience for custom detections or security tooling
- Experience in environments involving hardware, CAD or simulation workstations, or physical systems alongside traditional IT
What We Do
Fuse is on a mission to accelerate the world's transition to fusion energy while safeguarding humankind. Since 2019, we've built 3 functioning and record-breaking pulsed power fusion machines, with dual applications: commercial power generation (long term), and supporting the US and Allies' national security through radiation effects testing capabilities (immediate term). TITAN, our latest machine, is the world's first high-power (1TW) Impedance Matched Marx Generator, with experimental results peer-reviewed and published in Nature Scientific Reports: https://www.nature.com/articles/s41598-024-67774-4 TITAN is the building block of our technology roadmap, leading to fusion pilot plant demonstration with APEIRON I. Learn more and apply to join at www.f.energy








