Job Description
Security Engineer
Department: Infrastructure Security
Reports to: Senior Director / Head of Security
Role Overview
We are seeking a hands-on Security Engineer to design, implement, and maintain security controls across our GPU-as-a-Service (GPUaaS) platform and supporting infrastructure.
Reporting to the Senior Director / Head of Security, this role will focus on the practical implementation of security measures across cloud infrastructure, GPU clusters, networking systems, Kubernetes environments, CI/CD pipelines, applications, and operational tooling. The ideal candidate combines strong engineering fundamentals with experience securing high-performance computing, cloud-native, and distributed systems.
You will work closely with Platform Engineering, SRE, DevOps, Product teams to build secure-by-default systems, automate security operations, detect threats, and respond effectively to incidents.
Responsibilities
- Implement and maintain security controls across GPUaaS infrastructure, cloud environments, data centers, and production systems.
- Secure GPU clusters, bare-metal hosts, Kubernetes platforms, storage systems, management planes, and networking services.
- Configure network segmentation, firewalls, private networking, ingress and egress controls, and service-to-service security policies.
- Harden Linux hosts, container runtimes, Kubernetes clusters, hypervisors, system images, and platform components.
- Establish and maintain secure configuration baselines and system-hardening standards.
- Review infrastructure, platform, and architectural designs to identify and mitigate security risks.
- Implement workload, data, and tenant-isolation controls in multi-tenant environments.
- Protect customer workloads, model artifacts, datasets, secrets, credentials, and metadata.
- Implement IAM controls, including least privilege, RBAC, MFA, privileged access, and periodic access reviews.
- Manage secrets, encryption keys, certificates, service accounts, and credential-rotation processes.
- Deploy and maintain security monitoring, centralized logging, alerting, and detection capabilities.
- Develop detection rules, dashboards, and automated responses for suspicious or unauthorized activity.
- Participate in incident response, including investigation, containment, eradication, recovery, and post-incident analysis.
- Develop, test, and maintain incident-response playbooks and operational runbooks.
- Operate vulnerability-management processes across hosts, containers, Kubernetes, cloud services, applications, and network devices.
- Implement continuous scanning for vulnerabilities, misconfigurations, exposed secrets, insecure dependencies, and public-facing assets.
- Integrate security checks into CI/CD pipelines, infrastructure-as-code workflows, and software-development processes.
- Conduct threat modeling, secure design reviews, security testing, and remediation tracking with engineering teams.
- Build reusable security tooling, automation, dashboards, and infrastructure components.
- Support audits, customer security assessments, compliance activities, security documentation, metrics, and reporting.
Qualifications
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, or equivalent practical experience.
- 3-5 years of hands-on experience in security engineering, cloud security, infrastructure security, DevSecOps, or a related technical field.
- Strong knowledge of Linux security, networking, containers, Kubernetes, and infrastructure-as-code (e.g. SSH/OS Hardening, CVE scan and patch, Kubernetes pod security, Kyverno, OPA, Network Policy, Slurm munge keys, cgroups, filesystem)
- Experience implementing IAM controls, including least privilege, RBAC, MFA, privileged access, and secrets management.
- Experience with security monitoring, centralized logging, SIEM platforms, detection engineering, and alert investigation (e.g. security/audit/container logs, network flow, normalize/correlate events, alerts on unexpected events)
- Practical experience with vulnerability management, configuration assessment, penetration testing, and remediation.
- Experience integrating security controls into CI/CD pipelines and software-development workflows.
- Working knowledge of TLS, VPNs, DNS, firewalls, PKI, network segmentation, and related security technologies.
- Ability to automate security and infrastructure tasks using Python, Go, Bash, PowerShell, or similar languages.
- Familiarity with security tools for container scanning, dependency analysis, infrastructure-as-code scanning, and secrets detection.
- Understanding of incident response, digital forensics fundamentals, threat modeling, and security-risk prioritization.
- Experience securing GPU clusters, high-performance computing environments, AI/ML platforms, or distributed compute infrastructure.
- Knowledge of security frameworks and emerging practices, including NIST, ISO 27001, SOC 2, CIS Benchmarks or confidential computing.
More Info
Key Skills
Configuration assessment
Network segmentation
Infrastructure-as-code
IAM controls
Centralized logging
Containers



