Skip to content
FluidstackFluidstack

Information Security Engineer, Bare Metal

Build and own end-to-end security for Fluidstack's bare metal AI compute fleet, from supply chain to decommissioning. Harden Linux, enforce BMC security, implement zero-trust networking and encryption at gigawatt scale.

About the job

Responsibilities

  • Own end-to-end security for every server in the bare metal fleet, from supply chain and provisioning through hardening, operation, and secure decommissioning.
  • Design and maintain hardened golden OS images with automated vulnerability scanning, patch pipelines, and configuration-drift detection.
  • Define and enforce the BMC security model (access control, credential rotation, audit logging, firmware integrity).
  • Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture, applying zero-trust from the top-of-rack up.
  • Implement data-at-rest encryption, key management, and secure storage access at fleet scale; build automation that makes secure-by-default the path of least resistance.
  • Lead threat modeling and security reviews for new hardware platforms and network designs.
  • Respond to incidents touching the physical fleet.

Requirements

  • Experience in information security or infrastructure engineering with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure.
  • Deep Linux hardening (SELinux, AppArmor, kernel-level security).
  • Strong network security knowledge (TCP/IP, VPNs, firewall rulesets, zero-trust).
  • Practical experience implementing encryption (disk-level LUKS, hardware-level), HSMs, and trusted computing (TPM/TXT).
  • Fluency automating in Python, Go, or Rust; experience with configuration management (Ansible, Puppet, Chef).
  • Ability to work across engineering teams and communicate security decisions clearly.

Nice-to-Haves

  • Experience with BMC platforms (OpenBMC, iDRAC, iLO).
  • Knowledge of hardware root of trust and secure boot.
  • Familiarity with compliance standards (SOC 2, ISO 27001, FedRAMP).
  • Certifications such as CISSP, OSCP, or CEH.

Skills

Linux Hardening, Selinux, Apparmor, Kernel Security, Network Security, Zero-Trust, Encryption, Luks, Hsm, Tpm, Python, Go, Rust, Ansible, Bmc Security

Zoox

Zoox

Foster City, CA

Sensing and Perception System Safety Engineer
$170k+/yrHybrid3+ YOESecurity Engineering

Develops safety requirements, analyses, and fail-operational architectures for autonomous-vehicle sensing and perception systems. The role requires 3+ years analyzing safety-critical systems and familiarity with functional-safety standards, sensing hardware, perception, and cross-functional systems engineering.

Greptile

Greptile

San Francisco, CA

Security Engineer
$170k+/yrOn-site3+ YOESecurity Engineering

Own the security posture of a fast-growing developer product across application, infrastructure, cloud, and internal systems. The role requires at least three years of relevant engineering or security experience, strong vulnerability judgment, and hands-on JavaScript or TypeScript expertise.

Vannevar

Vannevar

United States

Application Security Engineer
$160k+/yrRemote5+ YOESecurity Engineering

The Application Security Engineer will embed security practices throughout the SaaS software development lifecycle, including threat modeling, automated testing, vulnerability remediation, and incident response. The role requires 5+ years of application or product security experience and expertise with DevSecOps workflows, web applications, and CI/CD automation.

Wiz

Wiz

Washington, DC

Cyber Threat Intel Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The Cyber Threat Intel Analyst tracks, investigates, attributes, and reports on advanced threats targeting cloud, AI, and developer environments. The role requires at least three years of security or threat research experience and strong technical analysis and writing skills.

Fireworks AI

Fireworks AI

San Mateo, CA

GRC Analyst
$160k+/yrOn-site3+ YOESecurity Engineering

The GRC Analyst will operate and mature security and compliance programs across major privacy and security frameworks, supporting risk assessments, access reviews, third-party risk, control monitoring, and audits. The role requires 3–5 years of GRC or information security experience and strong cross-functional communication.