Skip to content
FluidstackFluidstackNew York, NY

Information Security Engineer, Bare Metal

Build and own end-to-end security for Fluidstack's bare metal AI compute fleet, from supply chain to decommissioning. Harden Linux, enforce BMC security, implement zero-trust networking and encryption at gigawatt scale.

168k – 225k/yr
On-site5+ YOESecurity Engineering

About the role

Responsibilities

  • Own end-to-end security for every server in the bare metal fleet, from supply chain and provisioning through hardening, operation, and secure decommissioning.
  • Design and maintain hardened golden OS images with automated vulnerability scanning, patch pipelines, and configuration-drift detection.
  • Define and enforce the BMC security model (access control, credential rotation, audit logging, firmware integrity).
  • Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture, applying zero-trust from the top-of-rack up.
  • Implement data-at-rest encryption, key management, and secure storage access at fleet scale; build automation that makes secure-by-default the path of least resistance.
  • Lead threat modeling and security reviews for new hardware platforms and network designs.
  • Respond to incidents touching the physical fleet.

Requirements

  • Experience in information security or infrastructure engineering with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure.
  • Deep Linux hardening (SELinux, AppArmor, kernel-level security).
  • Strong network security knowledge (TCP/IP, VPNs, firewall rulesets, zero-trust).
  • Practical experience implementing encryption (disk-level LUKS, hardware-level), HSMs, and trusted computing (TPM/TXT).
  • Fluency automating in Python, Go, or Rust; experience with configuration management (Ansible, Puppet, Chef).
  • Ability to work across engineering teams and communicate security decisions clearly.

Nice-to-Haves

  • Experience with BMC platforms (OpenBMC, iDRAC, iLO).
  • Knowledge of hardware root of trust and secure boot.
  • Familiarity with compliance standards (SOC 2, ISO 27001, FedRAMP).
  • Certifications such as CISSP, OSCP, or CEH.

Skills

linux hardeningselinuxapparmorkernel securitynetwork securityzero-trustencryptionlukshsmtpmPythonGoRustAnsiblebmc security
Clickhouse

Incident Response Security Engineer

ClickhouseUnited States

Handles security incidents, develops detection and response processes, maintains logging platforms, and automates risk mitigation for cloud services. Requires experience in incident response, threat modeling, cloud security, and programming in Golang/Python.

169k – 225k/yr
RemoteSecurity Engineering
Collective Intelligence Project

Product Security Engineer

Collective Intelligence ProjectSan Francisco, CA

Build and operate an agentic application security program using AI for automated testing, triage, and PR review. Drive end-to-end vulnerability remediation, eliminate vulnerability classes via code changes, and lead threat modeling for a fintech platform handling sensitive financial data. Requires 4+ years appsec experience, hands-on tooling expertise, enthusiasm for LLMs, and Python engineering skills.

170k – 200k/yr
Hybrid4+ YOESecurity Engineering
Crusoe

Endpoint Security Engineer

CrusoeSan Francisco, CA +2

Security Engineer responsible for endpoint security architecture, MDM administration (Jamf, Intune), compliance enforcement, and automation across macOS, Windows, iOS, and Android devices. Requires 3-6 years MDM experience, OSQuery/CrowdStrike expertise, and a security-first mindset.

170k – 205k/yr
On-site3+ YOESecurity Engineering
Suno

Software Engineer, Trust & Safety

SunoSan Francisco, CA

Suno is seeking a Software Engineer, Trust & Safety to protect its platform and users from abuse, fraud, and harmful content. This role involves building data pipelines, anomaly detection systems, and internal tools to ensure user safety and platform integrity.

170k – 240k/yr
On-site3+ YOESecurity Engineering
Lumin Digital

Vulnerability Automation Engineer

Lumin DigitalUnited States

Designs and builds autonomous vulnerability automation pipelines using AI tools to discover assets, scan vulnerabilities, harden configurations, and auto-remediate in cloud-native environments. Requires 5+ years in security engineering, DevSecOps, IaC, and cloud security tools.

170k – 190k/yr
Remote5+ YOESecurity Engineering