# Information Security Engineer, Bare Metal

**Company:** [Fluidstack](https://hotfix.jobs/companies/fluidstack)
**Location:** New York, NY, San Francisco, CA, Austin, TX, Seattle, WA
**Role:** Security Engineering
**Salary:** $168k – $225k/yr
**Experience:** 5+ years
**Skills:** linux hardening, selinux, apparmor, kernel security, network security, zero-trust, encryption, luks, hsm, tpm, Python, Go, Rust, Ansible, bmc security
**Posted:** 2026-07-17

> Build and own end-to-end security for Fluidstack's bare metal AI compute fleet, from supply chain to decommissioning. Harden Linux, enforce BMC security, implement zero-trust networking and encryption at gigawatt scale.

## Job Description

## Responsibilities
- Own end-to-end security for every server in the bare metal fleet, from supply chain and provisioning through hardening, operation, and secure decommissioning.
- Design and maintain hardened golden OS images with automated vulnerability scanning, patch pipelines, and configuration-drift detection.
- Define and enforce the BMC security model (access control, credential rotation, audit logging, firmware integrity).
- Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture, applying zero-trust from the top-of-rack up.
- Implement data-at-rest encryption, key management, and secure storage access at fleet scale; build automation that makes secure-by-default the path of least resistance.
- Lead threat modeling and security reviews for new hardware platforms and network designs.
- Respond to incidents touching the physical fleet.

## Requirements
- Experience in information security or infrastructure engineering with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure.
- Deep Linux hardening (SELinux, AppArmor, kernel-level security).
- Strong network security knowledge (TCP/IP, VPNs, firewall rulesets, zero-trust).
- Practical experience implementing encryption (disk-level LUKS, hardware-level), HSMs, and trusted computing (TPM/TXT).
- Fluency automating in Python, Go, or Rust; experience with configuration management (Ansible, Puppet, Chef).
- Ability to work across engineering teams and communicate security decisions clearly.

## Nice-to-Haves
- Experience with BMC platforms (OpenBMC, iDRAC, iLO).
- Knowledge of hardware root of trust and secure boot.
- Familiarity with compliance standards (SOC 2, ISO 27001, FedRAMP).
- Certifications such as CISSP, OSCP, or CEH.

## Similar roles

- [Incident Response Security Engineer](https://hotfix.jobs/jobs/d002a19f-a1ab-4434-977e-b1a71be0e1c8) - Clickhouse - Remote - $169k – $225k/yr
- [Product Security Engineer](https://hotfix.jobs/jobs/04dc8629-c86c-4c38-a6ac-226ed3e7a745) - Collective Intelligence Project - San Francisco, CA - $170k – $200k/yr
- [Endpoint Security Engineer](https://hotfix.jobs/jobs/e9f904e5-b1d3-4a26-b61e-06c5e375ab90) - Crusoe - San Francisco, CA - $170k – $205k/yr
- [Software Engineer, Trust & Safety](https://hotfix.jobs/jobs/7d005694-1f26-43da-8d18-cb58960d2d1e) - Suno - San Francisco, CA - $170k – $240k/yr
- [Vulnerability Automation Engineer](https://hotfix.jobs/jobs/1a05493d-ddf1-4123-8eaa-22774b293d93) - Lumin Digital - Remote - $170k – $190k/yr

**Apply:** https://hotfix.jobs/jobs/c5206931-5d18-4b55-8654-12590cef008b
**Canonical:** https://hotfix.jobs/jobs/c5206931-5d18-4b55-8654-12590cef008b