11 дней назад
Principal Platform Identity Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Principal Platform Identity Engineer (AI): Building and operating the identity, certificate authority, secrets management, and privileged-access trust plane for a large-scale AI infrastructure estate with an accent on infrastructure-as-code, automated credential rotation, and auditable access controls. Focus on designing dual-control key custody, just-in-time elevation, resilient recovery paths, and production evidence for ISO 27001 and SOC 2.
Location: Based in Australia or Singapore, with travel to Australian AI Factory sites as required. The role shares an after-hours escalation roster in a 24/7 operating function.
Company
operates large-scale AI infrastructure and AI FactoryOS, an integrated platform for GPU telemetry, cooling, power, grid interaction, and AI cloud operations.
What you will do
- Design, build, and operate workforce and service identity platforms, including single sign-on and identity-provider integrations.
- Own the internal certificate authority, certificate lifecycle management, and secrets management platforms, including rotation, access policies, and audit.
- Automate identity, certificate, and secrets provisioning through CI/CD and infrastructure-as-code workflows.
- Implement privileged access management with just-in-time elevation, change-record approval, and controlled break-glass access.
- Design dual-control key custody, delegated authority, quorum operations, and tested recovery for production cryptographic material.
- Provide senior technical escalation, mentor engineers, and produce access and certificate evidence for audits and customer due diligence.
Requirements
- Deep experience designing, building, and operating identity and access management platforms, including SSO and identity-provider integration.
- Strong experience with internal PKI, certificate lifecycle management, and secrets management platforms, including rotation, access policy, and audit.
- Practical experience with privileged access management, just-in-time elevation, break-glass design, HSMs, and dual-control or quorum-based key custody.
- Understanding of zero-trust architecture, multi-tenant platforms, CI/CD, infrastructure as code, and identity automation using Python, Go, Bash, or similar.
- Experience as a senior escalation point for identity and security-related faults in a 24/7 production environment.
- Clear technical communication and understanding of evidence and control requirements for ISO 27001 and SOC 2.
Nice to have
- Experience with Kubernetes-native identity patterns such as workload identity or SPIFFE/SPIRE.
- Experience in a multi-tenant service provider, cloud, or colocation environment.
- Familiarity with GPU or HPC infrastructure and related identity and access requirements.
- Security or identity certification, or a degree in computer science, engineering, or a related discipline.
Culture & Benefits
- Hands-on ownership of a production trust plane supporting a large-scale AI infrastructure estate.
- 24/7 operational coverage with first-line monitoring and response provided by the operations centre.
- Shared after-hours escalation responsibility with senior engineers in the function.
- Work focused on automation, resilience, auditability, and replacing manual access processes with software-defined controls.
Hiring process
- No hiring process details are provided.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →