11 дней назад
Senior Platform Security Engineer (Kubernetes)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Platform Security Engineer (Kubernetes/AI infrastructure): Securing Firmus’s multi-tenant Kubernetes and AI FactoryOS platforms with an accent on runtime enforcement, workload identity, admission and network policy, and DevSecOps release controls. Focus on building eBPF-based detection, validating tenant-isolation boundaries, investigating production security anomalies, and maintaining ISO 27001 and NIST-aligned operational evidence.
Location: Based in Australia or Singapore, with travel to Australian AI Factory sites as required
Company
operates large-scale GPU infrastructure and AI FactoryOS, a proprietary platform for managing telemetry, cooling, power, grid interaction, and AI cloud operations across its sites.
What you will do
- Build and operate eBPF-based runtime visibility and enforcement using tools such as Cilium, Falco, and Tetragon.
- Own delivery-pipeline security gates covering image signing, software bills of materials, vulnerability gating, and policy checks.
- Define and validate admission policy, workload identity, network policy, and control-plane security for the multi-tenant Kubernetes estate.
- Test tenant-isolation and blast-radius controls against realistic failure and attack paths, and provide findings to platform engineering teams.
- Investigate security-related operational anomalies, lead technical escalation for platform security faults, and contribute to post-incident reviews.
- Monitor privileged activity across identity, certificate, and secrets platforms while producing operational security evidence.
Requirements
- Strong experience with privileged-access security, least-privilege design, secrets management, and production auditing.
- Extensive experience securing multi-tenant Kubernetes environments, including admission policy, workload identity, network policy, and control-plane hardening.
- Extensive experience with eBPF-based runtime security tooling and detection or enforcement integrated with security monitoring.
- Strong DevSecOps experience with image signing, software bills of materials, vulnerability gating, policy checks, and policy-as-code.
- Experience with tenant isolation, security escalation in 24/7 production environments, post-incident reviews, and security automation using Python, Go, or Bash.
- Ability to be based in Australia or Singapore and travel to Australian AI Factory sites when required.
Nice to have
- Experience securing GPU or HPC infrastructure and multi-tenant AI workloads.
- Experience in a cloud, colocation, or multi-tenant service-provider environment.
- Experience with ISO 27001, SOC 2, or NIST frameworks and security evidence production.
- Relevant security certification such as OSCP, GCFA, or a Kubernetes security credential.
- Bachelor’s degree in computer science, engineering, or a related discipline, or equivalent experience and training.
Culture & Benefits
- Work within a 24/7 operations function supporting production AI infrastructure.
- Share the after-hours escalation roster with other senior engineers.
- Collaborate with AI Infrastructure, Shared Services Operations, and Service Delivery teams.
- Operate security controls in line with ISO 27001 and NIST frameworks.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →