Назад
Company hidden
обновлено 13 дней назад

Linux Systems Engineer – Identity, PKI & Security (IDM)

Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Europe
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Linux Systems Engineer – Identity, PKI & Security (IDM) (Linux identity, PKI, and security): Building automated identity, certificate, SSH authentication, and secrets-management infrastructure for a European AI cloud with an accent on Linux-native access control, short-lived certificates, and declarative configuration. Focus on integrating Kanidm, SSSD, PAM, NSS, step-ca, OpenBao, OIDC, and OAuth2 while translating security policies and threat models into hardened production systems.

Location: Fully remote within the EU

Company

hirify.global is building a European AI cloud for training, experimenting with, and deploying AI models using GPUs powered by 100% renewable energy.

What you will do

  • Own Kanidm as the central identity source of truth and manage Linux host integrations with SSSD, PAM, and NSS.
  • Design and automate short-lived SSH Certificate Authority workflows for host and user authentication.
  • Operate step-ca for internal PKI and OpenBao for decentralized secrets management.
  • Use SaltStack and Ansible to enforce declarative configuration across identity services, OpenSSH, and system access policies.
  • Partner with Security Engineering to implement compliance requirements, zero-trust controls, and threat models in hardened Linux infrastructure.
  • Build and troubleshoot OIDC and OAuth2 integrations across internal engineering tools.

Requirements

  • Deep hands-on experience managing Linux systems at scale, including RHEL and Debian families.
  • Strong knowledge of SSSD, PAM, NSS, and OpenSSH authentication systems.
  • Operational expertise with SaltStack and/or Ansible for configuration management and zero-drift infrastructure.
  • Practical experience implementing SSH CAs, short-lived host and user certificates, and automated internal TLS issuance.
  • Understanding of OIDC, OAuth2, WebAuthn/FIDO2, and POSIX identity mapping.
  • Ability to translate security policies into precise system configurations, automation scripts, and infrastructure code.

Nice to have

  • Production experience with Kanidm, OpenBao, or step-ca.
  • Experience migrating from Active Directory or Windows domain architectures to Linux-native identity stacks.
  • Experience writing SSSD plugins, PAM modules, or Python/Rust tooling for system administration.

Culture & Benefits

  • Full-time, permanent employment.
  • Cash and equity compensation with healthcare, lunch, wellbeing, and other fringe benefits.
  • Work alongside engineers, researchers, and partners across the global AI ecosystem.
  • Low-hierarchy environment with an international workforce representing 31 nationalities.
  • Start date as soon as possible.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →