Solutions Architect – AI Infrastructure Security
Boston, United States · Remote · Full-time
- Posted 1h ago
- From Mirantis’s careers page
- Location
- Boston, United States
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 8+ years
- Department
- Engineering
Opens the listing on jobs.smartrecruiters.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Company Description
Mirantis, an IREN company, is the Kubernetes-native AI infrastructure company, enabling organizations to build and operate scalable, secure, and sovereign infrastructure for modern AI, machine learning, and data-intensive applications. By combining open source innovation with deep expertise in Kubernetes orchestration, Mirantis empowers platform engineering teams to deliver composable, production-ready developer platforms across any environment, on-premises, in the cloud, at the edge, or in sovereign data centers. Committed to open standards and freedom from lock-in, Mirantis ensures that customers retain full control of their infrastructure strategy.
Job Description
We are seeking a Senior Solutions Architect with deep security expertise to join the Voyager team in the Mirantis Office of the CTO. You will own the security solutioning of k0rdent AI, our platform for building and operating GPU clouds and AI factories, from metal to model.
You will define how k0rdent AI environments are secured end to end: the hardware and firmware they boot from, the hosts, virtual machines and Kubernetes clusters they run, the networks and storage they share, the secrets and certificates that hold them together, and the AI models and applications they serve. You will turn that design into published reference architectures, working code and proofs of concept that run on real hardware with our customers and partners.
As part of the Office of the CTO, research is a core part of the job. You will explore threats, designs and technologies before customers ask for them, prototype ideas that may not ship, and challenge established practice when a better approach exists.
This role combines research with hands-on, outward-facing work. You will split your time between exploring new designs, writing architecture, building and validating it in the lab, and explaining it to engineers, security teams, executives and conference audiences.
Key Responsibilities
- Design and publish security reference architectures and solution designs for k0rdent AI, covering single-tenant private AI clouds, multi-tenant GPU clouds and hybrid deployments.
- Define a defence-in-depth model across the stack, from hardware root of trust and firmware to hosts, virtual machines, Kubernetes, networks, storage, models and applications.
- Define tenant isolation boundaries and their guarantees, and document their strengths, weaknesses and cost to strengthen.
- Map designs to the controls and frameworks customers must meet, and document trade-offs with defensible reasoning.
- Own bare-metal and host security, including secure and measured boot, TPM-based attestation, BMC and Redfish hardening, firmware integrity, and hardened Linux hosts.
- Own virtual machine security, including hypervisor and KubeVirt hardening, VM isolation, and the implications of PCI passthrough and SR-IOV for GPUs and NICs.
- Own Kubernetes security, including RBAC, Pod Security Standards, admission control, policy-as-code, runtime security, and secure multi-cluster and multi-tenant operation.
- Design secrets management, certificates and PKI, network security, storage security, and public cloud security controls for hybrid deployments.
- Define how Transformer-based models are protected through their lifecycle, secure inference services against threats such as prompt injection and model exfiltration, and secure the software supply chain for platforms, containers and models.
- Track and evaluate emerging security technologies, prototype alternative designs in the lab, and publish findings as research notes, papers, blog posts or talks.
- Build and run proofs of concept with customers and partners, write automation and tooling that make reference architectures reproducible, and assess designs through threat modelling and hands-on testing.
- Act as the security subject matter expert in customer discovery, design reviews and architecture workshops, support customer security reviews, work with hardware and security partners, and present at industry events.
Location, Travel and Working Model
- This role is remote and based in the United States, with a strong preference for the East Coast.
- Work with a team spread across many time zones; some meetings will fall outside standard local hours.
- Travel of up to 25% for customer engagements, partner meetings, lab work and industry events, primarily within the US and EU.
Qualifications
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity or a related field, or equivalent practical experience.
- 8+ years in security engineering or security architecture, with at least 3 years securing cloud, Kubernetes or large-scale infrastructure platforms.
- Customer-facing experience as a solutions architect, pre-sales engineer, consultant or technical lead.
- Required technical skills include cloud security on at least one major public cloud (AWS, Azure or GCP) and on private cloud or bare-metal, Linux hardening, secure boot, TPM, hypervisor and VM isolation including KubeVirt, Kubernetes security, secrets and key management, PKI and identity, network security, storage and data security, AI security, software supply chain security, and programming or scripting in Python or Go.
- Behaviours we value: curiosity, ownership, proactivity, fast learning, business acumen, excellent written and spoken English, and comfort presenting to large audiences.
Nice to Have
- Experience with compliance frameworks such as NIST SP 800-53, NIST AI RMF, FedRAMP, SOC 2, ISO/IEC 27001, CIS benchmarks or DISA STIGs.
- Hands-on experience with confidential computing and remote attestation.
- Experience securing GPU cloud, neocloud or HPC environments.
- Experience with DPUs such as NVIDIA BlueField.
- Offensive security or red-teaming experience, including against AI systems.
- Experience with Mirantis products, MKE, k0s or k0rdent security.
- Security certifications such as CISSP, CCSP, CKS, OSCP, or public cloud security specialty certifications.
- Open-source security or Kubernetes contributions, public talks, standards body participation, or published research.
- Additional languages beyond English.
Skills they ask for
Pick one to see other roles that ask for it.
About Mirantis
Build AI infrastructure your wayMirantis provides tools for building and operating AI-ready infrastructure across environments, including its k0rdent AI platform.
See all 11 roles at MirantisMore roles at Mirantis
See all 11- Solutions ArchitectBoston · Senior · RemoteEngineering · Senior · RemoteBoston, United States5h
- Network EngineerCampbell · Senior · On-siteInformation Technology · Senior · On-siteCampbell, United States2d
- Product ManagerAustin · RemoteProduct Management · RemoteAustin, United States2w
- Senior AI Infrastructure & Platform Operations EngineerSenior · RemoteInformation Technology · Senior · Remote2w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.