Cloud Infrastructure Security Engineer (Systems/Kernel)
United States · Remote · Full-time
- Posted 4d ago
- From RunPod’s careers page
- Location
- United States
- Work mode
- Remote
- Type
- Full-time
- Experience
- 5+ years
- Department
- Engineering
Opens the listing on jobs.ashbyhq.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
Responsibilities:
-
Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.
-
Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.
-
Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.
-
Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.
-
Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.
-
Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.
Required Qualifications:
-
5+ years of experience in infrastructure or systems-level security engineering.
-
Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
-
Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments.
-
Strong systems-level programming skills in C, Go, Rust, or Python.
-
Familiarity with GPU architecture and hardware-level security considerations.
-
Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.
Preferred Qualifications:
-
Contributions to open-source systems security projects or virtualization research.
-
Experience writing or deploying eBPF-based security tooling.
-
Deep knowledge of low-level networking protocols and virtualized network security.
Skills they ask for
Pick one to see other roles that ask for it.
About RunPod
Cloud infrastructure for AI developersRunPod provides on-demand GPU cloud infrastructure and serverless endpoints for AI workloads.
See all 13 roles at RunPodMore roles at RunPod
See all 13- Director, SecurityUnited States · Director · RemoteEngineering · Director · RemoteUnited States1d
- Affiliate & Creator Marketing LeadUnited States · Senior · RemoteMarketing · Senior · RemoteUnited States3d
- Senior Video ProducerUnited States · Senior · RemoteMarketing · Senior · RemoteUnited States4d
- Senior ML Systems Engineer, InferenceUnited States · Senior · RemoteEngineering · Senior · RemoteUnited States2w
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.