Senior Security Engineer II, Cloud Security
Job description
About the role
CoreWeave is seeking a technical expert to protect our specialized AI infrastructure. You will focus on hardening our cloud environment and ensuring the integrity of our large-scale GPU compute platforms. This role requires a deep technical understanding of modern cloud architectures and the evolving threat landscape specific to AI workloads. You will act as a subject matter expert, driving security initiatives that enable secure and scalable operations. The position demands a proactive mindset to identify vulnerabilities before they can be exploited. You will be responsible for translating complex security requirements into actionable technical controls. Your work will directly impact the reliability and trustworthiness of the platforms powering critical AI applications.
Key facts
What you'll do
- Architect and deploy granular security controls tailored for our cloud-native AI infrastructure, ensuring defense-in-depth strategies are met.
- Perform iterative threat modeling sessions to uncover potential attack vectors across our GPU compute fabric and associated storage systems.
- Engineer sophisticated automated security monitoring, detection, and response workflows using infrastructure-as-code methodologies.
- Partner closely with cross-functional engineering teams to embed security requirements and checks directly into the hardware and software deployment pipelines.
- Oversee the comprehensive management of vulnerability assessments, prioritizing risks, and driving remediation strategies for critical findings.
- Implement and maintain robust identity and access management controls to enforce the principle of least privilege across all environments.
- Develop and maintain detailed security documentation, architecture diagrams, and runbooks to ensure operational consistency and knowledge sharing.
- Analyze complex security telemetry and log data to investigate incidents, perform root cause analysis, and refine detection rules.
- Contribute to the security design reviews for new products, features, and infrastructure changes, providing expert guidance on security best practices.
- Establish security baselines and performance metrics to measure the effectiveness of our security posture and program maturity.
- Lead incident response efforts for cloud security events, coordinating with stakeholders to ensure timely resolution and post-incident improvements.
- Evaluate and recommend new security tools and technologies to address emerging threats and improve operational efficiency.
- Ensure compliance with internal security policies and relevant industry standards governing cloud and data protection.
- Mentor junior security engineers by providing technical guidance, code reviews, and career development support within the security team.
Requirements
- Demonstrated proven experience in cloud security engineering or a closely related infrastructure security role within a professional setting.
- Possess a deep understanding of security principles, configurations, and best practices within Kubernetes and broader containerized environment ecosystems.
- Show proficiency in securing large-scale distributed systems, including the management of network policies and service-to-service communication.
- Exhibit the ability to write high-quality code for security automation, tooling, and custom scripts to enhance operational security workflows.
- Maintain strong knowledge of cloud architecture patterns and network security fundamentals, including firewalls, load balancers, and zero-trust models.
- Have hands-on experience with infrastructure security tools such as cloud security posture management (CSPM) and cloud workload protection platforms (CWPP).
- Show a history of working with infrastructure-as-code tools like Terraform or CloudFormation to define and enforce security configurations.
- Demonstrate strong analytical and problem-solving skills with the ability to interpret complex security data and translate it into actionable insights.
Nice to have
- Bring experience with GPU-accelerated computing environments and the unique security challenges they present.
- Show a background in securing bare metal infrastructures and high-performance networking setups common in HPC scenarios.
- Have meaningful contributions to open-source security projects that demonstrate technical excellence and community engagement.
Practical notes
CoreWeave provides high-performance AI infrastructure. Please apply through the official careers portal to be considered for this position. The role is based full-time and requires adherence to the standard working hours as defined by CoreWeave policies. Travel may be required occasionally to meet with global teams or for business-critical infrastructure reviews. Employment is contingent upon successful completion of background checks and relevant security clearances if required. Candidates must be authorized to work in the country where the position is located without sponsorship for this specific posting.