
Distinguished Engineer, End-to-End Security Architect
GraphcoreUSA2w ago
Job description
About the role
Graphcore is hiring a senior security architect to shape and lead the security strategy for its inference service platform. You will work across infrastructure, networking, operations, and customer-facing functions to establish protection, resilience, and trust. This position reports into the Systems Engineering organisation and requires close collaboration with teams spanning hardware, firmware, compliance, legal, and customer engineering.
Key facts
What you'll do
- Define and own the complete security architecture for the inference service platform, including infrastructure, networking, APIs, operational controls, monitoring, and customer assurance
- Create security principles, threat models, trust boundaries, tenant isolation requirements, and architectural standards
- Set security requirements for deployment environments covering physical security, operational controls, access management, and asset protection
- Establish platform security requirements for hardware, firmware, secure boot, attestation, software integrity, and lifecycle management
- Design network and service isolation controls, secure communications, segmentation strategies, and administrative access protections
- Own architecture for authentication, authorisation, secrets management, encryption, key management, and data protection
- Define privileged access management approaches, audit requirements, access review processes, and emergency access procedures
- Establish logging, monitoring, telemetry, incident response, and security assurance requirements
- Partner with engineering and operations teams to implement, maintain, and validate security requirements
- Evaluate security posture against customer, contractual, regulatory, and internal requirements
- Support customer security reviews, audits, penetration testing, security questionnaires, and technical assurance discussions
- Provide architectural guidance, mentoring, and design review expertise across multiple teams
Requirements
- Advanced degree in Computer Science, Computer Engineering, Cybersecurity, Electrical Engineering, or related technical field, or equivalent practical experience
- Significant experience in security architecture, platform security, cloud security, infrastructure security, or large-scale service security
- Demonstrated experience defining and owning security architecture for customer-facing platforms, infrastructure services, or large-scale production environments
- Deep understanding of threat modelling, zero-trust principles, tenant isolation, privileged access management, cryptographic controls, and secure operations
- Strong knowledge of trusted execution mechanisms, secure boot, attestation, firmware integrity, and supply-chain security concepts
- Experience defining security requirements for data centre deployments, operational environments, and physical security controls
- Expertise in network security architecture, segmentation, management-plane protection, secure communications, monitoring, and access control
- Experience with key management, secrets management, certificate lifecycle management, and encryption technologies
- Experience securing APIs, deployment pipelines, service control planes, and operational tooling
- Strong understanding of logging, monitoring, incident response, security operations, and evidence management
- Experience supporting customer security reviews, audits, penetration testing, and executive-level security discussions
- Excellent communication and stakeholder management skills with ability to influence technical and non-technical audiences
- Proven ability to lead through influence across engineering, security, operations, compliance, and customer-facing teams
Nice to have
- Experience securing AI/ML inference platforms, model-serving infrastructure, accelerator-based systems, or confidential AI workloads
- Experience with trusted execution environments, platform attestation technologies, secure firmware development, and workload identity solutions
- Experience with confidential computing, secure enclaves, measured boot technologies, and remote attestation
- Experience supporting highly regulated environments, critical infrastructure, or security-sensitive customer deployments
- Familiarity with SOC 2, ISO 27001, ISO 27017, ISO 27018, PCI DSS, FedRAMP, or NIST standards
- Knowledge of hardware platform security, high-performance networking, storage security, and accelerator ecosystem technologies
- Experience with supply-chain risk management, secure manufacturing practices, asset lifecycle controls, and secure disposal processes
- Understanding of emerging cryptographic technologies and future security trends
- Experience working with hyperscalers, enterprise customers, AI organisations, or managed infrastructure providers
Skills & tools
- Threat modelling and zero-trust architecture
- Secure boot, attestation, firmware integrity
- Network segmentation and management-plane protection
- Key management, secrets management, certificate lifecycle management
- API security and deployment pipeline security
- Logging, monitoring, and incident response
- Confidential computing and secure enclaves
Practical notes
- Graphcore is part of the SoftBank Group
- Benefits include medical, dental, and vision coverage, FSAs, HSAs, disability and life insurance, 401(k), commuter benefits, wellness services, and EAP
- Flexible working arrangements available
- Flexible interview approach and reasonable adjustments available upon request