Cloud Infrastructure Security Engineer (Systems/Kernel)
Job description
About the role
In the rapidly evolving landscape of AI infrastructure, RunPod is on the lookout for a dedicated Cloud Infrastructure Security Engineer with a focus on systems and kernel security. This role is essential for protecting our GPU cloud infrastructure, which serves over a million developers. You will be responsible for ensuring the security, integrity, and isolation of our bare-metal and virtualized environments. The ideal candidate will have a strong background in Linux systems, kernel internals, and virtualization technologies, and will be driven by a proactive approach to security.
Key facts
What you'll do
- Develop and implement advanced workload and network isolation strategies for our multi-tenant GPU cloud environments.
- Strengthen Linux kernel configurations, container runtimes (such as Docker and containerd), and orchestration platforms (like Kubernetes) to prevent privilege escalation and container breakouts.
- Conduct thorough security assessments and penetration tests focusing on our hypervisor, network stack, and hardware interfaces to identify vulnerabilities.
- Write low-level code primarily in C, Go, or Rust to establish custom security measures, telemetry, and solutions at the operating system and infrastructure levels.
- Assess and address security challenges related to GPU architecture, PCIe pass-through, and shared memory spaces to ensure hardware security.
- Act as the primary technical contact for security incidents at the infrastructure level, developing forensic capabilities tailored for ephemeral container environments.
- Collaborate with cross-functional teams to ensure security best practices are integrated into the development lifecycle.
- Stay updated on the latest security threats and trends, continuously refining our security posture in response to emerging risks.
Requirements
- A minimum of 5 years of experience in security engineering focused on infrastructure or systems.
- Profound understanding of Linux kernel internals, including cgroups, namespaces, eBPF, and security modules like SELinux and AppArmor.
- In-depth knowledge of virtualization technologies such as KVM and QEMU, along with techniques for workload and network isolation in multi-tenant setups.
- Strong programming skills in systems-level languages including C, Go, Rust, or Python.
- Familiarity with GPU architecture and the security implications associated with hardware.
- Proven experience in securing bare-metal cloud infrastructure and addressing lower-level Common Vulnerabilities and Exposures (CVEs).
Nice to have
- Contributions to open-source projects related to systems security or virtualization research.
- Experience with eBPF-based security tools and their deployment.
- Comprehensive understanding of low-level networking protocols and security measures for virtualized networks.
Skills & tools
- Proficient in Linux system administration and security practices.
- Knowledge of container orchestration and management tools.
- Familiarity with security assessment tools and methodologies.
- Experience with programming and scripting languages relevant to systems security.
Practical notes
- The salary range for this position is competitive, falling between $152,000 and $175,000, and may vary based on experience and qualifications.
- Employees will receive equity options, allowing them to share in the company's growth and success.
- Comprehensive medical, dental, and vision benefits are provided to all team members.
- Flexible paid time off (PTO) is available, encouraging employees to take necessary breaks to recharge.
- A $1,200 stipend is offered for home office setup, ensuring that you have the necessary equipment to create an effective workspace.
- RunPod fosters a collaborative and inclusive culture, utilizing tools like Slack for internal communication, and prioritizes a supportive work environment.
RunPod is dedicated to creating a diverse and inclusive workplace, valuing the unique contributions of every individual. As an equal opportunity employer, we assess applicants based on their qualifications without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, protected veteran status, disability status, or any other characteristic protected by law. We welcome all qualified candidates who are eligible to work in the United States; however, we are currently unable to sponsor employment visas.