Haystack
← Back to Jobs
Technology
FT

Senior Security Engineer, AI Platform and Infrastructure

Firmus Technologies Sydney🇬🇧United KingdomPosted 28 Sept 2026

Why This Role Stands Out

As a Senior Security Engineer at Firmus Technologies, you will play a pivotal role in securing cutting-edge AI infrastructure, offering significant opportunities for professional growth and skill development within a globally recognized leader. This position is ideal for a proactive and detail-oriented security professional eager to contribute to a mission-driven company at the forefront of technological innovation. Apply now to join a dynamic team and make a tangible impact.

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Sydney, United Kingdom
Posted
Yesterday
EncryptionSOC 2KubernetesPythonREST

Job Description

Firmus Technologies

Firmus Technologies is a global leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.  

Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a steadfast commitment to sustainability. 

At Firmus, we are unique in our approach. We design, build, and operate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally. 

Firmus AI Cloud

Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI compute at scale to customers. 

It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale. 

ROLE SUMMARY 

Firmus Technologies is seeking a Senior Security Engineer, AI Platform and Infrastructure for our Engineering and Technology team. Customers provision GPU compute through API and console, software engineers build against it, our infrastructure engineers build the bare metal, virtualisation layer and Kubernetes clusters behind it, and our operators run the platform through the same control plane. You own both layers of Firmus AI Cloud: the platform control plane that engineering teams built, and the bare-metal infrastructure it runs on. Automation is how you scale that ownership. 

KEY RESPONSIBILITIES 

Automation and secure delivery 

  • Own the security controls in platform delivery pipelines, infrastructure-as-code, hardware lifecycle, and Kubernetes deployment. Ship them as paved roads that engineering teams and delivery partners inherit. 
  • Build the systems that do the repeatable work: posture management, configuration validation, firmware and attestation checks, bulletin-driven fleet upgrades, evidence collection, and infrastructure risk detection.  
  • Write and review code, infrastructure-as-code, and policy-as-code that enforce security outcomes at scale. 

Security architecture and standards 

  • Set the standard for platform identity, workload identity, privileged access, and secrets: short-lived credentials, federation, least-privilege access to infrastructure APIs and Kubernetes, and audit trails for administrative and control-plane actions. 
  • Define the security baseline for Kubernetes and the container workloads the platform admits: control-plane isolation from worker and tenant networks, admission controls, policy-as-code, network policy, encrypted cluster secrets, no privileged containers or host mounts, least-privilege service accounts, and only trusted, pinned images. 
  • Lead threat modelling and secure design review for infrastructure, platform, and shared-service changes. Define what an attacker can do and what must be true before it ships. 
  • Design isolation in layers, so a single misconfiguration or outdated component cannot yield cross-tenant data access or code execution. Cover cluster, host, network, storage, control plane, and telemetry rather than relying on containers, namespaces, or dashboard filters alone. 
  • Separate the infrastructure management plane from tenant workloads: out-of-band and BMC access, device and attached-NIC management, and shared network device administration. 
  • Define how the platform is exposed and protected: default-deny at the edge, private endpoints for administrative and cluster APIs, enforcement placed in the path so volumetric and application-layer attacks are blocked or mitigated before it reaches services, encryption in transit and at rest, and automated certificate lifecycle. 
  • Set the standard for hardware roots of trust, remote attestation, secure and measured boot, firmware lifecycle, and sanitisation of GPU, host, attached device, and storage state before hardware is reassigned. Apply those controls across sites. 

Assurance and vulnerability management 

  • Own platform and infrastructure security posture: what is covered, what is open, what is accepted with a named owner and an expiry, and what is overdue. 
  • Prioritise fixes on exploitability and exposure alongside CVSS, hold them to the Firmus vulnerability SLAs, and drive remediation with the teams that own the platform components, so issues close at the source. 
  • Extend SOC 2 Type 2 and ISO 27001 into the infrastructure lifecycle as platforms and sites grow. Evidence that a control ran should be a query, not a spreadsheet exercise. 

Enablement and escalation 

  • Coach engineers so secure infrastructure decisions get made without waiting for you. 
  • Provide platform and infrastructure security expertise during incidents and convert recurring failure modes into controls, guardrails, standards, or automation. 
  • Give engineering leadership a straight read on infrastructure risk and operational security readiness. Join customer conversations when the question is platform and infrastructure security. 

 

SKILLS AND EXPERIENCE 

 

  • Bachelor's degree in computer science or a related technical field. 
  • 7+ years in infrastructure security, platform security, cloud security, site reliability engineering, or platform engineering with a strong security focus. 
  • Has secured production bare-metal and on-premises infrastructure used by multiple teams or customers, including Linux hosts, out-of-band management, and the hardware lifecycle from commissioning through sanitisation and reassignment. 
  • Deep, practical knowledge of Kubernetes and container security for a multi-tenant platform: control-plane isolation, admission controls, policy-as-code, network policy, cluster secrets, container privilege and host-access restrictions, and admitting only trusted images. Has threat modelled production infrastructure using STRIDE or an equivalent method. 
  • Has run platform and workload identity in production: federation, short-lived credentials, privileged access management, secrets platforms, and least-privilege access to infrastructure APIs. 
  • Has designed and tested isolation so a container or VM escape, an outdated GPU or container toolkit, or a shared control plane cannot become a cross-tenant incident. 
  • Understands hardware roots of trust, secure and measured boot, signed firmware, and remote attestation, and can specify how out-of-band and device management interfaces stay separated from tenant workloads. 
  • Has secured public network exposure and platform cryptography: default-deny edge controls, private endpoints for administrative APIs, encryption in transit and at rest, and automated certificate lifecycle. 
  • Writes production-quality code in at least one of Python or Go and has replaced manual security work with automation that engineers trusted and kept on. 
  • Has kept production host, container runtime, GPU, and firmware software current against published security bulletins. 
  • Has worked under SOC 2 Type 2 or ISO 27001 and can produce evidence that a control ran. 
  • Willing to join incident response for platform and infrastructure security. 
  • Willing to travel overseas occasionally when the role requires it. 
  • Clear and effective written and verbal communication in English. 

Bonus Points 

  • Experience securing AI infrastructure platforms, GPU clusters, or large-scale compute environments, including RoCE fabrics or automated hardware sanitisation. 
  • Experience securing large scale hypervisors and the boundaries between guests, hosts, and assigned devices, including dedicated GPU-node architectures. 
  • Experience with NVIDIA BlueField DPUs and DOCA or equivalent DPU platform software, including restricted host mode and device attestation. 
  • Experience with GPU confidential computing, remote attestation, or attestation-gated workload identity. 
  • Security certifications such as CISSP, Certified Kubernetes Security Specialist (CKS), or equivalent. 

 

LOCATION 

 

Singapore or Australia 

Similar jobs