Senior Platform Security Engineer
Firmus Technologies23 hours ago
Sydney, AustraliaSenior
Responsibilities
- Build and tune eBPF-based runtime visibility, detection, and enforcement using tools such as Cilium, Falco, or Tetragon.
- Own production security gates covering image signing, software bills of materials, vulnerability gating, policy checks, and policy-as-code controls.
- Define and continuously validate Kubernetes admission, workload identity, network policy, control-plane, and baseline security requirements.
- Test tenant-isolation and blast-radius controls against realistic failure and attack paths, escalating product findings to AI Infrastructure.
- Investigate security-related operational anomalies, provide deep technical escalation, and contribute to security incident post-incident reviews.
- Operate security controls under ISO 27001 and NIST frameworks and produce operational security evidence.
- Monitor privileged activity across identity, certificate, and secrets platforms and mentor engineers on secure design and runtime security.
Requirements
- Strong experience with privileged-access security, least-privilege design, secrets management, and production auditing of privileged operations.
- Strong experience securing multi-tenant Kubernetes environments, including admission policy, workload identity, network policy, and control-plane hardening.
- Extensive experience with eBPF-based runtime-security tooling and building detection and enforcement for security monitoring.
- Strong DevSecOps experience owning image signing, software bills of materials, vulnerability gating, and policy checks in delivery pipelines.
- Understanding of hardware-enforced or network-based tenant isolation and its interaction with Kubernetes policy.
- Experience with policy-as-code tooling for Kubernetes and delivery pipelines.
- Experience serving as a senior escalation point for security faults in a 24/7 production environment and participating in post-incident reviews.
- Strong scripting or programming ability with Python, Go, or Bash.
- Experience securing GPU or HPC infrastructure, multi-tenant AI workloads, cloud or colocation environments, and workload-identity or secrets-management patterns is preferred.
- Experience producing security evidence under ISO 27001, SOC 2, or NIST frameworks is preferred.
- Relevant security certification such as OSCP, GCFA, or a Kubernetes security credential is preferred.
- A Bachelor's degree in computer science, engineering, or a related discipline, or an equivalent combination of relevant experience and training, is listed as preferred.
Benefits
- Based in Australia or Singapore, with travel to Australian AI Factory sites as required.
- The role participates in a shared after-hours escalation roster within a 24/7 operations function.
Tech Stack
Categories
About Firmus Technologies
Firmus Technologies builds energy‑efficient AI infrastructure, developing liquid‑cooled “AI Factory” data centers and operating a large‑scale GPU cloud for model training. The company sells capacity and services to developers, enterprises, education, and government customers, with a focus on energy and cost efficiency across Asia‑Pacific. Founded in 2019 in Australia, Firmus is privately held and headquartered in St Leonards, Tasmania.