8 hours ago
Remote, United States or Boston, MA, USASenior
Responsibilities
- Design and publish security reference architectures for single-tenant, multi-tenant, and hybrid k0rdent AI deployments.
- Define defense-in-depth, tenant isolation, threat models, security controls, and trade-offs across hardware, firmware, hosts, VMs, Kubernetes, networking, storage, models, and applications.
- Research emerging infrastructure and AI security technologies, prototype alternative designs, and publish internal or external findings.
- Build and run customer, partner, and laboratory proofs of concept on real hardware, and validate results against agreed success criteria.
- Write automation, policies, and tooling using Python, Go, Bash, Ansible, Helm, Kubernetes manifests, Terraform, and policy-as-code.
- Assess designs and deployments through threat modeling, configuration review, and hands-on testing.
- Act as the security subject matter expert in customer discovery, design reviews, architecture workshops, security questionnaires, and strategic opportunities.
- Collaborate with Solutions Architects, Partner Management, Engineering, hardware vendors, software partners, and security vendors across distributed teams.
- Present at industry events, webinars, and partner summits; run technical workshops; and create reference architectures, solution briefs, blog posts, and enablement content.
- Feed research and customer findings into Product, Engineering, the security team, and the k0rdent AI roadmap.
Requirements
- Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, or a related field, or equivalent practical experience.
- At least 8 years of experience in security engineering or security architecture, including at least 3 years securing cloud, Kubernetes, or large-scale infrastructure platforms.
- Customer-facing experience as a solutions architect, pre-sales engineer, consultant, or technical lead.
- Experience designing and operating secure deployments on at least one major public cloud—AWS, Azure, or GCP—and on private cloud or bare-metal infrastructure.
- Experience with Linux hardening, secure boot, TPM, hypervisor and VM isolation, KubeVirt, Kubernetes security, RBAC, Pod Security Standards, admission controllers, policy engines, runtime security, and multi-tenancy patterns.
- Experience with secrets and key management, PKI, certificate lifecycle management, mTLS, OIDC, SSO, workload identity, network segmentation, zero-trust architectures, Kubernetes network policy, and shared-storage security.
- Working understanding of Transformer-based model training, packaging, serving, and threats affecting AI systems.
- Experience with image signing, SBOMs, vulnerability scanning, software provenance, SLSA concepts, Git, CI, and infrastructure-as-code.
- Programming or scripting experience in at least one language, with Python or Go preferred.
- Excellent written and spoken English, strong technical presentation skills, and the ability to communicate with engineers, security teams, CISOs, executives, and large technical audiences.
- Experience working in international, distributed teams across time zones and cultures.
- Preferred qualifications include compliance-framework experience, confidential computing and remote attestation, GPU-cloud or HPC security, DPU security, offensive security or AI red teaming, Mirantis products, security certifications, open-source contributions, public technical talks, published research, patents, or standards participation.
Benefits
- Remote role based in the United States, with a strong preference for the East Coast.
- Up to 25% travel for customer engagements, partner meetings, lab work, and industry events, primarily within the United States and European Union.
- Work with a distributed international team across time zones; some meetings may occur outside standard local hours.
- Collaborate directly with GPU cloud operators, NeoClouds, sovereign clouds, and AI-first enterprises.
- Influence the product narrative, roadmap, and go-to-market strategy while working on AI-cloud observability and infrastructure security.
- Compensation and benefits are set according to the local market and employment arrangement.
Tech Stack
Categories
Solutions Engineering
About Mirantis
Mirantis builds Kubernetes-native infrastructure software and services for enterprises to run cloud, container, and AI workloads across on-premises, public cloud, and edge environments. It sells subscriptions, support, and managed services around products like Mirantis Kubernetes Engine and the Lens Kubernetes platform; the company acquired Docker Enterprise in 2019. Founded in 1999 and headquartered in Campbell, California, Mirantis is privately held and an IREN company serving global enterprises.
