9 hours ago
Base Salary
$341k - $402k/yr
Responsibilities
- Set technical direction and own architecture for platform security capabilities across identity, authorization, infrastructure security, encryption, key management, and auditability.
- Design and build authentication, federation, authorization, workload identity, lifecycle provisioning, and administrative access systems.
- Build and scale Kubernetes and distributed-infrastructure security using software, policy, automation, APIs, controllers, Infrastructure-as-Code, and GitOps.
- Architect multi-tenant security controls and isolation across compute, network, storage, and control-plane boundaries.
- Own infrastructure lifecycle security, including secure provisioning, secrets and credential management, encryption, and certificate lifecycle.
- Build production software and automation that make secure infrastructure patterns reliable, scalable, and easy for engineering teams to adopt.
- Lead security-sensitive platform designs, translate risks and requirements into engineering decisions, and influence technical standards across Platform Engineering.
- Partner across engineering and security to support customer trust, platform reliability, compliance requirements, and clear communication of technical risk and tradeoffs.
Requirements
- 6+ years of software engineering experience building complex infrastructure or distributed systems, with deep experience in cloud and platform security, identity and access, Kubernetes, or related infrastructure security domains.
- Demonstrated experience setting technical direction and owning complex security architecture across multiple systems, teams, or infrastructure domains.
- Deep experience with OIDC, SAML, SCIM, RBAC, workload identity, short-lived credentials, and multi-factor authentication.
- Deep experience designing security for multi-tenant systems and isolation across network, compute, storage, and control-plane boundaries.
- Hands-on Kubernetes security expertise, including RBAC, admission control, service-account and workload identity, secrets and encryption, policy enforcement, and node security.
- Strong understanding of secrets management, encryption, key management, certificate lifecycle, and secure credential management.
- Strong software engineering skills in Go, Python, or similar languages, with experience designing, building, and operating production systems.
- Experience building security controls through APIs, controllers, automation, policy, Infrastructure-as-Code, GitOps, or similar approaches.
- Experience leading ambiguous cross-functional technical initiatives and influencing engineering direction across teams.
- Ability to reason about complex security systems end to end and communicate technical risk and architectural tradeoffs clearly.
- Valuable experience includes building identity, key-management, network security, or infrastructure security capabilities for cloud platforms; securing high-performance storage and distributed infrastructure; translating compliance requirements into automated evidence and production controls; and building Kubernetes operators or admission webhooks.
Benefits
- Hiring is prioritized in or near the San Francisco Bay Area, New York City, and Dallas.
- The position offers a Long-Term Incentive Program and a robust suite of employee benefits.
- The stated U.S. total cash salary range is $341,400-$401,600, inclusive of potential bonus value; international compensation varies by local market.
- Candidates must qualify as U.S. Persons for export-control purposes or otherwise be eligible for an applicable export license.
Tech Stack
Categories
About Groq
Groq designs and operates AI inference hardware and cloud services built around its LPU architecture, aimed at developers and enterprises running large language models and other ML workloads. It generates revenue by selling processors and offering pay-as-you-go inference through its hosted platform and APIs. Founded in 2016 and headquartered in Mountain View, California, the company is privately held.
