Senior Security Architect
Location
California
Posted
7 days ago
Salary
$184K - $356.5K / year
Seniority
Senior
Job Description
Senior Security Architect
NVIDIA
• Build and enforce security controls, systems, and policies for cluster infrastructure of new NVIDIA hardware. • Identify, assess, and reduce cybersecurity risks; report major risks clearly to leadership. • Develop and lead incident response and disaster recovery plans. • Investigate security incidents and drive root-cause analysis. • Ensure systems meet IT, legal, regulatory, and information security standards. • Improve security governance, documentation, and audit readiness. • Train peers and users on practical security standard methodologies. • Work with infrastructure, networking, storage, OS, firmware, and application teams to harden systems.
Job Requirements
- BS in Computer Science, Engineering, Cybersecurity, or equivalent experience with 8+ yrs of industry experience
- Experience securing large-scale Linux infrastructure
- Proven understanding of risk management, threat modeling, vulnerability management, and access control
- Experience with incident response, disaster recovery, and breach handling
- Knowledge of compliance, governance, and data protection requirements
- Experience in programming secure computing environments, with proficiency in C/C++
- Experience with system level threat modeling, risk management frameworks and risk mitigation techniques.
- Experience with compute and networking systems security architecture and engineering
- Experience in securing AI agents using sandboxing technologies and AI-based threat detection (e.g. Mythos)
- Experience with modern authentication and identity frameworks such as OAuth 2.1, OIDC, Kerberos, FIDO2/WebAuthn.
- Experience with Microsoft Active Directory and Entra ID, including cross-realm trusts and identity federation (SCIMv2)
- Experience managing centralized Linux identity (FreeIPA/RHEL IdM/SSSD), including PKI lifecycle management and Host-Based Access Control.
- Linux kernel hardening (SELinux/AppArmor) and observability (eBPF).
- Developing secure software in Rust, prioritizing memory safety
- Experience hardening HPC schedulers and storage, Slurm alongside parallel filesystems like Lustre and NFS.
- Experience securing containerized workloads (Docker, Enroot, Kubernetes).
- Knowledge of high-speed fabric security like InfiniBand PKeys/MKeys.
- Zero Trust, ZTNA, VRFs, VLANs, performance-optimized firewalls.
- Use of advanced vulnerability management and supply chain mitigation (CVSS 4.0, SBOM).
Benefits
- equity
- benefits
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Program Manager, Product Security
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
• Coach and mentor project teams in a collaborative, empathetic environment • Guide teams on best practices while allowing autonomy in implementation approaches • Create and manage project schedules from high-level phases to detailed tasks, including dependencies • Collaborate with worldwide business units to coordinate project involvement, goals, and expectations • Track project status and ensure schedules and priorities are met • Identify, track, and escalate critical issues through resolution • Manage project communication and status reporting cadences • Lead Scrum meetings and maintain action item follow-through • Drive continuous improvement through automation, AI, and process efficiencies • Flex engagement level across multiple projects—from hands-on execution on critical initiatives to high-level coaching and issue resolution across broader portfolios
Senior Container Security Engineer
RapidFort, Inc.RapidFort is at the intersection of Cybersecurity and AI. RapidFort is the leader in Software Supply Chain Security, delivering a comprehensive end-to-end vulnerability management platform that includes curated near-zero-CVE open-source images, advanced runtime profiling, automated CVE remediation, and software attack-surface-management (hardening) capabilities to continuously secure and optimize containerized applications.
Role Description We are looking for a hands-on Senior Container Security Engineer to lead vulnerability remediation and image hardening across Linux-based container environments. This role focuses on deep operating system and container security engineering rather than simple vulnerability scanning. You will analyze, remediate, rebuild, harden, and continuously optimize container images used in modern cloud-native platforms. You will work closely with platform engineering, DevOps, infrastructure, and security teams to build automated remediation pipelines, reduce the attack surface, and deliver production-ready hardened images. What You’ll Do - Own end-to-end CVE remediation across Linux-based container images. - Analyze vulnerabilities across OS packages, libraries, runtimes, and dependencies. - Patch, rebuild, validate, and maintain hardened container images at scale. - Reduce attack surface by removing unnecessary packages, binaries, services, and dependencies. - Build and scale automated remediation pipelines for continuous image patching. - Improve image security posture while minimizing operational disruption. - Generate, validate, and maintain SBOMs to support supply chain visibility and compliance. - Integrate remediation workflows into CI/CD and GitOps pipelines. - Optimize image size, startup performance, and operational efficiency. - Research emerging Linux, container, Kubernetes, and software supply chain threats. - Troubleshoot complex dependency, package compatibility, and runtime security issues. - Help define internal standards for hardened images and secure software delivery. Qualifications - 5+ years of experience in Linux systems engineering, platform engineering, DevSecOps, security engineering, or SRE. - Deep understanding of Linux distributions (Debian, Ubuntu, Alpine, RHEL). - Strong hands-on experience with Docker, Kubernetes, and containerized environments. - Proven experience remediating CVEs within Linux packages and container ecosystems. - Proficiency with package management systems (apt, yum/dnf, apk, rpm). - Experience with scanning tools such as Trivy, Grype, or Clair. - Strong scripting or programming skills in Python, Bash, or Go. - Solid understanding of container image layering and filesystem structures. - Familiarity with CI/CD automation and infrastructure-as-code workflows. - Experience with cloud-native infrastructure (AWS, Azure, or GCP). Nice to Have - Experience building minimal or distroless container images. - Familiarity with SBOM standards (SPDX, CycloneDX, Syft). - Experience with image signing and verification tools (Cosign, Sigstore). - Knowledge of software supply chain security frameworks like SLSA. - Familiarity with Kubernetes security controls and eBPF. What Success Looks Like - Delivery of production-ready container images with near-zero exploitable CVEs. - Established scalable automated remediation and image hardening pipelines. - Significant reduction in container attack surface and image bloat. - Improved remediation speed and operational efficiency. - Repeatable standards for secure container image delivery at scale. Compensation & Benefits - Base salary: $130,000 – $200,000 depending on experience and technical depth. - Equity participation. - Comprehensive health, dental, and vision coverage. - Remote-first work environment. - Opportunity to work on cutting-edge cloud-native and container security technologies. - Career growth within a rapidly scaling cybersecurity company.
Senior Information Security GRC Analyst
BranchWe provide cross-platform linking and attribution solutions to the world's leading digital brands.
• Manage and maintain the Branch Information Security Program, security function programs and processes. Own internal Branch controls. Maintain an accurate security program and all the associated processes across all corporate functions. • Ambassador and champion of the Branch Information Security Program and security awareness. • Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA). • Conduct comprehensive gap analysis to identify deficiencies and areas for improvement in existing controls. • Experience implementing new frameworks and integrating into existing audit cycles. • Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with the frameworks (SOC 2, ISO 27001, PCI, NIST, CCPA) implemented by Branch. • Manage Branch’s Drata GRC platform: • Ensure information is up to date and automated collections are working appropriately. • Ensure that Audit evidence is collected and validated. • Manage access to and keep information up to date for Branch’s Security Trust Center. • Manage and maintain frameworks, policies, control content and control mapping. • Inform the proper stakeholders of important concerns, hazards, and risk to the organization. • Collaborate with stakeholders (Security, Engineering, Cloud Operations, Procurement, and Legal) to ensure security practices are integrated into daily operations, and are aligned with our GRC objectives. • Maintain up-to-date knowledge of procedures and methods that serve to broaden team knowledge and industry expertise. • Write and manage security standards, policies, and practices on an ongoing basis to make sure they meet corporate demands. • Assist the department in responding to inquiries from the business units about ongoing operational compliance. • Be proactive in seeking out areas for improvement and offer insightful advice and value-added guidance and/or automation for process and control enhancements. • Manage the end-to-end third-party vendor management lifecycle, including onboarding, due diligence, and ongoing monitoring of vendor risk, performance, and operational changes through established governance processes. • Partner with the Risk and Legal teams to share information and seek out areas for improvement, streamline processes and to reduce risk throughout the company. • Manage the security training and awareness program, responsible for promoting and enhancing our organization's security culture through effective awareness programs and initiatives. • Support the planning of penetration tests and the coordination of remediation efforts.
• Design and implement a multi-layer AI security framework spanning data classification, detection and response, exfiltration prevention, governance, adversarial testing, and agentic identity management. • Evaluate, deploy, and operate AI-specific security tooling and integrate them into BlinkRx's security operations. • Architect secure MCP (Model Context Protocol) server deployments and define agent-to-agent authentication standards for agentic AI workflows. • Partner with Cloud Security to establish guardrails in AWS for AI workloads. • Define and enforce PHI/PII handling controls for all AI systems. • Design and execute AI red-team assessments against AI applications. • Integrate AI security controls into CI/CD pipelines and engineering workflows. • Develop automated testing and validation for AI applications and AI pipelines. • Build and operate an AI security testing pipeline using tools. • Perform adversarial testing of agentic AI workflows for privilege escalation, tool misuse, and unintended data access patterns.



