Runpod is pioneering the future of AI and machine learning, offering cutting-edge cloud infrastructure for full-stack AI applications. Founded in 2022, we are a rapidly growing, well-funded company with a remote-first organization spread globally. Our mission is to empower innovators and enterprises to unlock AI's true potential, driving technology and transforming industries. Join us as we shape the future of AI. We are building Cloud services focused on accelerating AI adoption. Whether you're an experienced ML developer training a large language model, or an enthusiast tinkering with stable diffusion, we strive to make GPU compute as seamless and affordable as possible.
Cloud Infrastructure Security Engineer
Location
United States
Posted
7 days ago
Salary
$152K - $175K / year
Seniority
Mid Level
Job Description
Cloud Infrastructure Security Engineer
Runpod
Role Description As RunPod continues to revolutionize the GPU cloud computing landscape, we are seeking a systems-focused Cloud Infrastructure Security Engineer. This critical position is instrumental in safeguarding our bare-metal and virtualized environments, ensuring the absolute security, multi-tenant isolation, and integrity of our underlying GPU cloud infrastructure. The ideal candidate possesses deep knowledge of Linux systems, kernel internals, hypervisors, and containerization. You will focus on the lowest levels of our stack—preventing tenant breakouts, securing GPU hardware allocations, and building resilient infrastructure to support AI and machine learning workloads. RunPod is seeking an innovative security engineer who thrives at the systems layer. You will operate with an Attacker's Mindset, actively hunting for ways to break container and virtualization boundaries, and then writing the low-level code to patch them. Responsibilities - Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments. - Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation. - Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces. - Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level. - Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces. - Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments. Qualifications - 5+ years of experience in infrastructure or systems-level security engineering. - Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor). - Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments. - Strong systems-level programming skills in C, Go, Rust, or Python. - Familiarity with GPU architecture and hardware-level security considerations. - Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs. Preferred Qualifications - Contributions to open-source systems security projects or virtualization research. - Experience writing or deploying eBPF-based security tooling. - Deep knowledge of low-level networking protocols and virtualized network security. Benefits - The competitive base pay for this position ranges from ($152,000 - $175,000). - Meaningful equity in a fast-growing company — everyone on the team receives stock options. - Generous medical, dental & vision plans. - Flexible PTO - take the time you need to recharge. - Most roles are remote work first with an inclusive, collaborative teams utilizing Slack as the main form of internal communication. - $1,200 Home Office & Equipment Stipend - we set you up for success from day one with gear and support to create your ideal workspace.
Related Guides
Related Categories
Related Job Pages
More Cloud Engineer Jobs
Cloud Security Engineer
Ardent MillsArdent Mills is committed to transforming how the world is nourished.
• Design, implement, and operate security controls primarily across Microsoft Azure environments • Lead design and implementation for cloud landing zones, identity, and network controls (VPC/VNet, security groups/NSGs, private endpoints) • Configure cloud-native security services (e.g., Microsoft Defender for Cloud, Microsoft Sentinel, Defender XDR) • Build posture management (CSPM) and workload protection (CWPP) with policy-as-code and automated remediation • Implement key management, encryption at rest/in transit, and certificate governance using KMS/Key Vault/Cloud KMS • Establish logging, telemetry, and alerting (Azure Monitor) integrated to SIEM/XDR • Work with key team members across IT and Security to test and validate total coverage / maturity of detection telemetry from cloud native sources • Determine architecture as needed to harden serverless containers and managed services (Functions, Logic Apps, Container Apps, AKS, ACI) • Perform threat modeling and security reviews for cloud architectures and application designs • Partner with platform and product teams to deliver IaC guardrails, image baselines, and patch/vulnerability workflows • Respond to cloud incidents as a point of escalation; perform triage, containment, and post-incident improvements • Develop automation architecture where applicable to optimize cloud detection and response capabilities • Leverage automation and AI-assisted capabilities where appropriate to enhance cloud detection and response • Document standards and runbooks; conduct enablement sessions with dev and ops teams • Design partner in cloud security strategy and program maturity
Infrastructure – Cloud Architecture
KyndrylWe design, build, manage and modernize the mission-critical technology systems that the world depends on every day.
• Designs and guides cloud, Linux platform, container, and edge infrastructure architecture for a Kyndryl client’s software engineering and product platform environment. • Key responsibilities include designing cloud and platform architecture supporting engineering workloads, Linux platforms, containerized services, Kubernetes environments, DevOps pipelines, and product integration needs. • Collaborates with software, DevOps, testing, technical support, and delivery teams.
• Design, build, and maintain cloud-native backend services that support residential applications, device integrations, and platform capabilities. • Develop scalable APIs, asynchronous workflows, and service integrations using modern backend technologies. • Contribute to architecture decisions across microservices, event-driven systems, Kubernetes-based runtime environments, and cloud infrastructure. • Support and improve device-to-cloud flows involving AWS IoT Core and related platform services. • Improve reliability, scalability, observability, and operational readiness across the Infinity platform. • Partner with mobile, web, product, QA, and platform teams to enable high-quality end-to-end delivery. • Troubleshoot production issues, lead root-cause analysis, and help implement durable fixes and long-term remediation. • Contribute to CI/CD, infrastructure automation, release engineering, and secure software delivery practices. • Identify technical risks early and help shape implementation plans and proof-of-concepts for new capabilities.
• Write scalable and maintainable Javascript for AWS services (e.g. Lambda, Fargate) • Develop and help monitor RESTful APIs • Build efficient services for storing and processing structured data • Contribute to clean and organized infrastructure-as-code templates (e.g. CloudFormation) and help deploy stacks across environments • Help manage the security and organization of data in S3 • Contribute to the AWS side of integrations with our Salesforce platform, and help refactor Salesforce processes (LWC, Apex) as part of that work • Partner with senior engineers and Product Managers to scope and deliver features • Contribute to project documentation and knowledge bases




