F

Senior Platform Security Engineer

Firmus

Sydney, New South Wales, Australia · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
1 week ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

AI FactoryOS Operations 

AI FactoryOS is Firmus' proprietary operating system for the AI Factory. It governs GPU telemetry, cooling, power and grid interaction as one integrated layer, so that every Firmus site can be optimised and monitored as a single system. 

AI FactoryOS Operations runs that platform in production and owns the 24/7 reliability of AI FactoryOS, Firmus AI Cloud and the platforms built on them, together with the service levels the estate is measured against. 

The remit is an engineering one. The function builds the guarded automation, remediation and operational tooling that turn manual response into a software-defined capability, and builds and operates the shared services the estate's own operation depends on. The function works closely with the engineering teams that build the platform, supplying the production evidence that shapes what they fix and what they build next. 

Senior Platform Security Engineer 
Role Summary 

Firmus runs large-scale, state-of-the-art AI infrastructure built on the latest generation of GPU rack-scale systems and operated as one estate to power the next generation of AI innovation. The Senior Platform Security Engineer owns the operational security of that platform.  The multi-tenant Kubernetes estate sits at its heart: production access, admission policy, workload identity and network policy in the live estate, and the operational security controls that keep it defensible as it grows. 

This is a hands-on senior role with deep technical expertise. This role owns security in production: runtime visibility and enforcement built with modern eBPF-based tooling, the security acceptance requirements a release has to meet before it is authorised, the authority to grant or refuse a security exception, and the deepest technical escalation for security-related platform faults. 

Key Responsibilities 

  • Build runtime visibility and enforcement using eBPF-based tooling (for example Cilium, Falco or Tetragon), feeding high-quality signal into the estate's security monitoring, and tune detection so that alerts stay actionable as the estate grows. 
  • Own the security gates in the delivery pipeline: image signing, software bills of materials, vulnerability gating and policy checks, and maintain the policy-as-code controls that govern what ships to production, running on the delivery toolchain operated by Shared Services Operations. 
  • Set and own the security content of the multi-tenant Kubernetes estate: admission policy, workload identity and network policy, and verify that what runs in production matches it. 
  • Set the operational security standard the platform's Kubernetes control planes and baselines must meet in production, validate against it continuously, and raise deviations as engineering requirements to the AI Infrastructure team. 
  • Validate the layered controls that limit the blast radius of a fault or compromise across tenant boundaries, test them against realistic failure and attack paths, and feed the findings to AI Infrastructure where the control belongs to the product. 
  • Investigate and respond to security-related operational anomalies, distinguishing a security signal from an ordinary operational symptom. 
  • Operate the platform's security controls in line with ISO 27001 and NIST frameworks, applying deep expertise in securing large-scale GPU infrastructure, and produce the security evidence those controls generate for collation by the Service Delivery Manager. 

Tools & software

Kubernetes required

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer