698,236open jobs
41,342companies
99,387added this week
Browse all
Salary
$92k – $218k per year (Estimated)
Location
In office (Sydney)
Seniority
Principal
Overview
Company
Impact
Profile match
Firmus Technologies builds immersion-cooled artificial intelligence factories that run large GPU fleets on renewable power. Founded in 2021 in Singapore, it develops both the data centre design and the cloud service on top. Its Project Southgate campuses in Australia are among the region's largest planned artificial intelligence sites.

AI FactoryOS Operations  

AI FactoryOS is Firmus' proprietary operating system for the AI Factory. It governs GPU telemetry, cooling, power and grid interaction as one integrated layer, so that every Firmus site can be optimised and monitored as a single system. 

AI FactoryOS Operations runs that platform in production and owns the 24/7 reliability of AI FactoryOS, Firmus AI Cloud and the platforms built on them, together with the service levels the estate is measured against. 

The remit is an engineering one. The function builds the guarded automation, remediation and operational tooling that turn manual response into a software-defined capability, and builds and operates the shared services the estate's own operation depends on. The function works closely with the engineering teams that build the platform, supplying the production evidence that shapes what they fix and what they build next. 

Principal Platform Identity Engineer  

Role Summary 

Firmus runs large-scale, state-of-the-art AI infrastructure built on the latest generation of GPU rack-scale systems and operated as one estate to power the next generation of AI innovation. The Principal Platform Identity Engineer builds and operatesthe trust plane the estate's administrative and privileged accessdepends on: workforce and privilegedidentity, the internal certificate authority, secrets management, and the just-in-time access model tied to the change record. This is the trust plane of the platform, the foundation that access, privilege and every service's authentication rest on. 

This is a hands-on principal-level role with deep technical expertise. The trust plane is engineered, not administered: identity, certificates and secrets are provisioned as code, integrated into the delivery pipeline, and designed for rotation and recovery from the outset. The role holds key custody for the estate and carries out-of-hours accountability for the trust plane alongside a peer. 

Key Responsibilities  

  • Design, build and operate the workforce and service identity platform, including single sign-on and identity provider integration (for example authentik, Okta, Keycloak or Entra ID). 
  • Design, build and operate the internal certificate authority and certificate lifecycle management for the estate (for example step-ca or an equivalent internal PKI), and the secrets management platform (for example OpenBao or HashiCorp Vault), including rotation, access policy and audit. 
  • Automate identity, certificate and secrets provisioning as code, embedded into CI/CD and infrastructure-as-code workflows, so that access and credentials are never provisioned by hand. 
  • Own the privileged access management model: just-in-time elevation tied to a change record, approval workflows, and recorded break-glass access for emergencies. 
  • Implement and enforce least-privilege access patterns across the estate to the policy set by the Platform Security Engineers, and report on whether access matches the model in practice, with independent audit of that access carried out by Security. 
  • Design the trust plane for resilience, including certificate and secret rotation. 
  • Design and operate key custody for the estate's cryptographic material under dual control, so that no single person can access or use production key material alone, with named custodians, recorded quorum operations and an auditable custody record. Own the delegated-authority model that keeps custody and out-of-hours cover available without depending on one individual. 
  • Harden the identity, certificate and secrets services to the same standard they enforce on everything else, and produce the access and certificate evidence ISO 27001, SOC 2 and enterprise customer due diligence require, for collation by the Service Delivery Manager. 
  • Provide the deepest technical expertise for identity, certificate and secrets faults, approve and review just-in-time access requests that require judgement beyond the standard workflow, and mentor engineers across the function on identity and secret management practice. 
  • Own the privileged access management model: just-in-time elevation tied to a change record, approval workflows, and recorded break-glass access for emergencies, designed so that no one approves their own access and privileged access to the trust plane itself is approved outside this role's own team. 

Skills & Experience  

Required Skills 

  • Deep experience designing, building and operating identity and access management platforms, including single sign-on and identity provider integration (for example Okta, Keycloak, Entra ID or authentik). 
  • Strong experience with certificate lifecycle management and internal public key infrastructure (for example step-ca, HashiCorp Vault PKI, or an equivalent internal CA). 
  • Strong experience with secrets management platforms (for example HashiCorp Vault, OpenBao, or equivalent), including rotation, access policy and audit. 
  • Practical experience with privileged access management, just-in-time elevation and break-glass design for production environments. 
  • Experience with hardware security modules and key custody practices for production cryptographic material, including dual control or quorum-based custody models. 
  • Solid understanding of zero-trust architecture principles, and how to apply them to a multi-tenant platform. 
  • Experience embedding identity and secrets into CI/CD and infrastructure-as-code workflows. 
  • Strong scripting or programming ability for identity automation and tooling (for example Python, Go or Bash). 
  • Demonstrated experience as a senior escalation point for identity and security-adjacent faults in a 24/7 production environment. 
  • Practical understanding of how identity and access controls produce evidence for frameworks such as ISO 27001 or SOC 2, including separation of duties, independent approval of privileged access, and the design of controls that hold when the person designing them is also a user of them. 
  • Clear technical judgement and communication, able to explain trust-model decisions to both engineers and auditors. 

Preferred Experience 

  • Experience with Kubernetes-native identity patterns, such as workload identity or SPIFFE/SPIRE. 
  • Experience in a multi-tenant service provider, cloud or colocation environment. 
  • Familiarity with GPU or HPC infrastructure and its identity and access requirements. 
  • Relevant security or identity certification (for example CISSP, or a vendor-specific identity credential). 
  • A Bachelor's degree in computer science, engineering or a related discipline, or an equivalent combination of relevant experience and training. 

Expected Outcomes  

  • Identity, certificate and secrets services built and running to their declared service levels, with certificate expiry no longer a source of incidents. 
  • Standing privileged access replaced by just-in-time elevation tied to a change record. 
  • Key custody operating under dual control, with a complete custody record and a tested recovery path. 
  • Certificate and secret rotation automated end to end and exercised in production rather than documented. 
  • Access and certificate evidence accepted at first pass in audit and customer due diligence. 

Location & Reporting  

Location: Based in Australia or Singapore, with travel to Australian AI Factory sites as required. 

On-call: The function runs 24/7. First line monitoring and first response sit with the operations centre. This role shares the after-hours escalation roster for its domain with the other senior engineers in the function. 

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
698,236 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sydney
$37k – $72k per year (Estimated) • In office • Internship • Bachelor's Degree • Singapore
Python
Java
C++
AI/ML
Pandas
NumPy
Machine Learning
DevOps
CI/CD
Git
Apply
In office • 5+ years exp
Python
JavaScript
TypeScript
SQL
Python
Django
Databases
MySQL
PostgreSQL
Frontend
Vue.js
GraphQL
Angular
React.js
DevOps
CI/CD
Docker
Apply
$22k – $57k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Dalian
Python
SQL
C#
C#
.NET
Databases
Microsoft Fabric
AI/ML
Copilot
AutoGen
LangChain
Prompt Engineering
AI Agents
Semantic Kernel
RAG
OpenAI
Copilot Studio
Machine Learning
DevOps
Rest API
Azure DevOps
Azure
CI/CD
Git
Management
ServiceNow
Power Automate
Power Apps
Agile
Apply
Architect - R01571233 8 hours ago
$26k – $73k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Bengaluru
Apex
Apex
Lightning Web Components
Gearset
Copado
MuleSoft
Salesforce Flow
DevOps
Rest API
CI/CD
Git
AWS
Kubernetes
Amazon EKS
AWS Lambda
Amazon S3
API Gateway
SOAP
Apply
$52k – $145k per year (Estimated) • In office • Internship • Singapore
Python
Analytics
Tableau
Power BI
Microsoft Excel
Apply
$71k – $164k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Singapore
Python
AI/ML
NCCL
InfiniBand
DevOps
Ansible
CI/CD
HPC
Linux
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Least Privilege
SIEM
Apply
$92k – $208k per year (Estimated) • In office • Bachelor's Degree • Sydney
Python
DevOps
Cilium
Kubernetes
Platform Engineering
eBPF
HPC
Cybersecurity
ISO 27001
Least Privilege
Cilium Tetragon
Apply
$76k – $191k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Sydney
Python
JavaScript
Node JS
Node JS
Commander.js
DevOps
Terraform
Ansible
OpenTofu
etcd
CI/CD
GitOps
ArgoCD
Kubernetes
Platform Engineering
HPC
Apply
$155k – $277k per year (Estimated) • In office • Full-Time • 5+ years exp • San Francisco
AI/ML
LLM
Management
Jira
Apply
$164k – $315k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • San Francisco
Python
C++
C++
TensorFlow C++
PyTorch C++
AI/ML
TensorFlow
PyTorch
InfiniBand
Apply
$132k – $236k per year (Estimated) • In office • 5+ years exp • Sydney
Apply
$132k – $236k per year (Estimated) • In office • 5+ years exp • Sydney
Apply
$101k – $189k per year (Estimated) • In office • Full-Time • 6+ years exp • Sydney
DevOps
IAM
Cybersecurity
Keycloak
LDAP
Apply
$68k – $89k per year • Remote/Hybrid • Full-Time • 5+ years exp • Sydney
AI/ML
Claude
Management
Notion
Marketing
HubSpot
Apply
$84k – $132k per year • Remote • Full-Time • 6+ years exp • Sydney
Apply
See all jobs
This is one of many
698,236 more open roles from verified company boards, updated every day.