410,740open jobs
14,301companies
73,665added this week
Browse all
Salary
$86k – $195k per year (Estimated)
Location
In office (Sydney)
Seniority
Senior · 7+ years exp
Employment
Contractor
Overview
Company
Impact
Profile match
Firmus Technologies builds immersion-cooled artificial intelligence factories that run large GPU fleets on renewable power. Founded in 2021 in Singapore, it develops both the data centre design and the cloud service on top. Its Project Southgate campuses in Australia are among the region's largest planned artificial intelligence sites.

Firmus Technologies

Firmus Technologies is a global leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.

Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a steadfast commitment to sustainability. 

At Firmus, we are unique in our approach. We design, build, and operate a new class of digital infrastructure - the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally.

Firmus AI Cloud

Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI compute at scale to customers.

It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale.

Why Firmus?

As an NVIDIA Cloud and Engineering partner in Asia Pacific, you will gain skills, experience, and exposure across the AI industry and be part of shaping what this industry looks like for decades to come.

We are founder-led, not a big corporate. Decisions happen fast, our leaders are accessible, and there's minimum bureaucracy between you and the work. Ownership comes early. Whatever your role, you will have a direct line to outcomes, helping shape how the business grows as we scale nationally across a long-term, large-scale roadmap. 

Work alongside founders and experts in AI infrastructure, energy systems and next-generation compute.

What we build here has impact beyond the business. Our AI Factories are designed to operate as assets to the energy grid to actively strengthen the communities and regions they operate in rather than drawing from them.

Considering applying? You don't need a perfect background to join our team. If you're driven and curious, there's a path for you. We back our people to grow into new domains and take on challenges beyond their previous experience.

ROLE SUMMARY  

Firmus Technologies is seeking a Senior Security Engineer, Application for our Engineering and Technology team. You own application security for Firmus AI Cloud and the internal software that runs it. Automation is how you scale that ownership. Customers provision GPU compute through API and console, software engineers build against it, and our operators run the platform through the same control plane. You own the security of that software: the public APIs, the services behind them, how tenants stay separated inside the application, and the AI assistants and agents we ship on top. 

KEY RESPONSIBILITIES  

Automation and secure delivery  

  • Own the CI/CD security gates that every production repository passes through: SAST, DAST, SCA, secrets detection, and SBOM generation. 
  • Build the systems that do the repeatable work: finding triage, dependency uplift, evidence collection, and draft threat models.  
  • Ship the secure paved roads other teams build on: reusable libraries, service templates, and developer tooling. 
  • Write and review code in the services you protect, including the security-critical paths that tools miss. 

Security architecture and standards  

  • Set the application security standard and control for authentication, authorisation between services, tenant isolation at the application boundary, secret handling and logging. 
  • Lead threat modelling and secure design review. Define what an attacker can do and what must be true before it ships. 
  • Set the security requirements for the AI assistants and agents we ship e.g. prompt injection, context poisoning. 
  • Govern which tools and tool servers our AI agents and software engineers may reach, and how those integrations are scoped, allow-listed, and audited. 

Assurance and vulnerability management  

  • Own application security posture across our services: what is covered, what is open, what is accepted with a named owner and an expiry, and what is overdue. 
  • Prioritise fixes on exploitability and exposure alongside CVSS and hold them to the Firmus vulnerability SLAs. 
  • Drive remediation with the teams that own the code so issues close at the source. 
  • Extend SOC 2 Type 2 and ISO 27001 into the software delivery path as services and sites grow. Evidence that a control ran should be a query, not a spreadsheet exercise. 

Enablement and escalation  

  • Coach security champions inside each team so secure design decisions get made without waiting for you. 
  • Provide application-security expertise during incidents and convert recurring failure modes into gates, tests, standards, or developer tooling. 
  • Give engineering leadership a straight read on application risk and release readiness. Join customer conversations when the question is application security. 

SKILLS AND EXPERIENCE 

  • Bachelor's degree in computer science or a related technical field. 
  • 7+ years in application security, product security, or software engineering with a security focus. 
  • Experience securing a public cloud or multi-tenant platform with a public API. 
  • Deep, practical knowledge of the OWASP Top 10 and the OWASP API Security Top 10. Has threat modelled multi-tenant APIs in production: identity, authorisation between services, tenant isolation, and the ways a client abuses a published contract using STRIDE or an equivalent method, both for REST and gRPC. 
  • Has improved the security posture of software built by other engineering teams through standards, tooling, review, or secure-by-default patterns. 
  • Has owned CI/CD security gates in production (SAST, DAST, SCA, secrets detection, SBOM) and tuned them to deliver actionable findings with low false-positive rates that engineers trusted and acted upon. 
  • Writes production-quality code in at least one of Python, Go, or TypeScript. 
  • Has replaced manual security work with automation: finding triage, dependency uplift, evidence collection, or regression tests that run without someone watching them. 
  • Hands-on with LLM-backed or agentic features: prompt injection, tool misuse, agent identity and delegated credentials, cross-tenant data leakage, and controls on generated code reaching production. Familiar with OWASP guidance for LLM and agentic applications. 
  • Deep practical experience with OAuth, OIDC, JWT, RBAC or ABAC, application-layer cryptography, token handling, and secrets in software. 
  • Has worked under SOC 2 Type 2 or ISO 27001 and can produce evidence that a control ran. 
  • Willing to join incident response for application and API security. 
  • Willing to travel overseas occasionally when the role requires it. 
  • Clear and effective written and verbal communication in English 

Bonus Points  

  • Experience securing AI agents, sandboxed code execution environments, or systems where AI-generated output can trigger automated actions. 
  • Has run a vulnerability disclosure programme. 
  • Security certifications with application-security depth, such as CSSLP or OSWE. 

LOCATION  

Singapore or Australia 

Diversity

At Firmus, we are committed to building a diverse and inclusive workplace. We encourage applications from candidates of all backgrounds who are passionate about creating a more sustainable future through innovative engineering solutions.

Join us in our mission to revolutionise the AI industry through sustainable practices and cutting-edge engineering. Apply now to be part of shaping the future of sustainable AI infrastructure.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
410,740 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sydney
$53k – $122k per year (Estimated) • In office • Full-Time • 3+ years exp • Stockholm
Python
TypeScript
AI/ML
AI Agents
Management
Dropbox
SharePoint
Apply
In office • Full-Time • 1+ year exp • Stockholm
AI/ML
AI Agents
Marketing
LinkedIn
Apply
$36k – $121k per year (Estimated) • In office • Full-Time • 3+ years exp • Stockholm
Python
SQL
TypeScript
AI/ML
AI Agents
DevOps
Platform Engineering
Apply
Account Executive 1 day ago
In office • Full-Time • 3+ years exp • Stockholm
AI/ML
AI Agents
Apply
In office • Internship • Stockholm
JavaScript
Python
SQL
TypeScript
AI/ML
AI Agents
Claude
Claude Code
DevOps
Docker
Git
Kubernetes
Apply
$40k – $96k per year (Estimated) • In office • Contractor • 2+ years exp • Singapore
DevOps
Incident Management
Apply
$89k – $201k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Sydney
Bash
Python
DevOps
AWS
Azure
GCP
Kubernetes
Platform Engineering
Cybersecurity
Auth0
Calico
Checkov
CIS Benchmarks
Cosign
Falco
HashiCorp Boundary
HashiCorp Vault
HIPAA
ISO 27001
kube-bench
Kyverno
OWASP Top 10
PCI DSS
Snyk
SOC 2
Teleport
Trivy
Cryptography
Vault
Apply
$78k – $188k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Singapore
Python
AI/ML
NCCL
NVLink
DevOps
Grafana
HPC
Platform Engineering
Apply
$77k – $204k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • Singapore
Go
Node JS
Python
SQL
JavaScript
Databases
Apache Kafka
ClickHouse
Kafka
Frontend
GraphQL
Mobile
JUnit
DevOps
Ansible
ArgoCD
AWS
Azure
CI/CD
Configuration Management
Docker
GCP
GitHub
GitHub Actions
Grafana
Jenkins
Loki
Platform Engineering
Prometheus
Thanos
Kubernetes
Cybersecurity
ISO 27001
SOC 2
Game Dev
Meta Quest SDK
QA
Cypress
k6
Pytest
Apply
$79k – $224k per year (Estimated) • In office • 10+ years exp • Bachelor's Degree • Singapore
Go
Python
AI/ML
AI Agents
DevOps
CI/CD
Incident Management
Kubernetes
Platform Engineering
SLI/SLO/SLA
Cybersecurity
ISO 27001
SOC 2
Apply
$123k – $182k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Sydney
AI/ML
AI Agents
DevOps
AWS
Azure
GCP
Apply
$77k – $201k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Sydney
JavaScript
Kotlin
Objective-C
TypeScript
Frontend
React.js
Mobile
Expo
React Native
DevOps
AWS
Azure
GCP
Apply
Remote/Hybrid • Full-Time • 5+ years exp • Sydney • Melbourne
Marketing
LinkedIn
Apply
Remote/Hybrid • Full-Time • 1+ year exp • Master's Degree • Sydney • Melbourne
Apply
Senior Recruiter 2 days ago
In office • 5+ years exp • Sydney
AI/ML
Human-in-the-Loop
Apply
See all jobs
This is one of many
410,740 more open roles from verified company boards, updated every day.