698,236open jobs
41,342companies
99,387added this week
Browse all
Salary
$92k – $208k per year (Estimated)
Location
In office (Sydney)
Seniority
Senior
Overview
Company
Impact
Profile match
Firmus Technologies builds immersion-cooled artificial intelligence factories that run large GPU fleets on renewable power. Founded in 2021 in Singapore, it develops both the data centre design and the cloud service on top. Its Project Southgate campuses in Australia are among the region's largest planned artificial intelligence sites.

AI FactoryOSOperations  

AI FactoryOSis Firmus' proprietary operating system for the AI Factory. It governs GPU telemetry, cooling, powerand grid interaction as one integrated layer, so that every Firmus site can be optimisedand monitoredas a single system. 

AI FactoryOS Operations runs that platform in production and owns the 24/7 reliability of AI FactoryOS, Firmus AI Cloud and the platforms built on them, together with the service levels the estate is measured against. 

The remit is an engineering one. The function builds the guarded automation, remediation and operational tooling that turn manual response into a software-defined capability, andbuilds and operatesthe shared services the estate's own operation depends on. The function works closely with the engineering teams that build the platform, supplying the production evidence that shapes what they fix and what they build next. 

Senior Platform Security Engineer  

Role Summary 

Firmus runs large-scale, state-of-the-artAI infrastructure built on the latest generation of GPU rack-scale systems and operatedas one estate to power the next generation of AI innovation. The Senior Platform Security Engineer owns the operational security of that platform. The multi-tenant Kubernetes estate sits at its heart: production access, admission policy, workload identityand network policy in the live estate, andthe operational security controls that keep it defensible as it grows. 

This is a hands-on senior role with deep technical expertise. This role owns security in production: runtime visibility and enforcement built with modern eBPF-based tooling, the security acceptance requirements a release has to meet before it is authorised, the authority to grant or refuse a security exception, and the deepest technical escalation for security-related platform faults. 

Key Responsibilities  

  • Build runtime visibility and enforcement using eBPF-based tooling (for example Cilium, Falcoor Tetragon), feeding high-quality signalinto the estate's security monitoring, and tune detection so that alerts stay actionable as the estate grows. 
  • Own the security gates in the delivery pipeline: image signing, software bills of materials, vulnerability gating and policy checks, and maintain the policy-as-code controls that govern what ships to production, running on the delivery toolchain operated by Shared Services Operations. 
  • Set and own the security content of the multi-tenant Kubernetes estate: admission policy, workload identityand network policy, and verify that what runs in production matches it. 
  • Set the operational security standard the platform's Kubernetes control planes and baselines must meet in production, validateagainst it continuously, and raise deviations as engineering requirements to the AI Infrastructure team. 
  • Validate the layered controls that limit the blast radius of a fault or compromise across tenant boundaries, test them against realistic failure and attack paths, and feed the findings to AI Infrastructure where the control belongs to the product. 
  • Investigate and respond to security-related operational anomalies, distinguishing a security signal from an ordinary operational symptom. 
  • Operatethe platform's security controls in line with ISO 27001 and NIST frameworks, applying deep expertisein securing large-scale GPU infrastructure, and produce the security evidence those controls generate for collation by the Service Delivery Manager. 
  • Provide the deepest technical expertisefor security-related platform faults, contribute to post-incident review for security incidents, and mentor engineers across the function on secure design and runtime security practice. 
  • Provide independent monitoring of privileged activity across the estate, including on the identity, certificateand secrets platforms, using the access mechanisms built by the Principal Platform Identity Engineer. 

Skills & Experience  

Required Skills 

  • Strong experienceof privileged access security, including least-privilege design, secrets management, and the auditing of privileged operations in production environments. 
  • Strong experience securing multi-tenant Kubernetes environments, including admission policy, workload identity, network policyand control plane hardening. 
  • Extensive experience with eBPF-based runtime security tooling (for example Cilium, Falcoor Tetragon), including building detection and enforcement that feeds a security monitoring platform. 
  • Strong DevSecOpsexperience owning security gates in a delivery pipeline: image signing, software bills of materials, vulnerability gatingand policy checks. 
  • Solid understanding of hardware-enforced or network-based tenant isolation, and how it interacts with Kubernetes-level policy. 
  • Experience with policy-as-code tooling for Kubernetes and delivery pipelines. 
  • Demonstrated experience as a senior escalation point for security-related faults in a 24/7 production environment, including post-incident review. 
  • Strong scripting or programming ability for security automation and tooling (for example Python, Go or Bash). 
  • Clear technical judgement and communication, with the ability to translate security findings and standards for engineering teams and leadership. 

Preferred Experience 

  • Experience securing GPU or HPC infrastructure and multi-tenant AI workloads. 
  • Experience in a multi-tenant service provider, cloudor colocation environment. 
  • Experiencewith workload identity and secrets management patterns, and how runtime enforcement ties back to them. 
  • Experience with security frameworks and evidence production under ISO 27001, SOC 2or NIST frameworks. 
  • Relevant security certification (for example OSCP, GCFA, or a Kubernetes security credential). 
  • A Bachelor's degree in computer science, engineering or a related discipline, or an equivalent combination of relevant experience and training. 

Expected Outcomes  

  • Runtime detection covering the estate, with an alert set that stays actionable as the estate grows. 
  • Every production release meeting the security acceptance requirements, with exceptions owned, time-bound, compensating-controlled and on the register. 
  • The operational security standard for Kubernetes validated continuously in production rather than asserted at design time. 
  • Blast radius controls tested against realistic failure and attack paths, with findings closed or evidenced to the platform engineering teams. 
  • Security evidence produced through normal operation rather than assembled before an audit. 

   

Location & Reporting  

Location: Based in Australia or Singapore, with travel to Australian AI Factory sites as required. 

On-call: The function runs 24/7. First line monitoring and first response sit with the operations centre. This role shares the after-hours escalation roster for its domain with the other senior engineers in the function. 

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
698,236 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sydney
$92k – $218k per year (Estimated) • In office • Bachelor's Degree • Sydney
Python
DevOps
CI/CD
Kubernetes
HPC
Cybersecurity
Keycloak
Okta
HashiCorp Vault
ISO 27001
Authentik
SOC 2
Zero Trust
Least Privilege
Microsoft Entra ID
PKI
Apply
In office • PhD
Python
Python
pySpark
Databases
Databricks
Delta Lake
AI/ML
Spark
MLFlow
Google AI Studio
Machine Learning
DevOps
Azure
CI/CD
Kubernetes
Platform Engineering
Apply
$101k – $221k per year (Estimated) • Remote • Bachelor's Degree
Python
JavaScript
TypeScript
Frontend
React.js
DevOps
Rest API
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Management
Agile
Apply
$76k – $191k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Sydney
Python
JavaScript
Node JS
Node JS
Commander.js
DevOps
Terraform
Ansible
OpenTofu
etcd
CI/CD
GitOps
ArgoCD
Kubernetes
Platform Engineering
HPC
Apply
$24k – $60k per year (Estimated) • Remote/Hybrid • 3+ years exp • Perm
Java
Kotlin
Java
Spring Boot
Quarkus
Micronaut
Vert.x
Databases
MySQL
PostgreSQL
RabbitMQ
ActiveMQ
Apache Kafka
DevOps
OpenShift
Docker
Kubernetes
Apply
$71k – $164k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • Singapore
Python
AI/ML
NCCL
InfiniBand
DevOps
Ansible
CI/CD
HPC
Linux
Cybersecurity
ISO 27001
SOC 2
Zero Trust
Least Privilege
SIEM
Apply
$92k – $218k per year (Estimated) • In office • Bachelor's Degree • Sydney
Python
DevOps
CI/CD
Kubernetes
HPC
Cybersecurity
Keycloak
Okta
HashiCorp Vault
ISO 27001
Authentik
SOC 2
Zero Trust
Least Privilege
Microsoft Entra ID
PKI
Apply
$76k – $191k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Sydney
Python
JavaScript
Node JS
Node JS
Commander.js
DevOps
Terraform
Ansible
OpenTofu
etcd
CI/CD
GitOps
ArgoCD
Kubernetes
Platform Engineering
HPC
Apply
$155k – $277k per year (Estimated) • In office • Full-Time • 5+ years exp • San Francisco
AI/ML
LLM
Management
Jira
Apply
$164k – $315k per year (Estimated) • In office • Full-Time • 8+ years exp • Bachelor's Degree • San Francisco
Python
C++
C++
TensorFlow C++
PyTorch C++
AI/ML
TensorFlow
PyTorch
InfiniBand
Apply
$132k – $236k per year (Estimated) • In office • 5+ years exp • Sydney
Apply
$132k – $236k per year (Estimated) • In office • 5+ years exp • Sydney
Apply
$101k – $189k per year (Estimated) • In office • Full-Time • 6+ years exp • Sydney
DevOps
IAM
Cybersecurity
Keycloak
LDAP
Apply
$68k – $89k per year • Remote/Hybrid • Full-Time • 5+ years exp • Sydney
AI/ML
Claude
Management
Notion
Marketing
HubSpot
Apply
$84k – $132k per year • Remote • Full-Time • 6+ years exp • Sydney
Apply
See all jobs
This is one of many
698,236 more open roles from verified company boards, updated every day.