Cloud Infrastructure Security Engineer (Systems/Kernel)

Runpod Inc

$152K — $175K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in infrastructure or systems-level security engineering.
  • Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
  • Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques.
  • Strong systems-level programming skills in C, Go, Rust, or Python.
  • Familiarity with GPU architecture and hardware-level security considerations.
  • Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.

Responsibilities

  • Design and implement robust workload and network isolation architectures for multitenant GPU environments.
  • Harden Linux kernel configurations, container runtimes, and orchestration layers against security threats.
  • Conduct deep-dive security assessments and penetration testing for hypervisors and network stacks.
  • Write code to implement custom security controls and telemetry at the OS and infrastructure level.
  • Evaluate and mitigate security risks specific to GPU architecture and shared memory.
  • Serve as the escalation point for infrastructure-level security incidents and develop forensic capabilities.

Benefits

  • Meaningful equity in a fast-growing company with stock options for all team members.
  • Generous medical, dental, and vision plans.
  • Flexible PTO allowing for a work-life balance.
  • Remote-first work environment with collaborative communication tools.
  • $1,200 Home Office & Equipment Stipend for ideal workspace setup.
Full Job Description
As RunPod continues to revolutionize the GPU cloud computing landscape, we are seeking a systems-focused Cloud Infrastructure Security Engineer. This critical position is instrumental in safeguarding our bare-metal and virtualized environments, ensuring the absolute security, multi tenant isolation, and integrity of our underlying GPU cloud infrastructure.

The ideal candidate possesses deep knowledge of Linux systems, kernel internals, hypervisors, and containerization. You will focus on the lowest levels of our stack-preventing tenant breakouts, securing GPU hardware allocations, and building resilient infrastructure to support AI and machine learning workloads.

RunPod is seeking an innovative security engineer who thrives at the systems layer. You will operate with an Attacker's Mindset, actively hunting for ways to break container and virtualization boundaries, and then writing the low-level code to patch them.

Responsibilities:
  • Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.
  • Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.
  • Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.
  • Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.
  • Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.
  • Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.

Required Qualifications:
  • 5+ years of experience in infrastructure or systems-level security engineering.
  • Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
  • Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments.
  • Strong systems-level programming skills in C, Go, Rust, or Python.
  • Familiarity with GPU architecture and hardware-level security considerations.
  • Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.

Preferred Qualifications:
  • Contributions to open-source systems security projects or virtualization research.
  • Experience writing or deploying eBPF-based security tooling.
  • Deep knowledge of low-level networking protocols and virtualized network security.


What You'll Receive:
  • The competitive base pay for this position ranges from ($152,000 - $175,000). This salary range may be inclusive of several career levels at Runpod and will be narrowed during the interview process based on a number of factors, including the candidate's experience, qualifications, and location
  • Meaningful equity in a fast-growing company- everyone on the team receives stock options - your impact drives our growth, and you share in the upside.
  • Generous medical, dental & vision plans
  • Flexible PTO- take the time you need to recharge
  • Most roles are remote work first with an inclusive, collaborative teams utilizing slack as the main form of internal communication
  • Join a passionate team on the cutting edge of AI infrastructure - where culture, learning, and ownership are at the heart of how we scale.
  • $1,200 Home Office & Equipment Stipend-We set you up for success from day one with gear and support to create your ideal workspace

Similar Jobs

More Jobs at Runpod Inc

More Information Technology Jobs

Find similar Cloud Infrastructure Security Engineer (Systems/Kernel) jobs: