THE ROLE:AMD's SW Ecosystem Security Engineering Team is seeking a software engineer to deliver confidential computing enablement for AMD EPYC platforms, with primary emphasis on Kubernetes and KubeVirt-based confidential virtual machine support. The role focuses on making AMD SEV-SNP capabilities usable through open source virtualization and confidential computing stacks such as KubeVirt, OpenShift Virtualization, Kata Containers, Confidential Containers, VirTEE, Trustee, and related attestation components. The developer will work across host, guest, hypervisor, orchestration, and container runtime layers to help turn AMD platform security features into production-ready software, validation, documentation, and partner-facing enablement. Success in this role requires strong systems software fundamentals, open source execution, and the ability to collaborate with upstream communities, OS vendors, and internal AMD stakeholders on technically rigorous solutions for confidential VMs, confidential containers, and AMD EPYC platform enablement.
THE PERSON: The ideal candidate is a hands-on systems engineer who can move comfortably between architecture, implementation, debug, test, and upstream review. They should be able to reason deeply about confidential VM behavior in KubeVirt-based environments, including guest-owner trust boundaries, firmware and hypervisor interactions, attestation evidence, policy enforcement, secret handling, and the practical integration work required to expose AMD SEV-SNP capabilities through open source virtualization stacks. This person communicates clearly with maintainers, OS vendor partners, and internal stakeholders; identifies practical gaps in evolving upstream projects; and converts ambiguous platform enablement needs into accepted designs, working code, reliable tests, and clear technical guidance.
KEY RESPONSIBILITIES: - Develop and upstream AMD SEV-SNP enablement for KubeVirt, including confidential VM configuration, libvirt/QEMU integration, guest launch flows, node feature discovery, and end-to-end validation.
- Implement confidential VM and attestation functionality across KubeVirt, VirTEE, Trustee, and related components, including secure workload launch, policy enforcement, evidence handling, and secret-release flows.
- Support confidential container enablement where it intersects with VM-based trusted execution environments, including Kata Containers and Confidential Containers integration points.
- Debug integration issues across Linux, KVM, QEMU, libvirt, KubeVirt, guest firmware, attestation services, container runtimes, and platform configuration.
- Create and maintain CI coverage, hardware-backed validation, functional tests, interoperability tests, and demonstrations for AMD confidential computing features.
- Collaborate with upstream maintainers, OS vendors, partner teams, and internal AMD stakeholders through design reviews, community discussions, roadmap alignment, and technical issue resolution.
- Develop AMD EPYC platform-aware, such as Kubernetes, enablement where NUMA locality, cache hierarchy, CCD/CCX organization, SMT placement, CPU pinning, or device locality affect confidential VM performance, placement, or deployment predictability.
- Produce technical documentation, planning material, usage guidance, and proof-of-concept support for confidential VM deployment and related confidential computing workflows.
PREFERRED EXPERIENCE: - Systems software development experience in Rust, Go, Python, and Bash for Linux, virtualization, or cloud-native infrastructure projects.
- Technical proficiency with Kubernetes, Linux, KVM, QEMU, libvirt, guest firmware, VM lifecycle management, and debugging across host, guest, hypervisor, and containers.
- Hands-on experience with KubeVirt, OpenShift Virtualization, Red Hat OpenShift Virtualization, or comparable open source virtualization environments.
- Experience with confidential computing technologies such as AMD SEV-SNP, SEV, SEV-ES, confidential VMs, confidential containers, trusted execution environments, or guest-owner trust models.
- Working knowledge of attestation concepts and components, including attestation evidence, VCEK handling, policy configuration, and secret-release workflows.
- Track record contributing code, tests, documentation, design proposals, or reviews to upstream open source projects.
- Experience developing CI, end-to-end tests, hardware-backed validation, demos, or technical guides for virtualization or platform enablement features.
- Experience collaborating with OS vendors, software partners, ISVs, customers, or upstream engineering teams on deployment guidance, proof-of-concept enablement, or production-readiness.
- Understanding of x86 or AMD EPYC architecture concepts relevant to confidential VM placement and performance, including memory encryption, NUMA topology, cache hierarchy, CPU pinning, SMT placement, and device locality.
ACADEMIC CREDENTIALS: - Bachelor's or Master's degree in Computer or Electrical Engineering or equivalent
This role is not eligible for visa sponsorship.#LI-AG1#LI-HYBRIDBenefits offered are described: AMD benefits at a glance.