Cloud Infrastructure Security Engineer (Systems/Kernel)

RunPod

Remote · USFull-time$152–175K/yrPosted 4 days agoStill listed 4 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$152–175K/yr
Location
Remote · US
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

Runpod, an AI developer cloud platform, seeks a systems-focused Cloud Infrastructure Security Engineer to protect its bare-metal and virtualized GPU environments. The role involves designing isolation architectures, hardening kernels and containers, threat modeling, writing low-level security code, and responding to infrastructure incidents, all within a remote-first engineering team.

Skills & qualifications

RequiredNice to have

Skills

Linux Kernel InternalsCgroupsNamespaceseBPFSELinux/AppArmorKVMQEMUDockerContainerdKubernetesC ProgrammingGo ProgrammingRust ProgrammingPython ProgrammingGPU ArchitecturePCIe Pass‑ThroughHardware Security

Qualifications

5+ Years Experience in Infrastructure or Systems‑Level Security EngineeringContributions to Open‑Source Systems Security Projects or Virtualization ResearchExperience Writing or Deploying eBPF‑Based Security ToolingDeep Knowledge of Low‑Level Networking Protocols and Virtualized Network Security

Benefits

Medical Insurance
Dental Insurance
Vision Insurance
Paid Time Off

Full job description

Runpod is the AI Developer Cloud. More than one million developers, from indie researchers to teams running frontier models in production, use Runpod to experiment, train, fine-tune, deploy, and scale AI on one platform. The platform has processed more than 20 billion inference requests. We closed a $100M Series A in June 2026. We're at an inflection point for AI infrastructure, and we're building the platform the next generation of developers will depend on. Learn more in our CEO's funding announcement: https://www.runpod.io/blog/one-million-developers. We're a small, remote-first team. We take ownership seriously, move fast, and ship work that more than a million developers rely on every day. We're looking for people who care deeply, build with urgency, and want to matter at scale. As Runpod continues to revolutionize the GPU cloud computing landscape, we are seeking a systems-focused Cloud Infrastructure Security Engineer. This critical position is instrumental in safeguarding our bare-metal and virtualized environments, ensuring the absolute security, multi tenant isolation, and integrity of our underlying GPU cloud infrastructure. The ideal candidate possesses deep knowledge of Linux systems, kernel internals, hypervisors, and containerization. You will focus on the lowest levels of our stack—preventing tenant breakouts, securing GPU hardware allocations, and building resilient infrastructure to support AI and machine learning workloads. Runpod is seeking an innovative security engineer who thrives at the systems layer. You will operate with an Attacker's Mindset, actively hunting for ways to break container and virtualization boundaries, and then writing the low-level code to patch them. Responsibilities:

  • Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.

  • Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.

  • Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.

  • Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.

  • Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.

  • Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.

Required Qualifications:

  • 5+ years of experience in infrastructure or systems-level security engineering.

  • Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).

  • Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments.

  • Strong systems-level programming skills in C, Go, Rust, or Python.

  • Familiarity with GPU architecture and hardware-level security considerations.

  • Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.

Preferred Qualifications:

  • Contributions to open-source systems security projects or virtualization research.

  • Experience writing or deploying eBPF-based security tooling.

  • Deep knowledge of low-level networking protocols and virtualized network security.

What You’ll Receive:

  • The competitive base pay for this position ranges from ($152,000 - $175,000). This salary range may be inclusive of several career levels at Runpod and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location

  • Meaningful equity in a fast-growing company- everyone on the team receives stock options — your impact drives our growth, and you share in the upside.

  • Generous medical, dental & vision plans

  • Flexible PTO- take the time you need to recharge

  • Most roles are remote work first with an inclusive, collaborative teams utilizing slack as the main form of internal communication

  • Join a passionate team on the cutting edge of AI infrastructure — where culture, learning, and ownership are at the heart of how we scale.

  • $1,200 Home Office & Equipment Stipend- We set you up for success from day one with gear and support to create your ideal workspace

Runpod is committed to maintaining a workplace free from discrimination and upholding the principles of equality and respect for all individuals. We believe that diversity in all its forms enhances our team. As an equal opportunity employer, Runpod is committed to creating an inclusive workforce at every level. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, protected veteran status, disability status, or any other characteristic protected by law. We welcome every qualified candidate eligible to work in the United States; however, we are currently unable to sponsor employment visas.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.