SpaceXAI is seeking a hands-on Infrastructure Security Engineer to help build and protect infrastructure from the physical layer through the platform and application stack. This role is focused on hardening bare metal and private-cloud foundations, embedding security into how systems are built and run, and securing hybrid connectivity across on-prem and cloud environments.
Work onsite in New York, NY, with a $100,000 - $258,000 USD base salary and a package that includes equity, comprehensive medical, vision, and dental coverage, retirement benefits, and additional discounts and perks.
Responsibilities
- Design and implement secure bare-metal and private-cloud architectures, including servers, storage, out-of-band management, and BIOS/UEFI/BMC firmware posture
- Harden physical and virtual fleets with Linux/Windows OS baselines, CIS benchmarks, patch and vulnerability management, and secure boot or measured boot where applicable
- Perform hands-on work across firmware and lifecycle security using BMC/iDRAC/iLO, PXE/Kickstart provisioning, and related hardware controls
- Build and secure network foundations on real hardware, including segmentation, load balancers, DNS, PKI, NAC, and IDS/IPS
- Own security for hybrid connectivity between on-prem and cloud using site-to-site VPN, Direct Connect / Interconnect / ExpressRoute, SD-WAN, and zero-trust access
- Manage identities and privileged access across hybrid environments using Active Directory / LDAP / Kerberos and cloud IAM, including federation, SAML/OIDC, and PAM
- Support security assessments and audits of physical, on-premises, and hybrid infrastructure
- Monitor and remediate infrastructure to align with regulations and best practices such as PCI, NIST CSF, GDPR, and HIPAA
- Design and implement secure container and Kubernetes standards for bare metal and private cloud, including RBAC, network policy, and secrets
- Develop and maintain Infrastructure as Code and configuration management with an emphasis on Puppet, including embedded security controls for physical and virtual fleets
- Partner with development teams to integrate security best practices into CI/CD pipelines
- Secure and enhance CI/CD pipelines by maintaining and integrating code and image scanning platforms
- Monitor and respond to security events and incidents spanning bare metal, network devices, hosts, and hybrid cloud
- Maintain SIEM data pipelines that ingest on-premises network, host, and cloud telemetry for reliable alerting
- Build, deploy, and maintain security operations infrastructure using Python, Terraform, and Puppet
- Create dashboards and alerts from security metrics across physical and platform layers
- Maintain infrastructure security policies, standards, and procedures from metal through platform
- Own security projects end to end, from identifying issues to implementing solutions
- Stay current with emerging threats and mitigations across bare-metal, firmware, network, and hybrid-cloud infrastructure
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, or a related field
- 3–5 years of experience in infrastructure security, platform security, or related hands-on roles
- Proven experience securing bare-metal, data-center, or private-cloud environments (not cloud-only)
- Hands-on experience with firmware, BMC/iDRAC/iLO, and PXE/Kickstart provisioning, including hardware lifecycle security
- Strong proficiency with Puppet for configuration management and fleet hardening in production
- Strong understanding of network security concepts and protocols, including hands-on work with firewalls, segmentation, and hybrid connectivity
- Experience with hybrid identity such as AD/LDAP integrated or federated with cloud IAM
- Infrastructure as Code experience (e.g., Terraform) applied to physical or VM fleets
- Familiarity with containerization and Kubernetes security implications for on-premises or bare-metal clusters
- Experience with automation and tool development using languages such as Python, Bash, and Golang
- Familiarity with regulatory compliance requirements including GDPR, HIPAA, PCI DSS, and NIST CSF
- Experience with banking, money transmission, P2P payments, or similarly regulated financial platforms
- Proactive mindset with strong ownership, critical thinking, and problem-solving
- Located in the SF Bay Area, Austin, New York, Palo Alto, or Seattle, or willing to relocate to a US office
Benefits
- Equity
- Comprehensive medical, vision, and dental coverage
- Access to a 401(k) retirement plan
- Short & long-term disability insurance
- Life insurance
- Various other discounts and perks
- $100,000 - $258,000 USD base salary
Preferred Skills and Experience
- Deep expertise operating and securing physical server fleets, colo, or private cloud (VMware, OpenStack, Proxmox, Nutanix, or similar)
- Relevant security certifications (e.g., CCSP, CSSK, OSCP, or a network/cloud security specialty)
- Strong proficiency with Python and Terraform on production fleets
- Deep expertise in Kubernetes and container security on bare metal or private cloud
- Experience with multi-cloud and cloud-to-on-prem security
- Knowledge of CI/CD best practices and hands-on GitHub Actions or equivalent
- Experience with observability and security operations tooling (e.g., Prometheus, Grafana, CloudWatch, Karma, and SIEM platforms such as Wazuh)
- Experience building custom security tools or integrations
- Interest in leveraging AI for infrastructure security monitoring and automation
- Contributions to open-source infrastructure or security projects
- Experience securing AI/ML and GPU workloads on bare metal or hybrid infrastructure
Technologies: Linux, Windows, BIOS/UEFI/BMC firmware, CIS benchmarks, secure boot, measured boot, BMC, iDRAC, iLO, PXE, Kickstart, Active Directory, LDAP, Kerberos, cloud IAM, SAML/OIDC, PAM, DNS, PKI, NAC, IDS/IPS, site-to-site VPN, Direct Connect, Interconnect, ExpressRoute, SD-WAN, zero-trust access, Kubernetes, RBAC, network policy, secrets, Infrastructure as Code, Puppet, CI/CD pipelines, SIEM, Python, Terraform, firewalls, Active directory / LDAP / Kerberos (hybrid identity), EKS, GKE, AKS