Infrastructure Security Engineer (Bare Metal & Platform)
Job Description
SpaceXAI is seeking a hands-on Infrastructure Security Engineer to build and secure infrastructure from bare metal through the platform and application stack. The role spans physical and private-cloud foundations, container and Kubernetes security standards, automation and tooling, and monitoring and incident response across hybrid environments.
Responsibilities
- Design and implement secure bare-metal and private-cloud architectures including servers, storage, out-of-band management, and BIOS/UEFI/BMC firmware posture.
- Harden physical and virtual fleets with OS baselines for Linux and Windows, CIS benchmarks, patch and vulnerability management, and secure boot or measured boot where applicable.
- Perform hands-on work across firmware and hardware lifecycle security, including BMC and tools such as iDRAC/iLO, as well as PXE/Kickstart provisioning.
- Build and secure network foundations on real hardware, including segmentation, load balancers, DNS, PKI, NAC, and IDS/IPS.
- Own hybrid connectivity between on-premises and cloud, including site-to-site VPN, Direct Connect/Interconnect/ExpressRoute, SD-WAN, and zero-trust access patterns.
- Manage identities and privileged access across Active Directory/LDAP/Kerberos and cloud IAM, including federation, SAML/OIDC, and PAM.
- Assist with security assessments and audits spanning physical, on-premises, and hybrid infrastructure.
- Monitor and remediate infrastructure to maintain compliance with regulations and best practices such as PCI, NIST CSF, GDPR, and HIPAA.
- Design and implement secure container and Kubernetes standards for bare metal and private cloud, including RBAC, network policy, and secrets (not limited to managed Kubernetes services).
- Develop and maintain Infrastructure as Code and configuration management with embedded security controls, with a focus on Puppet for physical and virtual fleets.
- Collaborate with development teams to integrate security best practices into CI/CD pipelines.
- Secure and enhance CI/CD pipelines by integrating and maintaining code and image scanning platforms.
- Monitor and respond to security events and incidents across bare metal, network devices, hosts, and hybrid cloud.
- Maintain SIEM data pipelines that ingest on-premises network, host, and cloud telemetry for reliable alerting.
- Build, deploy, and maintain security operations infrastructure using Python, Terraform, and Puppet.
- Create dashboards and alerts from security metrics across physical and platform layers.
- Develop and maintain infrastructure security policies, standards, and procedures from metal through the platform.
- Own security projects end to end, from identifying issues to implementing solutions.
- Stay current on emerging threats and mitigations for bare-metal, firmware, network, and hybrid-cloud infrastructure.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- 3–5 years of experience in infrastructure security, platform security, or related hands-on roles.
- Proven experience securing bare-metal, data-center, or private-cloud environments (not cloud-only resumes).
- Hands-on experience with firmware, BMC/iDRAC/iLO, PXE/Kickstart provisioning, and hardware lifecycle security.
- Strong proficiency with Puppet for configuration management and fleet hardening in production.
- Strong understanding of network security, including hands-on work with firewalls, segmentation, and hybrid connectivity.
- Experience with hybrid identity (AD/LDAP or similar) integrated or federated with cloud IAM.
- Experience with Infrastructure as Code (e.g., Terraform) applied to physical or VM fleets.
- Familiarity with containerization and Kubernetes security implications, including on-premises or bare-metal clusters.
- Experience with automation and tool development using languages such as Python, Bash, and Golang.
- Familiarity with regulatory compliance requirements including GDPR, HIPAA, PCI DSS, and NIST CSF.
- Experience in banking, money transmission, P2P payments, or similarly regulated financial platforms.
- Proactive mindset with strong ownership, critical thinking, and problem-solving skills.
- Located in the SF Bay Area, Austin, New York, Palo Alto, or Seattle, or willing to relocate to a US office.
Technologies
Linux, Windows, BIOS/UEFI, BMC, iDRAC, iLO, PXE, Kickstart, CIS benchmarks, secure boot / measured boot, DNS, PKI, NAC, IDS/IPS, site-to-site VPN, Direct Connect / Interconnect / ExpressRoute, SD-WAN, Active Directory, LDAP, Kerberos, SAML/OIDC, PAM, Kubernetes, RBAC, network policy, secrets, Infrastructure as Code, Puppet, CI/CD pipelines, SIEM, Python, Terraform, Active Directory / LDAP / Kerberos, firewalls, Bash, Golang, EKS, GKE, AKS.
Preferred Skills and Experience
- Deep expertise operating and securing physical server fleets, colo, or private cloud (VMware, OpenStack, Proxmox, Nutanix, or similar).
- Relevant security certifications (e.g., CCSP, CSSK, OSCP, network or cloud security specialty).
- Strong proficiency with Python and Terraform on production fleets.
- Deep expertise in Kubernetes and container security on bare metal or private cloud.
- Experience with multi-cloud and cloud-to-on-prem security.
- Knowledge of CI/CD best practices and hands-on work with GitHub Actions or equivalent.
- Experience with observability and security operations tooling (e.g., Prometheus, Grafana, CloudWatch, Karma; SIEM platforms such as Wazuh).
- Experience building custom security tools or integrations.
- Interest in leveraging AI for infrastructure security monitoring and automation.
- Contributions to open-source infrastructure or security projects.
- Experience securing AI/ML and GPU workloads on bare metal or hybrid infrastructure.
Compensation and Benefits
Salary: $100,000 - $258,000 USD per year.
- Equity
- Comprehensive medical, vision, and dental coverage
- Access to a 401(k) retirement plan
- Short & long-term disability insurance
- Life insurance
- Various other discounts and perks
Location
Palo Alto, CA (onsite)
Education
Bachelor’s degree in Computer Science, Cybersecurity, or a related field.