Sr. Staff Platform Security Engineer, Cloud Infrastructure
Job Description
Groq is hiring a senior platform security engineer to build and scale security foundations for its inference cloud platform.
Responsibilities
- Set technical direction and own architecture for critical platform security capabilities across identity, authorization, infrastructure security, encryption, key management, and auditability.
- Design and build identity and access systems covering authentication, federation, authorization, workload identity, lifecycle provisioning, and administrative access.
- Build and scale security capabilities for Kubernetes and distributed infrastructure using software, policy, automation, APIs, controllers, Infrastructure-as-Code, and GitOps.
- Architect security controls and isolation mechanisms for multi-tenant systems across compute, network, storage, and control-plane boundaries.
- Own infrastructure lifecycle security, including secure provisioning, secrets and credential management, encryption, and certificate lifecycle.
- Develop production software and automation so secure platform patterns are reliable, scalable, and adoptable by engineering teams.
- Lead security-sensitive platform designs and changes by translating risks and requirements into practical engineering decisions.
- Shape security architecture and technical standards across Platform Engineering, including influence beyond owned systems.
- Partner with engineering and security teams to build capabilities that strengthen customer trust, platform reliability, and compliance support.
- Communicate security architecture, technical tradeoffs, and risk clearly to engineers, technical leaders, and security leadership.
Requirements
- 6+ years of software engineering experience building complex infrastructure or distributed systems, with deep cloud and platform security experience (identity and access, Kubernetes, or related domains).
- Proven experience setting technical direction and owning complex security architecture across multiple systems, teams, or infrastructure domains.
- Deep experience with identity and access technologies including OIDC, SAML, SCIM, RBAC, workload identity, short-lived credentials, and multi-factor authentication.
- Deep experience designing security for multi-tenant systems and isolation across network, compute, storage, and control-plane boundaries.
- Hands-on Kubernetes security expertise: RBAC, admission control, service-account and workload identity, secrets and encryption, policy enforcement, and node security.
- Strong understanding of secrets management, encryption, key management, certificate lifecycle, and secure credential management.
- Strong software engineering skills in Go, Python, or similar languages, with experience designing, building, and operating production systems.
- Software-first security approach using APIs, controllers, automation, policy, Infrastructure-as-Code, GitOps, or similar mechanisms.
- Experience leading ambiguous cross-functional initiatives and influencing engineering direction across teams.
- Ability to reason about end-to-end security systems and communicate technical risk and architectural tradeoffs to different audiences.
- Experience building cloud platform capabilities in identity, key management, network security, or infrastructure security is valuable.
- Experience with network policy and encryption or security for high-performance storage and distributed infrastructure is valuable.
- Experience translating security and compliance requirements into automated evidence and production-ready controls is valuable.
- Experience building Kubernetes operators, admission webhooks, or similar infrastructure automation is valuable.
Technologies
- Kubernetes
- Go
- Python
- OIDC
- SAML
- SCIM
- RBAC
- Infrastructure-as-Code
- GitOps
- APIs
- Controllers
- Multi-factor authentication
- Short-lived credentials
Location
- San Francisco Bay Area, CA (hybrid).
- Role will be based in one of the hiring hubs: Dallas, San Francisco, or New York City area.
- Flexibility to work remotely while a local Groq office is established, with expectation of transition to onsite once the office opens.
Mission
- Build and scale the security foundations that enable customers to run sensitive AI workloads with confidence on Groq’s inference platform.
Compensation
- Total cash salary range: $341,400 - $401,600 (inclusive of potential bonus value), specific to candidates located in the United States.
- Individual placement determined by geographic location, experience, skills, and alignment with internal compensation standards.
- International candidate compensation varies based on local market dynamics.
- Long-Term Incentive (LTI) Program and a robust suite of employee benefits offered in addition to cash compensation.
Benefits
- Long-Term Incentive (LTI) Program
- Robust suite of employee benefits
Export Control
- US Job Postings: May require access to technology/information subject to US export control laws (including EAR). Candidates must qualify as US Persons for export control purposes or be eligible for an applicable export license.
- Non-US Job Postings: May require access to technology/information subject to US export control laws and applicable local laws, including EAR. Candidates must meet relevant export control eligibility criteria.
Equal Opportunity Employer
- Groq is an Equal Opportunity Employer committed to creating an inclusive environment.
- Employment decisions are made without regard to race, color, religion, national origin, sex (including gender identity, sexual orientation, and pregnancy), age, disability, genetic information, protected veteran status, or other protected characteristics under applicable law.
- Groq complies with applicable federal, state, and local nondiscrimination laws.
- Groq does not tolerate discrimination or harassment based on protected characteristics.
Reasonable Accommodations
- Groq is committed to providing reasonable accommodations to qualified individuals with disabilities.
- For accommodation requests related to the application or hiring process, contact [email protected] (case-by-case).
Other Employment Conditions
- Offers of employment are contingent upon verification of identity and employment authorization in accordance with federal law.
AI in the Hiring Process
- Groq may use AI tools or automated systems to assist with reviewing applications, evaluating qualifications, scheduling interviews, analyzing assessment responses, or supporting recruiting operations.
- Hiring decisions are subject to human review.
- Groq may process application materials, interview responses, assessments, and where applicable audio/video/transcript data.
- If legally required, Groq will request consent before using technologies that analyze biometric or video interview data.
- Candidates can request reasonable accommodations, an alternative evaluation process, additional information about AI use, or review of certain automated decisions by contacting [email protected].