Principal Platform Identity Engineer

Firmus Technologies Pty Ltd.

Sydney

On-site

AUD 260,000 - 380,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Firmus Technologies Pty Ltd. seeks a Principal Platform Identity Engineer to build and operate the trust plane for a global AI infra estate.

You will manage workforce identity, internal PKI, and secrets management with automated provisioning, CI/CD integration, and auditable access controls. This hands-on senior role requires deep expertise in IAM, PKI, and secret management, with dual-control custody and just-in-time access for emergencies.

Qualifications

  • Experience designing, building and operating identity and access management platforms.
  • Strong certificate lifecycle management experience.
  • Experience with secrets management platforms and rotation policies.
  • Practical experience with privileged access management and just-in-time elevation.
  • Understanding of zero-trust architecture in multi-tenant environments.
  • Experience embedding identity and secrets into CI/CD and IaC workflows.
  • Strong scripting/programming ability (Python/Go/Bash).
  • Escalation point for identity and security faults in 24/7 production environments.
  • Ability to articulate trust-model decisions to engineers and auditors.

Responsibilities

  • Design, build and operate the workforce and service identity platform (SSO and IdP integration).
  • Design, build and operate internal PKI and certificate lifecycle; manage secrets platform with rotation and audit.
  • Automate identity, certificate and secrets provisioning as code within CI/CD and IaC pipelines.
  • Own the privileged access management model with just-in-time elevation and break-glass procedures.
  • Enforce least-privilege access patterns and provide audit-ready evidence for audits.
  • Design resilience for the trust plane, including rotation and key custody under dual control.
  • Maintain dual-control custody for production cryptographic material with auditable records.
  • Harden services and provide evidence for ISO 27001 and SOC 2 standards.

Skills

Identity IAM platforms
Single sign-on
Certificate lifecycle
Secrets management
Privileged access mgmt
Just-in-time elevation
Zero-trust
CI/CD integration
Infrastructure-as-code
Python/Go/Bash
Auditing & compliance
PKI/HSM
Technical communication

Education

Bachelor's degree in computer science or engineering

Tools

authentik
Okta
Keycloak
Entra ID
HashiCorp Vault
OpenBao
step-ca

Job description

Principal Platform Identity Engineer

Role Summary

Firmus runs large-scale, state-of-the-art AI infrastructure built on the latest generation of GPU rack-scale systems and operated as one estate to power the next generation of AI innovation. The Principal Platform Identity Engineer builds and operates the trust plane the estate's administrative and privileged access depends on: workforce and privileged identity, the internal certificate authority, secrets management, and the just-in-time access model tied to the change record. This is the trust plane of the platform, the foundation that access, privilege and every service's authentication rest on.

This is a hands‑on principal‑level role with deep technical expertise. The trust plane is engineered, not administered: identity, certificates and secrets are provisioned as code, integrated into the delivery pipeline, and designed for rotation and recovery from the outset. The role holds key custody for the estate and carries out-of‑hours accountability for the trust plane alongside a peer.

Key Responsibilities
  • Design, build and operate the workforce and service identity platform, including single sign‑on and identity provider integration (for example authentik, Okta, Keycloak or Entra ID).
  • Design, build and operate the internal certificate authority and certificate lifecycle management for the estate (for example step-ca or an equivalent internal PKI), and the secrets management platform (for example OpenBao or HashiCorp Vault), including rotation, access policy and audit.
  • Automate identity, certificate and secrets provisioning as code, embedded into CI/CD and infrastructure-as-code workflows, so that access and credentials are never provisioned by hand.
  • Own the privileged access management model: just‑in‑time elevation tied to a change record, approval workflows, and recorded break‑glass access for emergencies.
  • Implement and enforce least‑privilege access patterns across the estate to the policy set by the Platform Security Engineers, and report on whether access matches the model in practice, with independent audit of that access carried out by Security.
  • Design the trust plane for resilience, including certificate and secret rotation.
  • Design and operate key custody for the estate's cryptographic material under dual control, so that no single person can access or use production key material alone, with named custodians, recorded quorum operations and an auditable custody record. Own the delegated‑authority model that keeps custody and out‑of‑hours cover available without depending on one individual.
  • Harden the identity, certificate and secrets services to the same standard they enforce on everything else, and produce the access and certificate evidence ISO 27001, SOC 2 and enterprise customer due diligence require, for collation by the Service Delivery Manager .
  • Provide the deepest technical expertise for identity, certificate and secrets faults, approve and review just‑in‑time access requests that require judgement beyond the standard workflow, and mentor engineers across the function on identity and secret management practice.
  • Own the privileged access management model: just‑in‑time elevation tied to a change record, approval workflows, and recorded break‑glass access for emergencies, designed so that no one approves their own access and privileged access to the trust plane itself is approved outside this role's own team.
Skills & Experience

Required Skills

  • Deep experience designing, building and operating identity and access management platforms, including single sign‑on and identity provider integration (for example Okta, Keycloak, Entra ID or authentik).
  • Strong experience with certificate lifecycle management and internal public key infrastructure (for example step‑ca, HashiCorp Vault PKI, or an equivalent internal CA).
  • Strong experience with secrets management platforms (for example HashiCorp Vault, OpenBao, or equivalent), including rotation, access policy and audit.
  • Practical experience with privileged access management, just‑in‑time elevation and break‑glass design for production environments.
  • Experience with hardware security modules and key custody practices for production cryptographic material, including dual control or quorum‑based custody models.
  • Solid understanding of zero‑trust architecture principles, and how to apply them to a multi‑tenant platform.
  • Experience embedding identity and secrets into CI/CD and infrastructure‑as‑code workflows.
  • Strong scripting or programming ability for identity automation and tooling (for example Python, Go or Bash).
  • Demonstrated experience as a senior escalation point for identity and security‑adjacent faults in a 24/7 production environment.
  • Practical understanding of how identity and access controls produce evidence for frameworks such as ISO 27001 or SOC 2, including separation of duties, independent approval of privileged access, and the design of controls that hold when the person designing them is also a user of them.
  • Clear technical judgement and communication, able to explain trust‑model decisions to both engineers and auditors.

Preferred Experience

  • Experience with Kubernetes‑native identity patterns, such as workload identity or SPIFFE/SPIRE.
  • Experience in a multi‑tenant service provider, cloud or colocation environment.
  • Familiarity with GPU or HPC infrastructure and its identity and access requirements.
  • Relevant security or identity certification (for example CISSP, or a vendor‑specific identity credential).
  • A Bachelor's degree in computer science, engineering or a related discipline, or an equivalent combination of relevant experience and training.
Expected Outcomes
  • Identity, certificate and secrets services built and running to their declared service levels, with certificate expiry no longer a source of incidents.
  • Standing privileged access replaced by just‑in‑time elevation tied to a change record.
  • Key custody operating under dual control, with a complete custody record and a tested recovery path.
  • Certificate and secret rotation automated end to end and exercised in production rather than documented.
  • Access and certificate evidence accepted at first pass in audit and customer due diligence.
Location & Reporting

Location : Based in Australia or Singapore, with travel to Australian AI Factory sites as required.

On-call: The function runs 24/7. First line monitoring and first response sit with the operations centre. This role shares the after‑hours escalation roster for its domain with the other senior engineers in the function.

About Firmus Technologies

Firmus Technologies is a global leader pioneering the solution to AI’s energy challenge, founded in Australia in 2019 by a visionary team of entrepreneurs and engineers passionate about sustainable computing infrastructure.

Firmus builds and operates AI infrastructure across Asia‑Pacific, utilising its proprietary AI Factory platform to deliver transformative cost‑effective GPU clusters and AI cloud services for developers, enterprise, education and government users.

We are committed to building a diverse and inclusive workplace. We encourage applications from candidates of all backgrounds who are passionate about creating a more sustainable future through innovative engineering solutions.

Join us in our mission to revolutionise the AI industry through sustainable practices and cutting‑edge engineering.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Platform Identity Engineer
Principal Platform Identity Engineer

Firmus Technologies • Sydney

On-site
AUD 180,000 - 230,000
Senior Platform Security Engineer
Senior Platform Security Engineer

Firmus Technologies Pty Ltd. • Sydney

Hybrid
AUD 180,000 - 210,000
Senior Kubernetes Platform Engineer
Senior Kubernetes Platform Engineer

Firmus Technologies Pty Ltd. • Sydney

On-site
AUD 180,000 - 260,000
Senior Platform Reliability Engineer
Senior Platform Reliability Engineer

Firmus Technologies • City of Melbourne

On-site
AUD 180,000 - 260,000
Service Delivery Manager
Service Delivery Manager

Firmus Technologies Pty Ltd. • Sydney

On-site
AUD 120,000 - 180,000
Senior Security Engineer, Platform Engineering
Senior Security Engineer, Platform Engineering

Firmus Technologies • Sydney

On-site
AUD 150,000 - 210,000
Senior Security Engineer, Platform Engineering
Senior Security Engineer, Platform Engineering

re-zoo-me • Sydney

Hybrid
AUD 180,000 - 240,000
Senior AI Security Engineer
Senior AI Security Engineer

Firmus Technologies • Sydney

Hybrid
AUD 180,000 - 240,000
Senior Platform Security Engineer
Senior Platform Security Engineer

Firmus Technologies • Sydney

On-site
AUD 170,000 - 260,000
null
Senior Platform Security Engineer
Senior Platform Security Engineer

Firmus • Sydney

On-site
AUD 180,000 - 260,000