Security Engineering Lead

Stealth Startup

Milano

On-site

EUR 110,000 - 160,000

Full time

28 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Stealth Startup is seeking a Security Engineering Lead to own the security posture of our self-contained AI/HPC compute systems. You will define end-to-end security across platform, product, and governance, with hands-on work and future leadership of the security function.

You will deliver an industrialized, defense‑in‑depth security architecture, drive supplier and software supply chain security, and work with hardware and software teams to ensure multi‑tenant isolation and regulatory readiness.

Qualifications

  • 7–12 years of hands-on security experience in cloud/infrastructure, platform, or product security.
  • Experience leading security incidents end to end and crisis management.
  • Familiarity with ISO/IEC 27001, SecNumCloud, NIS2/GDPR and EU-cloud regulation.

Responsibilities

  • Define end‑to‑end security posture for platform, product, and field deployments.
  • Implement defense‑in‑depth for Kubernetes/Talos platform including CIS benchmarks and runtime security.
  • Own identity, secrets, PKI, and multi‑tenant isolation across VMs and containers.
  • Lead security crisis management, incident response, and security runbooks.

Skills

Security leadership
Cloud security
Threat modeling
Incident response
Kubernetes security
Identity & PKI
Multi-tenant isolation

Education

Bachelor's degree (CS/Engineering/Cybersecurity)

Tools

Falco
Kyverno
OPA
Vault
cosign
sigstore
Trivy

Job description

About Us

We are an early-stage technology company operating at the intersection of Energy and AI infrastructure, focused on developing a new generation of efficient and scalable computing infrastructure.

Our approach combines distributed computing, modular infrastructure and energy efficiency to support the rapidly growing demand for AI and high-performance computing.

The company is developing a new model for deploying compute capacity in a flexible and scalable way, with a strong focus on efficiency, sustainability, reliability and responsible infrastructure development.

This is an opportunity to join a growing team at an early stage and contribute directly to the development of a new infrastructure platform, working at the intersection of power, data centers and advanced computing.

Position Type

Founding member of the Security function, initially reporting to the Head of Software

Role Overview

We are seeking a Security Engineering Lead to own the security posture and compliance of our self-contained, outdoor-deployable AI/HPC compute systems and the meshed clusters they form. This is a founding security role: you will define the end-to-end security of the product and be hands‑on building it, before growing and helping lead the security function as the company scales. The role spans three connected worlds: platform and infrastructure security (a sovereign Kubernetes/Talos GPU cloud), product and system security (physical units deployed in the field), and compliance and governance (a sovereign, multi-tenant offering operating under EU regulation). We do not expect deep mastery of every security domain on day one: we are looking for someone with a holistic security vision and a proven ability to lead through security crises, excellent in at least one core domain and with the appetite and ability to grow into the others.

What You Will Deliver

This is a high-impact, high-ownership role. You will define how our systems protect their tenants, their data, and themselves, and your security architecture will ship across every unit and cluster we deploy.

Within 6 months

You will own and deliver the security architecture of the first compute system prototype: a documented threat model of the system and mesh, hardened Talos/Kubernetes baselines, the identity, secrets and PKI foundations, a tenant-isolation model, and a first detection and incident‑response capability validated in the lab. This means driving security technology selection, making key design decisions, and working hands‑on to secure the platform and the software supply chain (signed images, SBOM) in our GitOps pipeline.

Within 12 months

You will own the security posture of the first production‑ready product: an industrialized, defense‑in‑depth platform with proven multi‑tenant isolation and secure wipe between tenants, and the compliance groundwork laid and ready for our first certification. Working closely with network, software, and hardware colleagues, you will deliver a security architecture that is documented, automated, auditable, and ready to scale into series deployment, and you will begin setting the standards and practices for a growing security team.

Key Responsibilities
  • Own the end‑to‑end security posture and threat model of the system and meshed cluster, across product/system, platform, identity, data, and inter‑site security
  • Define and implement defense‑in‑depth for the Kubernetes/Talos platform: node and cluster hardening (CIS benchmarks), admission control (OPA/Kyverno), runtime security (e.g. Falco), and NetworkPolicies
  • Own identity, secrets, and PKI: OIDC single sign‑on and RBAC, secrets management (e.g. Vault), an internal PKI, and key/certificate lifecycle (HSM where required)
  • Guarantee multi‑tenant isolation: workload isolation across VMs and containers (KubeVirt, MIG), encryption, secure wipe between tenants, and attestation
  • Stand up detection and incident response: security logging and SIEM, alerting, playbooks, and lead security crisis management end to end
  • Secure the software supply chain: SBOM, image signing (cosign/sigstore), dependency and infrastructure‑as‑code scanning, and secure GitOps practices
  • Own security compliance and governance: drive the information security management system and the sovereignty roadmap (ISO/IEC 27001, SecNumCloud, NIS2/GDPR and EU‑cloud alignment), including policies, risk management, and audit readiness
  • Contribute to product and system security together with the hardware team: secure boot, TPM/measured boot and attestation, supply‑chain integrity, and hardening of deployed units
  • Collaborate closely with network (segmentation, zero‑trust, mesh), software, and hardware colleagues, and produce security architecture documents, threat models, and operational runbooks
  • Set security standards and practices as the function grows, with a path to build and help lead a small security team
Requirements
  • Bachelor's degree in Computer Science, Engineering, Cybersecurity, or equivalent field
  • 7-12 years of hands‑on security experience in cloud/infrastructure, platform, or product security, including time in a lead or leadership role
  • A proven holistic security vision and a demonstrated ability to lead and manage security incidents and crises end to end
  • Hands‑on experience contributing to the implementation of at least one recognized framework, ISO/IEC 27001, SecNumCloud (ANSSI), or NIS2/GDPR and EU‑cloud regulation, with a solid command of its requirements
  • Deep expertise in at least one of: (a) cloud‑native/Kubernetes platform hardening, (b) identity, secrets and PKI, or (c) multi‑tenant workload isolation, with the appetite and ability to grow into the others
  • Strong foundations in detection and response and in software supply‑chain security
  • Ability to work in a fast‑paced, early‑stage environment with a high degree of ownership and autonomy
  • English speaking
Nice to Have
  • Experience securing sovereign, multi‑tenant, or otherwise regulated cloud/infrastructure
  • Product or system security and hardware‑integration security: secure boot, TPM/measured boot and attestation, and confidential computing
  • Hands‑on with cloud‑native security tooling (e.g. Falco/Tetragon, OPA/Kyverno, Vault, cosign/sigstore, Trivy)
  • Familiarity with the target stack (Talos Linux, Cilium, KubeVirt, Ceph, GitOps/FluxCD)
  • Familiarity with zero‑trust networking and network segmentation for multi‑tenant infrastructure
  • Prior experience at a hardware or infrastructure startup or scale‑up, where scope and pace require broad ownership
Location

Milan, Italy.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Network Architect Engineer
Network Architect Engineer

Stealth Startup • Milano

On-site
EUR 50,000 - 100,000
Equity
Senior Project Manager (Cyber Security)-Italy
Senior Project Manager (Cyber Security)-Italy

Integrity360 • Roma

Hybrid
EUR 75,000 - 110,000
Cybersecurity Solutions Architect
Cybersecurity Solutions Architect

NHOA Group • Torino

On-site
EUR 36,000 - 44,000
Permanent full-time contract
Flexible remote working
International, multicultural team
+1
Founding Security Engineer Lead for AI/HPC Infra
Founding Security Engineer Lead for AI/HPC Infra

Stealth Startup • Milano

On-site
EUR 110,000 - 160,000
Director of Infrastructure
Director of Infrastructure

Sysdig • Italy

On-site
EUR 150,000 - 190,000
Security Engineer (Fractional)
Security Engineer (Fractional)

Lever, Inc. • Italy

Remote
EUR 30,000 - 60,000
Fully remote
Part-time, fractional engagement
Exposure to security leadership across
Senior DevOps Engineer
Senior DevOps Engineer

EnerSys • Arezzo

On-site
EUR 90,000 - 120,000
IT & Security Manager at Exein
IT & Security Manager at Exein

Exein S.p.a. • Roma

Hybrid
EUR 55,000 - 65,000
Cyber Security Specialist
Cyber Security Specialist

Volkswagen Group Italia S.p.A. • Verona

On-site
EUR 48,000 - 56,000
Remote work up to 8 days/mo
Bonuses based on performance
Cafeteria and meal options
+1
DevSecOps Engineer
DevSecOps Engineer

Leaf Space S.r.l. • Como

On-site
EUR 45,000 - 70,000
Welfare platform
Meal vouchers
Hybrid work policy
+1