Senior Security Engineer, Platform Engineering

Firmus Technologies Pty Ltd.

Singapore

On-site

SGD 180,000 - 240,000

Full time

43 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Firmus Technologies Pty Ltd. in Singapore seeks a Senior Security Engineer for the AI Platform and Infrastructure. You will own security controls across the platform delivery pipelines, IaC, and Kubernetes deployment, designing scalable safeguards.

You’ll architect identity, access, attestations, and secrets management; enforce least privilege; perform threat modelling; and drive automation to reduce manual security work. Strong written and verbal English required; travel occasional.

Qualifications

  • Bachelor's degree in computer science or a related field.
  • 7+ years in infrastructure security, platform security, cloud security, or SRE with security focus.
  • Deep knowledge of Kubernetes and container security in multi-tenant environments.

Responsibilities

  • Own security controls in platform delivery pipelines, IaC, hardware lifecycle, and Kubernetes deployment.
  • Lead threat modelling and secure design reviews for infrastructure and platform changes.
  • Write and review policy-as-code, ensuring security outcomes at scale.

Skills

Kubernetes security
Platform security
Cloud security
Threat modelling
Automation and IaC
English communication
Security reviews

Education

Bachelor's degree in computer science

Tools

Python
Go
Terraform
GitHub Actions

Job description

Firmus Technologies is a global leader pioneering the development and operation of efficient AI infrastructure across Asia Pacific.

Founded in Australia in 2019, our mission is to create the most efficient AI infrastructure by combining cutting-edge technology with a steadfast commitment to sustainability.

At Firmus, we are unique in our approach. We design, build, and operate a new class of digital infrastructure – the AI Factory. Through our model-to-grid technology approach, we have pushed the boundaries of multi-generational liquid cooling systems, energy management, AI software orchestration, and construction. For our customers, this approach allows us to make every watt count and deliver low-cost AI tokens globally.

Firmus AI Cloud

Our large-scale GPU cloud platform, Firmus AI Cloud, is purpose-built to deliver energy-efficient AI compute at scale to customers.

It empowers developers, enterprises, educational institutions, and government users to train and deploy AI models with unmatched efficiency and cost savings. With an ever-growing suite of services and applications, we are committed to delivering a cloud experience that is market-leading, proprietary, and built to scale.

ROLE SUMMARY

Firmus Technologies is seeking a Senior Security Engineer, AI Platform and Infrastructure for our Engineering and Technology team. Customers provision GPU compute through API and console, software engineers build against it, our infrastructure engineers build the bare metal, virtualisation layer and Kubernetes clusters behind it, and our operators run the platform through the same control plane. You own both layers of Firmus AI Cloud: the platform control plane that engineering teams built, and the bare-metal infrastructure it runs on. Automation is how you scale that ownership.

KEY RESPONSIBILITIES
Automation and secure delivery
  • Own the security controls in platform delivery pipelines, infrastructure-as-code, hardware lifecycle, and Kubernetes deployment. Ship them as paved roads that engineering teams and delivery partners inherit.
  • Build the systems that do the repeatable work: posture management, configuration validation, firmware and attestation checks, bulletin-driven fleet upgrades, evidence collection, and infrastructure risk detection.
  • Write and review code, infrastructure-as-code, and policy-as-code that enforce security outcomes at scale.
Security architecture and standards
  • Set the standard for platform identity, workload identity, privileged access, and secrets: short-lived credentials, federation, least-privilege access to infrastructure APIs and Kubernetes, and audit trails for administrative and control-plane actions.
  • Define the security baseline for Kubernetes and the container workloads the platform admits: control-plane isolation from worker and tenant networks, admission controls, policy-as-code, network policy, encrypted cluster secrets, no privileged containers or host mounts, least-privilege service accounts, and only trusted, pinned images.
  • Lead threat modelling and secure design review for infrastructure, platform, and shared-service changes. Define what an attacker can do and what must be true before it ships.
  • Design isolation in layers, so a single misconfiguration or outdated component cannot yield cross-tenant data access or code execution. Cover cluster, host, network, storage, control plane, and telemetry rather than relying on containers, namespaces, or dashboard filters alone.
  • Separate the infrastructure management plane from tenant workloads: out-of-band and BMC access, device and attached-NIC management, and shared network device administration.
  • Define how the platform is exposed and protected: default-deny at the edge, private endpoints for administrative and cluster APIs, enforcement placed in the path so volumetric and application-layer attacks are blocked or mitigated before it reaches services, encryption in transit and at rest, and automated certificate lifecycle.
  • Set the standard for hardware roots of trust, remote attestation, secure and measured boot, firmware lifecycle, and sanitisation of GPU, host, attached device, and storage state before hardware is reassigned. Apply those controls across sites.
Assurance and vulnerability management
  • Own platform and infrastructure security posture: what is covered, what is open, what is accepted with a named owner and an expiry, and what is overdue.
  • Prioritise fixes on exploitability and exposure alongside CVSS, hold them to the Firmus vulnerability SLAs, and drive remediation with the teams that own the platform components, so issues close at the source.
  • Extend SOC 2 Type 2 and ISO 27001 into the infrastructure lifecycle as platforms and sites grow. Evidence that a control ran should be a query, not a spreadsheet exercise.
Enablement and escalation
  • Coach engineers so secure infrastructure decisions get made without waiting for you.
  • Provide platform and infrastructure security expertise during incidents and convert recurring failure modes into controls, guardrails, standards, or automation.
  • Give engineering leadership a straight read on infrastructure risk and operational security readiness. Join customer conversations when the question is platform and infrastructure security.
SKILLS AND EXPERIENCE
  • Bachelor's degree in computer science or a related technical field.
  • 7+ years in infrastructure security, platform security, cloud security, site reliability engineering, or platform engineering with a strong security focus.
  • Has secured production bare-metal and on-premises infrastructure used by multiple teams or customers, including Linux hosts, out-of-band management, and the hardware lifecycle from commissioning through sanitisation and reassignment.
  • Deep, practical knowledge of Kubernetes and container security for a multi-tenant platform: control-plane isolation, admission controls, policy-as-code, network policy, cluster secrets, container privilege and host-access restrictions, and admitting only trusted images. Has threat modelled production infrastructure using STRIDE or an equivalent method.
  • Has run platform and workload identity in production: federation, short-lived credentials, privileged access management, secrets platforms, and least-privilege access to infrastructure APIs.
  • Has designed and tested isolation so a container or VM escape, an outdated GPU or container toolkit, or a shared control plane cannot become a cross-tenant incident.
  • Understands hardware roots of trust, secure and measured boot, signed firmware, and remote attestation, and can specify how out-of-band and device management interfaces stay separated from tenant workloads.
  • Has secured public network exposure and platform cryptography: default-deny edge controls, private endpoints for administrative APIs, encryption in transit and at rest, and automated certificate lifecycle.
  • Writes production-quality code in at least one of Python or Go and has replaced manual security work with automation that engineers trusted and kept on.
  • Has kept production host, container runtime, GPU, and firmware software current against published security bulletins.
  • Has worked under SOC 2 Type 2 or ISO 27001 and can produce evidence that a control ran.
  • Willing to join incident response for platform and infrastructure security.
  • Willing to travel overseas occasionally when the role requires it.
  • Clear and effective written and verbal communication in English.
Bonus Points
  • Experience securing AI infrastructure platforms, GPU clusters, or large-scale compute environments, including RoCE fabrics or automated hardware sanitisation.
  • Experience securing large scale hypervisors and the boundaries between guests, hosts, and assigned devices, including dedicated GPU-node architectures.
  • Experience with NVIDIA BlueField DPUs and DOCA or equivalent DPU platform software, including restricted host mode and device attestation.
  • Experience with GPU confidential computing, remote attestation, or attestation-gated workload identity.
  • Security certifications such as CISSP, Certified Kubernetes Security Specialist (CKS), or equivalent.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior AI Infrastructure Engineer, Observability
Senior AI Infrastructure Engineer, Observability

Firmus • Singapore

On-site
SGD 180,000 - 260,000
Senior Software Engineer, Platform
Senior Software Engineer, Platform

Firmus • Singapore

On-site
SGD 140,000 - 200,000
Principal Data Engineer
Principal Data Engineer

Firmus • Singapore

On-site
SGD 180,000 - 270,000
Network Engineer – AI Network & Security
Network Engineer – AI Network & Security

Firmus Technologies • Singapore

On-site
SGD 120,000 - 170,000
Diversity commitment
Senior Delivery Manager, Platform
Senior Delivery Manager, Platform

Firmus Technologies • Singapore

On-site
SGD 180,000 - 240,000
Senior AI Infrastructure Engineer, Observability
Senior AI Infrastructure Engineer, Observability

Firmus Technologies • Singapore

On-site
SGD 180,000 - 240,000
Senior Platform Security Engineer, AI Infrastructure
Senior Platform Security Engineer, AI Infrastructure

Kerry Consulting • Singapore

On-site
SGD 120,000 - 180,000
Senior AI Infrastructure Support Engineer
Senior AI Infrastructure Support Engineer

nscale operations apac pte. ltd. • Singapore

On-site
SGD 120,000 - 180,000
Senior AI Engineer (Kubernetes & Customised Scheduler)
Senior AI Engineer (Kubernetes & Customised Scheduler)

Firmus • Singapore

On-site
SGD 180,000 - 240,000
UX Engineer (AI and Applications)
UX Engineer (AI and Applications)

Firmus Technologies • Singapore

On-site
SGD 120,000 - 180,000