Sr. Staff Platform Security Engineer, Cloud Infrastructure

Groq, Inc.

Texas

Remote

USD 341,000 - 402,000

Full time

4 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Groq, Inc. seeks a senior software engineer and security leader to set technical direction and build critical security capabilities across identity, access management, Kubernetes, multi-tenant infrastructure, secrets, encryption, and certificate management for Groq's inference platform.

This role is based in the Dallas, San Francisco, or New York City area with remote work flexibility as Groq establishes its local offices, transitioning to onsite once opened.

Qualifications

  • 6+ years of software engineering experience building complex infrastructure or distributed systems.
  • Deep experience in cloud and platform security, identity and access, Kubernetes.
  • Experience setting technical direction and owning complex security architecture.
  • Deep experience with identity and access technologies such as OIDC, SAML, SCIM, RBAC, workload identity, MFA.
  • Experience designing security for multi-tenant systems and isolation across network, compute, storage, and control-plane boundaries.
  • Hands-on Kubernetes security expertise: RBAC, admission control, service accounts, workload identity, secrets and encryption, policy enforcement, node security.

Responsibilities

  • Set technical direction and own the architecture for security capabilities across identity, authorization, infrastructure security, encryption, key management, and auditability.
  • Design and build identity and access systems spanning authentication, federation, authorization, workload identity, lifecycle provisioning, and administrative access.
  • Build and scale security capabilities for Kubernetes and distributed infrastructure using software, policy, automation, APIs, controllers, IaC, and GitOps.
  • Architect security controls and isolation mechanisms for multi-tenant systems across compute, network, storage, and control-plane boundaries.
  • Own infrastructure lifecycle security, including secure provisioning, secrets and credential management, encryption, and certificate lifecycle.
  • Build production software and automation that make secure infrastructure patterns reliable, scalable, and easy for engineering teams to adopt.
  • Lead security-sensitive platform designs and changes, translating complex risks and requirements into practical engineering decisions and scalable platform capabilities.
  • Shape security architecture and technical standards across Platform Engineering, influencing designs beyond the systems you directly own.
  • Partner across engineering and security to build capabilities that strengthen customer trust, platform reliability, and support compliance requirements.
  • Clearly communicate security architecture, technical tradeoffs, and risk to engineers, technical leaders, and security leadership.

Skills

Security architecture
Kubernetes security
Identity & access security
Go / Python
Leadership
Cross-functional collaboration

Tools

Go
Python
Kubernetes
GitOps
OIDC
SAML
RBAC

Job description

Mission:

Build and scale the security foundations that enable customers to run sensitive AI workloads with confidence on Groq's inference platform. You will set technical direction and build critical security capabilities across identity and access, Kubernetes, multi-tenant infrastructure, secrets, encryption, and key and certificate management. As a senior software engineer and technical leader, you will partner across Platform Engineering to turn complex security requirements into durable, automated systems that scale with the platform.

Location:

This role will be based in one of our three hiring hubs: the Dallas, San Francisco, or New York City area. The person hired for this role must be based in one of these three areas. You’ll have the flexibility to work remotely while we establish our local Groq office, with the expectation that this role will transition to onsite once the office opens.

Responsibilities & opportunities in this role:
  • Set technical direction and own the architecture for critical platform security capabilities across identity, authorization, infrastructure security, encryption, key management, and auditability.
  • Design and build identity and access systems spanning authentication, federation, authorization, workload identity, lifecycle provisioning, and administrative access.
  • Build and scale security capabilities for Kubernetes and other distributed infrastructure using software, policy, automation, APIs, controllers, Infrastructure-as-Code, and GitOps.
  • Architect security controls and isolation mechanisms for multi-tenant systems across compute, network, storage, and control-plane boundaries.
  • Own infrastructure lifecycle security, including secure provisioning, secrets and credential management, encryption, and certificate lifecycle.
  • Build production software and automation that make secure infrastructure patterns reliable, scalable, and easy for engineering teams to adopt.
  • Lead security-sensitive platform designs and changes, translating complex risks and requirements into practical engineering decisions and scalable platform capabilities.
  • Shape security architecture and technical standards across Platform Engineering, influencing designs beyond the systems you directly own.
  • Partner across engineering and security to build capabilities that strengthen customer trust, platform reliability, and support compliance requirements.
  • Clearly communicate security architecture, technical tradeoffs, and risk to engineers, technical leaders, and security leadership.
Ideal candidates have/are:
  • 6+ years of software engineering experience building complex infrastructure or distributed systems, with deep experience in cloud and platform security, identity and access, Kubernetes, or related infrastructure security domains.
  • Demonstrated experience setting technical direction and owning complex security architecture across multiple systems, teams, or infrastructure domains.
  • Deep experience with identity and access technologies such as OIDC, SAML, SCIM, RBAC, workload identity, short-lived credentials, and multi-factor authentication.
  • Deep experience designing security for multi-tenant systems and isolation across network, compute, storage, and control-plane boundaries.
  • Hands-on Kubernetes security expertise, including RBAC, admission control, service-account and workload identity, secrets and encryption, policy enforcement, and node security.
  • Strong understanding of secrets management, encryption, key management, certificate lifecycle, and secure credential management.
  • Strong software engineering skills in Go, Python, or similar languages, with experience designing, building, and operating production systems.
  • A software-first approach to security, with experience building controls through APIs, controllers, automation, policy, Infrastructure-as-Code, GitOps, or similar approaches.
  • Experience leading ambiguous, cross-functional technical initiatives and influencing engineering direction across teams.
  • Ability to reason about complex security systems end to end and communicate technical risk and architectural tradeoffs clearly to different audiences.
  • Experience building identity, key-management, network security, or infrastructure security capabilities for cloud platforms is valuable.
  • Experience with network policy and encryption or security for high-performance storage and distributed infrastructure is valuable.
  • Experience translating security and compliance requirements into automated evidence and production-ready controls is valuable.
  • Experience building Kubernetes operators, admission webhooks, or similar infrastructure automation is valuable.
Why Join Us:
  • Purposeful Hiring: You’re not here by accident, and neither is anyone else. Every teammate is handpicked with intention because who we build with matters.
  • Builders Wanted: You’re not just riding the rocket ship, you’re building it. Your work directly shapes the trajectory of our company.
  • Mission-Driven Work: We’re here to make a real impact. Our mission fuels everything we do.
  • Tackling Hard Problems: If easy isn’t your thing, you’re in the right place. We solve some of the most complex and exciting challenges in our space.
  • Excellence Is The Standard: High performance isn’t just encouraged, it’s the baseline. And it’s contagious.

If this sounds like you, we’d love to hear from you!

Compensation:

Groq is committed to providing competitive compensation through our Total Cash philosophy, which incorporates potential bonus value directly into base pay. The total cash salary range for this position, which is inclusive of the potential bonus value, is $341,400 - $401,600, with individual placement determined by your geographic location, experience, skills, and alignment with internal compensation standards. This range is specific to candidates located in the United States. Compensation for international candidates will vary based on local market dynamics. Beyond cash compensation, Groq also offers a Long-Term Incentive (LTI) Program and a robust suite of employee benefits.

#LI-MS1

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Sr. Staff Platform Security Engineer, Cloud Infrastructure
Sr. Staff Platform Security Engineer, Cloud Infrastructure

Groq, Inc. • San Francisco (CA)

On-site
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Cloud Infrastructure
Sr. Staff Platform Security Engineer, Cloud Infrastructure

Groq, Inc. • New York (NY)

Remote
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • United States

Hybrid
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • New York (NY)

Hybrid
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • Texas

Hybrid
USD 341,000 - 402,000
Sr. Staff Platform Security Engineer, Confidential Computing
Sr. Staff Platform Security Engineer, Confidential Computing

Groq, Inc. • San Francisco (CA)

On-site
USD 341,000 - 402,000
Cloud Platform Software Engineer
Cloud Platform Software Engineer

Groq, Inc. • New York (NY)

Hybrid
USD 224,000 - 366,000
Sr./Staff Forward Deployed Engineer
Sr./Staff Forward Deployed Engineer

Groq, Inc. • Town of Texas (WI)

Hybrid
USD 270,000 - 402,000
Sr./Staff Forward Deployed Engineer
Sr./Staff Forward Deployed Engineer

Groq, Inc. • San Francisco (CA)

Hybrid
USD 270,000 - 402,000
Sr./Staff Network Design Engineer, AI/HPC
Sr./Staff Network Design Engineer, AI/HPC

Groq, Inc. • Town of Texas (WI)

Hybrid
USD 270,000 - 402,000
Remote work flexibility
Bonus and LTI by Groq
Total Cash compensation