Staff Infrastructure Security Engineer

Crusoe

San Francisco (CA)

On-site

USD 215,000 - 260,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
Paid time off
401(k) match
Health, dental, vision insurance
Daily meals allowance
Cell phone stipend

Job summary

Crusoe is seeking a Senior Infrastructure Security Engineer to establish a high-assurance security posture across global compute infrastructure, leveraging Wiz and IaC. You will enforce secure defaults, manage certificates, and enable automated guardrails within CI/CD pipelines to protect cloud and bare-metal environments.

You will drive ISPM, support Just-In-Time access, Zero Trust, and automated authorization policies while collaborating with SRE, platform, and infra teams to close security

Qualifications

  • 8+ years of hands-on experience in infrastructure engineering, SRE, or security engineering.
  • Deep understanding of security principles across the stack, from Linux/container runtimes to cloud control planes.
  • Proven experience using Infrastructure-as-Code (Terraform) to manage multi-environment infra at scale.

Responsibilities

  • Drive Infrastructure Security Posture Management (ISPM) and cloud-native visibility with Wiz to identify risks, drift, and misconfigurations.
  • Champion Terraform IaC standards to enforce secure defaults and drift detection.
  • Build automated security guardrails into CI/CD and deployment pipelines.
  • Design and operate certificate lifecycles (X.509, SSH) for machine-to-machine trust.
  • Partner with SRE, platform, and infra teams to remediate security gaps in foundational systems.

Skills

Terraform
Security engineering
Kubernetes
Go/Python
Zero Trust
Cloud security
Networking
Secrets management
CI/CD security

Tools

Wiz
Vault
Terraform

Job description

Crusoe is on a mission to accelerate the abundance of energy and intelligence. As the only vertically integrated AI infrastructure company built from the ground up, we own and operate each layer of the stack — from electrons to tokens — to power the world's most ambitious AI workloads. When you join Crusoe, you join a team that is building the future, faster.

We're in the midst of the greatest industrial revolution of our time. The demand for AI compute is boundless, and power is a bottleneck. We're solving that — with an energy‑first approach that makes AI infrastructure better for the world and faster for the people innovating with AI.

We're looking for problem‑solving, opportunity‑finding teammates with a sense of urgency, who believe in the scale of our ambition and thrive on a path not fully paved — people who want to grow their careers alongside a team of experts across energy, manufacturing, data center construction, and cloud services.

If you want to do the most meaningful work of your career, help our customers and partners advance their AI strategies, and be part of a high‑performing team that believes in each other, come build with us at Crusoe.

About the Role

Crusoe’s mission is to accelerate the abundance of energy and intelligence. We’re seeking a Senior Infrastructure Security Engineer dedicated to establishing a high‑assurance security posture through deep visibility and granular access controls. In this role, you will leverage advanced tooling like Wiz to maintain an uncompromising security posture, using infrastructure service building as the primary mechanism to enforce these standards across our global compute platform.

What You'll Be Working On
  • Drive comprehensive Infrastructure Security Posture Management (ISPM) and cloud‑native visibility, leveraging tools like Wiz to identify risks, drift, and misconfigurations across cloud and on‑prem infrastructure.
  • Championing Infrastructure-as-Code (IaC) standards ("e.g., Terraform") to enforce secure defaults, immutability, and drift detection
  • Driving Infrastructure Security Access and Posture Management for both cloud and on‑prem infrastructure to ensure comprehensive visibility and governance
  • Building automated security guardrails embedded directly into CI/CD and deployment pipelines
  • Operate security‑as‑a‑service platforms ("e.g., secrets management, certificate lifecycles") designed to reinforce our security posture and simplify developer access workflows.
  • Designing and operating certificate lifecycles (X.509, SSH) to support secure machine‑to‑machine trust
  • Contribute to identity‑centric access control systems, specifically focusing on short‑lived, Just‑In‑Time (JIT) access models, Zero Trust, and automated authorization policies to eliminate standing privileges.
  • Securing core network foundations, including global DNS architecture, service discovery, and network authentication systems
  • Designing and maintaining authentication controls for network infrastructure to ensure secure, monitored access
  • Partnering closely with infrastructure, platform, and SRE teams to identify and remediate security gaps in foundational systems
What You'll Bring to the Team
  • 8+ years of hands‑on experience in infrastructure engineering, SRE, or security engineering
  • Deep understanding of security principles across the stack, from Linux and container runtimes to cloud control planes
  • Proven experience using Infrastructure-as-Code (Terraform) to manage complex, multi‑environment infrastructure at scale
  • Strong knowledge of cryptography, secrets management, PKI, and modern authentication standards
  • Experience securing public cloud ("AWS, GCP") and/or bare‑metal environments
  • Strong networking fundamentals, including routing, segmentation, firewalls, and Zero Trust architectures
  • Hands‑on experience with Kubernetes and container security, including secure secrets injection into microservices
  • Fluency in at least one programming language (Go or Python preferred) for automation and tooling
Bonus Points
  • Background securing high‑scale cloud or AI infrastructure
  • Experience implementing Zero Trust identity architectures end‑to‑end
  • Familiarity with bare‑metal provisioning and data center security considerations
  • Experience building or operating internal security platforms ("e.g., Vault‑as‑a‑Service")
  • Deep experience with Wiz or similar CSPM platforms for enterprise‑scale risk management.
Benefits
  • Competitive compensation and equity packages
  • Restricted Stock Units
  • Paid time off, paid holidays & leave of absence programs
  • Comprehensive health, dental & vision insurance
  • Employer contributions to HSA account
  • Paid parental leave
  • Paid life insurance, short‑term and long‑term disability
  • Professional development & tuition reimbursement
  • Mental health & wellness support
  • Commuter benefits (parking & transit)
  • Cell phone stipend
  • 401(k) Retirement plan with company match up to 4% of salary
  • Volunteer time off
  • Global travel insurance & emergency assistance
  • Daily meals allowance
  • Additional perks & programs specific to location
Compensation Range

Compensation will be paid in the range of up to $215,000 - $260,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's knowledge, education, and abilities, as well as internal equity and alignment with market data.

Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/ orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer, Security
Senior Software Engineer, Security

Crusoe • San Francisco (CA)

On-site
USD 175,000 - 210,000
Competitive compensation
401(k) plan with company match
Paid parental leave
+1
Senior Software Engineer, IAM
Senior Software Engineer, IAM

Crusoe • San Francisco (CA)

On-site
USD 175,000 - 220,000
Competitive compensation and equity packages
Paid time off and leave of absence programs
Comprehensive health, dental & vision insurance
+1
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Crusoe Energy Systems LLC • San Francisco (CA)

On-site
USD 210,000 - 255,000
Competitive compensation and equity packages
401(k) Retirement plan with company match
Paid parental leave
+2
Senior Manager, Infrastructure Platform Engineering
Senior Manager, Infrastructure Platform Engineering

Crusoe • San Francisco (CA)

On-site
USD 245,000 - 295,000
Competitive compensation and equity packages
Comprehensive health, dental & vision insurance
401(k) Retirement plan with company match
Director, Infrastructure Security
Director, Infrastructure Security

Crusoe • San Francisco (CA)

On-site
USD 285,000 - 335,000
Competitive compensation
Restricted Stock Units
Health, dental & vision insurance
+6
Staff Corporate Security Engineer
Staff Corporate Security Engineer

Epoch Biodesign • San Francisco (CA)

On-site
USD 210,000 - 255,000
Comprehensive health, dental & vision insurance
401(k) Retirement plan with company match
Paid parental leave
+2
Director, Infrastructure Security
Director, Infrastructure Security

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 285,000 - 335,000
Equity & RSUs
HSAs & Health Benefits
Paid time off
Senior Staff Technical Program Manager, Cloud Engineering Operations
Senior Staff Technical Program Manager, Cloud Engineering Operations

Crusoe • San Francisco (CA)

Hybrid
USD 230,000 - 280,000
Competitive compensation and equity
Equity packages
Paid time off
+12
Senior Staff Technical Program Manager, Cloud Engineering Operations
Senior Staff Technical Program Manager, Cloud Engineering Operations

AI Chopping Block • San Francisco (CA), Northern (KY)

Hybrid
USD 230,000 - 280,000
Competitive compensation and equity
401(k) Retirement plan with company-m
Comprehensive health, dental & vision
+2
Senior Staff Technical Program Manager, Cloud Engineering Operations
Senior Staff Technical Program Manager, Cloud Engineering Operations

ProducePay • United States

On-site
USD 230,000 - 280,000
Competitive compensation
Equity
Paid time off
+5