Runpod logo
Runpod·

Cloud Infrastructure Security Engineer (Systems/Kernel) - Runpod

Runpod is the AI Developer Cloud. More than one million developers, from indie researchers to teams running frontier models in production, use Runpod to experiment, train, fine-tune, deploy, and scale AI on one platform. The platform has processed more than 20 billion inference requests. We closed a $100M Series A in June 2026. We're at an inflection point for AI infrastructure, and we're building the platform the next generation of developers will depend on.

We're a small, remote-first team. We take ownership seriously, move fast, and ship work that more than a million developers rely on every day. We're looking for people who care deeply, build with urgency, and want to matter at scale.

As Runpod continues to revolutionize the GPU cloud computing landscape, we are seeking a systems-focused Cloud Infrastructure Security Engineer. This critical position is instrumental in safeguarding our bare-metal and virtualized environments, ensuring the absolute security, multi-tenant isolation, and integrity of our underlying GPU cloud infrastructure.

The ideal candidate possesses deep knowledge of Linux systems, kernel internals, hypervisors, and containerization. You will focus on the lowest levels of our stack—preventing tenant breakouts, securing GPU hardware allocations, and building resilient infrastructure to support AI and machine learning workloads.

Runpod is seeking an innovative security engineer who thrives at the systems layer. You will operate with an Attacker's Mindset, actively hunting for ways to break container and virtualization boundaries, and then writing the low-level code to patch them.

Responsibilities

  • Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.
  • Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.
  • Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.
  • Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.
  • Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.
  • Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.

Required Qualifications

  • 5+ years of experience in infrastructure or systems-level security engineering.
  • Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
  • Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments.
  • Strong systems-level programming skills in C, Go, Rust, or Python.
  • Familiarity with GPU architecture and hardware-level security considerations.
  • Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.

Preferred Qualifications

  • Contributions to open-source systems security projects or virtualization research.
  • Experience writing or deploying eBPF-based security tooling.
  • Deep knowledge of low-level networking protocols and virtualized network security.

What You’ll Receive

  • Competitive Salary: Base pay ranging from $152,000 - $175,000 (dependent on experience, qualifications, and location).
  • Equity: Meaningful stock options in a fast-growing company.
  • Benefits: Generous medical, dental & vision plans.
  • Time Off: Flexible PTO to take the time you need to recharge.
  • Equipment: $1,200 home office & equipment stipend to set up your ideal workspace.
  • Culture: Remote-first work environment with collaborative teams utilizing Slack as the main form of communication.

Timezone overlap

UTC-8–-4

Open to

US

Sign in to track applications and earn points.

More roles at Runpod

Similar remote roles