Senior Infrastructure Security Engineer

Crusoe

2h ago 0 views 0 applications
Full-time On-site
Dublin - IE
Competitive
Full-time
Security Engineer

Job Description

Senior Infrastructure Security Enginee

Imagine being at the forefront of the greatest industrial revolution of our time. At Crusoe, we're not just building the future; we're accelerating the abundance of energy and intelligence by owning and operating every layer of the AI infrastructure stack—from electrons to tokens. We're solving the boundless demand for AI compute, tackling the power bottleneck head-on with an energy-first approach that makes AI infrastructure better for the world and faster for innovators.

We're seeking problem-solvers, opportunity-finders, and urgent builders who believe in the scale of our ambition. If you thrive on a path not fully paved, want to grow your career alongside experts in energy, manufacturing, data center construction, and cloud services, and want to do the most meaningful work of your career, come build with us.

The Opportunity: Architecting AI's Secure Foundation

Crusoe's mission demands an uncompromising security posture. As a **Senior Infrastructure Security Engineer**, you will be pivotal in establishing this foundation through deep visibility and granular access controls across our global compute platform. This is a hands-on role where you will leverage advanced tooling like Wiz and build infrastructure services as the primary mechanism to enforce world-class security standards, ensuring the integrity and resilience of our cutting-edge AI infrastructure.

What You'll Be Building and Securing

Lead comprehensive **Infrastructure Security Posture Management (ISPM)** and cloud-native visibility initiatives. You'll expertly leverage tools like **Wiz** to proactively identify and mitigate risks, drift, and misconfigurations across our critical cloud and on-prem infrastructure.
Champion and enforce robust **Infrastructure-as-Code (IaC)** standards (e.g., **Terraform**) to establish secure defaults, ensure immutability, and implement proactive drift detection mechanisms.
Drive **Infrastructure Security Access and Posture Management** across both cloud and on-prem environments, ensuring unparalleled visibility and robust governance.
Design and implement automated security guardrails, seamlessly integrating them into our **CI/CD and deployment pipelines** to secure our release processes.
Develop and operate critical **security-as-a-service platforms**, including robust **secrets management** and streamlined **certificate lifecycle management**, simplifying secure developer workflows while reinforcing our overall security posture.
Engineer and maintain secure **certificate lifecycles (X.509, SSH)** to establish and manage trusted machine-to-machine communications.
Contribute to cutting-edge **identity-centric access control systems**, specifically focusing on **short-lived, Just-In-Time (JIT) access models**, **Zero Trust principles**, and automated authorization policies to eliminate standing privileges.
Secure core network foundations, including our global **DNS architecture, service discovery**, and critical **network authentication systems**.
Design and maintain stringent **authentication controls for network infrastructure** to ensure secure, continuously monitored access.
Partner closely with infrastructure, platform, and SRE teams to identify and remediate security gaps in foundational systems, fostering a culture of shared security ownership.

What You'll Bring to Our Team

5-8 years of hands-on experience in infrastructure engineering, SRE, or dedicated security engineering roles.
Deep understanding of security principles across the entire technology stack, from **Linux and container runtimes to cloud control planes**.
Proven expertise in utilizing **Infrastructure-as-Code (Terraform)** to manage complex, multi-environment infrastructure at enterprise scale.
Strong knowledge of **cryptography, secrets management, PKI**, and modern authentication standards.
Extensive experience securing public cloud environments (**AWS, GCP**) and/or bare-metal infrastructures.
Strong networking fundamentals, including **routing, segmentation, firewalls**, and a practical understanding of **Zero Trust architectures**.
Hands-on experience with **Kubernetes and container security**, including secure secrets injection into microservices.
Fluency in at least one programming language (**Go or Python preferred**) for automation, tooling, and security service development.

Bonus Points for:

A background in securing high-scale cloud or AI infrastructure environments.
Experience implementing **Zero Trust identity architectures** end-to-end.
Familiarity with bare-metal provisioning and data center security considerations.
Experience building or operating internal security platforms (e.g., Vault-as-a-Service).
Deep experience with **Wiz** or similar **CSPM platforms** for enterprise-scale risk management.

Benefits:
Crusoe offers a competitive benefits package designed to support financial security, health, and overall well-being, including pension contributions, private health and dental insurance, income protection, life assurance, and more.

Compensation:
Compensation will be paid as salary or hourly. Compensation to be determined by the applicant’s education, experience, knowledge, skills, and abilities, as well as internal equity and alignment with market data.

Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.