Staff Infrastructure Security Engineer

Crusoe

2h ago 0 views 0 applications
Full-time On-site
San Francisco, CA - US
Competitive
Full-time
Security Engineer

Job Description

Fortify the Future of AI: Senior Infrastructure Security Enginee

Crusoe is at the vanguard of the greatest industrial revolution of our time, relentlessly driving the convergence of abundant energy and intelligence. As the only vertically integrated AI infrastructure company, we don't just build layers – we own and operate every single one, from the electrons powering our systems to the tokens shaping the future of AI. Our mission? To accelerate the abundance of energy and intelligence, solving the boundless demand for AI compute by tackling the power bottleneck head-on with an energy-first approach.

We're seeking visionary problem-solvers with a keen sense of urgency, individuals who thrive on pioneering uncharted paths and believe in the monumental scale of our ambition. Join a team of experts across energy, manufacturing, data center construction, and cloud services, and build the future, faster.

If you're ready to make the most meaningful impact of your career, empowering our customers and partners to advance their AI strategies within a high-performing, mutually supportive team, then come build with us.

About the Role:
Crusoe’s mission demands an uncompromising security posture. As a Senior Infrastructure Security Engineer, you will be instrumental in architecting and establishing this high-assurance security framework. Your expertise will be critical in building deep visibility and implementing granular access controls across our global compute platform. You will leverage cutting-edge tooling, including Wiz, to ensure an ironclad security stance, using infrastructure service building as your primary mechanism to enforce these rigorous standards.

Your Impact & Key Responsibilities:

Pioneer comprehensive Infrastructure Security Posture Management (ISPM) and drive cloud-native visibility, utilizing advanced platforms like Wiz to proactively detect and mitigate risks, drift, and misconfigurations across our expansive cloud and on-prem infrastructure.
Champion Infrastructure-as-Code (IaC) standards (e.g., Terraform), implementing secure defaults, ensuring immutability, and establishing robust drift detection mechanisms.
Lead Infrastructure Security Access and Posture Management initiatives for both cloud and on-prem environments, ensuring unparalleled visibility and governance across all access vectors.
Design and embed automated security guardrails directly into our critical CI/CD and deployment pipelines, securing our development lifecycle from inception to operation.
Operate and enhance security-as-a-service platforms, including secrets management and certificate lifecycle management, to reinforce our security posture and streamline secure developer workflows.
Architect and maintain robust certificate lifecycles (X.509, SSH), foundational to establishing secure machine-to-machine trust across our systems.
Contribute actively to identity-centric access control systems, with a strong focus on implementing short-lived, Just-In-Time (JIT) access models, advocating Zero Trust principles, and developing automated authorization policies to eliminate standing privileges.
Fortify our core network foundations, encompassing global DNS architecture, sophisticated service discovery mechanisms, and advanced network authentication systems.
Design, implement, and maintain stringent authentication controls for all network infrastructure, ensuring secure and continuously monitored access.
Collaborate strategically with infrastructure, platform, and SRE teams to proactively identify and remediate security gaps within foundational systems, fostering a culture of shared security responsibility.

Who You Are & What You'll Bring:

A minimum of 8+ years of hands-on experience in critical infrastructure engineering, SRE, or dedicated security engineering roles.
Deep, foundational understanding of security principles spanning the entire stack, from Linux and container runtimes to sophisticated cloud control planes.
Proven expertise in leveraging Infrastructure-as-Code (Terraform) to meticulously manage complex, multi-environment infrastructure at enterprise scale.
Strong knowledge of advanced cryptography, secrets management, PKI, and modern authentication standards.
Extensive experience securing public cloud environments (AWS, GCP) and/or bare-metal data center operations.
Mastery of networking fundamentals, including routing, segmentation, firewalls, and modern Zero Trust architectures.
Hands-on experience with Kubernetes and container security, including secure secrets injection into microservices.
Fluency in at least one programming language (Go or Python preferred) for robust automation and tooling development.

Bonus Points for:

A demonstrable background in securing high-scale cloud or cutting-edge AI infrastructure.
Experience implementing end-to-end Zero Trust identity architectures.
Familiarity with bare-metal provisioning and critical data center security considerations.
Experience building or operating internal security platforms (e.g., Vault-as-a-Service).
Deep experience with Wiz or similar CSPM platforms for enterprise-scale risk management.

Benefits:

Competitive compensation and equity packages
Restricted Stock Units
Paid time off, paid holidays & leave of absence programs
Comprehensive health, dental & vision insurance
Employer contributions to HSA account
Paid parental leave
Paid life insurance, short-term and long-term disability
Professional development & tuition reimbursement
Mental health & wellness support
Commuter benefits (parking & transit)
Cell phone stipend
401(k) Retirement plan with company match up to 4% of salary
Volunteer time off
Global travel insurance & emergency assistance
Daily meals allowance
Additional perks & programs specific to location

Compensation Range:
Compensation will be paid in the range of up to $215,000 - $260,000 + Bonus. Restricted Stock Units are included in all offers. Compensation to be determined by the applicant's knowledge, education, and abilities, as well as internal equity and alignment with market data.

Crusoe is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, disability, genetic information, pregnancy, citizenship, marital status, sex/gender, sexual preference/orientation, gender identity, age, veteran status, national origin, or any other status protected by law or regulation.

CyberJob.app

Your trusted source for cybersecurity job opportunities worldwide.


© 2026 CyberJob.app. All rights reserved.