> Markdown version of [/jobs/ext/1889824-information-security-engineer](https://www.wearedevelopers.com/jobs/ext/1889824-information-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer - **Company:** Fluidstack Inc - **Location:** San Francisco, CA, United States - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Audit Trail, Cloud Computing, Configuration Management, Cyber Security, Data Security, Linux, Firmware, Infrastructure as a Service (IaaS), Intrusion Detection Systems, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Python (Programming Language), Key Management, Network Security, Logical Security, Network Planning and Design, Network Segmentation, Ansible, Zero Trust Network Access, Service Pack, TCP/IP, Scripting, Computer Network Operations, Model Validation, Firewalls (Computer Science), Selinux, Bare Metal, U-Boot, Puppet, Vulnerability Analysis, Golang - **Published:** July 31, 2026 - **Apply:** https://www.careerbuilder.com/job-details/information-security-engineer-bare-metal-san-francisco-ca--0dc15933-609a-4767-8872-5cfad3ecc90e ## About the Role Access Control, Ansible, Artificial Intelligence (AI), Automation, CISSP - Certified Information Systems Security Professional, Chef (Configuration Management), Cloud Computing, Communication Skills, Computer Firmware, Computer Security, Configuration Management, Cryptography, Go Programming Language (Golang), ISO (International Organization for Standardization), Incident Response, Information/Data Security (InfoSec), Infrastructure as a Service (IaaS), Model Review, Network Design, Network Operations Center, Operating Systems, Physical Security, Puppet (Configuration Management), Python Programming/Scripting Language, Regulatory Compliance, Security Infrastructure, Software Patches, Supply Chain, Threat Modeling, Vehicle Fleets, Vulnerability Scanners ## Description * High ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done. * Velocity. We drive everything forward as fast as possible. * First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins. * Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward. The Security Team Examples of key problems the team is working on * Youre securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and were standing up the compute to hold them faster than anyone ever has. A breach isnt a leak, its the frontier walking out the door. * Build the entire security program from scratch. Most leaders inherit someone elses system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents. * Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small. Role Scope * Own end-to-end security for every server in the bare metal fleet, from supply chain and provisioning through hardening, operation, and secure decommissioning. * Design and maintain hardened golden OS images with automated vulnerability scanning, patch pipelines, and configuration-drift detection. * Define and enforce the BMC security model (access control, credential rotation, audit logging, firmware integrity) for one of the most under-defended surfaces in the industry. * Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture, applying zero-trust from the top-of-rack up. * Implement data-at-rest encryption, key management, and secure storage access at fleet scale, and build the automation that makes secure-by-default the path of least resistance. * Lead threat modeling and security reviews for new hardware platforms and network designs, and respond to incidents touching the physical fleet. What Were Looking For The below is a starting point. We always make space for exceptional people, so if you dont fit this role exactly, tell us where you would. * Youve worked in information security or infrastructure engineering with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure. * You harden Linux deeply (SELinux, AppArmor, kernel-level security) and command network security (TCP/IP, VPNs, firewall rulesets, zero-trust). * You implement encryption in practice, including disk-level (LUKS) and hardware-level, and you understand HSMs and trusted computing (TPM/TXT). * You automate fluently in Python, Go, or Rust, with configuration management (Ansible, Puppet, Chef). * You work well across engineering teams and communicate security decisions clearly. * Bonus: BMC platforms (OpenBMC, iDRAC, iLO). Hardware root of trust and secure boot. Compliance standards (SOC 2, ISO 27001, FedRAMP). CISSP, OSCP, or CEH. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)