> Markdown version of [/jobs/ext/2305724-infrastructure-security-engineer](https://www.wearedevelopers.com/jobs/ext/2305724-infrastructure-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Infrastructure Security Engineer - **Company:** Crusoe's Inc - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $215,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Computing Platforms, Continuous Integration, Linux, Domain Name System (DNS), Information Security Management, Python (Programming Language), Key Management, Network Architecture, Routing, Public Key Infrastructure, X.509, Zero Trust Network Access, Service Discovery, AI Infrastructure, Google Cloud, Delivery Pipeline, Firewalls (Computer Science), Kubernetes, Infrastructure Automation Frameworks, Bare Metal, Hardware Infrastructure, Terraform, Microservices - **Published:** August 30, 2026 - **Apply:** https://www.dice.com/job-detail/91609ab7-cc44-4c5f-a50b-3e8579606acb ## About the Role * 8+ years of hands-on experience in infrastructure engineering, SRE, or security engineering * Deep understanding of security principles across the stack, from Linux and container runtimes to cloud control planes * Proven experience using Infrastructure-as-Code (Terraform) to manage complex, multi-environment infrastructure at scale * Strong knowledge of cryptography, secrets management, PKI, and modern authentication standards * Experience securing public cloud (AWS, Google Cloud Platform) and/or bare-metal environments * Strong networking fundamentals, including routing, segmentation, firewalls, and Zero Trust architectures * Hands-on experience with Kubernetes and container security, including secure secrets injection into microservices * Fluency in at least one programming language (Go or Python preferred) for automation and tooling Bonus Points * Background securing high-scale cloud or AI infrastructure * Experience implementing Zero Trust identity architectures end-to-end * Familiarity with bare-metal provisioning and data center security considerations * Experience building or operating internal security platforms (e.g., Vault-as-a-Service) * Deep experience with Wiz or similar CSPM platforms for enterprise-scale risk management. ## Description Crusoe's mission is to accelerate the abundance of energy and intelligence. We're seeking a Senior Infrastructure Security Engineer dedicated to establishing a high-assurance security posture through deep visibility and granular access controls. In this role, you will leverage advanced tooling like Wiz to maintain an uncompromising security posture, using infrastructure service building as the primary mechanism to enforce these standards across our global compute platform. What You'll Be Working On: * Drive comprehensive Infrastructure Security Posture Management (ISPM) and cloud-native visibility, leveraging tools like Wiz to identify risks, drift, and misconfigurations across cloud and on-prem infrastructure. * Championing Infrastructure-as-Code (IaC) standards (e.g., Terraform) to enforce secure defaults, immutability, and drift detection * Driving Infrastructure Security Access and Posture Management for both cloud and on-prem infrastructure to ensure comprehensive visibility and governance * Building automated security guardrails embedded directly into CI/CD and deployment pipelines * Operate security-as-a-service platforms (e.g., secrets management, certificate lifecycles) designed to reinforce our security posture and simplify developer access workflows. * Designing and operating certificate lifecycles (X.509, SSH) to support secure machine-to-machine trust * Contribute to identity-centric access control systems, specifically focusing on short-lived, Just-In-Time (JIT) access models, Zero Trust, and automated authorization policies to eliminate standing privileges. * Securing core network foundations, including global DNS architecture, service discovery, and network authentication systems * Designing and maintaining authentication controls for network infrastructure to ensure secure, monitored access * Partnering closely with infrastructure, platform, and SRE teams to identify and remediate security gaps in foundational systems ## Related Videos - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)