> Markdown version of [/jobs/ext/3465782-security-engineer-bare-metal](https://www.wearedevelopers.com/jobs/ext/3465782-security-engineer-bare-metal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Bare Metal - **Company:** Fluidstack Ltd - **Location:** New York, NY, United States - **Salary:** $224,000.0 - $275,000.0 - **Contract:** Permanent contract - **Skills:** Audit Trail, Cloud Computing, Configuration Management, Cyber Security, Linux, Firmware, Infrastructure as a Service (IaaS), Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Key Management, Network Security, Logical Security, Network Planning and Design, Network Segmentation, Ansible, Zero Trust Network Access, TCP/IP, Firewalls (Computer Science), Selinux, Bare Metal, U-Boot, Puppet, Vulnerability Analysis - **Published:** September 16, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=794fbbced7ac9098 ## About the Role The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would. * You've worked in information security or infrastructure engineering with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure. * You harden Linux deeply (SELinux, AppArmor, kernel-level security) and command network security (TCP/IP, VPNs, firewall rulesets, zero-trust). * You implement encryption in practice, including disk-level (LUKS) and hardware-level, and you understand HSMs and trusted computing (TPM/TXT). * You automate fluently in Python, Go, or Rust, with configuration management (Ansible, Puppet, Chef). * You work well across engineering teams and communicate security decisions clearly. * Bonus: BMC platforms (OpenBMC, iDRAC, iLO). Hardware root of trust and secure boot. Compliance standards (SOC 2, ISO 27001, FedRAMP). CISSP, OSCP, or CEH. ## Description * You're securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we're standing up the compute to hold them faster than anyone ever has. A breach isn't a leak, it's the frontier walking out the door. * Build the entire security program from scratch. Most leaders inherit someone else's system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents. * Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small., * Own end-to-end security for every server in the bare metal fleet, from supply chain and provisioning through hardening, operation, and secure decommissioning. * Design and maintain hardened golden OS images with automated vulnerability scanning, patch pipelines, and configuration-drift detection. * Define and enforce the BMC security model (access control, credential rotation, audit logging, firmware integrity) for one of the most under-defended surfaces in the industry. * Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture, applying zero-trust from the top-of-rack up. * Implement data-at-rest encryption, key management, and secure storage access at fleet scale, and build the automation that makes secure-by-default the path of least resistance. * Lead threat modeling and security reviews for new hardware platforms and network designs, and respond to incidents touching the physical fleet.