Information Security Engineer, Bare Metal
Skills
About the role
About Fluidstack
We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.
We're singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.
We hire people who care deeply about this problem space. If that is you, please apply!
About The Role
Frontier AI runs on bare metal — and the bare metal it runs on has to be trustworthy from the silicon up. As Fluidstack's Information Security Engineer for Bare Metal, you'll own the security of the physical fleet powering some of the most important AI workloads in the world. This is a deeply technical, hands-on role for an engineer who thinks in firmware, kernels, and packet flows, and who wants the rare opportunity to design fleet-wide security controls from a clean slate rather than inherit someone else's compromises.
You'll work at the intersection of hardware, operating systems, and network security in an environment where performance margins are thin, customer trust is paramount, and the threat model includes nation-state-level adversaries. The systems you build will protect tens of thousands of GPUs and the workloads of customers whose models will shape the next decade of computing.
What You’ll Own
Fleet lifecycle security. End-to-end security for every server in our bare metal fleet — from supply chain and provisioning through hardening, operation, and secure decommissioning.
Hardened OS images. Design and maintain the golden images that run our production and development environments, including automated vulnerability scanning, patch pipelines, and configuration drift detection.
BMC security. Define and enforce the security model for baseboard management controllers: access control, credential rotation, audit logging, and firmware integrity. BMCs are one of the most under-defended surfaces in the industry; you'll make ours the exception.
Network security. Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture for the bare metal environment, with zero-trust principles applied from the ToR up.
Storage and data protection. Implement data-at-rest encryption, key management, and secure access for local and networked storage at fleet scale.
Security automation. Build the tooling that makes secure-by-default the path of least resistance: configuration management, policy-as-code, and continuous compliance checks across the fleet.
Detection and response. Integrate monitoring tailored to bare metal infrastructure and act as a responder for incidents touching the physical fleet.
Threat modeling and review. Lead security reviews and threat modeling for new hardware platforms, network designs, and infrastructure changes — shaping decisions before they're locked in.
About You
7+ years of experience in an Information Security or Infrastructure Engineering role, with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure.
Deep practical experience with Linux operating system hardening (e.g., SELinux, AppArmor, kernel-level security).
Expert-level knowledge of network security principles, including TCP/IP, VPNs, firewall rulesets, and zero-trust concepts.
Proven ability to implement and manage encryption technologies, including disk-level encryption (e.g., LUKS) and hardware-level encryption.
Strong scripting and automation skills in languages such as Python, Go, or Rust, and experience with configuration management tools (e.g., Ansible, Puppet, Chef).
Understanding of hardware security modules (HSMs) and trusted computing concepts (e.g., TPM/TXT).
Excellent problem-solving and communication skills, with the ability to work collaboratively across engineering teams.
Nice to Haves
Experience with specific BMC platforms (e.g., OpenBMC, Dell iDRAC, HPE iLO).
Familiarity with compliance standards relevant to bare metal environments (e.g., SOC 2, ISO 27001, FedRAMP).
Experience with hardware-level root of trust and secure boot implementations.
Relevant security certifications (e.g., CISSP, OSCP, CEH).
Salary & Benefits
Competitive total compensation package (salary + equity).
Retirement or pension plan, in line with local norms.
Health, dental, and vision insurance.
Generous PTO policy, in line with local norms.
The base salary range for this position is $230,000 - $310,000 per year, depending on experience, skills, qualifications, and location. This range represents our good faith estimate of the compensation for this role at the time of posting. Total compensation may also include equity in the form of stock options.
We are committed to pay equity and transparency.
You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email careers@fluidstack.io with your resume/CV, the role you've applied for, and the date you submitted your application-- someone from our recruiting team will be in touch.
Compensation Range: $230K - $310K
Compensation
This Security Engineer role pays $230k-$310k/yr. Within typical range for security engineer roles in United States.
Questions about this role
How do I apply to this Information Security Engineer, Bare Metal role at Fluidstack?
Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.
What's the typical salary for Security Engineer in United States?
Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.
How fast does AI Applyd auto-apply?
Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.
What ATS does Fluidstack use?
AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, LinkedIn Easy Apply, and most other ATS platforms. If we can submit through the platform, we do.
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.