Information Security Engineer, Bare Metal

fluidstack

New York City, USonsite$230k-$310k/yrPosted May 26, 2026
Posting intelligenceListed a whileReposted 97×, possible evergreen/ghost posting

Skills

ansiblepythonleverrustgo

About the role

ABOUT FLUIDSTACK

We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We're singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.

We hire people who care deeply about this problem space. If that is you, please apply!

HOW WE OPERATE

- Extreme ownership. Full autonomy. Own things end to end often taking on scope outside your core role without being asked to get things done.

- Velocity. We drive everything forward as fast as possible.

- First principles. Challenge every assumption. Zero analogy thinking, no egos, the best idea wins.

- Love of the game. The frontier of AI is the most interesting problem of our time. We put in long hours at high intensity to push the frontier forward.

THE SECURITY TEAM

Examples of key problems the team is working on

- You're securing the frontier of AI. The model weights training on our infrastructure are the most valuable and most targeted artifacts in technology, and we're standing up the compute to hold them faster than anyone ever has. A breach isn't a leak, it's the frontier walking out the door.

- Build the entire security program from scratch. Most leaders inherit someone else's system and spend a career patching it. Here you own it end to end, bare metal to boardroom, as we scale across continents.

- Your threat surface is measured in gigawatts. The customers running on our infrastructure are building the most consequential technology in human history, and being responsible for the physical and logical security of that work makes everything else feel small.

ROLE SCOPE

- Own end-to-end security for every server in the bare metal fleet, from supply chain and provisioning through hardening, operation, and secure decommissioning.

- Design and maintain hardened golden OS images with automated vulnerability scanning, patch pipelines, and configuration-drift detection.

- Define and enforce the BMC security model (access control, credential rotation, audit logging, firmware integrity) for one of the most under-defended surfaces in the industry.

- Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture, applying zero-trust from the top-of-rack up.

- Implement data-at-rest encryption, key management, and secure storage access at fleet scale, and build the automation that makes secure-by-default the path of least resistance.

- Lead threat modeling and security reviews for new hardware platforms and network designs, and respond to incidents touching the physical fleet.

WHAT WE'RE LOOKING FOR

The below is a starting point. We always make space for exceptional people, so if you don't fit this role exactly, tell us where you would https://jobs.ashbyhq.com/fluidstack/05c2e69c-42f9-4fcb-9cf0-a467aaf98f1c.

- You've worked in information security or infrastructure engineering with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure.

- You harden Linux deeply (SELinux, AppArmor, kernel-level security) and command network security (TCP/IP, VPNs, firewall rulesets, zero-trust).

- You implement encryption in practice, including disk-level (LUKS) and hardware-level, and you understand HSMs and trusted computing (TPM/TXT).

- You automate fluently in Python, Go, or Rust, with configuration management (Ansible, Puppet, Chef).

- You work well across engineering teams and communicate security decisions clearly.

- Bonus: BMC platforms (OpenBMC, iDRAC, iLO). Hardware root of trust and secure boot. Compliance standards (SOC 2, ISO 27001, FedRAMP). CISSP, OSCP, or CEH.

SALARY & BENEFITS

- Competitive total compensation package (salary + equity).

- Retirement or pension plan, in line with local norms.

- Health, dental, and vision insurance.

- Generous PTO policy, in line with local norms.

The base salary range for this position is $230,000 - $310,000 per year, depending on experience, skills, qualifications, and location. This range represents our good faith estimate of the compensation for this role at the time of posting. Total compensation may also include equity in the form of stock options.

We are committed to pay equity and transparency.

You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email careers@fluidstack.io with your resume/CV, the role you've applied for, and the date you submitted your application-- someone from our recruiting team will be in touch.

Compensation

This Security Engineer role pays $230k-$310k/yr. Within typical range for security engineer roles in United States.

Questions about this role

Click "Apply with AI Applyd" above. We auto-fill the application from your resume and answer screening questions in seconds. No copy and paste, no juggling tabs.

Compensation for Security Engineer roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Security Engineer hub for United States medians across recent openings.

Most applications complete in under 90 seconds. You can track the status in your dashboard and watch the screenshot proof land the moment the application submits.

AI Applyd supports Greenhouse, Lever, Ashby, Workday, iCIMS, SmartRecruiters, Personio, Teamtailor and other major ATS platforms. If we can submit through the platform, we do.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.