Cloud Infrastructure Security Engineer (Systems/Kernel)
- Company
- Runpod
- Location
- Remote
- Work type
- Full Time
- Posted
- 2026-08-10
Job description
Responsibilities:
Systems Isolation: Design and implement robust workload and network isolation architectures for RunPod's multitenant GPU bare-metal and virtualized environments.
Kernel & Container Security: Harden Linux kernel configurations, container runtimes (e.g., Docker, containerd), and orchestration layers (e.g., Kubernetes) against breakouts and privilege escalation.
Infrastructure Threat Modeling: Conduct deep-dive security assessments and penetration testing specifically targeting our hypervisor, network stack, and hardware interfaces.
Active Defense: Write code (primarily C, Go, or Rust) to implement custom security controls, telemetry, and fixes at the OS and infrastructure level.
Hardware Security: Evaluate and mitigate security considerations specific to GPU architecture, PCIe pass-through, and shared memory spaces.
Incident Response: Serve as the technical escalation point for infrastructure-level security incidents, developing forensic capabilities for ephemeral container environments.
Required Qualifications:
5+ years of experience in infrastructure or systems-level security engineering.
Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor).
Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques in multitenant environments.
Strong systems-level programming skills in C, Go, Rust, or Python.
Familiarity with GPU architecture and hardware-level security considerations.
Experience in securing bare-metal cloud infrastructure and mitigating lower-level CVEs.
Preferred Qualifications:
Contributions to open-source systems security projects or virtualization research.
Experience writing or deploying eBPF-based security tooling.
Deep knowledge of low-level networking protocols and virtualized network security.
What You’ll Receive:
The competitive base pay for this position ranges from ($152,000 - $175,000). This salary range may be inclusive of several career levels at Runpod and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location
Meaningful equity in a fast-growing company- everyone on the team receives stock options — your impact drives our growth, and you share in the upside.
Generous medical, dental & vision plans
Flexible PTO- take the time you need to recharge
Most roles are remote work first with an inclusive, collaborative teams utilizing slack as the main form of internal communication
Join a passionate team on the cutting edge of AI infrastructure — where culture, learning, and ownership are at the heart of how we scale.
$1,200 Home Office & Equipment Stipend- We set you up for success from day one with gear and support to create your ideal workspace
Skills Required
5+ years of experience in infrastructure or systems-level security engineering
Extensive knowledge of Linux kernel internals (cgroups, namespaces, eBPF, SELinux/AppArmor)
Deep understanding of virtualization technologies (KVM, QEMU) and workload/network isolation techniques
Strong systems-level programming skills in C, Go, Rust, or Python
Familiarity with GPU architecture and hardware-level security considerations
Experience securing bare-metal cloud infrastructure and mitigating lower-level CVEs
Contributions to open-source systems security projects or virtualization research
Experience writing or deploying eBPF-based security tooling
Deep knowledge of low-level networking protocols and virtualized network security