Information Security Engineer, Bare Metal

fluidstackΒ· Security
Apply Now β†—
πŸ“ Austin, TXπŸ“ New York, NYπŸ“ San Francisco, CAFullTimeπŸ’° USD 230K–310K/yr

About this role

About Fluidstack

We exist to make humanity more free. For most of human history, you farmed or you starved. Technology gave people more time for the things they wanted to do, instead of things they had to do. Powerful AI will be the biggest lever for human choice we've ever built - but only if models are aligned with what humanity actually wants. There are groups building AI who don't share these goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands human freedom or shrinks it.

We're singularly focused on delivering 10 to 100s of GWs of compute faster than anyone else, rethinking every layer of the stack. We acquire power, design and build data centers, and operate them - with teams spanning hardware and software. Speed and scale are our key differentiators. Come be a part of building civilization-scale infrastructure for AI.


We hire people who care deeply about this problem space. If that is you, please apply!

About the Role

Frontier AI runs on bare metal β€” and the bare metal it runs on has to be trustworthy from the silicon up. As Fluidstack's Information Security Engineer for Bare Metal, you'll own the security of the physical fleet powering some of the most important AI workloads in the world. This is a deeply technical, hands-on role for an engineer who thinks in firmware, kernels, and packet flows, and who wants the rare opportunity to design fleet-wide security controls from a clean slate rather than inherit someone else's compromises.

You'll work at the intersection of hardware, operating systems, and network security in an environment where performance margins are thin, customer trust is paramount, and the threat model includes nation-state-level adversaries. The systems you build will protect tens of thousands of GPUs and the workloads of customers whose models will shape the next decade of computing.

What You’ll Own:

  • Fleet lifecycle security. End-to-end security for every server in our bare metal fleet β€” from supply chain and provisioning through hardening, operation, and secure decommissioning.

  • Hardened OS images. Design and maintain the golden images that run our production and development environments, including automated vulnerability scanning, patch pipelines, and configuration drift detection.

  • BMC security. Define and enforce the security model for baseboard management controllers: access control, credential rotation, audit logging, and firmware integrity. BMCs are one of the most under-defended surfaces in the industry; you'll make ours the exception.

  • Network security. Partner with network engineering on micro-segmentation, IDS/IPS, and firewall architecture for the bare metal environment, with zero-trust principles applied from the ToR up.

  • Storage and data protection. Implement data-at-rest encryption, key management, and secure access for local and networked storage at fleet scale.

  • Security automation. Build the tooling that makes secure-by-default the path of least resistance: configuration management, policy-as-code, and continuous compliance checks across the fleet.

  • Detection and response. Integrate monitoring tailored to bare metal infrastructure and act as a responder for incidents touching the physical fleet.

  • Threat modeling and review. Lead security reviews and threat modeling for new hardware platforms, network designs, and infrastructure changes β€” shaping decisions before they're locked in.

About You

  • 7+ years of experience in an Information Security or Infrastructure Engineering role, with a strong focus on bare metal, IaaS, or high-scale cloud infrastructure.

  • Deep practical experience with Linux operating system hardening (e.g., SELinux, AppArmor, kernel-level security).

  • Expert-level knowledge of network security principles, including TCP/IP, VPNs, firewall rulesets, and zero-trust concepts.

  • Proven ability to implement and manage encryption technologies, including disk-level encryption (e.g., LUKS) and hardware-level encryption.

  • Strong scripting and automation skills in languages such as Python, Go, or Rust, and experience with configuration management tools (e.g., Ansible, Puppet, Chef).

  • Understanding of hardware security modules (HSMs) and trusted computing concepts (e.g., TPM/TXT).

  • Excellent problem-solving and communication skills, with the ability to work collaboratively across engineering teams.

Nice to Haves

  • Experience with specific BMC platforms (e.g., OpenBMC, Dell iDRAC, HPE iLO).

  • Familiarity with compliance standards relevant to bare metal environments (e.g., SOC 2, ISO 27001, FedRAMP).

  • Experience with hardware-level root of trust and secure boot implementations.

  • Relevant security certifications (e.g., CISSP, OSCP, CEH).

Salary & Benefits

  • Competitive total compensation package (salary + equity).

  • Retirement or pension plan, in line with local norms.

  • Health, dental, and vision insurance.

  • Generous PTO policy, in line with local norms.

The base salary range for this position is $230,000 - $310,000 per year, depending on experience, skills, qualifications, and location. This range represents our good faith estimate of the compensation for this role at the time of posting. Total compensation may also include equity in the form of stock options.

We are committed to pay equity and transparency.

Fluidstack is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans’ status, or any other characteristic protected by law. Fluidstack will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.

You will receive a confirmation email once your application has successfully been accepted. If there is an error with your submission and you did not receive a confirmation email, please email careers@fluidstack.io with your resume/CV, the role you've applied for, and the date you submitted your application-- someone from our recruiting team will be in touch.

Frequently Asked Questions

What is the salary for the Information Security Engineer, Bare Metal role at fluidstack?
The listed salary for this Information Security Engineer, Bare Metal position at fluidstack is USD 230K–310K/yr. This is an FullTime role.
Where is the Information Security Engineer, Bare Metal position at fluidstack located?
This Information Security Engineer, Bare Metal role at fluidstack is based in Austin, TX, New York, NY, San Francisco, CA. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Information Security Engineer, Bare Metal role at fluidstack full-time or part-time?
This is listed as a FullTime position. It is posted as a Information Security Engineer, Bare Metal role in the Security department at fluidstack.
Which team or department does the Information Security Engineer, Bare Metal at fluidstack belong to?
This Information Security Engineer, Bare Metal position is part of the Security department at fluidstack. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Information Security Engineer, Bare Metal position at fluidstack?
Click the "Apply Now" button on this page. You will be redirected to fluidstack's official application portal hosted on ashby where you can submit your application directly.
When was the Information Security Engineer, Bare Metal job at fluidstack posted?
This Information Security Engineer, Bare Metal position at fluidstack was posted on May 26, 2026. Apply as soon as possible β€” early applications are often reviewed first.
Information Security Engineer, Bare Metal
fluidstack Β· πŸ’° USD 230K–310K/yr
Apply for this role β†—

You'll be redirected to fluidstack's official application page on Ashby ATS.